This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Search Links take me to different sites

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello people. I am having a problem with my girlfriends internet browsers. Both Internet Explorer and Firefox take me to random websites when I click on my search results. I've scanned the laptop with AVG, Malwarebyts and Dr Web Fix It. Unfortunately the scans have found no viruses.

Below I have both the system Information and the Hijack this file.
Thanks for your time.
Kelv


System Information:
OS Name Microsoft Windows 7 Home Premium
Version 6.1.7600 Build 7600
Other OS Description Not Available
OS Manufacturer Microsoft Corporation
System Name MONIKA-PC
System Manufacturer Hewlett-Packard
System Model Presario CQ61 Notebook PC
System Type x64-based PC
Processor AMD Sempron™ M100, 2000 Mhz, 1 Core(s), 1 Logical Processor(s)
BIOS Version/Date Hewlett-Packard F.07, 10/10/2009
SMBIOS Version 2.6
Windows Directory C:\Windows
System Directory C:\Windows\system32
Boot Device \Device\HarddiskVolume1
Locale United Kingdom
Hardware Abstraction Layer Version = "6.1.7600.16385"
User Name monika-PC\monika
Time Zone GMT Standard Time
Installed Physical Memory (RAM) 2.00 GB
Total Physical Memory 1.75 GB
Available Physical Memory 831 MB
Total Virtual Memory 3.49 GB
Available Virtual Memory 2.01 GB
Page File Space 1.75 GB
Page File C:\pagefile.sys

Hijack This Log File:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:09:57, on 02/01/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\monika\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ares] "C:\Program Files (x86)\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12069 bytes
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
Hi Kelv,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
My last topic was closed due to inactivity, this was because I was unable to get access to the laptop due to personal problems. I am reposting my last topic as it was unresolved and I'm now able to communicate with helpers.

Hello people. I am having a problem with my girlfriends internet browsers. Both Internet Explorer and Firefox take me to random websites when I click on my search results. I've scanned the laptop with AVG, Malwarebyts and Dr Web Fix It. Unfortunately the scans have found no viruses.

Below I have both the system Information and the Hijack this file.
I also have the DDS by sUBs files, one is included and one is attached.
Thanks for your time.
Kelv


System Information:
OS Name Microsoft Windows 7 Home Premium
Version 6.1.7600 Build 7600
Other OS Description Not Available
OS Manufacturer Microsoft Corporation
System Name MONIKA-PC
System Manufacturer Hewlett-Packard
System Model Presario CQ61 Notebook PC
System Type x64-based PC
Processor AMD Sempron™ M100, 2000 Mhz, 1 Core(s), 1 Logical Processor(s)
BIOS Version/Date Hewlett-Packard F.07, 10/10/2009
SMBIOS Version 2.6
Windows Directory C:\Windows
System Directory C:\Windows\system32
Boot Device \Device\HarddiskVolume1
Locale United Kingdom
Hardware Abstraction Layer Version = "6.1.7600.16385"
User Name monika-PC\monika
Time Zone GMT Standard Time
Installed Physical Memory (RAM) 2.00 GB
Total Physical Memory 1.75 GB
Available Physical Memory 831 MB
Total Virtual Memory 3.49 GB
Available Virtual Memory 2.01 GB
Page File Space 1.75 GB
Page File C:\pagefile.sys

Hijack This Log File:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:09:57, on 02/01/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…rio&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\monika\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ares] "C:\Program Files (x86)\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

Dss file———————————————————-


DDS (Ver_10-12-12.02) - NTFS_AMD64
Run by [removed] at 22:34:09.79 on 08/01/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.1788.899 [GMT 0:00]

AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Users\monika\AppData\Roaming\wbtooltb\wbbtool1_0dn.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Users\monika\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_GB&c=94&bd=Presario&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_GB&c=94&bd=Presario&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_GB&c=94&bd=Presario&pf=cnnb
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
BHO: Webblog: {c3947f4e-8894-4c04-98e0-df182c706ddf} - C:\Program Files (x86)\wbtooltb\wbtoolDx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: IEPluginBHO Class: {f5cc7f02-6f4e-4462-b5b1-394a57fd3e0d} - C:\Users\monika\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
TB: Webblog: {c3947f4e-8894-4c04-98e0-df182c706ddf} - C:\Program Files (x86)\wbtooltb\wbtoolDx.dll
TB: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [ares] "C:\Program Files (x86)\Ares\Ares.exe" -h
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: []
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Network Error Advisor] "C:\Program Files (x86)\wbtooltb\ExeRunner.exe" wbtooltb wbbtool1_0dn
StartupFolder: C:\Users\monika\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
uPolicies-system: WallpaperStyle = 2
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
dPolicies-system: WallpaperStyle = 2
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
TB-X64: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe

================= FIREFOX ===================

FF - ProfilePath - C:\Users\monika\AppData\Roaming\Mozilla\Firefox\Profiles\31trcvsh.default\
FF - prefs.js: browser.search.selectedEngine - Search The Web
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cbc32d4&v=6.010.006.004&i=23&tp=ab&iy=&ychte=uk&lng=en-GB&q=
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Sony\Media Go\npmediago.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\monika\AppData\Roaming\Gadu-Gadu 10\_userdata\npgg.2.dll
FF - plugin: C:\Users\monika\AppData\Roaming\Mozilla\plugins\np-mswmp.dll
FF - plugin: C:\Users\monika\AppData\Roaming\Nowe Gadu-Gadu\_userdata\npgg.1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-12-8 308304]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-11-12 382032]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [2009-10-20 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2009-7-2 203264]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-11-23 6128208]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2009-7-13 27136]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-19 157264]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-10-20 215040]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2009-10-20 36408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-10-18 517448]
S3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-8-22 228408]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2009-10-20 216576]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]

=============== Created Last 30 ================

2011-01-07 13:51:47 ——– d—–w- C:\Users\monika\AppData\Roaming\wbtooltb
2011-01-07 13:51:47 ——– d—–w- C:\PROGRA~3\EmailNotifier
2011-01-07 13:51:42 ——– d—–w- C:\Program Files (x86)\wbtooltb
2011-01-07 13:51:04 ——– d—–w- C:\Program Files (x86)\TubeDownloader
2011-01-03 13:54:26 ——– d—–w- C:\Users\monika\AppData\Roaming\Vast Studios
2010-12-29 03:51:44 ——– d—–w- C:\Users\monika\AppData\Local\Geckofx
2010-12-29 03:51:36 ——– d—–w- C:\Users\monika\AppData\Roaming\Firefly Studios
2010-12-29 03:49:14 ——– d—–w- C:\PROGRA~3\Firefly Studios
2010-12-29 03:47:59 81768 —-a-w- C:\Windows\SysWow64\xinput1_3.dll
2010-12-29 03:47:59 107368 —-a-w- C:\Windows\System32\xinput1_3.dll
2010-12-29 03:47:36 ——– d—–w- C:\Program Files (x86)\Firefly Studios
2010-12-29 03:29:32 388096 —-a-r- C:\Users\monika\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-29 03:29:30 ——– d—–w- C:\Program Files (x86)\Trend Micro
2010-12-21 13:46:06 ——– d—–w- C:\PROGRA~3\{23D58E70-3B83-4B83-A227-68770F84F5EC}
2010-12-19 16:28:58 ——– d—–w- C:\Users\monika\AppData\Local\Ares
2010-12-17 17:54:46 ——– d—–w- C:\Users\monika\AppData\Roaming\Taylki
2010-12-17 17:54:46 ——– d—–w- C:\Users\monika\AppData\Roaming\Ogly
2010-12-16 20:00:38 ——– d—–w- C:\Users\monika\AppData\Roaming\BESTplayer
2010-12-16 19:50:52 3124224 —-a-w- C:\Windows\System32\win32k.sys
2010-12-16 19:49:05 395776 —-a-w- C:\Windows\System32\webio.dll
2010-12-16 19:49:05 314368 —-a-w- C:\Windows\SysWow64\webio.dll
2010-12-16 19:49:04 516096 —-a-w- C:\Program Files\Windows Mail\wab.exe
2010-12-16 19:49:04 516096 —-a-w- C:\Program Files (x86)\Windows Mail\wab.exe
2010-12-16 19:49:04 35328 —-a-w- C:\Program Files\Windows Mail\wabfind.dll
2010-12-16 19:49:03 112000 —-a-w- C:\Windows\System32\consent.exe

==================== Find3M ====================

2010-12-08 04:12:36 308304 —-a-w- C:\Windows\System32\drivers\avgldx64.sys
2010-11-29 17:38:30 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2010-11-29 17:38:30 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts
2010-11-12 13:19:38 382032 —-a-w- C:\Windows\System32\drivers\avgtdia.sys
2010-11-04 06:35:53 1194496 —-a-w- C:\Windows\System32\wininet.dll
2010-11-04 06:31:34 57856 —-a-w- C:\Windows\System32\licmgr10.dll
2010-11-04 05:52:17 978944 —-a-w- C:\Windows\SysWow64\wininet.dll
2010-11-04 05:48:36 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2010-11-04 05:16:14 482816 —-a-w- C:\Windows\System32\html.iec
2010-11-04 04:41:26 386048 —-a-w- C:\Windows\SysWow64\html.iec
2010-11-04 04:35:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2010-11-04 04:08:54 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2010-11-02 05:18:17 524288 —-a-w- C:\Windows\System32\wmicmiplugin.dll
2010-11-02 05:17:38 473600 —-a-w- C:\Windows\System32\taskcomp.dll
2010-11-02 05:17:38 1169408 —-a-w- C:\Windows\System32\taskschd.dll
2010-11-02 05:16:53 1114624 —-a-w- C:\Windows\System32\schedsvc.dll
2010-11-02 05:10:47 464384 —-a-w- C:\Windows\System32\taskeng.exe
2010-11-02 05:10:32 285696 —-a-w- C:\Windows\System32\schtasks.exe
2010-11-02 04:40:36 496128 —-a-w- C:\Windows\SysWow64\taskschd.dll
2010-11-02 04:40:36 305152 —-a-w- C:\Windows\SysWow64\taskcomp.dll
2010-11-02 04:34:44 192000 —-a-w- C:\Windows\SysWow64\taskeng.exe
2010-11-02 04:34:33 179712 —-a-w- C:\Windows\SysWow64\schtasks.exe
2010-10-27 13:28:46 11320 —-a-w- C:\Windows\help\OEM\Scripts\HPSARedirectorLauncher.exe
2010-10-27 05:06:22 2048 —-a-w- C:\Windows\System32\tzres.dll
2010-10-27 04:32:36 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2010-10-20 05:20:01 46080 —-a-w- C:\Windows\System32\atmlib.dll
2010-10-20 04:54:18 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2010-10-20 03:05:46 367104 —-a-w- C:\Windows\System32\atmfd.dll
2010-10-20 02:58:41 294400 —-a-w- C:\Windows\SysWow64\atmfd.dll

============= FINISH: 22:36:53.44 ===============

Attachments:

Hi Kelv,

Please follow these instructions to remove Zango (a piece of adware):
  • Click Start > Control Panel
  • Click Uninstall a program
  • Find Zango in the list of installed programs
  • Select it and click Uninstall
  • You'll be presented with the following screen during the uninstall process, you'll want to check either the Zango toolbar or Search Assistant, or both before clicking Next to complete the uninstall.
  • Zango should now be uninstalled from your computer.
===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Also please describe how your computer behaves at the moment.

===================================================

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Here are the results for both the scan and the MBRCheck. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5489 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 09/01/2011 21:25:46 mbam-log-2011-01-09 (21-25-46).txt Scan type: Quick scan Objects scanned: 159063 Time elapsed: 9 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} (Adware.Zango) -> Value: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} (Adware.Zango) -> Value: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\Windows\$ntuninstallmtf197$ (Adware.Adrotator) -> Quarantined and deleted successfully. Files Infected: (No malicious items detected) MBRCheck————————————————————————————- MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows 7 Home Premium Edition Windows Information: (build 7600), 64-bit Base Board Manufacturer: Quanta BIOS Manufacturer: Hewlett-Packard System Manufacturer: Hewlett-Packard System Product Name: Presario CQ61 Notebook PC Logical Drives Mask: 0x0000007c Kernel Drivers (total 198): 0x02C0E000 \SystemRoot\system32\ntoskrnl.exe 0x031EA000 \SystemRoot\system32\hal.dll 0x00BB5000 \SystemRoot\system32\kdcom.dll 0x00CAA000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll 0x00CB7000 \SystemRoot\system32\PSHED.dll 0x00CCB000 \SystemRoot\system32\CLFS.SYS 0x00D29000 \SystemRoot\system32\CI.dll 0x00C00000 \SystemRoot\system32\drivers\Wdf01000.sys 0x00DE9000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x00E43000 \SystemRoot\System32\Drivers\spzu.sys 0x00F69000 \SystemRoot\System32\Drivers\WMILIB.SYS 0x00F72000 \SystemRoot\System32\Drivers\SCSIPORT.SYS 0x00FA1000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x00E00000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x00E0A000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x010C1000 \SystemRoot\system32\DRIVERS\pci.sys 0x010F4000 \SystemRoot\system32\DRIVERS\isapnp.sys 0x010FD000 \SystemRoot\system32\DRIVERS\mpio.sys 0x01127000 \SystemRoot\System32\drivers\partmgr.sys 0x0113C000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x01145000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x01151000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x01166000 \SystemRoot\System32\drivers\volmgrx.sys 0x011C2000 \SystemRoot\system32\DRIVERS\intelide.sys 0x011CA000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x011DA000 \SystemRoot\system32\DRIVERS\aliide.sys 0x011E1000 \SystemRoot\system32\DRIVERS\amdide.sys 0x011E8000 \SystemRoot\system32\DRIVERS\cmdide.sys 0x01000000 \SystemRoot\System32\drivers\mountmgr.sys 0x0101A000 \SystemRoot\system32\DRIVERS\msdsm.sys 0x01040000 \SystemRoot\system32\DRIVERS\nvraid.sys 0x01069000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x01099000 \SystemRoot\system32\DRIVERS\pciide.sys 0x010A0000 \SystemRoot\system32\DRIVERS\viaide.sys 0x01289000 \SystemRoot\system32\DRIVERS\iaStorV.sys 0x013A7000 \SystemRoot\system32\DRIVERS\atapi.sys 0x013B0000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x013DA000 \SystemRoot\system32\DRIVERS\lsi_sas.sys 0x01200000 \SystemRoot\system32\DRIVERS\storport.sys 0x01262000 \SystemRoot\system32\DRIVERS\msahci.sys 0x0126D000 \SystemRoot\system32\DRIVERS\HpSAMD.sys 0x0143F000 \SystemRoot\system32\DRIVERS\adp94xx.sys 0x014BA000 \SystemRoot\system32\DRIVERS\adpahci.sys 0x01510000 \SystemRoot\system32\DRIVERS\adpu320.sys 0x0153F000 \SystemRoot\system32\DRIVERS\amdsata.sys 0x0155D000 \SystemRoot\system32\DRIVERS\amdsbs.sys 0x015A4000 \SystemRoot\system32\DRIVERS\amdxata.sys 0x015AF000 \SystemRoot\system32\DRIVERS\arc.sys 0x015C8000 \SystemRoot\system32\DRIVERS\arcsas.sys 0x01653000 \SystemRoot\system32\DRIVERS\elxstor.sys 0x016DA000 \SystemRoot\system32\DRIVERS\iirsp.sys 0x016EB000 \SystemRoot\system32\DRIVERS\lsi_fc.sys 0x0170A000 \SystemRoot\system32\DRIVERS\lsi_sas2.sys 0x0171D000 \SystemRoot\system32\DRIVERS\lsi_scsi.sys 0x0173C000 \SystemRoot\system32\DRIVERS\megasas.sys 0x01748000 \SystemRoot\system32\DRIVERS\MegaSR.sys 0x017EC000 \SystemRoot\system32\DRIVERS\nfrd960.sys 0x01600000 \SystemRoot\system32\DRIVERS\nvstor.sys 0x0184B000 \SystemRoot\system32\DRIVERS\ql2300.sys 0x01A98000 \SystemRoot\system32\DRIVERS\ql40xx.sys 0x01AF7000 \SystemRoot\system32\DRIVERS\SiSRaid2.sys 0x01B05000 \SystemRoot\system32\DRIVERS\sisraid4.sys 0x01B1D000 \SystemRoot\system32\DRIVERS\stexstor.sys 0x01B27000 \SystemRoot\system32\DRIVERS\vsmraid.sys 0x01B51000 \SystemRoot\system32\drivers\fltmgr.sys 0x01B9D000 \SystemRoot\system32\drivers\fileinfo.sys 0x01C5D000 \SystemRoot\System32\Drivers\Ntfs.sys 0x01A00000 \SystemRoot\System32\Drivers\msrpc.sys 0x01C00000 \SystemRoot\System32\Drivers\ksecdd.sys 0x01E57000 \SystemRoot\System32\Drivers\cng.sys 0x01ECA000 \SystemRoot\System32\drivers\pcw.sys 0x01EDB000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x01EE5000 \SystemRoot\system32\drivers\ndis.sys 0x02031000 \SystemRoot\system32\drivers\NETIO.SYS 0x02091000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x02203000 \SystemRoot\System32\drivers\tcpip.sys 0x020BC000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x02106000 \SystemRoot\system32\DRIVERS\wd.sys 0x0210E000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x0215A000 \SystemRoot\System32\Drivers\spldr.sys 0x02162000 \SystemRoot\system32\DRIVERS\sbp2port.sys 0x0217F000 \SystemRoot\System32\drivers\rdyboost.sys 0x021B9000 \SystemRoot\System32\Drivers\mup.sys 0x021CB000 \SystemRoot\System32\drivers\hwpolicy.sys 0x01E00000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x021D4000 \SystemRoot\system32\DRIVERS\disk.sys 0x021EA000 \SystemRoot\system32\DRIVERS\avgrkx64.sys 0x021F4000 \SystemRoot\system32\DRIVERS\AVGIDSEH.Sys 0x02000000 \SystemRoot\system32\DRIVERS\AtiPcie.sys 0x01C1A000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x01FD7000 \SystemRoot\system32\DRIVERS\avgmfx64.sys 0x01FE6000 \SystemRoot\System32\Drivers\Null.SYS 0x01FEF000 \SystemRoot\System32\Drivers\Beep.SYS 0x01C44000 \SystemRoot\System32\drivers\vga.sys 0x01A5E000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x01A83000 \SystemRoot\System32\drivers\watchdog.sys 0x01FF6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x01E4D000 \SystemRoot\system32\drivers\rdpencdd.sys 0x01C52000 \SystemRoot\system32\drivers\rdprefmp.sys 0x01BB1000 \SystemRoot\System32\Drivers\Msfs.SYS 0x01BBC000 \SystemRoot\System32\Drivers\Npfs.SYS 0x01BCD000 \SystemRoot\system32\DRIVERS\tdx.sys 0x01BEB000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x036EE000 \SystemRoot\system32\DRIVERS\avgtdia.sys 0x0374F000 \SystemRoot\System32\DRIVERS\netbt.sys 0x03600000 \SystemRoot\system32\drivers\afd.sys 0x0368A000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x03693000 \SystemRoot\system32\DRIVERS\pacer.sys 0x036B9000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x036CF000 \SystemRoot\system32\DRIVERS\netbios.sys 0x037B1000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x037CC000 \SystemRoot\system32\DRIVERS\termdd.sys 0x04449000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x0449A000 \SystemRoot\system32\drivers\nsiproxy.sys 0x044A6000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x044B1000 \SystemRoot\System32\drivers\discache.sys 0x044C0000 \SystemRoot\System32\Drivers\dfsc.sys 0x044DE000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x044EF000 \SystemRoot\system32\DRIVERS\avgldx64.sys 0x0453F000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x04565000 \SystemRoot\system32\DRIVERS\amdppm.sys 0x04685000 \SystemRoot\system32\DRIVERS\atikmdag.sys 0x04C9C000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x04D90000 \SystemRoot\System32\drivers\dxgmms1.sys 0x04DD6000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x0524D000 \SystemRoot\system32\DRIVERS\athrx.sys 0x053D6000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x05200000 \SystemRoot\system32\DRIVERS\Rt64win7.sys 0x05239000 \SystemRoot\system32\DRIVERS\usbohci.sys 0x04600000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x053E3000 \SystemRoot\system32\DRIVERS\usbfilter.sys 0x053F0000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x04656000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x04667000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x053F2000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys 0x0457A000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x04589000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x045D2000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x04400000 \SystemRoot\System32\Drivers\aac2lt72.SYS 0x05244000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x045E1000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x045EA000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x037E0000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x01800000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x036DE000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x01400000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x03794000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x01824000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x0162B000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x05455000 \SystemRoot\system32\DRIVERS\mcdbus.sys 0x05492000 \SystemRoot\system32\DRIVERS\swenum.sys 0x05494000 \SystemRoot\system32\DRIVERS\ks.sys 0x054D7000 \SystemRoot\system32\DRIVERS\umbus.sys 0x054E9000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x05543000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x05558000 \SystemRoot\system32\drivers\AtiHdmi.sys 0x05578000 \SystemRoot\system32\drivers\portcls.sys 0x055B5000 \SystemRoot\system32\drivers\drmk.sys 0x055D7000 \SystemRoot\system32\drivers\ksthunk.sys 0x056CE000 \SystemRoot\system32\DRIVERS\stwrt64.sys 0x05749000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x05766000 \SystemRoot\System32\Drivers\fastfat.SYS 0x0579C000 \SystemRoot\System32\Drivers\usbvideo.sys 0x057CA000 \SystemRoot\System32\Drivers\crashdmp.sys 0x057D8000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x057E4000 \SystemRoot\System32\Drivers\dump_msahci.sys 0x05600000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x000D0000 \SystemRoot\System32\win32k.sys 0x05613000 \SystemRoot\System32\drivers\Dxapi.sys 0x00510000 \SystemRoot\System32\TSDDD.dll 0x00650000 \SystemRoot\System32\cdd.dll 0x00850000 \SystemRoot\System32\ATMFD.DLL 0x0562D000 \SystemRoot\system32\drivers\luafv.sys 0x05650000 \SystemRoot\system32\drivers\WudfPf.sys 0x05671000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x05400000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x05686000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x05699000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x03C18000 \SystemRoot\system32\drivers\HTTP.sys 0x03CE0000 \SystemRoot\system32\DRIVERS\bowser.sys 0x03CFE000 \SystemRoot\System32\drivers\mpsdrv.sys 0x03D16000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x03D43000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x03D91000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x0506F000 \SystemRoot\system32\DRIVERS\atksgt.sys 0x050BE000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys 0x050CA000 \SystemRoot\system32\DRIVERS\lirsgt.sys 0x050D7000 \SystemRoot\system32\drivers\peauth.sys 0x0517D000 \SystemRoot\System32\Drivers\secdrv.SYS 0x05188000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x051B5000 \SystemRoot\System32\drivers\tcpipreg.sys 0x051C7000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys 0x05000000 \SystemRoot\System32\DRIVERS\srv2.sys 0x0784C000 \SystemRoot\System32\DRIVERS\srv.sys 0x07991000 \SystemRoot\system32\DRIVERS\monitor.sys 0x77530000 \Windows\System32\ntdll.dll 0x47EB0000 \Windows\System32\smss.exe 0xFF850000 \Windows\System32\apisetschema.dll Processes (total 317): 0 System Idle Process 4 System 276 C:\Windows\System32\smss.exe 344 C:\PROGRA~2\AVG\AVG10\avgchsva.exe 552 csrss.exe 632 C:\Windows\System32\wininit.exe 644 csrss.exe 720 C:\Windows\System32\winlogon.exe 772 C:\Windows\System32\services.exe 780 C:\Windows\System32\lsass.exe 788 C:\Windows\System32\lsm.exe 940 C:\Windows\System32\svchost.exe 1016 C:\Windows\System32\svchost.exe 496 C:\Windows\System32\atiesrxx.exe 800 C:\Windows\System32\svchost.exe 892 C:\Windows\System32\svchost.exe 1076 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe 1284 C:\Windows\System32\svchost.exe 1308 C:\Windows\System32\atieclxx.exe 1420 C:\Windows\System32\svchost.exe 1588 C:\Windows\System32\wlanext.exe 1608 C:\Windows\System32\conhost.exe 1728 C:\Windows\System32\spoolsv.exe 1764 C:\Windows\System32\taskhost.exe 1812 C:\Windows\System32\svchost.exe 1832 C:\Windows\System32\dwm.exe 1896 C:\Windows\explorer.exe 2040 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe 1224 C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe 1712 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 1516 C:\Program Files\IDT\WDM\sttray64.exe 1820 C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe 1880 C:\Program Files\Windows Sidebar\sidebar.exe 2016 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE 1596 C:\Program Files (x86)\MagicDisc\MagicDisc.exe 1536 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 2136 C:\Windows\SysWOW64\svchost.exe 2220 C:\Windows\System32\svchost.exe 2332 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 2340 C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe 2412 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 2464 C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2612 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 2736 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE 2824 C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe 2968 C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe 3000 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe 828 C:\Program Files (x86)\AVG\AVG10\avgnsa.exe 3188 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 3208 C:\Program Files (x86)\AVG\AVG10\avgtray.exe 3860 C:\Windows\System32\SearchIndexer.exe 3888 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe 4036 C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe 4084 C:\Windows\System32\conhost.exe 3392 C:\Windows\System32\svchost.exe 3816 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe 4308 C:\Program Files\Windows Media Player\wmpnetwk.exe 4156 C:\Windows\System32\svchost.exe 4896 C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe 4324 C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe 4496 dllhost.exe 3476 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe 3408 C:\Windows\System32\svchost.exe 1652 C:\PROGRA~2\AVG\AVG10\avgrsa.exe 3692 C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe 964 WmiPrvSE.exe 5508 C:\Windows\System32\svchost.exe 6424 C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe 5872 C:\Windows\System32\taskeng.exe 4808 C:\Windows\System32\rundll32.exe 3292 C:\Windows\System32\VSSVC.exe 5504 C:\Windows\System32\svchost.exe 424 C:\Program Files (x86)\Mozilla Firefox\firefox.exe 1984 C:\Windows\System32\audiodg.exe 2796 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe 3472 C:\Users\monika\Downloads\MBRCheck.exe 5948 C:\Windows\System32\conhost.exe 5400 C:\Program Files (x86)\Real\realplayer\realplay.exe 5324 C:\Program Files (x86)\Real\realplayer\realplay.exe 1044 C:\Program Files (x86)\Real\realplayer\realplay.exe 6808 C:\Program Files (x86)\Real\realplayer\realplay.exe 3216 C:\Program Files (x86)\Real\realplayer\realplay.exe 5328 C:\Program Files (x86)\Real\realplayer\realplay.exe 7092 C:\Program Files (x86)\Real\realplayer\realplay.exe 4572 C:\Program Files (x86)\Real\realplayer\realplay.exe 6436 C:\Program Files (x86)\Real\realplayer\realplay.exe 4820 C:\Program Files (x86)\Real\realplayer\realplay.exe 4980 C:\Program Files (x86)\Real\realplayer\realplay.exe 1760 C:\Program Files (x86)\Real\realplayer\realplay.exe 3832 C:\Program Files (x86)\Real\realplayer\realplay.exe 3700 C:\Program Files (x86)\Real\realplayer\realplay.exe 3220 C:\Program Files (x86)\Real\realplayer\realplay.exe 5188 C:\Program Files (x86)\Real\realplayer\realplay.exe 444 C:\Program Files (x86)\Real\realplayer\realplay.exe 1036 C:\Program Files (x86)\Real\realplayer\realplay.exe 436 C:\Program Files (x86)\Real\realplayer\realplay.exe 5596 C:\Program Files (x86)\Real\realplayer\realplay.exe 6936 C:\Program Files (x86)\Real\realplayer\realplay.exe 5892 C:\Windows\System32\dllhost.exe 2528 C:\Program Files (x86)\Real\realplayer\realplay.exe 2452 C:\Program Files (x86)\Real\realplayer\realplay.exe 5248 C:\Program Files (x86)\Real\realplayer\realplay.exe 4400 C:\Program Files (x86)\Real\realplayer\realplay.exe 1756 C:\Program Files (x86)\Real\realplayer\realplay.exe 3604 C:\Program Files (x86)\Real\realplayer\realplay.exe 960 C:\Program Files (x86)\Real\realplayer\realplay.exe 4840 C:\Program Files (x86)\Real\realplayer\realplay.exe 5152 C:\Program Files (x86)\Real\realplayer\realplay.exe 6868 C:\Program Files (x86)\Real\realplayer\realplay.exe 6088 C:\Program Files (x86)\Real\realplayer\realplay.exe 4816 C:\Program Files (x86)\Real\realplayer\realplay.exe 3920 C:\Program Files (x86)\Real\realplayer\realplay.exe 6600 C:\Program Files (x86)\Real\realplayer\realplay.exe 6216 C:\Program Files (x86)\Real\realplayer\realplay.exe 1256 C:\Program Files (x86)\Real\realplayer\realplay.exe 6200 C:\Program Files (x86)\Real\realplayer\realplay.exe 6160 C:\Program Files (x86)\Real\realplayer\realplay.exe 4300 C:\Program Files (x86)\Real\realplayer\realplay.exe 5756 C:\Program Files (x86)\Real\realplayer\realplay.exe 7112 C:\Program Files (x86)\Real\realplayer\realplay.exe 1708 C:\Program Files (x86)\Real\realplayer\realplay.exe 3836 C:\Program Files (x86)\Real\realplayer\realplay.exe 1340 C:\Program Files (x86)\Real\realplayer\realplay.exe 6884 C:\Program Files (x86)\Real\realplayer\realplay.exe 5320 C:\Program Files (x86)\Real\realplayer\realplay.exe 6356 C:\Program Files (x86)\Real\realplayer\realplay.exe 5616 C:\Program Files (x86)\Real\realplayer\realplay.exe 3176 C:\Program Files (x86)\Real\realplayer\realplay.exe 7132 C:\Program Files (x86)\Real\realplayer\realplay.exe 6440 C:\Program Files (x86)\Real\realplayer\realplay.exe 6308 C:\Program Files (x86)\Real\realplayer\realplay.exe 6236 C:\Program Files (x86)\Real\realplayer\realplay.exe 4744 C:\Program Files (x86)\Real\realplayer\realplay.exe 3352 C:\Program Files (x86)\Real\realplayer\realplay.exe 640 C:\Program Files (x86)\Real\realplayer\realplay.exe 6752 C:\Program Files (x86)\Real\realplayer\realplay.exe 5588 C:\Program Files (x86)\Real\realplayer\realplay.exe 3244 C:\Program Files (x86)\Real\realplayer\realplay.exe 5308 C:\Program Files (x86)\Real\realplayer\realplay.exe 3268 C:\Program Files (x86)\Real\realplayer\realplay.exe 5332 C:\Program Files (x86)\Real\realplayer\realplay.exe 6576 C:\Program Files (x86)\Real\realplayer\realplay.exe 2180 C:\Program Files (x86)\Real\realplayer\realplay.exe 7116 C:\Program Files (x86)\Real\realplayer\realplay.exe 6996 C:\Program Files (x86)\Real\realplayer\realplay.exe 5760 C:\Program Files (x86)\Real\realplayer\realplay.exe 6012 C:\Program Files (x86)\Real\realplayer\realplay.exe 5336 C:\Program Files (x86)\Real\realplayer\realplay.exe 2564 C:\Program Files (x86)\Real\realplayer\realplay.exe 5848 C:\Program Files (x86)\Real\realplayer\realplay.exe 4124 C:\Program Files (x86)\Real\realplayer\realplay.exe 5724 C:\Program Files (x86)\Real\realplayer\realplay.exe 5292 C:\Program Files (x86)\Real\realplayer\realplay.exe 5092 C:\Program Files (x86)\Real\realplayer\realplay.exe 5924 C:\Program Files (x86)\Real\realplayer\realplay.exe 3764 C:\Program Files (x86)\Real\realplayer\realplay.exe 5664 C:\Program Files (x86)\Real\realplayer\realplay.exe 2472 C:\Program Files (x86)\Real\realplayer\realplay.exe 5632 C:\Program Files (x86)\Real\realplayer\realplay.exe 6964 C:\Program Files (x86)\Real\realplayer\realplay.exe 3872 C:\Program Files (x86)\Real\realplayer\realplay.exe 7096 C:\Program Files (x86)\Real\realplayer\realplay.exe 7128 C:\Program Files (x86)\Real\realplayer\realplay.exe 5232 C:\Program Files (x86)\Real\realplayer\realplay.exe 2852 C:\Program Files (x86)\Real\realplayer\realplay.exe 5116 C:\Program Files (x86)\Real\realplayer\realplay.exe 5976 C:\Program Files (x86)\Real\realplayer\realplay.exe 3440 C:\Program Files (x86)\Real\realplayer\realplay.exe 6760 C:\Program Files (x86)\Real\realplayer\realplay.exe 6988 C:\Program Files (x86)\Real\realplayer\realplay.exe 2204 C:\Program Files (x86)\Real\realplayer\realplay.exe 5996 C:\Program Files (x86)\Real\realplayer\realplay.exe 6788 C:\Program Files (x86)\Real\realplayer\realplay.exe 3464 C:\Program Files (x86)\Real\realplayer\realplay.exe 6068 C:\Program Files (x86)\Real\realplayer\realplay.exe 1792 C:\Program Files (x86)\Real\realplayer\realplay.exe 6296 C:\Program Files (x86)\Real\realplayer\realplay.exe 6224 C:\Program Files (x86)\Real\realplayer\realplay.exe 2900 C:\Program Files (x86)\Real\realplayer\realplay.exe 7088 C:\Program Files (x86)\Real\realplayer\realplay.exe 2932 C:\Program Files (x86)\Real\realplayer\realplay.exe 1244 C:\Program Files (x86)\Real\realplayer\realplay.exe 1064 C:\Program Files (x86)\Real\realplayer\realplay.exe 888 C:\Program Files (x86)\Real\realplayer\realplay.exe 5148 C:\Program Files (x86)\Real\realplayer\realplay.exe 5612 C:\Program Files (x86)\Real\realplayer\realplay.exe 416 C:\Program Files (x86)\Real\realplayer\realplay.exe 6132 C:\Program Files (x86)\Real\realplayer\realplay.exe 5256 C:\Program Files (x86)\Real\realplayer\realplay.exe 7108 C:\Program Files (x86)\Real\realplayer\realplay.exe 860 C:\Program Files (x86)\Real\realplayer\realplay.exe 6792 C:\Program Files (x86)\Real\realplayer\realplay.exe 324 C:\Program Files (x86)\Real\realplayer\realplay.exe 2620 C:\Program Files (x86)\Real\realplayer\realplay.exe 1164 C:\Program Files (x86)\Real\realplayer\realplay.exe 5284 C:\Program Files (x86)\Real\realplayer\realplay.exe 3716 C:\Program Files (x86)\Real\realplayer\realplay.exe 3076 C:\Program Files (x86)\Real\realplayer\realplay.exe 4552 C:\Program Files (x86)\Real\realplayer\realplay.exe 6628 C:\Program Files (x86)\Real\realplayer\realplay.exe 6684 C:\Program Files (x86)\Real\realplayer\realplay.exe 476 C:\Program Files (x86)\Real\realplayer\realplay.exe 900 C:\Program Files (x86)\Real\realplayer\realplay.exe 6260 C:\Program Files (x86)\Real\realplayer\realplay.exe 6384 C:\Program Files (x86)\Real\realplayer\realplay.exe 7044 C:\Program Files (x86)\Real\realplayer\realplay.exe 5652 C:\Program Files (x86)\Real\realplayer\realplay.exe 5540 C:\Program Files (x86)\Real\realplayer\realplay.exe 6464 C:\Program Files (x86)\Real\realplayer\realplay.exe 6620 C:\Program Files (x86)\Real\realplayer\realplay.exe 4508 C:\Program Files (x86)\Real\realplayer\realplay.exe 6768 C:\Program Files (x86)\Real\realplayer\realplay.exe 2772 C:\Program Files (x86)\Real\realplayer\realplay.exe 3060 C:\Program Files (x86)\Real\realplayer\realplay.exe 4596 C:\Program Files (x86)\Real\realplayer\realplay.exe 3344 C:\Program Files (x86)\Real\realplayer\realplay.exe 5696 C:\Program Files (x86)\Real\realplayer\realplay.exe 3680 C:\Program Files (x86)\Real\realplayer\realplay.exe 2500 C:\Program Files (x86)\Real\realplayer\realplay.exe 5184 C:\Program Files (x86)\Real\realplayer\realplay.exe 1296 C:\Program Files (x86)\Real\realplayer\realplay.exe 2404 6444 C:\Program Files (x86)\Real\realplayer\realplay.exe 1072 C:\Program Files (x86)\Real\realplayer\realplay.exe 6892 C:\Program Files (x86)\Real\realplayer\realplay.exe 5044 4396 968 6948 4456 5196 4388 C:\Program Files (x86)\Real\realplayer\realplay.exe 6256 C:\Program Files (x86)\Real\realplayer\realplay.exe 6980 5560 5512 1356 C:\Program Files (x86)\Real\realplayer\realplay.exe 3612 C:\Program Files (x86)\Real\realplayer\realplay.exe 6776 C:\Program Files (x86)\Real\realplayer\realplay.exe 524 C:\Program Files (x86)\Real\realplayer\realplay.exe 2916 C:\Program Files (x86)\Real\realplayer\realplay.exe 4804 C:\Program Files (x86)\Real\realplayer\realplay.exe 1012 7068 4576 5964 6104 5488 4888 2112 C:\Program Files (x86)\Real\realplayer\realplay.exe 3144 1860 1192 2156 2884 6156 6748 6856 5744 C:\Program Files (x86)\Real\realplayer\realplay.exe 172 6920 3588 3444 2752 1400 6636 C:\Program Files (x86)\Real\realplayer\realplay.exe 6044 C:\Program Files (x86)\Real\realplayer\realplay.exe 1616 C:\Program Files (x86)\Real\realplayer\realplay.exe 4152 3564 C:\Program Files (x86)\Real\realplayer\realplay.exe 6536 C:\Program Files (x86)\Real\realplayer\realplay.exe 4876 C:\Program Files (x86)\Real\realplayer\realplay.exe 2080 C:\Program Files (x86)\Real\realplayer\realplay.exe 488 4112 7104 5600 6540 6408 2164 7160 2296 624 6020 6064 2392 2068 4256 6608 5492 6652 5388 4352 6688 4372 7184 C:\Program Files (x86)\Real\realplayer\realplay.exe 7192 C:\Program Files (x86)\Real\realplayer\realplay.exe 7208 7228 C:\Program Files (x86)\Real\realplayer\realplay.exe 7248 C:\Program Files (x86)\Real\realplayer\realplay.exe 7264 C:\Program Files (x86)\Real\realplayer\realplay.exe 7280 C:\Program Files (x86)\Real\realplayer\realplay.exe 7288 C:\Program Files (x86)\Real\realplayer\realplay.exe 7296 7304 7312 C:\Program Files (x86)\Real\realplayer\realplay.exe 7328 7344 7360 7368 7376 7392 7408 7424 7432 7440 7456 \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`0c800000 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000036`db500000 (NTFS) PhysicalDrive0 Model Number: TOSHIBAMK2555GSX, Rev: FG002C Size Device Name MBR Status ——————————————– 232 GB \\.\PhysicalDrive0 MBR Code Faked! SHA1: CCF356FEC6D9BBB29EF3EF1E4270A2B799955EA4 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Hi Kelv,

Thanks for the log. Let's run TDSSKiller and clean up your MBR infection.

Please read carefully and follow these steps.
Hi Noodle Tech. I will be posting the results as soon as I get back on my girlfriends laptop as it's her laptop that has the problem. I will be seeing her within the next two days so I'll get back to you ASAP. Thanks for your patience. Kelv

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI