Thien
Topic Starter
I've followed your advice on the link:
http://forums.whatthetech.com/index.php?showtopic=119298
because I've got the same problem with my laptop. Here is my DDS info:
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_33
Run by [removed] at 19:18:23 on 2012-08-08
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.293 [GMT -5:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
C:\Program Files (x86)\PremierOpinion\pmservice.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.1.3\ToolbarUpdater.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\taskeng.exe
C:\Users\Thien\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\PremierOpinion\pmropn.exe
C:\Program Files (x86)\PremierOpinion\pmropn64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cnnb
mStart Page = hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
mWinlogon: Userinit=userinit.exe
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.DLL
BHO: Funmoods Helper Object: {75ebb0aa-4214-4cb4-90ec-e3e07ecd04f7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll
BHO: hpBHO Class: {abd3b5e1-b268-407b-a150-2641dab8d898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Yontoo: {fd72061e-9fde-484d-a58a-0bab4151cad8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll
TB: Funmoods Toolbar: {a4c272ec-ed9e-4ace-a6f2-9558c7f29ef3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "C:\Users\Thien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [WorkForce 630(Network)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGBA.EXE /FU "C:\Windows\TEMP\E_SF0B7.tmp" /EF "HKCU"
mRun: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: []
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe
uPolicies-system: WallpaperStyle = 2
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-system: WallpaperStyle = 2
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{902A3B59-A9F9-43C2-8854-09D4115496C1} : DhcpNameServer = 192.168.1.254
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.1.3\ViProtocol.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO-X64: AVG Do Not Track - No File
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
BHO-X64: Symantec NCO BHO - No File
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.DLL
BHO-X64: Symantec Intrusion Prevention - No File
BHO-X64: Funmoods Helper Object: {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll
BHO-X64: Funmoods Helper Object - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll
BHO-X64: hpBHO Class: {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
BHO-X64: HelloWorldBHO - No File
BHO-X64: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
BHO-X64: Yontoo Layers - No File
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
TB-X64: Microsoft Live Search Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll
TB-X64: Funmoods Toolbar: {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun-x64: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun-x64: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun-x64: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun-x64: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Thien\AppData\Roaming\Mozilla\Firefox\Profiles\akl1pazt.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
FF - prefs.js: keyword.URL - hxxps://isearch.avg.com/search?cid=%7Bcc19fdf3-9d50-4c0f-87c5-9b31b71a8148%7D&mid=3c5273a2c57c47d0b4afd16f6b50cff9-42d5d20038674a4efbf7ad2d41bb5b37c74e16e1&ds=AVG&v=12.1.0.20&lang=en&pr=fr&d=2012-07-21%2014%3A04%3A17&sap=ku&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.1.3\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Thien\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Users\Thien\AppData\Local\Roblox\Versions\version-037c042a4c1b49fd\NPRobloxProxy.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
—- FIREFOX POLICIES —-
FF - user.js: extensions.funmoods.hmpg - true
FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
FF - user.js: extensions.funmoods.dfltSrch - true
FF - user.js: extensions.funmoods.srchPrvdr - Search
FF - user.js: extensions.funmoods.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146&q=
FF - user.js: extensions.funmoods.id - 904CE567BC665E66
FF - user.js: extensions.funmoods.instlDay - 15557
FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2213:47:14
FF - user.js: extensions.funmoods.prtnrId - funmoods
FF - user.js: extensions.funmoods.prdct - funmoods
FF - user.js: extensions.funmoods.aflt - axl
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods.tlbrId - base
FF - user.js: extensions.funmoods.instlRef - axl
FF - user.js: extensions.funmoods.dfltLng -
FF - user.js: extensions.funmoods.excTlbr - false
FF - user.js: extensions.funmoods.autoRvrt - false
FF - user.js: extensions.funmoods.envrmnt - production
FF - user.js: extensions.funmoods.isdcmntcmplt - true
FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
FF - user.js: extentions.y2layers.installId - 78d23cb2-aeae-4c1f-b71c-64aa6d34c49d
FF - user.js: extentions.y2layers.defaultEnableAppsList - pagerage,buzzdock,bestvideodownloader,ezlooker,dropdowndeals,twittube,toprelated
topics,interstitialads
.
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys –> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 avgtp;avgtp;\??\C:\Windows\system32\drivers\avgtpx64.sys –> C:\Windows\system32\drivers\avgtpx64.sys [?]
R1 BHDrvx64;Symantec Heuristics Driver;C:\Windows\system32\Drivers\NISx64\1008030.006\BHDrvx64.sys –> C:\Windows\system32\Drivers\NISx64\1008030.006\BHDrvx64.sys [?]
R1 ccHP;Symantec Hash Provider;C:\Windows\system32\Drivers\NISx64\1008030.006\ccHPx64.sys –> C:\Windows\system32\Drivers\NISx64\1008030.006\ccHPx64.sys [?]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20120807.001\IDSviA64.sys [2012-8-7 509088]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys –> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys –> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys –> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-8-6 138912]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys –> C:\Windows\system32\drivers\IntcHdmi.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys –> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys –> C:\Windows\system32\Drivers\RtsUStor.sys [?]
.
=============== Created Last 30 ================
.
2012-08-07 14:16:45 279160 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symtdi.sys
2012-08-07 14:16:44 56952 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symndisv.sys
2012-08-07 14:16:44 44152 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symndis.sys
2012-08-07 14:16:44 43640 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symids.sys
2012-08-07 14:16:43 476720 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\srtsp64.sys
2012-08-07 14:16:43 402992 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\SymEFA64.sys
2012-08-07 14:16:43 32304 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\srtspx64.sys
2012-08-07 14:16:43 120952 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symfw.sys
2012-08-07 14:16:42 334384 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\BHDrvx64.sys
2012-08-07 14:15:56 561800 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\cchpx64.sys
2012-08-07 14:15:54 ——– d—–w- C:\Windows\System32\drivers\NISx64\1008030.006
2012-08-06 21:07:55 476976 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-08-06 21:07:51 472880 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-05 18:48:38 ——– d—–w- C:\Program Files (x86)\PremierOpinion
2012-08-05 18:48:21 ——– d—–w- C:\Program Files (x86)\Yontoo
2012-08-05 18:48:18 ——– d—–w- C:\ProgramData\Tarma Installer
2012-08-05 18:47:18 ——– d—–w- C:\Program Files (x86)\Funmoods
2012-07-31 16:48:47 ——– d—–w- C:\Users\Thien\AppData\Roaming\Unity
2012-07-28 16:56:08 ——– d—–w- C:\Users\Thien\AppData\Local\Unity
2012-07-28 16:56:00 ——– d—–w- C:\Program Files (x86)\Unity
2012-07-26 22:07:19 ——– d—–w- C:\Users\Thien\AppData\Roaming\HP Support Assistant
2012-07-25 02:39:46 ——– d—–w- C:\ProgramData\KingsIsle Entertainment
2012-07-24 00:34:48 77824 —-a-w- C:\Windows\SysWow64\EBAPI.dll
2012-07-24 00:34:48 65536 —-a-w- C:\Windows\SysWow64\EEBUtil.dll
2012-07-24 00:34:48 55808 —-a-w- C:\Windows\SysWow64\EEBSDKIF.dll
2012-07-24 00:34:48 135168 —-a-w- C:\Windows\SysWow64\EEBAPI.dll
2012-07-24 00:34:48 110592 —-a-w- C:\Windows\SysWow64\EEBDSCVR.dll
2012-07-24 00:34:42 ——– d—–w- C:\Program Files\Common Files\EPSON
2012-07-24 00:32:15 ——– d—–w- C:\Program Files (x86)\EpsonNet
2012-07-24 00:31:34 558080 —-a-w- C:\Windows\System32\ensppmon.dll
2012-07-24 00:31:34 558080 —-a-w- C:\Windows\System32\enppmon.dll
2012-07-24 00:31:34 537600 —-a-w- C:\Windows\System32\ensppui.dll
2012-07-24 00:31:34 537600 —-a-w- C:\Windows\System32\enppui.dll
2012-07-24 00:31:34 250880 —-a-w- C:\Windows\System32\enspres.dll
2012-07-24 00:31:34 250880 —-a-w- C:\Windows\System32\enpres.dll
2012-07-24 00:31:34 ——– d—–w- C:\Program Files\EpsonNet
2012-07-24 00:31:10 ——– d—–w- C:\Program Files (x86)\Common Files\EPSON
2012-07-24 00:28:11 ——– d—–w- C:\Program Files (x86)\Epson Software
2012-07-24 00:26:54 80024 —-a-w- C:\Windows\SysWow64\PICSDK.dll
2012-07-24 00:26:54 51360 —-a-w- C:\Windows\SysWow64\EpPicPrt.dll
2012-07-24 00:26:54 51360 —-a-w- C:\Windows\SysWow64\EpPicMgr.dll
2012-07-24 00:26:54 501912 —-a-w- C:\Windows\SysWow64\PICSDK2.dll
2012-07-24 00:26:54 108704 —-a-w- C:\Windows\SysWow64\PICEntry.dll
2012-07-24 00:25:55 118784 —-a-w- C:\Windows\System32\E_ILMGBA.DLL
2012-07-24 00:25:51 88064 —-a-w- C:\Windows\System32\E_IBCBGBA.DLL
2012-07-24 00:25:31 ——– d—–w- C:\ProgramData\EPSON
2012-07-24 00:24:38 464384 —-a-w- C:\Windows\System32\esxw2ud.dll
2012-07-24 00:24:38 17408 —-a-w- C:\Windows\System32\esxcdev.dll
2012-07-24 00:24:38 128392 —-a-w- C:\Windows\System32\esdevapp.exe
2012-07-24 00:24:28 ——– d—–w- C:\Program Files (x86)\epson
2012-07-23 00:07:48 ——– d—–w- C:\Perfect World Entertainment
2012-07-23 00:01:36 258352 —-a-w- C:\Windows\SysWow64\unicows.dll
2012-07-22 22:59:53 ——– d—–w- C:\Users\Thien\AppData\Local\PMB Files
2012-07-22 22:59:49 ——– d—–w- C:\ProgramData\PMB Files
2012-07-22 22:59:34 ——– d—–w- C:\Program Files (x86)\Pando Networks
2012-07-22 18:19:56 ——– d—–w- C:\Users\Thien\AppData\Local\Roblox
2012-07-21 19:15:00 ——– d—–w- C:\Users\Thien\AppData\Roaming\AVG
2012-07-21 19:05:49 ——– d—–w- C:\Users\Thien\AppData\Roaming\AVG2012
2012-07-21 19:04:35 ——– d—–w- C:\Users\Thien\AppData\Local\AVG Secure Search
2012-07-21 19:04:29 ——– d—–w- C:\ProgramData\AVG Secure Search
2012-07-21 19:04:15 30568 —-a-w- C:\Windows\System32\drivers\avgtpx64.sys
2012-07-21 19:04:11 ——– d—–w- C:\Program Files (x86)\Common Files\AVG Secure Search
2012-07-21 19:04:11 ——– d—–w- C:\Program Files (x86)\AVG Secure Search
2012-07-21 19:03:31 ——– d—–w- C:\Windows\SysWow64\drivers\AVG
2012-07-21 19:02:47 ——– d–h–w- C:\$AVG
2012-07-21 19:02:46 ——– d—–w- C:\Windows\System32\drivers\AVG
2012-07-21 19:02:46 ——– d—–w- C:\ProgramData\AVG2012
2012-07-21 19:01:03 ——– d—–w- C:\Program Files (x86)\AVG
2012-07-21 18:58:34 ——– d—–w- C:\Program Files\CCleaner
2012-07-21 18:57:24 ——– d–h–w- C:\ProgramData\Common Files
2012-07-21 18:57:23 ——– d—–w- C:\ProgramData\MFAData
2012-07-21 18:42:16 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-07-21 12:12:28 142336 —-a-w- C:\Windows\System32\poqexec.exe
2012-07-21 12:12:28 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe
2012-07-21 12:05:58 1895280 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-07-21 11:52:14 77312 —-a-w- C:\Windows\System32\packager.dll
2012-07-21 11:52:14 67072 —-a-w- C:\Windows\SysWow64\packager.dll
2012-07-21 00:26:20 2868736 —-a-w- C:\Windows\explorer.exe
2012-07-21 00:26:20 2613248 —-a-w- C:\Windows\SysWow64\explorer.exe
2012-07-21 00:24:56 ——– d—–w- C:\Windows\ehome
2012-07-20 23:47:31 4398360 —-a-w- C:\Windows\System32\d3dx9_32.dll
2012-07-20 23:47:31 3426072 —-a-w- C:\Windows\SysWow64\d3dx9_32.dll
2012-07-20 23:47:28 ——– d—–w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-07-20 23:46:55 74520 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f18527ff1cd66d1\DSETUP.dll
2012-07-20 23:46:55 484632 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f18527ff1cd66d1\DXSETUP.exe
2012-07-20 23:46:55 1670936 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f18527ff1cd66d1\dsetup32.dll
2012-07-20 23:46:44 140066664 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\wlc4B61.tmp
2012-07-20 23:45:27 ——– d—–w- C:\Program Files (x86)\muvee Technologies
2012-07-20 23:45:19 ——– d—–w- C:\Program Files (x86)\Common Files\muvee Technologies
2012-07-20 23:36:58 ——– d—–w- C:\ProgramData\Recovery
2012-07-20 23:34:47 ——– d—–w- C:\Windows\SysWow64\x64
2012-07-20 23:34:47 ——– d—–w- C:\Windows\SysWow64\Lang
2012-07-20 23:34:46 997912 —-a-w- C:\Windows\SysWow64\igxpun.exe
2012-07-20 23:34:45 ——– d—–w- C:\Intel
2012-07-20 23:34:27 ——– d—–w- C:\Program Files\CONEXANT
2012-07-20 23:33:46 67584 —-a-w- C:\Windows\System32\RtNicProp64.dll
2012-07-20 23:33:46 215040 —-a-w- C:\Windows\System32\drivers\Rt64win7.sys
2012-07-20 23:33:35 ——– d—–w- C:\Program Files\Synaptics
2012-07-20 23:33:13 53248 —-a-w- C:\Windows\SysWow64\CSVer.dll
2012-07-20 23:32:39 1484800 —-a-w- C:\Windows\System32\drivers\athrx.sys
2012-07-20 23:32:39 ——– d—–w- C:\Program Files (x86)\Atheros
2012-07-20 23:32:34 ——– d—–w- C:\ProgramData\Atheros
2012-07-20 22:50:53 ——– d—–w- C:\Users\Thien\AppData\Local\Macromedia
2012-07-20 22:49:00 ——– d—–w- C:\Users\Thien\AppData\Local\Adobe
2012-07-20 22:45:05 ——– d—–w- C:\ProgramData\McAfee Security Scan
2012-07-20 22:45:02 ——– d—–w- C:\Program Files (x86)\McAfee Security Scan
2012-07-20 22:44:59 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-20 22:44:59 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-20 22:27:40 139264 —-a-w- C:\Windows\System32\cabview.dll
2012-07-20 22:27:40 132608 —-a-w- C:\Windows\SysWow64\cabview.dll
2012-07-20 22:27:38 826368 —-a-w- C:\Windows\SysWow64\rdpcore.dll
2012-07-20 22:27:38 23552 —-a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-07-20 22:27:38 204800 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-07-20 22:27:38 1031680 —-a-w- C:\Windows\System32\rdpcore.dll
2012-07-20 22:26:03 ——– d—–w- C:\Users\Thien\AppData\Local\Mozilla
2012-07-20 22:23:52 ——– d—–w- C:\Users\Thien\AppData\Roaming\HpUpdate
2012-07-20 22:23:44 ——– d—–w- C:\Users\Thien\AppData\Local\Google
2012-07-20 22:22:31 ——– d—–w- C:\Users\Thien\AppData\Local\Deployment
2012-07-20 22:22:31 ——– d—–w- C:\Users\Thien\AppData\Local\Apps
2012-07-20 22:21:14 2622464 —-a-w- C:\Windows\System32\wucltux.dll
2012-07-20 22:20:34 99840 —-a-w- C:\Windows\System32\wudriver.dll
2012-07-20 22:20:34 31280 —-a-r- C:\Windows\System32\drivers\SymIMV.sys
2012-07-20 22:20:29 172592 —-a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-07-20 22:20:27 ——– d—–w- C:\Program Files\Symantec
2012-07-20 22:20:27 ——– d—–w- C:\Program Files\Common Files\Symantec Shared
2012-07-20 22:20:17 36864 —-a-w- C:\Windows\System32\wuapp.exe
2012-07-20 22:20:17 186752 —-a-w- C:\Windows\System32\wuwebv.dll
2012-07-20 22:18:17 ——– d—–w- C:\Users\Thien\AppData\Local\VirtualStore
2012-07-20 22:17:59 ——– d—–w- C:\Users\Thien\AppData\Roaming\hpqlog
2012-07-20 22:17:56 ——– d—–w- C:\Users\Thien\AppData\Local\Hewlett-Packard
2012-07-20 22:15:15 ——– d—–w- C:\Users\Thien\AppData\Roaming\HP TCS
.
==================== Find3M ====================
.
.
============= FINISH: 19:22:06.37 ===============
http://forums.whatthetech.com/index.php?showtopic=119298
because I've got the same problem with my laptop. Here is my DDS info:
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_33
Run by [removed] at 19:18:23 on 2012-08-08
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.293 [GMT -5:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
C:\Program Files (x86)\PremierOpinion\pmservice.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.1.3\ToolbarUpdater.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\taskeng.exe
C:\Users\Thien\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\PremierOpinion\pmropn.exe
C:\Program Files (x86)\PremierOpinion\pmropn64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cnnb
mStart Page = hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
mWinlogon: Userinit=userinit.exe
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.DLL
BHO: Funmoods Helper Object: {75ebb0aa-4214-4cb4-90ec-e3e07ecd04f7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll
BHO: hpBHO Class: {abd3b5e1-b268-407b-a150-2641dab8d898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Yontoo: {fd72061e-9fde-484d-a58a-0bab4151cad8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll
TB: Funmoods Toolbar: {a4c272ec-ed9e-4ace-a6f2-9558c7f29ef3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "C:\Users\Thien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [WorkForce 630(Network)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGBA.EXE /FU "C:\Windows\TEMP\E_SF0B7.tmp" /EF "HKCU"
mRun: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: []
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe
uPolicies-system: WallpaperStyle = 2
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-system: WallpaperStyle = 2
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{902A3B59-A9F9-43C2-8854-09D4115496C1} : DhcpNameServer = 192.168.1.254
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.1.3\ViProtocol.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO-X64: AVG Do Not Track - No File
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
BHO-X64: Symantec NCO BHO - No File
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.DLL
BHO-X64: Symantec Intrusion Prevention - No File
BHO-X64: Funmoods Helper Object: {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll
BHO-X64: Funmoods Helper Object - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll
BHO-X64: hpBHO Class: {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
BHO-X64: HelloWorldBHO - No File
BHO-X64: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
BHO-X64: Yontoo Layers - No File
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll
TB-X64: Microsoft Live Search Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.1.0.20\AVG Secure Search_toolbar.dll
TB-X64: Funmoods Toolbar: {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun-x64: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun-x64: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun-x64: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
mRun-x64: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Thien\AppData\Roaming\Mozilla\Firefox\Profiles\akl1pazt.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
FF - prefs.js: keyword.URL - hxxps://isearch.avg.com/search?cid=%7Bcc19fdf3-9d50-4c0f-87c5-9b31b71a8148%7D&mid=3c5273a2c57c47d0b4afd16f6b50cff9-42d5d20038674a4efbf7ad2d41bb5b37c74e16e1&ds=AVG&v=12.1.0.20&lang=en&pr=fr&d=2012-07-21%2014%3A04%3A17&sap=ku&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.1.3\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Thien\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Users\Thien\AppData\Local\Roblox\Versions\version-037c042a4c1b49fd\NPRobloxProxy.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
—- FIREFOX POLICIES —-
FF - user.js: extensions.funmoods.hmpg - true
FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
FF - user.js: extensions.funmoods.dfltSrch - true
FF - user.js: extensions.funmoods.srchPrvdr - Search
FF - user.js: extensions.funmoods.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146
FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://start.funmoods.com/?f=3&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzuzytDyE0C0EyDyCyB0B0CyCyCyD0EyCyCtN0D0Tzu0CtBtCzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1669928146&q=
FF - user.js: extensions.funmoods.id - 904CE567BC665E66
FF - user.js: extensions.funmoods.instlDay - 15557
FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2213:47:14
FF - user.js: extensions.funmoods.prtnrId - funmoods
FF - user.js: extensions.funmoods.prdct - funmoods
FF - user.js: extensions.funmoods.aflt - axl
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods.tlbrId - base
FF - user.js: extensions.funmoods.instlRef - axl
FF - user.js: extensions.funmoods.dfltLng -
FF - user.js: extensions.funmoods.excTlbr - false
FF - user.js: extensions.funmoods.autoRvrt - false
FF - user.js: extensions.funmoods.envrmnt - production
FF - user.js: extensions.funmoods.isdcmntcmplt - true
FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
FF - user.js: extentions.y2layers.installId - 78d23cb2-aeae-4c1f-b71c-64aa6d34c49d
FF - user.js: extentions.y2layers.defaultEnableAppsList - pagerage,buzzdock,bestvideodownloader,ezlooker,dropdowndeals,twittube,toprelated
topics,interstitialads
.
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys –> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 avgtp;avgtp;\??\C:\Windows\system32\drivers\avgtpx64.sys –> C:\Windows\system32\drivers\avgtpx64.sys [?]
R1 BHDrvx64;Symantec Heuristics Driver;C:\Windows\system32\Drivers\NISx64\1008030.006\BHDrvx64.sys –> C:\Windows\system32\Drivers\NISx64\1008030.006\BHDrvx64.sys [?]
R1 ccHP;Symantec Hash Provider;C:\Windows\system32\Drivers\NISx64\1008030.006\ccHPx64.sys –> C:\Windows\system32\Drivers\NISx64\1008030.006\ccHPx64.sys [?]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20120807.001\IDSviA64.sys [2012-8-7 509088]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys –> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys –> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys –> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-8-6 138912]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys –> C:\Windows\system32\drivers\IntcHdmi.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys –> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys –> C:\Windows\system32\Drivers\RtsUStor.sys [?]
.
=============== Created Last 30 ================
.
2012-08-07 14:16:45 279160 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symtdi.sys
2012-08-07 14:16:44 56952 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symndisv.sys
2012-08-07 14:16:44 44152 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symndis.sys
2012-08-07 14:16:44 43640 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symids.sys
2012-08-07 14:16:43 476720 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\srtsp64.sys
2012-08-07 14:16:43 402992 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\SymEFA64.sys
2012-08-07 14:16:43 32304 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\srtspx64.sys
2012-08-07 14:16:43 120952 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\symfw.sys
2012-08-07 14:16:42 334384 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\BHDrvx64.sys
2012-08-07 14:15:56 561800 —-a-w- C:\Windows\System32\drivers\NISx64\1008030.006\cchpx64.sys
2012-08-07 14:15:54 ——– d—–w- C:\Windows\System32\drivers\NISx64\1008030.006
2012-08-06 21:07:55 476976 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-08-06 21:07:51 472880 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-05 18:48:38 ——– d—–w- C:\Program Files (x86)\PremierOpinion
2012-08-05 18:48:21 ——– d—–w- C:\Program Files (x86)\Yontoo
2012-08-05 18:48:18 ——– d—–w- C:\ProgramData\Tarma Installer
2012-08-05 18:47:18 ——– d—–w- C:\Program Files (x86)\Funmoods
2012-07-31 16:48:47 ——– d—–w- C:\Users\Thien\AppData\Roaming\Unity
2012-07-28 16:56:08 ——– d—–w- C:\Users\Thien\AppData\Local\Unity
2012-07-28 16:56:00 ——– d—–w- C:\Program Files (x86)\Unity
2012-07-26 22:07:19 ——– d—–w- C:\Users\Thien\AppData\Roaming\HP Support Assistant
2012-07-25 02:39:46 ——– d—–w- C:\ProgramData\KingsIsle Entertainment
2012-07-24 00:34:48 77824 —-a-w- C:\Windows\SysWow64\EBAPI.dll
2012-07-24 00:34:48 65536 —-a-w- C:\Windows\SysWow64\EEBUtil.dll
2012-07-24 00:34:48 55808 —-a-w- C:\Windows\SysWow64\EEBSDKIF.dll
2012-07-24 00:34:48 135168 —-a-w- C:\Windows\SysWow64\EEBAPI.dll
2012-07-24 00:34:48 110592 —-a-w- C:\Windows\SysWow64\EEBDSCVR.dll
2012-07-24 00:34:42 ——– d—–w- C:\Program Files\Common Files\EPSON
2012-07-24 00:32:15 ——– d—–w- C:\Program Files (x86)\EpsonNet
2012-07-24 00:31:34 558080 —-a-w- C:\Windows\System32\ensppmon.dll
2012-07-24 00:31:34 558080 —-a-w- C:\Windows\System32\enppmon.dll
2012-07-24 00:31:34 537600 —-a-w- C:\Windows\System32\ensppui.dll
2012-07-24 00:31:34 537600 —-a-w- C:\Windows\System32\enppui.dll
2012-07-24 00:31:34 250880 —-a-w- C:\Windows\System32\enspres.dll
2012-07-24 00:31:34 250880 —-a-w- C:\Windows\System32\enpres.dll
2012-07-24 00:31:34 ——– d—–w- C:\Program Files\EpsonNet
2012-07-24 00:31:10 ——– d—–w- C:\Program Files (x86)\Common Files\EPSON
2012-07-24 00:28:11 ——– d—–w- C:\Program Files (x86)\Epson Software
2012-07-24 00:26:54 80024 —-a-w- C:\Windows\SysWow64\PICSDK.dll
2012-07-24 00:26:54 51360 —-a-w- C:\Windows\SysWow64\EpPicPrt.dll
2012-07-24 00:26:54 51360 —-a-w- C:\Windows\SysWow64\EpPicMgr.dll
2012-07-24 00:26:54 501912 —-a-w- C:\Windows\SysWow64\PICSDK2.dll
2012-07-24 00:26:54 108704 —-a-w- C:\Windows\SysWow64\PICEntry.dll
2012-07-24 00:25:55 118784 —-a-w- C:\Windows\System32\E_ILMGBA.DLL
2012-07-24 00:25:51 88064 —-a-w- C:\Windows\System32\E_IBCBGBA.DLL
2012-07-24 00:25:31 ——– d—–w- C:\ProgramData\EPSON
2012-07-24 00:24:38 464384 —-a-w- C:\Windows\System32\esxw2ud.dll
2012-07-24 00:24:38 17408 —-a-w- C:\Windows\System32\esxcdev.dll
2012-07-24 00:24:38 128392 —-a-w- C:\Windows\System32\esdevapp.exe
2012-07-24 00:24:28 ——– d—–w- C:\Program Files (x86)\epson
2012-07-23 00:07:48 ——– d—–w- C:\Perfect World Entertainment
2012-07-23 00:01:36 258352 —-a-w- C:\Windows\SysWow64\unicows.dll
2012-07-22 22:59:53 ——– d—–w- C:\Users\Thien\AppData\Local\PMB Files
2012-07-22 22:59:49 ——– d—–w- C:\ProgramData\PMB Files
2012-07-22 22:59:34 ——– d—–w- C:\Program Files (x86)\Pando Networks
2012-07-22 18:19:56 ——– d—–w- C:\Users\Thien\AppData\Local\Roblox
2012-07-21 19:15:00 ——– d—–w- C:\Users\Thien\AppData\Roaming\AVG
2012-07-21 19:05:49 ——– d—–w- C:\Users\Thien\AppData\Roaming\AVG2012
2012-07-21 19:04:35 ——– d—–w- C:\Users\Thien\AppData\Local\AVG Secure Search
2012-07-21 19:04:29 ——– d—–w- C:\ProgramData\AVG Secure Search
2012-07-21 19:04:15 30568 —-a-w- C:\Windows\System32\drivers\avgtpx64.sys
2012-07-21 19:04:11 ——– d—–w- C:\Program Files (x86)\Common Files\AVG Secure Search
2012-07-21 19:04:11 ——– d—–w- C:\Program Files (x86)\AVG Secure Search
2012-07-21 19:03:31 ——– d—–w- C:\Windows\SysWow64\drivers\AVG
2012-07-21 19:02:47 ——– d–h–w- C:\$AVG
2012-07-21 19:02:46 ——– d—–w- C:\Windows\System32\drivers\AVG
2012-07-21 19:02:46 ——– d—–w- C:\ProgramData\AVG2012
2012-07-21 19:01:03 ——– d—–w- C:\Program Files (x86)\AVG
2012-07-21 18:58:34 ——– d—–w- C:\Program Files\CCleaner
2012-07-21 18:57:24 ——– d–h–w- C:\ProgramData\Common Files
2012-07-21 18:57:23 ——– d—–w- C:\ProgramData\MFAData
2012-07-21 18:42:16 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-07-21 12:12:28 142336 —-a-w- C:\Windows\System32\poqexec.exe
2012-07-21 12:12:28 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe
2012-07-21 12:05:58 1895280 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-07-21 11:52:14 77312 —-a-w- C:\Windows\System32\packager.dll
2012-07-21 11:52:14 67072 —-a-w- C:\Windows\SysWow64\packager.dll
2012-07-21 00:26:20 2868736 —-a-w- C:\Windows\explorer.exe
2012-07-21 00:26:20 2613248 —-a-w- C:\Windows\SysWow64\explorer.exe
2012-07-21 00:24:56 ——– d—–w- C:\Windows\ehome
2012-07-20 23:47:31 4398360 —-a-w- C:\Windows\System32\d3dx9_32.dll
2012-07-20 23:47:31 3426072 —-a-w- C:\Windows\SysWow64\d3dx9_32.dll
2012-07-20 23:47:28 ——– d—–w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2012-07-20 23:46:55 74520 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f18527ff1cd66d1\DSETUP.dll
2012-07-20 23:46:55 484632 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f18527ff1cd66d1\DXSETUP.exe
2012-07-20 23:46:55 1670936 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f18527ff1cd66d1\dsetup32.dll
2012-07-20 23:46:44 140066664 —-a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\wlc4B61.tmp
2012-07-20 23:45:27 ——– d—–w- C:\Program Files (x86)\muvee Technologies
2012-07-20 23:45:19 ——– d—–w- C:\Program Files (x86)\Common Files\muvee Technologies
2012-07-20 23:36:58 ——– d—–w- C:\ProgramData\Recovery
2012-07-20 23:34:47 ——– d—–w- C:\Windows\SysWow64\x64
2012-07-20 23:34:47 ——– d—–w- C:\Windows\SysWow64\Lang
2012-07-20 23:34:46 997912 —-a-w- C:\Windows\SysWow64\igxpun.exe
2012-07-20 23:34:45 ——– d—–w- C:\Intel
2012-07-20 23:34:27 ——– d—–w- C:\Program Files\CONEXANT
2012-07-20 23:33:46 67584 —-a-w- C:\Windows\System32\RtNicProp64.dll
2012-07-20 23:33:46 215040 —-a-w- C:\Windows\System32\drivers\Rt64win7.sys
2012-07-20 23:33:35 ——– d—–w- C:\Program Files\Synaptics
2012-07-20 23:33:13 53248 —-a-w- C:\Windows\SysWow64\CSVer.dll
2012-07-20 23:32:39 1484800 —-a-w- C:\Windows\System32\drivers\athrx.sys
2012-07-20 23:32:39 ——– d—–w- C:\Program Files (x86)\Atheros
2012-07-20 23:32:34 ——– d—–w- C:\ProgramData\Atheros
2012-07-20 22:50:53 ——– d—–w- C:\Users\Thien\AppData\Local\Macromedia
2012-07-20 22:49:00 ——– d—–w- C:\Users\Thien\AppData\Local\Adobe
2012-07-20 22:45:05 ——– d—–w- C:\ProgramData\McAfee Security Scan
2012-07-20 22:45:02 ——– d—–w- C:\Program Files (x86)\McAfee Security Scan
2012-07-20 22:44:59 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-20 22:44:59 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-20 22:27:40 139264 —-a-w- C:\Windows\System32\cabview.dll
2012-07-20 22:27:40 132608 —-a-w- C:\Windows\SysWow64\cabview.dll
2012-07-20 22:27:38 826368 —-a-w- C:\Windows\SysWow64\rdpcore.dll
2012-07-20 22:27:38 23552 —-a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-07-20 22:27:38 204800 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-07-20 22:27:38 1031680 —-a-w- C:\Windows\System32\rdpcore.dll
2012-07-20 22:26:03 ——– d—–w- C:\Users\Thien\AppData\Local\Mozilla
2012-07-20 22:23:52 ——– d—–w- C:\Users\Thien\AppData\Roaming\HpUpdate
2012-07-20 22:23:44 ——– d—–w- C:\Users\Thien\AppData\Local\Google
2012-07-20 22:22:31 ——– d—–w- C:\Users\Thien\AppData\Local\Deployment
2012-07-20 22:22:31 ——– d—–w- C:\Users\Thien\AppData\Local\Apps
2012-07-20 22:21:14 2622464 —-a-w- C:\Windows\System32\wucltux.dll
2012-07-20 22:20:34 99840 —-a-w- C:\Windows\System32\wudriver.dll
2012-07-20 22:20:34 31280 —-a-r- C:\Windows\System32\drivers\SymIMV.sys
2012-07-20 22:20:29 172592 —-a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-07-20 22:20:27 ——– d—–w- C:\Program Files\Symantec
2012-07-20 22:20:27 ——– d—–w- C:\Program Files\Common Files\Symantec Shared
2012-07-20 22:20:17 36864 —-a-w- C:\Windows\System32\wuapp.exe
2012-07-20 22:20:17 186752 —-a-w- C:\Windows\System32\wuwebv.dll
2012-07-20 22:18:17 ——– d—–w- C:\Users\Thien\AppData\Local\VirtualStore
2012-07-20 22:17:59 ——– d—–w- C:\Users\Thien\AppData\Roaming\hpqlog
2012-07-20 22:17:56 ——– d—–w- C:\Users\Thien\AppData\Local\Hewlett-Packard
2012-07-20 22:15:15 ——– d—–w- C:\Users\Thien\AppData\Roaming\HP TCS
.
==================== Find3M ====================
.
.
============= FINISH: 19:22:06.37 ===============