This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Patched_c.LXT [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You did well running those logs but there are some entries I expected to see that are not there so we need to run another scan that might show more..

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
Satchfan
Hey
I was only able to download the DDS.scr. The other ling was the same file (asked me if i wan to replace with the one i have)
I ran the DDS.scr and here are the logs:

The DDS log:

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 14:48:24 on 2012-06-29
Microsoft Windows 7 Ultimate 6.1.7601.1.1255.972.1033.18.3993.2041 [GMT 3:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============

The second one:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 22/04/2012 21:12:58
System Uptime: 29/06/2012 09:39:47 (5 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | P8H61-M LX
Processor: Intel® Core™ i3-2120 CPU @ 3.30GHz | LGA1155 | 3300/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 931 GiB total, 703.854 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP28: 21/06/2012 12:47:16 - Windows Update
RP29: 24/06/2012 10:17:40 - Device Driver Package Install: DT Soft Ltd System devices
RP30: 25/06/2012 19:15:37 - 25-06-12
RP31: 26/06/2012 03:00:45 - Windows Update
RP32: 27/06/2012 17:30:15 - OTL Restore Point - 27/06/2012 17:30:15
.
==== Installed Programs ======================
.
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3)
Browser Defender 3.0
Catan Online World
Cooking Academy 3-Recipe for Success version 1.0.0
CreaVures
DAEMON Tools Pro
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
ESET Online Scanner v3
Foxit Reader
Google Chrome
Java Auto Updater
Java™ 6 Update 31
K-Lite Codec Pack 8.7.0 (Full)
May's Mysteries - The Secret of Dragonville version 1.0.0
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MotoHelper MergeModules
Mozilla Firefox 12.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
Notepad++
PC Tools Internet Security
Picasa 3
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Skype™ 5.9
Spooky Mall
The KMPlayer (remove only)
Torrent Episode Downloader
Trojan Remover 6.8.4
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Visual Studio 2008 x64 Redistributables
VLC media player 2.0.1
Windows Live Call
Windows Live Communications Platform
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
28/06/2012 20:58:13, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: The specified module could not be found.
28/06/2012 20:57:12, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
28/06/2012 20:56:31, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
28/06/2012 20:51:39, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891
28/06/2012 20:51:39, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891
28/06/2012 20:47:33, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
28/06/2012 20:43:29, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
28/06/2012 20:42:43, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
28/06/2012 20:42:43, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
28/06/2012 20:42:40, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
28/06/2012 20:42:34, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
28/06/2012 20:42:29, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 discache PCTSD spldr Wanarpv6
25/06/2012 09:23:32, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding
24/06/2012 23:34:30, Error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.0.100 with the system having network hardware address 5C-D9-98-86-77-4D. Network operations on this system may be disrupted as a result.
24/06/2012 17:26:04, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:39:10, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
24/06/2012 14:34:27, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
24/06/2012 14:34:05, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx64 Avgmfx64 Avgtdia CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:33:56, Error: Microsoft-Windows-Kernel-General [5] - {Registry Hive Recovered} Registry hive (file): '\SystemRoot\System32\Config\SOFTWARE' was corrupted and it has been recovered. Some data might have been lost.
.
==== End Of File ===========================


.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Java\jre6\bin\javaw.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\AUDIODG.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://express-google-search.blogspot.com
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
uRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe -update activex
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
mRun: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe
StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\TED-SH~1.LNK - C:\Program Files (x86)\Torrent Episode Downloader\ted.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
LSP: C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{80F25CC4-7E95-48CF-9109-A5139C8F3B46} : DhcpNameServer = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: PC Tools Browser Guard BHO: {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
BHO-X64: Browser Defender BHO - No File
BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO-X64: AVG Do Not Track - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: PC Tools Browser Guard: {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun-x64: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
mRun-x64: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\lblo695t.default\
FF - prefs.js: browser.startup.homepage - hxxp://express-google-search.blogspot.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q=
FF - prefs.js: browser.startup.homepage - hxxp://express-google-search.blogspot.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q=
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys –> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R0 PCTCore;PCTools KDS;C:\Windows\system32\drivers\PCTCore64.sys –> C:\Windows\system32\drivers\PCTCore64.sys [?]
R0 pctDS;PC Tools Data Store;C:\Windows\system32\drivers\pctDS64.sys –> C:\Windows\system32\drivers\pctDS64.sys [?]
R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\system32\drivers\pctEFA64.sys –> C:\Windows\system32\drivers\pctEFA64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys –> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 pctgntdi;pctgntdi;\??\C:\Windows\System32\drivers\pctgntdi64.sys –> C:\Windows\System32\drivers\pctgntdi64.sys [?]
R1 PCTSD;PC Tools Spyware Doctor Driver;C:\Windows\system32\Drivers\PCTSD64.sys –> C:\Windows\system32\Drivers\PCTSD64.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 Browser Defender Update Service;Browser Defender Update Service;C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2012-6-24 337872]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys –> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys –> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 pctNdisMP;PC Tools Driver;C:\Windows\system32\DRIVERS\pctNdis64.sys –> C:\Windows\system32\DRIVERS\pctNdis64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-4-30 5106744]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 KMService;KMService;C:\Windows\System32\srvany.exe [2012-5-2 8192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-22 250056]
S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-3-19 276248]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys –> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 30963576]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-1 129976]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;\??\C:\Windows\system32\drivers\pctNdis-PacketFilter64.sys –> C:\Windows\system32\drivers\pctNdis-PacketFilter64.sys [?]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;C:\Windows\system32\DRIVERS\pctNdis64.sys –> C:\Windows\system32\DRIVERS\pctNdis64.sys [?]
S3 pctplfw;pctplfw;\??\C:\Windows\System32\drivers\pctplfw64.sys –> C:\Windows\System32\drivers\pctplfw64.sys [?]
S3 pctplsg;pctplsg;\??\C:\Windows\System32\drivers\pctplsg64.sys –> C:\Windows\System32\drivers\pctplsg64.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [2012-6-24 371472]
S3 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [2012-6-24 1117144]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys –> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys –> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys –> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-06-28 17:58:27 ——– d-sh–w- C:\$RECYCLE.BIN
2012-06-28 17:50:38 98816 —-a-w- C:\Windows\sed.exe
2012-06-28 17:50:38 518144 —-a-w- C:\Windows\SWREG.exe
2012-06-28 17:50:38 256000 —-a-w- C:\Windows\PEV.exe
2012-06-28 17:50:38 208896 —-a-w- C:\Windows\MBR.exe
2012-06-25 13:32:21 ——– d—–w- C:\Program Files (x86)\ESET
2012-06-24 20:31:14 ——– d—–w- C:\Users\Home\AppData\Local\ElevatedDiagnostics
2012-06-24 17:04:10 ——– d—–w- C:\Users\Home\AppData\Roaming\PCTools
2012-06-24 16:52:40 ——– d—–w- C:\Users\Home\AppData\Roaming\PCToolsFirewallPlus
2012-06-24 16:52:39 ——– d—–w- C:\Users\Home\AppData\Roaming\Spam Monitor
2012-06-24 16:50:45 180488 —-a-w- C:\Windows\System32\drivers\pctplfw64.sys
2012-06-24 16:50:42 77784 —-a-w- C:\Windows\System32\drivers\pctNdis64.sys
2012-06-24 16:50:41 42968 —-a-w- C:\Windows\System32\drivers\pctNdis-DNS64.sys
2012-06-24 16:50:41 119688 —-a-w- C:\Windows\System32\drivers\pctNdis-PacketFilter64.sys
2012-06-24 15:59:23 767952 —-a-w- C:\Windows\BDTSupport.dll
2012-06-24 15:59:23 2029520 —-a-w- C:\Windows\PCTBDCore.dll
2012-06-24 15:59:23 1533904 —-a-w- C:\Windows\PCTBDRes.dll
2012-06-24 15:59:23 149456 —-a-w- C:\Windows\SGDetectionTool.dll
2012-06-24 15:56:43 816016 —-a-w- C:\Windows\System32\drivers\pctEFA64.sys
2012-06-24 15:56:43 452872 —-a-w- C:\Windows\System32\drivers\pctDS64.sys
2012-06-24 15:56:42 337048 —-a-w- C:\Windows\System32\drivers\pctgntdi64.sys
2012-06-24 15:56:42 143896 —-a-w- C:\Windows\System32\drivers\pctwfpfilter64.sys
2012-06-24 15:56:36 282440 —-a-w- C:\Windows\System32\drivers\PCTCore64.sys
2012-06-24 15:56:32 279344 —-a-w- C:\Windows\System32\drivers\PCTSD64.sys
2012-06-24 15:56:30 92896 —-a-w- C:\Windows\System32\drivers\pctplsg64.sys
2012-06-24 15:56:22 ——– d—–w- C:\ProgramData\PC Tools
2012-06-24 15:56:22 ——– d—–w- C:\Program Files (x86)\PC Tools Security
2012-06-24 15:56:22 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools
2012-06-24 07:20:59 ——– d—–w- C:\ProgramData\Arizona Rose
2012-06-24 07:17:38 283200 —-a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2012-06-24 07:17:33 ——– d—–w- C:\Users\Home\AppData\Roaming\DAEMON Tools Pro
2012-06-24 07:17:30 ——– d—–w- C:\Program Files (x86)\DAEMON Tools Pro
2012-06-24 07:16:06 ——– d—–w- C:\ProgramData\DAEMON Tools Pro
2012-06-24 06:51:50 77312 —-a-w- C:\Windows\SysWow64\ztvunace26.dll
2012-06-24 06:51:50 75264 —-a-w- C:\Windows\SysWow64\unacev2.dll
2012-06-24 06:51:50 69632 —-a-w- C:\Windows\SysWow64\ztvcabinet.dll
2012-06-24 06:51:50 162304 —-a-w- C:\Windows\SysWow64\ztvunrar36.dll
2012-06-24 06:51:50 153088 —-a-w- C:\Windows\SysWow64\UNRAR3.dll
2012-06-24 06:51:50 ——– d—–w- C:\Users\Home\AppData\Roaming\Simply Super Software
2012-06-24 06:51:50 ——– d—–w- C:\ProgramData\Simply Super Software
2012-06-24 06:51:50 ——– d—–w- C:\Program Files (x86)\Trojan Remover
2012-06-21 09:48:07 2622464 —-a-w- C:\Windows\System32\wucltux.dll
2012-06-21 09:47:48 99840 —-a-w- C:\Windows\System32\wudriver.dll
2012-06-21 09:47:37 36864 —-a-w- C:\Windows\System32\wuapp.exe
2012-06-21 09:47:37 186752 —-a-w- C:\Windows\System32\wuwebv.dll
2012-06-17 15:57:23 ——– d—–w- C:\Users\Home\AppData\Roaming\V5 Play
2012-06-15 11:34:48 ——– d—–w- C:\Users\Home\AppData\Local\Microsoft Games
2012-06-14 05:41:00 ——– d—–w- C:\Users\Home\AppData\Roaming\quickclick
2012-06-12 15:49:22 ——– d—–w- C:\ProgramData\Fugazo
2012-06-05 16:29:57 ——– d—–w- C:\Output Files
2012-06-05 16:28:44 ——– d—–w- C:\Program Files (x86)\office Convert Pdf to Jpg Jpeg Tiff Free
2012-06-05 16:20:01 ——– d—–w- C:\Users\Home\AppData\Local\Adobe
.
==================== Find3M ====================
.
2012-06-23 07:38:17 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-23 07:38:17 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-24 21:18:40 4472832 —-a-w- C:\Windows\SysWow64\GPhotos.scr
2012-05-18 02:06:48 2311680 —-a-w- C:\Windows\System32\jscript9.dll
2012-05-18 01:59:14 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-05-18 01:58:39 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-05-18 01:55:22 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-05-18 01:51:30 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-05-17 22:45:37 1800192 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-05-17 22:35:47 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-05-17 22:35:39 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-05-17 22:29:45 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-05-17 22:24:45 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-05-15 01:32:33 3146752 —-a-w- C:\Windows\System32\win32k.sys
2012-05-04 11:06:22 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 10:52:00 419840 —-a-w- C:\Windows\System32\systemcpl.dll
2012-05-01 10:52:00 14848 —-a-w- C:\Windows\System32\slwga.dll
2012-05-01 10:52:00 13824 —-a-w- C:\Windows\SysWow64\slwga.dll
2012-05-01 10:51:59 833024 —-a-w- C:\Windows\SysWow64\user32.dll
2012-05-01 10:51:59 1008640 —-a-w- C:\Windows\System32\user32.dll
2012-05-01 05:40:20 209920 —-a-w- C:\Windows\System32\profsvc.dll
2012-04-28 05:32:05 1112064 —-a-w- C:\Windows\System32\rdpcorets.dll
2012-04-28 03:55:21 210944 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 —-a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:37:37 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 —-a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 —-a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 —-a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
2012-04-22 20:56:54 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-04-19 01:50:26 28480 —-a-w- C:\Windows\System32\drivers\avgidsha.sys
2012-04-07 12:31:40 3216384 —-a-w- C:\Windows\System32\msi.dll
2012-04-07 11:26:29 2342400 —-a-w- C:\Windows\SysWow64\msi.dll
.
============= FINISH: 14:48:46.21 ===============

The Attached log:


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 22/04/2012 21:12:58
System Uptime: 29/06/2012 09:39:47 (5 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | P8H61-M LX
Processor: Intel® Core™ i3-2120 CPU @ 3.30GHz | LGA1155 | 3300/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 931 GiB total, 703.854 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP28: 21/06/2012 12:47:16 - Windows Update
RP29: 24/06/2012 10:17:40 - Device Driver Package Install: DT Soft Ltd System devices
RP30: 25/06/2012 19:15:37 - 25-06-12
RP31: 26/06/2012 03:00:45 - Windows Update
RP32: 27/06/2012 17:30:15 - OTL Restore Point - 27/06/2012 17:30:15
.
==== Installed Programs ======================
.
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3)
Browser Defender 3.0
Catan Online World
Cooking Academy 3-Recipe for Success version 1.0.0
CreaVures
DAEMON Tools Pro
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
ESET Online Scanner v3
Foxit Reader
Google Chrome
Java Auto Updater
Java™ 6 Update 31
K-Lite Codec Pack 8.7.0 (Full)
May's Mysteries - The Secret of Dragonville version 1.0.0
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MotoHelper MergeModules
Mozilla Firefox 12.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
Notepad++
PC Tools Internet Security
Picasa 3
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Skype™ 5.9
Spooky Mall
The KMPlayer (remove only)
Torrent Episode Downloader
Trojan Remover 6.8.4
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Visual Studio 2008 x64 Redistributables
VLC media player 2.0.1
Windows Live Call
Windows Live Communications Platform
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
28/06/2012 20:58:13, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: The specified module could not be found.
28/06/2012 20:57:12, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
28/06/2012 20:56:31, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
28/06/2012 20:51:39, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891
28/06/2012 20:51:39, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891
28/06/2012 20:47:33, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
28/06/2012 20:43:29, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
28/06/2012 20:42:43, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
28/06/2012 20:42:43, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
28/06/2012 20:42:40, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
28/06/2012 20:42:34, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
28/06/2012 20:42:29, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 discache PCTSD spldr Wanarpv6
25/06/2012 09:23:32, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding
24/06/2012 23:34:30, Error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.0.100 with the system having network hardware address 5C-D9-98-86-77-4D. Network operations on this system may be disrupted as a result.
24/06/2012 17:26:04, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:39:10, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
24/06/2012 14:34:27, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
24/06/2012 14:34:05, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx64 Avgmfx64 Avgtdia CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:34:05, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
24/06/2012 14:33:56, Error: Microsoft-Windows-Kernel-General [5] - {Registry Hive Recovered} Registry hive (file): '\SystemRoot\System32\Config\SOFTWARE' was corrupted and it has been recovered. Some data might have been lost.
.
==== End Of File ===========================
Here is the DDS log again (i saw that it was incomplete in my previous reply) . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 14:48:24 on 2012-06-29 Microsoft Windows 7 Ultimate 6.1.7601.1.1255.972.1033.18.3993.2041 [GMT 3:00] . AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\Java\jre6\bin\javaw.exe C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\AVG\AVG2012\avgtray.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\rundll32.exe C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\wuauclt.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\AUDIODG.EXE C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://express-google-search.blogspot.com uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun uRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe -update activex mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices mRun: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot mRun: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe StartupFolder: C:\Users\Home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\TED-SH~1.LNK - C:\Program Files (x86)\Torrent Episode Downloader\ted.exe mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll LSP: C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{80F25CC4-7E95-48CF-9109-A5139C8F3B46} : DhcpNameServer = 192.168.0.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: PC Tools Browser Guard BHO: {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll BHO-X64: Browser Defender BHO - No File BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO-X64: AVG Do Not Track - No File BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: PC Tools Browser Guard: {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices mRun-x64: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot mRun-x64: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\lblo695t.default\ FF - prefs.js: browser.startup.homepage - hxxp://express-google-search.blogspot.com FF - prefs.js: keyword.URL - hxxp://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q= FF - prefs.js: browser.startup.homepage - hxxp://express-google-search.blogspot.com FF - prefs.js: keyword.URL - hxxp://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q= . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys –> C:\Windows\system32\DRIVERS\avgidsha.sys [?] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?] R0 PCTCore;PCTools KDS;C:\Windows\system32\drivers\PCTCore64.sys –> C:\Windows\system32\drivers\PCTCore64.sys [?] R0 pctDS;PC Tools Data Store;C:\Windows\system32\drivers\pctDS64.sys –> C:\Windows\system32\drivers\pctDS64.sys [?] R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\system32\drivers\pctEFA64.sys –> C:\Windows\system32\drivers\pctEFA64.sys [?] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?] R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys –> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?] R1 pctgntdi;pctgntdi;\??\C:\Windows\System32\drivers\pctgntdi64.sys –> C:\Windows\System32\drivers\pctgntdi64.sys [?] R1 PCTSD;PC Tools Spyware Doctor Driver;C:\Windows\system32\Drivers\PCTSD64.sys –> C:\Windows\system32\Drivers\PCTSD64.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288] R2 Browser Defender Update Service;Browser Defender Update Service;C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2012-6-24 337872] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys –> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys –> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?] R3 pctNdisMP;PC Tools Driver;C:\Windows\system32\DRIVERS\pctNdis64.sys –> C:\Windows\system32\DRIVERS\pctNdis64.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-4-30 5106744] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 KMService;KMService;C:\Windows\System32\srvany.exe [2012-5-2 8192] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-22 250056] S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-3-19 276248] S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys –> C:\Windows\system32\drivers\dmvsc.sys [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-1-21 30963576] S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-1 129976] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;\??\C:\Windows\system32\drivers\pctNdis-PacketFilter64.sys –> C:\Windows\system32\drivers\pctNdis-PacketFilter64.sys [?] S3 pctNdis;PC Tools Firewall Intermediate Filter Service;C:\Windows\system32\DRIVERS\pctNdis64.sys –> C:\Windows\system32\DRIVERS\pctNdis64.sys [?] S3 pctplfw;pctplfw;\??\C:\Windows\System32\drivers\pctplfw64.sys –> C:\Windows\System32\drivers\pctplfw64.sys [?] S3 pctplsg;pctplsg;\??\C:\Windows\System32\drivers\pctplsg64.sys –> C:\Windows\System32\drivers\pctplsg64.sys [?] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?] S3 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [2012-6-24 371472] S3 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [2012-6-24 1117144] S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys –> C:\Windows\system32\drivers\synth3dvsc.sys [?] S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys –> C:\Windows\system32\drivers\terminpt.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys –> C:\Windows\system32\drivers\tsusbhub.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] . =============== Created Last 30 ================ . 2012-06-28 17:58:27 ——– d-sh–w- C:\$RECYCLE.BIN 2012-06-28 17:50:38 98816 —-a-w- C:\Windows\sed.exe 2012-06-28 17:50:38 518144 —-a-w- C:\Windows\SWREG.exe 2012-06-28 17:50:38 256000 —-a-w- C:\Windows\PEV.exe 2012-06-28 17:50:38 208896 —-a-w- C:\Windows\MBR.exe 2012-06-25 13:32:21 ——– d—–w- C:\Program Files (x86)\ESET 2012-06-24 20:31:14 ——– d—–w- C:\Users\Home\AppData\Local\ElevatedDiagnostics 2012-06-24 17:04:10 ——– d—–w- C:\Users\Home\AppData\Roaming\PCTools 2012-06-24 16:52:40 ——– d—–w- C:\Users\Home\AppData\Roaming\PCToolsFirewallPlus 2012-06-24 16:52:39 ——– d—–w- C:\Users\Home\AppData\Roaming\Spam Monitor 2012-06-24 16:50:45 180488 —-a-w- C:\Windows\System32\drivers\pctplfw64.sys 2012-06-24 16:50:42 77784 —-a-w- C:\Windows\System32\drivers\pctNdis64.sys 2012-06-24 16:50:41 42968 —-a-w- C:\Windows\System32\drivers\pctNdis-DNS64.sys 2012-06-24 16:50:41 119688 —-a-w- C:\Windows\System32\drivers\pctNdis-PacketFilter64.sys 2012-06-24 15:59:23 767952 —-a-w- C:\Windows\BDTSupport.dll 2012-06-24 15:59:23 2029520 —-a-w- C:\Windows\PCTBDCore.dll 2012-06-24 15:59:23 1533904 —-a-w- C:\Windows\PCTBDRes.dll 2012-06-24 15:59:23 149456 —-a-w- C:\Windows\SGDetectionTool.dll 2012-06-24 15:56:43 816016 —-a-w- C:\Windows\System32\drivers\pctEFA64.sys 2012-06-24 15:56:43 452872 —-a-w- C:\Windows\System32\drivers\pctDS64.sys 2012-06-24 15:56:42 337048 —-a-w- C:\Windows\System32\drivers\pctgntdi64.sys 2012-06-24 15:56:42 143896 —-a-w- C:\Windows\System32\drivers\pctwfpfilter64.sys 2012-06-24 15:56:36 282440 —-a-w- C:\Windows\System32\drivers\PCTCore64.sys 2012-06-24 15:56:32 279344 —-a-w- C:\Windows\System32\drivers\PCTSD64.sys 2012-06-24 15:56:30 92896 —-a-w- C:\Windows\System32\drivers\pctplsg64.sys 2012-06-24 15:56:22 ——– d—–w- C:\ProgramData\PC Tools 2012-06-24 15:56:22 ——– d—–w- C:\Program Files (x86)\PC Tools Security 2012-06-24 15:56:22 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools 2012-06-24 07:20:59 ——– d—–w- C:\ProgramData\Arizona Rose 2012-06-24 07:17:38 283200 —-a-w- C:\Windows\System32\drivers\dtsoftbus01.sys 2012-06-24 07:17:33 ——– d—–w- C:\Users\Home\AppData\Roaming\DAEMON Tools Pro 2012-06-24 07:17:30 ——– d—–w- C:\Program Files (x86)\DAEMON Tools Pro 2012-06-24 07:16:06 ——– d—–w- C:\ProgramData\DAEMON Tools Pro 2012-06-24 06:51:50 77312 —-a-w- C:\Windows\SysWow64\ztvunace26.dll 2012-06-24 06:51:50 75264 —-a-w- C:\Windows\SysWow64\unacev2.dll 2012-06-24 06:51:50 69632 —-a-w- C:\Windows\SysWow64\ztvcabinet.dll 2012-06-24 06:51:50 162304 —-a-w- C:\Windows\SysWow64\ztvunrar36.dll 2012-06-24 06:51:50 153088 —-a-w- C:\Windows\SysWow64\UNRAR3.dll 2012-06-24 06:51:50 ——– d—–w- C:\Users\Home\AppData\Roaming\Simply Super Software 2012-06-24 06:51:50 ——– d—–w- C:\ProgramData\Simply Super Software 2012-06-24 06:51:50 ——– d—–w- C:\Program Files (x86)\Trojan Remover 2012-06-21 09:48:07 2622464 —-a-w- C:\Windows\System32\wucltux.dll 2012-06-21 09:47:48 99840 —-a-w- C:\Windows\System32\wudriver.dll 2012-06-21 09:47:37 36864 —-a-w- C:\Windows\System32\wuapp.exe 2012-06-21 09:47:37 186752 —-a-w- C:\Windows\System32\wuwebv.dll 2012-06-17 15:57:23 ——– d—–w- C:\Users\Home\AppData\Roaming\V5 Play 2012-06-15 11:34:48 ——– d—–w- C:\Users\Home\AppData\Local\Microsoft Games 2012-06-14 05:41:00 ——– d—–w- C:\Users\Home\AppData\Roaming\quickclick 2012-06-12 15:49:22 ——– d—–w- C:\ProgramData\Fugazo 2012-06-05 16:29:57 ——– d—–w- C:\Output Files 2012-06-05 16:28:44 ——– d—–w- C:\Program Files (x86)\office Convert Pdf to Jpg Jpeg Tiff Free 2012-06-05 16:20:01 ——– d—–w- C:\Users\Home\AppData\Local\Adobe . ==================== Find3M ==================== . 2012-06-23 07:38:17 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-06-23 07:38:17 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-05-24 21:18:40 4472832 —-a-w- C:\Windows\SysWow64\GPhotos.scr 2012-05-18 02:06:48 2311680 —-a-w- C:\Windows\System32\jscript9.dll 2012-05-18 01:59:14 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-05-18 01:58:39 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-05-18 01:55:22 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-05-18 01:51:30 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-05-17 22:45:37 1800192 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-05-17 22:35:47 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-05-17 22:35:39 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-05-17 22:29:45 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-05-17 22:24:45 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-05-15 01:32:33 3146752 —-a-w- C:\Windows\System32\win32k.sys 2012-05-04 11:06:22 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe 2012-05-04 10:03:53 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03:50 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-05-01 10:52:00 419840 —-a-w- C:\Windows\System32\systemcpl.dll 2012-05-01 10:52:00 14848 —-a-w- C:\Windows\System32\slwga.dll 2012-05-01 10:52:00 13824 —-a-w- C:\Windows\SysWow64\slwga.dll 2012-05-01 10:51:59 833024 —-a-w- C:\Windows\SysWow64\user32.dll 2012-05-01 10:51:59 1008640 —-a-w- C:\Windows\System32\user32.dll 2012-05-01 05:40:20 209920 —-a-w- C:\Windows\System32\profsvc.dll 2012-04-28 05:32:05 1112064 —-a-w- C:\Windows\System32\rdpcorets.dll 2012-04-28 03:55:21 210944 —-a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-04-26 05:41:56 77312 —-a-w- C:\Windows\System32\rdpwsx.dll 2012-04-26 05:41:55 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll 2012-04-26 05:34:27 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe 2012-04-24 05:37:37 184320 —-a-w- C:\Windows\System32\cryptsvc.dll 2012-04-24 05:37:37 140288 —-a-w- C:\Windows\System32\cryptnet.dll 2012-04-24 05:37:36 1462272 —-a-w- C:\Windows\System32\crypt32.dll 2012-04-24 04:36:42 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll 2012-04-24 04:36:42 1158656 —-a-w- C:\Windows\SysWow64\crypt32.dll 2012-04-24 04:36:42 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll 2012-04-22 20:56:54 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2012-04-19 01:50:26 28480 —-a-w- C:\Windows\System32\drivers\avgidsha.sys 2012-04-07 12:31:40 3216384 —-a-w- C:\Windows\System32\msi.dll 2012-04-07 11:26:29 2342400 —-a-w- C:\Windows\SysWow64\msi.dll . ============= FINISH: 14:48:46.21 ===============
It’s all looking good. We need a couple of scans now and, if all is well, a final one before we can tidy up.


Download Malwarebytes-Anti-Malware

Click here
  • double-click mbam-setup.exe and follow the prompts to install the program.
  • at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
  • if an update is found, it will download and install the latest version.
  • once the program has loaded, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Logs to include with the next post:

Checkup.txt
Mbam.txt


Satchfan
Hello Here is the MBAM report: (no infections were found) Malwarebytes Anti-Malware (Trial) 1.61.0.1400 www.malwarebytes.org Database version: v2012.06.29.12 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Home :: HOME-PC [administrator] Protection: Enabled 30/06/2012 06:38:21 mbam-log-2012-06-30 (06-38-21).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 211283 Time elapsed: 1 minute(s), 59 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
And the checkup report:


Results of screen317's Security Check version 0.99.42
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG Anti-Virus Free Edition 2012
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Trojan Remover 6.8.4
Malwarebytes Anti-Malware version 1.61.0.1400
Java™ 6 Update 31
Java version out of Date!
Adobe Reader X (10.1.3)
Mozilla Firefox 12.0 Firefox out of Date!
Google Chrome 19.0.1084.46
Google Chrome 19.0.1084.56
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes Anti-Malware mbam.exe
AVG avgwdsvc.exe
AVG avgtray.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
Excellent.!!

One more and we should be ready to clean up.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

NOTE. If Eset doesn't find any threats, it won't produce a log.

Satchfan
Here is whet the ESET found: C:\Qoobox\Quarantine\C\Windows\Installer\{ac271d7b-5e2d-0342-1218-e7728d5d5798}\U\00000008.@.vir Win64/Agent.BA trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Windows\Installer\{ac271d7b-5e2d-0342-1218-e7728d5d5798}\U\80000000.@.vir Win64/Sirefef.AE trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Windows\System32\services.exe.vir Win64/Patched.A.Gen trojan deleted - quarantined F:\things from the old PC\ilan\Antivirus Business.Edition 4.0.417\eavbe_nt32_enu.exe a variant of Win32/PSW.Fignotok.K trojan cleaned by deleting - quarantined F:\things from the old PC\ilan\Programing Tools\Whole.Tomato.Visual.Assist.X.v10.5.1723.0.WinALL.Cracked-BRD.rar probably a variant of Win32/Agent.JQMSASQ trojan deleted - quarantined
The ones on your C drive are ComboFix's quarantined files and the others are stragglers that have now been deleted. Are there any remaining problems?
Well done YMR, your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

You can delete the DDS, TDSSKiller, SecurityCheck, RogueKiller and aswMBR logs and programs from your desktop. Just click on them and press Delete.


Uninstall Combofix

NOTE: it is important that you follow these directions carefully or you may lose your Internet connection.

Delete the existing ComboFix.exe from the following location by clicking on it and pressing Delete.:

c:\users\Home\Desktop\ComboFix.exe

Download a new version of Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It MUST be saved directly to your desktop. Choose save as and then make sure you choose Desktop

——————————————————————–

Follow these steps to uninstall Combofix
  • click START then RUN
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Uninstall OTL
  • double-click OTL.exe
  • click the CleanUp! button.
  • select Yes when the Begin cleanup Process? prompt appears.
  • if you are prompted to reboot during the cleanup, select Yes.
  • the tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

===================================================

Update installed programs

Java

You have an old version of Java on your computer which is vulnerable to infections.
  • from the Start menu, select Control Panel.
  • in Large or Small icon view, click Programs and Features. If you're using Category view, under "Programs", click Uninstall a program.
  • select any versions of Java then click Uninstall.
Install the latest version:here

===================================================

Recommended programs

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

=====================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Safe computing

Satchfan
After completing all the tasks in your last post I would like to say thanks SO much for all your help and patience :notworthy: . Goodbye and good luck to you :wavey:

I would like to say thanks SO much for all your help and patience

You are welcome. You made it easy by following the instructions well.

Goodbye and good luck to you

Likewise :adios:

I'll leave this open for now but but if I don't hear from you within 24 gours I will assume all is well and close the topic.

Take care

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI