This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Updates and AV downloads blocked

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, since 3 days I suspect my computer has been hijacked.

It started when javascript stopped working in Firefox… I tried to install opera but it wouldn't download… after the initial 175 kb was downloaded, the download stopped every time.
The same happened with other downloads… Normal internet was ok though.

At this time I became suspicious and tried to update Windows and Microsoft Security Essentials. That failed too.

I used another computer to download AVG and installed it to the infected computer. It found Win32/Heur.
I also installed malwarebytes anti-malware which didn't find anything.
I also installed superantispyware 4.55.1000 which didn't find anything.
I installed TDDSKiller which didn't find anything.

Then I reset my computer using an old image of drive C: (a drive image made with windows backup)

The first session afterwards was ok. Security essentials was able to update, I was able to download stuff again. So I thought I fixed it.

But when I restarted, the same thing happened as before.

Again:
I used another computer to download AVG and installed it. didn't find anything.
I also installed malwarebytes anti-malware which didn't find anything.
I also installed superantispyware 4.55.1000 which didn't find anything. It tries to update itself which doesn't work.
I installed TDDSKiller which didn't find anything.
I turned off Comodo firewall and turned on windows firewall —> still unable to update.
I ran AVG anti-rootkit scan –> it found nothing.

I installed GMER and it did find some issues:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-02 06:30:40
Windows 6.1.7601 Service Pack 1
Running: rt60ln90.exe


—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\88532e17d242
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\88532e17d242 (not active ControlSet)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}@iamoenfjakjmhaoohf 0x6A 0x61 0x6C 0x70 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}@haookbpfakgicnjk 0x6A 0x61 0x6C 0x70 …

—- EOF - GMER 1.0.15 —-


Then I ran DDS:



Output of DDS.txt:

.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 7:24:24.95 on Tue 08/02/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8106.3391 [GMT 7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Windows\System32\alg.exe
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files\Cypress\TrackPad\CyCpIo.exe
C:\Program Files\Cypress\TrackPad\CyHidWin.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files (x86)\Vertex Wireless\VW100 Connection Manager\Connection Manager.exe
C:\Program Files (x86)\SugarSync\SugarSyncManager.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\explorer.exe
C:\Windows\explorer.exe
E:\EVACopy-v5.2\EVACopy.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\WUDFHost.exe
C:\Users\ER\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page =
uDefault_Page_URL = hxxp://www1.ap.dell.com/content/default.aspx?c=th&l=en&s=gen
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: SSOIEAddonBHO Class: {da5bce70-d057-4d63-943d-5f3927ec59f1} - C:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [ccleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
uRun: [VW100 Connection Manager] C:\Program Files (x86)\Vertex Wireless\VW100 Connection Manager\Connection Manager.exe
uRun: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [FAStartup]
mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
mRunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
LSP: C:\Program Files (x86)\HMA! Pro VPN\bin\ForceInterfaceLSP.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: {505DBF54-EB18-49EE-A6C0-437CC9E42642} = 61.19.245.245 61.19.245.246
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll C:\Windows\SysWOW64\guard32.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: SSOIEAddonBHO Class: {DA5BCE70-D057-4D63-943D-5F3927EC59F1} - C:\Program Files (x86)\Sensible Vision\Fast Access\x64\FAIESSO.dll
BHO-X64: SSOIEAddonBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
mRun-x64: [CyCpIo] C:\Program Files\Cypress\TrackPad\CyCpIo.exe
mRun-x64: [CyHidWin] C:\Program Files\Cypress\TrackPad\CyHidWin.exe
mRun-x64: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
mRun-x64: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
mRun-x64: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
mRun-x64: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
mRun-x64: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun-x64: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
mRun-x64: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
mRun-x64: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
mRun-x64: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
AppInit_DLLs-X64: C:\Windows\system32\nvinitx.dll C:\Windows\system32\guard64.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\ER\AppData\Roaming\Mozilla\Firefox\Profiles\yyjp9n4x.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2011-2-22 26704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2011-3-16 37456]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2011-6-16 25960]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-6-15 55856]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2011-6-16 21616]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2011-1-7 304720]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-3-1 41552]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2011-4-5 377936]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2011-6-30 252344]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2011-6-30 41712]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2011-4-18 189440]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-18 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-18 12360]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-5-5 128384]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-6-16 98208]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-11-2 2428552]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-1 366640]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-26 2823000]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-6-15 1997416]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-31 1153368]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-6-15 689472]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-12-24 378984]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-11-30 16120]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-6-15 2656280]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2011-6-16 27760]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2011-4-14 118864]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2011-2-10 29264]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2011-6-15 176096]
R3 cyhid;Cypress Input Device;C:\Windows\System32\drivers\cyhid.sys [2011-6-15 104960]
R3 cykbfltrService;Cypress Keyboard Filter Driver;C:\Windows\System32\drivers\cykbfltr.sys [2011-6-16 13312]
R3 cymfltrService;Cypress Trackpad Filter Driver;C:\Windows\System32\drivers\cymfltr.sys [2011-6-16 62464]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-6-16 317440]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-6-16 76912]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-8-1 25912]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2011-6-16 56344]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2011-4-18 40832]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2011-6-16 8505856]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 84864]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-6-16 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-6-16 181248]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-6-15 155752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-14 17920]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2010-12-1 42392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-1-24 58128]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-1-24 274944]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2011-7-16 16776]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2011-7-16 9096]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\System32\drivers\facap.sys [2008-9-25 238848]
S3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-1-24 59904]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-6-16 158976]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-18 340240]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-30 149504]
S3 vwmfbus;Vertex Wireless Composite Device driver (WDM);C:\Windows\System32\drivers\vwmfbus.sys [2011-7-12 127488]
S3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM);C:\Windows\System32\drivers\vwmfdiag.sys [2011-7-12 128512]
S3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~;C:\Windows\System32\drivers\vwmfmdfl.sys [2011-7-12 18944]
S3 vwmfmdm;Vertex Wireless CDC Modem Driver;C:\Windows\System32\drivers\vwmfmdm.sys [2011-7-12 161280]
S3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM);C:\Windows\System32\drivers\vwmfserd.sys [2011-7-12 128512]
.
=============== Created Last 30 ================
.
2011-08-01 09:53:49 ——– d—–w- C:\Program Files (x86)\notepadplus
2011-08-01 03:37:05 ——– d—–w- C:\Program Files (x86)\ESET
2011-08-01 02:55:56 ——– d—–w- C:\Users\ER\AppData\Roaming\SUPERAntiSpyware.com
2011-08-01 02:55:56 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com
2011-08-01 02:55:54 ——– d—–w- C:\PROGRA~3\!SASCORE
2011-08-01 02:55:52 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2011-08-01 02:52:23 ——– d—–w- C:\PROGRAM FILES (X86) (X86)
2011-08-01 02:26:07 ——– d—–w- C:\Users\ER\AppData\Roaming\Malwarebytes
2011-08-01 02:26:04 41272 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-01 02:26:03 ——– d—–w- C:\PROGRA~3\Malwarebytes
2011-08-01 02:25:59 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-01 02:25:59 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-07-31 20:32:48 ——– d—–w- C:\Users\ER\AppData\Local\SugarSync
2011-07-31 20:30:41 ——– d—–w- C:\Program Files (x86)\SugarSync
2011-07-31 16:35:45 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-07-31 16:35:45 ——– d—–w- C:\PROGRA~3\Spybot - Search & Destroy
2011-07-31 16:15:44 ——– d—–w- C:\Users\ER\AppData\Roaming\AVG10
2011-07-31 16:15:09 ——– d—–w- C:\Windows\SysWow64\drivers\AVG
2011-07-31 16:14:50 ——– d—–w- C:\Windows\System32\drivers\AVG
2011-07-31 16:14:50 ——– d—–w- C:\PROGRA~3\AVG10
2011-07-31 16:14:40 ——– d—–w- C:\Program Files (x86)\AVG
2011-07-31 15:46:33 ——– d–h–w- C:\PROGRA~3\Common Files
2011-07-31 15:46:14 ——– d—–w- C:\PROGRA~3\MFAData
2011-07-31 15:07:26 8578896 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{9BE80B47-38DD-4BF3-80D9-84EBF20303B4}\mpengine.dll
2011-07-17 05:26:02 ——– d—–w- C:\Users\ER\AppData\Roaming\Djuggler
2011-07-17 03:58:59 ——– d—–w- C:\Program Files (x86)\Djuggler 4
2011-07-16 13:08:59 ——– d—–w- C:\Users\ER\AppData\Roaming\LibreOffice
2011-07-16 12:41:41 9096 —-a-w- C:\Windows\System32\EuGdiDrv.sys
2011-07-16 12:41:41 86408 —-a-w- C:\Windows\SysWow64\setupempdrv03.exe
2011-07-16 12:41:41 8456 —-a-w- C:\Windows\SysWow64\EuGdiDrv.sys
2011-07-16 12:41:41 2926208 —-a-w- C:\Windows\System32\BootMan.exe
2011-07-16 12:41:41 2340992 —-a-w- C:\Windows\SysWow64\BootMan.exe
2011-07-16 12:41:41 18048 —-a-w- C:\Windows\SysWow64\EuEpmGdi.dll
2011-07-16 12:41:41 16776 —-a-w- C:\Windows\System32\epmntdrv.sys
2011-07-16 12:41:41 14216 —-a-w- C:\Windows\SysWow64\epmntdrv.sys
2011-07-16 12:41:41 11264 —-a-w- C:\Windows\System32\EuEpmGdi.dll
2011-07-16 12:41:41 100232 —-a-w- C:\Windows\System32\setupempdrvx64.exe
2011-07-16 12:41:37 ——– d—–w- C:\Program Files (x86)\EASEUS
2011-07-14 05:12:55 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-14 03:50:22 ——– d—–w- C:\Program Files (x86)\HMA! Pro VPN
2011-07-14 03:22:33 ——– d—–w- C:\Users\ER\AppData\Roaming\Roxio Log Files
2011-07-14 03:22:33 ——– d—–w- C:\Users\ER\AppData\Roaming\Macrovision
2011-07-13 20:37:35 8873296 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-13 02:39:07 175616 ——w- C:\Windows\SysWow64\unrar.dll
2011-07-13 02:39:05 232448 ——w- C:\Windows\SysWow64\mp3fhg.acm
2011-07-13 02:39:05 151552 ——w- C:\Windows\SysWow64\ac3acm.acm
2011-07-13 02:39:04 73216 ——w- C:\Windows\SysWow64\ff_vfw.dll
2011-07-13 02:39:04 644608 ——w- C:\Windows\SysWow64\xvidcore.dll
2011-07-13 02:39:04 243200 ——w- C:\Windows\SysWow64\xvidvfw.dll
2011-07-13 02:39:04 237568 ——w- C:\Windows\SysWow64\yv12vfw.dll
2011-07-13 02:39:02 ——– d—–w- C:\Program Files (x86)\K-Lite Codec Pack
2011-07-12 22:29:43 ——– d—–w- C:\Program Files (x86)\LibreOffice 3
2011-07-12 15:16:47 ——– d—–w- C:\uTorrent
2011-07-12 15:15:32 ——– d—–w- C:\Program Files (x86)\uTorrent
2011-07-12 15:14:49 ——– d—–w- C:\Users\ER\AppData\Roaming\uTorrent
2011-07-12 15:14:49 ——– d—–w- C:\Users\ER\AppData\Local\uTorrent
2011-07-12 14:14:12 ——– d—–w- C:\Program Files\Bulk Rename Utility
2011-07-12 06:46:01 ——– d—–w- C:\Program Files\CCleaner
2011-07-12 04:21:19 ——– d—–w- C:\Users\ER\AppData\Roaming\Abine
2011-07-12 03:14:07 ——– d—–w- C:\Users\ER\AppData\Local\Connectify
2011-07-12 03:13:34 ——– d—–w- C:\Program Files (x86)\Connectify
2011-07-12 02:44:08 18944 —-a-w- C:\Windows\System32\drivers\vwmfmdfl.sys
2011-07-12 02:44:08 161280 —-a-w- C:\Windows\System32\drivers\vwmfmdm.sys
2011-07-12 02:44:08 15872 —-a-w- C:\Windows\System32\drivers\vwmfwhnt.sys
2011-07-12 02:44:08 15872 —-a-w- C:\Windows\System32\drivers\vwmfwh.sys
2011-07-12 02:44:08 15360 —-a-w- C:\Windows\System32\drivers\vwmfcmnt.sys
2011-07-12 02:44:08 15360 —-a-w- C:\Windows\System32\drivers\vwmfcm.sys
2011-07-12 02:44:08 128512 —-a-w- C:\Windows\System32\drivers\vwmfserd.sys
2011-07-12 02:44:08 128512 —-a-w- C:\Windows\System32\drivers\vwmfdiag.sys
2011-07-12 02:44:08 127488 —-a-w- C:\Windows\System32\drivers\vwmfbus.sys
2011-07-12 02:44:08 ——– d—–w- C:\Program Files\Vertex Wireless
2011-07-12 02:43:47 ——– d—–w- C:\Program Files (x86)\Vertex Wireless
2011-07-12 02:43:45 ——– d—–w- C:\PROGRA~3\Vertex Wireless
2011-07-12 02:02:24 142336 —-a-w- C:\Windows\System32\poqexec.exe
2011-07-12 02:02:24 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe
2011-07-12 01:58:52 ——– d—–w- C:\Users\ER\AppData\Local\Diagnostics
2011-07-12 01:16:10 5562240 —-a-w- C:\Windows\System32\ntoskrnl.exe
2011-07-11 18:19:17 ——– d—–w- C:\Users\ER\AppData\Local\ArcSoft
2011-07-11 18:18:31 ——– d—–w- C:\Program Files\COMODO
2011-07-11 18:17:26 ——– d—–w- C:\PROGRA~3\Comodo
2011-07-11 18:15:09 ——– d—–w- C:\PROGRA~3\Comodo Downloader
2011-07-11 18:03:50 601424 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{13D4BD41-A757-4681-96A5-BD38B6E20B81}\gapaengine.dll
2011-07-11 18:01:39 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client
2011-07-11 18:01:36 ——– d—–w- C:\Program Files\Microsoft Security Client
2011-07-11 10:07:45 ——– d—–w- C:\Users\ER\My Backup Files
2011-07-11 09:00:01 ——– d—–w- C:\PROGRA~3\PCDr
2011-07-11 08:58:34 ——– d-sh–w- C:\System Recovery
2011-07-11 08:57:39 ——– d—–w- C:\Users\ER\AppData\Local\Dell
2011-07-11 08:57:05 ——– d—–w- C:\Users\ER\AppData\Roaming\Dell
2011-07-11 08:57:02 ——– d—–w- C:\Users\ER\AppData\Roaming\Dell Touch Zone
2011-07-11 08:56:31 ——– d—–w- C:\Users\ER\AppData\Local\VirtualStore
2011-07-11 08:56:27 ——– d—–w- C:\Users\ER\AppData\Local\SoftThinks
.
==================== Find3M ====================
.
2011-06-30 02:38:10 41712 —-a-w- C:\Windows\System32\drivers\cmdhlp.sys
2011-06-30 02:38:08 252344 —-a-w- C:\Windows\System32\drivers\cmdGuard.sys
2011-06-30 02:38:08 16016 —-a-w- C:\Windows\System32\drivers\cmderd.sys
2011-06-30 02:37:26 363560 —-a-w- C:\Windows\System32\guard64.dll
2011-06-30 02:37:26 285256 ——w- C:\Windows\SysWow64\guard32.dll
2011-06-15 17:32:14 91648 —-a-w- C:\Windows\System32\SetIEInstalledDate.exe
2011-06-15 15:53:20 521448 —-a-w- C:\Windows\System32\deployJava1.dll
2011-06-11 03:07:25 3137536 —-a-w- C:\Windows\System32\win32k.sys
2011-06-03 06:57:45 362496 —-a-w- C:\Windows\System32\wow64win.dll
2011-06-03 06:57:45 243200 —-a-w- C:\Windows\System32\wow64.dll
2011-06-03 06:57:45 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2011-06-03 06:57:44 214528 —-a-w- C:\Windows\System32\winsrv.dll
2011-06-03 06:57:38 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2011-06-03 06:56:38 421888 —-a-w- C:\Windows\System32\KernelBase.dll
2011-06-03 06:53:33 338944 —-a-w- C:\Windows\System32\conhost.exe
2011-06-03 06:00:53 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-06-03 05:57:52 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2011-06-03 05:57:33 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2011-06-03 05:56:12 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2011-06-03 05:56:11 272384 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2011-06-03 03:53:31 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2011-06-03 03:53:31 2048 —-a-w- C:\Windows\SysWow64\user.exe
2011-06-03 03:48:32 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-06-03 03:48:31 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-06-03 03:48:31 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-03 03:48:31 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-05-24 12:14:10 270720 ——w- C:\Windows\System32\MpSigStub.exe
2011-05-24 11:42:55 404480 —-a-w- C:\Windows\System32\umpnpmgr.dll
2011-05-24 10:40:05 64512 —-a-w- C:\Windows\SysWow64\devobj.dll
2011-05-24 10:40:05 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll
2011-05-24 10:39:38 145920 —-a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-05-24 10:37:54 252928 —-a-w- C:\Windows\SysWow64\drvinst.exe
2011-05-04 05:25:03 2315776 —-a-w- C:\Windows\System32\tquery.dll
2011-05-04 05:22:25 778752 —-a-w- C:\Windows\System32\mssvp.dll
2011-05-04 05:22:25 2223616 —-a-w- C:\Windows\System32\mssrch.dll
2011-05-04 05:22:24 75264 —-a-w- C:\Windows\System32\msscntrs.dll
2011-05-04 05:22:24 491520 —-a-w- C:\Windows\System32\mssph.dll
2011-05-04 05:22:24 288256 —-a-w- C:\Windows\System32\mssphtb.dll
2011-05-04 05:19:28 591872 —-a-w- C:\Windows\System32\SearchIndexer.exe
2011-05-04 05:19:28 249856 —-a-w- C:\Windows\System32\SearchProtocolHost.exe
2011-05-04 05:19:28 113664 —-a-w- C:\Windows\System32\SearchFilterHost.exe
2011-05-04 04:34:43 1549312 —-a-w- C:\Windows\SysWow64\tquery.dll
2011-05-04 04:32:02 666624 —-a-w- C:\Windows\SysWow64\mssvp.dll
2011-05-04 04:32:01 337408 —-a-w- C:\Windows\SysWow64\mssph.dll
2011-05-04 04:32:01 197120 —-a-w- C:\Windows\SysWow64\mssphtb.dll
2011-05-04 04:32:01 1401344 —-a-w- C:\Windows\SysWow64\mssrch.dll
2011-05-04 04:32:00 59392 —-a-w- C:\Windows\SysWow64\msscntrs.dll
2011-05-04 04:28:31 86528 —-a-w- C:\Windows\SysWow64\SearchFilterHost.exe
2011-05-04 04:28:31 427520 —-a-w- C:\Windows\SysWow64\SearchIndexer.exe
2011-05-04 04:28:31 164352 —-a-w- C:\Windows\SysWow64\SearchProtocolHost.exe
.
============= FINISH: 7:25:40.78 ===============

Output of attach.txt:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 7/11/2011 3:52:59 PM
System Uptime: 8/1/2011 10:26:42 AM (21 hours ago)
.
Motherboard: Dell Inc. | | 060G42
Processor: Intel® Core™ i7-2620M CPU @ 2.70GHz | CPU | 2701/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 88 GiB total, 53.711 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 596 GiB total, 471.072 GiB free.
G: is Removable
W: is FIXED (NTFS) - 234 GiB total, 60.25 GiB free.
Y: is FIXED (NTFS) - 15 GiB total, 7.107 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: facap, FastAccess Video Capture
Device ID: ROOT\IMAGE\0000
Manufacturer: Sensible Vision
Name: facap, FastAccess Video Capture
PNP Device ID: ROOT\IMAGE\0000
Service: FACAP
.
Class GUID: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Description: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Adapter
Device ID: USB\VID_8086&PID_0189\6&3023DF2C&0&5
Manufacturer: Intel Corporation
Name: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Adapter
PNP Device ID: USB\VID_8086&PID_0189\6&3023DF2C&0&5
Service: BTHUSB
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
µTorrent
AccelerometerP11
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X MUI
Advanced Audio FX Engine
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Webcam Central
Djuggler 4.0.7.447
EASEUS Partition Master 8.0.1 Home Edition
ESET Online Scanner v3
FileZilla Client 3.5.0
HMA! Pro VPN 2.6.8
Intel® Control Center
Intel® Management Engine Components
Intel® Processor Graphics
Intel® Wireless Display
Java Auto Updater
Java™ 6 Update 26
K-Lite Mega Codec Pack 7.2.0
LibreOffice 3.3
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft Office 2010
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 5.0 (x86 en-US)
NVIDIA Stereoscopic 3D Driver
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Skype™ 4.2
Spybot - Search & Destroy
SugarSync Manager
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Visual Studio 2008 x64 Redistributables
VW100 Connection Manager
.
==== Event Viewer Messages From Past Week ========
.
8/2/2011 6:52:17 AM, Error: Microsoft-Windows-SharedAccess_NAT [31004] - The DNS proxy agent was unable to allocate 0 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
8/2/2011 6:17:04 AM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
8/1/2011 9:59:35 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:59:35 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:59:28 AM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
8/1/2011 9:59:24 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
8/1/2011 9:59:24 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
8/1/2011 9:59:19 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/1/2011 9:59:14 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
8/1/2011 9:59:09 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 cmdGuard discache MpFilter SASDIFSV SASKUTIL spldr Wanarpv6
8/1/2011 9:57:44 AM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
8/1/2011 9:56:05 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
8/1/2011 9:54:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
8/1/2011 9:54:32 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx64 Avgmfx64 Avgtdia cmdGuard cmdHlp DfsC discache inspect MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf ws2ifsl
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 3:12:04 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/31/2011 9:55:14 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
7/31/2011 9:55:14 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/31/2011 9:55:14 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
7/31/2011 9:55:14 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
7/31/2011 9:55:09 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
7/31/2011 9:55:09 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
7/31/2011 9:55:02 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
7/31/2011 11:17:19 PM, Error: Service Control Manager [7034] - The Bluetooth Media Service service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 11:17:08 PM, Error: Service Control Manager [7034] - The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 11:16:55 PM, Error: Service Control Manager [7034] - The Bluetooth Device Monitor service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 10:21:34 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
.
==== End Of File ===========================



Any help would be very much appreciated,

Thanks,

Ed
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!



It would appear that you have more than one anti-virus solution on your machine. I can see AVG, Microsoft Security Essentials, and Comodo Defense installed.
Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.
Before continuing on, please completely uninstall two of the programs. Since Comodo is also acting as your firewall, I might suggest that you keep it and remove the other two, but that is a matter of preference. Whatever you decide be sure only one remains.

If you have any trouble uninstalling two of them please let me know. After you are done, if you are not prompted to do so, please reboot your machine. Please advise if the issues continue once you only have one anti-virus on the machine.
Hi patndoris, I removed AVG from the computer, after that updates and downloads were possible again. The comodo product I have installed calls itself a firewall. I think they have another product which they call an antivirus. So i think that with microsoft security essentials, i have only 1 antivilrus left? What do you think? thanks, ed
I'm glad to hear things are improving. Let's do a couple of other scans to be sure we don't miss anything.


I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Uncheck Remove found threats.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic.
Hi, This is the output from the first step: Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7379 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 8/5/2011 8:15:20 AM mbam-log-2011-08-05 (08-15-20).txt Scan type: Quick scan Objects scanned: 188736 Time elapsed: 2 minute(s), 16 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I will do the second step (eset) now and post the results later today… thanks
Hello, this is the output from the ESET log file: ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK thanks, ed
Well, I'm not seeing any malware in the logs, are you still having issues of any kind or does everything seem to be running well?
Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Set a New Restore Point to prevent possible reinfection from an old one.
Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
* Go to Start > Programs > Accessories > System Tools
* Click "System Restore"
* Choose the radio button marked "Create a Restore Point" on the first screen then click "Next"
* Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
* Then go to Start > Run and type: Cleanmgr
* Click "OK"
* Click the "More Options" Tab.
* Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Use only one antivirus and one firewall on your machine
Having more than one anti-virus program and one firewall on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.

If you need more information on free anti-virus or firewall options please let me know and I will give you some recommendations.

Make your Internet Explorer more secure
This can be done by following these simple instructions:
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.
5. Change the Download signed ActiveX controls to Prompt
6. Change the Download unsigned ActiveX controls to Disable
7. Change the Initialize and script ActiveX controls not marked as safe to Disable
8. Change the Installation of desktop items to Prompt
9. Change the Launching programs and files in an IFRAME to Prompt
10. Change the Navigate sub-frames across different domains to Prompt
11. When all these settings have been made, click on the OK button.
12. If it prompts you as to whether or not you want to save the settings, press the Yes button.
13. Next press the Apply button and then the OK to exit the Internet Properties page.

Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

I would suggest you read:
Tony Klein's excellent article: How I got Infected in the First Place
PC Safety and Security–What Do I Need?
How to Prevent Malware

Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI