I think im infected. Ny comp is running slow and things are dissapearing.
Hello and
My name is
patndoris . I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs. Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean. Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask! Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive. Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so. Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post. Please reply within 3 days . If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed !
Vista and Windows 7 users:
Windows 7 and Vista users will always want to right-click and choose "run as administrator" to launch any tools we use.
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Download and Run DDS by sUBs
Please download
DDS and save it to your desktop.
Disable any script blocking protection Double click dds.scr to run the tool. When done, DDS.txt will open. Click Yes at the next prompt for Optional Scan . Save both reports to your desktop. —————————————————
Please Please copy / paste the scan reults.
DDS.txt
Please attach the second file;
Attach.txt . To attach a file, do the following:
Under the reply panel is the Attachments Panel Browse for the attachment file you want to upload, then click the green Upload button Once it has uploaded, click the Manage Current Attachments drop down box Click on [external image: Posted Image] to insert the attachment into your post
Scan With RootKitUnHooker
Please choose one link and download Rootkit Unhooker and save it to your desktop.
Link 1
Link 2
Link 3 Now double-click on RKUnhookerLE.exe to run it. Click the Report tab, then click Scan . Check (Tick) Drivers and Stealth Uncheck the rest. then click OK When prompted to Select Disks for Scan, make sure C:/ is checked and click OK Wait till the scanner has finished and then click File > Save Report. Save the report somewhere where you can find it. Click Close. Copy the entire contents of the report and paste it in your next reply.
Note** you may get the following warning, just click OK and continue.
"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
If you run into any trouble running the tools please let me know.
..
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 3/22/2011 1:07:21 AM
System Uptime: 3/28/2011 7:31:28 PM (3 hours ago)
.
Motherboard: Compal | | 30FC
Processor: AMD Turion™ X2 Dual-Core Mobile RM-72 | Socket M2/S1G1 | 2100/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 285 GiB total, 184.027 GiB free.
D: is FIXED (NTFS) - 13 GiB total, 2.005 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP53: 3/27/2011 8:56:03 PM - Removed HiJackThis
RP54: 3/27/2011 8:58:51 PM - Removed HP Total Care Advisor
RP55: 3/28/2011 3:00:10 AM - Windows Update
RP56: 3/28/2011 8:14:39 AM - Windows Update
RP57: 3/28/2011 9:08:37 AM - Windows Update
RP58: 3/28/2011 9:19:41 AM - Windows Update
RP59: 3/28/2011 10:03:49 AM - Windows Update
RP60: 3/28/2011 2:54:27 PM - OTL Restore Point
RP61: 3/28/2011 7:41:59 PM - OTL Restore Point
RP62: 3/28/2011 9:21:40 PM - OTL Restore Point
.
==== Installed Programs ======================
.
µTorrent
Acrobat.com
Activation Assistant for the 2007 Microsoft Office suites
Adobe AIR
Adobe Community Help
Adobe Creative Suite 5 Master Collection
Adobe Encore CS5 Third Party Royalty Content
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Reader 9
AMD USB Audio Driver Filter
AnyDVD
Atheros Driver Installation Program
AVG PC Tuneup 2011
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Compatibility Pack for the 2007 Office system
ConvertXtoDVD 4.0.9.322
ERUNT 1.1j
ESU for Microsoft Vista
GIMP 2.6.11
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Help and Support
HP MediaSmart DVD
HP MediaSmart Music/Photo/Video
HP MediaSmart TV
HP MediaSmart Webcam
HP MULTIPLE MODEM INSTALLER for VISTA
HP Quick Launch Buttons 6.40 H2
HP Update
HP User Guides 0129
HP Wireless Assistant
HPTCSSetup
IDT Audio
Java Auto Updater
Java™ 6 Update 24
Java™ 6 Update 7
JMicron JMB38X Flash Media Controller
LabelPrint
LightScribe System Software 1.14.17.1
Malwarebytes' Anti-Malware
Microsoft Live Search Toolbar
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox (3.6.16)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 8
neroxml
PDF Settings CS5
PxMergeModule
Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Skins
Splat! 1.0
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Office 2007 (KB934528)
Visual Studio 2008 x64 Redistributables
WinZip 15.0
.
==== Event Viewer Messages From Past Week ========
.
3/28/2011 9:20:45 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 for x64-based Systems (KB2160841).
3/28/2011 8:29:59 PM, Error: PlugPlayManager [12] - The device 'JMB38X xD Host Controller' (PCI\VEN_197B&DEV_2384&SUBSYS_30FC103C&REV_00\4&3b4983b4&0&0428) disappeared from the system without first being prepared for removal.
3/28/2011 8:29:59 PM, Error: PlugPlayManager [12] - The device 'JMB38X SD/MMC Host Controller' (PCI\VEN_197B&DEV_2382&SUBSYS_30FC103C&REV_00\4&3b4983b4&0&0028) disappeared from the system without first being prepared for removal.
3/28/2011 8:29:59 PM, Error: PlugPlayManager [12] - The device 'JMB38X SD Host Controller' (PCI\VEN_197B&DEV_2381&SUBSYS_30FC103C&REV_00\4&3b4983b4&0&0228) disappeared from the system without first being prepared for removal.
3/28/2011 8:29:59 PM, Error: PlugPlayManager [12] - The device 'JMB38X MS Host Controller' (PCI\VEN_197B&DEV_2383&SUBSYS_30FC103C&REV_00\4&3b4983b4&0&0328) disappeared from the system without first being prepared for removal.
3/28/2011 8:15:05 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070002: Security Update for Microsoft .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 for x64-based Systems (KB2160841).
3/28/2011 7:29:38 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
3/28/2011 6:39:14 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.14 for the Network Card with network address 00242BD32CA5 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
3/28/2011 11:08:17 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.13 for the Network Card with network address 00242BD32CA5 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 22:01:41.03 on Mon 03/28/2011
Internet Explorer: 8.0.6001.19019 BrowserJavaVersion: 1.6.0_24
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3837.1104 [GMT -4:00]
.
AV: AVG Anti-Virus 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Program Files (x86)\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_1b06afce\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agr64svc.exe
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\XPOLOG~1.3\XpoLog.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\XpoLogCenter4.3\jre\bin\javaw.exe
C:\Program Files (x86)\AVG\AVG10\avgam.exe
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Users\joe\Downloads\OTL.exe
C:\Windows\notepad.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\joe\Downloads\dds(2).scr
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
mWinlogon: Userinit=userinit.exe,
BHO: AutorunsDisabled - No File
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [CLMLServer for HP TouchSmart] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
mRun: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
mRun: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
mRun: [UCam_Menu] "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
mRun: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [TSMAgent] "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
mRun: [HP Software Update] "C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
StartupFolder: C:\Users\joe\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
uPolicies-explorer: GreyMSIAds = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 0 (0x0)
uPolicies-explorer: NoThumbnailCache = 1 (0x1)
uPolicies-explorer: DisableThumbnailsOnNetworkFolders = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableStartupSound = 1 (0x1)
mPolicies-system: DisableStatusMessages = 1 (0x1)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
BHO-X64: AutorunsDisabled - No File
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
mRun-x64: [Windows Defender] %PROGRAMFILES%\Windows Defender\MSASCui.exe -hide
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\joe\AppData\Roaming\Mozilla\Firefox\Profiles\0pgx703w.default\
FF - component: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}\components\Contribute.dll
FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Adobe Contribute Toolbar: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox
FF - Ext: Adblock Plus Pop-up Addon: [removed] - %profile%\extensions\[removed]
FF - Ext: Fasterfox Lite: FasterFox_Lite@BigRedBrent - %profile%\extensions\FasterFox_Lite@BigRedBrent
FF - Ext: NoSquint: [removed] - %profile%\extensions\[removed]
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\WINDOWS\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\WINDOWS\System32\drivers\avgrkx64.sys [2010-9-7 30288]
R0 PxHlpa64;PxHlpa64;C:\WINDOWS\System32\drivers\PxHlpa64.sys [2011-3-23 55280]
R1 Avgldx64;AVG AVI Loader Driver;C:\WINDOWS\System32\drivers\avgldx64.sys [2010-12-8 308304]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\WINDOWS\System32\drivers\avgmfx64.sys [2010-9-7 41040]
R1 Avgtdia;AVG TDI Driver;C:\WINDOWS\System32\drivers\avgtdia.sys [2010-11-12 382032]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-9-26 27632]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
R2 hpsrv;HP Service;C:\WINDOWS\System32\hpservice.exe [2008-3-18 30520]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-3-24 363344]
R2 XpoLogCenter;XpoLogCenter;C:\PROGRA~1\XPOLOG~1.3\XpoLog.exe -zglaxservice XpoLogCenter –> C:\PROGRA~1\XPOLOG~1.3\XpoLog.exe -zglaxservice XpoLogCenter [?]
R3 AVGIDSDriver;AVGIDSDriver;C:\WINDOWS\System32\drivers\AVGIDSDriver.sys [2010-8-3 133712]
R3 AVGIDSFilter;AVGIDSFilter;C:\WINDOWS\System32\drivers\AVGIDSFilter.sys [2010-8-3 35920]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-10-24 193840]
R3 enecir;ENE CIR Receiver;C:\WINDOWS\System32\drivers\enecir.sys [2008-1-24 60928]
R3 MBAMProtector;MBAMProtector;C:\WINDOWS\System32\drivers\mbam.sys [2011-3-22 24152]
R3 usbfilter;AMD USB Filter Driver;C:\WINDOWS\System32\drivers\usbfilter.sys [2011-3-21 26168]
S3 JMCR;JMCR;C:\WINDOWS\System32\drivers\jmcr.sys [2008-7-21 145496]
S3 NETw3v64;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit;C:\WINDOWS\System32\drivers\NETw3v64.sys [2008-1-20 3154432]
S3 PerfHost;Performance Counter DLL Host;C:\WINDOWS\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\WINDOWS\System32\drivers\yk60x64.sys [2006-11-2 273408]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-3-22 89920]
S4 Recovery Service for Windows;Recovery Service for Windows;C:\Program Files (x86)\SMINST\BLService.exe [2008-10-24 365952]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-03-28 21:00:50 ——– d—–w- C:\Program Files\XpoLogCenter4.3
2011-03-28 21:00:49 ——– d–h–w- C:\Program Files\Zero G Registry
2011-03-28 21:00:25 ——– d–h–w- C:\Users\joe\InstallAnywhere
2011-03-28 12:36:58 612864 —-a-w- C:\Windows\System32\vbscript.dll
2011-03-28 12:36:57 420352 —-a-w- C:\Windows\SysWow64\vbscript.dll
2011-03-27 17:39:24 ——– d—–w- C:\Users\joe\AppData\Local\Alien Skin
2011-03-27 17:25:37 ——– d—–w- C:\PROGRA~3\Alien Skin
2011-03-27 17:25:35 ——– d—–w- C:\Program Files\Alien Skin
2011-03-27 17:22:47 ——– d—–w- C:\Program Files (x86)\Alien Skin
2011-03-27 15:01:15 ——– d—–w- C:\$AVG
2011-03-27 14:06:47 ——– d—–w- C:\Users\joe\.thumbnails
2011-03-27 14:03:21 ——– d—–w- C:\Users\joe\.gimp-2.6
2011-03-27 14:01:58 ——– d—–w- C:\Program Files (x86)\GIMP-2.0
2011-03-27 01:09:34 ——– d—–w- C:\Users\joe\AppData\Roaming\AVG
2011-03-27 00:38:14 ——– d—–w- C:\Users\joe\AppData\Roaming\AVG10
2011-03-27 00:37:29 ——– d–h–w- C:\PROGRA~3\Common Files
2011-03-27 00:36:58 ——– d—–w- C:\Windows\SysWow64\drivers\AVG
2011-03-27 00:35:27 ——– d—–w- C:\Windows\System32\drivers\AVG
2011-03-27 00:35:27 ——– d—–w- C:\PROGRA~3\AVG10
2011-03-27 00:33:31 ——– d—–w- C:\Program Files (x86)\AVG
2011-03-27 00:31:52 ——– d—–w- C:\PROGRA~3\MFAData
2011-03-27 00:03:48 25048 —-a-w- C:\Program Files (x86)\Mozilla Firefox\components\browserdirprovider.dll
2011-03-27 00:03:48 140248 —-a-w- C:\Program Files (x86)\Mozilla Firefox\components\brwsrcmp.dll
2011-03-27 00:03:46 66520 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
2011-03-27 00:03:45 492504 —-a-w- C:\Program Files (x86)\Mozilla Firefox\sqlite3.dll
2011-03-27 00:03:45 1018328 —-a-w- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
2011-03-26 03:59:54 ——– d—–w- C:\Users\joe\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-03-25 23:58:18 ——– d—–w- C:\PROGRA~3\vsosdk
2011-03-25 22:15:37 ——– d—–w- C:\Program Files (x86)\SlySoft
2011-03-25 18:52:13 ——– d—–w- C:\Users\joe\AppData\Roaming\Adobe Mini Bridge CS5
2011-03-25 18:52:12 ——– d—–w- C:\Users\joe\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-03-25 03:09:08 ——– d—–w- C:\Users\joe\AppData\Local\Sony
2011-03-25 02:25:52 ——– d—–w- C:\Users\joe\AppData\Roaming\NeroDigital™
2011-03-24 22:48:01 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-24 13:10:04 ——– d—–w- C:\Windows\SysWow64\spool
2011-03-24 13:10:01 ——– d—–w- C:\Program Files (x86)\Windows Portable Devices
2011-03-24 13:09:54 ——– d—–w- C:\Program Files\Windows Portable Devices
2011-03-24 11:21:54 167424 —-a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll
2011-03-24 11:19:33 4096 —-a-w- C:\Windows\SysWow64\oleaccrc.dll
2011-03-24 11:19:33 4096 —-a-w- C:\Windows\System32\oleaccrc.dll
2011-03-24 11:19:31 736256 —-a-w- C:\Windows\System32\UIAutomationCore.dll
2011-03-24 11:19:31 555520 —-a-w- C:\Windows\SysWow64\UIAutomationCore.dll
2011-03-24 11:19:31 315904 —-a-w- C:\Windows\System32\oleacc.dll
2011-03-24 11:19:31 234496 —-a-w- C:\Windows\SysWow64\oleacc.dll
2011-03-24 11:14:15 92672 —-a-w- C:\Windows\SysWow64\UIAnimation.dll
2011-03-24 11:14:15 103424 —-a-w- C:\Windows\System32\UIAnimation.dll
2011-03-24 11:14:13 3815424 —-a-w- C:\Windows\System32\UIRibbon.dll
2011-03-24 11:14:13 1164800 —-a-w- C:\Windows\SysWow64\UIRibbonRes.dll
2011-03-24 11:14:13 1164800 —-a-w- C:\Windows\System32\UIRibbonRes.dll
2011-03-24 11:14:12 3023360 —-a-w- C:\Windows\SysWow64\UIRibbon.dll
2011-03-24 01:58:16 288768 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-03-24 01:58:15 479744 —-a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-03-24 01:58:13 1555968 —-a-w- C:\Windows\System32\DWrite.dll
2011-03-24 01:58:13 1149440 —-a-w- C:\Windows\System32\FntCache.dll
2011-03-24 01:58:12 1068544 —-a-w- C:\Windows\SysWow64\DWrite.dll
2011-03-24 00:40:15 ——– d—–w- C:\Windows\SysWow64\vi-VN
2011-03-24 00:40:15 ——– d—–w- C:\Windows\SysWow64\eu-ES
2011-03-24 00:40:15 ——– d—–w- C:\Windows\SysWow64\ca-ES
2011-03-24 00:40:15 ——– d—–w- C:\Windows\System32\eu-ES
2011-03-24 00:40:15 ——– d—–w- C:\Windows\System32\ca-ES
2011-03-24 00:40:14 ——– d—–w- C:\Windows\System32\vi-VN
2011-03-24 00:36:10 604672 ——w- C:\Windows\System32\stapi64.dll
2011-03-24 00:20:04 ——– d—–w- C:\Windows\System32\EventProviders
2011-03-23 23:32:26 654928 —-a-w- C:\Windows\System32\drivers\Wdf01000.sys
2011-03-23 23:32:26 42064 —-a-w- C:\Windows\System32\drivers\WdfLdr.sys
2011-03-23 23:32:26 2560 —-a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2011-03-23 23:21:27 ——– d—–w- C:\533fb943ae983f556e498f84
2011-03-23 23:09:31 88064 —-a-w- C:\Windows\System32\admparse.dll
2011-03-23 23:07:06 ——– d—–w- C:\Program Files\LSI SoftModem
2011-03-23 22:21:59 ——– d—–w- C:\Users\joe\.eclipse
2011-03-23 22:13:31 ——– d—–w- C:\Users\joe\AppData\Roaming\ResourceCentral.E6E1B28A311BC518DB6C6883EA3757FDE0E90ADC.1
2011-03-23 15:46:17 ——– d—–w- C:\PROGRA~3\regid.1986-12.com.adobe
2011-03-23 15:37:37 ——– d—–w- C:\PROGRA~3\ALM
2011-03-23 15:27:02 ——– d—–w- C:\Users\joe\Adobe Flash Builder 4
2011-03-23 15:17:33 55280 ——w- C:\Windows\System32\drivers\PxHlpa64.sys
2011-03-23 15:17:33 10224 ——w- C:\Windows\System32\drivers\cdralw2k.sys
2011-03-23 15:17:33 10224 ——w- C:\Windows\System32\drivers\cdr4_xp.sys
2011-03-23 15:17:32 ——– d—–w- C:\Program Files (x86)\My Company Name
2011-03-23 15:17:32 ——– d—–w- C:\Program Files (x86)\Common Files\Sonic Shared
2011-03-23 15:17:32 ——– d—–w- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-03-23 15:07:17 ——– d—–w- C:\Users\joe\AppData\Local\Adobe
2011-03-23 04:30:39 1228416 —-a-w- C:\Users\joe\MasterCollection_CS5_LS1.exe
2011-03-23 03:54:26 ——– d—–w- C:\PROGRA~3\LightScribe
2011-03-23 03:52:36 ——– d—–w- C:\Users\joe\AppData\Local\Ahead
2011-03-23 03:52:35 ——– d—–w- C:\Program Files (x86)\NeroInstall.bak
2011-03-23 03:47:08 ——– d—–w- C:\Program Files (x86)\Nero
2011-03-23 03:47:08 ——– d—–w- C:\PROGRA~3\Nero
2011-03-23 03:35:15 ——– d—–w- C:\Users\joe\AppData\Roaming\Azureus
2011-03-23 03:29:43 ——– d—–w- C:\Program Files (x86)\uTorrent
2011-03-23 03:28:58 ——– d—–w- C:\Users\joe\AppData\Roaming\uTorrent
2011-03-22 22:20:59 1381376 —-a-w- C:\Windows\SysWow64\Query.dll
2011-03-22 22:19:59 612864 —-a-w- C:\Windows\SysWow64\rdpencom.dll
2011-03-22 22:18:44 891392 —-a-w- C:\Windows\System32\wbem\fastprox.dll
2011-03-22 22:18:44 43520 —-a-w- C:\Windows\System32\wbem\wbemprox.dll
2011-03-22 22:18:44 1172992 —-a-w- C:\Windows\System32\wbem\wbemcore.dll
2011-03-22 22:18:42 936448 —-a-w- C:\Windows\System32\SmiEngine.dll
2011-03-22 22:18:40 293888 —-a-w- C:\Windows\System32\wdscore.dll
2011-03-22 22:18:40 138752 —-a-w- C:\Windows\System32\PkgMgr.exe
2011-03-22 22:18:32 315904 —-a-w- C:\Windows\System32\drvstore.dll
2011-03-22 21:52:21 442368 —-a-w- C:\Windows\System32\winhttp.dll
2011-03-22 21:52:21 377344 —-a-w- C:\Windows\SysWow64\winhttp.dll
2011-03-22 21:52:13 28160 —-a-w- C:\Windows\System32\drivers\en-US\http.sys.mui
2011-03-22 21:52:00 451584 —-a-w- C:\Windows\System32\drivers\srv.sys
2011-03-22 21:51:59 9728 —-a-w- C:\Windows\SysWow64\sscore.dll
2011-03-22 21:51:59 179712 —-a-w- C:\Windows\System32\srvsvc.dll
2011-03-22 21:51:59 17920 —-a-w- C:\Windows\SysWow64\netevent.dll
2011-03-22 21:51:59 17920 —-a-w- C:\Windows\System32\netevent.dll
2011-03-22 21:51:59 175104 —-a-w- C:\Windows\System32\drivers\srv2.sys
2011-03-22 21:51:59 145920 —-a-w- C:\Windows\System32\drivers\srvnet.sys
2011-03-22 21:51:59 12288 —-a-w- C:\Windows\System32\sscore.dll
2011-03-22 21:51:50 975360 —-a-w- C:\Windows\System32\inetcomm.dll
2011-03-22 21:51:50 739328 —-a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-22 20:34:33 ——– d—–w- C:\Users\joe\AppData\Roaming\Malwarebytes
2011-03-22 20:34:21 ——– d—–w- C:\PROGRA~3\Malwarebytes
2011-03-22 20:34:17 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-03-22 20:34:17 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-03-22 18:59:34 ——– d—–w- C:\f4b8fb97cbd4b74c426efbf11b
2011-03-22 18:59:15 99176 —-a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2011-03-22 18:59:15 49472 —-a-w- C:\Windows\SysWow64\netfxperf.dll
2011-03-22 18:59:15 48960 —-a-w- C:\Windows\System32\netfxperf.dll
2011-03-22 18:59:15 444752 —-a-w- C:\Windows\System32\mscoree.dll
2011-03-22 18:59:15 320352 —-a-w- C:\Windows\System32\PresentationHost.exe
2011-03-22 18:59:15 297808 —-a-w- C:\Windows\SysWow64\mscoree.dll
2011-03-22 18:59:15 295264 —-a-w- C:\Windows\SysWow64\PresentationHost.exe
2011-03-22 18:59:15 1942856 —-a-w- C:\Windows\System32\dfshim.dll
2011-03-22 18:59:15 1130824 —-a-w- C:\Windows\SysWow64\dfshim.dll
2011-03-22 18:59:15 109912 —-a-w- C:\Windows\System32\PresentationHostProxy.dll
2011-03-22 17:39:54 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2011-03-22 17:34:37 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared
2011-03-22 17:33:02 ——– d—–w- C:\Users\joe\AppData\Local\CrashDumps
2011-03-22 17:05:51 ——– d—–w- C:\Program Files (x86)\MSXML 4.0
2011-03-22 16:38:19 32768 —-a-w- C:\Windows\System32\nshhttp.dll
2011-03-22 16:38:19 24064 —-a-w- C:\Windows\SysWow64\nshhttp.dll
2011-03-22 16:38:15 620032 —-a-w- C:\Windows\System32\drivers\http.sys
2011-03-22 16:38:14 33792 —-a-w- C:\Windows\System32\httpapi.dll
2011-03-22 16:38:13 30720 —-a-w- C:\Windows\SysWow64\httpapi.dll
2011-03-22 16:22:13 ——– d—–w- C:\Users\joe\AppData\Roaming\Tific
2011-03-22 16:22:00 ——– d—–w- C:\Users\joe\AppData\Local\Symantec
2011-03-22 13:51:46 1486848 —-a-w- C:\Program Files\Windows Media Player\setup_wm.exe
2011-03-22 13:51:45 1418752 —-a-w- C:\Program Files (x86)\Windows Media Player\setup_wm.exe
2011-03-22 13:51:44 372736 —-a-w- C:\Windows\System32\unregmp2.exe
2011-03-22 13:51:44 310784 —-a-w- C:\Windows\SysWow64\unregmp2.exe
2011-03-22 13:51:00 1426816 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2011-03-22 13:49:58 280576 —-a-w- C:\Windows\System32\rastls.dll
2011-03-22 12:05:27 1689600 —-a-w- C:\Windows\System32\lsasrv.dll
2011-03-22 12:05:26 515656 —-a-w- C:\Windows\System32\drivers\ksecdd.sys
2011-03-22 12:05:26 269312 —-a-w- C:\Windows\System32\msv1_0.dll
2011-03-22 12:05:26 218624 —-a-w- C:\Windows\SysWow64\msv1_0.dll
2011-03-22 12:05:26 205312 —-a-w- C:\Windows\System32\wdigest.dll
2011-03-22 12:05:26 175104 —-a-w- C:\Windows\SysWow64\wdigest.dll
2011-03-22 12:05:25 94720 —-a-w- C:\Windows\System32\secur32.dll
2011-03-22 12:05:25 77312 —-a-w- C:\Windows\SysWow64\secur32.dll
2011-03-22 12:05:25 11264 —-a-w- C:\Windows\System32\lsass.exe
2011-03-22 12:05:09 1869824 —-a-w- C:\Windows\System32\msxml3.dll
2011-03-22 12:05:08 1248768 —-a-w- C:\Windows\SysWow64\msxml3.dll
2011-03-22 12:05:03 82944 —-a-w- C:\Windows\System32\msasn1.dll
2011-03-22 12:05:03 60928 —-a-w- C:\Windows\SysWow64\msasn1.dll
2011-03-22 12:03:53 621568 —-a-w- C:\Windows\System32\usp10.dll
2011-03-22 12:02:59 72704 —-a-w- C:\Windows\SysWow64\fontsub.dll
2011-03-22 12:02:59 48128 —-a-w- C:\Windows\System32\atmlib.dll
2011-03-22 12:02:59 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2011-03-22 12:02:59 23552 —-a-w- C:\Windows\SysWow64\lpk.dll
2011-03-22 12:02:59 14336 —-a-w- C:\Windows\System32\dciman32.dll
2011-03-22 12:02:59 10240 —-a-w- C:\Windows\SysWow64\dciman32.dll
2011-03-22 11:16:18 ——– d—–w- C:\PROGRA~3\PCSettings
2011-03-22 11:08:19 3765288 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-03-22 11:08:16 7947600 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{161125F6-1F0D-433D-8774-49A73C04B3DD}\mpengine.dll
2011-03-22 11:08:12 270720 ——w- C:\Windows\System32\MpSigStub.exe
2011-03-22 06:04:22 ——– d-sh–w- C:\$RECYCLE.BIN
2011-03-22 05:59:57 ——– d—a-w- C:\Windows\SMINST
2011-03-22 05:45:19 0 —-a-w- C:\Windows\ativpsrm.bin
2011-03-22 05:20:56 90624 —-a-w- C:\Windows\System32\AESTCo64.dll
2011-03-22 05:20:56 68608 —-a-w- C:\Windows\System32\AESTAR64.dll
2011-03-22 05:20:56 564224 —-a-w- C:\Windows\System32\idt64mp1.exe
2011-03-22 05:20:56 456192 —-a-w- C:\Windows\sttray64.exe
2011-03-22 05:20:56 444928 —-a-w- C:\Windows\System32\AESTEC64.dll
2011-03-22 05:20:56 3738112 —-a-w- C:\Windows\System32\stlang64.dll
2011-03-22 05:20:56 162304 —-a-w- C:\Windows\System32\AESTAC64.dll
2011-03-22 05:20:56 12350464 —-a-w- C:\Windows\System32\idtcpl64.cpl
2011-03-22 05:20:43 ——– d—–w- C:\Windows\System32\SRSLabs
2011-03-22 05:20:00 209920 —-a-w- C:\Windows\System32\staco64.dll
2011-03-22 05:19:58 1431552 —-a-w- C:\Windows\System32\stapo64.dll
2011-03-22 05:19:48 ——– d—–w- C:\Program Files\IDT
2011-03-22 05:19:24 131 —-a-w- C:\Windows\xUninstall.bat
2011-03-22 05:17:25 109568 —-a-w- C:\Windows\System32\JmCrIcon.dll
2011-03-22 05:17:25 ——– d—–w- C:\Windows\JMCR_DIR
2011-03-22 05:16:54 ——– d—–w- C:\Program Files (x86)\Realtek
2011-03-22 05:16:42 ——– d—–w- C:\Windows\SysWow64\HPMDP
2011-03-22 05:16:09 ——– d—–w- C:\Program Files\Synaptics
2011-03-22 05:15:56 1491528 —-a-w- C:\Windows\System32\WdfCoInstaller01000.dll
2011-03-22 05:15:55 396584 —-a-w- C:\Windows\System32\SynCOM.dll
2011-03-22 05:15:55 214824 —-a-w- C:\Windows\System32\SynTPAPI.dll
2011-03-22 05:15:55 147752 —-a-w- C:\Windows\System32\SynTPCo4.dll
2011-03-22 05:13:14 ——– d—–w- C:\Program Files\ATI
2011-03-22 05:13:12 ——– d—–w- C:\Program Files (x86)\ATI Technologies
2011-03-22 05:11:55 1133568 —-a-w- C:\Windows\System32\drivers\athrx.sys
2011-03-22 05:11:54 54784 —-a-w- C:\Windows\System32\athihvui.dll
2011-03-22 05:11:54 546816 —-a-w- C:\Windows\System32\S64CPA.exe
2011-03-22 05:11:54 430080 —-a-w- C:\Windows\System32\athihvs.dll
2011-03-22 05:11:54 ——– d—–w- C:\Windows\System32\nn-NO
2011-03-22 05:11:44 ——– d—–w- C:\Program Files (x86)\Atheros
2011-03-22 05:11:43 ——– d—–w- C:\Program Files (x86)\Cisco
2011-03-22 05:11:40 ——– d—–w- C:\PROGRA~3\Atheros
2011-03-22 05:10:50 54824 ——w- C:\Windows\SysWow64\agrsmdel.exe
2011-03-22 05:10:50 14336 ——w- C:\Windows\SysWow64\agrsco64.dll
2011-03-22 05:10:34 ——– d—–w- C:\Windows\Options
2011-03-22 03:36:50 ——– d—–w- C:\Program Files\AVAST Software
2011-03-22 03:36:50 ——– d—–w- C:\PROGRA~3\AVAST Software
2011-03-22 03:25:02 218624 —-a-w- C:\Windows\System32\wintrust.dll
2011-03-22 03:25:02 172032 —-a-w- C:\Windows\SysWow64\wintrust.dll
2011-03-22 03:25:01 98304 —-a-w- C:\Windows\SysWow64\cabview.dll
2011-03-22 03:25:01 104960 —-a-w- C:\Windows\System32\cabview.dll
2011-03-22 03:20:47 912344 —-a-w- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
2011-03-22 03:18:14 2621440 —-a-w- C:\Windows\System32\wucltux.dll
2011-03-22 03:18:00 98816 —-a-w- C:\Windows\System32\wudriver.dll
2011-03-22 03:18:00 87552 —-a-w- C:\Windows\SysWow64\wudriver.dll
2011-03-22 03:17:51 36864 —-a-w- C:\Windows\System32\wuapp.exe
2011-03-22 03:17:51 33792 —-a-w- C:\Windows\SysWow64\wuapp.exe
2011-03-22 03:17:51 185416 —-a-w- C:\Windows\System32\wuwebv.dll
2011-03-22 03:17:51 171608 —-a-w- C:\Windows\SysWow64\wuwebv.dll
2011-03-22 03:16:09 ——– d—–w- C:\Users\joe\AppData\Local\ATI
2011-03-22 03:16:07 ——– d—–w- C:\Users\joe\AppData\Local\Hewlett-Packard
2011-03-22 03:15:44 ——– d—–w- C:\Users\joe\AppData\Local\VirtualStore
2011-03-22 03:13:08 ——– d—–w- C:\Users\joe\AppData\Roaming\HP TCS
2011-03-22 03:12:01 26168 —-a-w- C:\Windows\System32\drivers\usbfilter.sys
2011-03-22 03:12:00 ——– d—–w- C:\Program Files (x86)\AMD
2011-03-07 02:08:13 93552 —-a-w- C:\Windows\SysWow64\ElbyCDIO.dll
.
==================== Find3M ====================
.
2011-03-25 22:34:45 99384 —-a-w- C:\Users\joe\AppData\Roaming\inst.exe
2011-03-25 22:34:45 82816 —-a-w- C:\Windows\System32\drivers\pcouffin.sys
2011-03-25 22:34:45 82816 —-a-w- C:\Users\joe\AppData\Roaming\pcouffin.sys
2011-01-20 16:46:10 900480 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2011-01-20 16:17:15 366592 —-a-w- C:\Windows\System32\winspool.drv
2011-01-20 16:17:03 625152 —-a-w- C:\Windows\System32\dxgi.dll
2011-01-20 16:16:53 287232 —-a-w- C:\Windows\System32\d3d10core.dll
2011-01-20 16:16:52 327680 —-a-w- C:\Windows\System32\d3d10_1core.dll
2011-01-20 16:16:52 196096 —-a-w- C:\Windows\System32\d3d10_1.dll
2011-01-20 16:16:52 1268224 —-a-w- C:\Windows\System32\d3d10.dll
2011-01-20 16:16:47 748544 —-a-w- C:\Windows\System32\stobject.dll
2011-01-20 16:16:40 47104 —-a-w- C:\Windows\System32\cdd.dll
2011-01-20 16:16:10 3548672 —-a-w- C:\Windows\System32\mf.dll
2011-01-20 16:16:08 35840 —-a-w- C:\Windows\System32\printfilterpipelineprxy.dll
2011-01-20 16:14:49 278528 —-a-w- C:\Windows\System32\mfplat.dll
2011-01-20 16:14:49 195072 —-a-w- C:\Windows\System32\mfps.dll
2011-01-20 16:08:16 478720 —-a-w- C:\Windows\SysWow64\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w- C:\Windows\SysWow64\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w- C:\Windows\SysWow64\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w- C:\Windows\SysWow64\d3d10.dll
2011-01-20 16:07:42 258048 —-a-w- C:\Windows\SysWow64\winspool.drv
2011-01-20 16:07:16 586240 —-a-w- C:\Windows\SysWow64\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w- C:\Windows\SysWow64\mf.dll
2011-01-20 16:04:54 98816 —-a-w- C:\Windows\SysWow64\mfps.dll
2011-01-20 16:04:54 209920 —-a-w- C:\Windows\SysWow64\mfplat.dll
2011-01-20 15:01:50 3068416 —-a-w- C:\Windows\System32\xpsservices.dll
2011-01-20 15:01:09 1653760 —-a-w- C:\Windows\System32\XpsPrint.dll
2011-01-20 14:59:59 1032192 —-a-w- C:\Windows\System32\printfilterpipelinesvc.exe
2011-01-20 14:58:38 1461760 —-a-w- C:\Windows\System32\OpcServices.dll
2011-01-20 14:57:28 231936 —-a-w- C:\Windows\System32\XpsRasterService.dll
2011-01-20 14:42:00 1257984 —-a-w- C:\Windows\System32\MFH264Dec.dll
2011-01-20 14:41:29 428544 —-a-w- C:\Windows\System32\MFHEAACdec.dll
2011-01-20 14:40:17 345088 —-a-w- C:\Windows\System32\mfreadwrite.dll
2011-01-20 14:40:14 34304 —-a-w- C:\Windows\System32\mfpmp.exe
2011-01-20 14:40:11 377344 —-a-w- C:\Windows\System32\mfmp4src.dll
2011-01-20 14:37:06 2002944 —-a-w- C:\Windows\System32\d3d10warp.dll
2011-01-20 14:35:30 566272 —-a-w- C:\Windows\System32\d3d10level9.dll
2011-01-20 14:28:38 1554432 —-a-w- C:\Windows\SysWow64\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-01-20 14:25:25 847360 —-a-w- C:\Windows\SysWow64\OpcServices.dll
2011-01-20 14:24:26 135680 —-a-w- C:\Windows\SysWow64\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w- C:\Windows\SysWow64\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w- C:\Windows\SysWow64\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w- C:\Windows\SysWow64\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w- C:\Windows\SysWow64\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w- C:\Windows\SysWow64\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w- C:\Windows\SysWow64\d3d10level9.dll
2011-01-20 14:06:15 834048 —-a-w- C:\Windows\System32\d2d1.dll
2011-01-20 13:47:51 683008 —-a-w- C:\Windows\SysWow64\d2d1.dll
2011-01-08 06:45:51 367104 —-a-w- C:\Windows\System32\atmfd.dll
2011-01-08 06:28:49 292352 —-a-w- C:\Windows\SysWow64\atmfd.dll
2010-12-31 14:16:41 2757632 —-a-w- C:\Windows\System32\win32k.sys
2010-12-29 19:01:38 416768 —-a-w- C:\Windows\System32\sbe.dll
2010-12-29 19:01:38 210944 —-a-w- C:\Windows\System32\sbeio.dll
2010-12-29 19:01:24 559616 —-a-w- C:\Windows\System32\EncDec.dll
2010-12-29 18:59:41 226816 —-a-w- C:\Windows\System32\mpg2splt.ax
2010-12-29 18:28:45 322560 —-a-w- C:\Windows\SysWow64\sbe.dll
2010-12-29 18:28:45 153088 —-a-w- C:\Windows\SysWow64\sbeio.dll
2010-12-29 18:28:28 429056 —-a-w- C:\Windows\SysWow64\EncDec.dll
2010-12-29 18:26:47 177664 —-a-w- C:\Windows\SysWow64\mpg2splt.ax
.
============= FINISH: 22:02:50.83 ===============
From the logs, it appears you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
Click on the tab labeled Update and then click on the button Check for updates . If an update is found, it will download and install the latest version. Once the program has loaded, select Perform quick scan , then click Scan .
[external image: Posted Image] When the scan is complete, click OK , then Show Results to view the results. Be sure that everything is checked , and click Remove Selected . When completed, a log will open in Notepad. Please save it to a convenient location and post the results. Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please let me know if there is any improvement in how your computer is running after this.
Are you having any trouble running Malwarebytes?
Reminder: Topics with no reply will be closed in 3 days
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic