eddie R
Topic Starter
Hi, since 3 days I suspect my computer has been hijacked.
It started when javascript stopped working in Firefox… I tried to install opera but it wouldn't download… after the initial 175 kb was downloaded, the download stopped every time.
The same happened with other downloads… Normal internet was ok though.
At this time I became suspicious and tried to update Windows and Microsoft Security Essentials. That failed too.
I used another computer to download AVG and installed it to the infected computer. It found Win32/Heur.
I also installed malwarebytes anti-malware which didn't find anything.
I also installed superantispyware 4.55.1000 which didn't find anything.
I installed TDDSKiller which didn't find anything.
Then I reset my computer using an old image of drive C: (a drive image made with windows backup)
The first session afterwards was ok. Security essentials was able to update, I was able to download stuff again. So I thought I fixed it.
But when I restarted, the same thing happened as before.
Again:
I used another computer to download AVG and installed it. didn't find anything.
I also installed malwarebytes anti-malware which didn't find anything.
I also installed superantispyware 4.55.1000 which didn't find anything. It tries to update itself which doesn't work.
I installed TDDSKiller which didn't find anything.
I turned off Comodo firewall and turned on windows firewall —> still unable to update.
I ran AVG anti-rootkit scan –> it found nothing.
I installed GMER and it did find some issues:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-02 06:30:40
Windows 6.1.7601 Service Pack 1
Running: rt60ln90.exe
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\88532e17d242
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\88532e17d242 (not active ControlSet)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}@iamoenfjakjmhaoohf 0x6A 0x61 0x6C 0x70 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}@haookbpfakgicnjk 0x6A 0x61 0x6C 0x70 …
—- EOF - GMER 1.0.15 —-
Then I ran DDS:
Output of DDS.txt:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 7:24:24.95 on Tue 08/02/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8106.3391 [GMT 7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Windows\System32\alg.exe
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files\Cypress\TrackPad\CyCpIo.exe
C:\Program Files\Cypress\TrackPad\CyHidWin.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files (x86)\Vertex Wireless\VW100 Connection Manager\Connection Manager.exe
C:\Program Files (x86)\SugarSync\SugarSyncManager.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\explorer.exe
C:\Windows\explorer.exe
E:\EVACopy-v5.2\EVACopy.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\WUDFHost.exe
C:\Users\ER\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page =
uDefault_Page_URL = hxxp://www1.ap.dell.com/content/default.aspx?c=th&l=en&s=gen
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: SSOIEAddonBHO Class: {da5bce70-d057-4d63-943d-5f3927ec59f1} - C:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [ccleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
uRun: [VW100 Connection Manager] C:\Program Files (x86)\Vertex Wireless\VW100 Connection Manager\Connection Manager.exe
uRun: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [FAStartup]
mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
mRunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
LSP: C:\Program Files (x86)\HMA! Pro VPN\bin\ForceInterfaceLSP.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: {505DBF54-EB18-49EE-A6C0-437CC9E42642} = 61.19.245.245 61.19.245.246
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll C:\Windows\SysWOW64\guard32.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: SSOIEAddonBHO Class: {DA5BCE70-D057-4D63-943D-5F3927EC59F1} - C:\Program Files (x86)\Sensible Vision\Fast Access\x64\FAIESSO.dll
BHO-X64: SSOIEAddonBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
mRun-x64: [CyCpIo] C:\Program Files\Cypress\TrackPad\CyCpIo.exe
mRun-x64: [CyHidWin] C:\Program Files\Cypress\TrackPad\CyHidWin.exe
mRun-x64: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
mRun-x64: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
mRun-x64: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
mRun-x64: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
mRun-x64: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun-x64: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
mRun-x64: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
mRun-x64: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
mRun-x64: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
AppInit_DLLs-X64: C:\Windows\system32\nvinitx.dll C:\Windows\system32\guard64.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\ER\AppData\Roaming\Mozilla\Firefox\Profiles\yyjp9n4x.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2011-2-22 26704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2011-3-16 37456]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2011-6-16 25960]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-6-15 55856]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2011-6-16 21616]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2011-1-7 304720]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-3-1 41552]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2011-4-5 377936]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2011-6-30 252344]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2011-6-30 41712]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2011-4-18 189440]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-18 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-18 12360]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-5-5 128384]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-6-16 98208]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-11-2 2428552]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-1 366640]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-26 2823000]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-6-15 1997416]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-31 1153368]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-6-15 689472]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-12-24 378984]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-11-30 16120]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-6-15 2656280]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2011-6-16 27760]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2011-4-14 118864]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2011-2-10 29264]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2011-6-15 176096]
R3 cyhid;Cypress Input Device;C:\Windows\System32\drivers\cyhid.sys [2011-6-15 104960]
R3 cykbfltrService;Cypress Keyboard Filter Driver;C:\Windows\System32\drivers\cykbfltr.sys [2011-6-16 13312]
R3 cymfltrService;Cypress Trackpad Filter Driver;C:\Windows\System32\drivers\cymfltr.sys [2011-6-16 62464]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-6-16 317440]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-6-16 76912]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-8-1 25912]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2011-6-16 56344]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2011-4-18 40832]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2011-6-16 8505856]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 84864]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-6-16 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-6-16 181248]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-6-15 155752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-14 17920]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2010-12-1 42392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-1-24 58128]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-1-24 274944]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2011-7-16 16776]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2011-7-16 9096]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\System32\drivers\facap.sys [2008-9-25 238848]
S3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-1-24 59904]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-6-16 158976]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-18 340240]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-30 149504]
S3 vwmfbus;Vertex Wireless Composite Device driver (WDM);C:\Windows\System32\drivers\vwmfbus.sys [2011-7-12 127488]
S3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM);C:\Windows\System32\drivers\vwmfdiag.sys [2011-7-12 128512]
S3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~;C:\Windows\System32\drivers\vwmfmdfl.sys [2011-7-12 18944]
S3 vwmfmdm;Vertex Wireless CDC Modem Driver;C:\Windows\System32\drivers\vwmfmdm.sys [2011-7-12 161280]
S3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM);C:\Windows\System32\drivers\vwmfserd.sys [2011-7-12 128512]
.
=============== Created Last 30 ================
.
2011-08-01 09:53:49 ——– d—–w- C:\Program Files (x86)\notepadplus
2011-08-01 03:37:05 ——– d—–w- C:\Program Files (x86)\ESET
2011-08-01 02:55:56 ——– d—–w- C:\Users\ER\AppData\Roaming\SUPERAntiSpyware.com
2011-08-01 02:55:56 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com
2011-08-01 02:55:54 ——– d—–w- C:\PROGRA~3\!SASCORE
2011-08-01 02:55:52 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2011-08-01 02:52:23 ——– d—–w- C:\PROGRAM FILES (X86) (X86)
2011-08-01 02:26:07 ——– d—–w- C:\Users\ER\AppData\Roaming\Malwarebytes
2011-08-01 02:26:04 41272 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-01 02:26:03 ——– d—–w- C:\PROGRA~3\Malwarebytes
2011-08-01 02:25:59 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-01 02:25:59 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-07-31 20:32:48 ——– d—–w- C:\Users\ER\AppData\Local\SugarSync
2011-07-31 20:30:41 ——– d—–w- C:\Program Files (x86)\SugarSync
2011-07-31 16:35:45 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-07-31 16:35:45 ——– d—–w- C:\PROGRA~3\Spybot - Search & Destroy
2011-07-31 16:15:44 ——– d—–w- C:\Users\ER\AppData\Roaming\AVG10
2011-07-31 16:15:09 ——– d—–w- C:\Windows\SysWow64\drivers\AVG
2011-07-31 16:14:50 ——– d—–w- C:\Windows\System32\drivers\AVG
2011-07-31 16:14:50 ——– d—–w- C:\PROGRA~3\AVG10
2011-07-31 16:14:40 ——– d—–w- C:\Program Files (x86)\AVG
2011-07-31 15:46:33 ——– d–h–w- C:\PROGRA~3\Common Files
2011-07-31 15:46:14 ——– d—–w- C:\PROGRA~3\MFAData
2011-07-31 15:07:26 8578896 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{9BE80B47-38DD-4BF3-80D9-84EBF20303B4}\mpengine.dll
2011-07-17 05:26:02 ——– d—–w- C:\Users\ER\AppData\Roaming\Djuggler
2011-07-17 03:58:59 ——– d—–w- C:\Program Files (x86)\Djuggler 4
2011-07-16 13:08:59 ——– d—–w- C:\Users\ER\AppData\Roaming\LibreOffice
2011-07-16 12:41:41 9096 —-a-w- C:\Windows\System32\EuGdiDrv.sys
2011-07-16 12:41:41 86408 —-a-w- C:\Windows\SysWow64\setupempdrv03.exe
2011-07-16 12:41:41 8456 —-a-w- C:\Windows\SysWow64\EuGdiDrv.sys
2011-07-16 12:41:41 2926208 —-a-w- C:\Windows\System32\BootMan.exe
2011-07-16 12:41:41 2340992 —-a-w- C:\Windows\SysWow64\BootMan.exe
2011-07-16 12:41:41 18048 —-a-w- C:\Windows\SysWow64\EuEpmGdi.dll
2011-07-16 12:41:41 16776 —-a-w- C:\Windows\System32\epmntdrv.sys
2011-07-16 12:41:41 14216 —-a-w- C:\Windows\SysWow64\epmntdrv.sys
2011-07-16 12:41:41 11264 —-a-w- C:\Windows\System32\EuEpmGdi.dll
2011-07-16 12:41:41 100232 —-a-w- C:\Windows\System32\setupempdrvx64.exe
2011-07-16 12:41:37 ——– d—–w- C:\Program Files (x86)\EASEUS
2011-07-14 05:12:55 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-14 03:50:22 ——– d—–w- C:\Program Files (x86)\HMA! Pro VPN
2011-07-14 03:22:33 ——– d—–w- C:\Users\ER\AppData\Roaming\Roxio Log Files
2011-07-14 03:22:33 ——– d—–w- C:\Users\ER\AppData\Roaming\Macrovision
2011-07-13 20:37:35 8873296 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-13 02:39:07 175616 ——w- C:\Windows\SysWow64\unrar.dll
2011-07-13 02:39:05 232448 ——w- C:\Windows\SysWow64\mp3fhg.acm
2011-07-13 02:39:05 151552 ——w- C:\Windows\SysWow64\ac3acm.acm
2011-07-13 02:39:04 73216 ——w- C:\Windows\SysWow64\ff_vfw.dll
2011-07-13 02:39:04 644608 ——w- C:\Windows\SysWow64\xvidcore.dll
2011-07-13 02:39:04 243200 ——w- C:\Windows\SysWow64\xvidvfw.dll
2011-07-13 02:39:04 237568 ——w- C:\Windows\SysWow64\yv12vfw.dll
2011-07-13 02:39:02 ——– d—–w- C:\Program Files (x86)\K-Lite Codec Pack
2011-07-12 22:29:43 ——– d—–w- C:\Program Files (x86)\LibreOffice 3
2011-07-12 15:16:47 ——– d—–w- C:\uTorrent
2011-07-12 15:15:32 ——– d—–w- C:\Program Files (x86)\uTorrent
2011-07-12 15:14:49 ——– d—–w- C:\Users\ER\AppData\Roaming\uTorrent
2011-07-12 15:14:49 ——– d—–w- C:\Users\ER\AppData\Local\uTorrent
2011-07-12 14:14:12 ——– d—–w- C:\Program Files\Bulk Rename Utility
2011-07-12 06:46:01 ——– d—–w- C:\Program Files\CCleaner
2011-07-12 04:21:19 ——– d—–w- C:\Users\ER\AppData\Roaming\Abine
2011-07-12 03:14:07 ——– d—–w- C:\Users\ER\AppData\Local\Connectify
2011-07-12 03:13:34 ——– d—–w- C:\Program Files (x86)\Connectify
2011-07-12 02:44:08 18944 —-a-w- C:\Windows\System32\drivers\vwmfmdfl.sys
2011-07-12 02:44:08 161280 —-a-w- C:\Windows\System32\drivers\vwmfmdm.sys
2011-07-12 02:44:08 15872 —-a-w- C:\Windows\System32\drivers\vwmfwhnt.sys
2011-07-12 02:44:08 15872 —-a-w- C:\Windows\System32\drivers\vwmfwh.sys
2011-07-12 02:44:08 15360 —-a-w- C:\Windows\System32\drivers\vwmfcmnt.sys
2011-07-12 02:44:08 15360 —-a-w- C:\Windows\System32\drivers\vwmfcm.sys
2011-07-12 02:44:08 128512 —-a-w- C:\Windows\System32\drivers\vwmfserd.sys
2011-07-12 02:44:08 128512 —-a-w- C:\Windows\System32\drivers\vwmfdiag.sys
2011-07-12 02:44:08 127488 —-a-w- C:\Windows\System32\drivers\vwmfbus.sys
2011-07-12 02:44:08 ——– d—–w- C:\Program Files\Vertex Wireless
2011-07-12 02:43:47 ——– d—–w- C:\Program Files (x86)\Vertex Wireless
2011-07-12 02:43:45 ——– d—–w- C:\PROGRA~3\Vertex Wireless
2011-07-12 02:02:24 142336 —-a-w- C:\Windows\System32\poqexec.exe
2011-07-12 02:02:24 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe
2011-07-12 01:58:52 ——– d—–w- C:\Users\ER\AppData\Local\Diagnostics
2011-07-12 01:16:10 5562240 —-a-w- C:\Windows\System32\ntoskrnl.exe
2011-07-11 18:19:17 ——– d—–w- C:\Users\ER\AppData\Local\ArcSoft
2011-07-11 18:18:31 ——– d—–w- C:\Program Files\COMODO
2011-07-11 18:17:26 ——– d—–w- C:\PROGRA~3\Comodo
2011-07-11 18:15:09 ——– d—–w- C:\PROGRA~3\Comodo Downloader
2011-07-11 18:03:50 601424 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{13D4BD41-A757-4681-96A5-BD38B6E20B81}\gapaengine.dll
2011-07-11 18:01:39 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client
2011-07-11 18:01:36 ——– d—–w- C:\Program Files\Microsoft Security Client
2011-07-11 10:07:45 ——– d—–w- C:\Users\ER\My Backup Files
2011-07-11 09:00:01 ——– d—–w- C:\PROGRA~3\PCDr
2011-07-11 08:58:34 ——– d-sh–w- C:\System Recovery
2011-07-11 08:57:39 ——– d—–w- C:\Users\ER\AppData\Local\Dell
2011-07-11 08:57:05 ——– d—–w- C:\Users\ER\AppData\Roaming\Dell
2011-07-11 08:57:02 ——– d—–w- C:\Users\ER\AppData\Roaming\Dell Touch Zone
2011-07-11 08:56:31 ——– d—–w- C:\Users\ER\AppData\Local\VirtualStore
2011-07-11 08:56:27 ——– d—–w- C:\Users\ER\AppData\Local\SoftThinks
.
==================== Find3M ====================
.
2011-06-30 02:38:10 41712 —-a-w- C:\Windows\System32\drivers\cmdhlp.sys
2011-06-30 02:38:08 252344 —-a-w- C:\Windows\System32\drivers\cmdGuard.sys
2011-06-30 02:38:08 16016 —-a-w- C:\Windows\System32\drivers\cmderd.sys
2011-06-30 02:37:26 363560 —-a-w- C:\Windows\System32\guard64.dll
2011-06-30 02:37:26 285256 ——w- C:\Windows\SysWow64\guard32.dll
2011-06-15 17:32:14 91648 —-a-w- C:\Windows\System32\SetIEInstalledDate.exe
2011-06-15 15:53:20 521448 —-a-w- C:\Windows\System32\deployJava1.dll
2011-06-11 03:07:25 3137536 —-a-w- C:\Windows\System32\win32k.sys
2011-06-03 06:57:45 362496 —-a-w- C:\Windows\System32\wow64win.dll
2011-06-03 06:57:45 243200 —-a-w- C:\Windows\System32\wow64.dll
2011-06-03 06:57:45 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2011-06-03 06:57:44 214528 —-a-w- C:\Windows\System32\winsrv.dll
2011-06-03 06:57:38 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2011-06-03 06:56:38 421888 —-a-w- C:\Windows\System32\KernelBase.dll
2011-06-03 06:53:33 338944 —-a-w- C:\Windows\System32\conhost.exe
2011-06-03 06:00:53 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-06-03 05:57:52 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2011-06-03 05:57:33 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2011-06-03 05:56:12 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2011-06-03 05:56:11 272384 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2011-06-03 03:53:31 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2011-06-03 03:53:31 2048 —-a-w- C:\Windows\SysWow64\user.exe
2011-06-03 03:48:32 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-06-03 03:48:31 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-06-03 03:48:31 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-03 03:48:31 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-05-24 12:14:10 270720 ——w- C:\Windows\System32\MpSigStub.exe
2011-05-24 11:42:55 404480 —-a-w- C:\Windows\System32\umpnpmgr.dll
2011-05-24 10:40:05 64512 —-a-w- C:\Windows\SysWow64\devobj.dll
2011-05-24 10:40:05 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll
2011-05-24 10:39:38 145920 —-a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-05-24 10:37:54 252928 —-a-w- C:\Windows\SysWow64\drvinst.exe
2011-05-04 05:25:03 2315776 —-a-w- C:\Windows\System32\tquery.dll
2011-05-04 05:22:25 778752 —-a-w- C:\Windows\System32\mssvp.dll
2011-05-04 05:22:25 2223616 —-a-w- C:\Windows\System32\mssrch.dll
2011-05-04 05:22:24 75264 —-a-w- C:\Windows\System32\msscntrs.dll
2011-05-04 05:22:24 491520 —-a-w- C:\Windows\System32\mssph.dll
2011-05-04 05:22:24 288256 —-a-w- C:\Windows\System32\mssphtb.dll
2011-05-04 05:19:28 591872 —-a-w- C:\Windows\System32\SearchIndexer.exe
2011-05-04 05:19:28 249856 —-a-w- C:\Windows\System32\SearchProtocolHost.exe
2011-05-04 05:19:28 113664 —-a-w- C:\Windows\System32\SearchFilterHost.exe
2011-05-04 04:34:43 1549312 —-a-w- C:\Windows\SysWow64\tquery.dll
2011-05-04 04:32:02 666624 —-a-w- C:\Windows\SysWow64\mssvp.dll
2011-05-04 04:32:01 337408 —-a-w- C:\Windows\SysWow64\mssph.dll
2011-05-04 04:32:01 197120 —-a-w- C:\Windows\SysWow64\mssphtb.dll
2011-05-04 04:32:01 1401344 —-a-w- C:\Windows\SysWow64\mssrch.dll
2011-05-04 04:32:00 59392 —-a-w- C:\Windows\SysWow64\msscntrs.dll
2011-05-04 04:28:31 86528 —-a-w- C:\Windows\SysWow64\SearchFilterHost.exe
2011-05-04 04:28:31 427520 —-a-w- C:\Windows\SysWow64\SearchIndexer.exe
2011-05-04 04:28:31 164352 —-a-w- C:\Windows\SysWow64\SearchProtocolHost.exe
.
============= FINISH: 7:25:40.78 ===============
Output of attach.txt:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 7/11/2011 3:52:59 PM
System Uptime: 8/1/2011 10:26:42 AM (21 hours ago)
.
Motherboard: Dell Inc. | | 060G42
Processor: Intel® Core™ i7-2620M CPU @ 2.70GHz | CPU | 2701/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 88 GiB total, 53.711 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 596 GiB total, 471.072 GiB free.
G: is Removable
W: is FIXED (NTFS) - 234 GiB total, 60.25 GiB free.
Y: is FIXED (NTFS) - 15 GiB total, 7.107 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: facap, FastAccess Video Capture
Device ID: ROOT\IMAGE\0000
Manufacturer: Sensible Vision
Name: facap, FastAccess Video Capture
PNP Device ID: ROOT\IMAGE\0000
Service: FACAP
.
Class GUID: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Description: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Adapter
Device ID: USB\VID_8086&PID_0189\6&3023DF2C&0&5
Manufacturer: Intel Corporation
Name: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Adapter
PNP Device ID: USB\VID_8086&PID_0189\6&3023DF2C&0&5
Service: BTHUSB
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
µTorrent
AccelerometerP11
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X MUI
Advanced Audio FX Engine
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Webcam Central
Djuggler 4.0.7.447
EASEUS Partition Master 8.0.1 Home Edition
ESET Online Scanner v3
FileZilla Client 3.5.0
HMA! Pro VPN 2.6.8
Intel® Control Center
Intel® Management Engine Components
Intel® Processor Graphics
Intel® Wireless Display
Java Auto Updater
Java™ 6 Update 26
K-Lite Mega Codec Pack 7.2.0
LibreOffice 3.3
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft Office 2010
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 5.0 (x86 en-US)
NVIDIA Stereoscopic 3D Driver
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Skype™ 4.2
Spybot - Search & Destroy
SugarSync Manager
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Visual Studio 2008 x64 Redistributables
VW100 Connection Manager
.
==== Event Viewer Messages From Past Week ========
.
8/2/2011 6:52:17 AM, Error: Microsoft-Windows-SharedAccess_NAT [31004] - The DNS proxy agent was unable to allocate 0 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
8/2/2011 6:17:04 AM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
8/1/2011 9:59:35 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:59:35 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:59:28 AM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
8/1/2011 9:59:24 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
8/1/2011 9:59:24 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
8/1/2011 9:59:19 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/1/2011 9:59:14 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
8/1/2011 9:59:09 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 cmdGuard discache MpFilter SASDIFSV SASKUTIL spldr Wanarpv6
8/1/2011 9:57:44 AM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
8/1/2011 9:56:05 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
8/1/2011 9:54:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
8/1/2011 9:54:32 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx64 Avgmfx64 Avgtdia cmdGuard cmdHlp DfsC discache inspect MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf ws2ifsl
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 3:12:04 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/31/2011 9:55:14 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
7/31/2011 9:55:14 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/31/2011 9:55:14 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
7/31/2011 9:55:14 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
7/31/2011 9:55:09 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
7/31/2011 9:55:09 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
7/31/2011 9:55:02 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
7/31/2011 11:17:19 PM, Error: Service Control Manager [7034] - The Bluetooth Media Service service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 11:17:08 PM, Error: Service Control Manager [7034] - The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 11:16:55 PM, Error: Service Control Manager [7034] - The Bluetooth Device Monitor service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 10:21:34 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
.
==== End Of File ===========================
Any help would be very much appreciated,
Thanks,
Ed
It started when javascript stopped working in Firefox… I tried to install opera but it wouldn't download… after the initial 175 kb was downloaded, the download stopped every time.
The same happened with other downloads… Normal internet was ok though.
At this time I became suspicious and tried to update Windows and Microsoft Security Essentials. That failed too.
I used another computer to download AVG and installed it to the infected computer. It found Win32/Heur.
I also installed malwarebytes anti-malware which didn't find anything.
I also installed superantispyware 4.55.1000 which didn't find anything.
I installed TDDSKiller which didn't find anything.
Then I reset my computer using an old image of drive C: (a drive image made with windows backup)
The first session afterwards was ok. Security essentials was able to update, I was able to download stuff again. So I thought I fixed it.
But when I restarted, the same thing happened as before.
Again:
I used another computer to download AVG and installed it. didn't find anything.
I also installed malwarebytes anti-malware which didn't find anything.
I also installed superantispyware 4.55.1000 which didn't find anything. It tries to update itself which doesn't work.
I installed TDDSKiller which didn't find anything.
I turned off Comodo firewall and turned on windows firewall —> still unable to update.
I ran AVG anti-rootkit scan –> it found nothing.
I installed GMER and it did find some issues:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-02 06:30:40
Windows 6.1.7601 Service Pack 1
Running: rt60ln90.exe
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\88532e17d242
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\88532e17d242 (not active ControlSet)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}@iamoenfjakjmhaoohf 0x6A 0x61 0x6C 0x70 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FED1940E-CE1A-FD19-AF9F-8DDBE40B0834}@haookbpfakgicnjk 0x6A 0x61 0x6C 0x70 …
—- EOF - GMER 1.0.15 —-
Then I ran DDS:
Output of DDS.txt:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 7:24:24.95 on Tue 08/02/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8106.3391 [GMT 7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Windows\System32\alg.exe
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files\Cypress\TrackPad\CyCpIo.exe
C:\Program Files\Cypress\TrackPad\CyHidWin.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files (x86)\Vertex Wireless\VW100 Connection Manager\Connection Manager.exe
C:\Program Files (x86)\SugarSync\SugarSyncManager.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\explorer.exe
C:\Windows\explorer.exe
E:\EVACopy-v5.2\EVACopy.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\WUDFHost.exe
C:\Users\ER\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page =
uDefault_Page_URL = hxxp://www1.ap.dell.com/content/default.aspx?c=th&l=en&s=gen
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: SSOIEAddonBHO Class: {da5bce70-d057-4d63-943d-5f3927ec59f1} - C:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [ccleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
uRun: [VW100 Connection Manager] C:\Program Files (x86)\Vertex Wireless\VW100 Connection Manager\Connection Manager.exe
uRun: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [FAStartup]
mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
mRunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
LSP: C:\Program Files (x86)\HMA! Pro VPN\bin\ForceInterfaceLSP.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: {505DBF54-EB18-49EE-A6C0-437CC9E42642} = 61.19.245.245 61.19.245.246
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll C:\Windows\SysWOW64\guard32.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: SSOIEAddonBHO Class: {DA5BCE70-D057-4D63-943D-5F3927EC59F1} - C:\Program Files (x86)\Sensible Vision\Fast Access\x64\FAIESSO.dll
BHO-X64: SSOIEAddonBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
mRun-x64: [CyCpIo] C:\Program Files\Cypress\TrackPad\CyCpIo.exe
mRun-x64: [CyHidWin] C:\Program Files\Cypress\TrackPad\CyHidWin.exe
mRun-x64: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
mRun-x64: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
mRun-x64: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
mRun-x64: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
mRun-x64: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
mRun-x64: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun-x64: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
mRun-x64: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
mRun-x64: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
mRun-x64: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
AppInit_DLLs-X64: C:\Windows\system32\nvinitx.dll C:\Windows\system32\guard64.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\ER\AppData\Roaming\Mozilla\Firefox\Profiles\yyjp9n4x.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2011-2-22 26704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2011-3-16 37456]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2011-6-16 25960]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-6-15 55856]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2011-6-16 21616]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2011-1-7 304720]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-3-1 41552]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2011-4-5 377936]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2011-6-30 252344]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2011-6-30 41712]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2011-4-18 189440]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-18 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-18 12360]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-5-5 128384]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-6-16 98208]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-11-2 2428552]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-1 366640]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-26 2823000]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-6-15 1997416]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-31 1153368]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-6-15 689472]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-12-24 378984]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-11-30 16120]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-6-15 2656280]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2011-6-16 27760]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2011-4-14 118864]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2011-2-10 29264]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2011-6-15 176096]
R3 cyhid;Cypress Input Device;C:\Windows\System32\drivers\cyhid.sys [2011-6-15 104960]
R3 cykbfltrService;Cypress Keyboard Filter Driver;C:\Windows\System32\drivers\cykbfltr.sys [2011-6-16 13312]
R3 cymfltrService;Cypress Trackpad Filter Driver;C:\Windows\System32\drivers\cymfltr.sys [2011-6-16 62464]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-6-16 317440]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-6-16 76912]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-8-1 25912]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2011-6-16 56344]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2011-4-18 40832]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2011-6-16 8505856]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2011-4-27 84864]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-6-16 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-6-16 181248]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-6-15 155752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-14 17920]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2010-12-1 42392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-1-24 58128]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-1-24 274944]
S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2011-7-16 16776]
S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2011-7-16 9096]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\System32\drivers\facap.sys [2008-9-25 238848]
S3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-1-24 59904]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-6-16 158976]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-18 340240]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-30 149504]
S3 vwmfbus;Vertex Wireless Composite Device driver (WDM);C:\Windows\System32\drivers\vwmfbus.sys [2011-7-12 127488]
S3 vwmfdiag;Vertex Wireless Diagnostic Monitor Port Driver (WDM);C:\Windows\System32\drivers\vwmfdiag.sys [2011-7-12 128512]
S3 vwmfmdfl;~Vertex Wireless CDC Modem Filter~;C:\Windows\System32\drivers\vwmfmdfl.sys [2011-7-12 18944]
S3 vwmfmdm;Vertex Wireless CDC Modem Driver;C:\Windows\System32\drivers\vwmfmdm.sys [2011-7-12 161280]
S3 vwmfserd;Vertex Wireless Device Management Port Driver (WDM);C:\Windows\System32\drivers\vwmfserd.sys [2011-7-12 128512]
.
=============== Created Last 30 ================
.
2011-08-01 09:53:49 ——– d—–w- C:\Program Files (x86)\notepadplus
2011-08-01 03:37:05 ——– d—–w- C:\Program Files (x86)\ESET
2011-08-01 02:55:56 ——– d—–w- C:\Users\ER\AppData\Roaming\SUPERAntiSpyware.com
2011-08-01 02:55:56 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com
2011-08-01 02:55:54 ——– d—–w- C:\PROGRA~3\!SASCORE
2011-08-01 02:55:52 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2011-08-01 02:52:23 ——– d—–w- C:\PROGRAM FILES (X86) (X86)
2011-08-01 02:26:07 ——– d—–w- C:\Users\ER\AppData\Roaming\Malwarebytes
2011-08-01 02:26:04 41272 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-01 02:26:03 ——– d—–w- C:\PROGRA~3\Malwarebytes
2011-08-01 02:25:59 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-01 02:25:59 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-07-31 20:32:48 ——– d—–w- C:\Users\ER\AppData\Local\SugarSync
2011-07-31 20:30:41 ——– d—–w- C:\Program Files (x86)\SugarSync
2011-07-31 16:35:45 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-07-31 16:35:45 ——– d—–w- C:\PROGRA~3\Spybot - Search & Destroy
2011-07-31 16:15:44 ——– d—–w- C:\Users\ER\AppData\Roaming\AVG10
2011-07-31 16:15:09 ——– d—–w- C:\Windows\SysWow64\drivers\AVG
2011-07-31 16:14:50 ——– d—–w- C:\Windows\System32\drivers\AVG
2011-07-31 16:14:50 ——– d—–w- C:\PROGRA~3\AVG10
2011-07-31 16:14:40 ——– d—–w- C:\Program Files (x86)\AVG
2011-07-31 15:46:33 ——– d–h–w- C:\PROGRA~3\Common Files
2011-07-31 15:46:14 ——– d—–w- C:\PROGRA~3\MFAData
2011-07-31 15:07:26 8578896 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{9BE80B47-38DD-4BF3-80D9-84EBF20303B4}\mpengine.dll
2011-07-17 05:26:02 ——– d—–w- C:\Users\ER\AppData\Roaming\Djuggler
2011-07-17 03:58:59 ——– d—–w- C:\Program Files (x86)\Djuggler 4
2011-07-16 13:08:59 ——– d—–w- C:\Users\ER\AppData\Roaming\LibreOffice
2011-07-16 12:41:41 9096 —-a-w- C:\Windows\System32\EuGdiDrv.sys
2011-07-16 12:41:41 86408 —-a-w- C:\Windows\SysWow64\setupempdrv03.exe
2011-07-16 12:41:41 8456 —-a-w- C:\Windows\SysWow64\EuGdiDrv.sys
2011-07-16 12:41:41 2926208 —-a-w- C:\Windows\System32\BootMan.exe
2011-07-16 12:41:41 2340992 —-a-w- C:\Windows\SysWow64\BootMan.exe
2011-07-16 12:41:41 18048 —-a-w- C:\Windows\SysWow64\EuEpmGdi.dll
2011-07-16 12:41:41 16776 —-a-w- C:\Windows\System32\epmntdrv.sys
2011-07-16 12:41:41 14216 —-a-w- C:\Windows\SysWow64\epmntdrv.sys
2011-07-16 12:41:41 11264 —-a-w- C:\Windows\System32\EuEpmGdi.dll
2011-07-16 12:41:41 100232 —-a-w- C:\Windows\System32\setupempdrvx64.exe
2011-07-16 12:41:37 ——– d—–w- C:\Program Files (x86)\EASEUS
2011-07-14 05:12:55 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-14 03:50:22 ——– d—–w- C:\Program Files (x86)\HMA! Pro VPN
2011-07-14 03:22:33 ——– d—–w- C:\Users\ER\AppData\Roaming\Roxio Log Files
2011-07-14 03:22:33 ——– d—–w- C:\Users\ER\AppData\Roaming\Macrovision
2011-07-13 20:37:35 8873296 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-13 02:39:07 175616 ——w- C:\Windows\SysWow64\unrar.dll
2011-07-13 02:39:05 232448 ——w- C:\Windows\SysWow64\mp3fhg.acm
2011-07-13 02:39:05 151552 ——w- C:\Windows\SysWow64\ac3acm.acm
2011-07-13 02:39:04 73216 ——w- C:\Windows\SysWow64\ff_vfw.dll
2011-07-13 02:39:04 644608 ——w- C:\Windows\SysWow64\xvidcore.dll
2011-07-13 02:39:04 243200 ——w- C:\Windows\SysWow64\xvidvfw.dll
2011-07-13 02:39:04 237568 ——w- C:\Windows\SysWow64\yv12vfw.dll
2011-07-13 02:39:02 ——– d—–w- C:\Program Files (x86)\K-Lite Codec Pack
2011-07-12 22:29:43 ——– d—–w- C:\Program Files (x86)\LibreOffice 3
2011-07-12 15:16:47 ——– d—–w- C:\uTorrent
2011-07-12 15:15:32 ——– d—–w- C:\Program Files (x86)\uTorrent
2011-07-12 15:14:49 ——– d—–w- C:\Users\ER\AppData\Roaming\uTorrent
2011-07-12 15:14:49 ——– d—–w- C:\Users\ER\AppData\Local\uTorrent
2011-07-12 14:14:12 ——– d—–w- C:\Program Files\Bulk Rename Utility
2011-07-12 06:46:01 ——– d—–w- C:\Program Files\CCleaner
2011-07-12 04:21:19 ——– d—–w- C:\Users\ER\AppData\Roaming\Abine
2011-07-12 03:14:07 ——– d—–w- C:\Users\ER\AppData\Local\Connectify
2011-07-12 03:13:34 ——– d—–w- C:\Program Files (x86)\Connectify
2011-07-12 02:44:08 18944 —-a-w- C:\Windows\System32\drivers\vwmfmdfl.sys
2011-07-12 02:44:08 161280 —-a-w- C:\Windows\System32\drivers\vwmfmdm.sys
2011-07-12 02:44:08 15872 —-a-w- C:\Windows\System32\drivers\vwmfwhnt.sys
2011-07-12 02:44:08 15872 —-a-w- C:\Windows\System32\drivers\vwmfwh.sys
2011-07-12 02:44:08 15360 —-a-w- C:\Windows\System32\drivers\vwmfcmnt.sys
2011-07-12 02:44:08 15360 —-a-w- C:\Windows\System32\drivers\vwmfcm.sys
2011-07-12 02:44:08 128512 —-a-w- C:\Windows\System32\drivers\vwmfserd.sys
2011-07-12 02:44:08 128512 —-a-w- C:\Windows\System32\drivers\vwmfdiag.sys
2011-07-12 02:44:08 127488 —-a-w- C:\Windows\System32\drivers\vwmfbus.sys
2011-07-12 02:44:08 ——– d—–w- C:\Program Files\Vertex Wireless
2011-07-12 02:43:47 ——– d—–w- C:\Program Files (x86)\Vertex Wireless
2011-07-12 02:43:45 ——– d—–w- C:\PROGRA~3\Vertex Wireless
2011-07-12 02:02:24 142336 —-a-w- C:\Windows\System32\poqexec.exe
2011-07-12 02:02:24 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe
2011-07-12 01:58:52 ——– d—–w- C:\Users\ER\AppData\Local\Diagnostics
2011-07-12 01:16:10 5562240 —-a-w- C:\Windows\System32\ntoskrnl.exe
2011-07-11 18:19:17 ——– d—–w- C:\Users\ER\AppData\Local\ArcSoft
2011-07-11 18:18:31 ——– d—–w- C:\Program Files\COMODO
2011-07-11 18:17:26 ——– d—–w- C:\PROGRA~3\Comodo
2011-07-11 18:15:09 ——– d—–w- C:\PROGRA~3\Comodo Downloader
2011-07-11 18:03:50 601424 ——w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{13D4BD41-A757-4681-96A5-BD38B6E20B81}\gapaengine.dll
2011-07-11 18:01:39 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client
2011-07-11 18:01:36 ——– d—–w- C:\Program Files\Microsoft Security Client
2011-07-11 10:07:45 ——– d—–w- C:\Users\ER\My Backup Files
2011-07-11 09:00:01 ——– d—–w- C:\PROGRA~3\PCDr
2011-07-11 08:58:34 ——– d-sh–w- C:\System Recovery
2011-07-11 08:57:39 ——– d—–w- C:\Users\ER\AppData\Local\Dell
2011-07-11 08:57:05 ——– d—–w- C:\Users\ER\AppData\Roaming\Dell
2011-07-11 08:57:02 ——– d—–w- C:\Users\ER\AppData\Roaming\Dell Touch Zone
2011-07-11 08:56:31 ——– d—–w- C:\Users\ER\AppData\Local\VirtualStore
2011-07-11 08:56:27 ——– d—–w- C:\Users\ER\AppData\Local\SoftThinks
.
==================== Find3M ====================
.
2011-06-30 02:38:10 41712 —-a-w- C:\Windows\System32\drivers\cmdhlp.sys
2011-06-30 02:38:08 252344 —-a-w- C:\Windows\System32\drivers\cmdGuard.sys
2011-06-30 02:38:08 16016 —-a-w- C:\Windows\System32\drivers\cmderd.sys
2011-06-30 02:37:26 363560 —-a-w- C:\Windows\System32\guard64.dll
2011-06-30 02:37:26 285256 ——w- C:\Windows\SysWow64\guard32.dll
2011-06-15 17:32:14 91648 —-a-w- C:\Windows\System32\SetIEInstalledDate.exe
2011-06-15 15:53:20 521448 —-a-w- C:\Windows\System32\deployJava1.dll
2011-06-11 03:07:25 3137536 —-a-w- C:\Windows\System32\win32k.sys
2011-06-03 06:57:45 362496 —-a-w- C:\Windows\System32\wow64win.dll
2011-06-03 06:57:45 243200 —-a-w- C:\Windows\System32\wow64.dll
2011-06-03 06:57:45 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2011-06-03 06:57:44 214528 —-a-w- C:\Windows\System32\winsrv.dll
2011-06-03 06:57:38 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2011-06-03 06:56:38 421888 —-a-w- C:\Windows\System32\KernelBase.dll
2011-06-03 06:53:33 338944 —-a-w- C:\Windows\System32\conhost.exe
2011-06-03 06:00:53 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-06-03 05:57:52 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2011-06-03 05:57:33 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2011-06-03 05:56:12 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2011-06-03 05:56:11 272384 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2011-06-03 03:53:31 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2011-06-03 03:53:31 2048 —-a-w- C:\Windows\SysWow64\user.exe
2011-06-03 03:48:32 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-06-03 03:48:31 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-06-03 03:48:31 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-03 03:48:31 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-05-24 12:14:10 270720 ——w- C:\Windows\System32\MpSigStub.exe
2011-05-24 11:42:55 404480 —-a-w- C:\Windows\System32\umpnpmgr.dll
2011-05-24 10:40:05 64512 —-a-w- C:\Windows\SysWow64\devobj.dll
2011-05-24 10:40:05 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll
2011-05-24 10:39:38 145920 —-a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-05-24 10:37:54 252928 —-a-w- C:\Windows\SysWow64\drvinst.exe
2011-05-04 05:25:03 2315776 —-a-w- C:\Windows\System32\tquery.dll
2011-05-04 05:22:25 778752 —-a-w- C:\Windows\System32\mssvp.dll
2011-05-04 05:22:25 2223616 —-a-w- C:\Windows\System32\mssrch.dll
2011-05-04 05:22:24 75264 —-a-w- C:\Windows\System32\msscntrs.dll
2011-05-04 05:22:24 491520 —-a-w- C:\Windows\System32\mssph.dll
2011-05-04 05:22:24 288256 —-a-w- C:\Windows\System32\mssphtb.dll
2011-05-04 05:19:28 591872 —-a-w- C:\Windows\System32\SearchIndexer.exe
2011-05-04 05:19:28 249856 —-a-w- C:\Windows\System32\SearchProtocolHost.exe
2011-05-04 05:19:28 113664 —-a-w- C:\Windows\System32\SearchFilterHost.exe
2011-05-04 04:34:43 1549312 —-a-w- C:\Windows\SysWow64\tquery.dll
2011-05-04 04:32:02 666624 —-a-w- C:\Windows\SysWow64\mssvp.dll
2011-05-04 04:32:01 337408 —-a-w- C:\Windows\SysWow64\mssph.dll
2011-05-04 04:32:01 197120 —-a-w- C:\Windows\SysWow64\mssphtb.dll
2011-05-04 04:32:01 1401344 —-a-w- C:\Windows\SysWow64\mssrch.dll
2011-05-04 04:32:00 59392 —-a-w- C:\Windows\SysWow64\msscntrs.dll
2011-05-04 04:28:31 86528 —-a-w- C:\Windows\SysWow64\SearchFilterHost.exe
2011-05-04 04:28:31 427520 —-a-w- C:\Windows\SysWow64\SearchIndexer.exe
2011-05-04 04:28:31 164352 —-a-w- C:\Windows\SysWow64\SearchProtocolHost.exe
.
============= FINISH: 7:25:40.78 ===============
Output of attach.txt:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 7/11/2011 3:52:59 PM
System Uptime: 8/1/2011 10:26:42 AM (21 hours ago)
.
Motherboard: Dell Inc. | | 060G42
Processor: Intel® Core™ i7-2620M CPU @ 2.70GHz | CPU | 2701/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 88 GiB total, 53.711 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 596 GiB total, 471.072 GiB free.
G: is Removable
W: is FIXED (NTFS) - 234 GiB total, 60.25 GiB free.
Y: is FIXED (NTFS) - 15 GiB total, 7.107 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: facap, FastAccess Video Capture
Device ID: ROOT\IMAGE\0000
Manufacturer: Sensible Vision
Name: facap, FastAccess Video Capture
PNP Device ID: ROOT\IMAGE\0000
Service: FACAP
.
Class GUID: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Description: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Adapter
Device ID: USB\VID_8086&PID_0189\6&3023DF2C&0&5
Manufacturer: Intel Corporation
Name: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Adapter
PNP Device ID: USB\VID_8086&PID_0189\6&3023DF2C&0&5
Service: BTHUSB
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
µTorrent
AccelerometerP11
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X MUI
Advanced Audio FX Engine
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Webcam Central
Djuggler 4.0.7.447
EASEUS Partition Master 8.0.1 Home Edition
ESET Online Scanner v3
FileZilla Client 3.5.0
HMA! Pro VPN 2.6.8
Intel® Control Center
Intel® Management Engine Components
Intel® Processor Graphics
Intel® Wireless Display
Java Auto Updater
Java™ 6 Update 26
K-Lite Mega Codec Pack 7.2.0
LibreOffice 3.3
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft Office 2010
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 5.0 (x86 en-US)
NVIDIA Stereoscopic 3D Driver
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Skype™ 4.2
Spybot - Search & Destroy
SugarSync Manager
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Visual Studio 2008 x64 Redistributables
VW100 Connection Manager
.
==== Event Viewer Messages From Past Week ========
.
8/2/2011 6:52:17 AM, Error: Microsoft-Windows-SharedAccess_NAT [31004] - The DNS proxy agent was unable to allocate 0 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
8/2/2011 6:17:04 AM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
8/1/2011 9:59:35 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:59:35 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:59:28 AM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
8/1/2011 9:59:24 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
8/1/2011 9:59:24 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
8/1/2011 9:59:19 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/1/2011 9:59:14 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
8/1/2011 9:59:09 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 cmdGuard discache MpFilter SASDIFSV SASKUTIL spldr Wanarpv6
8/1/2011 9:57:44 AM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
8/1/2011 9:56:05 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
8/1/2011 9:54:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
8/1/2011 9:54:32 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx64 Avgmfx64 Avgtdia cmdGuard cmdHlp DfsC discache inspect MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf ws2ifsl
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 9:54:32 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/1/2011 3:12:04 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/31/2011 9:55:14 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
7/31/2011 9:55:14 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/31/2011 9:55:14 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
7/31/2011 9:55:14 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
7/31/2011 9:55:09 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
7/31/2011 9:55:09 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
7/31/2011 9:55:02 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
7/31/2011 11:17:19 PM, Error: Service Control Manager [7034] - The Bluetooth Media Service service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 11:17:08 PM, Error: Service Control Manager [7034] - The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 11:16:55 PM, Error: Service Control Manager [7034] - The Bluetooth Device Monitor service terminated unexpectedly. It has done this 1 time(s).
7/31/2011 10:21:34 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.109.768.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7104.0 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
.
==== End Of File ===========================
Any help would be very much appreciated,
Thanks,
Ed