This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with something from AV [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has become infected with a trajan or virus. It keeps popping up a program that says i need to upgrade to AV.. There are pop-ups i cant get rid of. I have installed and run D.D.S. It keeps telling me it is restarting windows—. TY for any help you can give . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 1:44:38.30 on Sun 11/20/2011 Internet Explorer: 9.0.8112.16421 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6109.3603 [GMT -5:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\PROGRA~2\AVG\AVG2012\avgrsa.exe C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Windows\Explorer.EXE C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe C:\Windows\SysWOW64\bgsvcgen.exe C:\Program Files (x86)\Acer\Registration\GregHSRW.exe C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe C:\Program Files (x86)\AVG\AVG2012\avgemca.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Acer\Acer Updater\UpdaterService.exe C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe C:\Users\Phillip\AppData\Local\Akamai\netsession_win.exe C:\Program Files (x86)\Common Files\Panasonic\VideoCam Suite AutoStart\VideoCamSuiteAutoStart.exe C:\Users\Phillip\AppData\Local\Akamai\netsession_win.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe C:\Program Files (x86)\AVG\AVG2012\avgtray.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe C:\Users\Phillip\AppData\Local\Temp\0.8655315824531321.exe C:\Users\Phillip\AppData\Roaming\NggRZ99YXwUVlBz\AV Protection 2011v121.exe C:\Windows\system32\msiexec.exe C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe C:\Windows\splwow64.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Phillip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0D6QWHTO\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.cnn.com/ uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x3810&r=173603107507p0338v185w4931t24p mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x3810&r=173603107507p0338v185w4931t24p mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x3810&r=173603107507p0338v185w4931t24p uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll EB: &Research: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [Akamai NetSession Interface] C:\Users\Phillip\AppData\Local\Akamai\netsession_win.exe uRun: [NQQJJddK8fZ8234A] C:\Users\Phillip\AppData\Roaming\NggRZ99YXwUVlBz\AV Protection 2011v121.exe uRun: [InstallIQUpdater] "C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k mRun: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe mRun: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" mRun: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" mRun: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Reader Library Launcher] C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\VIDEOC~1.LNK - C:\Program Files (x86)\Common Files\Panasonic\VideoCam Suite AutoStart\VideoCamSuiteAutoStart.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} - hxxp://zone.msn.com/bingame/zpagames/zpa_hrtz.cab99160.cab DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} - hxxp://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File EB-X64: {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - No File mRun-x64: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe mRun-x64: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe mRun-x64: [PLD_FrameworkRun] c:\windows\system32\oem\setEvent.exe mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe Hosts: 127.0.0.1 www.spywareinfo.com . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2011-7-11 26704] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2011-9-13 37456] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2011-10-7 283728] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-8-8 46672] R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2011-7-11 375376] R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2009-6-2 22576] R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2009-6-2 20016] R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2009-6-2 60464] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 27136] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776] R2 Greg_Service;GRegService;C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-8-28 1150496] R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-8-12 62208] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-3-24 1153368] R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-10-20 240160] R2 vToolbarUpdater;vToolbarUpdater;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-9-23 246600] R3 AE1000;Linksys AE1000 Driver;C:\Windows\System32\drivers\ae1000w7.sys [2010-11-19 1101600] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2011-7-11 120400] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2011-7-11 29776] R3 e1yexpress;Intel® Gigabit Network Connections Driver;C:\Windows\System32\drivers\e1y60x64.sys [2009-6-10 281088] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\System32\drivers\IntcHdmi.sys [2009-10-20 138752] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-5-13 1025352] S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe [2009-9-10 305448] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-27 59392] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-5-5 1255736] . =============== Created Last 30 ================ . 2011-11-20 06:41:08 ——– d—–w- C:\Users\Phillip\AppData\Roaming\FreeFileViewer 2011-11-20 06:40:05 ——– d—–w- C:\Program Files (x86)\File Type Assistant 2011-11-20 06:39:58 ——– d—–w- C:\Program Files (x86)\FreeFileViewer 2011-11-20 06:39:48 ——– d-sh–w- C:\Windows\SysWow64\AI_RecycleBin 2011-11-20 06:39:47 ——– d—–w- C:\Program Files (x86)\W3i 2011-11-20 06:39:47 ——– d—–w- C:\PROGRA~3\W3i 2011-11-20 06:37:40 2894336 —-a-w- C:\Users\Phillip\AppData\Roaming\java.exe 2011-11-20 06:31:56 2894336 —-a-w- C:\Users\Phillip\AppData\Roaming\iexplore.exe 2011-11-20 06:17:38 ——– d—–w- C:\Users\Phillip\AppData\Roaming\r3pnn44aH 2011-11-20 06:17:38 ——– d—–w- C:\Users\Phillip\AppData\Roaming\oVrzzNNtA0uS2b 2011-11-20 06:17:31 ——– d—–w- C:\Users\Phillip\AppData\Roaming\BXwwjUCelBrzNx1 2011-11-20 06:17:30 ——– d—–w- C:\Users\Phillip\AppData\Roaming\NggRZ99YXwUVlBz 2011-11-20 06:17:30 ——– d—–w- C:\Users\Phillip\AppData\Roaming\HOOBBzz0ycAiDoF 2011-11-20 04:50:39 ——– d—–w- C:\Users\Phillip\AppData\Local\{8F9E82CF-2729-4385-991D-65B3AC81476C} 2011-11-19 16:50:18 ——– d—–w- C:\Users\Phillip\AppData\Local\{150E4D06-6A44-4D8E-8BA3-4D59DD9A4432} 2011-11-19 04:49:58 ——– d—–w- C:\Users\Phillip\AppData\Local\{43599E48-F2AD-49F6-9FAF-B849D2744143} 2011-11-18 16:49:37 ——– d—–w- C:\Users\Phillip\AppData\Local\{1E2EF693-F6E7-4418-AA0D-2F1017151AFD} 2011-11-18 16:49:27 ——– d—–w- C:\Users\Phillip\AppData\Local\{BAF715C8-E46C-4888-98E4-1946BD87FD17} 2011-11-18 04:49:03 ——– d—–w- C:\Users\Phillip\AppData\Local\{BCA877DD-D9A0-403A-843E-A8E5D0F6B24D} 2011-11-18 04:48:53 ——– d—–w- C:\Users\Phillip\AppData\Local\{9B7CFFED-4EAE-4442-8B27-74FB2FA578BB} 2011-11-17 16:48:42 ——– d—–w- C:\Users\Phillip\AppData\Local\{84451F4A-3540-41C0-AD67-318F98DC099D} 2011-11-17 16:48:32 ——– d—–w- C:\Users\Phillip\AppData\Local\{58957285-5FDE-4E15-9356-D952B42A4061} 2011-11-17 04:48:21 ——– d—–w- C:\Users\Phillip\AppData\Local\{AF6F5A02-9C01-490B-973B-FFA03DBDCCF0} 2011-11-17 04:48:11 ——– d—–w- C:\Users\Phillip\AppData\Local\{27B95A28-EECE-42A1-A289-D85BA8FAA692} 2011-11-16 16:48:00 ——– d—–w- C:\Users\Phillip\AppData\Local\{6CDEA015-8010-40C2-A5D5-389A78932145} 2011-11-16 16:47:47 ——– d—–w- C:\Users\Phillip\AppData\Local\{5974A0A0-F6F4-4B79-ABAF-0285AE406028} 2011-11-16 04:47:36 ——– d—–w- C:\Users\Phillip\AppData\Local\{38B13F7F-8276-4AC2-BFE8-32BD48A72715} 2011-11-16 04:47:26 ——– d—–w- C:\Users\Phillip\AppData\Local\{975FD21D-D88E-452D-A28E-F1723C43B591} 2011-11-15 16:47:15 ——– d—–w- C:\Users\Phillip\AppData\Local\{A62C6C40-A943-42FE-86E6-28D9EA0EC01F} 2011-11-15 16:47:05 ——– d—–w- C:\Users\Phillip\AppData\Local\{E5E168BA-1D33-48DF-BD22-4A873AA7F8E5} 2011-11-15 04:46:54 ——– d—–w- C:\Users\Phillip\AppData\Local\{FBB8837B-A3B4-4A16-9C7A-25323CAC2261} 2011-11-15 04:46:44 ——– d—–w- C:\Users\Phillip\AppData\Local\{D50C99D4-1545-4EFF-A389-C0C56F5F9CE7} 2011-11-14 16:46:33 ——– d—–w- C:\Users\Phillip\AppData\Local\{22DB6408-F4EE-430A-A814-A3E971794AE3} 2011-11-14 16:46:23 ——– d—–w- C:\Users\Phillip\AppData\Local\{87C19EC5-CF60-4EB4-8924-83CD68C9C157} 2011-11-14 04:46:12 ——– d—–w- C:\Users\Phillip\AppData\Local\{BFFD01C0-A1E6-4B55-AB32-A3D7500BEF9F} 2011-11-14 04:46:02 ——– d—–w- C:\Users\Phillip\AppData\Local\{00537C69-A3C7-45A5-A391-DC0B0853040E} 2011-11-13 16:45:51 ——– d—–w- C:\Users\Phillip\AppData\Local\{4E5C3090-D91C-4DDC-8C27-35C6DE6E5FE2} 2011-11-13 16:45:41 ——– d—–w- C:\Users\Phillip\AppData\Local\{176C06E1-AA35-4938-95D6-9A1164A936D5} 2011-11-13 04:45:30 ——– d—–w- C:\Users\Phillip\AppData\Local\{E412BCD1-9F3F-47B8-A163-18D720B9DCF7} 2011-11-13 04:45:20 ——– d—–w- C:\Users\Phillip\AppData\Local\{32730EBC-7123-46E1-9B78-E08A9D17BA24} 2011-11-12 16:45:09 ——– d—–w- C:\Users\Phillip\AppData\Local\{68939F3D-6A53-43EC-B5E4-ED82B2652D9F} 2011-11-12 16:44:59 ——– d—–w- C:\Users\Phillip\AppData\Local\{A8535160-1E91-48EA-99F7-E2FCB8D5E158} 2011-11-12 04:44:48 ——– d—–w- C:\Users\Phillip\AppData\Local\{DE4FCD5E-8C06-418A-B00E-7285A36B89B8} 2011-11-12 04:44:39 ——– d—–w- C:\Users\Phillip\AppData\Local\{AA30859E-EFDD-4F2D-9CB8-52278EC06D24} 2011-11-11 16:44:28 ——– d—–w- C:\Users\Phillip\AppData\Local\{BA90B12D-2631-46E8-991F-22F4DA3FE73E} 2011-11-11 16:44:18 ——– d—–w- C:\Users\Phillip\AppData\Local\{FA365EA1-5D95-449A-9DE7-62543DFD45AD} 2011-11-11 04:44:07 ——– d—–w- C:\Users\Phillip\AppData\Local\{9DC6148D-9089-4206-8AED-F06CDCDAAD7A} 2011-11-11 04:43:57 ——– d—–w- C:\Users\Phillip\AppData\Local\{88766DA6-D1A5-4331-8A39-124BAE316F6F} 2011-11-10 16:43:46 ——– d—–w- C:\Users\Phillip\AppData\Local\{22C25439-FA4C-4706-987D-61286A514AAB} 2011-11-10 16:43:36 ——– d—–w- C:\Users\Phillip\AppData\Local\{713E92CC-5CD1-4BA5-9871-585E212983E0} 2011-11-10 04:43:25 ——– d—–w- C:\Users\Phillip\AppData\Local\{7A706121-23BE-4E92-B158-7FBCFA35B20E} 2011-11-10 04:43:15 ——– d—–w- C:\Users\Phillip\AppData\Local\{FF337107-F113-43BA-AE50-135FEC0B9714} 2011-11-10 00:07:05 ——– d—–w- C:\Users\Phillip\AppData\Local\Akamai 2011-11-09 16:43:04 ——– d—–w- C:\Users\Phillip\AppData\Local\{082ED654-EA7E-452A-9B43-3D0490E98721} 2011-11-09 16:42:54 ——– d—–w- C:\Users\Phillip\AppData\Local\{885CED35-F5AE-43C3-A401-868333DDD7BD} 2011-11-09 04:42:22 ——– d—–w- C:\Users\Phillip\AppData\Local\{B13134CA-02D1-4F85-9883-293432400A9B} 2011-11-09 04:42:12 ——– d—–w- C:\Users\Phillip\AppData\Local\{2B6471D2-AC3C-4B06-94C1-3C8307CF02D1} 2011-11-08 21:30:55 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll 2011-11-08 21:30:55 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll 2011-11-08 21:30:55 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-11-08 21:30:54 3144704 —-a-w- C:\Windows\System32\win32k.sys 2011-11-08 16:42:01 ——– d—–w- C:\Users\Phillip\AppData\Local\{77DD3070-1818-4181-A91D-4C2477CC4F90} 2011-11-08 16:41:51 ——– d—–w- C:\Users\Phillip\AppData\Local\{1DD27FFB-1443-4502-A499-47882CF028C4} 2011-11-08 04:41:40 ——– d—–w- C:\Users\Phillip\AppData\Local\{CBC0250E-2FC8-4287-8649-3980541DB269} 2011-11-08 04:41:29 ——– d—–w- C:\Users\Phillip\AppData\Local\{5909A721-51A0-40EE-978E-1C0A738B81A1} 2011-11-07 18:37:35 ——– d—–w- C:\Users\Phillip\AppData\Local\DOSBox 2011-11-07 18:37:24 ——– d—–w- C:\Program Files (x86)\DOSBox-0.74 2011-11-07 16:41:18 ——– d—–w- C:\Users\Phillip\AppData\Local\{97A38677-52B0-4386-A643-F56E7CF215D3} 2011-11-07 16:41:09 ——– d—–w- C:\Users\Phillip\AppData\Local\{0ED5FC65-CD05-4B09-AB93-F92E59C567CB} 2011-11-07 04:40:57 ——– d—–w- C:\Users\Phillip\AppData\Local\{9BE51098-3624-4B00-B1ED-984F5B71AAA1} 2011-11-07 04:40:47 ——– d—–w- C:\Users\Phillip\AppData\Local\{9A36E708-2B38-4835-9ACC-4C3C5ABAE05D} 2011-11-06 16:40:36 ——– d—–w- C:\Users\Phillip\AppData\Local\{AF750A14-5C73-4D05-8006-703C200F0921} 2011-11-06 16:40:26 ——– d—–w- C:\Users\Phillip\AppData\Local\{85F93782-3A35-4EE8-B7F3-30B05E288991} 2011-11-06 04:40:16 ——– d—–w- C:\Users\Phillip\AppData\Local\{64C84684-2924-4D05-BD61-B30C25875FB4} 2011-11-06 04:40:06 ——– d—–w- C:\Users\Phillip\AppData\Local\{D30C811F-C316-4AD5-A467-C0F59E2D9BFC} 2011-11-05 16:39:55 ——– d—–w- C:\Users\Phillip\AppData\Local\{3BC14ECD-E179-47B6-954A-9DC4DD089A8F} 2011-11-05 16:39:45 ——– d—–w- C:\Users\Phillip\AppData\Local\{073BCB0B-B87F-4A30-9F66-36AFEB9EC970} 2011-11-05 04:39:34 ——– d—–w- C:\Users\Phillip\AppData\Local\{48025D69-3E6E-4A95-B2B6-19F88A42735D} 2011-11-05 04:39:24 ——– d—–w- C:\Users\Phillip\AppData\Local\{B51D120B-FC35-4616-9C4A-729670E5B3AD} 2011-11-04 16:39:13 ——– d—–w- C:\Users\Phillip\AppData\Local\{30E47D29-5FC3-4375-8A41-50F1D7155910} 2011-11-04 16:39:03 ——– d—–w- C:\Users\Phillip\AppData\Local\{40D26283-2243-4225-A757-5A1D7B188F56} 2011-11-04 04:38:52 ——– d—–w- C:\Users\Phillip\AppData\Local\{14BA8FA9-0296-45EF-9541-7A068191ADA4} 2011-11-04 04:38:42 ——– d—–w- C:\Users\Phillip\AppData\Local\{F49E71C3-4388-4CCF-B9AC-B89FD97368B8} 2011-11-03 16:38:31 ——– d—–w- C:\Users\Phillip\AppData\Local\{39229A95-73EA-45C0-9713-E69E1FB888FA} 2011-11-03 16:38:21 ——– d—–w- C:\Users\Phillip\AppData\Local\{98DC8C1D-F00A-4A82-99AE-6C3194401E42} 2011-11-03 04:38:10 ——– d—–w- C:\Users\Phillip\AppData\Local\{005EA086-1C2A-4154-A645-9CB3FA8A0654} 2011-11-03 04:38:00 ——– d—–w- C:\Users\Phillip\AppData\Local\{25C07E1D-D1C1-42EC-9829-598A7B1F61B1} 2011-11-02 16:37:49 ——– d—–w- C:\Users\Phillip\AppData\Local\{7B78AEE0-6468-4BA7-BFEB-0D45CA6EDB28} 2011-11-02 16:37:39 ——– d—–w- C:\Users\Phillip\AppData\Local\{F7B3E9E0-4302-458B-9446-F32C7BF4944F} 2011-11-02 04:37:28 ——– d—–w- C:\Users\Phillip\AppData\Local\{48265878-4A5B-4BC4-8FCF-6519280B708B} 2011-11-02 04:37:18 ——– d—–w- C:\Users\Phillip\AppData\Local\{49E6AB3C-7DC3-4E96-9C89-1068BEE14B22} 2011-11-01 16:37:07 ——– d—–w- C:\Users\Phillip\AppData\Local\{6D8AC2C3-D6D8-4C98-AC01-B3A039054CB1} 2011-11-01 16:36:57 ——– d—–w- C:\Users\Phillip\AppData\Local\{07039CF9-1542-4AF9-9E12-5A8E2D7AC323} 2011-11-01 04:36:46 ——– d—–w- C:\Users\Phillip\AppData\Local\{4797BA8B-6D73-4AC7-AFFA-580DFA88935E} 2011-11-01 04:36:36 ——– d—–w- C:\Users\Phillip\AppData\Local\{D06AC217-4B82-4843-A478-64BB1A46114A} 2011-10-31 16:36:26 ——– d—–w- C:\Users\Phillip\AppData\Local\{1F9C39AE-8CD8-479F-A7B1-BB85DC144F68} 2011-10-31 16:36:16 ——– d—–w- C:\Users\Phillip\AppData\Local\{688B175F-D0E9-467E-A63C-D314E1B57074} 2011-10-31 04:36:05 ——– d—–w- C:\Users\Phillip\AppData\Local\{A461A0D9-DD38-4347-8626-C1810B75FBFD} 2011-10-31 04:35:55 ——– d—–w- C:\Users\Phillip\AppData\Local\{58046AEC-A039-4358-B898-E2CC0864E062} 2011-10-30 16:35:44 ——– d—–w- C:\Users\Phillip\AppData\Local\{EFD96FD5-B236-47D6-8136-2A992F5A1ABA} 2011-10-30 16:35:34 ——– d—–w- C:\Users\Phillip\AppData\Local\{5F6AC572-8AD9-4AA8-B1EA-74596B77FB3C} 2011-10-30 04:35:23 ——– d—–w- C:\Users\Phillip\AppData\Local\{033C32E6-C329-4D32-97A1-A557F37082C3} 2011-10-30 04:35:13 ——– d—–w- C:\Users\Phillip\AppData\Local\{A94A4115-1623-4509-9AF9-31DAABE03F49} 2011-10-29 16:35:02 ——– d—–w- C:\Users\Phillip\AppData\Local\{5F13CBF6-CD63-4699-A7D4-F683F72B5D51} 2011-10-29 16:34:51 ——– d—–w- C:\Users\Phillip\AppData\Local\{88785DD0-A2E1-4AE3-BB74-0092C98D726F} 2011-10-29 04:34:40 ——– d—–w- C:\Users\Phillip\AppData\Local\{3BA99321-CBE2-47C3-B85B-1284936C94B2} 2011-10-29 04:34:30 ——– d—–w- C:\Users\Phillip\AppData\Local\{96A5719E-6F5B-429B-8274-4A12B3A487CE} 2011-10-28 16:34:20 ——– d—–w- C:\Users\Phillip\AppData\Local\{303B4ADF-CDAC-473F-8EA8-E5B740E1E19A} 2011-10-28 16:34:10 ——– d—–w- C:\Users\Phillip\AppData\Local\{693C6123-7E43-41C0-ADEF-FBC36302E659} 2011-10-28 04:33:59 ——– d—–w- C:\Users\Phillip\AppData\Local\{23257ACA-D2F0-40DE-B4A9-E6FA3242BFE7} 2011-10-28 04:33:49 ——– d—–w- C:\Users\Phillip\AppData\Local\{DBDE45DD-C2A5-47D5-A342-88400AE8B326} 2011-10-27 16:33:38 ——– d—–w- C:\Users\Phillip\AppData\Local\{635D94F0-CB9F-40D8-AA65-51F44CB90C7A} 2011-10-27 16:33:28 ——– d—–w- C:\Users\Phillip\AppData\Local\{3020DAA5-194C-49A8-862E-CCD685A794D0} 2011-10-27 04:33:17 ——– d—–w- C:\Users\Phillip\AppData\Local\{24D1C5F1-CB0D-4608-95FB-A458D618162E} 2011-10-27 04:33:05 ——– d—–w- C:\Users\Phillip\AppData\Local\{1DE0878A-A1F4-45F1-BDB8-D61613A4E913} 2011-10-26 16:32:54 ——– d—–w- C:\Users\Phillip\AppData\Local\{09078683-1B46-4D19-A19F-B1FA396E8262} 2011-10-26 16:32:44 ——– d—–w- C:\Users\Phillip\AppData\Local\{607F4797-75F4-4D28-AEED-873A8AFFFCE7} 2011-10-26 04:32:32 ——– d—–w- C:\Users\Phillip\AppData\Local\{C2463E97-8F84-4B07-9824-9439CF7627A8} 2011-10-26 04:32:22 ——– d—–w- C:\Users\Phillip\AppData\Local\{580A9B87-80EC-4F0E-A71E-8CC163B22CB5} 2011-10-25 16:32:11 ——– d—–w- C:\Users\Phillip\AppData\Local\{BE71229D-A252-43B7-8CB8-20ED15797FFC} 2011-10-25 16:32:01 ——– d—–w- C:\Users\Phillip\AppData\Local\{FD67C38D-4CEC-47CD-A689-6FEF4BEA1345} 2011-10-25 04:31:50 ——– d—–w- C:\Users\Phillip\AppData\Local\{A0EBDE51-3F76-41A6-9E83-603C2E252117} 2011-10-25 04:31:40 ——– d—–w- C:\Users\Phillip\AppData\Local\{7E73F968-78BB-4A82-A9BE-75367AE69309} 2011-10-24 16:31:29 ——– d—–w- C:\Users\Phillip\AppData\Local\{315EDE64-3C1F-40BB-A398-D708916D6306} 2011-10-24 16:31:19 ——– d—–w- C:\Users\Phillip\AppData\Local\{932C724C-3AAA-435D-B3F8-B065EE60BF2F} 2011-10-24 04:31:08 ——– d—–w- C:\Users\Phillip\AppData\Local\{CCB5757E-CCFE-4C7D-BA63-5E30AEB956C5} 2011-10-24 04:30:58 ——– d—–w- C:\Users\Phillip\AppData\Local\{82DFD50F-AEA6-4F1B-88A2-7CB881D9804C} 2011-10-23 16:30:47 ——– d—–w- C:\Users\Phillip\AppData\Local\{2B10ADD7-B48B-400F-AFE5-4B54CB4B1E0E} 2011-10-23 16:30:37 ——– d—–w- C:\Users\Phillip\AppData\Local\{82003948-22E4-42AA-BA76-94A6EED7B351} 2011-10-23 04:30:26 ——– d—–w- C:\Users\Phillip\AppData\Local\{DEB7529B-E754-4749-9E68-E80DE4CD14D6} 2011-10-23 04:30:16 ——– d—–w- C:\Users\Phillip\AppData\Local\{8918DEC0-BC9F-4F1F-BA70-343E7970C7B4} 2011-10-22 16:30:05 ——– d—–w- C:\Users\Phillip\AppData\Local\{5A83FF5E-4931-42C2-A1D9-07C58FE56AA4} 2011-10-22 16:29:54 ——– d—–w- C:\Users\Phillip\AppData\Local\{2908340B-CF8B-478D-A394-CFB9932A0D08} 2011-10-22 04:29:43 ——– d—–w- C:\Users\Phillip\AppData\Local\{E07EBEB9-329A-42EE-AAA2-1D1F6F1C9519} 2011-10-22 04:29:33 ——– d—–w- C:\Users\Phillip\AppData\Local\{53DC03BF-C73D-4569-B881-295C7D29EEB2} 2011-10-21 16:29:22 ——– d—–w- C:\Users\Phillip\AppData\Local\{6456682A-18B8-4FD5-A9FD-14BB05DA41C6} 2011-10-21 16:29:12 ——– d—–w- C:\Users\Phillip\AppData\Local\{A2FAABA8-25F0-4822-BF7B-63C0D83040D9} .==================== Find3M ==================== . 2011-11-19 06:34:13 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-10-07 10:23:46 283728 —-a-w- C:\Windows\System32\drivers\avgldx64.sys 2011-09-13 10:30:08 37456 —-a-w- C:\Windows\System32\drivers\avgrkx64.sys 2011-09-01 05:24:07 2309120 —-a-w- C:\Windows\System32\jscript9.dll 2011-09-01 05:17:57 1389056 —-a-w- C:\Windows\System32\wininet.dll 2011-09-01 05:12:04 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-09-01 02:35:59 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-09-01 02:28:15 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-09-01 02:22:54 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-08-27 05:37:49 861696 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-27 05:37:48 331776 —-a-w- C:\Windows\System32\oleacc.dll 2011-08-27 04:26:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-27 04:26:27 233472 —-a-w- C:\Windows\SysWow64\oleacc.dll . ============= FINISH: 1:45:10.90 ===============
Hi watertownbard, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download OTL to your desktop.
  • Right click on OTL.exe and click "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    conserv.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Download aswMBR.exe to your desktop.

Right click on aswMBR.exe and click "Run as Administrator"click the to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • both OTL logs
  • aswMBR log
TY for your help. when i attempted to download OTL i got a message saying that it could not be downloaded and OTL was a virus. I tried to override but i was not allowed

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI