This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

A trojan [Closed]

58 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a Dell Inspirion laptop which started having trouble accessing the internet about a month or so ago. The laptop now has trouble even staying on. Sometimes it goes to a blue screen with alot of words on it and then shuts off. A virus scan from AVG detected about 6 trojans.
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
β€”β€”β€”

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
β€”β€”β€”-
aswMBR version 0.9.9.1665 CopyrightΒ© 2011 AVAST Software Run date: 2012-05-30 22:15:25 —————————– 22:15:25.857 OS Version: Windows x64 6.1.7600 22:15:25.857 Number of processors: 2 586 0x603 22:15:25.857 ComputerName: BRITTANY-PC UserName: Brittany 22:15:29.207 Initialize success 22:15:34.397 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005e 22:15:34.397 Disk 0 Vendor: WDC_WD32 01.0 Size: 305245MB BusType: 11 22:15:34.397 Device \Driver\amd_sata -> MajorFunction fffffa80034745c4 22:15:34.407 Disk 0 MBR read successfully 22:15:34.407 Disk 0 MBR scan 22:15:34.407 Disk 0 Windows 7 default MBR code 22:15:34.417 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048 22:15:34.427 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848 22:15:34.437 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290143 MB offset 30926848 22:15:34.487 SubSystem.Windows: C:\Windows\system32\consrv.dll **SUSPICIOUS** 22:15:34.497 Disk 0 scanning C:\Windows\system32\drivers 22:15:46.137 Service scanning 22:16:02.777 Service FastUserSwitchingCompatibility C:\Windows\C:\Windows\system32\FastUserSwitchingCompatibilityex.dll **LOCKED** 123 22:16:48.458 Modules scanning 22:16:48.868 Disk 0 trace - called modules: 22:16:48.875 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys >>UNKNOWN [0xfffffa80034745c4]<< 22:16:48.881 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8002dd9630] 22:16:48.909 3 CLASSPNP.SYS[fffff8800192443f] -> nt!IofCallDriver -> [0xfffffa8002da5040] 22:16:48.916 5 amd_xata.sys[fffff8800107b7a8] -> nt!IofCallDriver -> \Device\0000005e[0xfffffa8002d9f060] 22:16:48.924 \Driver\amd_sata[0xfffffa80033db2f0] -> IRP_MJ_CREATE -> 0xfffffa80034745c4 22:16:48.932 Scan finished successfully 22:17:11.808 Disk 0 MBR has been saved successfully to "C:\Users\Brittany\Documents\MBR.dat" 22:17:11.828 The log file has been saved successfully to "C:\Users\Brittany\Documents\aswMBR.txt"
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
β€”β€”β€”-

Please double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • Click the Scan button to start scan.
  • When scan finishes, press the Fix Button. Once the Fix is done, press the Save Log button and save the log to your desktop. You need to reboot your computer when its done before you do anything else, then post the log that will be on your desktop.

[external image: Posted Image]
Click the image to enlarge it
β€”β€”β€”-

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hey for some reason the fix button on the aswMBR will not work after the scan. I am currently trying to get the combofix to run but the computer keeps freezing up. I wouldnt be opposed to a total reinstall but my daughter lost her cd. I am still trying the combo fix, if it works, i will post the logs.
Hi,

Let's do this….

Delete your copy of ComboFix from your Desktop. Download a fresh copy, but BEFORE you download it, rename it vageta.com and download it to your C:\ folder. Once it is there, give it a run.
Hi,

Let's do this….

Delete your copy of ComboFix from your Desktop. Download a fresh copy, but BEFORE you download it, rename it vageta.com and download it to your C:\ folder. Once it is there, give it a run.
When i am downloading it, it automatically is going to downloads folder and it doesnt appear that i can rename it before the download? But I am not THAT computer savvy. Nevermind, I figured it out. Is it supposed to take like an hour? :pullhair:
I finally managed to get combofix to run and complete. I can finally start the computer up in regular mode and use internet explorer BUT very very slowly. I am sure there are still things that we need to do. I am really amazed that it can access the internet now though! ComboFix 12-05-31.02 - Brittany 05/31/2012 20:54:21.3.2 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1680 [GMT -5:00] Running from: C:\vageta.com AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\svchost.exe . β€”- Previous Run β€”β€”- . c:\programdata\CGWGCnHLqP.exe c:\programdata\eddfdacbbbbbfdct.exe c:\programdata\gwFlGEU2ZvADHH c:\programdata\gwFlGEU2ZvADHH.exe c:\programdata\qd9yFYczockCad c:\programdata\qd9yFYczockCad.exe c:\users\Brittany\AppData\Local\kvwaes.exe c:\users\Brittany\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SMART_HDD.lnk c:\users\Brittany\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SMART HDD\SMART HDD.lnk c:\users\Brittany\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SMART HDD\Uninstall SMART HDD.lnk c:\windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\GAC_64\Desktop.ini c:\windows\ff.exe c:\windows\iun6002.exe c:\windows\svchost.exe c:\windows\system32\dds_trash_log.cmd c:\windows\SysWow64\FastUserSwitchingCompatibilityex.dll . . ((((((((((((((((((((((((( Files Created from 2012-05-01 to 2012-06-01 ))))))))))))))))))))))))))))))) . . 2012-06-01 02:04 . 2012-06-01 02:04 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-06-01 01:19 . 2012-06-01 01:19 ——– d—–w- C:\b063d835c6d2de29cd 2012-05-30 02:41 . 2012-05-30 13:27 ——– d—–w- C:\0371d38db3e5a2add34d943d 2012-05-30 02:33 . 2012-05-30 02:33 388096 β€”-a-r- c:\users\Brittany\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-05-30 02:33 . 2012-05-30 02:33 ——– d—–w- c:\program files (x86)\Trend Micro 2012-05-30 02:23 . 2012-03-17 07:55 75632 β€”-a-w- c:\windows\system32\drivers\partmgr.sys 2012-05-30 02:18 . 2012-05-30 02:18 ——– d—–w- c:\users\Brittany\AppData\Roaming\AVG2012 2012-05-30 02:16 . 2012-05-30 02:16 ——– d—–w- c:\users\Brittany\AppData\Local\AVG Secure Search 2012-05-30 02:14 . 2012-05-30 02:17 ——– d—–w- c:\programdata\AVG Secure Search 2012-05-30 02:14 . 2012-05-30 02:14 ——– d—–w- c:\program files (x86)\Common Files\AVG Secure Search 2012-05-30 02:14 . 2012-05-30 13:49 ——– d—–w- c:\program files (x86)\AVG Secure Search 2012-05-30 02:12 . 2012-05-30 02:12 ——– d—–w- c:\windows\SysWow64\drivers\AVG 2012-05-30 02:11 . 2012-06-01 00:36 ——– d—–w- c:\windows\system32\drivers\AVG 2012-05-30 02:11 . 2012-05-30 02:25 ——– d—–w- c:\programdata\AVG2012 2012-05-30 02:11 . 2012-05-30 02:11 ——– d—–w- C:\$AVG 2012-05-30 02:02 . 2012-05-30 02:02 ——– d—–w- c:\program files (x86)\AVG 2012-05-30 00:46 . 2012-05-30 00:46 ——– d—–w- C:\1c2d2d9ca812a7a53a35910d93 2012-05-27 08:19 . 2012-04-02 05:26 1732096 β€”-a-w- c:\program files\Windows Journal\NBDoc.DLL 2012-05-27 08:19 . 2012-04-02 05:24 1367552 β€”-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2012-05-27 08:19 . 2012-04-02 04:40 936960 β€”-a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2012-05-27 08:19 . 2012-04-02 05:24 1402880 β€”-a-w- c:\program files\Windows Journal\JNWDRV.dll 2012-05-27 08:19 . 2012-04-02 05:24 1393664 β€”-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2012-05-07 22:42 . 2012-05-07 22:42 ——– d—–w- C:\95953255d67f06028941d8e2be60 . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-19 09:50 . 2012-04-19 09:50 28480 β€”-a-w- c:\windows\system32\drivers\avgidsha.sys 2012-03-19 10:17 . 2012-03-19 10:17 383808 β€”-a-w- c:\windows\system32\drivers\avgtdia.sys 2012-03-19 01:24 . 2012-03-19 01:24 86528 β€”-a-w- c:\windows\SysWow64\iesysprep.dll 2012-03-19 01:24 . 2012-03-19 01:24 76800 β€”-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-03-19 01:24 . 2012-03-19 01:24 74752 β€”-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-03-19 01:24 . 2012-03-19 01:24 74752 β€”-a-w- c:\windows\SysWow64\iesetup.dll 2012-03-19 01:24 . 2012-03-19 01:24 63488 β€”-a-w- c:\windows\SysWow64\tdc.ocx 2012-03-19 01:24 . 2012-03-19 01:24 48640 β€”-a-w- c:\windows\SysWow64\mshtmler.dll 2012-03-19 01:24 . 2012-03-19 01:24 420864 β€”-a-w- c:\windows\SysWow64\vbscript.dll 2012-03-19 01:24 . 2012-03-19 01:24 367104 β€”-a-w- c:\windows\SysWow64\html.iec 2012-03-19 01:24 . 2012-03-19 01:24 35840 β€”-a-w- c:\windows\SysWow64\imgutil.dll 2012-03-19 01:24 . 2012-03-19 01:24 2382848 β€”-a-w- c:\windows\SysWow64\mshtml.tlb 2012-03-19 01:24 . 2012-03-19 01:24 23552 β€”-a-w- c:\windows\SysWow64\licmgr10.dll 2012-03-19 01:24 . 2012-03-19 01:24 1798656 β€”-a-w- c:\windows\SysWow64\jscript9.dll 2012-03-19 01:24 . 2012-03-19 01:24 161792 β€”-a-w- c:\windows\SysWow64\msls31.dll 2012-03-19 01:24 . 2012-03-19 01:24 152064 β€”-a-w- c:\windows\SysWow64\wextract.exe 2012-03-19 01:24 . 2012-03-19 01:24 150528 β€”-a-w- c:\windows\SysWow64\iexpress.exe 2012-03-19 01:24 . 2012-03-19 01:24 142848 β€”-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-03-19 01:24 . 2012-03-19 01:24 1427456 β€”-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-03-19 01:24 . 2012-03-19 01:24 11776 β€”-a-w- c:\windows\SysWow64\mshta.exe 2012-03-19 01:24 . 2012-03-19 01:24 1127424 β€”-a-w- c:\windows\SysWow64\wininet.dll 2012-03-19 01:24 . 2012-03-19 01:24 110592 β€”-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-03-19 01:24 . 2012-03-19 01:24 101888 β€”-a-w- c:\windows\SysWow64\admparse.dll 2012-03-19 01:24 . 2012-03-19 01:24 91648 β€”-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-03-19 01:24 . 2012-03-19 01:24 89088 β€”-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-03-19 01:24 . 2012-03-19 01:24 85504 β€”-a-w- c:\windows\system32\iesetup.dll 2012-03-19 01:24 . 2012-03-19 01:24 76800 β€”-a-w- c:\windows\system32\tdc.ocx 2012-03-19 01:24 . 2012-03-19 01:24 603648 β€”-a-w- c:\windows\system32\vbscript.dll 2012-03-19 01:24 . 2012-03-19 01:24 49664 β€”-a-w- c:\windows\system32\imgutil.dll 2012-03-19 01:24 . 2012-03-19 01:24 48640 β€”-a-w- c:\windows\system32\mshtmler.dll 2012-03-19 01:24 . 2012-03-19 01:24 448512 β€”-a-w- c:\windows\system32\html.iec 2012-03-19 01:24 . 2012-03-19 01:24 30720 β€”-a-w- c:\windows\system32\licmgr10.dll 2012-03-19 01:24 . 2012-03-19 01:24 2382848 β€”-a-w- c:\windows\system32\mshtml.tlb 2012-03-19 01:24 . 2012-03-19 01:24 2308096 β€”-a-w- c:\windows\system32\jscript9.dll 2012-03-19 01:24 . 2012-03-19 01:24 222208 β€”-a-w- c:\windows\system32\msls31.dll 2012-03-19 01:24 . 2012-03-19 01:24 173056 β€”-a-w- c:\windows\system32\ieUnatt.exe 2012-03-19 01:24 . 2012-03-19 01:24 165888 β€”-a-w- c:\windows\system32\iexpress.exe 2012-03-19 01:24 . 2012-03-19 01:24 160256 β€”-a-w- c:\windows\system32\wextract.exe 2012-03-19 01:24 . 2012-03-19 01:24 1493504 β€”-a-w- c:\windows\system32\inetcpl.cpl 2012-03-19 01:24 . 2012-03-19 01:24 1390080 β€”-a-w- c:\windows\system32\wininet.dll 2012-03-19 01:24 . 2012-03-19 01:24 135168 β€”-a-w- c:\windows\system32\IEAdvpack.dll 2012-03-19 01:24 . 2012-03-19 01:24 12288 β€”-a-w- c:\windows\system32\mshta.exe 2012-03-19 01:24 . 2012-03-19 01:24 114176 β€”-a-w- c:\windows\system32\admparse.dll 2012-03-19 01:24 . 2012-03-19 01:24 111616 β€”-a-w- c:\windows\system32\iesysprep.dll 2012-01-11 07:42 . 2012-01-11 07:57 165824 β€”-a-w- c:\program files (x86)\27res.dll 2012-01-11 07:42 . 2012-01-11 07:57 689552 β€”-a-w- c:\program files (x86)\27Uninstall OurBabymaker.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-05-30 02:14 2068536 β€”-a-w- c:\program files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2012-01-03 22:31 1514152 β€”-a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll" [2012-05-30 2068536] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008] "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-05-30 1104440] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-11 559616] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-10-13 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [x] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2010-05-21 98208] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\avgidsagent.exe [2012-04-30 5106744] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856] S2 vToolbarUpdater11.1.0;vToolbarUpdater11.1.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe [2012-05-30 935480] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [x] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496] . . Contents of the 'Scheduled Tasks' folder . 2012-05-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1631236111-812278920-1098875194-1000Core.job - c:\users\Brittany\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-15 20:04] . 2012-06-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1631236111-812278920-1098875194-1000UA.job - c:\users\Brittany\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-15 20:04] . . β€”β€”β€” x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-05-21 10810912] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-04-05 384296] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs viairda . β€”β€”- Supplementary Scan β€”β€”- . uStart Page = hxxp://www.yahoo.com uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://www.yahoo.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: {{68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files (x86)\AVG\AVG2012\avgdtiex.dll TCP: DhcpNameServer = 192.168.1.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll FF - ProfilePath - c:\users\Brittany\AppData\Roaming\Mozilla\Firefox\Profiles\bqv7eohl.default\ FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Ba50d80b7-9679-457d-8e28-a88018a628a3%7D&mid=f7dce79d518f47d1bcc9a9628d0fe27b-f26f4441ce43115f0535dfc845db6a15517fb66c&ds=AVG&v=11.1.0.7&lang=en&pr=fr&d=2012-05-29%2021%3A14%3A56&sap=ku&q= FF - prefs.js: network.proxy.type - 0 FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file) Wow6432Node-HKU-Default-Run-dplaysvr - c:\windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) . . . β€”β€”β€”β€”β€”β€”β€” LOCKED REGISTRY KEYS β€”β€”β€”β€”β€”β€”β€” . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . β€”β€”β€”β€”β€”β€”β€”β€” Other Running Processes β€”β€”β€”β€”β€”β€”β€”β€” . c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\\.\globalroot\systemroot\svchost.exe c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe c:\program files (x86)\Dell DataSafe Local Backup\Toaster.exe . ************************************************************************** . Completion time: 2012-05-31 21:40:34 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-01 02:40 . Pre-Run: 257,890,942,976 bytes free Post-Run: 257,654,042,624 bytes free . - - End Of File - - 21ACAFBB41E69C6A1723126DC164DF9B
Hi,

You are doing a great job! Just so you know this infection on your computer is the real deal and may take some time to finish. If you have any questions along the way be sure to ask. :)
———–

First….I need you to move the file that we named Vageta.com to your Desktop and leave it there. :) You can just drag and drop it to the Desktop or however you know how to move files on your system as long as it is moved there.

Once there do the following…

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    uURLSearchHooks: H - No File
    BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File
    TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    dRun: [dplaysvr] C:\Windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe
    Hosts: 94.63.147.16	 www.google.com
    Hosts: 94.63.147.17	 www.bing.com
    
    File::
    C:\Program Files (x86)\27res.dll
    C:\Program Files (x86)\27Uninstall OurBabymaker.dll
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
β€”β€”β€”-

OTL
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    %systemroot%\*. /rp /s
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
β€”β€”β€”-

In your next reply please post the logs made by ComboFix and OTL. :)
I have tried to do what you said to do with the combo fix countless times and it will not finish, it just goes to this blue screen with a lot of words and numbers and then shuts itself down. I have not tried OTL again yet. I got way too frustrated trying combo fix over and over!
Hi, I know it can be very frustrating. I have been in your shoes too and know how it feels. Forego ComboFix right now and run OTL per the instructions I provided. Post those logs. :)
OTL logfile created on: 6/3/2012 8:48:01 PM - Run 1
OTL by OldTimer - Version 3.2.46.0 Folder = C:\Users\Brittany\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 31.34% Memory free
5.49 Gb Paging File | 3.22 Gb Available in Paging File | 58.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.34 Gb Total Space | 238.40 Gb Free Space | 84.14% Space Free | Partition Type: NTFS

Computer Name: BRITTANY-PC | User Name: Brittany | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Brittany\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgcfgex.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\SiteSafety.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\6d859463c9e6a7423ddb335211a79dda\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5672e6b9d976feca51deb06d8dd1df0e\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\09e39322b47f9b4e8dd2199ff03acb2e\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\d2dc021a8311197516e4fa325b292f21\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\SftBRCCPiped.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STBRCCServCLR.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (RemoteAccess) – C:\Windows\SysNative\mprdim.dll (Microsoft Corporation)
SRV:64bit: - (Mcx2Svc) – C:\Windows\SysNative\Mcx2Svc.dll (Microsoft Corporation)
SRV:64bit: - (viairda) – C:\Windows\SysNative\vpctcom.dll (Oak Technology Inc.)
SRV - (vToolbarUpdater11.1.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (RoxWatch12) – c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe (Sonic Solutions)
SRV - (RoxMediaDB12OEM) – c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe (Sonic Solutions)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RemoteAccess) – C:\Windows\SysWOW64\mprdim.dll (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (udfs) – C:\Windows\SysNative\drivers\udfs.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (amd_sata) – C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
DRV:64bit: - (amd_xata) – C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (crcdisk) – C:\Windows\SysNative\drivers\crcdisk.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (cdfs) – C:\Windows\SysNative\drivers\cdfs.sys (Microsoft Corporation)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{2F1E335A-858A-4BE9-8F6B-D0AF1D018B53}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{41396b1b-447e-473b-a34b-bb583136c7fc}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\..\SearchScopes\{41396b1b-447e-473b-a34b-bb583136c7fc}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={EE8F6D9…mp;d=2012-05-29 21:14:56&v;=11.1.0.7&sap;=dsp&q;={searchTerms}
IE - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}
IE - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Ba50d80b7-9679-457d-8e28-a88018a628a3%7D∣=f7dce79d518f47d1bcc9a9628d0fe27b-f26f4441ce43115f0535dfc845db6a15517fb66c&ds;=AVG&v;=11.1.0.7⟨=enβ‰Ί=fr&d;=2012-05-29%2021%3A14%3A56&sap;=ku&q;="
FF - prefs.js..network.proxy.type: 0


FF:64bit: - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\Brittany\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011/05/06 10:24:33 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/05/06 10:24:36 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/05/06 10:24:41 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/05/29 21:15:46 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/05/29 21:11:46 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.7\ [2012/05/29 21:15:23 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/30 08:49:08 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/08/19 12:08:15 | 000,000,000 | β€”D | M] (No name found) – C:\Users\Brittany\AppData\Roaming\Mozilla\Extensions
[2012/05/30 13:22:37 | 000,000,000 | β€”D | M] (No name found) – C:\Users\Brittany\AppData\Roaming\Mozilla\Firefox\Profiles\bqv7eohl.default\extensions
[2012/05/30 13:22:37 | 000,000,000 | β€”D | M] (Yahoo! Toolbar) – C:\Users\Brittany\AppData\Roaming\Mozilla\Firefox\Profiles\bqv7eohl.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/05/29 19:41:54 | 000,000,000 | β€”D | M] ("ooVoo toolbar, powered by Ask.com") – C:\Users\Brittany\AppData\Roaming\Mozilla\Firefox\Profiles\bqv7eohl.default\extensions\[removed]
[2011/08/19 12:55:47 | 000,000,000 | β€”D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/08/19 12:55:48 | 000,000,000 | β€”D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/08/19 12:30:36 | 000,000,000 | β€”D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/05/29 21:11:46 | 000,000,000 | β€”D | M] (AVG Do Not Track) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/05/29 21:15:46 | 000,000,000 | β€”D | M] (AVG Safe Search) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX4
[2012/05/29 21:15:23 | 000,000,000 | β€”D | M] (AVG Security Toolbar) – C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.7
[1832/11/28 23:51:36 | 000,004,813 | β€”- | M] () (No name found) – C:\USERS\BRITTANY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BQV7EOHL.DEFAULT\EXTENSIONS\[removed]
[2011/09/19 14:50:14 | 000,134,104 | β€”- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/05/29 21:14:41 | 000,003,747 | β€”- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2011/09/19 14:50:10 | 000,002,252 | β€”- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Brittany\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: Chrome NaCl (Enabled) = C:\Users\Brittany\AppData\Local\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Brittany\AppData\Local\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Best Buy pc app Detector (Enabled) = C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Brittany\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Skype Extension = C:\Users\Brittany\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\

O1 HOSTS File: ([2012/05/31 19:35:59 | 000,000,027 | β€”- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AmdAgent] C:\Windows\Temp\temp22.exe ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKU\.DEFAULT..\Run: [dplaysvr] C:\Windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe File not found
O4 - HKU\.DEFAULT..\Run: [eddfdacbbbbbfdct] C:\ProgramData\eddfdacbbbbbfdct.exe (tttt Corporation)
O4 - HKU\S-1-5-18..\Run: [dplaysvr] C:\Windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe File not found
O4 - HKU\S-1-5-18..\Run: [eddfdacbbbbbfdct] C:\ProgramData\eddfdacbbbbbfdct.exe (tttt Corporation)
O4 - HKU\S-1-5-21-1631236111-812278920-1098875194-1000..\Run: [eddfdacbbbbbfdct] C:\ProgramData\eddfdacbbbbbfdct.exe (tttt Corporation)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1631236111-812278920-1098875194-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{536EBA0F-AAB1-4259-9D6D-FBFD00B7D0CE}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: viairda - C:\Windows\SysNative\vpctcom.dll (Oak Technology Inc.)

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2012/06/03 20:46:19 | 000,596,480 | β€”- | C] (OldTimer Tools) – C:\Users\Brittany\Desktop\OTL.exe
[2012/06/02 22:06:51 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2012/06/02 03:03:30 | 000,000,000 | β€”D | C] – C:\9c26b3522f1e72d280d0131084
[2012/06/02 01:46:10 | 000,096,736 | β€”- | C] (tttt Corporation) – C:\ProgramData\eddfdacbbbbbfdct.exe
[2012/06/02 01:24:58 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/06/02 01:08:02 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/05/31 20:19:42 | 000,000,000 | β€”D | C] – C:\b063d835c6d2de29cd
[2012/05/31 18:41:13 | 000,518,144 | β€”- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/05/31 18:41:13 | 000,406,528 | β€”- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/05/31 18:41:13 | 000,060,416 | β€”- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/05/31 18:41:04 | 000,000,000 | β€”D | C] – C:\Windows\ERDNT
[2012/05/31 18:40:39 | 000,000,000 | β€”D | C] – C:\Qoobox
[2012/05/29 21:46:48 | 000,000,000 | β€”D | C] – C:\Config.Msi
[2012/05/29 21:41:00 | 000,000,000 | β€”D | C] – C:\0371d38db3e5a2add34d943d
[2012/05/29 21:33:23 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/05/29 21:33:22 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\Trend Micro
[2012/05/29 21:18:01 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Roaming\AVG2012
[2012/05/29 21:16:16 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\AVG Secure Search
[2012/05/29 21:15:47 | 000,000,000 | β€”D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/05/29 21:14:55 | 000,000,000 | β€”D | C] – C:\ProgramData\AVG Secure Search
[2012/05/29 21:14:46 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2012/05/29 21:14:45 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\AVG Secure Search
[2012/05/29 21:12:40 | 000,000,000 | β€”D | C] – C:\Windows\SysWow64\drivers\AVG
[2012/05/29 21:11:40 | 000,000,000 | β€”D | C] – C:\ProgramData\AVG2012
[2012/05/29 21:11:40 | 000,000,000 | β€”D | C] – C:\Windows\SysNative\drivers\AVG
[2012/05/29 21:11:40 | 000,000,000 | β€”D | C] – C:\$AVG
[2012/05/29 21:02:46 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\AVG
[2012/05/29 20:21:22 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{E05977DE-F8B4-433E-A3E4-AC798E5803A2}
[2012/05/29 19:46:16 | 000,000,000 | β€”D | C] – C:\1c2d2d9ca812a7a53a35910d93
[2012/05/29 19:27:43 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{78ADFA9E-485A-41D8-85EF-50697126C7E9}
[2012/05/29 19:19:43 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{862A5E6C-D447-46CB-A19B-01770E741AC3}
[2012/05/29 19:19:20 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{EBF3D444-D023-4580-B375-2502721E5047}
[2012/05/29 19:14:16 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{8AEC251D-C057-48FC-9476-8730C8D0391F}
[2012/05/29 19:13:56 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{B38CB687-8451-4314-9AC3-D049696D0DA0}
[2012/05/22 13:01:58 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{7C85A0DE-3541-4082-BF86-6BFD9479AF0E}
[2012/05/22 12:36:07 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{0E465BC6-612E-4F29-A068-6ADB28EB5CC5}
[2012/05/22 12:35:44 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{9BC77FEE-3E41-49DF-9FF4-A295A3BF19EE}
[2012/05/09 21:42:14 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{F4909947-6F26-44A9-81B4-AC5CB7A2910E}
[2012/05/09 16:38:40 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{1A45E387-9612-4E38-8687-84D6399288FF}
[2012/05/09 16:38:36 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SMART HDD
[2012/05/09 16:38:14 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{FF9659DC-72F9-424B-9259-804E5444DCC8}
[2012/05/09 16:32:22 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{323E3E3F-D412-40C1-BE75-6F90337F9510}
[2012/05/09 16:31:55 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{AB127E64-334C-4CDC-A8CA-4CC1B6CC4FB7}
[2012/05/07 17:42:05 | 000,000,000 | β€”D | C] – C:\95953255d67f06028941d8e2be60
[2012/05/07 17:27:33 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{F5913895-4C74-4A11-8F17-3673F08598FC}
[2012/05/07 17:26:45 | 000,000,000 | β€”D | C] – C:\Users\Brittany\AppData\Local\{E9046086-2E0E-4E7E-9496-BAA1BE55CBD5}
[2012/01/11 02:57:23 | 000,689,552 | β€”- | C] (MindSpark) – C:\Program Files (x86)\27Uninstall OurBabymaker.dll

========== Files - Modified Within 30 Days ==========

[2012/06/03 21:03:36 | 000,000,920 | β€”- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1631236111-812278920-1098875194-1000UA.job
[2012/06/03 21:03:36 | 000,000,868 | β€”- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1631236111-812278920-1098875194-1000Core.job
[2012/06/03 20:46:48 | 000,596,480 | β€”- | M] (OldTimer Tools) – C:\Users\Brittany\Desktop\OTL.exe
[2012/06/03 20:44:46 | 000,013,872 | β€”- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/03 20:44:46 | 000,013,872 | β€”- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/03 20:38:52 | 099,711,565 | β€”- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/03 20:34:47 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/03 20:34:41 | 2211,307,520 | -HS- | M] () – C:\hiberfil.sys
[2012/06/02 03:06:33 | 000,868,838 | β€”- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/02 03:06:33 | 000,717,018 | β€”- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/02 03:06:33 | 000,139,310 | β€”- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/02 02:05:17 | 000,002,376 | β€”- | M] () – C:\Users\Brittany\Desktop\Google Chrome.lnk
[2012/06/02 01:46:10 | 000,096,736 | β€”- | M] (tttt Corporation) – C:\ProgramData\eddfdacbbbbbfdct.exe
[2012/06/02 01:41:05 | 417,332,942 | β€”- | M] () – C:\Windows\MEMORY.DMP
[2012/06/01 03:51:48 | 000,000,512 | β€”- | M] () – C:\Users\Brittany\Documents\MBR.dat
[2012/05/31 21:11:11 | 000,006,576 | β€”- | M] () – C:\bootsqm.dat
[2012/05/31 19:35:59 | 000,000,027 | β€”- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/05/31 19:12:51 | 000,001,131 | β€”- | M] () – C:\Users\Brittany\Desktop\vageta.com.lnk
[2012/05/29 21:33:23 | 000,002,991 | β€”- | M] () – C:\Users\Brittany\Desktop\HiJackThis.lnk
[2012/05/29 21:15:47 | 000,000,967 | β€”- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/05/29 21:12:40 | 000,000,000 | β€”- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/05/29 21:12:40 | 000,000,000 | β€”- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/05/29 20:31:20 | 000,000,824 | β€”- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/05/29 20:09:56 | 000,346,040 | β€”- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/06/03 20:38:52 | 099,711,565 | β€”- | C] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/05/31 21:11:11 | 000,006,576 | β€”- | C] () – C:\bootsqm.dat
[2012/05/31 19:12:51 | 000,001,131 | β€”- | C] () – C:\Users\Brittany\Desktop\vageta.com.lnk
[2012/05/31 18:41:13 | 000,256,000 | β€”- | C] () – C:\Windows\PEV.exe
[2012/05/31 18:41:13 | 000,208,896 | β€”- | C] () – C:\Windows\MBR.exe
[2012/05/31 18:41:13 | 000,098,816 | β€”- | C] () – C:\Windows\sed.exe
[2012/05/31 18:41:13 | 000,080,412 | β€”- | C] () – C:\Windows\grep.exe
[2012/05/31 18:41:13 | 000,068,096 | β€”- | C] () – C:\Windows\zip.exe
[2012/05/30 22:26:16 | 417,332,942 | β€”- | C] () – C:\Windows\MEMORY.DMP
[2012/05/30 22:17:11 | 000,000,512 | β€”- | C] () – C:\Users\Brittany\Documents\MBR.dat
[2012/05/29 21:33:23 | 000,002,991 | β€”- | C] () – C:\Users\Brittany\Desktop\HiJackThis.lnk
[2012/05/29 21:15:47 | 000,000,967 | β€”- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/05/29 21:12:40 | 000,000,000 | β€”- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/05/29 21:12:40 | 000,000,000 | β€”- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/05/29 20:31:20 | 000,000,824 | β€”- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/02/25 00:39:37 | 000,059,392 | Rβ€” | C] () – C:\Windows\SysWow64\streamhlp.dll
[2012/01/11 02:57:23 | 000,165,824 | β€”- | C] () – C:\Program Files (x86)\27res.dll
[2011/06/24 00:24:01 | 000,012,800 | β€”- | C] () – C:\Users\Brittany\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/15 16:37:31 | 000,000,056 | β€”- | C] () – C:\ProgramData\ezsidmv.dat
[2011/05/06 12:22:18 | 000,001,035 | β€”- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/05/06 12:20:45 | 000,000,096 | β€”- | C] () – C:\Windows\LaunApp.ini
[2011/05/06 12:20:41 | 000,000,271 | β€”- | C] () – C:\Windows\WisPriority.ini
[2011/05/06 12:20:41 | 000,000,035 | β€”- | C] () – C:\Windows\DELL_LANGCODE.ini
[2011/05/06 12:20:41 | 000,000,033 | β€”- | C] () – C:\Windows\DELL_OSTYPE.ini
[2011/05/06 12:20:41 | 000,000,032 | β€”- | C] () – C:\Windows\WisHWDest.ini
[2011/05/06 12:20:41 | 000,000,028 | β€”- | C] () – C:\Windows\WisLangCode.ini
[2011/05/06 12:20:41 | 000,000,023 | β€”- | C] () – C:\Windows\WisSysInfo.ini
[2011/05/06 10:07:03 | 000,000,000 | β€”- | C] () – C:\Windows\ativpsrm.bin
[2011/05/06 10:05:10 | 000,000,080 | RHS- | C] () – C:\Windows\CT4CET.bin
[2011/03/20 21:49:03 | 000,000,325 | β€”- | C] () – C:\Windows\Prelaunch.ini

========== LOP Check ==========

[2012/05/29 21:18:01 | 000,000,000 | β€”D | M] – C:\Users\Brittany\AppData\Roaming\AVG2012
[2011/06/15 14:23:40 | 000,000,000 | β€”D | M] – C:\Users\Brittany\AppData\Roaming\Leadertech
[2012/01/04 22:30:32 | 000,000,000 | β€”D | M] – C:\Users\Brittany\AppData\Roaming\ooVoo Details
[2012/05/23 03:07:05 | 000,000,000 | β€”D | M] – C:\Users\Brittany\AppData\Roaming\SecondLife
[2012/05/23 03:07:05 | 000,000,000 | β€”D | M] – C:\Users\Brittany\AppData\Roaming\SoftGrid Client
[2011/08/19 13:03:49 | 000,000,000 | β€”D | M] – C:\Users\Brittany\AppData\Roaming\TP
[2012/02/25 00:48:28 | 000,000,000 | β€”D | M] – C:\Users\Brittany\AppData\Roaming\TrojanHunter
[2012/03/06 18:26:40 | 000,013,594 | β€”- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %systemroot%\*. /rp /s >

< %SYSTEMDRIVE%\*.exe >

< MD5 for: CONSRV.DLL >
[2009/07/13 20:39:46 | 000,053,248 | β€”- | M] () MD5=6BF2039986AF96D98E08824AC6C383FD – C:\Windows\SysNative\consrv.dll

< MD5 for: EXPLORER.EXE >
[2011/03/20 21:52:40 | 002,613,248 | β€”- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/26 01:23:14 | 002,870,272 | β€”- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\explorer.exe
[2011/02/26 01:23:14 | 002,870,272 | β€”- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | β€”- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | β€”- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | β€”- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2011/03/20 21:58:53 | 002,614,272 | β€”- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | β€”- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\SysWOW64\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | β€”- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | β€”- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | β€”- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | β€”- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/03/20 21:52:40 | 002,868,736 | β€”- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2011/03/20 21:50:26 | 002,868,224 | β€”- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | β€”- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2011/03/20 21:58:53 | 002,870,272 | β€”- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2011/03/20 21:50:26 | 002,613,248 | β€”- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | β€”- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2011/03/20 21:58:53 | 002,870,272 | β€”- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2011/03/20 21:50:26 | 002,613,248 | β€”- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | β€”- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2011/03/20 21:58:53 | 002,614,272 | β€”- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/03/20 21:52:40 | 002,868,736 | β€”- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | β€”- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2011/03/20 21:50:26 | 002,868,224 | β€”- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2011/03/20 21:52:40 | 002,613,248 | β€”- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:45 | 000,020,480 | β€”- | M] (Microsoft Corporation) MD5=2CEFF13ACE25A40BD8D97654944297CD – C:\Windows\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | β€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | β€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | β€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | β€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | β€”- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | β€”- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\SysWOW64\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | β€”- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | β€”- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\SysNative\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | β€”- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | β€”- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | β€”- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | β€”- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2011/03/20 21:58:53 | 000,389,632 | β€”- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2011/03/20 21:58:53 | 000,389,632 | β€”- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\SysNative\winlogon.exe
[2011/03/20 21:58:53 | 000,389,632 | β€”- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI