Hi CatByte
nothing to lose by doing the scans so here goes.
results
DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 12:04:14 on 2011-12-23
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.8183.5747 [GMT 0:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
G:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
G:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe
C:\Windows\system32\svchost.exe -k imgsvc
G:\Program Files\Logitech\SetPointP\SetPoint.exe
G:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
G:\Program Files (x86)\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
G:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
G:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
C:\Program Files (x86)\Brownie\BrStsW64.exe
G:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
G:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe
C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
G:\Program Files\AVAST Software\Avast\AvastUI.exe
G:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe
H:\Program Files (x86)\iTunes\iTunesHelper.exe
G:\Program Files (x86)\KeyScrambler\KeyScrambler.exe
G:\Program Files (x86)\KeyScrambler\x64\KeyScrambler.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Brownie\brpjp04a.exe
C:\Program Files (x86)\Brownie\brpjp04a.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Windows\SysWOW64\WinMsgBalloonServer.exe
C:\Windows\SysWOW64\WinMsgBalloonClient.exe
G:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\splwow64.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/ig?hl=en&source=iglk
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [SUPERAntiSpyware] G:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: []
uRun: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
mRun: [TrueImageMonitor.exe] G:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
mRun: [StartCCC] "G:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [RemoteControl9] "G:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9\PDVD9Serv.exe"
mRun: [BrStsWnd] C:\Program Files (x86)\Brownie\BrstsW64.exe Autorun
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [avast] "G:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [NSU_agent] "C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe"
mRun: [iTunesHelper] "H:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [KeyScrambler] G:\Program Files (x86)\KeyScrambler\keyscrambler.exe /a
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AVERHI~1.LNK - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AVERQU~1.LNK - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: E&xport to Microsoft Excel - G:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - G:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - G:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{198217FF-D50A-4C27-A98E-A59C83A452AA} : NameServer = 8.26.56.26,156.154.70.22
TCP: Interfaces\{198217FF-D50A-4C27-A98E-A59C83A452AA} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{22458A6F-89C9-4F0E-A226-8341BCFDDF00} : NameServer = 8.26.56.26,156.154.70.22
Notify: !SASWinLogon - G:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll
AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - G:\Program Files (x86)\SUPERAntiSpyware\SASSEH.DLL
mASetup: {F0173905-8498-4452-A4BD-EC689AFA6B3A} - "%ProgramFiles%\Common Files\Sage SBD\ForceEIRRegistration.exe"
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
mRun-x64: [TrueImageMonitor.exe] G:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
mRun-x64: [StartCCC] "G:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [RemoteControl9] "G:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9\PDVD9Serv.exe"
mRun-x64: [BrStsWnd] C:\Program Files (x86)\Brownie\BrstsW64.exe Autorun
mRun-x64: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [avast] "G:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [NSU_agent] "C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe"
mRun-x64: [iTunesHelper] "H:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [KeyScrambler] G:\Program Files (x86)\KeyScrambler\keyscrambler.exe /a
AppInit_DLLs-X64: C:\Windows\SysWOW64\guard32.dll
SEH-X64: SABShellExecuteHook Class: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - G:\Program Files (x86)\SUPERAntiSpyware\SASSEH.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 ahcix64s;ahcix64s;C:\Windows\system32\DRIVERS\ahcix64s.sys –> C:\Windows\system32\DRIVERS\ahcix64s.sys [?]
R0 hotcore3;hc3ServiceName;C:\Windows\system32\DRIVERS\hotcore3.sys –> C:\Windows\system32\DRIVERS\hotcore3.sys [?]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);C:\Windows\system32\DRIVERS\tdrpm273.sys –> C:\Windows\system32\DRIVERS\tdrpm273.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys –> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys –> C:\Windows\system32\drivers\aswSP.sys [?]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys –> C:\Windows\system32\DRIVERS\cmdguard.sys [?]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys –> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/04/02 23:01:17];G:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9\000.fcl [2009-2-28 146928]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 afcdpsrv;Acronis Nonstop Backup Service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2011-6-2 3246040]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?]
R2 AMD_RAIDXpert;AMD RAIDXpert;C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe [2009-3-15 122880]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys –> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys –> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;G:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-12-3 44768]
R2 AVerRemote;AVerRemote;C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2011-3-20 348160]
R2 AVerScheduleService;AVerScheduleService;C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2011-3-20 397312]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-4 503080]
R2 Sage SData Service;Sage SData Service;C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe [2011-7-28 53248]
R3 afcdp;afcdp;C:\Windows\system32\DRIVERS\afcdp.sys –> C:\Windows\system32\DRIVERS\afcdp.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AVerA706_x64;AVerMedia A706 BDA Service;C:\Windows\system32\DRIVERS\AVerA706_x64.sys –> C:\Windows\system32\DRIVERS\AVerA706_x64.sys [?]
R3 DKRtWrt;DKRtWrt;C:\Windows\system32\DRIVERS\DKRtWrt.sys –> C:\Windows\system32\DRIVERS\DKRtWrt.sys [?]
R3 KeyScrambler;KeyScrambler;C:\Windows\system32\drivers\keyscrambler.sys –> C:\Windows\system32\drivers\keyscrambler.sys [?]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\system32\DRIVERS\LEqdUsb.Sys –> C:\Windows\system32\DRIVERS\LEqdUsb.Sys [?]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\system32\DRIVERS\LHidEqd.Sys –> C:\Windows\system32\DRIVERS\LHidEqd.Sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S1 SASDIFSV;SASDIFSV;G:\Program Files (x86)\SUPERAntiSpyware\sasdifsv.sys [2010-2-17 12872]
S1 SASKUTIL;SASKUTIL;G:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS [2010-2-17 67656]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 FLASHSYS;FLASHSYS;C:\Program Files (x86)\MSI\Live Update 4\LU4\Flashsys64.sys [2010-4-2 15192]
S3 GenericMount;Generic Mount Driver;C:\Windows\system32\DRIVERS\GenericMount.sys –> C:\Windows\system32\DRIVERS\GenericMount.sys [?]
S3 SASENUM;SASENUM;G:\Program Files (x86)\SUPERAntiSpyware\SASENUM.SYS [2010-2-17 12872]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-12-23 07:55:08 8822856 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5BF3A29D-064E-40A7-8588-F27EF5DE4164}\mpengine.dll
2011-12-23 07:55:08 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5BF3A29D-064E-40A7-8588-F27EF5DE4164}\offreg.dll
2011-12-17 00:34:46 388096 —-a-r- C:\Users\Keith\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-16 03:56:44 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-14 21:16:44 43520 —-a-w- C:\Windows\System32\csrsrv.dll
2011-12-14 21:14:22 3145216 —-a-w- C:\Windows\System32\win32k.sys
2011-12-14 21:13:22 723456 —-a-w- C:\Windows\System32\EncDec.dll
2011-12-14 21:13:22 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-14 21:13:16 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2011-12-14 21:13:16 2048 —-a-w- C:\Windows\System32\tzres.dll
2011-12-13 09:08:31 ——– d—–w- C:\Program Files\iPod
2011-12-13 09:08:30 ——– d—–w- C:\Program Files\iTunes
2011-12-12 11:11:41 ——– d—–w- C:\Program Files (x86)\WinPcap
.
==================== Find3M ====================
.
2011-12-19 18:59:17 43248 —-a-w- C:\Windows\System32\drivers\cmdhlp.sys
2011-12-19 18:59:16 577824 —-a-w- C:\Windows\System32\drivers\cmdGuard.sys
2011-12-19 18:59:15 22696 —-a-w- C:\Windows\System32\drivers\cmderd.sys
2011-12-19 18:58:57 41200 —-a-w- C:\Windows\System32\cmdcsr.dll
2011-12-19 18:58:55 301224 —-a-w- C:\Windows\SysWow64\guard32.dll
2011-12-19 18:58:54 389840 —-a-w- C:\Windows\System32\guard64.dll
2011-12-15 00:46:42 222904 —-a-w- C:\Windows\System32\drivers\keyscrambler.sys
2011-11-28 18:01:25 41184 —-a-w- C:\Windows\avastSS.scr
2011-11-28 17:54:06 591192 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-11-28 17:52:11 66904 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-11-04 01:53:39 2309120 —-a-w- C:\Windows\System32\jscript9.dll
2011-11-04 01:44:47 1390080 —-a-w- C:\Windows\System32\wininet.dll
2011-11-04 01:44:21 1493504 —-a-w- C:\Windows\System32\inetcpl.cpl
2011-11-04 01:34:43 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2011-11-03 22:47:42 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll
2011-11-03 22:40:21 1427456 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-11-03 22:39:47 1127424 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-11-03 22:31:57 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-28 15:59:50 544768 ——w- C:\Windows\SysWow64\S18DBC32.dll
2011-10-24 14:29:02 94208 —-a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-10-24 14:29:02 69632 —-a-w- C:\Windows\SysWow64\QuickTime.qts
2011-09-29 16:29:28 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 12:17:32.36 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 31/03/2010 20:35:19
System Uptime: 23/12/2011 11:33:52 (1 hours ago)
.
Motherboard: MICRO-STAR INTERNATIONAL CO.,LTD | | 790FX-GD70(MS-7577)
Processor: AMD Phenom™ II X4 955 Processor | CPU1 | 3200/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 78 GiB total, 2.85 GiB free.
D: is CDROM (UDF)
E: is CDROM (UDF)
F: is CDROM ()
G: is FIXED (NTFS) - 49 GiB total, 46.429 GiB free.
H: is FIXED (NTFS) - 1257 GiB total, 1221.936 GiB free.
I: is FIXED (NTFS) - 279 GiB total, 276.932 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Accounts
Acoustica CD/DVD Label Maker
Acoustica MP3 CD Burner
Acronis True Image Home
Adobe AIR
Adobe Reader X (10.1.1)
Amazon Kindle For PC
AMD DnD V1.0.20
Apple Application Support
Apple Software Update
avast! Free Antivirus
AVerMedia M135-Series PCI TV Tuner 3.6.64.15
AVerMedia Media Center Plug-ins 2.0.8.0
AVerTV 3D
AVS Cover Editor [removed] (AVSMedia)
AVS DVD Copy version 1.4
Brother HL-5340D
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
ccc-core-static
CCC Help English
CyberLink PowerDVD 9
DotNet20withMsi30
DVD Decrypter (Remove Only)
eReg
Fences
fmXML version 0.3
Football Manager 2011
HiJackThis
ImTOO Audio Converter Pro
IS Update for Sage Payroll
Japanese Fonts Support For Adobe Reader X
KeyScrambler
Liveupdate4
MailWasherPro
Malwarebytes' Anti-Malware version 1.51.2.1300
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft WSE 2.0 SP3 Runtime
Microsoft_VC100_CRT_SP1_x86
MSVC80_x86_v2
MSVC90_x86
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
Nero Burning ROM 10
Nero BurningROM 10 Help (CHM)
Nero BurnRights 10
Nero BurnRights 10 Help (CHM)
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero Update
Nokia Connectivity Cable Driver
Nokia Software Updater
Nokia Suite
OpenAL
Payroll for Windows
PC Connectivity Solution
QuickTime
RAIDXpert
Realtek Ethernet Controller Driver For Windows Vista
Realtek High Definition Audio Driver
Revo Uninstaller 1.92
Sage 50 Accounts 2011
Sage 50 Accounts 2012
Sage Instant Payroll v12.00
Sage Payroll for Windows
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Groove 2007 (KB2552997)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
SUPERAntiSpyware Professional
The Lord of the Rings FREE Trial
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2596560)
WinPcap 4.1.2
.
==== Event Viewer Messages From Past Week ========
.
23/12/2011 11:36:01, Error: Service Control Manager [7000] - The SASKUTIL service failed to start due to the following error: This driver has been blocked from loading
23/12/2011 11:36:01, Error: Application Popup [1060] - \??\G:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
23/12/2011 11:34:51, Error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: This driver has been blocked from loading
23/12/2011 11:34:51, Error: Application Popup [1060] - \??\G:\Program Files (x86)\SUPERAntiSpyware\SASDIFSV.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
23/12/2011 11:34:48, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SASDIFSV SASKUTIL UimBus Uim_IM
23/12/2011 01:09:24, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
18/12/2011 14:32:05, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8a01779b000, 0x0000000000000000, 0xfffff88008d12790, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 121811-31761-01.
17/12/2011 22:05:03, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
.
==== End Of File ===========================
aswMBR.txt
aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software
Run date: 2011-12-23 12:30:33
—————————–
12:30:33.747 OS Version: Windows x64 6.1.7601 Service Pack 1
12:30:33.747 Number of processors: 4 586 0x402
12:30:33.748 ComputerName: KEITH-PC UserName: Keith
12:30:38.500 Initialize success
12:30:38.572 AVAST engine defs: 11122300
12:33:57.708 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000066
12:33:57.712 Disk 0 Vendor: Seagate_ CC38 Size: 476940MB BusType: 8
12:33:57.714 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000067
12:33:57.716 Disk 1 Vendor: AMD_____ 1.10 Size: 1287460MB BusType: 8
12:33:57.719 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000068
12:33:57.722 Disk 2 Vendor: AMD_____ 1.10 Size: 286102MB BusType: 8
12:33:59.738 Disk 0 MBR read successfully
12:33:59.746 Disk 0 MBR scan
12:33:59.753 Disk 0 Windows 7 default MBR code
12:33:59.782 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
12:33:59.792 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 80067 MB offset 206848
12:33:59.810 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 50485 MB offset 164184300
12:33:59.813 Disk 0 Partition - 00 05 Extended 346283 MB offset 267578640
12:34:00.157 Disk 0 Partition 4 00 BC BOOTWIZ0 346283 MB offset 267578703
12:34:00.193 Service scanning
12:34:01.281 Modules scanning
12:34:01.342 Disk 0 trace - called modules:
12:34:01.373 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix64s.sys
12:34:01.378 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800890a060]
12:34:01.382 3 CLASSPNP.SYS[fffff8800148c43f] -> nt!IofCallDriver -> \Device\00000066[0xfffffa8007f609c0]
12:34:01.783 AVAST engine scan C:\Windows
12:34:03.970 AVAST engine scan C:\Windows\system32
12:35:33.878 AVAST engine scan C:\Windows\system32\drivers
12:35:43.293 AVAST engine scan C:\Users\Keith
12:35:57.683 Disk 0 MBR has been saved successfully to "C:\Users\Keith\Desktop\MBR.dat"
12:35:57.688 The log file has been saved successfully to "C:\Users\Keith\Desktop\aswMBR.txt"
i have attached file MBR in a compressed zip file.
Once again thanks for your help
and Best Wishes for a happy Christmas
thanks
ralphie7