This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My first BSOD... Windows 7 trying to fix myself [Solved]

74 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am totally stumped with this problem I am having with my Dell Inspiron. One day the laptop was just sitting there… I use it to watch netflix, hulu, and news sites over my flatscreen…. and it started acting like it had a life of its own and shut itself down. after rebooting itself it went into a BSOD and just kept repeating the cycle. shutdown..BSOD..shutdown..BSOD…etc. I am able to power it off and f8 it until I can get into safe mode. Bluescreen view highlights the files causing the problem… FSPFltd.sys and NTOSKRNL.exe. My computer guy tells me its a virus and says it will take him time to clean it… he suggested I might want to try it myself … he suggested I use Rkill and then install a free antivirus program to find the culprits. I have run Rkill and I am now at the end of the Malwarebytes scan. Malearebytes says I have a trojan.agent svchost.exe malicious software on the computer… is that where my problem lies? Does anyone have suggestions on how I proceed from here? Thanks in advance
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Malearebytes says I have a trojan.agent svchost.exe malicious software on the computer… is that where my problem lies?

Please post the log that was made by Malwarebytes.
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Huuhhhh?… well I'll be danged. I was starting it up and waiting for the initial screen where I can tap F8 to get it into safe mode. It popped me into the safe mode selection screen and this time it had several other otions to select.. One of the options was at the very top. It was (I don't remember exactly) a choice to "repair computer boot problems" or something like that. I had never seen that choice before when I was playing with it getting in and out of safe mode.. trying to fix the BSOD. That choice took me to a screen that was light blue in color and one of the choices there was to restore the computer to the way it was at an earlier time. So I chose that option… I was curious what would happen. That option took me to a screen that had the sytem settings from previous dates. One of the choices was August 6, Another choice was July 12th. I chose the one for August and it started a progress screen that was telling me "files being restored" or something like that. That took about 10 or 12 minutes. After it said "finfshing restoring files it stopped and said "finished". I then clicke on ok and I believe it just started rebooting itself. I kept watching the screen to see if it blinked on me during the "welcome" screen… which is what it was doing to me…. it would blink at that point and then immediately go into BSOD… It would then just keep cycling reboot…BSOD…reboot…BSOD. Anyway. This time it did not blink on me and it completed the "welcome screen" routine. Finally …LO and Behold… the computer rebooted just like if nothing was wrong with it!! I tried restarting to test it again and it rebooted just fine. Jeffce… do you have any clue what the heck just happened to my computer? Should I check anything else now that it is running normal? Will it crash on me again? I guess I should give you a littel more background on this machine. My wife and I had a wreck… totalled the car and theh computer was tossed around like a pinball. Ended up having the screen shattered but the computer worked after the hardrive was reseated. I ran it that way for a while viewing the vidoe on a flat screen. Eventually it jsut stopped working and my computer guy told me the screen was causing it to crash. He changed the screen for me (200 bucks including labor) and it ran just fine for about two months. Then I got this BSOD problem last week around the 6th or 7th. And here I am now with a computer that is now working but not sure if it will blow up on me. So anyway… do you have any suggestions for me? What shoudl I check? Btw I very much appreciate your quick response during my time of need. Thanks
Well it sounds as if that computer has been through some turmoil. :) Go ahead and run the scans for DDS and aswMBR.exe like I had posted for before.
Bad news.. the problem reoccurred. I was again able to recover it and I was downloading the dds and asMBR files as you directed when the power chord popped off. My battery only lasts about 25 minutes and I was unaware it popped off so the computer died while in the middle of doing another malware scan. I plugged it in but it again wient into the safe mode screen. I selected to start computer normally and it popped me into a start up repair screen… it took 20 minutes and finally came back with "cannot repair computer". Details showed: Problem event: startup repair offline problem signature 01: 6.1.7600.16385 problem signature 02: 6.1.7600.16385 problem signature 02: unkown problem signature 02: 21201083 problem signature 02: normal repair problem signature 02: 2 problem signature 02: NoBoot failure problem signature 02: OS version: 6.1.7600.2.0.0.256.1 Local ID: 1033 I was again successful in restoring windows to an earlier point in time but my AVG and Malware did not show along with those dds and asMBR files. So I am once abin loading those and wioll do a malware scan and try running those files you sent me….. More to come. ohh boy. I am beginning to think this is a hardware problem instead of a virus. I'll send those logs after I can get to run them. Thanks :huh: :(
When you get those downloaded and ran please post the logs. If you need to download and run the tool in Safe Mode with Networking go ahead and do that. :)
Well after a couple of BSODs and reboots to normal windows I got all the scans completed and here are the logs. First Malwarebytes. It picked up the three trojan.agent files I asked it to clean a couple of days ago. Here is the latest scan log: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.19.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Manuel :: MANUEL-PC [administrator] 8/19/2012 9:55:48 AM mbam-log-2012-08-19 (12-09-29).txt Scan type: Full scan (C:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 478643 Time elapsed: 2 hour(s), 6 minute(s), 29 second(s) Memory Processes Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> 8428 -> No action taken. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Users\Manuel\AppData\Local\Temp\BDD6.tmp (Trojan.Agent.BRVGen) -> No action taken. C:\Windows\svchost.exe (Trojan.Agent) -> No action taken. (end) Next ran DDS scan, here is that DDS.txt log: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_34 Run by [removed] at 12:11:03 on 2012-08-19 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4056.1948 [GMT -5:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\PROGRA~2\AVG\AVG2012\avgrsa.exe C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe C:\Program Files (x86)\AVG\AVG2012\avgemca.exe c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe C:\Program Files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\My Lockbox\mylbx.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files (x86)\Evaer\videochannel.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe C:\Program Files\DellTPad\HidFind.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe C:\Program Files (x86)\real\realplayer\Update\realsched.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\AVG\AVG2012\avgtray.exe C:\Program Files (x86)\AVG Secure Search\vprot.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\system32\conhost.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\AVG\AVG2012\avgui.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\AVG\AVG2012\avgsrmaa.exe C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files (x86)\JGsoft\EditPadLite\EditPadLite.exe -netsvcs C:\Windows\system32\conhost.exe C:\Windows\system32\taskeng.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uSearch Bar = Preserve mStart Page = about:blank mURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Solid Converter PDF: {259f616c-a300-44f5-b04a-ed001a26c85c} - C:\Program Files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\12.2.0.5\AVG Secure Search_toolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB: Solid Converter PDF: {259f616c-a300-44f5-b04a-ed001a26c85c} - C:\Program Files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB: {aac55042-b985-4a23-a4c9-3ba84830ef84} - No File TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\12.2.0.5\AVG Secure Search_toolbar.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet uRun: [avichannel] "C:\Program Files (x86)\Evaer\videochannel.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s mRun: [QuickFinder Scheduler] "c:\Program Files (x86)\Corel\WordPerfect Office X5\Programs\QFSCHD150.EXE" mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" mRun: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Copy to &Lightning; Note - C:\Program Files (x86)\Corel\WordPerfect Lightning\Programs\WPLightningCopyToNote.hta IE: Open with WordPerfect - c:\Program Files (x86)\Corel\WordPerfect Office X5\Programs\WPLauncher.hta IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL Trusted Zone: intuit.com\ttlc DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB DPF: {CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://transoftsolutionsevents.webex.com/client/T27LB/event/ieatgpc1.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.254.254 TCP: Interfaces\{715E6297-B9BA-4101-AB49-8A3061AB65E6} : DhcpNameServer = 192.168.254.254 TCP: Interfaces\{715E6297-B9BA-4101-AB49-8A3061AB65E6}\2627534393 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{715E6297-B9BA-4101-AB49-8A3061AB65E6}\6596277696E6D4F62696C65602D4966496232303030244931302355636572756 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{715E6297-B9BA-4101-AB49-8A3061AB65E6}\D696461647C616E64796362626 : DhcpNameServer = 10.71.0.1 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.0\ViProtocol.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Solid Converter PDF: {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll BHO-X64: AVG Do Not Track - No File BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.0.5\AVG Secure Search_toolbar.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO-X64: SkypeIEPluginBHO - No File BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll BHO-X64: SmartSelect - No File TB-X64: Solid Converter PDF: {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB-X64: {aac55042-b985-4a23-a4c9-3ba84830ef84} - No File TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.0.5\AVG Secure Search_toolbar.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter mRun-x64: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s mRun-x64: [QuickFinder Scheduler] "c:\Program Files (x86)\Corel\WordPerfect Office X5\Programs\QFSCHD150.EXE" mRun-x64: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" mRun-x64: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" mRunOnce-x64: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Manuel\AppData\Roaming\Mozilla\Firefox\Profiles\kp6s54a2.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 59274 FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Weathersoft\NpWeatherScope32.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll FF - plugin: C:\Users\Manuel\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys –> C:\Windows\system32\DRIVERS\avgidsha.sys [?] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?] R0 FSProFilter;FSPro File Filter;C:\Windows\system32\Drivers\FSPFltd.sys –> C:\Windows\system32\Drivers\FSPFltd.sys [?] R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?] R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?] R1 avgtp;avgtp;\??\C:\Windows\system32\drivers\avgtpx64.sys –> C:\Windows\system32\drivers\avgtpx64.sys [?] R1 sbtis;sbtis;C:\Windows\system32\drivers\sbtis.sys –> C:\Windows\system32\drivers\sbtis.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-7-4 5160568] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288] R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648] R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys –> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys –> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys –> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys –> C:\Windows\system32\Drivers\RtsUStor.sys [?] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys –> C:\Windows\system32\DRIVERS\yk62x64.sys [?] S2 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-21 136176] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-6-21 250056] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-21 136176] S3 SUSTUCAM;Susteen USB Cable Modem Driver;C:\Windows\system32\DRIVERS\sustucam.sys –> C:\Windows\system32\DRIVERS\sustucam.sys [?] S3 SUSTUCAP;Susteen USB Cable Port Driver;C:\Windows\system32\DRIVERS\sustucap.sys –> C:\Windows\system32\DRIVERS\sustucap.sys [?] S3 SUSTUCAU;Susteen USB Cable USB Driver;C:\Windows\system32\DRIVERS\sustucau.sys –> C:\Windows\system32\DRIVERS\sustucau.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys –> C:\Windows\system32\DRIVERS\wdcsam64.sys [?] . =============== Created Last 30 ================ . 2012-08-19 14:53:15 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-08-19 03:21:11 31080 —-a-w- C:\Windows\System32\drivers\avgtpx64.sys 2012-08-19 03:21:04 ——– d—–w- C:\Program Files (x86)\AVG Secure Search 2012-08-19 03:19:11 ——– d—–w- C:\Windows\System32\drivers\AVG 2012-08-19 03:13:32 9133488 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8B620935-52B6-4707-9D20-A83CDCE0E351}\mpengine.dll 2012-08-19 03:00:40 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-08-19 02:58:54 ——– d—–w- C:\AntiVirus 2012-08-19 00:22:10 ——– d—–w- C:\Users\Manuel\AppData\Roaming\AVG2012 2012-08-19 00:20:52 ——– d—–w- C:\Users\Manuel\AppData\Local\AVG Secure Search 2012-08-19 00:20:50 ——– d—–w- C:\ProgramData\AVG Secure Search 2012-08-19 00:20:29 ——– d—–w- C:\Program Files (x86)\Common Files\AVG Secure Search 2012-08-19 00:17:14 ——– d–h–w- C:\$AVG 2012-08-19 00:17:14 ——– d—–w- C:\ProgramData\AVG2012 2012-08-19 00:02:19 ——– d–h–w- C:\ProgramData\Common Files 2012-08-19 00:02:19 ——– d—–w- C:\ProgramData\MFAData 2012-08-18 23:53:33 477168 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll 2012-08-18 23:33:17 20480 —-a-w- C:\Windows\svchost.exe 2012-08-12 14:45:07 ——– d—–w- C:\Program Files (x86)\SopCast 2012-07-23 01:46:50 ——– d—–w- C:\ProgramData\ParetoLogic 2012-07-23 01:46:50 ——– d—–w- C:\Program Files (x86)\Common Files\ParetoLogic . ==================== Find3M ==================== . 2012-08-19 03:08:15 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-19 03:08:15 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-08-18 23:53:10 473072 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2012-07-18 18:15:06 3148800 —-a-w- C:\Windows\System32\win32k.sys 2012-07-04 22:13:27 59392 —-a-w- C:\Windows\System32\browcli.dll 2012-07-04 22:13:27 136704 —-a-w- C:\Windows\System32\browser.dll 2012-07-04 21:14:34 41984 —-a-w- C:\Windows\SysWow64\browcli.dll 2012-06-29 03:56:34 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-06-29 03:49:11 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-06-29 03:48:07 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-06-29 03:43:49 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-06-29 03:39:48 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-06-29 00:16:58 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-06-29 00:09:01 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-06-29 00:08:59 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-06-29 00:04:43 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-06-29 00:00:45 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-06-28 16:07:16 175616 —-a-w- C:\Windows\System32\msclmd.dll 2012-06-28 16:07:16 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll 2012-06-21 23:51:32 499712 —-a-w- C:\Windows\SysWow64\msvcp71.dll 2012-06-21 23:51:32 348160 —-a-w- C:\Windows\SysWow64\msvcr71.dll 2012-06-06 06:06:16 2004480 —-a-w- C:\Windows\System32\msxml6.dll 2012-06-06 06:06:16 1881600 —-a-w- C:\Windows\System32\msxml3.dll 2012-06-06 06:02:54 1133568 —-a-w- C:\Windows\System32\cdosys.dll 2012-06-06 05:05:52 1390080 —-a-w- C:\Windows\SysWow64\msxml6.dll 2012-06-06 05:05:52 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll 2012-06-06 05:03:06 805376 —-a-w- C:\Windows\SysWow64\cdosys.dll 2012-06-02 22:15:31 2622464 —-a-w- C:\Windows\System32\wucltux.dll 2012-06-02 22:15:08 99840 —-a-w- C:\Windows\System32\wudriver.dll 2012-06-02 20:19:42 186752 —-a-w- C:\Windows\System32\wuwebv.dll 2012-06-02 20:15:12 36864 —-a-w- C:\Windows\System32\wuapp.exe 2012-06-02 05:50:10 458704 —-a-w- C:\Windows\System32\drivers\cng.sys 2012-06-02 05:48:16 95600 —-a-w- C:\Windows\System32\drivers\ksecdd.sys 2012-06-02 05:48:16 151920 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys 2012-06-02 05:45:31 340992 —-a-w- C:\Windows\System32\schannel.dll 2012-06-02 05:44:21 307200 —-a-w- C:\Windows\System32\ncrypt.dll 2012-06-02 04:40:42 22016 —-a-w- C:\Windows\SysWow64\secur32.dll 2012-06-02 04:40:39 225280 —-a-w- C:\Windows\SysWow64\schannel.dll 2012-06-02 04:39:10 219136 —-a-w- C:\Windows\SysWow64\ncrypt.dll 2012-06-02 04:34:09 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll 2012-05-31 17:25:12 279656 ——w- C:\Windows\System32\MpSigStub.exe . ============= FINISH: 12:14:40.31 =============== Next… here is theAttach.txt log DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 10/23/2009 10:35:18 PM System Uptime: 8/19/2012 6:32:21 AM (6 hours ago) . Motherboard: Dell Inc. | | 0G848F Processor: Pentium® Dual-Core CPU T4300 @ 2.10GHz | Microprocessor | 2100/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 214 GiB total, 29.839 GiB free. D: is CDROM () G: is FIXED (NTFS) - 466 GiB total, 261.511 GiB free. Y: is FIXED (NTFS) - 19 GiB total, 14.266 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP318: 8/18/2012 10:12:58 PM - Windows Update RP319: 8/18/2012 10:18:23 PM - Installed AVG 2012 RP320: 8/19/2012 3:00:58 AM - Windows Update . ==== Installed Programs ====================== . µTorrent ACDSee Pro 3 Adobe Acrobat 9 Pro - English, Français, Deutsch Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.1.2 Advanced Audio FX Engine Apple Application Support Apple Software Update AVS Audio Converter version 6.1 AVS Update Manager 1.0 AVS Video Converter 6 AVS4YOU Software Navigator 1.4 BeamBoy v2.2 Belltech Business Card Designer Pro 5.3.1 Better Homes and Gardens Landscaping and Deck Designer 7.0 Better Homes and Gardens Landscaping and Deck Designer 7.0 Training Videos Bing Bar Choice Guard Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module CloneCD CoffeeCup Visual Site Designer Software Compatibility Pack for the 2007 Office system ConvertXtoDVD 4.0.3.313 Dell DataSafe Local Backup Dell DataSafe Local Backup - Support Software Dell Getting Started Guide Dell Support Center (Support Software) Dell Webcam Central EPSON Printer Software EPSON Scan Evaer Video Recorder for Skype [removed] Google Earth Pro Google Toolbar for Internet Explorer Google Update Helper GoToAssist 8.0.0.514 HEC-HMS 3.4 HEC-RAS 4.0 HY-8 7.2 Intel® Rapid Storage Technology Java Auto Updater Java™ 6 Update 34 Junk Mail filter update Just Great Software EditPad Lite 6.4.3 Live! Cam Avatar Creator Malwarebytes Anti-Malware version 1.62.0.1300 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft Office File Validation Add-In Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Standard Edition 2003 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable - KB2467175 Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft Works Mozilla Firefox 10.0.2 (x86 en-US) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK Nuclear Coffee - VideoGet Octoshape add-in for Adobe Flash Player Paradox PDF Password Remover v3.1 PL-2303 USB-to-Serial Play_Pacman Toolbar PowerDVD DX Quicken 2007 Quicken WillMaker Plus 2011 QuickTime RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer RealUpgrade 1.1 RedistSysFiles RegCure Roxio Burn Roxio Update Manager Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Skype Click to Call Skype™ 5.10 SolidConverterPDF Spybot - Search & Destroy TxDOT Concrete Box Culvert Analysis Program (CULV5) UltraISO Premium V9.33 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) VBA (2627.01) Visual Basic for Applications ® Core Visual Basic for Applications ® Core - English Visual C++ 8.0 Runtime Setup Package (x64) Visual Studio 2008 x64 Redistributables VLC media player 1.1.4 WeatherScope WebEx Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sync Windows Live Upload Tool Windows Live Writer WinTR-55, Version 1.00.08 WordPerfect Lightning WordPerfect Lightning - IPM WordPerfect Lightning - Messages WordPerfect Lightning - MSOM WordPerfect Office X5 WordPerfect Office X5 - Common Wordperfect Office X5 - EN WordPerfect Office X5 - Filters WordPerfect Office X5 - Graphics WordPerfect Office X5 - IPM WordPerfect Office X5 - LegalTools WordPerfect Office X5 - Migration Manager WordPerfect Office X5 - Oxford WordPerfect Office X5 - PerfectExperts EN WordPerfect Office X5 - PR WordPerfect Office X5 - QP WordPerfect Office X5 - Setup Files WordPerfect Office X5 - Sharepoint WordPerfect Office X5 - Skins WordPerfect Office X5 - System EN WordPerfect Office X5 - Templates WordPerfect Office X5 - WP WordPerfect Office X5 - WT Xvid MPEG-4 Video Codec Yahoo! BrowserPlus 2.9.8 Yahoo! Detect Yahoo! Messenger . ==== Event Viewer Messages From Past Week ======== . 8/19/2012 3:33:28 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service. 8/19/2012 3:32:15 AM, Error: Service Control Manager [7000] - The Messenger service failed to start due to the following error: The system cannot find the file specified. 8/19/2012 10:26:03 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2. 8/19/2012 1:53:11 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1. 8/19/2012 1:04:20 AM, Error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{715E6297-B9BA-4101-AB49-8A3061AB65E6} because another computer on the network has the same name. The server could not start. 8/19/2012 1:04:20 AM, Error: NetBT [4321] - The name "MANUEL-PC :20" could not be registered on the interface with IP address 192.168.254.5. The computer with the IP address 192.168.254.2 did not allow the name to be claimed by this computer. 8/19/2012 1:03:46 AM, Error: NetBT [4321] - The name "MANUEL-PC :0" could not be registered on the interface with IP address 192.168.254.5. The computer with the IP address 192.168.254.2 did not allow the name to be claimed by this computer. 8/18/2012 6:57:39 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer ANGELICA-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{715E6297-B9BA-4101-AB49-8A3061AB65E6}. The master browser is stopping or an election is being forced. 8/18/2012 6:32:19 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803963ff50, 0x0000000000000001, 0xfffffa80071352e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081812-31777-01. 8/17/2012 11:43:14 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803f6bbb50, 0x0000000000000001, 0xfffffa80045e22e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081712-29811-01. 8/15/2012 8:44:31 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 8/15/2012 8:42:39 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 8/15/2012 8:42:39 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 8/15/2012 8:42:37 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 8/15/2012 8:42:37 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 8/15/2012 8:42:32 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 8/15/2012 8:42:25 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 8/15/2012 8:42:15 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803fc7cf50, 0x0000000000000001, 0xfffffa800703c2e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081512-23821-01. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BdfNdisf bdfsfltr bdfwfpf DfsC discache NetBIOS NetBT nsiproxy Psched rdbss sbtis spldr tdx vwififlt Wanarpv6 WfpLwf 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The Messenger service depends on the NetBIOS Interface service which failed to start because of the following error: A device attached to the system is not functioning. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 8/15/2012 8:42:04 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 8/14/2012 6:10:51 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803f73d150, 0x0000000000000001, 0xfffffa800703a2e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081412-22120-01. 8/13/2012 8:21:35 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\bcmihvsrv64.dll Error Code: 21 8/13/2012 8:21:19 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: bdfsfltr bdfwfpf discache spldr Wanarpv6 8/13/2012 8:21:17 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803cfd1550, 0x0000000000000001, 0xfffffa800710f2e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081312-24476-01. 8/13/2012 8:19:21 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803bcb4750, 0x0000000000000001, 0xfffffa80071232e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081312-22729-02. 8/13/2012 7:53:38 PM, Error: NetBT [4321] - The name "MANUEL-PC :0" could not be registered on the interface with IP address 192.168.254.3. The computer with the IP address 192.168.254.2 did not allow the name to be claimed by this computer. 8/13/2012 7:53:21 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff88047d73950, 0x0000000000000001, 0xfffffa800706b2e6, 0x0000000000000005). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081312-20498-01. 8/13/2012 7:51:53 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803cf92b50, 0x0000000000000001, 0xfffffa800703e2e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081312-20155-01. 8/13/2012 7:46:29 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service VSSERV with arguments "" in order to run the server: {6DFC0DC7-FDC5-44C2-8B80-5977BA8F8ACC} 8/13/2012 7:39:03 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff88041cf5f50, 0x0000000000000001, 0xfffffa800701f2e6, 0x0000000000000005). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081312-22698-01. 8/12/2012 2:48:32 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803b2e1350, 0x0000000000000001, 0xfffffa80071342e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081212-22963-01. 8/12/2012 2:46:36 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff88045396550, 0x0000000000000001, 0xfffffa80070352e6, 0x0000000000000005). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081212-20607-01. 8/12/2012 1:22:02 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803d267950, 0x0000000000000001, 0xfffffa80071022e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081212-28938-01. 8/12/2012 1:20:07 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803c79fb50, 0x0000000000000001, 0xfffffa80071152e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081212-24991-01. 8/12/2012 1:17:38 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8804021dd50, 0x0000000000000001, 0xfffffa80071012e6, 0x0000000000000005). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081212-24757-01. 8/12/2012 1:15:42 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8803ff88f50, 0x0000000000000001, 0xfffffa800714e2e6, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081212-24850-01. . ==== End Of File =========================== Finally here is the aswMBR.txt log. on the computer screen it highlighted in red 13:11:53.999, 13:11:54.030, and 13:26:44.588 aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-19 13:10:27 —————————– 13:10:27.621 OS Version: Windows x64 6.1.7601 Service Pack 1 13:10:27.621 Number of processors: 2 586 0x170A 13:10:27.621 ComputerName: MANUEL-PC UserName: Manuel 13:10:28.604 Initialize success 13:10:38.853 AVAST engine defs: 12081900 13:10:43.580 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 13:10:43.580 Disk 0 Vendor: TOSHIBA_ FG00 Size: 238475MB BusType: 3 13:10:43.596 Device \Driver\iaStor -> MajorFunction fffffa80070945e8 13:10:43.596 Disk 0 MBR read successfully 13:10:43.596 Disk 0 MBR scan 13:10:43.611 Disk 0 Windows VISTA default MBR code 13:10:43.642 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 298 MB offset 63 13:10:43.674 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 19328 MB offset 612352 13:10:43.705 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 218847 MB offset 40196096 13:10:43.814 Disk 0 scanning C:\Windows\system32\drivers 13:10:58.837 Service scanning 13:11:53.983 Modules scanning 13:11:53.999 Disk 0 trace - called modules: 13:11:53.999 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa80070945e8]<< 13:11:54.014 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80044ef060] 13:11:54.030 3 CLASSPNP.SYS[fffff88001dbb43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800412e050] 13:11:54.030 \Driver\iaStor[0xfffffa8006fe9ab0] -> IRP_MJ_CREATE -> 0xfffffa80070945e8 13:11:55.293 AVAST engine scan C:\Windows 13:11:58.148 AVAST engine scan C:\Windows\system32 13:17:44.328 AVAST engine scan C:\Windows\system32\drivers 13:18:02.128 AVAST engine scan C:\Users\Manuel 13:24:24.909 Disk 0 MBR has been saved successfully to "C:\Users\Manuel\Desktop\MBR.dat" 13:24:25.029 The log file has been saved successfully to "C:\Users\Manuel\Desktop\aswMBR.txt" 13:26:44.588 File: C:\Users\Manuel\AppData\Local\Temp\BDD6.tmp **INFECTED** Win32:Alureon-AVJ [Trj] 13:38:30.481 AVAST engine scan C:\ProgramData 13:41:02.310 Scan finished successfully 13:42:16.368 Disk 0 MBR has been saved successfully to "C:\Users\Manuel\Desktop\MBR.dat" 13:42:16.378 The log file has been saved successfully to "C:\Users\Manuel\Desktop\aswMBR.txt" I did an AVG antivirus install an scanned. it picked up 28 rootkits and gave me the option to remove them. I realize you didn't ask for an AVG scan but I thought it might reveal some other problems. Should I let AVG remove them at this point? Again… Thank you kindly for your help. I'll invest some more time on this machine and hope I can revive it. Otherwise I am afraid I will be retiring it. :thumbup: Manny
Sorry ..forgot to paste the AVG Log. here it is: Thanks "Scan ""Whole computer scan"" completed." "Rootkits";"28";"1";"27" "Folders selected for scanning:";"Whole computer scan" "Scan started:";"Sunday, August 19, 2012, 8:37:52 AM" "Scan finished:";"Sunday, August 19, 2012, 9:03:34 AM (25 minute(s) 42 second(s))" "Total object scanned:";"2293672" "User who launched the scan:";"Manuel" "Rootkits" "";"File";"Infection";"Result" "";"";"IRP hook, \Driver\iaStor IRP_MJ_CREATE -> 0xFFFFFA800701D674";"Reboot is required to finish the action" "";"";"IRP hook, \Driver\iaStor IRP_MJ_CREATE_NAMED_PIPE -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_CLOSE -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_READ -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_WRITE -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_QUERY_INFORMATION -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_SET_INFORMATION -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_QUERY_EA -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_SET_EA -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_FLUSH_BUFFERS -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_QUERY_VOLUME_INFORMATION -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_SET_VOLUME_INFORMATION -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_DIRECTORY_CONTROL -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_FILE_SYSTEM_CONTROL -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_DEVICE_CONTROL -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_SHUTDOWN -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_LOCK_CONTROL -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_CLEANUP -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_CREATE_MAILSLOT -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_QUERY_SECURITY -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_SET_SECURITY -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_POWER -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_SYSTEM_CONTROL -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_DEVICE_CHANGE -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_QUERY_QUOTA -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_SET_QUOTA -> 0xFFFFFA800701D674";"Object is hidden" "";"";"IRP hook, \Driver\iaStor IRP_MJ_PNP -> 0xFFFFFA800701D674";"Object is hidden"
Hi,

I did an AVG antivirus install an scanned. it picked up 28 rootkits and gave me the option to remove them. I realize you didn't ask for an AVG scan but I thought it might reveal some other problems. Should I let AVG remove them at this point?

Thanks for the log but please do not remove anything on your own. We may miss something that we need to see or unintentionally remove something we don't want to.

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
OK.. COMBOFIX loaded and launched. I temporarily lost my widows exlorer and Internet explorer. got it back and was able to get online. The log is as follows: ComboFix 12-08-18.03 - Manuel 08/19/2012 18:07:55.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4056.2586 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\D4669D1006.sys c:\users\Manuel\AppData\Local\{4950A805-4155-4AD6-843A-FEBD3BC367D8} c:\users\Manuel\AppData\Local\{4950A805-4155-4AD6-843A-FEBD3BC367D8}\chrome.manifest c:\users\Manuel\AppData\Local\{4950A805-4155-4AD6-843A-FEBD3BC367D8}\chrome\content\_cfg.js c:\users\Manuel\AppData\Local\{4950A805-4155-4AD6-843A-FEBD3BC367D8}\chrome\content\overlay.xul c:\users\Manuel\AppData\Local\{4950A805-4155-4AD6-843A-FEBD3BC367D8}\install.rdf c:\windows\svchost.exe c:\windows\SysWow64\URTTemp c:\windows\SysWow64\URTTemp\regtlib.exe . . ((((((((((((((((((((((((( Files Created from 2012-07-19 to 2012-08-19 ))))))))))))))))))))))))))))))) . . 2012-08-19 23:29 . 2012-08-19 23:29 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-08-19 14:53 . 2012-07-03 18:46 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-08-19 03:21 . 2012-08-19 03:21 31080 —-a-w- c:\windows\system32\drivers\avgtpx64.sys 2012-08-19 03:21 . 2012-08-19 03:21 ——– d—–w- c:\program files (x86)\AVG Secure Search 2012-08-19 03:19 . 2012-08-19 23:38 ——– d—–w- c:\windows\system32\drivers\AVG 2012-08-19 03:13 . 2012-07-16 07:40 9133488 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B620935-52B6-4707-9D20-A83CDCE0E351}\mpengine.dll 2012-08-19 03:00 . 2012-08-19 14:53 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-08-19 02:58 . 2012-08-19 04:23 ——– d—–w- C:\AntiVirus 2012-08-19 00:22 . 2012-08-19 00:22 ——– d—–w- c:\users\Manuel\AppData\Roaming\AVG2012 2012-08-19 00:20 . 2012-08-19 00:20 ——– d—–w- c:\users\Manuel\AppData\Local\AVG Secure Search 2012-08-19 00:20 . 2012-08-19 00:20 ——– d—–w- c:\programdata\AVG Secure Search 2012-08-19 00:20 . 2012-08-19 03:21 ——– d—–w- c:\program files (x86)\Common Files\AVG Secure Search 2012-08-19 00:17 . 2012-08-19 18:06 ——– d—–w- c:\programdata\AVG2012 2012-08-19 00:17 . 2012-08-19 00:17 ——– d—–w- C:\$AVG 2012-08-19 00:02 . 2012-08-19 14:50 ——– d—–w- c:\programdata\MFAData 2012-08-19 00:02 . 2012-08-19 00:02 ——– d–h–w- c:\programdata\Common Files 2012-08-18 23:53 . 2012-08-19 05:55 ——– d—–w- c:\program files (x86)\Common Files\Java 2012-08-18 23:53 . 2012-08-18 23:53 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-08-18 04:19 . 2012-08-18 04:19 ——– d—–w- c:\windows\Sun 2012-08-12 14:45 . 2012-08-18 04:42 ——– d—–w- c:\program files (x86)\SopCast 2012-07-23 01:46 . 2012-08-19 05:55 ——– d—–w- c:\program files (x86)\Common Files\ParetoLogic 2012-07-23 01:46 . 2012-07-23 01:46 ——– d—–w- c:\programdata\ParetoLogic . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-19 08:02 . 2009-10-25 03:20 62134624 —-a-w- c:\windows\system32\MRT.exe 2012-08-19 03:08 . 2012-06-22 04:50 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-19 03:08 . 2011-06-08 02:09 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-18 23:53 . 2011-03-27 02:01 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-06-28 16:07 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2012-06-28 16:07 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2012-06-21 23:51 . 2012-06-21 23:51 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll 2012-06-21 23:51 . 2012-06-21 23:51 348160 —-a-w- c:\windows\SysWow64\msvcr71.dll 2012-06-09 05:43 . 2012-07-11 20:42 14172672 —-a-w- c:\windows\system32\shell32.dll 2012-06-06 06:06 . 2012-07-11 20:42 2004480 —-a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-11 20:42 1881600 —-a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-11 20:39 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-11 20:42 1390080 —-a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-11 20:42 1236992 —-a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-11 20:39 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 22:19 . 2012-06-22 04:46 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-22 04:46 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-22 04:46 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-22 04:46 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-22 04:46 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-22 04:46 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-22 04:46 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 20:19 . 2012-06-22 04:45 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 20:15 . 2012-06-22 04:45 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-02 05:50 . 2012-07-11 20:42 458704 —-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-11 20:42 95600 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:48 . 2012-07-11 20:42 151920 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:45 . 2012-07-11 20:42 340992 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-11 20:42 307200 —-a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-11 20:42 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-11 20:42 225280 —-a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-11 20:42 219136 —-a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-11 20:42 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2012-05-31 17:25 . 2009-10-27 01:23 279656 ——w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-08-19 03:21 2045024 —-a-w- c:\program files (x86)\AVG Secure Search\12.2.0.5\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\12.2.0.5\AVG Secure Search_toolbar.dll" [2012-08-19 2045024] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\program files (x86)\Yahoo!\Messenger\YahooMessenger.exe" [2010-04-29 5248312] "avichannel"="c:\program files (x86)\Evaer\videochannel.exe" [2011-07-29 1689088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744] "Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-19 494064] "DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-18 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-03-26 142120] "CloneCDTray"="c:\program files (x86)\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344] "QuickFinder Scheduler"="c:\program files (x86)\Corel\WordPerfect Office X5\Programs\QFSCHD150.EXE" [2010-03-12 136600] "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2012-06-21 296056] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008] "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-08-19 1162848] "ROC_roc_ssl_v12"="c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" [2012-08-19 1020512] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-09 559616] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-21 136176] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-08 160944] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-19 250056] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-21 136176] R3 SUSTUCAM;Susteen USB Cable Modem Driver;c:\windows\system32\DRIVERS\sustucam.sys [2009-11-25 56832] R3 SUSTUCAP;Susteen USB Cable Port Driver;c:\windows\system32\DRIVERS\sustucap.sys [2009-11-25 56832] R3 SUSTUCAU;Susteen USB Cable USB Driver;c:\windows\system32\DRIVERS\sustucau.sys [2009-11-25 33792] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2009-10-16 50176] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-13 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944] S0 FSProFilter;FSPro File Filter;c:\windows\System32\Drivers\FSPFltd.sys [2010-07-22 54848] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-02-22 289872] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-03-19 383808] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2012-08-19 31080] S1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2008-10-09 82480] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\avgidsagent.exe [2012-07-04 5160568] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288] S2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.exe [2011-08-18 1692480] S2 vToolbarUpdater12.2.0;vToolbarUpdater12.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe [2012-08-19 927840] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2011-12-23 124496] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704] S3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [2010-07-01 51600] S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2009-12-25 82816] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2010-07-21 45456] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-05-08 215552] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-08-19 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-22 03:08] . 2012-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-21 23:55] . 2012-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-21 23:55] . 2012-08-19 c:\windows\Tasks\RegCure Program Check.job - c:\program files (x86)\RegCure\RegCure.exe [2012-07-13 21:21] . 2012-08-19 c:\windows\Tasks\RegCure.job - c:\program files (x86)\RegCure\RegCure.exe [2012-07-13 21:21] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-01-23 305664] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-29 444416] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-30 165912] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-30 385560] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-30 365080] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960] "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2009-07-02 3180624] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 2327952] "mylbx"="c:\program files\My Lockbox\mylbx.exe" [2010-11-09 1792224] "MRT"="c:\windows\system32\MRT.exe" [2012-08-19 62134624] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.yahoo.com/ mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm IE: Copy to &Lightning Note - c:\program files (x86)\Corel\WordPerfect Lightning\Programs\WPLightningCopyToNote.hta IE: Open with WordPerfect - c:\program files (x86)\Corel\WordPerfect Office X5\Programs\WPLauncher.hta Trusted Zone: intuit.com\ttlc TCP: DhcpNameServer = 192.168.254.254 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.0\ViProtocol.dll FF - ProfilePath - c:\users\Manuel\AppData\Roaming\Mozilla\Firefox\Profiles\kp6s54a2.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 59274 FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-{aac55042-b985-4a23-a4c9-3ba84830ef84} - (no file) SafeBoot-mcmscsvc SafeBoot-MCODS Toolbar-Locked - (no file) WebBrowser-{AAC55042-B985-4A23-A4C9-3BA84830EF84} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{259F616C-A300-44F5-B04A-ED001A26C85C}"=hex:51,66,7a,6c,4c,1d,38,12,02,62,8c, 21,32,ed,9b,01,cf,5c,ae,40,1f,78,8c,48 "{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90, 43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87 "{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8, 89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b, 27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b "{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4, 91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a, 34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de "{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}"=hex:51,66,7a,6c,4c,1d,38,12,81,2d,20, 35,ad,85,e1,00,d0,fd,90,4e,9f,38,f2,ae "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b, ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3 "{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f, aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04 "{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93, aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83 "{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd, d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84, f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63 "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:c3,05,fc,ad,dd,7d,cd,01 . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.032" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.abr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ani" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.apd" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.arw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.bay" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.bmp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.bw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bwf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.bwf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.cr2" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.crw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.cs1" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.cur" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.dcr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.dcx" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.dib" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.djv" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.djvu" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.dng" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.emf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.eps" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.erf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.fff" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.flc" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.fli" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.fpx" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.gif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.hdr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.icl" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.icn" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.iff" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ilbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.int" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.inta" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.iw4" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.j2c" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.j2k" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jbr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jfif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jp2" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpc" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpe" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpeg" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpg" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpk" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpx" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kar\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.kar" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.kdc" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.lbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m15\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.m15" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1a\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.m1a" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.m2a" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m75\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.m75" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.mef" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.mos" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.mpv" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.mrw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.nef" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.nrw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.orf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pbr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pcd" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pct" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pcx" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pef" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pgm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pic" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pics\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pics" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pict" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pix" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.png" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ppm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.psd" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.psp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pspbrush" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pspimage" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qtpf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.qtpf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.raf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ras" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.raw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rgb" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rgba" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rle" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rsb" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rw2" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rwl" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sdv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sdv" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sfil\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sfil" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sgi" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.smf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sml" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sr2" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.srf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.swa\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.swa" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.tga" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.thm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.tif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.tiff" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ttc" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ttf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ulw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ulw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30po\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.v30po" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30pp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.v30pp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30ppf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.v30ppf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vfw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.vfw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.wbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.wbmp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.wmf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.xbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.xif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.xmp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.xpm" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe c:\program files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\Dell DataSafe Local Backup\TOASTER.EXE c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe c:\\.\globalroot\systemroot\svchost.exe c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe . ************************************************************************** . Completion time: 2012-08-19 18:49:29 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-19 23:49 . Pre-Run: 33,011,126,272 bytes free Post-Run: 35,365,662,720 bytes free . - - End Of File - - 252F538BADBD4D0BA3E4086FE8D2CC68 Thanks Jeffce for the quick response. Let me know what you need me to do next.

No I wasn't aware… What does that mean? what are the consequences of a proxy server? is it a bad thing? if so how do I change it?

Well if you aren't aware that it was set than it is more than likely bad. We will remove it with my next set of instructions.

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:


    ClearJavaCache::

    Firefox::
    FF - ProfilePath - c:\users\Manuel\AppData\Roaming\Mozilla\Firefox\Profiles\kp6s54a2.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 59274

    File::
    c:\program files (x86)\RegCure\RegCure.exe

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Jeffce. Sorry for the dumb question but you mentioned it twice now. Script Blocking. What is it? how do I know if it is enabled? and how do I disable it if it is enabled?

Script Blocking. What is it? how do I know if it is enabled? and how do I disable it if it is enabled?

Just be sure that your antivirus and firewall programs are disabled and you will be fine. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI