This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Confirm removal of Win32:Sirefef-PL

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was told by Robybel on this forum that I was infected with Win32:Siref-PL. He advised that it would be time consuming to remove without any guarantees that it would be successful, and that often times it was better to simply start from scratch with a clean install of the OS. I opted for this and had my IT guy come in to handle the install and set up to reintroduce the computer on my office network. Once he got here, he felt that he could easily clean the computer. I'm not sure of all the steps that were taken, but he claims the system is clean and safe. It did not take him long. I would feel a lot better if you could confirm that indeed the system was free of infection. Here's the initial DDS log from right after he left with clean bill of health: . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 15:06:33.12 on Mon 06/10/2013 Internet Explorer: 9.10.9200.16576 BrowserJavaVersion: 10.9.2 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8089.5915 [GMT -4:00] . AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\SysWOW64\atashost.exe C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe C:\Program Files (x86)\AVG\AVG2013\avgui.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\EagleSoft\Shared Files\EagleSoft.exe C:\EagleSoft\Shared Files\esmessenger.exe C:\Users\Front Desk\Desktop\OTL.exe C:\Windows\System32\MsSpellCheckingFacility.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Windows\notepad.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Front Desk\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ BHO: TmIEPlugInBHO Class: {1ca1377b-dc1d-4a52-9585-6e06050fac53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll BHO: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - No File BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [ESInetConnect] C:\EagleSoft\Shared Files\esinetconnect.exe mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) TCP: {DD25B057-1747-48D2-8302-4C7DA5F4826F} = [removed],[removed] Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - BHO-X64: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll BHO-X64: Trend Micro NSC BHO - No File BHO-X64: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - No File BHO-X64: AVG Do Not Track - No File mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe . ============= SERVICES / DRIVERS =============== . R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-2-8 311096] R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-2-8 116536] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-2-8 45880] R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-3-29 246072] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-2-8 206136] R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-3-21 240952] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-5-10 65640] R2 atashost;WebEx Service Host for Support Center;C:\Windows\SysWOW64\atashost.exe [2012-10-16 134456] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-5-14 4937264] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-4-18 283136] R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-10-15 2754984] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-9-27 2594584] R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-9-27 317440] R3 MEIx64;Intel® Management Engine Interface ;C:\Windows\System32\drivers\HECIx64.sys [2012-9-27 56600] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-9-27 685672] S0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-2-8 71480] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2012-10-8 1256192] S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168] S3 netvsc;netvsc;C:\Windows\System32\drivers\netvsc60.sys [2010-11-21 168448] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136] S3 SynthVid;SynthVid;C:\Windows\System32\drivers\VMBusVideoM.sys [2010-11-21 22528] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-8 1255736] . =============== Created Last 30 ================ . 2013-06-10 18:32:45 ——– d—–w- C:\INfections from 06062013 2013-06-10 18:30:46 ——– d—–w- C:\Users\FRONTD~1\AppData\Roaming\AVG2013 2013-06-10 18:29:57 ——– d—–w- C:\PROGRA~3\AVG2013 2013-06-10 18:17:59 ——– d—–w- C:\Users\FRONTD~1\AppData\Local\MFAData 2013-06-10 18:17:59 ——– d—–w- C:\Users\FRONTD~1\AppData\Local\Avg2013 2013-06-10 17:41:04 ——– d—–w- C:\Users\FRONTD~1\AppData\Roaming\TuneUp Software 2013-06-06 12:10:25 ——– d—–w- C:\Users\FRONTD~1\AppData\Roaming\Malwarebytes 2013-06-06 12:10:13 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys 2013-06-06 12:10:13 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-06-06 12:10:13 ——– d—–w- C:\PROGRA~3\Malwarebytes 2013-06-06 12:09:57 ——– d—–w- C:\Users\FRONTD~1\AppData\Local\Programs 2013-05-15 08:50:03 983400 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2013-05-15 08:50:03 265064 —-a-w- C:\Windows\System32\drivers\dxgmms1.sys 2013-05-15 08:50:03 144384 —-a-w- C:\Windows\System32\cdd.dll 2013-05-15 08:49:57 70144 —-a-w- C:\Windows\System32\appinfo.dll 2013-05-15 08:49:57 1930752 —-a-w- C:\Windows\System32\authui.dll 2013-05-15 08:49:57 1796096 —-a-w- C:\Windows\SysWow64\authui.dll 2013-05-15 08:49:57 111448 —-a-w- C:\Windows\System32\consent.exe 2013-05-15 08:49:55 48640 —-a-w- C:\Windows\System32\wwanprotdim.dll 2013-05-15 08:49:55 3153920 —-a-w- C:\Windows\System32\win32k.sys 2013-05-15 08:49:55 230400 —-a-w- C:\Windows\System32\wwansvc.dll . ==================== Find3M ==================== . 2013-04-13 05:49:23 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49:19 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49:19 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49:19 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45:16 474624 —-a-w- C:\Windows\apppatch\AcSpecfc.dll 2013-04-13 04:45:15 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll 2013-04-12 14:45:08 1656680 —-a-w- C:\Windows\System32\drivers\ntfs.sys 2013-03-29 06:53:48 246072 —-a-w- C:\Windows\System32\drivers\avgidsdrivera.sys 2013-03-21 07:08:24 240952 —-a-w- C:\Windows\System32\drivers\avgtdia.sys 2013-03-19 06:04:06 5550424 —-a-w- C:\Windows\System32\ntoskrnl.exe 2013-03-19 05:46:56 43520 —-a-w- C:\Windows\System32\csrsrv.dll 2013-03-19 05:04:13 3968856 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04:10 3913560 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47:50 6656 —-a-w- C:\Windows\SysWow64\apisetschema.dll 2013-03-19 03:06:33 112640 —-a-w- C:\Windows\System32\smss.exe . ============= FINISH: 15:06:44.38 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows 7 Professional Boot Device: \Device\HarddiskVolume2 Install Date: 10/8/2012 1:11:17 PM System Uptime: 6/10/2013 2:15:19 PM (1 hours ago) . Motherboard: Dell Inc. | | 0M5DCD Processor: Intel® Core™ i3-2120 CPU @ 3.30GHz | CPU 1 | 3300/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 219 GiB total, 185.792 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318} Description: PS/2 Compatible Mouse Device ID: ACPI\PNP0F13\5&1B5A4B03&0 Manufacturer: Microsoft Name: PS/2 Compatible Mouse PNP Device ID: ACPI\PNP0F13\5&1B5A4B03&0 Service: i8042prt . ==== System Restore Points =================== . RP76: 6/10/2013 2:17:10 PM - ComboFix created restore point RP77: 6/10/2013 2:29:20 PM - Installed AVG 2013 RP78: 6/10/2013 2:29:35 PM - Installed AVG 2013 RP79: 6/10/2013 2:55:31 PM - OTL Restore Point - 6/10/2013 2:55:31 PM . ==== Installed Programs ====================== . Adobe Flash Player 11 ActiveX Adobe Reader X (10.1.7) Cisco WebEx Meetings ImgBurn Intel® Management Engine Components Intel® Processor Graphics Java 7 Update 9 Java Auto Updater LibreOffice 3.6 Malwarebytes Anti-Malware version 1.75.0.1300 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Patterson EagleSoft PINPadDevice Files Realtek Ethernet Controller All-In-One Windows Driver Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) TeamViewer 7 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Visual Studio 2008 x64 Redistributables . ==== Event Viewer Messages From Past Week ======== . 6/6/2013 8:41:28 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F} 6/6/2013 8:41:28 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 6/6/2013 8:08:29 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. 6/6/2013 8:07:39 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 discache spldr vpcvmm Wanarpv6 6/6/2013 8:07:39 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 6/6/2013 8:06:30 AM, Error: Service Control Manager [7000] - The Intel® Management and Security Application Local Management Service service failed to start due to the following error: The pipe has been ended. 6/6/2013 8:06:17 AM, Error: Service Control Manager [7031] - The Intel® Management and Security Application Local Management Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. 6/6/2013 8:04:26 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3. 6/5/2013 12:30:36 PM, Error: Service Control Manager [7034] - The Intel® Management and Security Application User Notification Service service terminated unexpectedly. It has done this 1 time(s). 6/5/2013 12:28:46 PM, Error: Service Control Manager [7034] - The TeamViewer 7 service terminated unexpectedly. It has done this 3 time(s). 6/5/2013 12:28:43 PM, Error: Service Control Manager [7034] - The AVG WatchDog service terminated unexpectedly. It has done this 6 time(s). 6/5/2013 12:28:43 PM, Error: Service Control Manager [7031] - The TeamViewer 7 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 2000 milliseconds: Restart the service. 6/5/2013 12:28:43 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 5 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:28:42 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:28:41 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:28:41 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:28:40 PM, Error: Service Control Manager [7034] - The WebEx Service Host for Support Center service terminated unexpectedly. It has done this 1 time(s). 6/5/2013 12:28:40 PM, Error: Service Control Manager [7034] - The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s). 6/5/2013 12:28:40 PM, Error: Service Control Manager [7031] - The TeamViewer 7 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 2000 milliseconds: Restart the service. 6/5/2013 12:28:40 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:21 PM, Error: Service Control Manager [7038] - The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). 6/5/2013 12:27:21 PM, Error: Service Control Manager [7000] - The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure. 6/5/2013 12:27:21 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1069" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 6/5/2013 12:27:18 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 223 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:17 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 222 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:17 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 221 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:16 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 220 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:16 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 219 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:15 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 218 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:15 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 217 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:14 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 216 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:14 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 215 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:13 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 214 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:13 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 213 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:12 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 212 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:12 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 211 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:11 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 210 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:11 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 209 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:10 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 208 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:10 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 207 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:09 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 206 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:09 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 205 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:08 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 204 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:08 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 203 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:07 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 202 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:07 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 201 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:06 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 200 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:06 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 199 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:05 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 198 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:05 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 197 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:04 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 196 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:04 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 195 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:03 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 194 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:03 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 193 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:03 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 192 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:02 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 191 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:02 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 190 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:01 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 189 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:00 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 188 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:27:00 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 187 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:59 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 186 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:59 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 185 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:58 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 184 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:58 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 183 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:57 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 182 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:57 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 181 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:56 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 180 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:56 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 179 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:55 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 178 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:55 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 177 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:54 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 176 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:54 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 175 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:53 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 174 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:53 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 173 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:52 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 172 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:52 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 171 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:51 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 170 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:51 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 169 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:50 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 168 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:50 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 167 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:49 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 166 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:49 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 165 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:48 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 164 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:47 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 163 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:47 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 162 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:46 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 161 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:46 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 160 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:45 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 159 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:45 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 158 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:44 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 157 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:44 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 156 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:43 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 155 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:43 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 154 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:42 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 153 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:42 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 152 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:41 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 151 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:41 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 150 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:40 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 149 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:40 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 148 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:39 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 147 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:39 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 146 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:38 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 145 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:38 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 144 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:37 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 143 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:37 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 142 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:36 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 141 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:35 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 140 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:35 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 139 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:34 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 138 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:34 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 137 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:33 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 136 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:33 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 135 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:32 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 134 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:32 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 133 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:31 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 132 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:31 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 131 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:30 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 130 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:29 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 129 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:29 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 128 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:28 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 127 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:28 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 126 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:27 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 125 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:27 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 124 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:26 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 123 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:26 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 122 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:25 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 121 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:24 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 120 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:24 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 119 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:23 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 118 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:23 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 117 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:22 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 116 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:21 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 115 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:20 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 114 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:20 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 113 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:19 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 112 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:19 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 111 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:18 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 110 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:18 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 109 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:17 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 108 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:17 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 107 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:16 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 106 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:16 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 105 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:15 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 104 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:15 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 103 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:14 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 102 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:14 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 101 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:13 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 100 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:12 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 99 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:11 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 98 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:11 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 97 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:10 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 96 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:10 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 95 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:09 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 94 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:09 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 93 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:08 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 92 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:07 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 91 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:07 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 90 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:06 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 89 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:06 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 88 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:05 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 87 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:05 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 86 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:04 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 85 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:04 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 84 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:03 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 83 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:03 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 82 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:02 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 81 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:26:00 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 80 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:59 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 79 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:58 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 78 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:58 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 77 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:57 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 76 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:57 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 75 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:56 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 74 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:55 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 73 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:54 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 72 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:54 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 71 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:53 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 70 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:52 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 69 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:52 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 68 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:51 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 67 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:50 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 66 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:50 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 65 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:49 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 64 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:49 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 63 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:48 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 62 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:48 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 61 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:47 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 60 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:47 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 59 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:46 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 58 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:45 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 57 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:45 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 56 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:44 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 55 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:44 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 54 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:43 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 53 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:42 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 52 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:42 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 51 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:41 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 50 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:40 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 49 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:40 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 48 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:39 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 47 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:38 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 46 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:38 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 45 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:37 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 44 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:37 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 43 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:36 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 42 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:35 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 41 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:34 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 40 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:34 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 39 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:33 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 38 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:32 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 37 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:31 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 36 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:31 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 35 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:30 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 34 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:30 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 33 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:29 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 32 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:27 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 31 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:27 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 30 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:26 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 29 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:26 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 28 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:24 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 27 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:24 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 26 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:23 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 25 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:22 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 24 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:21 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 23 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:20 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 22 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:20 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 21 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:19 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 20 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:19 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 19 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:18 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 18 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:13 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 17 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:12 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 16 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:12 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 15 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:11 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 14 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:10 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 13 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:10 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 12 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:09 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 11 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:09 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 10 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:08 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 9 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:07 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 8 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:06 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 7 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 12:25:06 PM, Error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 6 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 6/5/2013 1:27:36 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2. 6/10/2013 2:08:46 PM, Error: Service Control Manager [7023] - The WinDefend service terminated with the following error: Access is denied. 6/10/2013 2:07:45 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 6/10/2013 2:07:05 PM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. 6/10/2013 2:02:20 PM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891 6/10/2013 2:02:20 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%-2147024891 6/10/2013 1:59:55 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1. 6/10/2013 1:55:05 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 6/10/2013 1:54:31 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 6/10/2013 1:54:31 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 6/10/2013 1:54:31 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 6/10/2013 1:54:31 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 6/10/2013 1:54:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 6/10/2013 1:54:24 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 6/10/2013 1:54:16 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgmfx64 CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vpcnfltr vpcvmm vwififlt Wanarpv6 WfpLwf 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning. 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 6/10/2013 1:54:16 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 6/10/2013 1:54:16 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B} . ==== End Of File ===========================
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.




Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you for your help. Here are the logs you requested:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-06-2013 03
Ran by [removed] (administrator) on 10-06-2013 16:23:11
Running from C:\Users\[removed]\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Cisco WebEx LLC) C:\Windows\SysWOW64\atashost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Patterson Companies) C:\EagleSoft\Shared Files\EagleSoft.exe
(Patterson Companies) C:\EagleSoft\Shared Files\esmessenger.exe
(OldTimer Tools) C:\Users\Front Desk\Desktop\OTL.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKCU\…\Policies\system: [disableregistrytools] 0
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\…\Run: [ESInetConnect] C:\EagleSoft\Shared Files\esinetconnect.exe [204800 2010-08-11] (Patterson Companies, Inc.)
HKLM-x32\…\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [4408368 2013-04-29] (AVG Technologies CZ, s.r.o.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
HKCU SearchScopes: DefaultScope {5305F888-6716-478C-9FC7-5B902E46C1C2} URL =
SearchScopes: HKCU - {5305F888-6716-478C-9FC7-5B902E46C1C2} URL =
BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll No File
BHO: No Name - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - No File
BHO-x32: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll No File
BHO-x32: No Name - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - No File
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll No File
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll No File
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\..\Interfaces\{DD25B057-1747-48D2-8302-4C7DA5F4826F}: [NameServer]65.32.5.74,65.32.5.75

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)

==================== Drivers (Whitelisted) ====================

R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-03-29] (AVG Technologies CZ, s.r.o.)
S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206136 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-10 16:22 - 2013-06-10 16:22 - 01920086 ____A (Farbar) C:\Users\Front Desk\Desktop\FRST64.exe
2013-06-10 16:22 - 2013-06-10 16:22 - 00000000 ____D C:\FRST
2013-06-10 15:06 - 2013-06-10 15:06 - 00625664 ____A C:\Users\Front Desk\Desktop\dds.scr
2013-06-10 14:58 - 2013-06-10 14:58 - 00141238 ____A C:\Users\Front Desk\Desktop\OTL.Txt
2013-06-10 14:53 - 2013-06-10 14:53 - 00602112 ____A (OldTimer Tools) C:\Users\Front Desk\Desktop\OTL.exe
2013-06-10 14:32 - 2013-06-10 14:33 - 00000000 ____D C:\INfections from 06062013
2013-06-10 14:30 - 2013-06-10 14:30 - 00000297 ____A C:\Windows\SysWOW64\userawacs.cfg
2013-06-10 14:30 - 2013-06-10 14:30 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\AVG2013
2013-06-10 14:29 - 2013-06-10 14:30 - 00000000 ____D C:\ProgramData\AVG2013
2013-06-10 14:23 - 2013-06-10 14:23 - 01056768 ____A C:\Users\Front Desk\defltbase.sdb
2013-06-10 14:17 - 2013-06-10 14:33 - 00000000 ____D C:\Users\Front Desk\AppData\Local\Avg2013
2013-06-10 14:17 - 2013-06-10 14:17 - 00000000 ____D C:\Users\Front Desk\AppData\Local\MFAData
2013-06-10 14:11 - 2013-06-10 14:11 - 00013556 ____A C:\ComboFix.txt
2013-06-10 14:03 - 2013-06-10 14:16 - 00000000 ____D C:\Windows\erdnt
2013-06-10 13:55 - 2013-06-10 13:55 - 00000183 ____A C:\Windows\System32\avgrep.txt
2013-06-10 13:41 - 2013-06-10 13:41 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\TuneUp Software
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\Malwarebytes
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-06 08:10 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-05 12:24 - 2013-06-05 12:24 - 00000000 ____D C:\Windows\Sun
2013-05-21 03:03 - 2013-05-21 03:03 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-05-21 03:03 - 2013-05-21 03:03 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-05-21 03:03 - 2013-05-21 03:03 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-05-21 03:03 - 2013-05-21 03:03 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-05-21 03:03 - 2013-05-21 03:03 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-05-21 03:03 - 2013-05-21 03:03 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-05-21 03:03 - 2013-05-21 03:03 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2013-05-21 03:03 - 2013-05-21 03:03 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-05-21 03:03 - 2013-05-21 03:03 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-05-21 03:03 - 2013-05-21 03:03 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-05-21 03:03 - 2013-05-21 03:03 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-05-21 03:00 - 2013-05-21 03:04 - 00007183 ____A C:\Windows\IE10_main.log
2013-05-15 04:50 - 2013-04-10 02:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-15 04:50 - 2013-04-10 02:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-05-15 04:50 - 2011-02-03 07:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2013-05-15 04:49 - 2013-04-09 23:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-15 04:49 - 2013-03-19 01:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-05-15 04:49 - 2013-03-19 01:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-05-15 04:49 - 2013-02-27 02:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-15 04:49 - 2013-02-27 01:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-15 04:49 - 2013-02-27 01:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-15 04:49 - 2013-02-27 01:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-15 04:49 - 2013-02-27 01:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-15 04:49 - 2013-02-27 00:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-15 04:49 - 2013-02-27 00:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-15 04:49 - 2013-02-27 00:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll

==================== One Month Modified Files and Folders =======

2013-06-10 16:22 - 2013-06-10 16:22 - 01920086 ____A (Farbar) C:\Users\Front Desk\Desktop\FRST64.exe
2013-06-10 16:22 - 2013-06-10 16:22 - 00000000 ____D C:\FRST
2013-06-10 15:06 - 2013-06-10 15:06 - 00625664 ____A C:\Users\Front Desk\Desktop\dds.scr
2013-06-10 14:58 - 2013-06-10 14:58 - 00141238 ____A C:\Users\Front Desk\Desktop\OTL.Txt
2013-06-10 14:53 - 2013-06-10 14:53 - 00602112 ____A (OldTimer Tools) C:\Users\Front Desk\Desktop\OTL.exe
2013-06-10 14:33 - 2013-06-10 14:32 - 00000000 ____D C:\INfections from 06062013
2013-06-10 14:33 - 2013-06-10 14:17 - 00000000 ____D C:\Users\Front Desk\AppData\Local\Avg2013
2013-06-10 14:33 - 2012-10-08 14:12 - 00000000 ____D C:\ProgramData\MFAData
2013-06-10 14:30 - 2013-06-10 14:30 - 00000297 ____A C:\Windows\SysWOW64\userawacs.cfg
2013-06-10 14:30 - 2013-06-10 14:30 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\AVG2013
2013-06-10 14:30 - 2013-06-10 14:29 - 00000000 ____D C:\ProgramData\AVG2013
2013-06-10 14:29 - 2012-10-08 14:22 - 00000000 ____D C:\Program Files (x86)\AVG
2013-06-10 14:23 - 2013-06-10 14:23 - 01056768 ____A C:\Users\Front Desk\defltbase.sdb
2013-06-10 14:23 - 2012-10-08 13:11 - 00000000 ____D C:\users\Front Desk
2013-06-10 14:22 - 2009-07-14 00:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-10 14:22 - 2009-07-14 00:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-10 14:20 - 2012-10-08 14:23 - 00000000 ____D C:\ProgramData\AVG2012
2013-06-10 14:19 - 2009-07-14 01:13 - 00771138 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-10 14:18 - 2012-09-27 08:08 - 01462735 ____A C:\Windows\WindowsUpdate.log
2013-06-10 14:17 - 2013-06-10 14:17 - 00000000 ____D C:\Users\Front Desk\AppData\Local\MFAData
2013-06-10 14:16 - 2013-06-10 14:03 - 00000000 ____D C:\Windows\erdnt
2013-06-10 14:15 - 2009-07-14 01:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-10 14:15 - 2009-07-14 00:51 - 00035161 ____A C:\Windows\setupact.log
2013-06-10 14:11 - 2013-06-10 14:11 - 00013556 ____A C:\ComboFix.txt
2013-06-10 14:09 - 2009-07-13 22:34 - 00000215 ____A C:\Windows\system.ini
2013-06-10 14:08 - 2010-11-20 23:47 - 00022040 ____A C:\Windows\PFRO.log
2013-06-10 13:55 - 2013-06-10 13:55 - 00000183 ____A C:\Windows\System32\avgrep.txt
2013-06-10 13:41 - 2013-06-10 13:41 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\TuneUp Software
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\Malwarebytes
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-05 12:24 - 2013-06-05 12:24 - 00000000 ____D C:\Windows\Sun
2013-06-04 16:28 - 2005-03-02 17:24 - 00006337 ____A C:\Windows\SysWOW64\ESDictionary.cud
2013-05-21 03:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2013-05-21 03:19 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-05-21 03:04 - 2013-05-21 03:00 - 00007183 ____A C:\Windows\IE10_main.log
2013-05-21 03:03 - 2013-05-21 03:03 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-05-21 03:03 - 2013-05-21 03:03 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-05-21 03:03 - 2013-05-21 03:03 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-05-21 03:03 - 2013-05-21 03:03 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-05-21 03:03 - 2013-05-21 03:03 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-05-21 03:03 - 2013-05-21 03:03 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-05-21 03:03 - 2013-05-21 03:03 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2013-05-21 03:03 - 2013-05-21 03:03 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-05-21 03:03 - 2013-05-21 03:03 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-05-21 03:03 - 2013-05-21 03:03 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-05-21 03:03 - 2013-05-21 03:03 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-05-16 07:27 - 2012-10-08 13:12 - 00000000 ___RD C:\Users\Front Desk\Virtual Machines
2013-05-16 03:22 - 2009-07-14 00:45 - 00311040 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-16 03:04 - 2012-10-08 16:52 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-03 00:27

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-06-2013 03
Ran by [removed] at 2013-06-10 16:23:23 Run:
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Adobe Flash Player 11 ActiveX (Version: 11.4.402.287)
Adobe Reader X (10.1.7) (Version: 10.1.7)
AVG 2013 (Version: 13.0.3199)
AVG 2013 (Version: 13.0.3345)
AVG 2013 (Version: 2013.0.3345)
Cisco WebEx Meetings
Conexant HD Audio (Version: 8.50.4.0)
Dell Edoc Viewer (Version: 1.0.0)
ImgBurn (Version: 2.5.0.0)
Intel® Management Engine Components (Version: 7.1.50.1172)
Intel® Processor Graphics (Version: 8.15.10.2418)
Java 7 Update 9 (Version: 7.0.90)
Java Auto Updater (Version: 2.1.9.0)
LibreOffice 3.6 (Version: 3.6.2.2)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Patterson EagleSoft (Version: 16.00.0021)
PINPadDevice Files
Realtek Ethernet Controller All-In-One Windows Driver (Version: 1.12.0019)
TeamViewer 7 (Version: 7.0.14563)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Visual Studio 2008 x64 Redistributables (Version: 10.0.0.2)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)

==================== Restore Points =========================

10-06-2013 18:17:10 ComboFix created restore point
10-06-2013 18:29:20 Installed AVG 2013
10-06-2013 18:29:35 Installed AVG 2013
10-06-2013 18:55:31 OTL Restore Point - 6/10/2013 2:55:31 PM

==================== Faulty Device Manager Devices =============

Name: PS/2 Compatible Mouse
Description: PS/2 Compatible Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/10/2013 02:29:18 PM) (Source: MsiInstaller) (User: FRONTDESK)
Description: Product: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 – Error 1704.An installation for AVG 2012 is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?

Error: (06/10/2013 02:17:19 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 02:10:20 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 02:03:36 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 02:00:26 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 01:55:54 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 01:49:28 PM) (Source: MsiInstaller) (User: FRONTDESK)
Description: SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2012 – Error 1719. SA_Error1719: StandardAction(0xC00706B7): The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance.

Error: (06/10/2013 07:59:51 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/06/2013 08:44:20 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/06/2013 08:08:59 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/10/2013 02:08:46 PM) (Source: Service Control Manager) (User: )
Description: The WinDefend service terminated with the following error:
%%5

Error: (06/10/2013 02:07:45 PM) (Source: Service Control Manager) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Error: (06/10/2013 02:07:05 PM) (Source: Application Popup) (User: )
Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (06/10/2013 02:06:19 PM) (Source: Service Control Manager) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Error: (06/10/2013 02:02:20 PM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (06/10/2013 02:02:20 PM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (06/10/2013 01:59:55 PM) (Source: Disk) (User: )
Description: The driver detected a controller error on \Device\Harddisk1\DR1.

Error: (06/10/2013 01:59:08 PM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (06/10/2013 01:59:08 PM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (06/10/2013 01:55:05 PM) (Source: Service Control Manager) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
%%1068


Microsoft Office Sessions:
=========================
Error: (06/10/2013 02:29:18 PM) (Source: MsiInstaller)(User: FRONTDESK)
Description: Product: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 – Error 1704.An installation for AVG 2012 is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (06/10/2013 02:17:19 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 02:10:20 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 02:03:36 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 02:00:26 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 01:55:54 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2013 01:49:28 PM) (Source: MsiInstaller)(User: FRONTDESK)
Description: SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2012 – Error 1719. SA_Error1719: StandardAction(0xC00706B7): The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (06/10/2013 07:59:51 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/06/2013 08:44:20 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/06/2013 08:08:59 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
Date: 2013-06-10 14:07:05.608
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2013-06-10 14:07:05.577
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-10-23 01:12:22.415
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2012-10-23 01:00:29.991
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2012-10-22 23:32:21.614
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 26%
Total physical RAM: 8089.06 MB
Available physical RAM: 5914.07 MB
Total Pagefile: 9087.24 MB
Available Pagefile: 7163.17 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:219.16 GB) (Free:185.73 GB) NTFS (Disk=0 Partition=3)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: E87CCBBF)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=14 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=219 GB) - (Type=07 NTFS)

==================== End Of Log ============================

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-10 16:33:44
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST250DM000-1BD141 rev.KC45 232.89GB
Running: p87qu063.exe; Driver: C:\Users\FRONTD~1\AppData\Local\Temp\fwddipog.sys


—- Threads - GMER 2.1 —-

Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3064:2796] 000007fefae82a7c

—- EOF - GMER 2.1 —-
Sure I didn´t. But your IT Operator did that without asking someone.

2013-06-10 14:11 - 2013-06-10 14:11 - 00013556 ____A C:\ComboFix.txt

ComboFix 13-06-08.02 - Front Desk 06/10/2013 14:04:40.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8089.7033 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\GAC_64\Desktop.ini . . ((((((((((((((((((((((((( Files Created from 2013-05-10 to 2013-06-10 ))))))))))))))))))))))))))))))) . . 2013-06-10 18:07 . 2013-06-10 18:07 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-06-10 18:00 . 2013-06-10 18:00 ——– d—–w- c:\users\Front Desk\AppData\Local\Avg2013 2013-06-10 17:41 . 2013-06-10 17:41 ——– d—–w- c:\users\Front Desk\AppData\Roaming\TuneUp Software 2013-06-06 12:10 . 2013-06-06 12:10 ——– d—–w- c:\users\Front Desk\AppData\Roaming\Malwarebytes 2013-06-06 12:10 . 2013-06-06 12:10 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-06-06 12:10 . 2013-06-06 12:10 ——– d—–w- c:\programdata\Malwarebytes 2013-06-06 12:10 . 2013-04-04 18:50 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-06-06 12:09 . 2013-06-06 12:09 ——– d—–w- c:\users\Front Desk\AppData\Local\Programs 2013-06-05 16:24 . 2013-06-05 16:24 ——– d—–w- c:\windows\Sun 2013-05-15 08:50 . 2013-04-10 06:01 265064 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-05-15 08:50 . 2013-04-10 06:01 983400 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-05-15 08:50 . 2011-02-03 11:25 144384 —-a-w- c:\windows\system32\cdd.dll 2013-05-15 08:49 . 2013-02-27 06:02 111448 —-a-w- c:\windows\system32\consent.exe 2013-05-15 08:49 . 2013-02-27 05:52 14172672 —-a-w- c:\windows\system32\shell32.dll 2013-05-15 08:49 . 2013-02-27 05:52 197120 —-a-w- c:\windows\system32\shdocvw.dll 2013-05-15 08:49 . 2013-02-27 05:48 1930752 —-a-w- c:\windows\system32\authui.dll 2013-05-15 08:49 . 2013-02-27 05:47 70144 —-a-w- c:\windows\system32\appinfo.dll 2013-05-15 08:49 . 2013-02-27 04:49 1796096 —-a-w- c:\windows\SysWow64\authui.dll 2013-05-15 08:49 . 2013-04-10 03:30 3153920 —-a-w- c:\windows\system32\win32k.sys 2013-05-15 08:49 . 2013-03-19 05:53 48640 —-a-w- c:\windows\system32\wwanprotdim.dll 2013-05-15 08:49 . 2013-03-19 05:53 230400 —-a-w- c:\windows\system32\wwansvc.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-16 07:04 . 2012-10-08 20:52 75016696 —-a-w- c:\windows\system32\MRT.exe 2013-04-13 05:49 . 2013-05-15 08:50 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-05-15 08:50 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-05-15 08:50 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-05-15 08:50 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-05-15 08:50 474624 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-05-15 08:50 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 14:45 . 2013-04-24 10:05 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-03-19 06:04 . 2013-04-10 21:40 5550424 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 05:46 . 2013-04-10 21:40 43520 —-a-w- c:\windows\system32\csrsrv.dll 2013-03-19 05:04 . 2013-04-10 21:40 3968856 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-10 21:40 3913560 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47 . 2013-04-10 21:40 6656 —-a-w- c:\windows\SysWow64\apisetschema.dll 2013-03-19 03:06 . 2013-04-10 21:40 112640 —-a-w- c:\windows\system32\smss.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "ESInetConnect"="c:\eaglesoft\Shared Files\esinetconnect.exe" [2010-08-11 204800] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x] R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys;c:\windows\SYSNATIVE\DRIVERS\bcmwlhigh664.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 netvsc;netvsc;c:\windows\system32\DRIVERS\netvsc60.sys;c:\windows\SYSNATIVE\DRIVERS\netvsc60.sys [x] R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys;c:\windows\SYSNATIVE\DRIVERS\VMBusVideoM.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x] S2 atashost;WebEx Service Host for Support Center;c:\windows\SysWOW64\atashost.exe;c:\windows\SysWOW64\atashost.exe [x] S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-28 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-28 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-28 416024] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm TCP: Interfaces\{DD25B057-1747-48D2-8302-4C7DA5F4826F}: NameServer = 65.32.5.74,65.32.5.75 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-ROC_ROC_APR2013_AV - c:\users\Front Desk\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe Wow6432Node-HKLM-Run-AVG_TRAY - c:\program files (x86)\AVG\AVG2012\avgtray.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) AddRemove-PINPadDevice Files - c:\windows\System32\UNWISE.EXE . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2013-06-10 14:11:18 - machine was rebooted ComboFix-quarantined-files.txt 2013-06-10 18:11 . Pre-Run: 180,768,210,944 bytes free Post-Run: 189,647,257,600 bytes free . - - End Of File - - 8A112B04C6B4CC66F03A227115F20C87 5C616939100B85E558DA92B899A0FC36
Hit the Windows-key, don´t highlight anything within start menu, write cmd.
Your menu will change and show up cmd./b].
Right click it and select "Run as administrator", confirm the message with "yes".

Within the opening DOS window, write down the command from the following code-box and hit enter:

netsh winsock reset catalog

Restart and post up a new log from FRST
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-06-2013 02
Ran by [removed] (administrator) on 11-06-2013 08:09:34
Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HZAO09P5
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(Cisco WebEx LLC) C:\Windows\SysWOW64\atashost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Patterson Companies, Inc.) C:\EagleSoft\Shared Files\esinetconnect.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

==================== Registry (Whitelisted) ==================

HKCU\…\Policies\system: [disableregistrytools] 0
HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\…\Run: [ESInetConnect] C:\EagleSoft\Shared Files\esinetconnect.exe [204800 2010-08-11] (Patterson Companies, Inc.)
HKLM-x32\…\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [4408368 2013-04-29] (AVG Technologies CZ, s.r.o.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
HKCU SearchScopes: DefaultScope {5305F888-6716-478C-9FC7-5B902E46C1C2} URL =
SearchScopes: HKCU - {5305F888-6716-478C-9FC7-5B902E46C1C2} URL =
BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll No File
BHO: No Name - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - No File
BHO-x32: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll No File
BHO-x32: No Name - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - No File
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll No File
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll No File
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\..\Interfaces\{DD25B057-1747-48D2-8302-4C7DA5F4826F}: [NameServer]65.32.5.74,65.32.5.75

==================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)

==================== Drivers (Whitelisted) ====================

R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-03-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206136 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-10 16:33 - 2013-06-10 16:33 - 00000436 ____A C:\Users\Front Desk\Desktop\ark.txt
2013-06-10 16:32 - 2013-06-10 16:32 - 00000436 ____A C:\Users\Front Desk\Documents\ark.txt
2013-06-10 16:25 - 2013-06-10 16:25 - 00377856 ____A C:\Users\Front Desk\Desktop\p87qu063.exe
2013-06-10 16:23 - 2013-06-10 16:23 - 00012847 ____A C:\Users\Front Desk\Desktop\Addition.txt
2013-06-10 16:22 - 2013-06-10 16:22 - 00000000 ____D C:\FRST
2013-06-10 15:06 - 2013-06-10 15:06 - 00625664 ____A C:\Users\Front Desk\Desktop\dds.scr
2013-06-10 14:58 - 2013-06-10 14:58 - 00141238 ____A C:\Users\Front Desk\Desktop\OTL.Txt
2013-06-10 14:53 - 2013-06-10 14:53 - 00602112 ____A (OldTimer Tools) C:\Users\Front Desk\Desktop\OTL.exe
2013-06-10 14:32 - 2013-06-10 14:33 - 00000000 ____D C:\INfections from 06062013
2013-06-10 14:30 - 2013-06-10 14:30 - 00000297 ____A C:\Windows\SysWOW64\userawacs.cfg
2013-06-10 14:30 - 2013-06-10 14:30 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\AVG2013
2013-06-10 14:29 - 2013-06-10 14:30 - 00000000 ____D C:\ProgramData\AVG2013
2013-06-10 14:23 - 2013-06-10 14:23 - 01056768 ____A C:\Users\Front Desk\defltbase.sdb
2013-06-10 14:17 - 2013-06-10 14:33 - 00000000 ____D C:\Users\Front Desk\AppData\Local\Avg2013
2013-06-10 14:17 - 2013-06-10 14:17 - 00000000 ____D C:\Users\Front Desk\AppData\Local\MFAData
2013-06-10 14:11 - 2013-06-10 14:11 - 00013556 ____A C:\ComboFix.txt
2013-06-10 14:03 - 2013-06-10 14:16 - 00000000 ____D C:\Windows\erdnt
2013-06-10 13:55 - 2013-06-10 13:55 - 00000183 ____A C:\Windows\System32\avgrep.txt
2013-06-10 13:41 - 2013-06-10 13:41 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\TuneUp Software
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\Malwarebytes
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-06 08:10 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-05 12:24 - 2013-06-05 12:24 - 00000000 ____D C:\Windows\Sun
2013-05-21 03:03 - 2013-05-21 03:03 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-05-21 03:03 - 2013-05-21 03:03 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-05-21 03:03 - 2013-05-21 03:03 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-05-21 03:03 - 2013-05-21 03:03 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-05-21 03:03 - 2013-05-21 03:03 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-05-21 03:03 - 2013-05-21 03:03 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-05-21 03:03 - 2013-05-21 03:03 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2013-05-21 03:03 - 2013-05-21 03:03 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-05-21 03:03 - 2013-05-21 03:03 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-05-21 03:03 - 2013-05-21 03:03 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-05-21 03:03 - 2013-05-21 03:03 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-05-21 03:00 - 2013-05-21 03:04 - 00007183 ____A C:\Windows\IE10_main.log
2013-05-15 04:50 - 2013-04-10 02:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-15 04:50 - 2013-04-10 02:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-05-15 04:50 - 2011-02-03 07:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2013-05-15 04:49 - 2013-04-09 23:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-15 04:49 - 2013-03-19 01:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-05-15 04:49 - 2013-03-19 01:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-05-15 04:49 - 2013-02-27 02:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-15 04:49 - 2013-02-27 01:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-15 04:49 - 2013-02-27 01:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-15 04:49 - 2013-02-27 01:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-15 04:49 - 2013-02-27 01:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-15 04:49 - 2013-02-27 00:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-15 04:49 - 2013-02-27 00:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-15 04:49 - 2013-02-27 00:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll

==================== One Month Modified Files and Folders =======

2013-06-11 08:06 - 2009-07-14 01:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-11 08:06 - 2009-07-14 00:51 - 00035217 ____A C:\Windows\setupact.log
2013-06-11 08:05 - 2012-09-27 08:08 - 01467070 ____A C:\Windows\WindowsUpdate.log
2013-06-10 17:22 - 2012-10-08 14:12 - 00000000 ____D C:\ProgramData\MFAData
2013-06-10 16:33 - 2013-06-10 16:33 - 00000436 ____A C:\Users\Front Desk\Desktop\ark.txt
2013-06-10 16:32 - 2013-06-10 16:32 - 00000436 ____A C:\Users\Front Desk\Documents\ark.txt
2013-06-10 16:27 - 2009-07-14 00:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-10 16:27 - 2009-07-14 00:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-10 16:25 - 2013-06-10 16:25 - 00377856 ____A C:\Users\Front Desk\Desktop\p87qu063.exe
2013-06-10 16:23 - 2013-06-10 16:23 - 00012847 ____A C:\Users\Front Desk\Desktop\Addition.txt
2013-06-10 16:22 - 2013-06-10 16:22 - 00000000 ____D C:\FRST
2013-06-10 15:06 - 2013-06-10 15:06 - 00625664 ____A C:\Users\Front Desk\Desktop\dds.scr
2013-06-10 14:58 - 2013-06-10 14:58 - 00141238 ____A C:\Users\Front Desk\Desktop\OTL.Txt
2013-06-10 14:53 - 2013-06-10 14:53 - 00602112 ____A (OldTimer Tools) C:\Users\Front Desk\Desktop\OTL.exe
2013-06-10 14:33 - 2013-06-10 14:32 - 00000000 ____D C:\INfections from 06062013
2013-06-10 14:33 - 2013-06-10 14:17 - 00000000 ____D C:\Users\Front Desk\AppData\Local\Avg2013
2013-06-10 14:30 - 2013-06-10 14:30 - 00000297 ____A C:\Windows\SysWOW64\userawacs.cfg
2013-06-10 14:30 - 2013-06-10 14:30 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\AVG2013
2013-06-10 14:30 - 2013-06-10 14:29 - 00000000 ____D C:\ProgramData\AVG2013
2013-06-10 14:29 - 2012-10-08 14:22 - 00000000 ____D C:\Program Files (x86)\AVG
2013-06-10 14:23 - 2013-06-10 14:23 - 01056768 ____A C:\Users\Front Desk\defltbase.sdb
2013-06-10 14:23 - 2012-10-08 13:11 - 00000000 ____D C:\users\Front Desk
2013-06-10 14:20 - 2012-10-08 14:23 - 00000000 ____D C:\ProgramData\AVG2012
2013-06-10 14:19 - 2009-07-14 01:13 - 00771138 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-10 14:17 - 2013-06-10 14:17 - 00000000 ____D C:\Users\Front Desk\AppData\Local\MFAData
2013-06-10 14:16 - 2013-06-10 14:03 - 00000000 ____D C:\Windows\erdnt
2013-06-10 14:11 - 2013-06-10 14:11 - 00013556 ____A C:\ComboFix.txt
2013-06-10 14:09 - 2009-07-13 22:34 - 00000215 ____A C:\Windows\system.ini
2013-06-10 14:08 - 2010-11-20 23:47 - 00022040 ____A C:\Windows\PFRO.log
2013-06-10 13:55 - 2013-06-10 13:55 - 00000183 ____A C:\Windows\System32\avgrep.txt
2013-06-10 13:41 - 2013-06-10 13:41 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\TuneUp Software
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\Users\Front Desk\AppData\Roaming\Malwarebytes
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-06 08:10 - 2013-06-06 08:10 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-05 12:24 - 2013-06-05 12:24 - 00000000 ____D C:\Windows\Sun
2013-06-04 16:28 - 2005-03-02 17:24 - 00006337 ____A C:\Windows\SysWOW64\ESDictionary.cud
2013-05-21 03:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2013-05-21 03:19 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-05-21 03:04 - 2013-05-21 03:00 - 00007183 ____A C:\Windows\IE10_main.log
2013-05-21 03:03 - 2013-05-21 03:03 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-05-21 03:03 - 2013-05-21 03:03 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-05-21 03:03 - 2013-05-21 03:03 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-05-21 03:03 - 2013-05-21 03:03 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-05-21 03:03 - 2013-05-21 03:03 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-05-21 03:03 - 2013-05-21 03:03 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-05-21 03:03 - 2013-05-21 03:03 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2013-05-21 03:03 - 2013-05-21 03:03 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-05-21 03:03 - 2013-05-21 03:03 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-05-21 03:03 - 2013-05-21 03:03 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-05-21 03:03 - 2013-05-21 03:03 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-05-21 03:03 - 2013-05-21 03:03 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-05-21 03:03 - 2013-05-21 03:03 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-05-16 07:27 - 2012-10-08 13:12 - 00000000 ___RD C:\Users\Front Desk\Virtual Machines
2013-05-16 03:22 - 2009-07-14 00:45 - 00311040 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-16 03:04 - 2012-10-08 16:52 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-03 00:27

==================== End Of Log ============================
Looks good, but he didn´t clean up properly.

Let´s check the system for malware first:


Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Download ComboFix from here:

Link

Save the file to your desktop.
Rename it to uninstall and run it - this will remove combofix.


Uninstall our tools.
Please follow these steps in order:

  • In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  • In the case we used Combofix. Rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  • In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process
  • If there is still something left please delete it manualy.



SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2013
Antivirus out of date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 9
Java version out of Date!
Adobe Reader 10.1.7 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
AVG avgwdsvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````
That´s it - your system is clean now! :)



Java update update


Your Java runtime environment is outdated. We will fix this.
  • Get the actual JRE from here
  • Save jxpiinstall.exe to your desktop
  • Close all running programs, especially your browser(s)
  • Run jxpiinstall.exe. This will download the newest JRE installer ( Java 7 Update 4 ) and install the software
  • when finished, go to
    Start–>control panel–>add/remove programs and remove all older Java versions. (if existing)
  • When finished, reboot your computer.
After the reboot
  • Open control panel again and click the java symbol.
  • Click Settings under Temporary Internet Files.
    The Temporary Files Settings dialog box appears.
  • Click Delete Files.
    The Delete Temporary Files dialog box appears
  • Click OK on Delete Temporary Files window.
  • Click OK again.




Adobe Reader update


Your Adobe Reader is outdated. We will fix this.


  • Get the actual software from here. Important: Uncheck any optional software (for example Google Chrome, etc.) offered.
  • Run setup and follow the instructions.
  • Click upon Start–>control panel–>add/remove programs.
  • Search for and remove any older reader versions.




Reading Material
How to protect yourself

  • System Updates
    Beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
    Windows XP | Windows Vista |
    Windows 7 | windows 8
  • Protection
    What you need is one (not more) good virus scanner with backgroud protection. Additionally I recommend a special malwarescanner that you run from time to time.
    Personally I am using the avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer you good protection for free use. But please remember: You get only the full protection if you use the payed versions of your security software.
  • Up to date Software
    Stay up to date with all the programs you use. Some of those really have to have an eye on are: your browser(s) including add-ons and plug-ins, Java, Flash Player, your virus scanner, and basically every software you use often. These link may help you to check:
    • Secunia Online Software Inspector - Checks if your software has updates available.
    • Filehippo Update Checkere - This tool also scans your computer for outdated software.
    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins in your Firefox browser.
  • Backups
    There are chances for an emergency every day. So be prepared. Back up your data on a regular basis. If you burn it to DVDs from time to time, use a cloud-drive or a professional network backup system is your choice.
  • Brains
    It's no joke! You really need one of those things. :) It is very important not just to click anywhere it is colored or flashing while you surfing on the web. Do not click an OK button on any popping window without reading what it says. While installing software always choose the custom mode, read what those windows says and uncheck adware that will be installed along the software you want.
Something strange happened when I replaced the Java program. Right after I installed the new Java program I noticed 2 .ini files on the desktop, that I don't believe were there before. After the reboot they were gone, but now my browser is acting weird: ie. I can't log into this web site from that computer. Any ideas what's going on?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI