This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet Server Not Found.

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

All my connections on all the other computers work completely fine, this one goes out and says it's online and gives me blank pages with "Server Not Found" and randomly works again.

I tried everything, here's the log.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:23:27 PM, on 8/8/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\AIM\aim.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Auto (HPAuto) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RoxioNow Service - Roxio - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 10077 bytes
Hi Riak,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I'd like to see a different log.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Here's the report, again like I said, all my other computers on the network work fine with the internet, I tried re-establishing the wires and resetting the system, but it don't work correctly. It goes out once in awhile and its this computer that only does it. I checked everything. . DDS (Ver_2011-06-23.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 16:13:16 on 2011-08-11 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.1884 [GMT -7:00] . AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\PROGRA~2\AVG\AVG10\avgchsva.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\atieclxx.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe C:\Program Files (x86)\PDF Complete\pdfsvc.exe C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\Explorer.EXE C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\AVG\AVG10\avgnsa.exe C:\Program Files (x86)\AVG\AVG10\avgemca.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files (x86)\AIM\aim.exe C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe C:\Program Files (x86)\Giraffic\Giraffic.exe C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\explorer.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\servicing\TrustedInstaller.exe C:\PROGRA~2\AVG\AVG10\avgrsa.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Program Files (x86)\AVG\AVG10\avgscana.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll mWinlogon: Userinit=userinit.exe BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [] mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{84F2469B-6A0B-413A-8E0F-2978AFA9E09C} : DhcpNameServer = 192.168.2.1 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: AVG Security Toolbar BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll TB-X64: AVG Security Toolbar: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll mRun-x64: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun-x64: [(Default)] mRun-x64: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\hb2d60hp.default\ FF - prefs.js: browser.startup.homepage - google.com FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . —- FIREFOX POLICIES —- FF - user.js: general.useragent.extra.brc - FF - user.js: network.protocol-handler.warn-external.dnupdate - false ============= SERVICES / DRIVERS =============== . R0 amd_sata;amd_sata;C:\Windows\system32\drivers\amd_sata.sys –> C:\Windows\system32\drivers\amd_sata.sys [?] R0 amd_xata;amd_xata;C:\Windows\system32\drivers\amd_xata.sys –> C:\Windows\system32\drivers\amd_xata.sys [?] R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys –> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?] R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664] R2 Giraffic;Giraffic Video Accelerator;C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe –service –> C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe –service [?] R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-16 682040] R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-1-25 92216] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-7 366640] R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568] R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-5-1 1127448] R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-11-26 399344] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-31 1153368] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys –> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys –> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192su.sys –> C:\Windows\system32\DRIVERS\RTL8192su.sys [?] R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys –> C:\Windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys –> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys –> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys –> C:\Windows\system32\DRIVERS\Sftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768] R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\drivers\usbfilter.sys –> C:\Windows\system32\drivers\usbfilter.sys [?] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-7-31 1025352] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-8-9 1431888] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2011-08-11 06:39:00 ——– d-sh–w- C:\Windows\System32\%APPDATA% 2011-08-11 04:16:54 1923968 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-08-11 04:14:02 5561216 —-a-w- C:\Windows\System32\ntoskrnl.exe 2011-08-11 04:14:02 3967872 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-08-11 04:14:02 3912576 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-08-10 06:51:31 ——– d—–w- C:\ProgramData\Giraffic 2011-08-10 06:51:31 ——– d—–w- C:\Program Files (x86)\Giraffic 2011-08-10 06:51:27 ——– d—–w- C:\Program Files (x86)\Veoh Networks 2011-08-10 05:16:55 ——– d—–w- C:\Users\Admin\Autodesk 2011-08-10 01:03:58 ——– d—–w- C:\ProgramData\boost_interprocess 2011-08-10 00:38:31 ——– d—–w- C:\Program Files\NVIDIA Corporation 2011-08-10 00:38:31 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation 2011-08-10 00:28:53 ——– d—–w- C:\Program Files\Common Files\Softimage 2011-08-10 00:28:53 ——– d—–w- C:\Program Files (x86)\Common Files\Softimage 2011-08-10 00:28:53 ——– d—–w- C:\Program Files (x86)\Common Files\Autodesk Shared 2011-08-10 00:28:27 ——– d—–w- C:\Program Files\Common Files\Alias Shared 2011-08-10 00:27:57 ——– d—–w- C:\Program Files\Common Files\Macrovision Shared 2011-08-10 00:27:38 ——– d—–w- C:\Program Files\Common Files\Autodesk Shared 2011-08-10 00:25:07 ——– d—–w- C:\Program Files\Autodesk 2011-08-10 00:22:59 4992520 —-a-w- C:\Windows\System32\D3DX9_39.dll 2011-08-10 00:15:43 ——– d—–w- C:\Users\Admin\AppData\Roaming\Autodesk 2011-08-08 23:17:30 388096 —-a-r- C:\Users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-08-08 23:17:30 ——– d—–w- C:\Program Files (x86)\Trend Micro 2011-08-08 06:50:57 23112 —-a-w- C:\Windows\System32\drivers\hitmanpro35.sys 2011-08-08 06:48:28 ——– d—–w- C:\Users\Admin\AppData\Roaming\Malwarebytes 2011-08-08 06:48:26 41272 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-08-08 06:48:25 ——– d—–w- C:\ProgramData\Malwarebytes 2011-08-08 06:48:22 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-08-08 06:48:22 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-08-08 06:47:47 ——– d—–w- C:\Program Files\Hitman Pro 3.5 2011-08-08 06:47:25 ——– d—–w- C:\ProgramData\Hitman Pro 2011-08-07 20:36:55 ——– d—–w- C:\Users\Admin\AppData\Local\AOL 2011-08-07 20:36:55 ——– d—–w- C:\Users\Admin\AppData\Local\AIM 2011-08-07 20:36:49 ——– d—–w- C:\ProgramData\AIM 2011-08-07 20:36:47 ——– d—–w- C:\Program Files (x86)\AIM 2011-08-07 20:36:46 ——– d—–w- C:\Program Files (x86)\Common Files\Software Update Utility 2011-08-07 20:36:45 ——– d—–w- C:\Program Files (x86)\Common Files\AOL 2011-08-03 17:55:02 902656 —-a-w- C:\Windows\System32\d2d1.dll 2011-08-03 17:55:02 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll 2011-08-03 17:55:02 1544192 —-a-w- C:\Windows\System32\DWrite.dll 2011-08-03 17:55:02 1139200 —-a-w- C:\Windows\System32\FntCache.dll 2011-08-03 17:55:02 1076736 —-a-w- C:\Windows\SysWow64\DWrite.dll 2011-08-03 06:06:23 ——– d—–w- C:\Users\Admin\AppData\Local\CrashDumps 2011-08-03 03:00:54 ——– d—–w- C:\Users\Admin\AppData\Local\Diagnostics 2011-08-01 11:15:41 748336 —-a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2011-08-01 10:20:36 642944 —-a-w- C:\Windows\System32\winload.efi 2011-08-01 10:20:36 605552 —-a-w- C:\Windows\System32\winload.exe 2011-08-01 10:20:36 566208 —-a-w- C:\Windows\System32\winresume.efi 2011-08-01 10:20:36 518672 —-a-w- C:\Windows\System32\winresume.exe 2011-08-01 10:20:36 19328 —-a-w- C:\Windows\System32\kd1394.dll 2011-08-01 10:20:36 17792 —-a-w- C:\Windows\System32\kdcom.dll 2011-08-01 10:20:35 20352 —-a-w- C:\Windows\System32\kdusb.dll 2011-08-01 10:20:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-01 10:20:26 861696 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-01 10:20:16 3137536 —-a-w- C:\Windows\System32\win32k.sys 2011-08-01 10:13:14 ——– d-sh–w- C:\Windows\SysWow64\%APPDATA% 2011-08-01 10:11:36 ——– d—–w- C:\Program Files (x86)\MSXML 4.0 2011-08-01 05:48:34 ——– d—–w- C:\Users\Admin\riotsGamesLogs 2011-08-01 05:15:07 ——– d—–w- C:\Users\Admin\AppData\Roaming\LolClient 2011-08-01 03:31:53 27520 —-a-w- C:\Windows\System32\drivers\Diskdump.sys 2011-08-01 03:30:06 197120 —-a-w- C:\Windows\System32\d3d10_1.dll 2011-08-01 03:30:06 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2011-08-01 03:30:03 31232 —-a-w- C:\Windows\SysWow64\prevhost.exe 2011-08-01 03:30:03 31232 —-a-w- C:\Windows\System32\prevhost.exe 2011-08-01 02:43:11 ——– d—–w- C:\Users\Admin\AppData\Roaming\HP Support Assistant 2011-08-01 01:16:59 ——– d—–w- C:\ProgramData\VirtualizedApplications 2011-08-01 01:09:16 68616 —-a-w- C:\Windows\SysWow64\XAPOFX1_1.dll 2011-08-01 01:09:16 509448 —-a-w- C:\Windows\SysWow64\XAudio2_2.dll 2011-08-01 01:09:15 467984 —-a-w- C:\Windows\SysWow64\d3dx10_39.dll 2011-08-01 01:09:15 3851784 —-a-w- C:\Windows\SysWow64\D3DX9_39.dll 2011-08-01 01:09:15 1493528 —-a-w- C:\Windows\SysWow64\D3DCompiler_39.dll 2011-08-01 01:06:33 ——– d—–w- C:\Riot Games 2011-07-31 23:05:43 ——– d—–w- C:\Program Files (x86)\Microsoft Application Virtualization Client 2011-07-31 22:53:51 ——– d—–w- C:\Program Files (x86)\Pando Networks 2011-07-31 21:15:11 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-07-31 21:05:17 ——– d—–w- C:\Users\Admin\AppData\Local\AVG Security Toolbar 2011-07-31 20:59:00 ——– d—–w- C:\ProgramData\Spybot - Search & Destroy 2011-07-31 20:59:00 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy 2011-07-31 20:57:10 267776 —-a-w- C:\Windows\System32\FXSCOVER.exe 2011-07-31 20:57:08 715776 —-a-w- C:\Windows\System32\kerberos.dll 2011-07-31 20:57:08 542208 —-a-w- C:\Windows\SysWow64\kerberos.dll 2011-07-31 20:57:03 961024 —-a-w- C:\Windows\System32\CPFilters.dll 2011-07-31 20:57:03 850944 —-a-w- C:\Windows\SysWow64\sbe.dll 2011-07-31 20:57:03 723968 —-a-w- C:\Windows\System32\EncDec.dll 2011-07-31 20:57:03 642048 —-a-w- C:\Windows\SysWow64\CPFilters.dll 2011-07-31 20:57:03 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll 2011-07-31 20:57:03 259072 —-a-w- C:\Windows\System32\mpg2splt.ax 2011-07-31 20:57:03 1118720 —-a-w- C:\Windows\System32\sbe.dll 2011-07-31 20:57:02 199680 —-a-w- C:\Windows\SysWow64\mpg2splt.ax 2011-07-31 20:57:00 499200 —-a-w- C:\Windows\System32\drivers\afd.sys 2011-07-31 20:56:29 142336 —-a-w- C:\Windows\System32\poqexec.exe 2011-07-31 20:56:29 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe 2011-07-31 20:56:28 158208 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-07-31 20:56:27 128000 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-07-31 20:56:26 976896 —-a-w- C:\Windows\System32\inetcomm.dll 2011-07-31 20:56:26 741376 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-07-31 20:46:45 64512 —-a-w- C:\Windows\SysWow64\devobj.dll 2011-07-31 20:46:45 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll 2011-07-31 20:46:45 404480 —-a-w- C:\Windows\System32\umpnpmgr.dll 2011-07-31 20:46:45 252928 —-a-w- C:\Windows\SysWow64\drvinst.exe 2011-07-31 20:46:45 145920 —-a-w- C:\Windows\SysWow64\cfgmgr32.dll 2011-07-31 20:46:03 90624 —-a-w- C:\Windows\System32\drivers\bowser.sys 2011-07-31 20:45:41 ——– d—–w- C:\Windows\SysWow64\Wat 2011-07-31 20:45:41 ——– d—–w- C:\Windows\System32\Wat 2011-07-31 20:41:50 ——– d—–w- C:\Users\Admin\AppData\Roaming\AVG10 2011-07-31 20:40:34 ——– d—–w- C:\Windows\SysWow64\drivers\AVG 2011-07-31 20:39:27 ——– d—–w- C:\Windows\System32\drivers\AVG 2011-07-31 20:31:20 ——– d—–w- C:\Program Files (x86)\Belkin 2011-07-31 20:30:54 ——– d—–w- C:\Windows\{26F3D17D-4FF9-46D5-9255-A1F9FF6BD7E4} 2011-07-31 20:15:07 ——– d—–w- C:\ProgramData\AVG Security Toolbar 2011-07-31 20:14:39 ——– d—–w- C:\ProgramData\AVG10 2011-07-31 20:13:46 ——– d—–w- C:\Program Files (x86)\AVG 2011-07-31 19:46:07 ——– d—–w- C:\Users\Admin\AppData\Local\WinZip 2011-07-31 19:43:08 ——– d—–w- C:\Users\Admin\AppData\Roaming\Trillian 2011-07-31 19:41:52 ——– d—–w- C:\Program Files (x86)\StartNow Toolbar 2011-07-31 19:41:41 ——– d—–w- C:\Program Files (x86)\JDownloader 2011-07-31 19:38:02 ——– d—–r- C:\Program Files (x86)\Skype 2011-07-31 19:34:00 ——– d—–w- C:\Users\Admin\AppData\Roaming\HpUpdate 2011-07-31 19:33:59 ——– d—–w- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite 2011-07-31 05:36:41 ——– d—–w- C:\Program Files (x86)\OpenOffice.org 3 2011-07-31 05:36:23 ——– d—–w- C:\ProgramData\DAEMON Tools Lite 2011-07-31 04:44:21 ——– d—–w- C:\ProgramData\Blio 2011-07-31 04:44:06 ——– d—–w- C:\Users\Admin\AppData\Roaming\Blio 2011-07-31 03:48:38 ——– d–h–w- C:\ProgramData\Common Files 2011-07-31 03:48:27 ——– d—–w- C:\ProgramData\MFAData 2011-07-31 03:34:34 ——– d—–w- C:\ProgramData\regid.1986-12.com.adobe 2011-07-31 03:32:12 ——– d—–w- C:\Users\Admin\AppData\Local\Adobe 2011-07-31 03:31:32 ——– d—–w- C:\Program Files (x86)\Photoshop 2011-07-31 03:26:45 ——– d—–w- C:\Program Files (x86)\uTorrent 2011-07-31 03:26:22 ——– d—–w- C:\Users\Admin\AppData\Roaming\uTorrent 2011-07-31 03:26:22 ——– d—–w- C:\Users\Admin\AppData\Local\uTorrent 2011-07-30 18:26:36 ——– d—–w- C:\Users\Admin\AppData\Local\Apple Computer 2011-07-30 18:26:32 34152 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2011-07-30 18:26:32 126312 —-a-w- C:\Windows\System32\GEARAspi64.dll 2011-07-30 18:26:32 107368 —-a-w- C:\Windows\SysWow64\GEARAspi.dll 2011-07-30 18:26:23 ——– d—–w- C:\Program Files\iPod 2011-07-30 18:26:22 ——– d—–w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2011-07-30 18:26:22 ——– d—–w- C:\Program Files\iTunes 2011-07-30 18:26:22 ——– d—–w- C:\Program Files (x86)\iTunes 2011-07-30 18:25:57 ——– d—–w- C:\Users\Admin\AppData\Local\Apple 2011-07-30 18:25:42 ——– d—–w- C:\Program Files\Bonjour 2011-07-30 18:25:42 ——– d—–w- C:\Program Files (x86)\Bonjour 2011-07-30 18:25:11 ——– d—–w- C:\Program Files\CCleaner 2011-07-30 18:23:03 ——– d—–w- C:\Users\Admin\AppData\Local\Mozilla 2011-07-30 17:35:07 ——– d—–w- C:\Users\Admin\hpremote 2011-07-30 17:26:23 ——– d—–w- C:\Users\Admin\AppData\Local\ATI 2011-07-30 17:25:23 ——– d—–w- C:\Users\Admin\AppData\Local\PDFC 2011-07-30 17:24:54 ——– d—–w- C:\Users\Admin\AppData\Local\RemEngine 2011-07-30 17:21:19 ——– d—–w- C:\Users\Admin\AppData\Local\VirtualStore . ==================== Find3M ==================== . 2011-07-22 05:42:23 2303488 —-a-w- C:\Windows\System32\jscript9.dll 2011-07-22 05:36:16 1389056 —-a-w- C:\Windows\System32\wininet.dll 2011-07-22 05:32:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-07-22 02:54:43 1797632 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-07-22 02:48:26 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-07-22 02:44:36 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-07-16 05:41:50 362496 —-a-w- C:\Windows\System32\wow64win.dll 2011-07-16 05:41:49 243200 —-a-w- C:\Windows\System32\wow64.dll 2011-07-16 05:41:49 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2011-07-16 05:39:10 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2011-07-16 05:37:12 421888 —-a-w- C:\Windows\System32\KernelBase.dll 2011-07-16 04:29:19 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2011-07-16 04:26:00 44032 —-a-w- C:\Windows\apppatch\acwow64.dll 2011-07-16 04:25:37 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2011-07-16 04:24:23 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2011-07-16 04:24:22 272384 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2011-07-16 02:21:44 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2011-07-16 02:21:41 2048 —-a-w- C:\Windows\SysWow64\user.exe 2011-07-16 02:17:19 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17:19 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17:19 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17:19 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2011-07-12 18:34:00 96104 —-a-w- C:\Windows\System32\dns-sd.exe 2011-07-12 18:34:00 85864 —-a-w- C:\Windows\System32\dnssd.dll 2011-07-12 18:34:00 61288 —-a-w- C:\Windows\System32\jdns_sd.dll 2011-07-12 18:34:00 212840 —-a-w- C:\Windows\System32\dnssdX.dll 2011-07-12 18:20:54 83816 —-a-w- C:\Windows\SysWow64\dns-sd.exe 2011-07-12 18:20:54 73064 —-a-w- C:\Windows\SysWow64\dnssd.dll 2011-07-12 18:20:54 50536 —-a-w- C:\Windows\SysWow64\jdns_sd.dll 2011-07-12 18:20:54 178536 —-a-w- C:\Windows\SysWow64\dnssdX.dll 2011-07-09 02:46:28 288768 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-07-06 01:37:00 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2011-07-06 01:37:00 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2011-06-24 05:34:53 214528 —-a-w- C:\Windows\System32\winsrv.dll 2011-06-24 05:25:49 338432 —-a-w- C:\Windows\System32\conhost.exe 2011-06-15 10:02:23 212992 —-a-w- C:\Windows\System32\odbctrac.dll 2011-06-15 10:02:23 163840 —-a-w- C:\Windows\System32\odbccp32.dll 2011-06-15 10:02:23 106496 —-a-w- C:\Windows\System32\odbccu32.dll 2011-06-15 10:02:23 106496 —-a-w- C:\Windows\System32\odbccr32.dll 2011-06-15 08:55:19 86016 —-a-w- C:\Windows\SysWow64\odbccu32.dll 2011-06-15 08:55:19 81920 —-a-w- C:\Windows\SysWow64\odbccr32.dll 2011-06-15 08:55:19 319488 —-a-w- C:\Windows\SysWow64\odbcjt32.dll 2011-06-15 08:55:19 163840 —-a-w- C:\Windows\SysWow64\odbctrac.dll 2011-06-15 08:55:19 122880 —-a-w- C:\Windows\SysWow64\odbccp32.dll . ============= FINISH: 16:14:21.68 ===============

Attachments:

Riak,

µTorrent
You have µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm


I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

One issue you are having… though it might not be all of the time… is that your computer has been assigned the same IP address as another computer on your network.

Let's try this:

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I had a problem after the text log was opened, It said my firefox and other programs were "registry marked for deletion" so I had to restart. Here's the log, thanks. ComboFix 11-08-11.06 - Admin 08/11/2011 21:47:06.3.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2181 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Veoh Networks\VeohWebPlayer\ConduitInstaller_veoh.exe . . ((((((((((((((((((((((((( Files Created from 2011-07-12 to 2011-08-12 ))))))))))))))))))))))))))))))) . . 2011-08-12 04:50 . 2011-08-12 04:50 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-08-11 06:39 . 2011-08-11 06:39 ——– d-sh–w- c:\windows\system32\%APPDATA% 2011-08-11 04:16 . 2011-06-21 06:34 1923968 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-08-11 04:14 . 2011-06-23 05:43 5561216 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-08-11 04:14 . 2011-06-23 04:33 3967872 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-08-11 04:14 . 2011-06-23 04:33 3912576 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-08-10 06:51 . 2011-08-12 04:51 ——– d—–w- c:\program files (x86)\Giraffic 2011-08-10 06:51 . 2011-08-10 06:51 ——– d—–w- c:\programdata\Giraffic 2011-08-10 06:51 . 2011-08-10 06:51 ——– d—–w- c:\program files (x86)\Veoh Networks 2011-08-10 01:03 . 2011-08-11 04:05 ——– d—–w- c:\programdata\boost_interprocess 2011-08-10 00:59 . 2011-08-10 00:59 ——– d—–w- c:\programdata\FLEXnet 2011-08-10 00:38 . 2011-08-10 00:38 ——– d—–w- c:\program files\NVIDIA Corporation 2011-08-10 00:38 . 2011-08-10 00:38 ——– d—–w- c:\program files (x86)\NVIDIA Corporation 2011-08-10 00:28 . 2011-08-10 00:29 ——– d—–w- c:\program files\Common Files\Softimage 2011-08-10 00:28 . 2011-08-10 00:29 ——– d—–w- c:\program files (x86)\Common Files\Softimage 2011-08-10 00:28 . 2011-08-10 00:28 ——– d—–w- c:\program files (x86)\Common Files\Autodesk Shared 2011-08-10 00:28 . 2011-08-10 00:28 ——– d—–w- c:\program files\Common Files\Alias Shared 2011-08-10 00:27 . 2011-08-10 00:27 ——– d—–w- c:\program files\Common Files\Macrovision Shared 2011-08-10 00:27 . 2011-08-10 00:27 ——– d—–w- c:\program files\Common Files\Autodesk Shared 2011-08-10 00:25 . 2011-08-10 00:37 ——– d—–w- c:\program files\Autodesk 2011-08-10 00:22 . 2008-07-10 18:00 4992520 —-a-w- c:\windows\system32\D3DX9_39.dll 2011-08-10 00:15 . 2011-08-10 05:32 ——– d—–w- c:\programdata\Autodesk 2011-08-08 23:17 . 2011-08-08 23:17 ——– d—–w- c:\program files (x86)\Trend Micro 2011-08-08 06:50 . 2011-08-08 06:50 23112 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys 2011-08-08 06:48 . 2011-07-07 02:52 41272 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-08-08 06:48 . 2011-08-08 06:48 ——– d—–w- c:\programdata\Malwarebytes 2011-08-08 06:48 . 2011-08-08 06:48 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-08-08 06:48 . 2011-07-07 02:52 25912 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-08 06:47 . 2011-08-08 06:47 ——– d—–w- c:\program files\Hitman Pro 3.5 2011-08-08 06:47 . 2011-08-08 06:50 ——– d—–w- c:\programdata\Hitman Pro 2011-08-07 20:41 . 2011-08-07 20:41 ——– d—–w- c:\program files (x86)\Safari 2011-08-07 20:39 . 2011-08-07 20:39 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-08-07 20:39 . 2011-08-07 20:39 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-08-07 20:39 . 2011-08-07 20:39 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-08-07 20:39 . 2011-08-07 20:39 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-08-07 20:39 . 2011-08-07 20:39 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-08-07 20:39 . 2011-08-07 20:39 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-08-07 20:39 . 2011-08-07 20:39 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-08-07 20:39 . 2011-08-07 20:39 ——– d—–w- c:\program files (x86)\QuickTime 2011-08-07 20:36 . 2011-08-07 20:36 ——– d—–w- c:\programdata\AIM 2011-08-07 20:36 . 2011-08-07 20:36 ——– d—–w- c:\program files (x86)\AIM 2011-08-07 20:36 . 2011-08-07 20:36 ——– d—–w- c:\program files (x86)\Common Files\Software Update Utility 2011-08-07 20:36 . 2011-08-07 20:36 ——– d—–w- c:\program files (x86)\Common Files\AOL 2011-08-03 17:55 . 2011-02-19 12:05 1139200 —-a-w- c:\windows\system32\FntCache.dll 2011-08-03 17:55 . 2011-02-19 12:04 1544192 —-a-w- c:\windows\system32\DWrite.dll 2011-08-03 17:55 . 2011-02-19 12:04 902656 —-a-w- c:\windows\system32\d2d1.dll 2011-08-03 17:55 . 2011-02-19 06:30 1076736 —-a-w- c:\windows\SysWow64\DWrite.dll 2011-08-03 17:55 . 2011-02-19 06:30 739840 —-a-w- c:\windows\SysWow64\d2d1.dll 2011-08-01 11:15 . 2011-08-01 11:15 748336 —-a-w- c:\program files (x86)\Internet Explorer\iexplore.exe 2011-08-01 10:20 . 2011-02-05 17:10 642944 —-a-w- c:\windows\system32\winload.efi 2011-08-01 10:20 . 2011-02-05 17:10 19328 —-a-w- c:\windows\system32\kd1394.dll 2011-08-01 10:20 . 2011-02-05 17:10 17792 —-a-w- c:\windows\system32\kdcom.dll 2011-08-01 10:20 . 2011-02-05 17:06 605552 —-a-w- c:\windows\system32\winload.exe 2011-08-01 10:20 . 2011-02-05 17:06 566208 —-a-w- c:\windows\system32\winresume.efi 2011-08-01 10:20 . 2011-02-05 17:06 518672 —-a-w- c:\windows\system32\winresume.exe 2011-08-01 10:20 . 2011-02-05 17:10 20352 —-a-w- c:\windows\system32\kdusb.dll 2011-08-01 10:20 . 2011-02-25 05:34 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-08-01 10:20 . 2011-02-25 06:22 861696 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-01 10:20 . 2011-06-11 03:07 3137536 —-a-w- c:\windows\system32\win32k.sys 2011-08-01 10:13 . 2011-08-01 10:13 ——– d-sh–w- c:\windows\SysWow64\%APPDATA% 2011-08-01 10:11 . 2011-08-01 10:11 ——– d—–w- c:\program files (x86)\MSXML 4.0 2011-08-01 03:31 . 2011-04-22 22:15 27520 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-08-01 03:30 . 2011-01-17 11:09 197120 —-a-w- c:\windows\system32\d3d10_1.dll 2011-08-01 03:30 . 2011-01-17 05:47 161792 —-a-w- c:\windows\SysWow64\d3d10_1.dll 2011-08-01 03:30 . 2011-02-18 10:51 31232 —-a-w- c:\windows\system32\prevhost.exe 2011-08-01 03:30 . 2011-02-18 05:39 31232 —-a-w- c:\windows\SysWow64\prevhost.exe 2011-08-01 01:16 . 2011-08-07 01:55 ——– d—–w- c:\programdata\VirtualizedApplications 2011-08-01 01:09 . 2008-07-31 17:41 68616 —-a-w- c:\windows\SysWow64\XAPOFX1_1.dll 2011-08-01 01:09 . 2008-07-31 17:40 509448 —-a-w- c:\windows\SysWow64\XAudio2_2.dll 2011-08-01 01:09 . 2008-07-12 15:18 467984 —-a-w- c:\windows\SysWow64\d3dx10_39.dll 2011-08-01 01:09 . 2008-07-12 15:18 3851784 —-a-w- c:\windows\SysWow64\D3DX9_39.dll 2011-08-01 01:09 . 2008-07-12 15:18 1493528 —-a-w- c:\windows\SysWow64\D3DCompiler_39.dll 2011-08-01 01:06 . 2011-08-01 01:06 ——– d—–w- C:\Riot Games 2011-07-31 23:05 . 2011-08-01 10:10 ——– d—–w- c:\program files (x86)\Microsoft Application Virtualization Client 2011-07-31 22:53 . 2011-08-08 08:27 ——– d—–w- c:\program files (x86)\Pando Networks 2011-07-31 21:15 . 2011-07-31 21:15 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-07-31 20:59 . 2011-08-11 23:07 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2011-07-31 20:59 . 2011-08-01 10:33 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2011-07-31 20:57 . 2011-02-12 11:34 267776 —-a-w- c:\windows\system32\FXSCOVER.exe 2011-07-31 20:57 . 2010-12-17 11:40 715776 —-a-w- c:\windows\system32\kerberos.dll 2011-07-31 20:57 . 2010-12-17 07:07 542208 —-a-w- c:\windows\SysWow64\kerberos.dll 2011-07-31 20:57 . 2010-12-23 10:42 1118720 —-a-w- c:\windows\system32\sbe.dll 2011-07-31 20:57 . 2010-12-23 10:42 961024 —-a-w- c:\windows\system32\CPFilters.dll 2011-07-31 20:57 . 2010-12-23 10:42 723968 —-a-w- c:\windows\system32\EncDec.dll 2011-07-31 20:57 . 2010-12-23 10:36 259072 —-a-w- c:\windows\system32\mpg2splt.ax 2011-07-31 20:57 . 2010-12-23 05:54 850944 —-a-w- c:\windows\SysWow64\sbe.dll 2011-07-31 20:57 . 2010-12-23 05:54 642048 —-a-w- c:\windows\SysWow64\CPFilters.dll 2011-07-31 20:57 . 2010-12-23 05:54 534528 —-a-w- c:\windows\SysWow64\EncDec.dll 2011-07-31 20:57 . 2010-12-23 05:50 199680 —-a-w- c:\windows\SysWow64\mpg2splt.ax 2011-07-31 20:57 . 2011-04-25 02:34 499200 —-a-w- c:\windows\system32\drivers\afd.sys 2011-07-31 20:56 . 2011-04-09 06:58 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-07-31 20:56 . 2011-04-09 05:56 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-07-31 20:56 . 2011-04-27 02:40 158208 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-31 20:56 . 2011-04-27 02:39 128000 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-07-31 20:56 . 2011-05-03 05:29 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-07-31 20:56 . 2011-05-03 04:30 741376 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-07-31 20:46 . 2011-05-24 11:42 404480 —-a-w- c:\windows\system32\umpnpmgr.dll 2011-07-31 20:46 . 2011-05-24 10:40 64512 —-a-w- c:\windows\SysWow64\devobj.dll 2011-07-31 20:46 . 2011-05-24 10:40 44544 —-a-w- c:\windows\SysWow64\devrtl.dll 2011-07-31 20:46 . 2011-05-24 10:39 145920 —-a-w- c:\windows\SysWow64\cfgmgr32.dll 2011-07-31 20:46 . 2011-05-24 10:37 252928 —-a-w- c:\windows\SysWow64\drvinst.exe 2011-07-31 20:46 . 2011-02-23 04:55 90624 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-07-31 20:45 . 2011-07-31 20:45 ——– d—–w- c:\windows\SysWow64\Wat 2011-07-31 20:45 . 2011-07-31 20:45 ——– d—–w- c:\windows\system32\Wat 2011-07-31 20:40 . 2011-07-31 20:40 ——– d—–w- c:\windows\SysWow64\drivers\AVG 2011-07-31 20:39 . 2011-08-11 23:08 ——– d—–w- c:\windows\system32\drivers\AVG 2011-07-31 20:31 . 2011-07-31 20:31 ——– d—–w- c:\program files (x86)\Belkin 2011-07-31 20:30 . 2011-07-31 20:30 ——– d—–w- c:\windows\{26F3D17D-4FF9-46D5-9255-A1F9FF6BD7E4} 2011-07-31 20:15 . 2011-07-31 20:40 ——– d—–w- c:\programdata\AVG Security Toolbar 2011-07-31 20:14 . 2011-07-31 20:39 ——– d—–w- c:\programdata\AVG10 2011-07-31 20:13 . 2011-07-31 20:13 ——– d—–w- c:\program files (x86)\AVG 2011-07-31 19:46 . 2011-07-31 19:46 ——– d—–w- c:\programdata\WinZip 2011-07-31 19:41 . 2011-07-31 21:28 ——– d—–w- c:\program files (x86)\JDownloader 2011-07-31 19:38 . 2011-07-31 20:51 ——– d—–r- c:\program files (x86)\Skype 2011-07-31 19:37 . 2011-07-31 21:28 ——– d—–w- c:\programdata\Skype 2011-07-31 05:36 . 2011-07-31 21:28 ——– d—–w- c:\program files (x86)\OpenOffice.org 3 2011-07-31 05:36 . 2011-07-31 05:36 ——– d—–w- c:\programdata\DAEMON Tools Lite 2011-07-31 05:36 . 2011-07-31 05:36 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-07-31 05:35 . 2011-07-31 05:35 ——– d—–w- c:\program files (x86)\Java 2011-07-31 05:32 . 2011-07-31 20:47 ——– d—–w- c:\program files (x86)\Winamp 2011-07-31 05:32 . 2011-07-31 20:48 ——– d—–w- c:\program files (x86)\Trillian 2011-07-31 04:50 . 2011-07-31 20:37 ——– d—–w- c:\users\Family 2011-07-31 04:44 . 2011-07-31 04:44 ——– d—–w- c:\programdata\Blio 2011-07-31 03:48 . 2011-07-31 03:48 ——– d–h–w- c:\programdata\Common Files 2011-07-31 03:48 . 2011-07-31 20:41 ——– d—–w- c:\programdata\MFAData . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-07-31 20:35 . 2010-06-24 18:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-07-16 04:26 . 2011-08-11 04:17 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-07-12 18:34 . 2011-07-12 18:34 96104 —-a-w- c:\windows\system32\dns-sd.exe 2011-07-12 18:34 . 2011-07-12 18:34 85864 —-a-w- c:\windows\system32\dnssd.dll 2011-07-12 18:34 . 2011-07-12 18:34 61288 —-a-w- c:\windows\system32\jdns_sd.dll 2011-07-12 18:34 . 2011-07-12 18:34 212840 —-a-w- c:\windows\system32\dnssdX.dll 2011-07-12 18:20 . 2011-07-12 18:20 83816 —-a-w- c:\windows\SysWow64\dns-sd.exe 2011-07-12 18:20 . 2011-07-12 18:20 73064 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-07-12 18:20 . 2011-07-12 18:20 50536 —-a-w- c:\windows\SysWow64\jdns_sd.dll 2011-07-12 18:20 . 2011-07-12 18:20 178536 —-a-w- c:\windows\SysWow64\dnssdX.dll 2011-07-06 01:37 . 2011-07-06 01:37 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2011-07-06 01:37 . 2011-07-06 01:37 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}] 2011-05-30 18:33 2495816 —-a-w- c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816] . [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Aim"="c:\program files (x86)\AIM\aim.exe" [2011-05-03 4321112] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-05-12 102400] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2011-02-01 656920] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-20 421736] "AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2011-04-19 2334560] "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-06 421888] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-07 366640] R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-05-30 1025352] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-08-10 1431888] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys [x] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-04-19 7398752] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664] S2 Giraffic;Giraffic Video Accelerator;c:\program files (x86)\Giraffic\GirafficWatchdog.exe [2011-07-13 2211984] S2 HPAuto;HP Auto;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-17 682040] S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-01-26 92216] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448] S2 RoxioNow Service;RoxioNow Service;c:\program files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-11-26 399344] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768] S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-08-08 c:\windows\Tasks\HPCeeScheduleForAdmin.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.2.1 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll FF - ProfilePath - c:\users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\hb2d60hp.default\ FF - prefs.js: browser.startup.homepage - google.com FF - user.js: general.useragent.extra.brc - FF - user.js: network.protocol-handler.warn-external.dnupdate - false . - - - - ORPHANS REMOVED - - - - . WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) AddRemove-{E92D47A1-D27D-430A-8368-0BAFD956507D} - c:\program files (x86)\InstallShield Installation Information\{E92D47A1-D27D-430A-8368-0BAFD956507D}\setup.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher] "ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe . ************************************************************************** . Completion time: 2011-08-11 21:54:28 - machine was rebooted ComboFix-quarantined-files.txt 2011-08-12 04:54 . Pre-Run: 934,016,614,400 bytes free Post-Run: 933,834,846,208 bytes free . - - End Of File - - 7C6049759944A54ADB976CDDA922497C
I'm still not seeing a malware cause of your problem. Let's get one more scan… an online one, then we'll try resetting your IP.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
I got a Candy malware, but I'm not sure if its the one messing with my internet server or IP Address. Maybe I should take it into Geek Squad at Best Buy. ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=cc4f5f14ca157b47b343929d0c918a07 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-08-13 02:23:19 # local_time=2011-08-12 07:23:19 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1032 16777213 100 87 0 55535909 0 0 # compatibility_mode=5893 16776574 100 94 21958306 64742967 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=181635 # found=2 # cleaned=0 # scan_time=2681 C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\OCSetupHlp.dll Win32/OpenCandy application (unable to clean) 00000000000000000000000000000000 I C:\Users\Admin\Downloads\VeohWebPlayerSetup_eng.exe Win32/OpenCandy application (unable to clean) 00000000000000000000000000000000 I
Riak,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\OCSetupHlp.dll 
    C:\Users\Admin\Downloads\VeohWebPlayerSetup_eng.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Then please run DDS again and post the logs. Also let me know if you are still having trouble with your internet access.
My ComboFix didn't create a log file where it said it would be. Am I doing something wrong? Or did the script do something to make this happen? Would you like the DDS log instead with the attach document?
The log should be found at C:\ComboFix.txt .

Yes… I'd also like to see both DDS logs… and I'd like to know if you are still having connection problems.
I ran it again, and there is still no log, maybe it's under a hidden file? I forgot how to change the status to view hidden files. I play League of Legends, and the latency I noticed is now really really high, 4,500. And, it still freezes (the internet) but I can disable the network adapter and it will work for a good 20 minutes or so but I still have to keep reconnecting the thing. Here's the DDS. . DDS (Ver_2011-06-23.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 21:54:51 on 2011-08-13 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2466 [GMT -7:00] . AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe C:\Program Files (x86)\PDF Complete\pdfsvc.exe C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files (x86)\AIM\aim.exe C:\Program Files (x86)\Giraffic\Giraffic.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{84F2469B-6A0B-413A-8E0F-2978AFA9E09C} : DhcpNameServer = 192.168.2.1 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: AVG Security Toolbar BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll TB-X64: AVG Security Toolbar: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll mRun-x64: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun-x64: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\hb2d60hp.default\ FF - prefs.js: browser.startup.homepage - google.com FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . —- FIREFOX POLICIES —- FF - user.js: general.useragent.extra.brc - FF - user.js: network.protocol-handler.warn-external.dnupdate - false . ============= SERVICES / DRIVERS =============== . R0 amd_sata;amd_sata;C:\Windows\system32\drivers\amd_sata.sys –> C:\Windows\system32\drivers\amd_sata.sys [?] R0 amd_xata;amd_xata;C:\Windows\system32\drivers\amd_xata.sys –> C:\Windows\system32\drivers\amd_xata.sys [?] R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys –> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?] R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664] R2 Giraffic;Giraffic Video Accelerator;C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe –service –> C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe –service [?] R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-16 682040] R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-1-25 92216] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-7 366640] R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568] R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-5-1 1127448] R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-11-26 399344] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-31 1153368] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys –> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys –> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192su.sys –> C:\Windows\system32\DRIVERS\RTL8192su.sys [?] R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys –> C:\Windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys –> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys –> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys –> C:\Windows\system32\DRIVERS\Sftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768] R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\drivers\usbfilter.sys –> C:\Windows\system32\drivers\usbfilter.sys [?] S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-7-31 1025352] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-8-9 1431888] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== File Associations =============== . inffile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1 VBEFile=%SystemRoot%\SysWow64\WScript.exe "%1" %* VBSFile=%SystemRoot%\SysWow64\WScript.exe "%1" %* . =============== Created Last 30 ================ . 2011-08-14 04:10:03 ——– d-sh–w- C:\$RECYCLE.BIN 2011-08-14 03:50:43 ——– d—–w- C:\ComboFix 2011-08-13 01:02:03 ——– d—–w- C:\Program Files (x86)\ESET 2011-08-12 04:36:38 98816 —-a-w- C:\Windows\sed.exe 2011-08-12 04:36:38 518144 —-a-w- C:\Windows\SWREG.exe 2011-08-12 04:36:38 256000 —-a-w- C:\Windows\PEV.exe 2011-08-12 04:36:38 208896 —-a-w- C:\Windows\MBR.exe 2011-08-11 06:39:00 ——– d-sh–w- C:\Windows\System32\%APPDATA% 2011-08-11 04:16:54 1923968 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-08-11 04:14:02 5561216 —-a-w- C:\Windows\System32\ntoskrnl.exe 2011-08-11 04:14:02 3967872 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-08-11 04:14:02 3912576 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-08-10 06:51:31 ——– d—–w- C:\ProgramData\Giraffic 2011-08-10 06:51:31 ——– d—–w- C:\Program Files (x86)\Giraffic 2011-08-10 06:51:27 ——– d—–w- C:\Program Files (x86)\Veoh Networks 2011-08-10 05:16:55 ——– d—–w- C:\Users\Admin\Autodesk 2011-08-10 01:03:58 ——– d—–w- C:\ProgramData\boost_interprocess 2011-08-10 00:38:31 ——– d—–w- C:\Program Files\NVIDIA Corporation 2011-08-10 00:38:31 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation 2011-08-10 00:28:53 ——– d—–w- C:\Program Files\Common Files\Softimage 2011-08-10 00:28:53 ——– d—–w- C:\Program Files (x86)\Common Files\Softimage 2011-08-10 00:28:53 ——– d—–w- C:\Program Files (x86)\Common Files\Autodesk Shared 2011-08-10 00:28:27 ——– d—–w- C:\Program Files\Common Files\Alias Shared 2011-08-10 00:27:57 ——– d—–w- C:\Program Files\Common Files\Macrovision Shared 2011-08-10 00:27:38 ——– d—–w- C:\Program Files\Common Files\Autodesk Shared 2011-08-10 00:25:07 ——– d—–w- C:\Program Files\Autodesk 2011-08-10 00:22:59 4992520 —-a-w- C:\Windows\System32\D3DX9_39.dll 2011-08-10 00:15:43 ——– d—–w- C:\Users\Admin\AppData\Roaming\Autodesk 2011-08-08 23:17:30 388096 —-a-r- C:\Users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-08-08 23:17:30 ——– d—–w- C:\Program Files (x86)\Trend Micro 2011-08-08 06:50:57 23112 —-a-w- C:\Windows\System32\drivers\hitmanpro35.sys 2011-08-08 06:48:28 ——– d—–w- C:\Users\Admin\AppData\Roaming\Malwarebytes 2011-08-08 06:48:26 41272 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-08-08 06:48:25 ——– d—–w- C:\ProgramData\Malwarebytes 2011-08-08 06:48:22 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-08-08 06:48:22 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-08-08 06:47:47 ——– d—–w- C:\Program Files\Hitman Pro 3.5 2011-08-08 06:47:25 ——– d—–w- C:\ProgramData\Hitman Pro 2011-08-07 20:36:55 ——– d—–w- C:\Users\Admin\AppData\Local\AOL 2011-08-07 20:36:55 ——– d—–w- C:\Users\Admin\AppData\Local\AIM 2011-08-07 20:36:49 ——– d—–w- C:\ProgramData\AIM 2011-08-07 20:36:47 ——– d—–w- C:\Program Files (x86)\AIM 2011-08-07 20:36:46 ——– d—–w- C:\Program Files (x86)\Common Files\Software Update Utility 2011-08-07 20:36:45 ——– d—–w- C:\Program Files (x86)\Common Files\AOL 2011-08-03 17:55:02 902656 —-a-w- C:\Windows\System32\d2d1.dll 2011-08-03 17:55:02 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll 2011-08-03 17:55:02 1544192 —-a-w- C:\Windows\System32\DWrite.dll 2011-08-03 17:55:02 1139200 —-a-w- C:\Windows\System32\FntCache.dll 2011-08-03 17:55:02 1076736 —-a-w- C:\Windows\SysWow64\DWrite.dll 2011-08-03 06:06:23 ——– d—–w- C:\Users\Admin\AppData\Local\CrashDumps 2011-08-03 03:00:54 ——– d—–w- C:\Users\Admin\AppData\Local\Diagnostics 2011-08-01 11:15:41 748336 —-a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2011-08-01 10:20:36 642944 —-a-w- C:\Windows\System32\winload.efi 2011-08-01 10:20:36 605552 —-a-w- C:\Windows\System32\winload.exe 2011-08-01 10:20:36 566208 —-a-w- C:\Windows\System32\winresume.efi 2011-08-01 10:20:36 518672 —-a-w- C:\Windows\System32\winresume.exe 2011-08-01 10:20:36 19328 —-a-w- C:\Windows\System32\kd1394.dll 2011-08-01 10:20:36 17792 —-a-w- C:\Windows\System32\kdcom.dll 2011-08-01 10:20:35 20352 —-a-w- C:\Windows\System32\kdusb.dll 2011-08-01 10:20:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-01 10:20:26 861696 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-01 10:20:16 3137536 —-a-w- C:\Windows\System32\win32k.sys 2011-08-01 10:13:14 ——– d-sh–w- C:\Windows\SysWow64\%APPDATA% 2011-08-01 10:11:36 ——– d—–w- C:\Program Files (x86)\MSXML 4.0 2011-08-01 05:48:34 ——– d—–w- C:\Users\Admin\riotsGamesLogs 2011-08-01 05:15:07 ——– d—–w- C:\Users\Admin\AppData\Roaming\LolClient 2011-08-01 03:31:53 27520 —-a-w- C:\Windows\System32\drivers\Diskdump.sys 2011-08-01 03:30:06 197120 —-a-w- C:\Windows\System32\d3d10_1.dll 2011-08-01 03:30:06 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2011-08-01 03:30:03 31232 —-a-w- C:\Windows\SysWow64\prevhost.exe 2011-08-01 03:30:03 31232 —-a-w- C:\Windows\System32\prevhost.exe 2011-08-01 02:43:11 ——– d—–w- C:\Users\Admin\AppData\Roaming\HP Support Assistant 2011-08-01 01:16:59 ——– d—–w- C:\ProgramData\VirtualizedApplications 2011-08-01 01:09:16 68616 —-a-w- C:\Windows\SysWow64\XAPOFX1_1.dll 2011-08-01 01:09:16 509448 —-a-w- C:\Windows\SysWow64\XAudio2_2.dll 2011-08-01 01:09:15 467984 —-a-w- C:\Windows\SysWow64\d3dx10_39.dll 2011-08-01 01:09:15 3851784 —-a-w- C:\Windows\SysWow64\D3DX9_39.dll 2011-08-01 01:09:15 1493528 —-a-w- C:\Windows\SysWow64\D3DCompiler_39.dll 2011-08-01 01:06:33 ——– d—–w- C:\Riot Games 2011-07-31 23:05:43 ——– d—–w- C:\Program Files (x86)\Microsoft Application Virtualization Client 2011-07-31 22:53:51 ——– d—–w- C:\Program Files (x86)\Pando Networks 2011-07-31 21:15:11 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-07-31 21:05:17 ——– d—–w- C:\Users\Admin\AppData\Local\AVG Security Toolbar 2011-07-31 20:59:00 ——– d—–w- C:\ProgramData\Spybot - Search & Destroy 2011-07-31 20:59:00 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy 2011-07-31 20:57:10 267776 —-a-w- C:\Windows\System32\FXSCOVER.exe 2011-07-31 20:57:08 715776 —-a-w- C:\Windows\System32\kerberos.dll 2011-07-31 20:57:08 542208 —-a-w- C:\Windows\SysWow64\kerberos.dll 2011-07-31 20:57:03 961024 —-a-w- C:\Windows\System32\CPFilters.dll 2011-07-31 20:57:03 850944 —-a-w- C:\Windows\SysWow64\sbe.dll 2011-07-31 20:57:03 723968 —-a-w- C:\Windows\System32\EncDec.dll 2011-07-31 20:57:03 642048 —-a-w- C:\Windows\SysWow64\CPFilters.dll 2011-07-31 20:57:03 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll 2011-07-31 20:57:03 259072 —-a-w- C:\Windows\System32\mpg2splt.ax 2011-07-31 20:57:03 1118720 —-a-w- C:\Windows\System32\sbe.dll 2011-07-31 20:57:02 199680 —-a-w- C:\Windows\SysWow64\mpg2splt.ax 2011-07-31 20:57:00 499200 —-a-w- C:\Windows\System32\drivers\afd.sys 2011-07-31 20:56:29 142336 —-a-w- C:\Windows\System32\poqexec.exe 2011-07-31 20:56:29 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe 2011-07-31 20:56:28 158208 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-07-31 20:56:27 128000 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-07-31 20:56:26 976896 —-a-w- C:\Windows\System32\inetcomm.dll 2011-07-31 20:56:26 741376 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-07-31 20:46:45 64512 —-a-w- C:\Windows\SysWow64\devobj.dll 2011-07-31 20:46:45 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll 2011-07-31 20:46:45 404480 —-a-w- C:\Windows\System32\umpnpmgr.dll 2011-07-31 20:46:45 252928 —-a-w- C:\Windows\SysWow64\drvinst.exe 2011-07-31 20:46:45 145920 —-a-w- C:\Windows\SysWow64\cfgmgr32.dll 2011-07-31 20:46:03 90624 —-a-w- C:\Windows\System32\drivers\bowser.sys 2011-07-31 20:45:41 ——– d—–w- C:\Windows\SysWow64\Wat 2011-07-31 20:45:41 ——– d—–w- C:\Windows\System32\Wat 2011-07-31 20:41:50 ——– d—–w- C:\Users\Admin\AppData\Roaming\AVG10 2011-07-31 20:40:34 ——– d—–w- C:\Windows\SysWow64\drivers\AVG 2011-07-31 20:39:27 ——– d—–w- C:\Windows\System32\drivers\AVG 2011-07-31 20:31:20 ——– d—–w- C:\Program Files (x86)\Belkin 2011-07-31 20:30:54 ——– d—–w- C:\Windows\{26F3D17D-4FF9-46D5-9255-A1F9FF6BD7E4} 2011-07-31 20:15:07 ——– d—–w- C:\ProgramData\AVG Security Toolbar 2011-07-31 20:14:39 ——– d—–w- C:\ProgramData\AVG10 2011-07-31 20:13:46 ——– d—–w- C:\Program Files (x86)\AVG 2011-07-31 19:46:07 ——– d—–w- C:\Users\Admin\AppData\Local\WinZip 2011-07-31 19:43:08 ——– d—–w- C:\Users\Admin\AppData\Roaming\Trillian 2011-07-31 19:41:41 ——– d—–w- C:\Program Files (x86)\JDownloader 2011-07-31 19:38:02 ——– d—–r- C:\Program Files (x86)\Skype 2011-07-31 19:34:00 ——– d—–w- C:\Users\Admin\AppData\Roaming\HpUpdate 2011-07-31 19:33:59 ——– d—–w- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite 2011-07-31 05:36:41 ——– d—–w- C:\Program Files (x86)\OpenOffice.org 3 2011-07-31 05:36:23 ——– d—–w- C:\ProgramData\DAEMON Tools Lite 2011-07-31 04:44:21 ——– d—–w- C:\ProgramData\Blio 2011-07-31 04:44:06 ——– d—–w- C:\Users\Admin\AppData\Roaming\Blio 2011-07-31 03:48:38 ——– d–h–w- C:\ProgramData\Common Files 2011-07-31 03:48:27 ——– d—–w- C:\ProgramData\MFAData 2011-07-31 03:34:34 ——– d—–w- C:\ProgramData\regid.1986-12.com.adobe 2011-07-31 03:32:12 ——– d—–w- C:\Users\Admin\AppData\Local\Adobe 2011-07-31 03:31:32 ——– d—–w- C:\Program Files (x86)\Photoshop 2011-07-31 03:26:45 ——– d—–w- C:\Program Files (x86)\uTorrent 2011-07-31 03:26:22 ——– d—–w- C:\Users\Admin\AppData\Roaming\uTorrent 2011-07-31 03:26:22 ——– d—–w- C:\Users\Admin\AppData\Local\uTorrent 2011-07-30 18:26:36 ——– d—–w- C:\Users\Admin\AppData\Local\Apple Computer 2011-07-30 18:26:32 34152 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2011-07-30 18:26:32 126312 —-a-w- C:\Windows\System32\GEARAspi64.dll 2011-07-30 18:26:32 107368 —-a-w- C:\Windows\SysWow64\GEARAspi.dll 2011-07-30 18:26:23 ——– d—–w- C:\Program Files\iPod 2011-07-30 18:26:22 ——– d—–w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2011-07-30 18:26:22 ——– d—–w- C:\Program Files\iTunes 2011-07-30 18:26:22 ——– d—–w- C:\Program Files (x86)\iTunes 2011-07-30 18:25:57 ——– d—–w- C:\Users\Admin\AppData\Local\Apple 2011-07-30 18:25:42 ——– d—–w- C:\Program Files\Bonjour 2011-07-30 18:25:42 ——– d—–w- C:\Program Files (x86)\Bonjour 2011-07-30 18:25:11 ——– d—–w- C:\Program Files\CCleaner 2011-07-30 18:23:03 ——– d—–w- C:\Users\Admin\AppData\Local\Mozilla 2011-07-30 17:35:07 ——– d—–w- C:\Users\Admin\hpremote 2011-07-30 17:26:23 ——– d—–w- C:\Users\Admin\AppData\Local\ATI 2011-07-30 17:25:23 ——– d—–w- C:\Users\Admin\AppData\Local\PDFC 2011-07-30 17:24:54 ——– d—–w- C:\Users\Admin\AppData\Local\RemEngine 2011-07-30 17:21:19 ——– d—–w- C:\Users\Admin\AppData\Local\VirtualStore . ==================== Find3M ==================== . 2011-07-22 05:42:23 2303488 —-a-w- C:\Windows\System32\jscript9.dll 2011-07-22 05:36:16 1389056 —-a-w- C:\Windows\System32\wininet.dll 2011-07-22 05:32:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-07-22 02:54:43 1797632 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-07-22 02:48:26 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-07-22 02:44:36 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-07-16 05:41:50 362496 —-a-w- C:\Windows\System32\wow64win.dll 2011-07-16 05:41:49 243200 —-a-w- C:\Windows\System32\wow64.dll 2011-07-16 05:41:49 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2011-07-16 05:39:10 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2011-07-16 05:37:12 421888 —-a-w- C:\Windows\System32\KernelBase.dll 2011-07-16 04:29:19 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2011-07-16 04:26:00 44032 —-a-w- C:\Windows\apppatch\acwow64.dll 2011-07-16 04:25:37 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2011-07-16 04:24:23 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2011-07-16 04:24:22 272384 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2011-07-16 02:21:44 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2011-07-16 02:21:41 2048 —-a-w- C:\Windows\SysWow64\user.exe 2011-07-16 02:17:19 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17:19 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17:19 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17:19 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2011-07-12 18:34:00 96104 —-a-w- C:\Windows\System32\dns-sd.exe 2011-07-12 18:34:00 85864 —-a-w- C:\Windows\System32\dnssd.dll 2011-07-12 18:34:00 61288 —-a-w- C:\Windows\System32\jdns_sd.dll 2011-07-12 18:34:00 212840 —-a-w- C:\Windows\System32\dnssdX.dll 2011-07-12 18:20:54 83816 —-a-w- C:\Windows\SysWow64\dns-sd.exe 2011-07-12 18:20:54 73064 —-a-w- C:\Windows\SysWow64\dnssd.dll 2011-07-12 18:20:54 50536 —-a-w- C:\Windows\SysWow64\jdns_sd.dll 2011-07-12 18:20:54 178536 —-a-w- C:\Windows\SysWow64\dnssdX.dll 2011-07-09 02:46:28 288768 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-07-06 01:37:00 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2011-07-06 01:37:00 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2011-06-24 05:34:53 214528 —-a-w- C:\Windows\System32\winsrv.dll 2011-06-24 05:25:49 338432 —-a-w- C:\Windows\System32\conhost.exe 2011-06-15 10:02:23 212992 —-a-w- C:\Windows\System32\odbctrac.dll 2011-06-15 10:02:23 163840 —-a-w- C:\Windows\System32\odbccp32.dll 2011-06-15 10:02:23 106496 —-a-w- C:\Windows\System32\odbccu32.dll 2011-06-15 10:02:23 106496 —-a-w- C:\Windows\System32\odbccr32.dll 2011-06-15 08:55:19 86016 —-a-w- C:\Windows\SysWow64\odbccu32.dll 2011-06-15 08:55:19 81920 —-a-w- C:\Windows\SysWow64\odbccr32.dll 2011-06-15 08:55:19 319488 —-a-w- C:\Windows\SysWow64\odbcjt32.dll 2011-06-15 08:55:19 163840 —-a-w- C:\Windows\SysWow64\odbctrac.dll 2011-06-15 08:55:19 122880 —-a-w- C:\Windows\SysWow64\odbccp32.dll . ============= FINISH: 21:55:20.68 ===============
I ran it again, and there is still no log, maybe it's under a hidden file? I forgot how to change the status to view hidden files. I play League of Legends, and the latency I noticed is now really really high, 4,500. And, it still freezes (the internet) but I can disable the network adapter and it will work for a good 20 minutes or so but I still have to keep reconnecting the thing. Here's the DDS. . DDS (Ver_2011-06-23.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 21:54:51 on 2011-08-13 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2466 [GMT -7:00] . AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe C:\Program Files (x86)\PDF Complete\pdfsvc.exe C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files (x86)\AIM\aim.exe C:\Program Files (x86)\Giraffic\Giraffic.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{84F2469B-6A0B-413A-8E0F-2978AFA9E09C} : DhcpNameServer = 192.168.2.1 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: AVG Security Toolbar BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll TB-X64: AVG Security Toolbar: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll mRun-x64: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun-x64: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\hb2d60hp.default\ FF - prefs.js: browser.startup.homepage - google.com FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . —- FIREFOX POLICIES —- FF - user.js: general.useragent.extra.brc - FF - user.js: network.protocol-handler.warn-external.dnupdate - false . ============= SERVICES / DRIVERS =============== . R0 amd_sata;amd_sata;C:\Windows\system32\drivers\amd_sata.sys –> C:\Windows\system32\drivers\amd_sata.sys [?] R0 amd_xata;amd_xata;C:\Windows\system32\drivers\amd_xata.sys –> C:\Windows\system32\drivers\amd_xata.sys [?] R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys –> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?] R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664] R2 Giraffic;Giraffic Video Accelerator;C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe –service –> C:\Program Files (x86)\Giraffic\GirafficWatchdog.exe –service [?] R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-16 682040] R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-1-25 92216] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-7 366640] R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568] R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-5-1 1127448] R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-11-26 399344] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-31 1153368] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys –> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys –> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192su.sys –> C:\Windows\system32\DRIVERS\RTL8192su.sys [?] R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys –> C:\Windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys –> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys –> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys –> C:\Windows\system32\DRIVERS\Sftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768] R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\drivers\usbfilter.sys –> C:\Windows\system32\drivers\usbfilter.sys [?] S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-7-31 1025352] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-8-9 1431888] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== File Associations =============== . inffile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1 VBEFile=%SystemRoot%\SysWow64\WScript.exe "%1" %* VBSFile=%SystemRoot%\SysWow64\WScript.exe "%1" %* . =============== Created Last 30 ================ . 2011-08-14 04:10:03 ——– d-sh–w- C:\$RECYCLE.BIN 2011-08-14 03:50:43 ——– d—–w- C:\ComboFix 2011-08-13 01:02:03 ——– d—–w- C:\Program Files (x86)\ESET 2011-08-12 04:36:38 98816 —-a-w- C:\Windows\sed.exe 2011-08-12 04:36:38 518144 —-a-w- C:\Windows\SWREG.exe 2011-08-12 04:36:38 256000 —-a-w- C:\Windows\PEV.exe 2011-08-12 04:36:38 208896 —-a-w- C:\Windows\MBR.exe 2011-08-11 06:39:00 ——– d-sh–w- C:\Windows\System32\%APPDATA% 2011-08-11 04:16:54 1923968 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-08-11 04:14:02 5561216 —-a-w- C:\Windows\System32\ntoskrnl.exe 2011-08-11 04:14:02 3967872 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-08-11 04:14:02 3912576 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-08-10 06:51:31 ——– d—–w- C:\ProgramData\Giraffic 2011-08-10 06:51:31 ——– d—–w- C:\Program Files (x86)\Giraffic 2011-08-10 06:51:27 ——– d—–w- C:\Program Files (x86)\Veoh Networks 2011-08-10 05:16:55 ——– d—–w- C:\Users\Admin\Autodesk 2011-08-10 01:03:58 ——– d—–w- C:\ProgramData\boost_interprocess 2011-08-10 00:38:31 ——– d—–w- C:\Program Files\NVIDIA Corporation 2011-08-10 00:38:31 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation 2011-08-10 00:28:53 ——– d—–w- C:\Program Files\Common Files\Softimage 2011-08-10 00:28:53 ——– d—–w- C:\Program Files (x86)\Common Files\Softimage 2011-08-10 00:28:53 ——– d—–w- C:\Program Files (x86)\Common Files\Autodesk Shared 2011-08-10 00:28:27 ——– d—–w- C:\Program Files\Common Files\Alias Shared 2011-08-10 00:27:57 ——– d—–w- C:\Program Files\Common Files\Macrovision Shared 2011-08-10 00:27:38 ——– d—–w- C:\Program Files\Common Files\Autodesk Shared 2011-08-10 00:25:07 ——– d—–w- C:\Program Files\Autodesk 2011-08-10 00:22:59 4992520 —-a-w- C:\Windows\System32\D3DX9_39.dll 2011-08-10 00:15:43 ——– d—–w- C:\Users\Admin\AppData\Roaming\Autodesk 2011-08-08 23:17:30 388096 —-a-r- C:\Users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-08-08 23:17:30 ——– d—–w- C:\Program Files (x86)\Trend Micro 2011-08-08 06:50:57 23112 —-a-w- C:\Windows\System32\drivers\hitmanpro35.sys 2011-08-08 06:48:28 ——– d—–w- C:\Users\Admin\AppData\Roaming\Malwarebytes 2011-08-08 06:48:26 41272 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-08-08 06:48:25 ——– d—–w- C:\ProgramData\Malwarebytes 2011-08-08 06:48:22 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-08-08 06:48:22 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-08-08 06:47:47 ——– d—–w- C:\Program Files\Hitman Pro 3.5 2011-08-08 06:47:25 ——– d—–w- C:\ProgramData\Hitman Pro 2011-08-07 20:36:55 ——– d—–w- C:\Users\Admin\AppData\Local\AOL 2011-08-07 20:36:55 ——– d—–w- C:\Users\Admin\AppData\Local\AIM 2011-08-07 20:36:49 ——– d—–w- C:\ProgramData\AIM 2011-08-07 20:36:47 ——– d—–w- C:\Program Files (x86)\AIM 2011-08-07 20:36:46 ——– d—–w- C:\Program Files (x86)\Common Files\Software Update Utility 2011-08-07 20:36:45 ——– d—–w- C:\Program Files (x86)\Common Files\AOL 2011-08-03 17:55:02 902656 —-a-w- C:\Windows\System32\d2d1.dll 2011-08-03 17:55:02 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll 2011-08-03 17:55:02 1544192 —-a-w- C:\Windows\System32\DWrite.dll 2011-08-03 17:55:02 1139200 —-a-w- C:\Windows\System32\FntCache.dll 2011-08-03 17:55:02 1076736 —-a-w- C:\Windows\SysWow64\DWrite.dll 2011-08-03 06:06:23 ——– d—–w- C:\Users\Admin\AppData\Local\CrashDumps 2011-08-03 03:00:54 ——– d—–w- C:\Users\Admin\AppData\Local\Diagnostics 2011-08-01 11:15:41 748336 —-a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2011-08-01 10:20:36 642944 —-a-w- C:\Windows\System32\winload.efi 2011-08-01 10:20:36 605552 —-a-w- C:\Windows\System32\winload.exe 2011-08-01 10:20:36 566208 —-a-w- C:\Windows\System32\winresume.efi 2011-08-01 10:20:36 518672 —-a-w- C:\Windows\System32\winresume.exe 2011-08-01 10:20:36 19328 —-a-w- C:\Windows\System32\kd1394.dll 2011-08-01 10:20:36 17792 —-a-w- C:\Windows\System32\kdcom.dll 2011-08-01 10:20:35 20352 —-a-w- C:\Windows\System32\kdusb.dll 2011-08-01 10:20:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-01 10:20:26 861696 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-01 10:20:16 3137536 —-a-w- C:\Windows\System32\win32k.sys 2011-08-01 10:13:14 ——– d-sh–w- C:\Windows\SysWow64\%APPDATA% 2011-08-01 10:11:36 ——– d—–w- C:\Program Files (x86)\MSXML 4.0 2011-08-01 05:48:34 ——– d—–w- C:\Users\Admin\riotsGamesLogs 2011-08-01 05:15:07 ——– d—–w- C:\Users\Admin\AppData\Roaming\LolClient 2011-08-01 03:31:53 27520 —-a-w- C:\Windows\System32\drivers\Diskdump.sys 2011-08-01 03:30:06 197120 —-a-w- C:\Windows\System32\d3d10_1.dll 2011-08-01 03:30:06 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2011-08-01 03:30:03 31232 —-a-w- C:\Windows\SysWow64\prevhost.exe 2011-08-01 03:30:03 31232 —-a-w- C:\Windows\System32\prevhost.exe 2011-08-01 02:43:11 ——– d—–w- C:\Users\Admin\AppData\Roaming\HP Support Assistant 2011-08-01 01:16:59 ——– d—–w- C:\ProgramData\VirtualizedApplications 2011-08-01 01:09:16 68616 —-a-w- C:\Windows\SysWow64\XAPOFX1_1.dll 2011-08-01 01:09:16 509448 —-a-w- C:\Windows\SysWow64\XAudio2_2.dll 2011-08-01 01:09:15 467984 —-a-w- C:\Windows\SysWow64\d3dx10_39.dll 2011-08-01 01:09:15 3851784 —-a-w- C:\Windows\SysWow64\D3DX9_39.dll 2011-08-01 01:09:15 1493528 —-a-w- C:\Windows\SysWow64\D3DCompiler_39.dll 2011-08-01 01:06:33 ——– d—–w- C:\Riot Games 2011-07-31 23:05:43 ——– d—–w- C:\Program Files (x86)\Microsoft Application Virtualization Client 2011-07-31 22:53:51 ——– d—–w- C:\Program Files (x86)\Pando Networks 2011-07-31 21:15:11 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-07-31 21:05:17 ——– d—–w- C:\Users\Admin\AppData\Local\AVG Security Toolbar 2011-07-31 20:59:00 ——– d—–w- C:\ProgramData\Spybot - Search & Destroy 2011-07-31 20:59:00 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy 2011-07-31 20:57:10 267776 —-a-w- C:\Windows\System32\FXSCOVER.exe 2011-07-31 20:57:08 715776 —-a-w- C:\Windows\System32\kerberos.dll 2011-07-31 20:57:08 542208 —-a-w- C:\Windows\SysWow64\kerberos.dll 2011-07-31 20:57:03 961024 —-a-w- C:\Windows\System32\CPFilters.dll 2011-07-31 20:57:03 850944 —-a-w- C:\Windows\SysWow64\sbe.dll 2011-07-31 20:57:03 723968 —-a-w- C:\Windows\System32\EncDec.dll 2011-07-31 20:57:03 642048 —-a-w- C:\Windows\SysWow64\CPFilters.dll 2011-07-31 20:57:03 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll 2011-07-31 20:57:03 259072 —-a-w- C:\Windows\System32\mpg2splt.ax 2011-07-31 20:57:03 1118720 —-a-w- C:\Windows\System32\sbe.dll 2011-07-31 20:57:02 199680 —-a-w- C:\Windows\SysWow64\mpg2splt.ax 2011-07-31 20:57:00 499200 —-a-w- C:\Windows\System32\drivers\afd.sys 2011-07-31 20:56:29 142336 —-a-w- C:\Windows\System32\poqexec.exe 2011-07-31 20:56:29 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe 2011-07-31 20:56:28 158208 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-07-31 20:56:27 128000 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-07-31 20:56:26 976896 —-a-w- C:\Windows\System32\inetcomm.dll 2011-07-31 20:56:26 741376 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-07-31 20:46:45 64512 —-a-w- C:\Windows\SysWow64\devobj.dll 2011-07-31 20:46:45 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll 2011-07-31 20:46:45 404480 —-a-w- C:\Windows\System32\umpnpmgr.dll 2011-07-31 20:46:45 252928 —-a-w- C:\Windows\SysWow64\drvinst.exe 2011-07-31 20:46:45 145920 —-a-w- C:\Windows\SysWow64\cfgmgr32.dll 2011-07-31 20:46:03 90624 —-a-w- C:\Windows\System32\drivers\bowser.sys 2011-07-31 20:45:41 ——– d—–w- C:\Windows\SysWow64\Wat 2011-07-31 20:45:41 ——– d—–w- C:\Windows\System32\Wat 2011-07-31 20:41:50 ——– d—–w- C:\Users\Admin\AppData\Roaming\AVG10 2011-07-31 20:40:34 ——– d—–w- C:\Windows\SysWow64\drivers\AVG 2011-07-31 20:39:27 ——– d—–w- C:\Windows\System32\drivers\AVG 2011-07-31 20:31:20 ——– d—–w- C:\Program Files (x86)\Belkin 2011-07-31 20:30:54 ——– d—–w- C:\Windows\{26F3D17D-4FF9-46D5-9255-A1F9FF6BD7E4} 2011-07-31 20:15:07 ——– d—–w- C:\ProgramData\AVG Security Toolbar 2011-07-31 20:14:39 ——– d—–w- C:\ProgramData\AVG10 2011-07-31 20:13:46 ——– d—–w- C:\Program Files (x86)\AVG 2011-07-31 19:46:07 ——– d—–w- C:\Users\Admin\AppData\Local\WinZip 2011-07-31 19:43:08 ——– d—–w- C:\Users\Admin\AppData\Roaming\Trillian 2011-07-31 19:41:41 ——– d—–w- C:\Program Files (x86)\JDownloader 2011-07-31 19:38:02 ——– d—–r- C:\Program Files (x86)\Skype 2011-07-31 19:34:00 ——– d—–w- C:\Users\Admin\AppData\Roaming\HpUpdate 2011-07-31 19:33:59 ——– d—–w- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite 2011-07-31 05:36:41 ——– d—–w- C:\Program Files (x86)\OpenOffice.org 3 2011-07-31 05:36:23 ——– d—–w- C:\ProgramData\DAEMON Tools Lite 2011-07-31 04:44:21 ——– d—–w- C:\ProgramData\Blio 2011-07-31 04:44:06 ——– d—–w- C:\Users\Admin\AppData\Roaming\Blio 2011-07-31 03:48:38 ——– d–h–w- C:\ProgramData\Common Files 2011-07-31 03:48:27 ——– d—–w- C:\ProgramData\MFAData 2011-07-31 03:34:34 ——– d—–w- C:\ProgramData\regid.1986-12.com.adobe 2011-07-31 03:32:12 ——– d—–w- C:\Users\Admin\AppData\Local\Adobe 2011-07-31 03:31:32 ——– d—–w- C:\Program Files (x86)\Photoshop 2011-07-31 03:26:45 ——– d—–w- C:\Program Files (x86)\uTorrent 2011-07-31 03:26:22 ——– d—–w- C:\Users\Admin\AppData\Roaming\uTorrent 2011-07-31 03:26:22 ——– d—–w- C:\Users\Admin\AppData\Local\uTorrent 2011-07-30 18:26:36 ——– d—–w- C:\Users\Admin\AppData\Local\Apple Computer 2011-07-30 18:26:32 34152 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2011-07-30 18:26:32 126312 —-a-w- C:\Windows\System32\GEARAspi64.dll 2011-07-30 18:26:32 107368 —-a-w- C:\Windows\SysWow64\GEARAspi.dll 2011-07-30 18:26:23 ——– d—–w- C:\Program Files\iPod 2011-07-30 18:26:22 ——– d—–w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} 2011-07-30 18:26:22 ——– d—–w- C:\Program Files\iTunes 2011-07-30 18:26:22 ——– d—–w- C:\Program Files (x86)\iTunes 2011-07-30 18:25:57 ——– d—–w- C:\Users\Admin\AppData\Local\Apple 2011-07-30 18:25:42 ——– d—–w- C:\Program Files\Bonjour 2011-07-30 18:25:42 ——– d—–w- C:\Program Files (x86)\Bonjour 2011-07-30 18:25:11 ——– d—–w- C:\Program Files\CCleaner 2011-07-30 18:23:03 ——– d—–w- C:\Users\Admin\AppData\Local\Mozilla 2011-07-30 17:35:07 ——– d—–w- C:\Users\Admin\hpremote 2011-07-30 17:26:23 ——– d—–w- C:\Users\Admin\AppData\Local\ATI 2011-07-30 17:25:23 ——– d—–w- C:\Users\Admin\AppData\Local\PDFC 2011-07-30 17:24:54 ——– d—–w- C:\Users\Admin\AppData\Local\RemEngine 2011-07-30 17:21:19 ——– d—–w- C:\Users\Admin\AppData\Local\VirtualStore . ==================== Find3M ==================== . 2011-07-22 05:42:23 2303488 —-a-w- C:\Windows\System32\jscript9.dll 2011-07-22 05:36:16 1389056 —-a-w- C:\Windows\System32\wininet.dll 2011-07-22 05:32:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-07-22 02:54:43 1797632 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-07-22 02:48:26 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-07-22 02:44:36 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-07-16 05:41:50 362496 —-a-w- C:\Windows\System32\wow64win.dll 2011-07-16 05:41:49 243200 —-a-w- C:\Windows\System32\wow64.dll 2011-07-16 05:41:49 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2011-07-16 05:39:10 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2011-07-16 05:37:12 421888 —-a-w- C:\Windows\System32\KernelBase.dll 2011-07-16 04:29:19 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2011-07-16 04:26:00 44032 —-a-w- C:\Windows\apppatch\acwow64.dll 2011-07-16 04:25:37 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2011-07-16 04:24:23 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2011-07-16 04:24:22 272384 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2011-07-16 02:21:44 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2011-07-16 02:21:41 2048 —-a-w- C:\Windows\SysWow64\user.exe 2011-07-16 02:17:19 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17:19 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17:19 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17:19 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2011-07-12 18:34:00 96104 —-a-w- C:\Windows\System32\dns-sd.exe 2011-07-12 18:34:00 85864 —-a-w- C:\Windows\System32\dnssd.dll 2011-07-12 18:34:00 61288 —-a-w- C:\Windows\System32\jdns_sd.dll 2011-07-12 18:34:00 212840 —-a-w- C:\Windows\System32\dnssdX.dll 2011-07-12 18:20:54 83816 —-a-w- C:\Windows\SysWow64\dns-sd.exe 2011-07-12 18:20:54 73064 —-a-w- C:\Windows\SysWow64\dnssd.dll 2011-07-12 18:20:54 50536 —-a-w- C:\Windows\SysWow64\jdns_sd.dll 2011-07-12 18:20:54 178536 —-a-w- C:\Windows\SysWow64\dnssdX.dll 2011-07-09 02:46:28 288768 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-07-06 01:37:00 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx 2011-07-06 01:37:00 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts 2011-06-24 05:34:53 214528 —-a-w- C:\Windows\System32\winsrv.dll 2011-06-24 05:25:49 338432 —-a-w- C:\Windows\System32\conhost.exe 2011-06-15 10:02:23 212992 —-a-w- C:\Windows\System32\odbctrac.dll 2011-06-15 10:02:23 163840 —-a-w- C:\Windows\System32\odbccp32.dll 2011-06-15 10:02:23 106496 —-a-w- C:\Windows\System32\odbccu32.dll 2011-06-15 10:02:23 106496 —-a-w- C:\Windows\System32\odbccr32.dll 2011-06-15 08:55:19 86016 —-a-w- C:\Windows\SysWow64\odbccu32.dll 2011-06-15 08:55:19 81920 —-a-w- C:\Windows\SysWow64\odbccr32.dll 2011-06-15 08:55:19 319488 —-a-w- C:\Windows\SysWow64\odbcjt32.dll 2011-06-15 08:55:19 163840 —-a-w- C:\Windows\SysWow64\odbctrac.dll 2011-06-15 08:55:19 122880 —-a-w- C:\Windows\SysWow64\odbccp32.dll . ============= FINISH: 21:55:20.68 ===============
Riak,

I don't think your problem is malware related. My suggestion is that you post in the Windows forum and let the Tech Team take a shot at getting you straightened out. When you post there… please include a link back to this thread so that they can see the information in the logs you provided.

But first.. we need to clean up our tools…

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved (as far as malware is concerned). :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI