This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow computer [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:52:43 PM, on 6/19/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=14196
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: NETGEAR WNDA3100v2 Genie.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.



Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-06-2013
Ran by [removed] (administrator) on 20-06-2013 19:21:55
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Sygate Technologies, Inc.) C:\Program Files\Sygate\SPF\smc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
() C:\WINDOWS\system32\PnkBstrA.exe
() C:\WINDOWS\system32\PnkBstrB.exe
(New Boundary Technologies, Inc.) C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
() C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastUI.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe [966656 2005-03-09] (SoftThinks)
HKLM\…\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE [212992 2002-09-13] ()
HKLM\…\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe [86016 2003-03-11] (Intel® Corporation)
HKLM\…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\…\Run: [CHotkey] zHotkey.exe [x]
HKLM\…\Run: [ShowWnd] ShowWnd.exe [x]
HKLM\…\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [32768 2003-10-31] (Cyberlink Corp.)
HKLM\…\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4241512 2012-03-06] (AVAST Software)
HKLM\…\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui [2577632 2004-10-15] (Sygate Technologies, Inc.)
HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\…\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t [437160 2007-02-26] (Microsoft Corporation)
HKLM\…\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM\…\Runonce: [Del168113765] cmd.exe /Q /D /c del "C:\DOCUME~1\Tyler\LOCALS~1\Temp\0.del" [x]
HKLM\…\Runonce: [Del168139984] cmd.exe /Q /D /c del "C:\DOCUME~1\Tyler\LOCALS~1\Temp\0.del" [x]
Winlogon\Notify\igfxcui: igfxsrvc.dll (Intel Corporation)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKCU\…\Run: [Google Update] "C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [116648 2012-05-18] (Google Inc.)
HKCU\…\Runonce: [Del168113328] cmd.exe /Q /D /c del "C:\DOCUME~1\Tyler\LOCALS~1\Temp\0.del" [x]
HKCU\…\Runonce: [Del168139843] cmd.exe /Q /D /c del "C:\DOCUME~1\Tyler\LOCALS~1\Temp\0.del" [x]
HKU\Default User\…\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [ 2008-04-13] (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk
ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()
BootExecute: autocheck autochk * sasnative32

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=14196
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM SearchScopes: DefaultScope {56256A51-B582-467e-B8D4-7786EDA79AE0} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
HKCU SearchScopes: DefaultScope {20F81C18-BC78-4656-B3E3-A455672D1F82} URL = http://search.yahoo.com/search?p={searchTe…tf-8&fr=ie8
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/web/{searchTerms…ch&AF=19766
SearchScopes: HKCU - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
SearchScopes: HKCU - {20F81C18-BC78-4656-B3E3-A455672D1F82} URL = http://search.yahoo.com/search?p={searchTe…tf-8&fr=ie8
SearchScopes: HKCU - {24C133C0-313B-4591-A20E-0C044EE12FAD} URL = http://rover.ebay.com/rover/1/711-43047-14…e={searchTerms}
SearchScopes: HKCU - {8213A076-4908-404F-9AEE-8436AE5E71EB} URL = http://delicious.com/search?p={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2830765
SearchScopes: HKCU - {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = http://toolbar.inbox.com/search/dispatcher…0197&lng=en
SearchScopes: HKCU - {C3BFE04A-DC1C-44B9-93F8-0FD98FCAE10E} URL = http://www.flickr.com/search/?q={searchTerms}
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-06-2013 Ran by [removed] at 2013-06-20 19:23:45 Run: Running from C:\Documents and Settings\[removed]\My Documents\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe Flash Player 11 ActiveX (Version: 11.4.402.278) Adobe Flash Player 11 Plugin (Version: 11.6.602.180) Adobe Reader X (10.1.7) (Version: 10.1.7) Apple Application Support (Version: 2.1.9) Apple Mobile Device Support (Version: 5.2.0.6) Apple Software Update (Version: 2.1.3.127) avast! Free Antivirus (Version: 7.0.1426.0) Bonjour (Version: 3.0.0.10) CCleaner (Version: 3.28) DealPly (remove only) (Version: 4.8.6.1) File Type Assistant Google Chrome (Version: 27.0.1453.116) HiJackThis (Version: 1.0.0) ImageMixer VCD2 (Version: 2.01.002.3) InCD EasyWrite Reader Intel® PRO Network Adapters and Drivers Intel® PROSet (Version: 6.05.2001) iTunes (Version: 10.6.3.25) Java 2 Runtime Environment, SE v1.4.2 (Version: 1.4.2) Java 7 Update 17 (Version: 7.0.170) Java Auto Updater (Version: 2.1.9.0) Java™ 6 Update 27 (Version: 6.0.270) Java™ SE Development Kit 7 (Version: 1.7.0.0) JavaFX 2.0.3 (Version: 2.0.3) Junk Mail filter update (Version: 14.0.8117.416) Macromedia Shockwave Player (Version: 10.1.0.11) Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300) Microsoft .NET Framework 1.1 (Version: 1.1.4322) Microsoft .NET Framework 1.1 Security Update (KB2698023) Microsoft .NET Framework 1.1 Security Update (KB2742597) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729) Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Choice Guard (Version: 2.0.48.0) Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1) Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Outlook Connector (Version: 12.0.6423.1000) Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0) Microsoft Office Publisher 2003 (Version: 11.0.8173.0) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Mozilla Firefox 19.0.2 (x86 en-US) (Version: 19.0.2) Mozilla Maintenance Service (Version: 19.0.2) MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Multimedia Keyboard Driver Nero BurnRights Nero OEM NETGEAR WNDA3100v2 wireless USB 2.0 adapter (Version: 1.03.000) Open It! (Version: 1.1.1) Picture Package (Version: 1.05.001) POINT (Version: 3.06.134) Point (Version: 5.0) PowerDVD QuickTime (Version: 7.72.80.56) QuickTime 3.0 Reading Basics Safari (Version: 5.34.57.2) Segoe UI (Version: 14.0.4327.805) Serif PhotoPlus 6.0 (Version: 6.00) Soft Data Fax Modem with SmartCP Sony USB Driver SoundMAX (Version: 5.12.01.5240) SpaceCowboy (Version: 0.3.3.55) SpywareBlaster 4.6 (Version: 4.6.0) Sygate Personal Firewall (Version: 5.6.2808) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Windows Internet Explorer 8 (KB2447568) (Version: 1) Update for Windows Internet Explorer 8 (KB976662) (Version: 1) Update for Windows XP (KB2345886) (Version: 1) Update for Windows XP (KB2492386) (Version: 1) Update for Windows XP (KB2541763) (Version: 1) Update for Windows XP (KB2607712) (Version: 1) Update for Windows XP (KB2616676) (Version: 1) Update for Windows XP (KB2641690) (Version: 1) Update for Windows XP (KB2661254-v2) (Version: 2) Update for Windows XP (KB2718704) (Version: 1) Update for Windows XP (KB2736233) (Version: 1) Update for Windows XP (KB2749655) (Version: 1) Update for Windows XP (KB951978) (Version: 1) Update for Windows XP (KB955759) (Version: 1) Update for Windows XP (KB961503) (Version: 1) Update for Windows XP (KB967715) (Version: 1) Update for Windows XP (KB968389) (Version: 1) Update for Windows XP (KB971029) (Version: 1) Update for Windows XP (KB971737) (Version: 1) Update for Windows XP (KB973687) (Version: 1) Update for Windows XP (KB973815) (Version: 1) Update for Zip Opener WebFldrs XP (Version: 9.50.7523) Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0) Windows Internet Explorer 7 (Version: 20070813.185237) Windows Internet Explorer 8 (Version: 20090308.140743) Windows Live Communications Platform (Version: 14.0.8117.416) Windows Live Essentials (Version: 14.0.8117.0416) Windows Live Essentials (Version: 14.0.8117.416) Windows Live Family Safety (Version: 14.0.8118.427) Windows Live Photo Gallery (Version: 14.0.8117.416) Windows Live Sign-in Assistant (Version: 5.000.818.5) Windows Live Sync (Version: 14.0.8117.416) Windows Live Upload Tool (Version: 14.0.8014.1029) Windows Live Writer (Version: 14.0.8117.0416) Windows Management Framework Core Windows Media Format 11 runtime Windows Media Player 11 Windows Search 4.0 (Version: 04.00.6001.503) Windows XP Service Pack 3 (Version: 20080414.031525) Yahoo! Toolbar Zip Opener Packages ==================== Restore Points ========================= 31-03-2013 23:33:14 Software Distribution Service 3.0 01-04-2013 23:57:23 System Checkpoint 02-04-2013 08:00:23 Software Distribution Service 3.0 03-04-2013 08:00:25 Software Distribution Service 3.0 04-04-2013 08:00:27 Software Distribution Service 3.0 05-04-2013 08:00:27 Software Distribution Service 3.0 06-04-2013 08:00:27 Software Distribution Service 3.0 07-04-2013 08:00:30 Software Distribution Service 3.0 08-04-2013 08:00:26 Software Distribution Service 3.0 09-04-2013 01:28:21 Software Distribution Service 3.0 09-04-2013 08:00:21 Software Distribution Service 3.0 10-04-2013 08:01:07 Software Distribution Service 3.0 11-04-2013 08:00:47 Software Distribution Service 3.0 12-04-2013 08:00:23 Software Distribution Service 3.0 13-04-2013 08:00:22 Software Distribution Service 3.0 14-04-2013 08:00:24 Software Distribution Service 3.0 15-04-2013 08:00:28 Software Distribution Service 3.0 16-04-2013 08:00:31 Software Distribution Service 3.0 17-04-2013 08:00:35 Software Distribution Service 3.0 18-04-2013 08:00:30 Software Distribution Service 3.0 19-04-2013 08:00:23 Software Distribution Service 3.0 20-04-2013 08:00:25 Software Distribution Service 3.0 21-04-2013 08:00:27 Software Distribution Service 3.0 22-04-2013 08:00:25 Software Distribution Service 3.0 23-04-2013 08:00:26 Software Distribution Service 3.0 24-04-2013 08:00:27 Software Distribution Service 3.0 25-04-2013 08:00:30 Software Distribution Service 3.0 26-04-2013 08:00:23 Software Distribution Service 3.0 27-04-2013 08:00:29 Software Distribution Service 3.0 28-04-2013 08:00:25 Software Distribution Service 3.0 29-04-2013 08:00:27 Software Distribution Service 3.0 30-04-2013 08:00:29 Software Distribution Service 3.0 01-05-2013 08:00:26 Software Distribution Service 3.0 02-05-2013 08:00:23 Software Distribution Service 3.0 03-05-2013 08:00:28 Software Distribution Service 3.0 04-05-2013 08:00:22 Software Distribution Service 3.0 05-05-2013 08:00:20 Software Distribution Service 3.0 05-05-2013 20:01:54 Software Distribution Service 3.0 06-05-2013 08:00:23 Software Distribution Service 3.0 07-05-2013 08:00:25 Software Distribution Service 3.0 08-05-2013 08:00:24 Software Distribution Service 3.0 09-05-2013 08:00:25 Software Distribution Service 3.0 10-05-2013 08:00:25 Software Distribution Service 3.0 10-05-2013 23:14:05 Software Distribution Service 3.0 11-05-2013 00:04:34 Software Distribution Service 3.0 12-05-2013 00:41:37 System Checkpoint 12-05-2013 08:00:25 Software Distribution Service 3.0 13-05-2013 08:00:25 Software Distribution Service 3.0 14-05-2013 08:00:23 Software Distribution Service 3.0 15-05-2013 08:00:50 Software Distribution Service 3.0 16-05-2013 08:00:25 Software Distribution Service 3.0 17-05-2013 08:00:22 Software Distribution Service 3.0 18-05-2013 08:00:22 Software Distribution Service 3.0 19-05-2013 08:00:23 Software Distribution Service 3.0 20-05-2013 08:00:24 Software Distribution Service 3.0 21-05-2013 08:00:28 Software Distribution Service 3.0 22-05-2013 08:00:45 Software Distribution Service 3.0 23-05-2013 08:00:24 Software Distribution Service 3.0 24-05-2013 08:00:25 Software Distribution Service 3.0 25-05-2013 08:00:24 Software Distribution Service 3.0 26-05-2013 08:00:30 Software Distribution Service 3.0 27-05-2013 08:00:27 Software Distribution Service 3.0 28-05-2013 08:00:30 Software Distribution Service 3.0 29-05-2013 00:06:38 Software Distribution Service 3.0 29-05-2013 08:00:21 Software Distribution Service 3.0 30-05-2013 08:00:24 Software Distribution Service 3.0 31-05-2013 08:00:23 Software Distribution Service 3.0 01-06-2013 08:00:23 Software Distribution Service 3.0 02-06-2013 08:00:32 Software Distribution Service 3.0 03-06-2013 08:00:25 Software Distribution Service 3.0 04-06-2013 08:00:26 Software Distribution Service 3.0 05-06-2013 08:00:23 Software Distribution Service 3.0 06-06-2013 08:00:23 Software Distribution Service 3.0 07-06-2013 08:00:24 Software Distribution Service 3.0 08-06-2013 08:00:24 Software Distribution Service 3.0 09-06-2013 08:01:18 Software Distribution Service 3.0 10-06-2013 08:00:23 Software Distribution Service 3.0 11-06-2013 08:00:23 Software Distribution Service 3.0 12-06-2013 08:00:48 Software Distribution Service 3.0 13-06-2013 08:00:24 Software Distribution Service 3.0 14-06-2013 08:00:24 Software Distribution Service 3.0 15-06-2013 08:00:23 Software Distribution Service 3.0 16-06-2013 08:00:23 Software Distribution Service 3.0 17-06-2013 08:00:26 Software Distribution Service 3.0 18-06-2013 08:00:27 Software Distribution Service 3.0 19-06-2013 08:00:23 Software Distribution Service 3.0 20-06-2013 08:00:26 Software Distribution Service 3.0 ==================== Faulty Device Manager Devices ============= Name: Video Controller (VGA Compatible) Description: Video Controller (VGA Compatible) Class Guid: Manufacturer:
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-20 20:12:56
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600JB-22GVC0 rev.08.02D08 149.05GB
Running: 7d9sy3k2.exe; Driver: C:\DOCUME~1\Tyler\LOCALS~1\Temp\pgrcqaod.sys


—- System - GMER 2.1 —-

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xF6406DF8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xF6493A5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0xF640785E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xF6433D5D]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xF640C2E4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xF640C330]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xF640C422]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xF6433711]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xF640C252]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xF640C374]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xF640C29A]
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.) ZwCreateThread [0xF77E16F0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xF640C3DC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xF6406E44]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xF6434423]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xF64346D9]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xF64099A8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xF643428E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xF64340F9]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xF6493B34]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xF6406AD6]
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.) ZwMapViewOfSection [0xF77E1470]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xF6406E90]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xF6409D1C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xF6407B02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xF640C30E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xF640C352]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xF640C446]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xF6433A6D]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xF640C278]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xF6409518]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xF640C3AE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xF640C2C2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xF640974C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xF640C400]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xF6493CA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xF6433F74]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xF64079CE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xF6433DC6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xF649DB68]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xF6432D84]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xF6406EDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xF6406F28]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xF6406B46]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xF6406CEA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xF643452A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xF6406C92]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xF6406D5A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwTerminateProcess [0xF6493D60]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xF6406F74]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwWriteVirtualMemory [0xF6493BE0]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xF64A9D92]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

—- Devices - GMER 2.1 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/AVAST Software)
Device \Driver\Tcpip \Device\Ip wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\Tcpip \Device\Udp wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)

AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\Tcpip \Device\IPMULTICAST wpsdrvnt.sys (wpsdrvnt/Sygate Technologies, Inc.)
Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

—- Processes - GMER 2.1 —-

Process hidden process (*** hidden *** ) 14516
Process hidden process (*** hidden *** ) 47348

—- Registry - GMER 2.1 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{40940170-2910-B285-0FBA-DA987D852E01}\InprocServer32@ C:\WINDOWS\system32\msi.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{40940170-2910-B285-0FBA-DA987D852E01}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\AuxUserType@
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\AuxUserType\2
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\AuxUserType\2@ File
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\AuxUserType\3
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\AuxUserType\3@ Outlook File Attachment
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\InprocHandler32@ ole32.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\LocalServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\LocalServer32@LocalServer32 (f'^Vn-}f(ZXfeAR6.jiOUTLOOKFiles>ir@X7cr$%@u$}&V7{4p'?
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\ProgID@ Outlook.FileAttach
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\Verb@
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\Verb\0
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\Verb\0@ &Open,0,2
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\Verb\1
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\Verb\1@ P&rint,0,2
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\Verb\2
Reg HKLM\SOFTWARE\Classes\CLSID\{68ED4D73-9D5B-D39A-CAB0-202567DE6422}\Verb\2@ &Save As…,0,2
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\Implemented Categories\{62C8FE65-4EBB-45E7-B440-6E39B2CDBF29}
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\Implemented Categories\{62C8FE65-4EBB-45E7-B440-6E39B2CDBF29}@
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32@ C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32@Class Microsoft.CLRAdmin.CCommandHistory
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32@Assembly mscorcfg, Version=1.0.5000.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32@RuntimeVersion v1.1.4322
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32\1.0.5000.0
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32\1.0.5000.0@Class Microsoft.CLRAdmin.CCommandHistory
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32\1.0.5000.0@Assembly mscorcfg, Version=1.0.5000.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\InprocServer32\1.0.5000.0@RuntimeVersion v1.1.4322
Reg HKLM\SOFTWARE\Classes\CLSID\{88AC8A2F-D879-79AA-5D8F-F9A1A820F6A9}\ProgId@ Microsoft.CLRAdmin.CCommandHistory
Reg HKLM\SOFTWARE\Classes\CLSID\{D0B390FB-898C-4CD4-830D-A7665CF8E0E8}\InProcServer32@ C:\Program Files\Symantec\LiveUpdate\LuComServerPS_2_6.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{D0B390FB-898C-4CD4-830D-A7665CF8E0E8}\InProcServer32@ThreadingModel Both

—- Disk sectors - GMER 2.1 —-

Disk \Device\Harddisk0\DR0 unknown MBR code

—- EOF - GMER 2.1 —-

Attachments:

Ok sorry for the inconvienance.I wasnt familiar with the upload option before but now I am.This is the exact log of the frst.Thank you

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-06-2013
Ran by [removed] (administrator) on 20-06-2013 19:21:55
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Sygate Technologies, Inc.) C:\Program Files\Sygate\SPF\smc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
() C:\WINDOWS\system32\PnkBstrA.exe
() C:\WINDOWS\system32\PnkBstrB.exe
(New Boundary Technologies, Inc.) C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
() C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastUI.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe [966656 2005-03-09] (SoftThinks)
HKLM\…\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE [212992 2002-09-13] ()
HKLM\…\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe [86016 2003-03-11] (Intel(R) Corporation)
HKLM\…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\…\Run: [CHotkey] zHotkey.exe [x]
HKLM\…\Run: [ShowWnd] ShowWnd.exe [x]
HKLM\…\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [32768 2003-10-31] (Cyberlink Corp.)
HKLM\…\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4241512 2012-03-06] (AVAST Software)
HKLM\…\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui [2577632 2004-10-15] (Sygate Technologies, Inc.)
HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\…\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t [437160 2007-02-26] (Microsoft Corporation)
HKLM\…\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM\…\Runonce: [Del168113765] cmd.exe /Q /D /c del "C:\DOCUME~1\Tyler\LOCALS~1\Temp\0.del" [x]
HKLM\…\Runonce: [Del168139984] cmd.exe /Q /D /c del "C:\DOCUME~1\Tyler\LOCALS~1\Temp\0.del" [x]
Winlogon\Notify\igfxcui: igfxsrvc.dll (Intel Corporation)
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKCU\…\Run: [Google Update] "C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [116648 2012-05-18] (Google Inc.)
HKCU\…\Runonce: [Del168113328] cmd.exe /Q /D /c del "C:\DOCUME~1\Tyler\LOCALS~1\Temp\0.del" [x]
HKCU\…\Runonce: [Del168139843] cmd.exe /Q /D /c del "C:\DOCUME~1\Tyler\LOCALS~1\Temp\0.del" [x]
HKU\Default User\…\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [ 2008-04-13] (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk
ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()
BootExecute: autocheck autochk * sasnative32

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o;=14196
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKLM SearchScopes: DefaultScope {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = 
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
SearchScopes: HKLM - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZXxdm002YYus&ptb;=02F284AB-A45B-4CBB-BDF1-0E0AF22444DD&ind;=2011070817&ptnrS;=ZXxdm002YYus&si;=COLdr4TW8qkCFQzHKgodtjMIZA&n;=77de8161&psa;=&st;=sb&searchfor;={searchTerms}
HKCU SearchScopes: DefaultScope {20F81C18-BC78-4656-B3E3-A455672D1F82} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ie8
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF;=19766
SearchScopes: HKCU - {110a9ea2-8810-4c04-b916-cfd4e9427fec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZXxdm002YYus&ptb;=02F284AB-A45B-4CBB-BDF1-0E0AF22444DD&ind;=2011070817&ptnrS;=ZXxdm002YYus&si;=COLdr4TW8qkCFQzHKgodtjMIZA&n;=77de8161&psa;=&st;=sb&searchfor;={searchTerms}
SearchScopes: HKCU - {20F81C18-BC78-4656-B3E3-A455672D1F82} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ie8
SearchScopes: HKCU - {24C133C0-313B-4591-A20E-0C044EE12FAD} URL = http://rover.ebay.com/rover/1/711-43047-14818-1/4?satitle={searchTerms}
SearchScopes: HKCU - {8213A076-4908-404F-9AEE-8436AE5E71EB} URL = http://delicious.com/search?p={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT2830765
SearchScopes: HKCU - {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = http://toolbar.inbox.com/search/dispatcher.aspx?tp=bs&qkw;={searchTerms}&tbid;=80197&lng;=en
SearchScopes: HKCU - {C3BFE04A-DC1C-44B9-93F8-0FD98FCAE10E} URL = http://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKCU - {C6AE98FD-6E92-4C1C-8753-1074A9A688F6} URL = http://www.facebook.com/search/?src=os&q;={searchTerms}
SearchScopes: HKCU - {FE6A8BFF-334E-4ADC-9D12-3098BA9AB63D} URL = http://websearch.ask.com/redirect?client=ie&tb;=FWV5&o;=14193&src;=crm&q;={searchTerms}&locale;=&apn;_ptnrs=FM&apn;_dtid=PFM010YYUS&apn;_uid=6add4d32-753c-42ea-b5ce-59e145fdc0cb&apn;_sauid=33A11B9E-C92A-4440-A8FC-335C254DF4A1
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: DealPly - {EF7BD87A-8024-11E2-F316-F3E56188709B} - C:\Program Files\DealPly\DealPlyIE.dll (DealPly)
Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} http://www.acclaim.com/cabs/acclaim_v4.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ipp - No CLSID Value - 
Handler: msdaipp - No CLSID Value - 
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Tyler\Application Data\Mozilla\Firefox\Profiles\ojpxk470.default
FF SearchEngine: Ask.com
FF Homepage: hxxp://www.yahoo.com/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @RadioRage_4j.com/Plugin - C:\Program Files\RadioRage_4j\bar\1.bin\NP4jStub.dll No File
FF Plugin: @real.com/npracplug;version=1.0.0.0 - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin: npDisplayEngine - C:\Program Files\LivingPlay\nplplaypop.dll ( )
FF Extension: Bitlord 1.2 Community Toolbar - C:\Documents and Settings\Tyler\Application Data\Mozilla\Firefox\Profiles\ojpxk470.default\Extensions\{8c5878d0-6106-423b-aaa8-144c143dbf44}(2)
FF Extension: ShopToWin13 - C:\Documents and Settings\Tyler\Application Data\Mozilla\Firefox\Profiles\ojpxk470.default\Extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}

Chrome: 
=======
CHR HomePage: hxxp://www.ask.com/?l=dis&o;=14196cr
CHR RestoreOnStartup: "hxxp://www.yahoo.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\27.0.1453.116\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\Application\27.0.1453.116\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Shockwave for Director) - C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll (Macromedia, Inc.)
CHR Plugin: (Microsoft Office 2003) - C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Update) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Display Engine v2) - C:\Program Files\LivingPlay\nplplaypop.dll ( )
CHR Plugin: (Java(TM) Platform SE 7 U3) - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Java Deployment Toolkit 7.0.30.255) - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (RealArcade Mozilla Plugin) - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (YouTube) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (DealPly Shopping  ) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma\3.5.0.0_0
CHR Extension: (avast! WebRep) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0
CHR Extension: (Gmail) - C:\Documents and Settings\Tyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44768 2012-03-06] (AVAST Software)
S3 NetSvc; C:\Program Files\Intel\NCS\Sync\NetSvc.exe [143360 2003-03-03] (Intel(R) Corporation)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [66872 2007-10-06] ()
R2 PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [103736 2007-11-18] ()
R2 PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [172032 2005-07-15] (New Boundary Technologies, Inc.)
R2 SmcService; C:\Program Files\Sygate\SPF\smc.exe [2577632 2004-10-15] (Sygate Technologies, Inc.)
S3 usprserv; C:\Windows\System32\svchost.exe [14336 2008-04-13] (Microsoft Corporation)
R2 WSWNDA3100v2; C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe [303360 2011-12-14] ()
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x]

==================== Drivers (Whitelisted) ====================

R1 Aavmker4; C:\Windows\System32\Drivers\Aavmker4.sys [24920 2012-03-06] (AVAST Software)
R2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21035 2011-04-14] (Meetinghouse Data Communications)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [20696 2012-03-06] (AVAST Software)
R2 aswMon2; C:\Windows\System32\Drivers\aswMon2.sys [95704 2012-03-06] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [35672 2012-03-06] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [612184 2012-03-06] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [337880 2012-03-06] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [53848 2012-03-06] (AVAST Software)
R2 Av260cn; C:\Windows\System32\Drivers\Av260cn.sys [83456 1997-09-08] ()
R2 Av260cnb; C:\Windows\System32\Drivers\Av260cnb.sys [83168 1997-09-08] ()
R3 BCMH43XX; C:\Windows\System32\DRIVERS\bcmwlhigh5.sys [1034240 2011-03-28] (Broadcom Corporation)
R1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [13567 2004-03-08] (B.H.A Corporation)
S3 DC21x4; C:\Windows\System32\DRIVERS\dc21x4.sys [63208 2001-08-17] (Intel Corporation.)
R3 E1000; C:\Windows\System32\DRIVERS\e1000325.sys [131584 2004-03-12] (Intel Corporation)
R2 fssfltr; C:\Windows\System32\DRIVERS\fssfltr_tdi.sys [54760 2010-04-28] (Microsoft Corporation)
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.sys [1035008 2005-07-22] (Conexant Systems, Inc.)
S3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [737874 2004-08-20] (Intel Corporation)
R1 incdrm; C:\Windows\System32\Drivers\incdrm.sys [28080 2003-12-30] (Ahead Software AG)
S3 NPF; C:\Windows\System32\DRIVERS\npf.sys [50704 2010-02-03] (CACE Technologies, Inc.)
S1 P3; C:\Windows\System32\DRIVERS\p3.sys [42752 2008-04-13] (Microsoft Corporation)
S3 PnkBstrK; C:\WINDOWS\system32\drivers\PnkBstrK.sys [22328 2007-11-18] ()
S3 SONYPVU1; C:\Windows\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
R0 Teefer; C:\Windows\System32\Drivers\Teefer.sys [60496 2004-10-15] (Sygate Technologies, Inc.)
R2 wg3n; C:\Windows\SYSTEM32\Drivers\wg3n.sys [14568 2004-10-15] (Sygate Technologies, Inc.)
R2 wg4n; C:\Windows\SYSTEM32\Drivers\wg4n.sys [14568 2004-10-15] (Sygate Technologies, Inc.)
R2 wg5n; C:\Windows\SYSTEM32\Drivers\wg5n.sys [14568 2004-10-15] (Sygate Technologies, Inc.)
R2 wg6n; C:\Windows\SYSTEM32\Drivers\wg6n.sys [14568 2004-10-15] (Sygate Technologies, Inc.)
R1 wpsdrvnt; C:\WINDOWS\system32\drivers\wpsdrvnt.sys [21075 2004-10-15] (Sygate Technologies, Inc.)
S4 Abiosdsk; No ImagePath
S4 Atdisk; No ImagePath
S3 BCASPROT; \??\C:\Program Files\Systweak\Advanced System Protector\sasprot32.sys [x]
S1 Changer; No ImagePath
S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [x]
S1 lbrtfdc; No ImagePath
S1 MpKsl21d913d8; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A95B116-D1D3-49A2-9AD2-ED673004EB16}\MpKsl21d913d8.sys [x]
S1 MpKsl2427cc8c; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{22C061A2-FB1A-4610-9088-CB1B987A5DF2}\MpKsl2427cc8c.sys [x]
S1 MpKsl2ef0bc21; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{00847D90-B314-41C8-880F-387E7F6308B5}\MpKsl2ef0bc21.sys [x]
S1 MpKsl60373af4; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{37A2814F-3079-4929-B445-F5B2061F9231}\MpKsl60373af4.sys [x]
S1 MpKsl73d3f940; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A95B116-D1D3-49A2-9AD2-ED673004EB16}\MpKsl73d3f940.sys [x]
S1 MpKsl7a76119b; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F818605D-3633-4059-8462-9F2073FA3020}\MpKsl7a76119b.sys [x]
S1 MpKslb57e5e65; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C9B4139-3B83-4D78-9F6D-7FD0576DDB7A}\MpKslb57e5e65.sys [x]
S1 MpKslc8a114d4; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B6E3FFF2-0CC0-43F1-ACAE-F97D183C5045}\MpKslc8a114d4.sys [x]
S1 PCIDump; No ImagePath
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
S3 RTLWUSB; system32\DRIVERS\wg111v2.sys [x]
S4 Simbad; No ImagePath
S4 vsdatant;  [x]
S3 WDICA; No ImagePath
U3 Winsock - Google Desktop Search Backup Before First Install; No ImagePath
U3 Winsock - Google Desktop Search Backup Before Last Install; No ImagePath
U1 WS2IFSL; 

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-20 19:19 - 2013-06-20 19:19 - 00000000 ____D C:\FRST
2013-06-20 18:38 - 2013-06-20 18:38 - 00000763 ____A C:\Documents and Settings\All Users\Desktop\Open It!.lnk
2013-06-20 18:38 - 2013-06-20 18:38 - 00000412 ____A C:\Windows\Tasks\At2.job
2013-06-20 18:38 - 2013-06-20 18:38 - 00000408 ____A C:\Windows\Tasks\At1.job
2013-06-20 18:38 - 2013-06-20 18:38 - 00000290 ____A C:\Windows\Tasks\DealPlyUpdate.job
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Program Files\OpenIt
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Program Files\DealPly
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Documents and Settings\Tyler\Application Data\Zip Opener Packages
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Documents and Settings\Tyler\Application Data\DSite
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Documents and Settings\Tyler\Application Data\DealPly
2013-06-12 03:10 - 2013-06-12 03:10 - 00000000 __HDC C:\Windows\$NtUninstallKB2839229$
2013-06-12 03:01 - 2013-06-12 03:03 - 00011078 ____A C:\Windows\KB2838727-IE8.log
2013-06-11 18:22 - 2013-06-12 03:10 - 00013921 ____A C:\Windows\KB2839229.log
2013-05-27 10:44 - 2013-05-27 10:44 - 00000278 ____A C:\Documents and Settings\Tyler\Desktop\Shortcut to TaxReturn.lnk

==================== One Month Modified Files and Folders ========

2013-06-20 19:19 - 2013-06-20 19:19 - 00000000 ____D C:\FRST
2013-06-20 19:15 - 2012-04-04 17:49 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-20 19:10 - 2004-05-26 15:23 - 01623539 ____A C:\Windows\WindowsUpdate.log
2013-06-20 19:04 - 2012-05-18 10:41 - 00000978 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1330836935-1025085790-3687105625-1008UA.job
2013-06-20 18:55 - 2005-07-15 01:43 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-06-20 18:38 - 2013-06-20 18:38 - 00000763 ____A C:\Documents and Settings\All Users\Desktop\Open It!.lnk
2013-06-20 18:38 - 2013-06-20 18:38 - 00000412 ____A C:\Windows\Tasks\At2.job
2013-06-20 18:38 - 2013-06-20 18:38 - 00000408 ____A C:\Windows\Tasks\At1.job
2013-06-20 18:38 - 2013-06-20 18:38 - 00000290 ____A C:\Windows\Tasks\DealPlyUpdate.job
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Program Files\OpenIt
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Program Files\DealPly
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Documents and Settings\Tyler\Application Data\Zip Opener Packages
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Documents and Settings\Tyler\Application Data\DSite
2013-06-20 18:38 - 2013-06-20 18:38 - 00000000 ____D C:\Documents and Settings\Tyler\Application Data\DealPly
2013-06-20 18:38 - 2011-10-15 22:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Norton
2013-06-20 18:11 - 2011-10-12 20:31 - 00000664 ____A C:\Windows\System32\d3d9caps.dat
2013-06-20 16:31 - 2012-05-18 11:14 - 00002284 ____A C:\Documents and Settings\Tyler\Desktop\Google Chrome.lnk
2013-06-20 10:04 - 2012-05-18 10:41 - 00000926 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1330836935-1025085790-3687105625-1008Core.job
2013-06-20 01:04 - 2004-05-26 15:32 - 00032466 ____A C:\Windows\SchedLgU.Txt
2013-06-19 20:32 - 2011-09-30 15:19 - 00002447 ____A C:\Documents and Settings\Tyler\Desktop\HiJackThis.lnk
2013-06-19 19:46 - 2011-12-27 20:30 - 00000784 ____A C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-06-19 19:46 - 2011-09-30 14:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-06-18 20:10 - 2006-10-13 19:08 - 00000062 __ASH C:\Documents and Settings\Tyler\Local Settings\desktop.ini
2013-06-18 20:10 - 2004-05-26 15:32 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2013-06-18 20:10 - 2004-05-26 15:32 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2013-06-18 20:10 - 2004-05-26 15:32 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-18 20:10 - 2004-05-26 14:30 - 00001170 ____A C:\Windows\System32\wpa.dbl
2013-06-18 20:10 - 2004-05-26 08:18 - 00000159 ____A C:\Windows\wiadebug.log
2013-06-18 20:10 - 2004-05-26 08:18 - 00000049 ____A C:\Windows\wiaservc.log
2013-06-18 20:08 - 2006-10-13 19:08 - 00000278 ___SH C:\Documents and Settings\Tyler\ntuser.ini
2013-06-15 22:59 - 2011-04-15 19:22 - 00000284 ____A C:\Windows\Tasks\AppleSoftwareUpdate.job
2013-06-12 03:10 - 2013-06-12 03:10 - 00000000 __HDC C:\Windows\$NtUninstallKB2839229$
2013-06-12 03:10 - 2013-06-11 18:22 - 00013921 ____A C:\Windows\KB2839229.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00072502 ____A C:\Windows\iis6.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00068940 ____A C:\Windows\FaxSetup.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00032516 ____A C:\Windows\ocgen.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00031034 ____A C:\Windows\tsoc.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00022437 ____A C:\Windows\comsetup.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00020452 ____A C:\Windows\msmqinst.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00013617 ____A C:\Windows\ntdtcsetup.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00011913 ____A C:\Windows\netfxocm.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00004675 ____A C:\Windows\MedCtrOC.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00003762 ____A C:\Windows\ocmsn.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00003421 ____A C:\Windows\tabletoc.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00003399 ____A C:\Windows\msgsocm.log
2013-06-12 03:10 - 2013-04-11 03:02 - 00001374 ____A C:\Windows\imsins.log
2013-06-12 03:03 - 2013-06-12 03:01 - 00011078 ____A C:\Windows\KB2838727-IE8.log
2013-06-12 03:03 - 2013-04-11 03:10 - 00008329 ____A C:\Windows\updspapi.log
2013-06-12 03:03 - 2013-04-11 03:02 - 00001374 ____A C:\Windows\imsins.BAK
2013-06-12 03:03 - 2005-11-10 16:21 - 73381792 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-12 03:02 - 2011-06-17 13:06 - 00000000 ____D C:\Windows\ie8updates
2013-05-28 19:30 - 2005-08-23 14:53 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-05-27 11:53 - 2011-10-12 21:50 - 00002497 ____A C:\Documents and Settings\Tyler\Desktop\Microsoft Office Word 2003.lnk
2013-05-27 10:44 - 2013-05-27 10:44 - 00000278 ____A C:\Documents and Settings\Tyler\Desktop\Shortcut to TaxReturn.lnk
2013-05-24 17:27 - 2013-03-23 20:18 - 00002418 ____A C:\Windows\wmsetup.log

Files to move or delete:
====================
C:\Windows\Tasks\At1.job
C:\Windows\Tasks\At2.job

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-06-2013
Ran by [removed] at 2013-06-20 19:23:45 Run:
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Adobe Flash Player 11 ActiveX (Version: 11.4.402.278)
Adobe Flash Player 11 Plugin (Version: 11.6.602.180)
Adobe Reader X (10.1.7) (Version: 10.1.7)
Apple Application Support (Version: 2.1.9)
Apple Mobile Device Support (Version: 5.2.0.6)
Apple Software Update (Version: 2.1.3.127)
avast! Free Antivirus (Version: 7.0.1426.0)
Bonjour (Version: 3.0.0.10)
CCleaner (Version: 3.28)
DealPly (remove only) (Version: 4.8.6.1)
File Type Assistant
Google Chrome (Version: 27.0.1453.116)
HiJackThis (Version: 1.0.0)
ImageMixer VCD2 (Version: 2.01.002.3)
InCD EasyWrite Reader
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet (Version: 6.05.2001)
iTunes (Version: 10.6.3.25)
Java 2 Runtime Environment, SE v1.4.2 (Version: 1.4.2)
Java 7 Update 17 (Version: 7.0.170)
Java Auto Updater (Version: 2.1.9.0)
Java(TM) 6 Update 27 (Version: 6.0.270)
Java(TM) SE Development Kit 7 (Version: 1.7.0.0)
JavaFX 2.0.3 (Version: 2.0.3)
Junk Mail filter update (Version: 14.0.8117.416)
Macromedia Shockwave Player (Version: 10.1.0.11)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2742597)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office Outlook Connector (Version: 12.0.6423.1000)
Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0)
Microsoft Office Publisher 2003 (Version: 11.0.8173.0)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Mozilla Firefox 19.0.2 (x86 en-US) (Version: 19.0.2)
Mozilla Maintenance Service (Version: 19.0.2)
MSVCRT (Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Multimedia Keyboard Driver
Nero BurnRights
Nero OEM
NETGEAR WNDA3100v2 wireless USB 2.0 adapter (Version: 1.03.000)
Open It! (Version: 1.1.1)
Picture Package (Version: 1.05.001)
POINT (Version: 3.06.134)
Point (Version: 5.0)
PowerDVD
QuickTime (Version: 7.72.80.56)
QuickTime 3.0
Reading Basics
Safari (Version: 5.34.57.2)
Segoe UI (Version: 14.0.4327.805)
Serif PhotoPlus 6.0 (Version: 6.00)
Soft Data Fax Modem with SmartCP
Sony USB Driver
SoundMAX (Version: 5.12.01.5240)
SpaceCowboy (Version: 0.3.3.55)
SpywareBlaster 4.6 (Version: 4.6.0)
Sygate Personal Firewall (Version: 5.6.2808)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Windows Internet Explorer 8 (KB2447568) (Version: 1)
Update for Windows Internet Explorer 8 (KB976662) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2492386) (Version: 1)
Update for Windows XP (KB2541763) (Version: 1)
Update for Windows XP (KB2607712) (Version: 1)
Update for Windows XP (KB2616676) (Version: 1)
Update for Windows XP (KB2641690) (Version: 1)
Update for Windows XP (KB2661254-v2) (Version: 2)
Update for Windows XP (KB2718704) (Version: 1)
Update for Windows XP (KB2736233) (Version: 1)
Update for Windows XP (KB2749655) (Version: 1)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB961503) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
Update for Zip Opener
WebFldrs XP (Version: 9.50.7523)
Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0)
Windows Internet Explorer 7 (Version: 20070813.185237)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Live Communications Platform (Version: 14.0.8117.416)
Windows Live Essentials (Version: 14.0.8117.0416)
Windows Live Essentials (Version: 14.0.8117.416)
Windows Live Family Safety (Version: 14.0.8118.427)
Windows Live Photo Gallery (Version: 14.0.8117.416)
Windows Live Sign-in Assistant (Version: 5.000.818.5)
Windows Live Sync (Version: 14.0.8117.416)
Windows Live Upload Tool (Version: 14.0.8014.1029)
Windows Live Writer (Version: 14.0.8117.0416)
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0 (Version: 04.00.6001.503)
Windows XP Service Pack 3 (Version: 20080414.031525)
Yahoo! Toolbar
Zip Opener Packages

==================== Restore Points  =========================

31-03-2013 23:33:14 Software Distribution Service 3.0
01-04-2013 23:57:23 System Checkpoint
02-04-2013 08:00:23 Software Distribution Service 3.0
03-04-2013 08:00:25 Software Distribution Service 3.0
04-04-2013 08:00:27 Software Distribution Service 3.0
05-04-2013 08:00:27 Software Distribution Service 3.0
06-04-2013 08:00:27 Software Distribution Service 3.0
07-04-2013 08:00:30 Software Distribution Service 3.0
08-04-2013 08:00:26 Software Distribution Service 3.0
09-04-2013 01:28:21 Software Distribution Service 3.0
09-04-2013 08:00:21 Software Distribution Service 3.0
10-04-2013 08:01:07 Software Distribution Service 3.0
11-04-2013 08:00:47 Software Distribution Service 3.0
12-04-2013 08:00:23 Software Distribution Service 3.0
13-04-2013 08:00:22 Software Distribution Service 3.0
14-04-2013 08:00:24 Software Distribution Service 3.0
15-04-2013 08:00:28 Software Distribution Service 3.0
16-04-2013 08:00:31 Software Distribution Service 3.0
17-04-2013 08:00:35 Software Distribution Service 3.0
18-04-2013 08:00:30 Software Distribution Service 3.0
19-04-2013 08:00:23 Software Distribution Service 3.0
20-04-2013 08:00:25 Software Distribution Service 3.0
21-04-2013 08:00:27 Software Distribution Service 3.0
22-04-2013 08:00:25 Software Distribution Service 3.0
23-04-2013 08:00:26 Software Distribution Service 3.0
24-04-2013 08:00:27 Software Distribution Service 3.0
25-04-2013 08:00:30 Software Distribution Service 3.0
26-04-2013 08:00:23 Software Distribution Service 3.0
27-04-2013 08:00:29 Software Distribution Service 3.0
28-04-2013 08:00:25 Software Distribution Service 3.0
29-04-2013 08:00:27 Software Distribution Service 3.0
30-04-2013 08:00:29 Software Distribution Service 3.0
01-05-2013 08:00:26 Software Distribution Service 3.0
02-05-2013 08:00:23 Software Distribution Service 3.0
03-05-2013 08:00:28 Software Distribution Service 3.0
04-05-2013 08:00:22 Software Distribution Service 3.0
05-05-2013 08:00:20 Software Distribution Service 3.0
05-05-2013 20:01:54 Software Distribution Service 3.0
06-05-2013 08:00:23 Software Distribution Service 3.0
07-05-2013 08:00:25 Software Distribution Service 3.0
08-05-2013 08:00:24 Software Distribution Service 3.0
09-05-2013 08:00:25 Software Distribution Service 3.0
10-05-2013 08:00:25 Software Distribution Service 3.0
10-05-2013 23:14:05 Software Distribution Service 3.0
11-05-2013 00:04:34 Software Distribution Service 3.0
12-05-2013 00:41:37 System Checkpoint
12-05-2013 08:00:25 Software Distribution Service 3.0
13-05-2013 08:00:25 Software Distribution Service 3.0
14-05-2013 08:00:23 Software Distribution Service 3.0
15-05-2013 08:00:50 Software Distribution Service 3.0
16-05-2013 08:00:25 Software Distribution Service 3.0
17-05-2013 08:00:22 Software Distribution Service 3.0
18-05-2013 08:00:22 Software Distribution Service 3.0
19-05-2013 08:00:23 Software Distribution Service 3.0
20-05-2013 08:00:24 Software Distribution Service 3.0
21-05-2013 08:00:28 Software Distribution Service 3.0
22-05-2013 08:00:45 Software Distribution Service 3.0
23-05-2013 08:00:24 Software Distribution Service 3.0
24-05-2013 08:00:25 Software Distribution Service 3.0
25-05-2013 08:00:24 Software Distribution Service 3.0
26-05-2013 08:00:30 Software Distribution Service 3.0
27-05-2013 08:00:27 Software Distribution Service 3.0
28-05-2013 08:00:30 Software Distribution Service 3.0
29-05-2013 00:06:38 Software Distribution Service 3.0
29-05-2013 08:00:21 Software Distribution Service 3.0
30-05-2013 08:00:24 Software Distribution Service 3.0
31-05-2013 08:00:23 Software Distribution Service 3.0
01-06-2013 08:00:23 Software Distribution Service 3.0
02-06-2013 08:00:32 Software Distribution Service 3.0
03-06-2013 08:00:25 Software Distribution Service 3.0
04-06-2013 08:00:26 Software Distribution Service 3.0
05-06-2013 08:00:23 Software Distribution Service 3.0
06-06-2013 08:00:23 Software Distribution Service 3.0
07-06-2013 08:00:24 Software Distribution Service 3.0
08-06-2013 08:00:24 Software Distribution Service 3.0
09-06-2013 08:01:18 Software Distribution Service 3.0
10-06-2013 08:00:23 Software Distribution Service 3.0
11-06-2013 08:00:23 Software Distribution Service 3.0
12-06-2013 08:00:48 Software Distribution Service 3.0
13-06-2013 08:00:24 Software Distribution Service 3.0
14-06-2013 08:00:24 Software Distribution Service 3.0
15-06-2013 08:00:23 Software Distribution Service 3.0
16-06-2013 08:00:23 Software Distribution Service 3.0
17-06-2013 08:00:26 Software Distribution Service 3.0
18-06-2013 08:00:27 Software Distribution Service 3.0
19-06-2013 08:00:23 Software Distribution Service 3.0
20-06-2013 08:00:26 Software Distribution Service 3.0

==================== Faulty Device Manager Devices =============

Name: Video Controller (VGA Compatible)
Description: Video Controller (VGA Compatible)
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/20/2013 06:54:55 PM) (Source: crypt32) (User: )
Description: Failed extract of third-party root list from auto update cab at:  with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (06/20/2013 06:54:55 PM) (Source: crypt32) (User: )
Description: Failed extract of third-party root list from auto update cab at:  with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (06/20/2013 06:54:55 PM) (Source: crypt32) (User: )
Description: Failed extract of third-party root list from auto update cab at:  with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (06/20/2013 03:01:08 AM) (Source: HotFixInstaller) (User: )
Description: EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb2756918, P2 1033, P3 1605, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 visualstudio8setup0, P10 visualstudio8setup1.

Error: (06/19/2013 03:00:45 AM) (Source: HotFixInstaller) (User: )
Description: EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb2756918, P2 1033, P3 1605, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 visualstudio8setup0, P10 visualstudio8setup1.

Error: (06/18/2013 03:01:06 AM) (Source: HotFixInstaller) (User: )
Description: EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb2756918, P2 1033, P3 1605, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 visualstudio8setup0, P10 visualstudio8setup1.

Error: (06/17/2013 03:01:06 AM) (Source: HotFixInstaller) (User: )
Description: EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb2756918, P2 1033, P3 1605, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 visualstudio8setup0, P10 visualstudio8setup1.

Error: (06/16/2013 03:01:07 AM) (Source: HotFixInstaller) (User: )
Description: EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb2756918, P2 1033, P3 1605, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 visualstudio8setup0, P10 visualstudio8setup1.

Error: (06/15/2013 03:00:47 AM) (Source: HotFixInstaller) (User: )
Description: EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb2756918, P2 1033, P3 1605, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 visualstudio8setup0, P10 visualstudio8setup1.

Error: (06/14/2013 03:00:53 AM) (Source: HotFixInstaller) (User: )
Description: EventType visualstudio8setup, P1 microsoft .net framework 3.0-kb2756918, P2 1033, P3 1605, P4 msi, P5 f, P6 9.0.40215.0, P7 install, P8 x86, P9 visualstudio8setup0, P10 visualstudio8setup1.


System errors:
=============
Error: (06/20/2013 01:03:46 PM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.1.105 for the Network Card with network address 2CB05D6CD75C has been
denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

Error: (06/20/2013 03:05:40 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).

Error: (06/19/2013 03:02:11 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).

Error: (06/18/2013 03:06:44 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).

Error: (06/17/2013 03:05:14 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).

Error: (06/16/2013 03:03:45 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).

Error: (06/15/2013 03:03:04 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).

Error: (06/14/2013 03:03:06 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).

Error: (06/13/2013 03:02:27 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).

Error: (06/12/2013 03:14:42 AM) (Source: Windows Update Agent) (User: )
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 3.0 SP2 on Windows Server 2003 and Windows XP x86 (KB2756918).


Microsoft Office Sessions:
=========================
Error: (06/20/2013 06:54:55 PM) (Source: crypt32)(User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (06/20/2013 06:54:55 PM) (Source: crypt32)(User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (06/20/2013 06:54:55 PM) (Source: crypt32)(User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (06/20/2013 03:01:08 AM) (Source: HotFixInstaller)(User: )
Description: visualstudio8setupmicrosoft .net framework 3.0-kb275691810331605msif9.0.40215.0installx86xp0

Error: (06/19/2013 03:00:45 AM) (Source: HotFixInstaller)(User: )
Description: visualstudio8setupmicrosoft .net framework 3.0-kb275691810331605msif9.0.40215.0installx86xp0

Error: (06/18/2013 03:01:06 AM) (Source: HotFixInstaller)(User: )
Description: visualstudio8setupmicrosoft .net framework 3.0-kb275691810331605msif9.0.40215.0installx86xp0

Error: (06/17/2013 03:01:06 AM) (Source: HotFixInstaller)(User: )
Description: visualstudio8setupmicrosoft .net framework 3.0-kb275691810331605msif9.0.40215.0installx86xp0

Error: (06/16/2013 03:01:07 AM) (Source: HotFixInstaller)(User: )
Description: visualstudio8setupmicrosoft .net framework 3.0-kb275691810331605msif9.0.40215.0installx86xp0

Error: (06/15/2013 03:00:47 AM) (Source: HotFixInstaller)(User: )
Description: visualstudio8setupmicrosoft .net framework 3.0-kb275691810331605msif9.0.40215.0installx86xp0

Error: (06/14/2013 03:00:53 AM) (Source: HotFixInstaller)(User: )
Description: visualstudio8setupmicrosoft .net framework 3.0-kb275691810331605msif9.0.40215.0installx86xp0


==================== Memory info =========================== 

Percentage of memory in use: 71%
Total physical RAM: 494.73 MB
Available physical RAM: 140.3 MB
Total Pagefile: 1357.57 MB
Available Pagefile: 683.21 MB
Total Virtual: 2047.88 MB
Available Virtual: 1943.72 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:145.89 GB) (Free:75.66 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:3.14 GB) (Free:2.56 GB) FAT32
Drive f: () (Removable) (Total:3.74 GB) (Free:0 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 149 GB) (Disk ID: CBA1B13A)
Partition 1: (Active) - (Size=146 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=3 GB) - (Type=0B)

========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)

==================== End Of Log ============================
Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.
Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-***.txt . Please attach that to your next reply.
That was the wrong one! You'll find the log in that mbar folder as MBAR-log-***.txt . Please attach that to your next reply.
Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.




Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications


====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Looks good til here!


Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI