This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Personal Antivirus, Backdoor.Win32

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!



Vista and Windows 7 users:
Windows 7 and Vista users will always want to right-click and choose "run as administrator" to launch any tools we use.

1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")




Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post



Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.

    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:/ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"




If you run into any trouble running the tools please let me know.
.. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 3/22/2011 1:07:21 AM System Uptime: 3/28/2011 7:31:28 PM (3 hours ago) . Motherboard: Compal | | 30FC Processor: AMD Turion™ X2 Dual-Core Mobile RM-72 | Socket M2/S1G1 | 2100/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 285 GiB total, 184.027 GiB free. D: is FIXED (NTFS) - 13 GiB total, 2.005 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP53: 3/27/2011 8:56:03 PM - Removed HiJackThis RP54: 3/27/2011 8:58:51 PM - Removed HP Total Care Advisor RP55: 3/28/2011 3:00:10 AM - Windows Update RP56: 3/28/2011 8:14:39 AM - Windows Update RP57: 3/28/2011 9:08:37 AM - Windows Update RP58: 3/28/2011 9:19:41 AM - Windows Update RP59: 3/28/2011 10:03:49 AM - Windows Update RP60: 3/28/2011 2:54:27 PM - OTL Restore Point RP61: 3/28/2011 7:41:59 PM - OTL Restore Point RP62: 3/28/2011 9:21:40 PM - OTL Restore Point . ==== Installed Programs ====================== . µTorrent Acrobat.com Activation Assistant for the 2007 Microsoft Office suites Adobe AIR Adobe Community Help Adobe Creative Suite 5 Master Collection Adobe Encore CS5 Third Party Royalty Content Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Media Player Adobe Reader 9 AMD USB Audio Driver Filter AnyDVD Atheros Driver Installation Program AVG PC Tuneup 2011 Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization Chinese Standard Catalyst Control Center Localization Chinese Traditional Catalyst Control Center Localization Czech Catalyst Control Center Localization Danish Catalyst Control Center Localization Dutch Catalyst Control Center Localization Finnish Catalyst Control Center Localization French Catalyst Control Center Localization German Catalyst Control Center Localization Greek Catalyst Control Center Localization Hungarian Catalyst Control Center Localization Italian Catalyst Control Center Localization Japanese Catalyst Control Center Localization Korean Catalyst Control Center Localization Norwegian Catalyst Control Center Localization Polish Catalyst Control Center Localization Portuguese Catalyst Control Center Localization Russian Catalyst Control Center Localization Spanish Catalyst Control Center Localization Swedish Catalyst Control Center Localization Thai Catalyst Control Center Localization Turkish ccc-core-static CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Compatibility Pack for the 2007 Office system ConvertXtoDVD 4.0.9.322 ERUNT 1.1j ESU for Microsoft Vista GIMP 2.6.11 Hewlett-Packard Active Check for Health Check Hewlett-Packard Asset Agent for Health Check Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Customer Experience Enhancements HP Doc Viewer HP Help and Support HP MediaSmart DVD HP MediaSmart Music/Photo/Video HP MediaSmart TV HP MediaSmart Webcam HP MULTIPLE MODEM INSTALLER for VISTA HP Quick Launch Buttons 6.40 H2 HP Update HP User Guides 0129 HP Wireless Assistant HPTCSSetup IDT Audio Java Auto Updater Java™ 6 Update 24 Java™ 6 Update 7 JMicron JMB38X Flash Media Controller LabelPrint LightScribe System Software 1.14.17.1 Malwarebytes' Anti-Malware Microsoft Live Search Toolbar Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 Mozilla Firefox (3.6.16) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 8 neroxml PDF Settings CS5 PxMergeModule Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Skins Splat! 1.0 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Office 2007 (KB934528) Visual Studio 2008 x64 Redistributables WinZip 15.0 . ==== Event Viewer Messages From Past Week ======== . 3/28/2011 9:20:45 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 for x64-based Systems (KB2160841). 3/28/2011 8:29:59 PM, Error: PlugPlayManager [12] - The device 'JMB38X xD Host Controller' (PCI\VEN_197B&DEV_2384&SUBSYS_30FC103C&REV_00\4&3b4983b4&0&0428) disappeared from the system without first being prepared for removal. 3/28/2011 8:29:59 PM, Error: PlugPlayManager [12] - The device 'JMB38X SD/MMC Host Controller' (PCI\VEN_197B&DEV_2382&SUBSYS_30FC103C&REV_00\4&3b4983b4&0&0028) disappeared from the system without first being prepared for removal. 3/28/2011 8:29:59 PM, Error: PlugPlayManager [12] - The device 'JMB38X SD Host Controller' (PCI\VEN_197B&DEV_2381&SUBSYS_30FC103C&REV_00\4&3b4983b4&0&0228) disappeared from the system without first being prepared for removal. 3/28/2011 8:29:59 PM, Error: PlugPlayManager [12] - The device 'JMB38X MS Host Controller' (PCI\VEN_197B&DEV_2383&SUBSYS_30FC103C&REV_00\4&3b4983b4&0&0328) disappeared from the system without first being prepared for removal. 3/28/2011 8:15:05 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070002: Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 for x64-based Systems (KB2160841). 3/28/2011 7:29:38 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 3/28/2011 6:39:14 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.14 for the Network Card with network address 00242BD32CA5 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 3/28/2011 11:08:17 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.13 for the Network Card with network address 00242BD32CA5 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 22:01:41.03 on Mon 03/28/2011 Internet Explorer: 8.0.6001.19019 BrowserJavaVersion: 1.6.0_24 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3837.1104 [GMT -4:00] . AV: AVG Anti-Virus 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Program Files (x86)\AVG\AVG10\avgchsva.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_1b06afce\STacSV64.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agr64svc.exe C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\PROGRA~1\XPOLOG~1.3\XpoLog.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\XpoLogCenter4.3\jre\bin\javaw.exe C:\Program Files (x86)\AVG\AVG10\avgam.exe C:\Program Files (x86)\AVG\AVG10\avgnsa.exe C:\Program Files (x86)\AVG\AVG10\avgemca.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Program Files (x86)\AVG\AVG10\avgrsa.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Users\joe\Downloads\OTL.exe C:\Windows\notepad.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\joe\Downloads\dds(2).scr C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://google.com/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb mWinlogon: Userinit=userinit.exe, BHO: AutorunsDisabled - No File mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" mRun: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start mRun: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe mRun: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" mRun: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam" mRun: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" mRun: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" mRun: [HP Software Update] "C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe StartupFolder: C:\Users\joe\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE uPolicies-explorer: GreyMSIAds = 1 (0x1) uPolicies-explorer: NoInstrumentation = 0 (0x0) uPolicies-explorer: NoThumbnailCache = 1 (0x1) uPolicies-explorer: DisableThumbnailsOnNetworkFolders = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: DisableStartupSound = 1 (0x1) mPolicies-system: DisableStatusMessages = 1 (0x1) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll BHO-X64: AutorunsDisabled - No File BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe mRun-x64: [Windows Defender] %PROGRAMFILES%\Windows Defender\MSASCui.exe -hide . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\joe\AppData\Roaming\Mozilla\Firefox\Profiles\0pgx703w.default\ FF - component: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}\components\Contribute.dll FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Adobe Contribute Toolbar: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox FF - Ext: Adblock Plus Pop-up Addon: [removed] - %profile%\extensions\[removed] FF - Ext: Fasterfox Lite: FasterFox_Lite@BigRedBrent - %profile%\extensions\FasterFox_Lite@BigRedBrent FF - Ext: NoSquint: [removed] - %profile%\extensions\[removed] FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;C:\WINDOWS\System32\drivers\AVGIDSEH.sys [2010-9-13 27216] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\WINDOWS\System32\drivers\avgrkx64.sys [2010-9-7 30288] R0 PxHlpa64;PxHlpa64;C:\WINDOWS\System32\drivers\PxHlpa64.sys [2011-3-23 55280] R1 Avgldx64;AVG AVI Loader Driver;C:\WINDOWS\System32\drivers\avgldx64.sys [2010-12-8 308304] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\WINDOWS\System32\drivers\avgmfx64.sys [2010-9-7 41040] R1 Avgtdia;AVG TDI Driver;C:\WINDOWS\System32\drivers\avgtdia.sys [2010-11-12 382032] R2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-9-26 27632] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648] R2 hpsrv;HP Service;C:\WINDOWS\System32\hpservice.exe [2008-3-18 30520] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-3-24 363344] R2 XpoLogCenter;XpoLogCenter;C:\PROGRA~1\XPOLOG~1.3\XpoLog.exe -zglaxservice XpoLogCenter –> C:\PROGRA~1\XPOLOG~1.3\XpoLog.exe -zglaxservice XpoLogCenter [?] R3 AVGIDSDriver;AVGIDSDriver;C:\WINDOWS\System32\drivers\AVGIDSDriver.sys [2010-8-3 133712] R3 AVGIDSFilter;AVGIDSFilter;C:\WINDOWS\System32\drivers\AVGIDSFilter.sys [2010-8-3 35920] R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-10-24 193840] R3 enecir;ENE CIR Receiver;C:\WINDOWS\System32\drivers\enecir.sys [2008-1-24 60928] R3 MBAMProtector;MBAMProtector;C:\WINDOWS\System32\drivers\mbam.sys [2011-3-22 24152] R3 usbfilter;AMD USB Filter Driver;C:\WINDOWS\System32\drivers\usbfilter.sys [2011-3-21 26168] S3 JMCR;JMCR;C:\WINDOWS\System32\drivers\jmcr.sys [2008-7-21 145496] S3 NETw3v64;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit;C:\WINDOWS\System32\drivers\NETw3v64.sys [2008-1-20 3154432] S3 PerfHost;Performance Counter DLL Host;C:\WINDOWS\SysWOW64\perfhost.exe [2008-1-20 19968] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768] S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\WINDOWS\System32\drivers\yk60x64.sys [2006-11-2 273408] S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-3-22 89920] S4 Recovery Service for Windows;Recovery Service for Windows;C:\Program Files (x86)\SMINST\BLService.exe [2008-10-24 365952] . =============== File Associations =============== . JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %* . =============== Created Last 30 ================ . 2011-03-28 21:00:50 ——– d—–w- C:\Program Files\XpoLogCenter4.3 2011-03-28 21:00:49 ——– d–h–w- C:\Program Files\Zero G Registry 2011-03-28 21:00:25 ——– d–h–w- C:\Users\joe\InstallAnywhere 2011-03-28 12:36:58 612864 —-a-w- C:\Windows\System32\vbscript.dll 2011-03-28 12:36:57 420352 —-a-w- C:\Windows\SysWow64\vbscript.dll 2011-03-27 17:39:24 ——– d—–w- C:\Users\joe\AppData\Local\Alien Skin 2011-03-27 17:25:37 ——– d—–w- C:\PROGRA~3\Alien Skin 2011-03-27 17:25:35 ——– d—–w- C:\Program Files\Alien Skin 2011-03-27 17:22:47 ——– d—–w- C:\Program Files (x86)\Alien Skin 2011-03-27 15:01:15 ——– d—–w- C:\$AVG 2011-03-27 14:06:47 ——– d—–w- C:\Users\joe\.thumbnails 2011-03-27 14:03:21 ——– d—–w- C:\Users\joe\.gimp-2.6 2011-03-27 14:01:58 ——– d—–w- C:\Program Files (x86)\GIMP-2.0 2011-03-27 01:09:34 ——– d—–w- C:\Users\joe\AppData\Roaming\AVG 2011-03-27 00:38:14 ——– d—–w- C:\Users\joe\AppData\Roaming\AVG10 2011-03-27 00:37:29 ——– d–h–w- C:\PROGRA~3\Common Files 2011-03-27 00:36:58 ——– d—–w- C:\Windows\SysWow64\drivers\AVG 2011-03-27 00:35:27 ——– d—–w- C:\Windows\System32\drivers\AVG 2011-03-27 00:35:27 ——– d—–w- C:\PROGRA~3\AVG10 2011-03-27 00:33:31 ——– d—–w- C:\Program Files (x86)\AVG 2011-03-27 00:31:52 ——– d—–w- C:\PROGRA~3\MFAData 2011-03-27 00:03:48 25048 —-a-w- C:\Program Files (x86)\Mozilla Firefox\components\browserdirprovider.dll 2011-03-27 00:03:48 140248 —-a-w- C:\Program Files (x86)\Mozilla Firefox\components\brwsrcmp.dll 2011-03-27 00:03:46 66520 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll 2011-03-27 00:03:45 492504 —-a-w- C:\Program Files (x86)\Mozilla Firefox\sqlite3.dll 2011-03-27 00:03:45 1018328 —-a-w- C:\Program Files (x86)\Mozilla Firefox\js3250.dll 2011-03-26 03:59:54 ——– d—–w- C:\Users\joe\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2011-03-25 23:58:18 ——– d—–w- C:\PROGRA~3\vsosdk 2011-03-25 22:15:37 ——– d—–w- C:\Program Files (x86)\SlySoft 2011-03-25 18:52:13 ——– d—–w- C:\Users\joe\AppData\Roaming\Adobe Mini Bridge CS5 2011-03-25 18:52:12 ——– d—–w- C:\Users\joe\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 2011-03-25 03:09:08 ——– d—–w- C:\Users\joe\AppData\Local\Sony 2011-03-25 02:25:52 ——– d—–w- C:\Users\joe\AppData\Roaming\NeroDigital™ 2011-03-24 22:48:01 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-03-24 13:10:04 ——– d—–w- C:\Windows\SysWow64\spool 2011-03-24 13:10:01 ——– d—–w- C:\Program Files (x86)\Windows Portable Devices 2011-03-24 13:09:54 ——– d—–w- C:\Program Files\Windows Portable Devices 2011-03-24 11:21:54 167424 —-a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll 2011-03-24 11:19:33 4096 —-a-w- C:\Windows\SysWow64\oleaccrc.dll 2011-03-24 11:19:33 4096 —-a-w- C:\Windows\System32\oleaccrc.dll 2011-03-24 11:19:31 736256 —-a-w- C:\Windows\System32\UIAutomationCore.dll 2011-03-24 11:19:31 555520 —-a-w- C:\Windows\SysWow64\UIAutomationCore.dll 2011-03-24 11:19:31 315904 —-a-w- C:\Windows\System32\oleacc.dll 2011-03-24 11:19:31 234496 —-a-w- C:\Windows\SysWow64\oleacc.dll 2011-03-24 11:14:15 92672 —-a-w- C:\Windows\SysWow64\UIAnimation.dll 2011-03-24 11:14:15 103424 —-a-w- C:\Windows\System32\UIAnimation.dll 2011-03-24 11:14:13 3815424 —-a-w- C:\Windows\System32\UIRibbon.dll 2011-03-24 11:14:13 1164800 —-a-w- C:\Windows\SysWow64\UIRibbonRes.dll 2011-03-24 11:14:13 1164800 —-a-w- C:\Windows\System32\UIRibbonRes.dll 2011-03-24 11:14:12 3023360 —-a-w- C:\Windows\SysWow64\UIRibbon.dll 2011-03-24 01:58:16 288768 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2011-03-24 01:58:15 479744 —-a-w- C:\Windows\System32\XpsGdiConverter.dll 2011-03-24 01:58:13 1555968 —-a-w- C:\Windows\System32\DWrite.dll 2011-03-24 01:58:13 1149440 —-a-w- C:\Windows\System32\FntCache.dll 2011-03-24 01:58:12 1068544 —-a-w- C:\Windows\SysWow64\DWrite.dll 2011-03-24 00:40:15 ——– d—–w- C:\Windows\SysWow64\vi-VN 2011-03-24 00:40:15 ——– d—–w- C:\Windows\SysWow64\eu-ES 2011-03-24 00:40:15 ——– d—–w- C:\Windows\SysWow64\ca-ES 2011-03-24 00:40:15 ——– d—–w- C:\Windows\System32\eu-ES 2011-03-24 00:40:15 ——– d—–w- C:\Windows\System32\ca-ES 2011-03-24 00:40:14 ——– d—–w- C:\Windows\System32\vi-VN 2011-03-24 00:36:10 604672 ——w- C:\Windows\System32\stapi64.dll 2011-03-24 00:20:04 ——– d—–w- C:\Windows\System32\EventProviders 2011-03-23 23:32:26 654928 —-a-w- C:\Windows\System32\drivers\Wdf01000.sys 2011-03-23 23:32:26 42064 —-a-w- C:\Windows\System32\drivers\WdfLdr.sys 2011-03-23 23:32:26 2560 —-a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui 2011-03-23 23:21:27 ——– d—–w- C:\533fb943ae983f556e498f84 2011-03-23 23:09:31 88064 —-a-w- C:\Windows\System32\admparse.dll 2011-03-23 23:07:06 ——– d—–w- C:\Program Files\LSI SoftModem 2011-03-23 22:21:59 ——– d—–w- C:\Users\joe\.eclipse 2011-03-23 22:13:31 ——– d—–w- C:\Users\joe\AppData\Roaming\ResourceCentral.E6E1B28A311BC518DB6C6883EA3757FDE0E90ADC.1 2011-03-23 15:46:17 ——– d—–w- C:\PROGRA~3\regid.1986-12.com.adobe 2011-03-23 15:37:37 ——– d—–w- C:\PROGRA~3\ALM 2011-03-23 15:27:02 ——– d—–w- C:\Users\joe\Adobe Flash Builder 4 2011-03-23 15:17:33 55280 ——w- C:\Windows\System32\drivers\PxHlpa64.sys 2011-03-23 15:17:33 10224 ——w- C:\Windows\System32\drivers\cdralw2k.sys 2011-03-23 15:17:33 10224 ——w- C:\Windows\System32\drivers\cdr4_xp.sys 2011-03-23 15:17:32 ——– d—–w- C:\Program Files (x86)\My Company Name 2011-03-23 15:17:32 ——– d—–w- C:\Program Files (x86)\Common Files\Sonic Shared 2011-03-23 15:17:32 ——– d—–w- C:\Program Files (x86)\Common Files\PX Storage Engine 2011-03-23 15:07:17 ——– d—–w- C:\Users\joe\AppData\Local\Adobe 2011-03-23 04:30:39 1228416 —-a-w- C:\Users\joe\MasterCollection_CS5_LS1.exe 2011-03-23 03:54:26 ——– d—–w- C:\PROGRA~3\LightScribe 2011-03-23 03:52:36 ——– d—–w- C:\Users\joe\AppData\Local\Ahead 2011-03-23 03:52:35 ——– d—–w- C:\Program Files (x86)\NeroInstall.bak 2011-03-23 03:47:08 ——– d—–w- C:\Program Files (x86)\Nero 2011-03-23 03:47:08 ——– d—–w- C:\PROGRA~3\Nero 2011-03-23 03:35:15 ——– d—–w- C:\Users\joe\AppData\Roaming\Azureus 2011-03-23 03:29:43 ——– d—–w- C:\Program Files (x86)\uTorrent 2011-03-23 03:28:58 ——– d—–w- C:\Users\joe\AppData\Roaming\uTorrent 2011-03-22 22:20:59 1381376 —-a-w- C:\Windows\SysWow64\Query.dll 2011-03-22 22:19:59 612864 —-a-w- C:\Windows\SysWow64\rdpencom.dll 2011-03-22 22:18:44 891392 —-a-w- C:\Windows\System32\wbem\fastprox.dll 2011-03-22 22:18:44 43520 —-a-w- C:\Windows\System32\wbem\wbemprox.dll 2011-03-22 22:18:44 1172992 —-a-w- C:\Windows\System32\wbem\wbemcore.dll 2011-03-22 22:18:42 936448 —-a-w- C:\Windows\System32\SmiEngine.dll 2011-03-22 22:18:40 293888 —-a-w- C:\Windows\System32\wdscore.dll 2011-03-22 22:18:40 138752 —-a-w- C:\Windows\System32\PkgMgr.exe 2011-03-22 22:18:32 315904 —-a-w- C:\Windows\System32\drvstore.dll 2011-03-22 21:52:21 442368 —-a-w- C:\Windows\System32\winhttp.dll 2011-03-22 21:52:21 377344 —-a-w- C:\Windows\SysWow64\winhttp.dll 2011-03-22 21:52:13 28160 —-a-w- C:\Windows\System32\drivers\en-US\http.sys.mui 2011-03-22 21:52:00 451584 —-a-w- C:\Windows\System32\drivers\srv.sys 2011-03-22 21:51:59 9728 —-a-w- C:\Windows\SysWow64\sscore.dll 2011-03-22 21:51:59 179712 —-a-w- C:\Windows\System32\srvsvc.dll 2011-03-22 21:51:59 17920 —-a-w- C:\Windows\SysWow64\netevent.dll 2011-03-22 21:51:59 17920 —-a-w- C:\Windows\System32\netevent.dll 2011-03-22 21:51:59 175104 —-a-w- C:\Windows\System32\drivers\srv2.sys 2011-03-22 21:51:59 145920 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2011-03-22 21:51:59 12288 —-a-w- C:\Windows\System32\sscore.dll 2011-03-22 21:51:50 975360 —-a-w- C:\Windows\System32\inetcomm.dll 2011-03-22 21:51:50 739328 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-03-22 20:34:33 ——– d—–w- C:\Users\joe\AppData\Roaming\Malwarebytes 2011-03-22 20:34:21 ——– d—–w- C:\PROGRA~3\Malwarebytes 2011-03-22 20:34:17 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-03-22 20:34:17 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-03-22 18:59:34 ——– d—–w- C:\f4b8fb97cbd4b74c426efbf11b 2011-03-22 18:59:15 99176 —-a-w- C:\Windows\SysWow64\PresentationHostProxy.dll 2011-03-22 18:59:15 49472 —-a-w- C:\Windows\SysWow64\netfxperf.dll 2011-03-22 18:59:15 48960 —-a-w- C:\Windows\System32\netfxperf.dll 2011-03-22 18:59:15 444752 —-a-w- C:\Windows\System32\mscoree.dll 2011-03-22 18:59:15 320352 —-a-w- C:\Windows\System32\PresentationHost.exe 2011-03-22 18:59:15 297808 —-a-w- C:\Windows\SysWow64\mscoree.dll 2011-03-22 18:59:15 295264 —-a-w- C:\Windows\SysWow64\PresentationHost.exe 2011-03-22 18:59:15 1942856 —-a-w- C:\Windows\System32\dfshim.dll 2011-03-22 18:59:15 1130824 —-a-w- C:\Windows\SysWow64\dfshim.dll 2011-03-22 18:59:15 109912 —-a-w- C:\Windows\System32\PresentationHostProxy.dll 2011-03-22 17:39:54 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-03-22 17:34:37 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared 2011-03-22 17:33:02 ——– d—–w- C:\Users\joe\AppData\Local\CrashDumps 2011-03-22 17:05:51 ——– d—–w- C:\Program Files (x86)\MSXML 4.0 2011-03-22 16:38:19 32768 —-a-w- C:\Windows\System32\nshhttp.dll 2011-03-22 16:38:19 24064 —-a-w- C:\Windows\SysWow64\nshhttp.dll 2011-03-22 16:38:15 620032 —-a-w- C:\Windows\System32\drivers\http.sys 2011-03-22 16:38:14 33792 —-a-w- C:\Windows\System32\httpapi.dll 2011-03-22 16:38:13 30720 —-a-w- C:\Windows\SysWow64\httpapi.dll 2011-03-22 16:22:13 ——– d—–w- C:\Users\joe\AppData\Roaming\Tific 2011-03-22 16:22:00 ——– d—–w- C:\Users\joe\AppData\Local\Symantec 2011-03-22 13:51:46 1486848 —-a-w- C:\Program Files\Windows Media Player\setup_wm.exe 2011-03-22 13:51:45 1418752 —-a-w- C:\Program Files (x86)\Windows Media Player\setup_wm.exe 2011-03-22 13:51:44 372736 —-a-w- C:\Windows\System32\unregmp2.exe 2011-03-22 13:51:44 310784 —-a-w- C:\Windows\SysWow64\unregmp2.exe 2011-03-22 13:51:00 1426816 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-03-22 13:49:58 280576 —-a-w- C:\Windows\System32\rastls.dll 2011-03-22 12:05:27 1689600 —-a-w- C:\Windows\System32\lsasrv.dll 2011-03-22 12:05:26 515656 —-a-w- C:\Windows\System32\drivers\ksecdd.sys 2011-03-22 12:05:26 269312 —-a-w- C:\Windows\System32\msv1_0.dll 2011-03-22 12:05:26 218624 —-a-w- C:\Windows\SysWow64\msv1_0.dll 2011-03-22 12:05:26 205312 —-a-w- C:\Windows\System32\wdigest.dll 2011-03-22 12:05:26 175104 —-a-w- C:\Windows\SysWow64\wdigest.dll 2011-03-22 12:05:25 94720 —-a-w- C:\Windows\System32\secur32.dll 2011-03-22 12:05:25 77312 —-a-w- C:\Windows\SysWow64\secur32.dll 2011-03-22 12:05:25 11264 —-a-w- C:\Windows\System32\lsass.exe 2011-03-22 12:05:09 1869824 —-a-w- C:\Windows\System32\msxml3.dll 2011-03-22 12:05:08 1248768 —-a-w- C:\Windows\SysWow64\msxml3.dll 2011-03-22 12:05:03 82944 —-a-w- C:\Windows\System32\msasn1.dll 2011-03-22 12:05:03 60928 —-a-w- C:\Windows\SysWow64\msasn1.dll 2011-03-22 12:03:53 621568 —-a-w- C:\Windows\System32\usp10.dll 2011-03-22 12:02:59 72704 —-a-w- C:\Windows\SysWow64\fontsub.dll 2011-03-22 12:02:59 48128 —-a-w- C:\Windows\System32\atmlib.dll 2011-03-22 12:02:59 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2011-03-22 12:02:59 23552 —-a-w- C:\Windows\SysWow64\lpk.dll 2011-03-22 12:02:59 14336 —-a-w- C:\Windows\System32\dciman32.dll 2011-03-22 12:02:59 10240 —-a-w- C:\Windows\SysWow64\dciman32.dll 2011-03-22 11:16:18 ——– d—–w- C:\PROGRA~3\PCSettings 2011-03-22 11:08:19 3765288 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2011-03-22 11:08:16 7947600 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{161125F6-1F0D-433D-8774-49A73C04B3DD}\mpengine.dll 2011-03-22 11:08:12 270720 ——w- C:\Windows\System32\MpSigStub.exe 2011-03-22 06:04:22 ——– d-sh–w- C:\$RECYCLE.BIN 2011-03-22 05:59:57 ——– d—a-w- C:\Windows\SMINST 2011-03-22 05:45:19 0 —-a-w- C:\Windows\ativpsrm.bin 2011-03-22 05:20:56 90624 —-a-w- C:\Windows\System32\AESTCo64.dll 2011-03-22 05:20:56 68608 —-a-w- C:\Windows\System32\AESTAR64.dll 2011-03-22 05:20:56 564224 —-a-w- C:\Windows\System32\idt64mp1.exe 2011-03-22 05:20:56 456192 —-a-w- C:\Windows\sttray64.exe 2011-03-22 05:20:56 444928 —-a-w- C:\Windows\System32\AESTEC64.dll 2011-03-22 05:20:56 3738112 —-a-w- C:\Windows\System32\stlang64.dll 2011-03-22 05:20:56 162304 —-a-w- C:\Windows\System32\AESTAC64.dll 2011-03-22 05:20:56 12350464 —-a-w- C:\Windows\System32\idtcpl64.cpl 2011-03-22 05:20:43 ——– d—–w- C:\Windows\System32\SRSLabs 2011-03-22 05:20:00 209920 —-a-w- C:\Windows\System32\staco64.dll 2011-03-22 05:19:58 1431552 —-a-w- C:\Windows\System32\stapo64.dll 2011-03-22 05:19:48 ——– d—–w- C:\Program Files\IDT 2011-03-22 05:19:24 131 —-a-w- C:\Windows\xUninstall.bat 2011-03-22 05:17:25 109568 —-a-w- C:\Windows\System32\JmCrIcon.dll 2011-03-22 05:17:25 ——– d—–w- C:\Windows\JMCR_DIR 2011-03-22 05:16:54 ——– d—–w- C:\Program Files (x86)\Realtek 2011-03-22 05:16:42 ——– d—–w- C:\Windows\SysWow64\HPMDP 2011-03-22 05:16:09 ——– d—–w- C:\Program Files\Synaptics 2011-03-22 05:15:56 1491528 —-a-w- C:\Windows\System32\WdfCoInstaller01000.dll 2011-03-22 05:15:55 396584 —-a-w- C:\Windows\System32\SynCOM.dll 2011-03-22 05:15:55 214824 —-a-w- C:\Windows\System32\SynTPAPI.dll 2011-03-22 05:15:55 147752 —-a-w- C:\Windows\System32\SynTPCo4.dll 2011-03-22 05:13:14 ——– d—–w- C:\Program Files\ATI 2011-03-22 05:13:12 ——– d—–w- C:\Program Files (x86)\ATI Technologies 2011-03-22 05:11:55 1133568 —-a-w- C:\Windows\System32\drivers\athrx.sys 2011-03-22 05:11:54 54784 —-a-w- C:\Windows\System32\athihvui.dll 2011-03-22 05:11:54 546816 —-a-w- C:\Windows\System32\S64CPA.exe 2011-03-22 05:11:54 430080 —-a-w- C:\Windows\System32\athihvs.dll 2011-03-22 05:11:54 ——– d—–w- C:\Windows\System32\nn-NO 2011-03-22 05:11:44 ——– d—–w- C:\Program Files (x86)\Atheros 2011-03-22 05:11:43 ——– d—–w- C:\Program Files (x86)\Cisco 2011-03-22 05:11:40 ——– d—–w- C:\PROGRA~3\Atheros 2011-03-22 05:10:50 54824 ——w- C:\Windows\SysWow64\agrsmdel.exe 2011-03-22 05:10:50 14336 ——w- C:\Windows\SysWow64\agrsco64.dll 2011-03-22 05:10:34 ——– d—–w- C:\Windows\Options 2011-03-22 03:36:50 ——– d—–w- C:\Program Files\AVAST Software 2011-03-22 03:36:50 ——– d—–w- C:\PROGRA~3\AVAST Software 2011-03-22 03:25:02 218624 —-a-w- C:\Windows\System32\wintrust.dll 2011-03-22 03:25:02 172032 —-a-w- C:\Windows\SysWow64\wintrust.dll 2011-03-22 03:25:01 98304 —-a-w- C:\Windows\SysWow64\cabview.dll 2011-03-22 03:25:01 104960 —-a-w- C:\Windows\System32\cabview.dll 2011-03-22 03:20:47 912344 —-a-w- C:\Program Files (x86)\Mozilla Firefox\firefox.exe 2011-03-22 03:18:14 2621440 —-a-w- C:\Windows\System32\wucltux.dll 2011-03-22 03:18:00 98816 —-a-w- C:\Windows\System32\wudriver.dll 2011-03-22 03:18:00 87552 —-a-w- C:\Windows\SysWow64\wudriver.dll 2011-03-22 03:17:51 36864 —-a-w- C:\Windows\System32\wuapp.exe 2011-03-22 03:17:51 33792 —-a-w- C:\Windows\SysWow64\wuapp.exe 2011-03-22 03:17:51 185416 —-a-w- C:\Windows\System32\wuwebv.dll 2011-03-22 03:17:51 171608 —-a-w- C:\Windows\SysWow64\wuwebv.dll 2011-03-22 03:16:09 ——– d—–w- C:\Users\joe\AppData\Local\ATI 2011-03-22 03:16:07 ——– d—–w- C:\Users\joe\AppData\Local\Hewlett-Packard 2011-03-22 03:15:44 ——– d—–w- C:\Users\joe\AppData\Local\VirtualStore 2011-03-22 03:13:08 ——– d—–w- C:\Users\joe\AppData\Roaming\HP TCS 2011-03-22 03:12:01 26168 —-a-w- C:\Windows\System32\drivers\usbfilter.sys 2011-03-22 03:12:00 ——– d—–w- C:\Program Files (x86)\AMD 2011-03-07 02:08:13 93552 —-a-w- C:\Windows\SysWow64\ElbyCDIO.dll . ==================== Find3M ==================== . 2011-03-25 22:34:45 99384 —-a-w- C:\Users\joe\AppData\Roaming\inst.exe 2011-03-25 22:34:45 82816 —-a-w- C:\Windows\System32\drivers\pcouffin.sys 2011-03-25 22:34:45 82816 —-a-w- C:\Users\joe\AppData\Roaming\pcouffin.sys 2011-01-20 16:46:10 900480 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2011-01-20 16:17:15 366592 —-a-w- C:\Windows\System32\winspool.drv 2011-01-20 16:17:03 625152 —-a-w- C:\Windows\System32\dxgi.dll 2011-01-20 16:16:53 287232 —-a-w- C:\Windows\System32\d3d10core.dll 2011-01-20 16:16:52 327680 —-a-w- C:\Windows\System32\d3d10_1core.dll 2011-01-20 16:16:52 196096 —-a-w- C:\Windows\System32\d3d10_1.dll 2011-01-20 16:16:52 1268224 —-a-w- C:\Windows\System32\d3d10.dll 2011-01-20 16:16:47 748544 —-a-w- C:\Windows\System32\stobject.dll 2011-01-20 16:16:40 47104 —-a-w- C:\Windows\System32\cdd.dll 2011-01-20 16:16:10 3548672 —-a-w- C:\Windows\System32\mf.dll 2011-01-20 16:16:08 35840 —-a-w- C:\Windows\System32\printfilterpipelineprxy.dll 2011-01-20 16:14:49 278528 —-a-w- C:\Windows\System32\mfplat.dll 2011-01-20 16:14:49 195072 —-a-w- C:\Windows\System32\mfps.dll 2011-01-20 16:08:16 478720 —-a-w- C:\Windows\SysWow64\dxgi.dll 2011-01-20 16:08:06 219648 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll 2011-01-20 16:08:06 189952 —-a-w- C:\Windows\SysWow64\d3d10core.dll 2011-01-20 16:08:06 160768 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2011-01-20 16:08:06 1029120 —-a-w- C:\Windows\SysWow64\d3d10.dll 2011-01-20 16:07:42 258048 —-a-w- C:\Windows\SysWow64\winspool.drv 2011-01-20 16:07:16 586240 —-a-w- C:\Windows\SysWow64\stobject.dll 2011-01-20 16:06:38 2873344 —-a-w- C:\Windows\SysWow64\mf.dll 2011-01-20 16:04:54 98816 —-a-w- C:\Windows\SysWow64\mfps.dll 2011-01-20 16:04:54 209920 —-a-w- C:\Windows\SysWow64\mfplat.dll 2011-01-20 15:01:50 3068416 —-a-w- C:\Windows\System32\xpsservices.dll 2011-01-20 15:01:09 1653760 —-a-w- C:\Windows\System32\XpsPrint.dll 2011-01-20 14:59:59 1032192 —-a-w- C:\Windows\System32\printfilterpipelinesvc.exe 2011-01-20 14:58:38 1461760 —-a-w- C:\Windows\System32\OpcServices.dll 2011-01-20 14:57:28 231936 —-a-w- C:\Windows\System32\XpsRasterService.dll 2011-01-20 14:42:00 1257984 —-a-w- C:\Windows\System32\MFH264Dec.dll 2011-01-20 14:41:29 428544 —-a-w- C:\Windows\System32\MFHEAACdec.dll 2011-01-20 14:40:17 345088 —-a-w- C:\Windows\System32\mfreadwrite.dll 2011-01-20 14:40:14 34304 —-a-w- C:\Windows\System32\mfpmp.exe 2011-01-20 14:40:11 377344 —-a-w- C:\Windows\System32\mfmp4src.dll 2011-01-20 14:37:06 2002944 —-a-w- C:\Windows\System32\d3d10warp.dll 2011-01-20 14:35:30 566272 —-a-w- C:\Windows\System32\d3d10level9.dll 2011-01-20 14:28:38 1554432 —-a-w- C:\Windows\SysWow64\xpsservices.dll 2011-01-20 14:27:50 876032 —-a-w- C:\Windows\SysWow64\XpsPrint.dll 2011-01-20 14:25:25 847360 —-a-w- C:\Windows\SysWow64\OpcServices.dll 2011-01-20 14:24:26 135680 —-a-w- C:\Windows\SysWow64\XpsRasterService.dll 2011-01-20 14:15:10 979456 —-a-w- C:\Windows\SysWow64\MFH264Dec.dll 2011-01-20 14:14:39 357376 —-a-w- C:\Windows\SysWow64\MFHEAACdec.dll 2011-01-20 14:14:03 302592 —-a-w- C:\Windows\SysWow64\mfmp4src.dll 2011-01-20 14:14:03 261632 —-a-w- C:\Windows\SysWow64\mfreadwrite.dll 2011-01-20 14:12:46 1172480 —-a-w- C:\Windows\SysWow64\d3d10warp.dll 2011-01-20 14:11:34 486400 —-a-w- C:\Windows\SysWow64\d3d10level9.dll 2011-01-20 14:06:15 834048 —-a-w- C:\Windows\System32\d2d1.dll 2011-01-20 13:47:51 683008 —-a-w- C:\Windows\SysWow64\d2d1.dll 2011-01-08 06:45:51 367104 —-a-w- C:\Windows\System32\atmfd.dll 2011-01-08 06:28:49 292352 —-a-w- C:\Windows\SysWow64\atmfd.dll 2010-12-31 14:16:41 2757632 —-a-w- C:\Windows\System32\win32k.sys 2010-12-29 19:01:38 416768 —-a-w- C:\Windows\System32\sbe.dll 2010-12-29 19:01:38 210944 —-a-w- C:\Windows\System32\sbeio.dll 2010-12-29 19:01:24 559616 —-a-w- C:\Windows\System32\EncDec.dll 2010-12-29 18:59:41 226816 —-a-w- C:\Windows\System32\mpg2splt.ax 2010-12-29 18:28:45 322560 —-a-w- C:\Windows\SysWow64\sbe.dll 2010-12-29 18:28:45 153088 —-a-w- C:\Windows\SysWow64\sbeio.dll 2010-12-29 18:28:28 429056 —-a-w- C:\Windows\SysWow64\EncDec.dll 2010-12-29 18:26:47 177664 —-a-w- C:\Windows\SysWow64\mpg2splt.ax . ============= FINISH: 22:02:50.83 ===============
From the logs, it appears you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

Please let me know if there is any improvement in how your computer is running after this.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI