<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Safer-Networking Forums - Archives</title>
		<link>http://forums.spybot.info/</link>
		<description>Archived malware topics.
READ ONLY</description>
		<language>en</language>
		<lastBuildDate>Wed, 16 May 2012 14:43:39 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.spybot.info/images/misc/rss.jpg</url>
			<title>Safer-Networking Forums - Archives</title>
			<link>http://forums.spybot.info/</link>
		</image>
		<item>
			<title>Removal of IDP.Trojan.1C8D1A13 and Trojan horse crypt.AQLW</title>
			<link>http://forums.spybot.info/showthread.php?t=65862&amp;goto=newpost</link>
			<pubDate>Tue, 08 May 2012 20:36:34 GMT</pubDate>
			<description>Hi 
 
I have an optiplex 990 infected with both IDP.Trojan.1C8D1A13 and Trojan horse crypt.AQLW.  Smart Fortress 2012 was initially found yesterday...</description>
			<content:encoded><![CDATA[<div>Hi<br />
<br />
I have an optiplex 990 infected with both IDP.Trojan.1C8D1A13 and Trojan horse crypt.AQLW.  Smart Fortress 2012 was initially found yesterday (5/7/12) and Malwarebytes appears to have removed that.  AVG detected the two threats mentioned above but cannot do anything about them.<br />
<br />
Can you please help with the steps for removal of these two infections?  I am open to doing a step by step restore if that's a possibility.  Layman terms please.<br />
<br />
Thanks for help!<br />
Heather</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>hns2700</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65862</guid>
		</item>
		<item>
			<title>Browser Redirect Problems</title>
			<link>http://forums.spybot.info/showthread.php?t=65840&amp;goto=newpost</link>
			<pubDate>Sat, 05 May 2012 01:02:09 GMT</pubDate>
			<description>I am trying to help out my sister-in-law with a problem she is having with her laptop.  In Internet Explorer, she is getting redirected to websites...</description>
			<content:encoded><![CDATA[<div>I am trying to help out my sister-in-law with a problem she is having with her laptop.  In Internet Explorer, she is getting redirected to websites she does not want to be going to.  I have run a scan of the computer, but it is not coming up with any viruses, and can use some help. Below is the DDS report.<br />
<br />
Thank you!<br />
<br />
Jon<br />
<br />
<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.7600.16385<br />
Run by Amy at 20:53:06 on 2012-05-04<br />
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.1.1033.18.3891.2245 [GMT -4:00]<br />
.<br />
AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}<br />
FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\windows\system32\wininit.exe<br />
C:\windows\system32\lsm.exe<br />
C:\windows\system32\svchost.exe -k DcomLaunch<br />
C:\windows\system32\svchost.exe -k RPCSS<br />
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\windows\system32\svchost.exe -k netsvcs<br />
C:\windows\system32\svchost.exe -k LocalService<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe<br />
C:\windows\system32\Dwm.exe<br />
C:\windows\Explorer.EXE<br />
C:\windows\system32\svchost.exe -k NetworkService<br />
C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\windows\system32\WLANExt.exe<br />
C:\windows\system32\conhost.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\windows\System32\spoolsv.exe<br />
C:\windows\system32\taskhost.exe<br />
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\System32\ThpSrv.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe<br />
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe<br />
C:\windows\system32\ThpSrv.exe<br />
C:\Windows\system32\TODDSrv.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
C:\Program Files\TOSHIBA\TECO\TecoService.exe<br />
C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe<br />
C:\windows\system32\SearchIndexer.exe<br />
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe<br />
C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe<br />
C:\Program Files\TOSHIBA\TECO\Teco.exe<br />
C:\windows\system32\wbem\unsecapp.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe<br />
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe<br />
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe<br />
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe<br />
C:\Program Files\TOSHIBA\FlashCards\Hotkey\TcrdKBB.exe<br />
C:\windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE<br />
C:\windows\system32\igfxext.exe<br />
C:\windows\system32\wbem\unsecapp.exe<br />
C:\windows\system32\igfxsrvc.exe<br />
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\windows\SysWOW64\rundll32.exe<br />
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe<br />
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe<br />
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe<br />
C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe<br />
C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe<br />
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe<br />
C:\windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe<br />
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe<br />
C:\windows\system32\sppsvc.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe<br />
C:\windows\System32\svchost.exe -k secsvcs<br />
C:\windows\system32\SearchProtocolHost.exe<br />
C:\windows\system32\SearchFilterHost.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\windows\system32\SearchProtocolHost.exe<br />
C:\windows\SysWOW64\cmd.exe<br />
C:\windows\system32\conhost.exe<br />
C:\windows\SysWOW64\cscript.exe<br />
C:\windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://verizon.my.yahoo.com/<br />
uDefault_Page_URL = hxxp://www.google.com/ig?brand=TSND&amp;bmod=TSND<br />
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSND&amp;bmod=TSND<br />
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&amp;bmod=TSND<br />
uInternet Settings,ProxyOverride = &lt;local&gt;<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDHelper.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO: TOSHIBA Media Controller Plug-in: {f3c88694-effa-4d78-b409-54b7b2535b14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
uRun: [swg] &quot;C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
uRun: [Adobe] rundll32.exe &quot;C:\Users\Amy\AppData\Local\Apps\Adobe\mtshn.dll&quot;,DllRegisterServer<br />
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
mRun: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe<br />
mRun: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP<br />
mRun: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL<br />
mRun: [ToshibaServiceStation] &quot;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe&quot; /hide:60<br />
mRun: [TWebCamera] &quot;C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe&quot; autorun<br />
mRun: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe<br />
mRun: [Adobe Photo Downloader] &quot;C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe&quot;<br />
mRun: [ccApp] &quot;C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe&quot;<br />
StartupFolder: C:\Users\Amy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDHelper.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
TCP: DhcpNameServer = 192.168.1.1 68.237.161.12<br />
TCP: Interfaces\{9E92147B-E3BE-4B72-ACF2-646E3077C79B} : DhcpNameServer = 192.168.1.1 68.237.161.12<br />
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO-X64:     AcroIEHelperStub - No File<br />
BHO-X64: Spybot-S&amp;D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDHelper.dll<br />
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO-X64: TOSHIBA Media Controller Plug-in: {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll<br />
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
mRun-x64: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe<br />
mRun-x64: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP<br />
mRun-x64: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL<br />
mRun-x64: [ToshibaServiceStation] &quot;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe&quot; /hide:60<br />
mRun-x64: [TWebCamera] &quot;C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe&quot; autorun<br />
mRun-x64: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe<br />
mRun-x64: [Adobe Photo Downloader] &quot;C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe&quot;<br />
mRun-x64: [ccApp] &quot;C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe&quot;<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 PxHlpa64;PxHlpa64;C:\windows\system32\Drivers\PxHlpa64.sys --&gt; C:\windows\system32\Drivers\PxHlpa64.sys [?]<br />
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\windows\system32\DRIVERS\thpdrv.sys --&gt; C:\windows\system32\DRIVERS\thpdrv.sys [?]<br />
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\windows\system32\DRIVERS\Thpevm.SYS --&gt; C:\windows\system32\DRIVERS\Thpevm.SYS [?]<br />
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\system32\DRIVERS\tos_sps64.sys --&gt; C:\windows\system32\DRIVERS\tos_sps64.sys [?]<br />
R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --&gt; C:\windows\system32\DRIVERS\vwififlt.sys [?]<br />
R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2009-12-29 404992]<br />
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe [2012-4-29 1153368]<br />
R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2009-10-15 2477304]<br />
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-4-6 258928]<br />
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\system32\DRIVERS\TVALZFL.sys --&gt; C:\windows\system32\DRIVERS\TVALZFL.sys [?]<br />
R2 UNS;Intel(R) Management &amp; Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-9-6 2320920]<br />
R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2009-12-29 911360]<br />
R3 bpenum;bpenum;C:\windows\system32\DRIVERS\bpenum.sys --&gt; C:\windows\system32\DRIVERS\bpenum.sys [?]<br />
R3 bpmp;bpmp;C:\windows\system32\DRIVERS\bpmp.sys --&gt; C:\windows\system32\DRIVERS\bpmp.sys [?]<br />
R3 bpusb;bpusb;C:\windows\system32\Drivers\bpusb.sys --&gt; C:\windows\system32\Drivers\bpusb.sys [?]<br />
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-2-3 138360]<br />
R3 HECIx64;Intel(R) Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys --&gt; C:\windows\system32\DRIVERS\HECIx64.sys [?]<br />
R3 Impcd;Impcd;C:\windows\system32\DRIVERS\Impcd.sys --&gt; C:\windows\system32\DRIVERS\Impcd.sys [?]<br />
R3 IntcDAud;Intel(R) Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys --&gt; C:\windows\system32\DRIVERS\IntcDAud.sys [?]<br />
R3 JMCR;JMCR;C:\windows\system32\DRIVERS\jmcr.sys --&gt; C:\windows\system32\DRIVERS\jmcr.sys [?]<br />
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\windows\system32\DRIVERS\NETw5s64.sys --&gt; C:\windows\system32\DRIVERS\NETw5s64.sys [?]<br />
R3 PGEffect;Pangu effect driver;C:\windows\system32\DRIVERS\pgeffect.sys --&gt; C:\windows\system32\DRIVERS\pgeffect.sys [?]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --&gt; C:\windows\system32\DRIVERS\Rt64win7.sys [?]<br />
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-9-6 51512]<br />
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]<br />
R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-2-23 835952]<br />
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys --&gt; C:\windows\system32\DRIVERS\vwifimp.sys [?]<br />
R3 wdkmd;Intel WiDi KMD;C:\windows\system32\DRIVERS\WDKMD.sys --&gt; C:\windows\system32\DRIVERS\WDKMD.sys [?]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-29 136176]<br />
S3 acpials;ALS Sensor Filter;C:\windows\system32\DRIVERS\acpials.sys --&gt; C:\windows\system32\DRIVERS\acpials.sys [?]<br />
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-29 136176]<br />
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-3-5 340240]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --&gt; C:\windows\system32\Wat\WatAdminSvc.exe [?]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-05-05 00:33:33	8917360	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0F31EFB-147E-45E6-AA5E-62595071B770}\mpengine.dll<br />
2012-04-29 04:44:23	--------	d-----w-	C:\ProgramData\Spybot - Search &amp; Destroy<br />
2012-04-29 04:44:23	--------	d-----w-	C:\Program Files (x86)\Spybot - Search &amp; Destroy<br />
2012-04-29 02:38:56	8917360	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll<br />
2012-04-29 01:52:59	16294328	----a-w-	C:\Users\Amy\Windows-KB890830-x64-V4.7.exe<br />
2012-04-12 05:54:27	5504880	----a-w-	C:\windows\System32\ntoskrnl.exe<br />
2012-04-12 05:54:26	3958128	----a-w-	C:\windows\SysWow64\ntkrnlpa.exe<br />
2012-04-12 05:54:25	3902320	----a-w-	C:\windows\SysWow64\ntoskrnl.exe<br />
2012-04-12 05:53:56	22896	----a-w-	C:\windows\System32\drivers\fs_rec.sys<br />
2012-04-12 05:53:55	80896	----a-w-	C:\windows\System32\imagehlp.dll<br />
2012-04-12 05:53:55	158720	----a-w-	C:\windows\SysWow64\imagehlp.dll<br />
2012-04-12 05:53:54	5120	----a-w-	C:\windows\SysWow64\wmi.dll<br />
2012-04-12 05:53:54	5120	----a-w-	C:\windows\System32\wmi.dll<br />
2012-04-12 05:53:54	220672	----a-w-	C:\windows\System32\wintrust.dll<br />
2012-04-12 05:53:54	172544	----a-w-	C:\windows\SysWow64\wintrust.dll<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-02-28 06:35:54	1197568	----a-w-	C:\windows\System32\wininet.dll<br />
2012-02-28 06:33:03	57856	----a-w-	C:\windows\System32\licmgr10.dll<br />
2012-02-28 05:40:21	981504	----a-w-	C:\windows\SysWow64\wininet.dll<br />
2012-02-28 05:38:16	44544	----a-w-	C:\windows\SysWow64\licmgr10.dll<br />
2012-02-28 05:17:41	482816	----a-w-	C:\windows\System32\html.iec<br />
2012-02-28 04:35:01	1638912	----a-w-	C:\windows\System32\mshtml.tlb<br />
2012-02-28 04:31:46	386048	----a-w-	C:\windows\SysWow64\html.iec<br />
2012-02-28 03:57:55	1638912	----a-w-	C:\windows\SysWow64\mshtml.tlb<br />
2012-02-23 14:18:36	279656	------w-	C:\windows\System32\MpSigStub.exe<br />
2012-02-15 06:27:54	1031680	----a-w-	C:\windows\System32\rdpcore.dll<br />
2012-02-15 05:44:57	826368	----a-w-	C:\windows\SysWow64\rdpcore.dll<br />
2012-02-15 04:47:21	204800	----a-w-	C:\windows\System32\drivers\rdpwd.sys<br />
2012-02-15 04:46:59	23552	----a-w-	C:\windows\System32\drivers\tdtcp.sys<br />
2012-02-10 06:18:10	1541120	----a-w-	C:\windows\System32\DWrite.dll<br />
2012-02-10 06:17:55	1837568	----a-w-	C:\windows\System32\d3d10warp.dll<br />
2012-02-10 06:17:54	902656	----a-w-	C:\windows\System32\d2d1.dll<br />
2012-02-10 06:17:54	320512	----a-w-	C:\windows\System32\d3d10_1core.dll<br />
2012-02-10 06:17:54	197120	----a-w-	C:\windows\System32\d3d10_1.dll<br />
2012-02-10 05:41:38	1074176	----a-w-	C:\windows\SysWow64\DWrite.dll<br />
2012-02-10 05:41:20	218624	----a-w-	C:\windows\SysWow64\d3d10_1core.dll<br />
2012-02-10 05:41:20	161792	----a-w-	C:\windows\SysWow64\d3d10_1.dll<br />
2012-02-10 05:41:20	1170944	----a-w-	C:\windows\SysWow64\d3d10warp.dll<br />
2012-02-10 05:41:19	739840	----a-w-	C:\windows\SysWow64\d2d1.dll<br />
.<br />
============= FINISH: 20:53:51.89 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9495&amp;d=1336179494">Attach.zip</a> (2.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>deplanche</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65840</guid>
		</item>
		<item>
			<title><![CDATA[Win32.Agent.adb won't disappear]]></title>
			<link>http://forums.spybot.info/showthread.php?t=65837&amp;goto=newpost</link>
			<pubDate>Fri, 04 May 2012 08:09:21 GMT</pubDate>
			<description>Hi, 
My spybot has detected a trojan called win32.agent.adb. Even though spybot corrected it, the trojan appeared again after I did the second scan. ...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
My spybot has detected a trojan called win32.agent.adb. Even though spybot corrected it, the trojan appeared again after I did the second scan. <br />
I think this trojan might be the one responsible for this ---» ´´~~ and ^^ (duplication of accent marks)... :s<br />
<br />
Could you please help me with this issue?<br />
<br />
Thank you for your time and help! =) <br />
<br />
Here is the DDS report:<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 9.0.8112.16421<br />
Run by User at 9:00:04 on 2012-05-04<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.351.2070.18.8096.5598 [GMT 1:00]<br />
.<br />
AV: G Data InternetSecurity 2011 *Enabled/Updated* {54ACC2FC-837E-E665-7A92-5352D560D5EF}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
FW: G Data Personal Firewall *Enabled* {6C9743D9-C911-E73D-51CD-FA672BB39294}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\FBAgent.exe<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe<br />
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe<br />
C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\AsScrPro.exe<br />
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe<br />
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe<br />
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe<br />
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe<br />
C:\Program Files\P4G\BatteryLife.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe<br />
C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe<br />
C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe<br />
C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe<br />
C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlX64.exe<br />
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe<br />
C:\Windows\system32\svchost.exe -k bthsvcs<br />
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\ASUS.SYS\SIONExportService.exe<br />
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
C:\Program Files\Intel\TurboBoost\TurboBoost.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
C:\Windows\SysWOW64\ACEngSvr.exe<br />
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe<br />
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files (x86)\uTorrent\uTorrent.exe<br />
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe<br />
C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\servicing\TrustedInstaller.exe<br />
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe<br />
C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe<br />
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe<br />
C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe<br />
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe<br />
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe<br />
C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe<br />
C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe<br />
C:\Program Files (x86)\Common Files\G Data\AVKProxy\AvkBap64.exe<br />
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe<br />
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe<br />
C:\Windows\SysWOW64\NOTEPAD.EXE<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.pt/<br />
uDefault_Page_URL = hxxp://asus.msn.com<br />
mStart Page = hxxp://asus.msn.com<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: G Data WebFilter: {0124123d-61b4-456f-af86-78c53a0790c5} - C:\Program Files (x86)\G Data\InternetSecurity\WebFilter\AvkWebIE.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB: G Data WebFilter: {0124123d-61b4-456f-af86-78c53a0790c5} - C:\Program Files (x86)\G Data\InternetSecurity\WebFilter\AvkWebIE.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
uRun: [uTorrent] &quot;C:\Program Files (x86)\uTorrent\uTorrent.exe&quot;  /MINIMIZED<br />
uRun: [DAEMON Tools Lite] &quot;C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe&quot; -autorun<br />
uRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler<br />
uRun: [AdobeBridge] <br />
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
mRun: [Nuance PDF Reader-reminder] &quot;C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe&quot; -r &quot;C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini&quot;<br />
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S<br />
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe<br />
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe<br />
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe<br />
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe<br />
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe<br />
mRun: [RemoteControl10] &quot;C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe&quot;<br />
mRun: [UpdatePSTShortCut] &quot;C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files (x86)\Cyberlink\DVD Suite&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerStarter&quot;<br />
mRun: [UpdateLBPShortCut] &quot;C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files (x86)\CyberLink\LabelPrint&quot; UpdateWithCreateOnce &quot;Software\CyberLink\LabelPrint\2.5&quot;<br />
mRun: [UpdateP2GoShortCut] &quot;C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files (x86)\CyberLink\Power2Go&quot; UpdateWithCreateOnce &quot;SOFTWARE\CyberLink\Power2Go\6.0&quot;<br />
mRun: [GrooveMonitor] &quot;C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
mRun: [G Data AntiVirus Tray Application] C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe<br />
mRun: [GDFirewallTray] C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe<br />
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br />
mRun: [AdobeCS5ServiceManager] &quot;C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe&quot; -launchedbylogin<br />
StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE<br />
StartupFolder: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOS~2.EXE<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)<br />
IE: E&amp;xportar para o Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll<br />
TCP: DhcpNameServer = 213.13.175.65 212.55.154.174 212.55.154.190<br />
TCP: Interfaces\{6C69B304-E3A8-4A52-BFDB-01262BE32BDF} : DhcpNameServer = 213.13.175.65 212.55.154.174 212.55.154.190<br />
TCP: Interfaces\{6C69B304-E3A8-4A52-BFDB-01262BE32BDF}\079647164616 : DhcpNameServer = 192.168.1.254<br />
TCP: Interfaces\{6C69B304-E3A8-4A52-BFDB-01262BE32BDF}\4586F6D637F6E6244423446383 : DhcpNameServer = 192.168.1.254 192.168.1.254<br />
TCP: Interfaces\{6C69B304-E3A8-4A52-BFDB-01262BE32BDF}\56465727F616D6 : DhcpNameServer = 193.137.16.65 193.137.16.145 193.137.16.75<br />
TCP: Interfaces\{6C69B304-E3A8-4A52-BFDB-01262BE32BDF}\C464D265F646 : DhcpNameServer = 192.168.25.2<br />
TCP: Interfaces\{94A59F7C-B91E-44A0-8A1B-28CABCA82446} : DhcpNameServer = 192.168.25.2<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
{0124123D-61B4-456f-AF86-78C53A0790C5}<br />
{53707962-6F74-2D53-2644-206D7942484F}<br />
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}<br />
{9030D464-4C02-4ABF-8ECC-5164760863C6}<br />
{AA58ED58-01DD-4d91-8333-CF10577473F7}<br />
{0124123D-61B4-456f-AF86-78C53A0790C5}<br />
{2318C2B1-4965-11d4-9B18-009027A5CD4F}<br />
mRun-x64: [Nuance PDF Reader-reminder] &quot;C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe&quot; -r &quot;C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini&quot;<br />
mRun-x64: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S<br />
mRun-x64: [SonicMasterTray] C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe<br />
mRun-x64: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe<br />
mRun-x64: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe<br />
mRun-x64: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe<br />
mRun-x64: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe<br />
mRun-x64: [RemoteControl10] &quot;C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe&quot;<br />
mRun-x64: [UpdatePSTShortCut] &quot;C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files (x86)\Cyberlink\DVD Suite&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerStarter&quot;<br />
mRun-x64: [UpdateLBPShortCut] &quot;C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files (x86)\CyberLink\LabelPrint&quot; UpdateWithCreateOnce &quot;Software\CyberLink\LabelPrint\2.5&quot;<br />
mRun-x64: [UpdateP2GoShortCut] &quot;C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe&quot; &quot;C:\Program Files (x86)\CyberLink\Power2Go&quot; UpdateWithCreateOnce &quot;SOFTWARE\CyberLink\Power2Go\6.0&quot;<br />
mRun-x64: [GrooveMonitor] &quot;C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
mRun-x64: [G Data AntiVirus Tray Application] C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe<br />
mRun-x64: [GDFirewallTray] C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe<br />
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br />
mRun-x64: [AdobeCS5ServiceManager] &quot;C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe&quot; -launchedbylogin<br />
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll<br />
SEH-X64: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}: Groove GFS Stub Execution Hook<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 GDBehave;GDBehave;C:\Windows\system32\drivers\GDBehave.sys --&gt; C:\Windows\system32\drivers\GDBehave.sys [?]<br />
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --&gt; C:\Windows\system32\DRIVERS\nvpciflt.sys [?]<br />
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-5-26 17536]<br />
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --&gt; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]<br />
R1 GDMnIcpt;GDMnIcpt;\??\C:\Windows\system32\drivers\MiniIcpt.sys --&gt; C:\Windows\system32\drivers\MiniIcpt.sys [?]<br />
R1 gdwfpcd;G DATA WFP CD;C:\Windows\system32\drivers\gdwfpcd64.sys --&gt; C:\Windows\system32\drivers\gdwfpcd64.sys [?]<br />
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --&gt; C:\Windows\system32\DRIVERS\vwififlt.sys [?]<br />
R2 AFBAgent;AFBAgent;&quot;C:\Windows\system32\FBAgent.exe&quot; --&gt; C:\Windows\system32\FBAgent.exe [?]<br />
R2 AMPPALR3;Intel® Centrino® Bluetooth 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-4-21 1136640]<br />
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]<br />
R2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe [2011-7-8 88704]<br />
R2 AVKProxy;Proxy do G Data AntiVírus;C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2010-8-10 1072200]<br />
R2 AVKService;G Data Scheduler;C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [2010-8-10 410696]<br />
R2 AVKWCtl;G Data Sentinela do sistema de ficheiros;C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlX64.exe [2010-3-15 1778336]<br />
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-3-30 923984]<br />
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-3-30 1001808]<br />
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-4-21 134928]<br />
R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-1-14 1839616]<br />
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2012-4-12 1997416]<br />
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe [2012-5-3 1153368]<br />
R2 Splashtop MDES;Splashtop Meta Data Export Service;C:\ASUS.SYS\SIONExportService.exe [2011-5-10 338208]<br />
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-5-27 378472]<br />
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --&gt; C:\Windows\system32\DRIVERS\TurboB.sys [?]<br />
R2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-4-17 134928]<br />
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-4-12 2655768]<br />
R3 AiCharger;ASUS Charger Driver;C:\Windows\system32\DRIVERS\AiCharger.sys --&gt; C:\Windows\system32\DRIVERS\AiCharger.sys [?]<br />
R3 AMPPAL;Intel(R) Centrino(R) Bluetooth 3.0 + High Speed Virtual Adapter;C:\Windows\system32\DRIVERS\AMPPAL.sys --&gt; C:\Windows\system32\DRIVERS\AMPPAL.sys [?]<br />
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\system32\DRIVERS\asmthub3.sys --&gt; C:\Windows\system32\DRIVERS\asmthub3.sys [?]<br />
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\system32\DRIVERS\asmtxhci.sys --&gt; C:\Windows\system32\DRIVERS\asmtxhci.sys [?]<br />
R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-3-30 1321296]<br />
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\system32\DRIVERS\btmaux.sys --&gt; C:\Windows\system32\DRIVERS\btmaux.sys [?]<br />
R3 btmhsf;btmhsf;C:\Windows\system32\DRIVERS\btmhsf.sys --&gt; C:\Windows\system32\DRIVERS\btmhsf.sys [?]<br />
R3 GDFwSvc;G Data Personal Firewall;C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2010-4-16 1666096]<br />
R3 GDPkIcpt;GDPkIcpt;\??\C:\Windows\system32\drivers\PktIcpt.sys --&gt; C:\Windows\system32\drivers\PktIcpt.sys [?]<br />
R3 GDScan;G Data Scanner;C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [2010-4-22 339016]<br />
R3 HookCentre;HookCentre;\??\C:\Windows\system32\drivers\HookCentre.sys --&gt; C:\Windows\system32\drivers\HookCentre.sys [?]<br />
R3 iBtFltCoex;iBtFltCoex;C:\Windows\system32\DRIVERS\iBtFltCoex.sys --&gt; C:\Windows\system32\DRIVERS\iBtFltCoex.sys [?]<br />
R3 iwdbus;IWD Bus Enumerator;C:\Windows\system32\DRIVERS\iwdbus.sys --&gt; C:\Windows\system32\DRIVERS\iwdbus.sys [?]<br />
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --&gt; C:\Windows\system32\DRIVERS\L1C62x64.sys [?]<br />
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --&gt; C:\Windows\system32\DRIVERS\HECIx64.sys [?]<br />
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --&gt; C:\Windows\system32\DRIVERS\NETwNs64.sys [?]<br />
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --&gt; C:\Windows\system32\DRIVERS\vwifimp.sys [?]<br />
R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys --&gt; C:\Windows\system32\DRIVERS\WDKMD.sys [?]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 gupdate;Serviço Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-5-3 136176]<br />
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-16 253088]<br />
S3 AMPPALP;Intel(R) Centrino(R) Bluetooth 3.0 + High Speed Protocol;C:\Windows\system32\DRIVERS\amppal.sys --&gt; C:\Windows\system32\DRIVERS\amppal.sys [?]<br />
S3 AmUStor;AM USB Stroage Driver;C:\Windows\system32\drivers\AmUStor.SYS --&gt; C:\Windows\system32\drivers\AmUStor.SYS [?]<br />
S3 cphs;Intel(R) Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-2-14 276248]<br />
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-8-7 3276800]<br />
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --&gt; C:\Windows\system32\DRIVERS\fssfltr.sys [?]<br />
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]<br />
S3 gupdatem;Serviço Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-5-3 136176]<br />
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\system32\drivers\intelaud.sys --&gt; C:\Windows\system32\drivers\intelaud.sys [?]<br />
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-5-2 340240]<br />
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --&gt; C:\Windows\system32\drivers\nvhda64v.sys [?]<br />
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSG664.sys --&gt; C:\Windows\system32\DRIVERS\SiSG664.sys [?]<br />
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]<br />
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --&gt; C:\Windows\system32\drivers\tsusbflt.sys [?]<br />
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --&gt; C:\Windows\system32\drivers\TsUsbGD.sys [?]<br />
S3 WatAdminSvc;Serviço de Tecnologias de Activação do Windows;C:\Windows\system32\Wat\WatAdminSvc.exe --&gt; C:\Windows\system32\Wat\WatAdminSvc.exe [?]<br />
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-05-03 17:25:48	--------	d-----w-	C:\Program Files\CCleaner<br />
2012-05-03 17:25:31	--------	d-----w-	C:\Users\User\AppData\Local\Google<br />
2012-05-03 13:26:33	--------	d-----w-	C:\Users\User\AppData\Roaming\Malwarebytes<br />
2012-05-03 13:26:30	38224	----a-w-	C:\Windows\SysWow64\drivers\mbamswissarmy.sys<br />
2012-05-03 13:26:29	--------	d-----w-	C:\ProgramData\Malwarebytes<br />
2012-05-03 13:26:28	22104	----a-w-	C:\Windows\System32\drivers\mbam.sys<br />
2012-05-03 13:26:28	--------	d-----w-	C:\Program Files (x86)\Malwarebytes' Anti-Malware<br />
2012-05-03 13:06:15	--------	d-----w-	C:\ProgramData\Spybot - Search &amp; Destroy<br />
2012-05-03 13:06:15	--------	d-----w-	C:\Program Files (x86)\Spybot - Search &amp; Destroy<br />
2012-05-03 11:30:05	--------	d-----w-	C:\Users\User\AppData\Local\G DATA<br />
2012-05-02 20:55:03	--------	d-----w-	C:\Users\User\AppData\Local\Windows Live<br />
2012-05-02 20:54:45	--------	d-----w-	C:\Users\User\AppData\Local\{FCE76A81-D966-4E2A-BEDE-21970D98B724}<br />
2012-05-02 08:06:30	16200	----a-w-	C:\Windows\stinger.sys<br />
2012-05-02 08:06:13	--------	d-----w-	C:\Program Files (x86)\stinger<br />
2012-05-01 21:00:29	8917360	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EDF11637-ED57-44F5-957B-F99F04341B73}\mpengine.dll<br />
2012-05-01 11:39:11	--------	d-----w-	C:\Users\User\AppData\Roaming\dclogs<br />
2012-05-01 11:39:06	1097728	----a-w-	C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOS~2.EXE<br />
2012-05-01 11:06:42	--------	d-----w-	C:\ProgramData\regid.1986-12.com.adobe<br />
2012-05-01 10:59:59	--------	d-----w-	C:\Users\User\AppData\Local\Adobe<br />
2012-04-26 16:47:33	--------	d-----w-	C:\Program Files (x86)\Satillana MIM<br />
2012-04-23 14:46:05	--------	d-----w-	C:\Users\User\AppData\Local\{F16823D5-E2C4-40BF-9C2B-A907C2D6BA7E}<br />
2012-04-23 14:46:05	--------	d-----w-	C:\Users\User\AppData\Local\{6773AA2D-EFE5-4BF6-8179-0E4A5190A62B}<br />
2012-04-23 14:02:02	--------	d-----w-	C:\Users\User\AppData\Local\Diagnostics<br />
2012-04-18 18:01:57	--------	d-----w-	C:\Program Files\WinPcap<br />
2012-04-18 18:01:50	3623592	----a-w-	C:\Program Files (x86)\Common Files\ApnToolbarInstaller.exe<br />
2012-04-18 18:01:50	143240	----a-w-	C:\Program Files (x86)\Common Files\ApnStub.exe<br />
2012-04-17 19:49:04	--------	d-----w-	C:\Program Files (x86)\Microsoft WSE<br />
2012-04-17 19:48:35	3977496	----a-w-	C:\Windows\System32\d3dx9_31.dll<br />
2012-04-17 19:48:35	2414360	----a-w-	C:\Windows\SysWow64\d3dx9_31.dll<br />
2012-04-17 19:41:02	283200	----a-w-	C:\Windows\System32\drivers\dtsoftbus01.sys<br />
2012-04-17 19:40:59	--------	d-----w-	C:\Users\User\AppData\Roaming\DAEMON Tools Lite<br />
2012-04-17 19:40:59	--------	d-----w-	C:\Program Files (x86)\DAEMON Tools Lite<br />
2012-04-17 19:40:16	--------	d-----w-	C:\ProgramData\DAEMON Tools Lite<br />
2012-04-17 18:10:34	98816	----a-w-	C:\Windows\System32\drivers\usbccgp.sys<br />
2012-04-17 18:10:34	7936	----a-w-	C:\Windows\System32\drivers\usbd.sys<br />
2012-04-17 18:10:34	52736	----a-w-	C:\Windows\System32\drivers\usbehci.sys<br />
2012-04-17 18:10:34	343040	----a-w-	C:\Windows\System32\drivers\usbhub.sys<br />
2012-04-17 18:10:34	325120	----a-w-	C:\Windows\System32\drivers\usbport.sys<br />
2012-04-17 18:10:34	30720	----a-w-	C:\Windows\System32\drivers\usbuhci.sys<br />
2012-04-17 18:10:34	25600	----a-w-	C:\Windows\System32\drivers\usbohci.sys<br />
2012-04-17 18:06:22	80384	----a-w-	C:\Windows\System32\drivers\BTHUSB.SYS<br />
2012-04-17 18:06:22	552960	----a-w-	C:\Windows\System32\drivers\bthport.sys<br />
2012-04-17 17:23:33	--------	d-----w-	C:\ProgramData\ASUS<br />
2012-04-17 17:18:56	--------	d-----w-	C:\Users\User\AppData\Local\{375F6513-C406-4855-BBF5-AE473559B0EB}<br />
2012-04-17 17:16:48	--------	d-----w-	C:\Users\User\AppData\Roaming\MAGIX<br />
2012-04-17 15:32:09	--------	d-----w-	C:\Users\User\AppData\Local\Cyberlink<br />
2012-04-17 14:27:10	--------	d-----w-	C:\Users\User\AppData\Roaming\Princess Isabella<br />
2012-04-17 10:27:25	--------	d-----w-	C:\Windows\SysWow64\Wat<br />
2012-04-17 10:27:25	--------	d-----w-	C:\Windows\System32\Wat<br />
2012-04-17 10:17:00	--------	d-----w-	C:\Program Files (x86)\MSXML 4.0<br />
2012-04-17 10:11:24	5559152	----a-w-	C:\Windows\System32\ntoskrnl.exe<br />
2012-04-17 10:11:24	3968368	----a-w-	C:\Windows\SysWow64\ntkrnlpa.exe<br />
2012-04-17 10:11:24	3913072	----a-w-	C:\Windows\SysWow64\ntoskrnl.exe<br />
2012-04-17 10:08:17	81408	----a-w-	C:\Windows\System32\imagehlp.dll<br />
2012-04-17 10:08:17	5120	----a-w-	C:\Windows\SysWow64\wmi.dll<br />
2012-04-17 10:08:17	5120	----a-w-	C:\Windows\System32\wmi.dll<br />
2012-04-17 10:08:17	23408	----a-w-	C:\Windows\System32\drivers\fs_rec.sys<br />
2012-04-17 10:08:17	220672	----a-w-	C:\Windows\System32\wintrust.dll<br />
2012-04-17 10:08:17	172544	----a-w-	C:\Windows\SysWow64\wintrust.dll<br />
2012-04-17 10:08:17	159232	----a-w-	C:\Windows\SysWow64\imagehlp.dll<br />
2012-04-17 09:31:59	3145728	----a-w-	C:\Windows\System32\win32k.sys<br />
2012-04-16 20:46:36	--------	d-----w-	C:\Program Files (x86)\uTorrent<br />
2012-04-16 20:45:34	--------	d-----w-	C:\Users\User\AppData\Roaming\uTorrent<br />
2012-04-16 20:43:54	9216	----a-w-	C:\Windows\System32\rdrmemptylst.exe<br />
2012-04-16 20:43:54	77312	----a-w-	C:\Windows\System32\rdpwsx.dll<br />
2012-04-16 20:43:54	149504	----a-w-	C:\Windows\System32\rdpcorekmts.dll<br />
2012-04-16 20:43:53	826880	----a-w-	C:\Windows\SysWow64\rdpcore.dll<br />
2012-04-16 20:43:53	23552	----a-w-	C:\Windows\System32\drivers\tdtcp.sys<br />
2012-04-16 20:43:53	210944	----a-w-	C:\Windows\System32\drivers\rdpwd.sys<br />
2012-04-16 20:43:53	1031680	----a-w-	C:\Windows\System32\rdpcore.dll<br />
2012-04-16 16:42:48	--------	d-----w-	C:\Users\User\AppData\Roaming\FLEXnet<br />
2012-04-16 16:42:46	--------	d-----w-	C:\Users\User\AppData\Roaming\Nuance<br />
2012-04-16 16:42:44	--------	d-----w-	C:\Users\User\AppData\Roaming\Zeon<br />
2012-04-16 13:00:38	279656	------w-	C:\Windows\System32\MpSigStub.exe<br />
2012-04-16 12:54:38	106224	----a-w-	C:\Windows\SysWow64\drivers\GRD.sys<br />
2012-04-16 12:38:00	40392	----a-w-	C:\Windows\System32\drivers\GDBehave.sys<br />
2012-04-16 12:37:59	57288	----a-w-	C:\Windows\System32\drivers\PktIcpt.sys<br />
2012-04-16 12:37:56	49096	----a-w-	C:\Windows\System32\drivers\HookCentre.sys<br />
2012-04-16 12:37:44	84936	----a-w-	C:\Windows\System32\drivers\MiniIcpt.sys<br />
2012-04-16 12:37:43	48584	----a-w-	C:\Windows\System32\drivers\gdwfpcd64.sys<br />
2012-04-16 12:37:35	--------	d-----w-	C:\ProgramData\G Data<br />
2012-04-16 12:37:35	--------	d-----w-	C:\Program Files (x86)\G Data<br />
2012-04-16 12:37:35	--------	d-----w-	C:\Program Files (x86)\Common Files\G Data<br />
2012-04-16 12:36:04	--------	d-----w-	C:\Users\User\AppData\Local\Downloaded Installations<br />
2012-04-16 12:00:32	--------	d-----w-	C:\Program Files (x86)\The KMPlayer<br />
2012-04-16 10:01:29	70304	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2012-04-16 10:01:29	418464	----a-w-	C:\Windows\SysWow64\FlashPlayerApp.exe<br />
2012-04-16 09:54:47	--------	d-----w-	C:\Program Files (x86)\Microsoft Visual Studio 8<br />
2012-04-16 09:54:30	--------	d-----w-	C:\Users\User\AppData\Local\Microsoft Help<br />
2012-04-16 09:49:03	--------	d-----w-	C:\Program Files (x86)\AVG<br />
2012-04-16 09:45:23	--------	d--h--w-	C:\ProgramData\Common Files<br />
2012-04-16 09:44:57	--------	d-----w-	C:\ProgramData\MFAData<br />
2012-04-16 01:36:27	--------	d-----w-	C:\Users\User\AppData\Roaming\ASUS WebStorage<br />
2012-04-16 01:34:00	--------	d-----w-	C:\Users\User\AppData\Local\Power2Go<br />
2012-04-16 01:32:13	--------	d-sh--we	C:\Programme<br />
2012-04-16 01:32:13	--------	d-sh--we	C:\ProgramData\Vorlagen<br />
2012-04-16 01:32:13	--------	d-sh--we	C:\ProgramData\Startmenü<br />
2012-04-16 01:32:13	--------	d-sh--we	C:\ProgramData\Favoriten<br />
2012-04-16 01:32:13	--------	d-sh--we	C:\ProgramData\Dokumente<br />
2012-04-16 01:32:13	--------	d-sh--we	C:\ProgramData\Anwendungsdaten<br />
2012-04-16 01:32:13	--------	d-sh--we	C:\Program Files\Gemeinsame Dateien<br />
2012-04-16 01:32:13	--------	d-sh--we	C:\Dokumente und Einstellungen<br />
2012-04-12 20:59:51	--------	d--h--w-	C:\ASUS.DAT<br />
2012-04-12 20:59:51	--------	d-----w-	C:\ProgramData\FolderView<br />
2012-04-12 20:05:03	--------	d-----w-	C:\eSupport<br />
2012-04-12 19:38:24	--------	d-----w-	C:\Windows\System32\AsMakeLink<br />
2012-04-12 19:38:23	80512	----a-w-	C:\Windows\AsusScr_N5_En Uninstaller.exe<br />
2012-04-12 19:38:19	3058304	----a-w-	C:\Windows\AsScrPro.exe<br />
2012-04-12 19:38:19	287176399	------w-	C:\Windows\System32\AsusScr_N5_En.scr<br />
2012-04-12 19:37:56	--------	d-----w-	C:\ProgramData\USBChargerPlus<br />
2012-04-12 19:37:54	45056	----a-w-	C:\Windows\System32\acovcnt.exe<br />
2012-04-12 19:36:22	16768	----a-w-	C:\Windows\System32\drivers\AiCharger.sys<br />
2012-04-12 19:35:06	499712	----a-w-	C:\Windows\SysWow64\msvcp71.dll<br />
2012-04-12 19:35:06	348160	----a-w-	C:\Windows\SysWow64\msvcr71.dll<br />
2012-04-12 19:35:06	29480	----a-w-	C:\Windows\SysWow64\msxml3a.dll<br />
2012-04-12 19:31:04	--------	d-----w-	C:\ProgramData\ASUS Music Maker<br />
2012-04-12 19:31:04	--------	d-----w-	C:\Program Files (x86)\ASUS Music Maker<br />
2012-04-12 19:30:59	--------	d-----w-	C:\ProgramData\MAGIX<br />
2012-04-12 19:30:58	--------	d-----w-	C:\Program Files (x86)\Common Files\MAGIX Services<br />
2012-04-12 19:30:27	--------	d--h--w-	C:\dvmexp<br />
2012-04-12 19:30:06	--------	d--h--w-	C:\ASUS.SYS<br />
2012-04-12 19:30:00	--------	d--h--w-	C:\temp<br />
2012-04-12 19:28:39	--------	d-----w-	C:\Program Files (x86)\Intel Corporation<br />
2012-04-12 19:28:39	--------	d-----w-	C:\Program Files (x86)\Common Files\Intel Corporation<br />
2012-04-12 19:24:11	--------	d-----w-	C:\ProgramData\Roaming<br />
2012-04-12 19:23:33	--------	d-----w-	C:\Program Files (x86)\Cisco<br />
2012-04-12 19:23:25	--------	d-----w-	C:\Program Files\Synaptics<br />
2012-04-12 19:21:47	--------	d-----w-	C:\Program Files (x86)\ASM104xUSB3<br />
2012-04-12 19:21:43	--------	d-----w-	C:\ProgramData\AmUStor<br />
2012-04-12 19:21:43	--------	d-----w-	C:\Program Files (x86)\AmIcoSingLun<br />
2012-04-12 19:21:08	--------	d-----w-	C:\ProgramData\SonicFocus<br />
2012-04-12 19:21:06	--------	d-----w-	C:\Windows\SysWow64\RTCOM<br />
2012-04-12 19:21:06	--------	d-----w-	C:\Program Files\Realtek<br />
2012-04-12 19:19:28	--------	d-----w-	C:\Windows\SysWow64\NV<br />
2012-04-12 19:19:28	--------	d-----w-	C:\Windows\System32\NV<br />
2012-04-12 19:15:40	--------	d-----w-	C:\Program Files\Common Files\Intel<br />
2012-04-12 19:15:40	--------	d-----w-	C:\Program Files (x86)\Common Files\Intel<br />
2012-04-12 19:14:27	8192	----a-w-	C:\Windows\SysWow64\drivers\IntelMEFWVer.dll<br />
2012-04-12 19:14:27	8192	----a-w-	C:\Windows\System32\drivers\IntelMEFWVer.dll<br />
2012-04-12 19:14:24	--------	d-----w-	C:\Program Files (x86)\Common Files\postureAgent<br />
2012-04-12 19:11:47	53248	----a-w-	C:\Windows\SysWow64\CSVer.dll<br />
2012-04-12 19:11:43	--------	d-----w-	C:\Intel<br />
2012-04-12 19:10:21	951680	----a-w-	C:\Windows\System32\drivers\ndis.sys<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-02-28 06:56:48	2311168	----a-w-	C:\Windows\System32\jscript9.dll<br />
2012-02-28 06:49:56	1390080	----a-w-	C:\Windows\System32\wininet.dll<br />
2012-02-28 06:48:57	1493504	----a-w-	C:\Windows\System32\inetcpl.cpl<br />
2012-02-28 06:42:55	2382848	----a-w-	C:\Windows\System32\mshtml.tlb<br />
2012-02-28 01:18:55	1799168	----a-w-	C:\Windows\SysWow64\jscript9.dll<br />
2012-02-28 01:11:21	1427456	----a-w-	C:\Windows\SysWow64\inetcpl.cpl<br />
2012-02-28 01:11:07	1127424	----a-w-	C:\Windows\SysWow64\wininet.dll<br />
2012-02-28 01:03:16	2382848	----a-w-	C:\Windows\SysWow64\mshtml.tlb<br />
2012-02-14 17:55:04	276248	----a-w-	C:\Windows\SysWow64\IntelCpHeciSvc.exe<br />
2012-02-14 17:55:02	5886232	----a-w-	C:\Windows\System32\GfxUI.exe<br />
2012-02-14 17:55:02	511768	----a-w-	C:\Windows\System32\igfxsrvc.exe<br />
2012-02-14 17:55:02	440600	----a-w-	C:\Windows\System32\igfxpers.exe<br />
2012-02-14 17:55:02	398616	----a-w-	C:\Windows\System32\hkcmd.exe<br />
2012-02-14 17:55:02	250136	----a-w-	C:\Windows\System32\igfxext.exe<br />
2012-02-14 17:55:02	184600	----a-w-	C:\Windows\System32\difx64.exe<br />
2012-02-14 17:55:02	170264	----a-w-	C:\Windows\System32\igfxtray.exe<br />
2012-02-14 17:53:26	90112	----a-w-	C:\Windows\System32\igfxCoIn_v2653.dll<br />
2012-02-14 17:47:40	8086528	----a-w-	C:\Windows\System32\igdumd64.dll<br />
2012-02-14 17:47:38	14692224	----a-w-	C:\Windows\System32\drivers\igdkmd64.sys<br />
2012-02-14 17:47:06	963912	----a-w-	C:\Windows\SysWow64\igkrng600.bin<br />
2012-02-14 17:47:06	963912	----a-w-	C:\Windows\System32\igkrng600.bin<br />
2012-02-14 17:47:06	79360	----a-w-	C:\Windows\System32\igdde64.dll<br />
2012-02-14 17:47:06	261208	----a-w-	C:\Windows\SysWow64\igfcg600m.bin<br />
2012-02-14 17:47:06	261208	----a-w-	C:\Windows\System32\igfcg600m.bin<br />
2012-02-14 17:44:54	6120960	----a-w-	C:\Windows\SysWow64\igdumd32.dll<br />
2012-02-14 17:44:24	58880	----a-w-	C:\Windows\SysWow64\igdde32.dll<br />
2012-02-14 17:42:58	9605632	----a-w-	C:\Windows\System32\igd10umd64.dll<br />
2012-02-14 17:35:26	7794688	----a-w-	C:\Windows\SysWow64\igd10umd32.dll<br />
2012-02-14 17:07:18	18125312	----a-w-	C:\Windows\System32\ig4icd64.dll<br />
2012-02-14 16:59:56	13209600	----a-w-	C:\Windows\SysWow64\ig4icd32.dll<br />
2012-02-14 16:56:42	110592	----a-w-	C:\Windows\System32\hccutils.dll<br />
2012-02-14 16:56:34	9216	----a-w-	C:\Windows\System32\IGFXDEVLib.dll<br />
2012-02-14 16:56:34	430080	----a-w-	C:\Windows\System32\igfxdev.dll<br />
2012-02-14 16:56:34	172032	----a-w-	C:\Windows\System32\gfxSrvc.dll<br />
2012-02-14 16:56:06	286208	----a-w-	C:\Windows\System32\igfxrenu.lrc<br />
2012-02-14 16:56:04	142336	----a-w-	C:\Windows\System32\igfxdo.dll<br />
2012-02-14 16:56:02	9007616	----a-w-	C:\Windows\System32\igfxress.dll<br />
2012-02-14 16:55:06	25088	----a-w-	C:\Windows\SysWow64\igfxexps32.dll<br />
2012-02-14 16:54:36	321024	----a-w-	C:\Windows\SysWow64\igfxdv32.dll<br />
2012-02-14 16:53:08	524800	----a-w-	C:\Windows\System32\iglhsip64.dll<br />
2012-02-14 16:53:08	519680	----a-w-	C:\Windows\SysWow64\iglhsip32.dll<br />
2012-02-14 16:53:08	2967040	----a-w-	C:\Windows\System32\igfxcmjit64.dll<br />
2012-02-14 16:53:08	237056	----a-w-	C:\Windows\SysWow64\igfxcmrt32.dll<br />
2012-02-14 16:53:08	2321408	----a-w-	C:\Windows\SysWow64\igfxcmjit32.dll<br />
2012-02-14 16:53:08	213504	----a-w-	C:\Windows\System32\iglhcp64.dll<br />
2012-02-14 16:53:08	193024	----a-w-	C:\Windows\System32\igfxcmrt64.dll<br />
2012-02-14 16:53:08	177152	----a-w-	C:\Windows\SysWow64\iglhcp32.dll<br />
2012-02-10 06:36:07	1544192	----a-w-	C:\Windows\System32\DWrite.dll<br />
2012-02-10 05:38:43	1077248	----a-w-	C:\Windows\SysWow64\DWrite.dll<br />
2012-02-07 10:02:40	1070352	----a-w-	C:\Windows\SysWow64\MSCOMCTL.OCX<br />
.<br />
============= FINISH:  9:01:06,15 ===============<br />
<br />
I've also attached the zip'ed attach report from DDS.<br />
<br />
Thank you for your time and help! =)</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9494&amp;d=1336118934">Attach report.zip</a> (2.8 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>Mar_Rib</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65837</guid>
		</item>
		<item>
			<title><![CDATA[Win32.Agent.adb won't disappear]]></title>
			<link>http://forums.spybot.info/showthread.php?t=65835&amp;goto=newpost</link>
			<pubDate>Thu, 03 May 2012 17:01:17 GMT</pubDate>
			<description>Hi, 
My spybot has detected a trojan called win32.agent.adb. Even though spybot corrected it, the trojan appeared again after I did the second scan. ...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
My spybot has detected a trojan called win32.agent.adb. Even though spybot corrected it, the trojan appeared again after I did the second scan. <br />
I think this trojan might be the one responsible for this ---»  ´´~~ and ^^ (duplication of accent marks)... :s<br />
<br />
Could you please help me with this issue?<br />
<br />
Thank you for your time and help! =)</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>Mar_Rib</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65835</guid>
		</item>
		<item>
			<title>I think I have a virus...plz help me!</title>
			<link>http://forums.spybot.info/showthread.php?t=65812&amp;goto=newpost</link>
			<pubDate>Tue, 01 May 2012 07:51:55 GMT</pubDate>
			<description><![CDATA[I've been getting blue screen errors and then I found this...>> Requested to remove devices controlled by the "FBIKB_NT" service. 
And then I found...]]></description>
			<content:encoded><![CDATA[<div>I've been getting blue screen errors and then I found this...&gt;&gt; Requested to remove devices controlled by the &quot;FBIKB_NT&quot; service.<br />
And then I found this...checksurlauncher,in a file password protected called....a030646fd05494d38d...I dn't knw if this is a virus or wot but the blue screen errors are happening mre often..any1 knw how 2 help me plz???</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>tracibaby</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65812</guid>
		</item>
		<item>
			<title>safesurf.exe keeps appearing and disappearing</title>
			<link>http://forums.spybot.info/showthread.php?t=65804&amp;goto=newpost</link>
			<pubDate>Mon, 30 Apr 2012 03:45:52 GMT</pubDate>
			<description>Hi. Recently, this trojan came to annoy me during my gaming time. I tried to remove it by using the task manager but it keeps coming back after a few...</description>
			<content:encoded><![CDATA[<div>Hi. Recently, this trojan came to annoy me during my gaming time. I tried to remove it by using the task manager but it keeps coming back after a few minutes. Right now, that thing keeps crashing and wants me to manually &quot;close&quot; it. A sort a popup message. It stills come back afterward. Anyway here's the DDS log.<br />
<br />
<b>DDS log</b><br />
----<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 8.0.7601.17514<br />
Run by Alex at 23:34:46 on 2012-04-29<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3070.1568 [GMT -4:00]<br />
.<br />
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}<br />
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}<br />
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}<br />
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\system32\atiesrxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\atieclxx.exe<br />
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\System32\svchost.exe -k Akamai<br />
C:\Windows\system32\svchost.exe -k apphost<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe<br />
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files\Alwil Software\Avast5\AvastUI.exe<br />
C:\Windows\system32\svchost.exe -k iissvcs<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\Microsoft Security Client\msseces.exe<br />
C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\chrome\chrome.exe<br />
C:\Program Files\DAEMON Tools Pro\DTAgent.exe<br />
C:\Users\Alex\AppData\Local\Akamai\netsession_win.exe<br />
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files\Logitech\SetPointG\SetPointII.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\system32\DllHost.exe<br />
C:\Program Files\Microsoft Security Client\MsMpEng.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Windows\system32\rundll32.exe<br />
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe<br />
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Windows\system32\taskmgr.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://google.ca/<br />
uInternet Settings,ProxyOverride = 127.0.0.1:9421;*.local;&lt;local&gt;<br />
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
{ae07101b-46d4-4a98-af68-0333ea26e113}<br />
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll<br />
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;c:\program files\common files\nero\lib\NMBgMonitor.exe&quot;<br />
uRun: [Google Update] &quot;c:\users\alex\appdata\local\google\update\GoogleUpdate.exe&quot; /c<br />
uRun: [Steam] &quot;c:\program files\valve\steam\steam.exe&quot; -silent<br />
uRun: [Akamai NetSession Interface] &quot;c:\users\alex\appdata\local\akamai\netsession_win.exe&quot;<br />
uRun: [PlayNC Launcher] <br />
uRun: [Facebook Update] &quot;c:\users\alex\appdata\local\facebook\update\FacebookUpdate.exe&quot; /c /nocrashserver<br />
uRun: [AdobeBridge] <br />
uRun: [Skype] &quot;c:\program files\skype\phone\Skype.exe&quot; /nosplash /minimized<br />
uRun: [DAEMON Tools Pro Agent] &quot;c:\program files\daemon tools pro\DTAgent.exe&quot; -autorun<br />
mRun: [avast5] &quot;c:\program files\alwil software\avast5\avastUI.exe&quot; /nogui<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [StartCCC] &quot;c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe&quot; MSRun<br />
mRun: [PlusService] c:\program files\yuna software\messenger plus!\PlusService.exe<br />
mRun: [VX6000] c:\windows\vVX6000.exe<br />
mRun: [LifeCam] &quot;c:\program files\microsoft lifecam\LifeExp.exe&quot;<br />
mRun: [AdobeAAMUpdater-1.0] &quot;c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe&quot;<br />
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe<br />
mRun: [AdobeCS5ServiceManager] &quot;c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe&quot; -launchedbylogin<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\common files\java\java update\jusched.exe&quot;<br />
mRun: [Wondershare Helper Compact.exe] c:\program files\common files\wondershare\wondershare helper compact\WSHelper.exe<br />
mRun: [APSDaemon] &quot;c:\program files\common files\apple\apple application support\APSDaemon.exe&quot;<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [LogMeIn GUI] &quot;c:\program files\logmein\x86\LogMeInSystray.exe&quot;<br />
mRun: [IntelliPoint] &quot;c:\program files\microsoft intellipoint\ipoint.exe&quot;<br />
mRun: [Chrome] c:\chrome\chrome.exe<br />
mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming<br />
mRun: [PCTools FGuard] c:\program files\pc tools security\bdt\FGuard.exe<br />
mRun: [NBKeyScan] &quot;c:\program files\nero\nero8\nero backitup\NBKeyScan.exe&quot;<br />
mRun: [MSC] &quot;c:\program files\microsoft security client\msseces.exe&quot; -hide -runkey<br />
StartupFolder: c:\users\alex\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\alex\appdata\roaming\dropbox\bin\Dropbox.exe<br />
StartupFolder: c:\users\alex\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableLUA = 0 (0x0)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1<br />
TCP: Interfaces\{E312710C-FAD5-4D94-ACA4-370BCEF2D1A6} : DhcpNameServer = 192.168.2.1 192.168.2.1<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll<br />
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]<br />
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2012-4-14 263888]<br />
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2012-4-14 338880]<br />
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2012-4-14 656320]<br />
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-24 357968]<br />
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-9-24 294608]<br />
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-3-28 242240]<br />
R1 MpKsl394e62c9;MpKsl394e62c9;c:\programdata\microsoft\microsoft antimalware\definition updates\{090aacaa-c495-4dff-8a6a-4c76dd8ba2f9}\MpKsl394e62c9.sys [2012-4-29 29904]<br />
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2012-4-14 233976]<br />
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-13 20992]<br />
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-3-9 176128]<br />
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-9-24 17744]<br />
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-9-24 51280]<br />
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2011-9-24 40384]<br />
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2012-3-2 47640]<br />
R2 TeamViewer7;TeamViewer 7;c:\program files\teamviewer\version7\TeamViewer_Service.exe [2012-1-3 2984832]<br />
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-3-9 7723008]<br />
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-3-9 239616]<br />
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2011-9-24 101392]<br />
R3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [2010-5-20 2074480]<br />
RUnknown DiagnosticScan;DiagnosticScan; [x]<br />
RUnknown Start1Driver;Start1Driver; [x]<br />
S2 Browser Defender Update Service;Browser Defender Update Service;&quot;c:\program files\pc tools security\bdt\bdtupdateservice.exe&quot; --&gt; c:\program files\pc tools security\bdt\BDTUpdateService.exe [?]<br />
S2 DiskManager;DiskManager;c:\diskmanager\Updater.exe [2012-3-20 609792]<br />
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-29 253088]<br />
S3 apf003;apf003;c:\windows\system32\apf003.sys [2012-3-17 13232]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]<br />
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 74112]<br />
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-3-26 214952]<br />
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --&gt; c:\windows\system32\GameMon.des -service [?]<br />
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsauxs.exe --&gt; c:\program files\pc tools security\pctsAuxs.exe [?]<br />
S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctssvc.exe --&gt; c:\program files\pc tools security\pctsSvc.exe [?]<br />
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]<br />
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-9-24 52224]<br />
S3 xsherlock;xsherlock;c:\windows\system32\xsherlock.xem [2012-2-3 658528]<br />
SUnknown MpKsl74aa916b;MpKsl74aa916b; [x]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-04-29 09:14:08	56200	----a-w-	c:\programdata\microsoft\microsoft antimalware\definition updates\{090aacaa-c495-4dff-8a6a-4c76dd8ba2f9}\offreg.dll<br />
2012-04-29 09:14:08	29904	----a-w-	c:\programdata\microsoft\microsoft antimalware\definition updates\{090aacaa-c495-4dff-8a6a-4c76dd8ba2f9}\MpKsl394e62c9.sys<br />
2012-04-29 09:12:36	6734704	----a-w-	c:\programdata\microsoft\microsoft antimalware\definition updates\{090aacaa-c495-4dff-8a6a-4c76dd8ba2f9}\mpengine.dll<br />
2012-04-29 04:46:20	6734704	------w-	c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll<br />
2012-04-29 03:31:56	--------	d-----w-	C:\ijji<br />
2012-04-29 03:30:08	713312	----a-w-	c:\windows\system32\ijjiSetup.exe<br />
2012-04-29 03:30:08	62048	----a-w-	c:\windows\system32\ijjiProcessRestarter.exe<br />
2012-04-29 03:30:08	--------	d-----w-	C:\Temp<br />
2012-04-29 02:51:47	--------	d-----w-	c:\users\alex\appdata\local\{1876F58D-4CCC-4B24-8FEE-A854085116A3}<br />
2012-04-29 02:51:32	--------	d-----w-	c:\users\alex\appdata\local\{85F537F4-3138-459D-86FF-61220A961B99}<br />
2012-04-28 06:58:45	--------	d-----w-	c:\users\alex\appdata\local\{CD5C8CC6-D91B-4020-806A-286F997BD638}<br />
2012-04-28 06:58:24	--------	d-----w-	c:\users\alex\appdata\local\{8147E985-2753-4023-A700-056F1335553C}<br />
2012-04-28 03:15:58	713784	------w-	c:\programdata\microsoft\microsoft antimalware\definition updates\{84b91b85-077d-4d3d-ab5c-c3720f52b8e9}\gapaengine.dll<br />
2012-04-28 03:12:33	--------	d-----w-	c:\program files\Microsoft Security Client<br />
2012-04-28 03:02:18	--------	d-----w-	c:\users\alex\appdata\local\{A83B8262-8D04-4DEC-9E59-A28529E5F870}<br />
2012-04-28 03:01:41	--------	d-----w-	c:\users\alex\appdata\local\{113BC27C-5E11-4D67-A076-983F2CD203C5}<br />
2012-04-28 02:55:06	--------	d-----w-	C:\AMD<br />
2012-04-27 23:50:34	--------	d-----w-	c:\users\alex\appdata\local\{0D201DC6-F0D2-4D73-9A69-B269A0B24EA4}<br />
2012-04-27 23:49:02	537432	----a-w-	c:\program files\common files\windows live\.cache\5217452c1cd24d001\DXSETUP.exe<br />
2012-04-27 23:49:01	89944	----a-w-	c:\program files\common files\windows live\.cache\5217452c1cd24d001\DSETUP.dll<br />
2012-04-27 23:49:01	1801048	----a-w-	c:\program files\common files\windows live\.cache\5217452c1cd24d001\dsetup32.dll<br />
2012-04-27 23:47:29	--------	d-----w-	c:\users\alex\appdata\local\{DA1944F4-CE67-4BEB-9925-9B3FF82C82C0}<br />
2012-04-27 23:47:09	--------	d-----w-	c:\users\alex\appdata\local\{F2D0BC2F-F70B-4AF3-AB70-1934D16A0580}<br />
2012-04-26 02:53:38	--------	d-----w-	c:\program files\REACTOR<br />
2012-04-24 20:43:56	--------	d-----w-	C:\koramgame<br />
2012-04-24 20:43:00	32768	----a-w-	c:\program files\common files\installshield\professional\runtime\Objectps.dll<br />
2012-04-24 20:43:00	180224	----a-w-	c:\program files\common files\installshield\professional\runtime\10\50\intel32\iuser.dll<br />
2012-04-24 20:42:59	69715	----a-w-	c:\program files\common files\installshield\professional\runtime\10\50\intel32\ctor.dll<br />
2012-04-24 20:42:59	5632	----a-w-	c:\program files\common files\installshield\professional\runtime\10\50\intel32\DotNetInstaller.exe<br />
2012-04-24 20:42:59	274432	----a-w-	c:\program files\common files\installshield\professional\runtime\10\50\intel32\iscript.dll<br />
2012-04-24 20:42:58	749568	----a-w-	c:\program files\common files\installshield\professional\runtime\10\50\intel32\iKernel.dll<br />
2012-04-24 20:42:57	192644	----a-w-	c:\program files\common files\installshield\professional\runtime\10\50\intel32\iGdi.dll<br />
2012-04-24 20:42:55	323716	----a-w-	c:\program files\common files\installshield\professional\runtime\10\50\intel32\setup.dll<br />
2012-04-20 17:01:38	--------	d-----w-	c:\programdata\Blizzard Entertainment<br />
2012-04-20 07:22:58	--------	d-----w-	c:\program files\common files\Blizzard Entertainment<br />
2012-04-20 07:21:35	--------	d-----w-	c:\programdata\Battle.net<br />
2012-04-19 22:45:11	--------	d-----w-	c:\program files\SplitMediaLabs<br />
2012-04-15 03:39:22	767952	----a-w-	c:\windows\BDTSupport.dll<br />
2012-04-15 03:39:21	2074576	----a-w-	c:\windows\PCTBDCore.dll<br />
2012-04-15 03:39:21	1533904	----a-w-	c:\windows\PCTBDRes.dll<br />
2012-04-15 03:39:21	149456	----a-w-	c:\windows\SGDetectionTool.dll<br />
2012-04-15 03:36:01	656320	----a-w-	c:\windows\system32\drivers\pctEFA.sys<br />
2012-04-15 03:36:01	338880	----a-w-	c:\windows\system32\drivers\pctDS.sys<br />
2012-04-15 03:36:01	251560	----a-w-	c:\windows\system32\drivers\pctgntdi.sys<br />
2012-04-15 03:36:01	105280	----a-w-	c:\windows\system32\drivers\pctwfpfilter.sys<br />
2012-04-15 03:35:57	263888	----a-w-	c:\windows\system32\drivers\PCTCore.sys<br />
2012-04-15 03:35:57	160576	----a-w-	c:\windows\system32\drivers\PCTAppEvent.sys<br />
2012-04-15 03:35:56	233976	----a-w-	c:\windows\system32\drivers\PCTSD.sys<br />
2012-04-15 03:35:55	70536	----a-w-	c:\windows\system32\drivers\pctplsg.sys<br />
2012-04-15 03:35:44	--------	d-----w-	c:\programdata\PC Tools<br />
2012-04-15 03:35:44	--------	d-----w-	c:\program files\common files\PC Tools<br />
2012-04-10 06:49:10	--------	d-----w-	c:\users\alex\appdata\local\{7E301E07-9DAC-4636-B60C-E69B38DEA3B4}<br />
2012-04-10 06:48:48	--------	d-----w-	c:\users\alex\appdata\local\{E8A3579D-C501-497C-9A68-208482B7B595}<br />
2012-04-10 03:48:50	--------	d-----w-	c:\users\alex\appdata\local\{B19DF15C-7B59-474D-B23C-174911AC7315}<br />
2012-04-10 03:47:04	--------	d-----w-	c:\users\alex\appdata\local\Smartbar<br />
2012-04-10 03:44:32	--------	d-----w-	c:\users\alex\appdata\local\{3E6ABEC2-B6A0-40B6-BE58-73DAFA5044C6}<br />
2012-04-10 03:44:19	--------	d-----w-	c:\users\alex\appdata\local\{429AB84A-D459-4931-8471-431022A34645}<br />
2012-04-09 08:09:07	40960	----a-r-	c:\users\alex\appdata\roaming\microsoft\installer\{9559f7ca-5e34-4237-a2d9-d856464ad727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe<br />
2012-04-09 08:09:07	40960	----a-r-	c:\users\alex\appdata\roaming\microsoft\installer\{9559f7ca-5e34-4237-a2d9-d856464ad727}\ARPPRODUCTICON.exe<br />
2012-04-09 08:08:41	--------	d-----w-	c:\program files\Project64 1.6<br />
2012-04-07 23:23:29	--------	d-----w-	c:\users\alex\appdata\local\SplitMediaLabs<br />
2012-04-07 01:52:24	--------	d-----w-	c:\programdata\WEBZEN<br />
2012-04-06 21:11:23	--------	d-----w-	c:\users\alex\appdata\local\{95330642-5F64-4A0A-8CF8-9DBD0FF001A3}<br />
2012-04-02 18:56:42	--------	d-----w-	c:\users\alex\appdata\local\{D65D35CB-A627-4C14-B145-5AC44AE2039C}<br />
2012-04-02 18:56:20	--------	d-----w-	c:\users\alex\appdata\local\{65CEB3C0-B140-45C0-BA78-F83095C9241E}<br />
2012-04-02 06:56:44	--------	d-----w-	c:\users\alex\appdata\local\{53D2A0FA-1E0A-46AA-971D-12ECF8CDCCFB}<br />
2012-04-02 06:56:22	--------	d-----w-	c:\users\alex\appdata\local\{DEEF0F14-157E-45A1-9F33-A4B27F453C7E}<br />
2012-04-01 18:56:43	--------	d-----w-	c:\users\alex\appdata\local\{A94C6CA0-76BE-48D1-B934-A5AD5EB942AB}<br />
2012-04-01 18:56:21	--------	d-----w-	c:\users\alex\appdata\local\{AC7BF34D-303F-463B-A1B2-AF03210ECF90}<br />
2012-04-01 06:56:45	--------	d-----w-	c:\users\alex\appdata\local\{0A3CDA1E-FA16-42F5-B4AF-BB97DE583727}<br />
2012-04-01 06:56:20	--------	d-----w-	c:\users\alex\appdata\local\{520D16A1-B92C-44E6-ABEA-BCC450659534}<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-04-14 07:07:10	70304	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2012-04-14 07:07:10	418464	----a-w-	c:\windows\system32\FlashPlayerApp.exe<br />
2012-04-07 02:09:43	658528	----a-w-	c:\windows\system32\xsherlock.xem<br />
2012-04-04 00:47:02	16400	----a-w-	c:\windows\system32\drivers\LNonPnP.sys<br />
2012-03-28 18:14:21	242240	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys<br />
2012-03-21 00:44:12	74112	----a-w-	c:\windows\system32\drivers\NisDrvWFP.sys<br />
2012-03-21 00:44:12	171064	----a-w-	c:\windows\system32\drivers\MpFilter.sys<br />
2012-03-17 23:02:41	16304	------w-	c:\windows\system32\apl003.sys<br />
2012-03-17 23:02:41	13232	------w-	c:\windows\system32\apf003.sys<br />
2012-02-29 19:21:24	42392	----a-w-	c:\windows\system32\xfcodec.dll<br />
2012-02-02 22:50:43	5265	----a-w-	c:\windows\system32\nppt9x.vxd<br />
2012-02-02 22:50:43	4774	----a-w-	c:\windows\system32\npptNT2.sys<br />
2012-02-01 02:30:36	83360	----a-w-	c:\windows\system32\LMIRfsClientNP.dll<br />
2012-02-01 02:30:26	52096	----a-w-	c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll<br />
2012-02-01 02:30:18	30592	----a-w-	c:\windows\system32\LMIport.dll<br />
2012-02-01 02:30:16	87424	----a-w-	c:\windows\system32\LMIinit.dll<br />
2012-01-31 12:44:05	237072	------w-	c:\windows\system32\MpSigStub.exe<br />
.<br />
============= FINISH: 23:35:56.29 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9482&amp;d=1335757504">Attach.txt</a> (8.6 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>insaniclol</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65804</guid>
		</item>
		<item>
			<title><![CDATA[safesurf.exe keeps coming back & crashing.]]></title>
			<link>http://forums.spybot.info/showthread.php?t=65802&amp;goto=newpost</link>
			<pubDate>Sun, 29 Apr 2012 22:03:04 GMT</pubDate>
			<description><![CDATA[So recently, I've had this trojan on my computer. I did some research about it being located in the windows, program files, system32 folders and...]]></description>
			<content:encoded><![CDATA[<div>So recently, I've had this trojan on my computer. I did some research about it being located in the windows, program files, system32 folders and can't seem to find the program. While gaming, my game keeps getting &quot;alt-tabbed&quot; and that safesurf.exe popup appears saying that it got &quot;crashed&quot;.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>insaniclol</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65802</guid>
		</item>
		<item>
			<title>Infected - Smart Fortress 2012</title>
			<link>http://forums.spybot.info/showthread.php?t=65800&amp;goto=newpost</link>
			<pubDate>Sun, 29 Apr 2012 16:15:49 GMT</pubDate>
			<description>. 
 
 
Hello......please help with possible multiple infection. 
 
I was browsing through some Google results when Avast started firing multiple...</description>
			<content:encoded><![CDATA[<div>.<br />
<br />
<br />
Hello......please help with possible multiple infection.<br />
<br />
I was browsing through some Google results when Avast started firing multiple warnings (bad urls / files)<br />
<br />
I shut down the computer and restarted.....at which point Smart Fortress 2012 was installed and started scanning.<br />
<br />
It also disabled my internet (WIND Mobile)<br />
<br />
I restarted in safe mode......couldn't update Malwarebytes but scanned anyways.....found this:<br />
<br />
Files Detected: 1 ...... C:\Documents and Settings\Gooderham.LAPTOP\Local Settings\temp\ms0cfg32.exe (Exploit.Drop.CFG)<br />
<br />
Then ran Avast scan......see attached screen capture.<br />
<br />
It appears that Spybot may have been removed but not sure....Safe Mode prevents me from seeing full screen.<br />
<br />
Not sure how to procede with required scans.<br />
<br />
Everything will need to be done via an 8GB SD card jump drive as I am now posting from another computer.<br />
<br />
Please help as I am dead in the water with this one.......Best Regards<br />
<br />
<br />
.</div>


	<br />
	<div style="padding:6px">

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Images</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/jpg.gif" alt="File Type: jpg" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9481&amp;d=1335715223">Scan Result.jpg</a> (27.4 KB)</td>
</tr>
			</table>
			</fieldset>
	

	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>Halton</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65800</guid>
		</item>
		<item>
			<title>smitfraud-c.generic infection removal help</title>
			<link>http://forums.spybot.info/showthread.php?t=65795&amp;goto=newpost</link>
			<pubDate>Sat, 28 Apr 2012 00:07:54 GMT</pubDate>
			<description><![CDATA[I seem to have the smitfraud-c.generic trojan on my PC and cant seem to get rid of it using SpybotS&D,MalewareBytes, Norton;so I need your help. 
A...]]></description>
			<content:encoded><![CDATA[<div>I seem to have the smitfraud-c.generic trojan on my PC and cant seem to get rid of it using SpybotS&amp;D,MalewareBytes, Norton;so I need your help.<br />
A little backround on the troubelshooting I did on my end- The issue started yesterday when I was having trouble logging into windows-screen freeze on the credentials step(and very slow post login). After mucking around with the hw(ram); I was able to start windows and ran Spybot S&amp;D. This is when I realized that I had the smitfraud. I proceeded to try and remove it Spybot; but it seemed to return on a restart.  When spybot dint do the trick,I downloaded &amp; tried Malware Bytes; and finally I tried this tool called Norton Power Eraser - Neither did the job.<br />
<br />
I need your inputs on getting this resolved. Please help!!<br />
<br />
One observation - the PC occasionally is superfast(almost like for a few hours block); then it becomes super slow(again for a few hours continiously). Why is that? Why isnt it consitantly slow?<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 9.0.8112.16421<br />
Run by Vik at 20:05:00 on 2012-04-27<br />
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.4094.2550 [GMT -4:00]<br />
.<br />
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\system32\Ati2evxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\Ati2evxx.exe<br />
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe<br />
C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe<br />
C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe<br />
C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe<br />
C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe<br />
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\Hauppauge\MediaCenterService\HcwMceSvc.exe<br />
C:\Program Files (x86)\IR Server Suite\IR Server.exe<br />
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe<br />
C:\Program Files (x86)\SnugTV\SnugTV Station\AMAServer.exe<br />
C:\Program Files (x86)\MillieSoft\TunerFreeMCE\TunerFreeMCEService.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files (x86)\M.Play Home Center\MHC.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files (x86)\IR Server Suite\IR Server Tray.exe<br />
C:\Users\Vik\AppData\Local\Google\Update\GoogleUpdate.exe<br />
C:\Users\Vik\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe<br />
E:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe<br />
E:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe<br />
C:\Program Files (x86)\WinTV\Ir.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
E:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe<br />
C:\Program Files (x86)\Cyberlink\Shared files\brs.exe<br />
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe<br />
E:\Program Files (x86)\MediaBrowser\MediaBrowser\MediaBrowserService.exe<br />
C:\Program Files (x86)\SnugTV\SnugTV Station\QuickStart.exe<br />
E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe<br />
E:\Program Files (x86)\SlySoft\AnyDVD\ADvdDiscHlp64.exe<br />
C:\Windows\system32\conhost.exe<br />
E:\Program Files (x86)\ArcSoft\TotalMedia Theatre 5\TotalMedia Server\TM Server.exe<br />
E:\Program Files (x86)\MagicDisc\MagicDisc.exe<br />
C:\Program Files (x86)\ZeeVee\ZvRemote\ZvRemote.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Windows\system32\DllHost.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Windows\SysWOW64\NOTEPAD.EXE<br />
C:\Windows\system32\vssvc.exe<br />
C:\Windows\System32\svchost.exe -k swprv<br />
C:\Windows\SysWOW64\NOTEPAD.EXE<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.com/<br />
mWinlogon: Userinit=userinit.exe,<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - E:\PROGRA~2\SPYBOT~1\SDHelper.dll<br />
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\coIEPlg.dll<br />
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\IPS\IPSBHO.DLL<br />
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\coIEPlg.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File<br />
uRun: [swg] &quot;C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
uRun: [IR Server Tray] &quot;C:\Program Files (x86)\IR Server Suite\IR Server Tray.exe&quot;<br />
uRun: [Google Update] &quot;C:\Users\Vik\AppData\Local\Google\Update\GoogleUpdate.exe&quot; /c<br />
uRun: [IR Server] <br />
uRun: [Octoshape Streaming Services] &quot;C:\Users\Vik\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe&quot; -inv:bootrun<br />
uRun: [12Voip] &quot;E:\Program Files (x86)\12Voip.com\12Voip\12Voip.exe&quot; -nosplash -minimized<br />
uRun: [AnyDVD] E:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe<br />
mRun: [TrueImageMonitor.exe] E:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe<br />
mRun: [GrooveMonitor] &quot;C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
mRun: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
mRun: [UpdateLBPShortCut] &quot;E:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe&quot; &quot;E:\Program Files (x86)\CyberLink\LabelPrint&quot; UpdateWithCreateOnce &quot;Software\CyberLink\LabelPrint\2.5&quot;<br />
mRun: [RemoteControl9] &quot;E:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe&quot;<br />
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe<br />
mRun: [UpdatePPShortCut] &quot;E:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe&quot; &quot;E:\Program Files (x86)\CyberLink\PowerProducer&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerProducer\5.0&quot;<br />
mRun: [LGODDFU] &quot;E:\Program Files (x86)\lg_toolkit\fwupdate.exe&quot; blrun<br />
mRun: [UpdatePSTShortCut] &quot;E:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe&quot; &quot;E:\Program Files (x86)\CyberLink\Blu-ray Disc Suite&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerStarter&quot;<br />
mRun: [Malwarebytes' Anti-Malware] &quot;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /starttray<br />
StartupFolder: C:\Users\Vik\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - E:\Program Files (x86)\ERUNT\AUTOBACK.EXE<br />
StartupFolder: C:\Users\Vik\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK - E:\Program Files (x86)\MagicDisc\MagicDisc.exe<br />
StartupFolder: C:\Users\Vik\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ZvRemote.lnk - C:\Program Files (x86)\ZeeVee\ZvRemote\ZvRemote.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AUTOST~1.LNK - C:\Program Files (x86)\WinTV\Ir.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AVERHI~1.LNK - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AVERQU~1.LNK - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MEDIAB~1.LNK - E:\Program Files (x86)\MediaBrowser\MediaBrowser\MediaBrowserService.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SNUGTV~1.LNK - C:\Windows\Installer\{F6C368A7-0DD5-4DA1-BDE1-4369AFA45B4E}\NewShortcut1_46FEF19C05F1475DAA14D9007DC15270_2.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\TOTALM~1.LNK - E:\Program Files (x86)\ArcSoft\TotalMedia Theatre 5\TotalMedia Server\TM Server.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: E&amp;xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000<br />
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~2\SPYBOT~1\SDHelper.dll<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab<br />
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1<br />
TCP: Interfaces\{CB682261-DFD6-4B36-8A59-B075D9EAAFC7} : DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1<br />
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - &quot;C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe&quot;<br />
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO-X64:     AcroIEHelperStub - No File<br />
BHO-X64: Spybot-S&amp;D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~2\SPYBOT~1\SDHelper.dll<br />
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\coIEPlg.dll<br />
BHO-X64:     Symantec NCO BHO - No File<br />
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\IPS\IPSBHO.DLL<br />
BHO-X64:     Symantec Intrusion Prevention - No File<br />
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll<br />
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\coIEPlg.dll<br />
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File<br />
mRun-x64: [TrueImageMonitor.exe] E:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe<br />
mRun-x64: [GrooveMonitor] &quot;C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe&quot;<br />
mRun-x64: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
mRun-x64: [UpdateLBPShortCut] &quot;E:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe&quot; &quot;E:\Program Files (x86)\CyberLink\LabelPrint&quot; UpdateWithCreateOnce &quot;Software\CyberLink\LabelPrint\2.5&quot;<br />
mRun-x64: [RemoteControl9] &quot;E:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe&quot;<br />
mRun-x64: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe<br />
mRun-x64: [UpdatePPShortCut] &quot;E:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe&quot; &quot;E:\Program Files (x86)\CyberLink\PowerProducer&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerProducer\5.0&quot;<br />
mRun-x64: [LGODDFU] &quot;E:\Program Files (x86)\lg_toolkit\fwupdate.exe&quot; blrun<br />
mRun-x64: [UpdatePSTShortCut] &quot;E:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe&quot; &quot;E:\Program Files (x86)\CyberLink\Blu-ray Disc Suite&quot; UpdateWithCreateOnce &quot;Software\CyberLink\PowerStarter&quot;<br />
mRun-x64: [Malwarebytes' Anti-Malware] &quot;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe&quot; /starttray<br />
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\N360x64\0502000.00D\SYMDS64.SYS --&gt; C:\Windows\system32\drivers\N360x64\0502000.00D\SYMDS64.SYS [?]<br />
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\N360x64\0502000.00D\SYMEFA64.SYS --&gt; C:\Windows\system32\drivers\N360x64\0502000.00D\SYMEFA64.SYS [?]<br />
R0 tdrpman251;Acronis Try&amp;Decide and Restore Points filter (build 251);C:\Windows\system32\DRIVERS\tdrpm251.sys --&gt; C:\Windows\system32\DRIVERS\tdrpm251.sys [?]<br />
R1 ArcSec;archlp;C:\Windows\system32\drivers\ArcSec.sys --&gt; C:\Windows\system32\drivers\ArcSec.sys [?]<br />
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120416.001\IDSviA64.sys [2012-4-16 488568]<br />
R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\N360x64\0502000.00D\Ironx64.SYS --&gt; C:\Windows\system32\drivers\N360x64\0502000.00D\Ironx64.SYS [?]<br />
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\N360x64\0502000.00D\SYMNETS.SYS --&gt; C:\Windows\system32\Drivers\N360x64\0502000.00D\SYMNETS.SYS [?]<br />
R2 ADExchange;ArcSoft Exchange Service;C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2011-9-16 39528]<br />
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]<br />
R2 afcdpsrv;Acronis Nonstop Backup service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2011-9-11 2326920]<br />
R2 AVerRemote;AVerRemote;C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2011-12-30 348160]<br />
R2 AVerScheduleService;AVerScheduleService;C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2011-12-30 397312]<br />
R2 AVerUpdateServer;AVerUpdateServer;C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe [2010-3-9 169984]<br />
R2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-11 136176]<br />
R2 HcwMceSvc;Hauppauge Media Center Service;C:\Program Files (x86)\Hauppauge\MediaCenterService\HcwMceSvc.exe [2011-9-17 113192]<br />
R2 IRServer;IR Server;C:\Program Files (x86)\IR Server Suite\IR Server.exe [2009-12-18 356352]<br />
R2 MBAMService;MBAMService;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-4-27 654408]<br />
R2 SnugTV Service;SnugTV Service;C:\Program Files (x86)\SnugTV\SnugTV Station\AMAServer.exe [2010-4-12 526336]<br />
R2 TunerFreeMCEService;TunerFreeMCEService;C:\Program Files (x86)\MillieSoft\TunerFreeMCE\TunerFreeMCEService.exe [2011-10-27 14336]<br />
R3 afcdp;afcdp;C:\Windows\system32\DRIVERS\afcdp.sys --&gt; C:\Windows\system32\DRIVERS\afcdp.sys [?]<br />
R3 AVerFx2hbtv64;AVerMedia H826 USB Hybrid Tuner;C:\Windows\system32\drivers\AVerFx2hbtv64.sys --&gt; C:\Windows\system32\drivers\AVerFx2hbtv64.sys [?]<br />
R3 hcw49swt;Hauppauge HD PVR Tuner Device;C:\Windows\system32\drivers\hcw49swt.sys --&gt; C:\Windows\system32\drivers\hcw49swt.sys [?]<br />
R3 hcwD1capture;Hauppauge Colossus Capture Service;C:\Windows\system32\DRIVERS\hcwD1cap.sys --&gt; C:\Windows\system32\DRIVERS\hcwD1cap.sys [?]<br />
R3 hcwD1encoder;Hauppauge Colossus Encoder Service;C:\Windows\system32\DRIVERS\hcwD1xcd.sys --&gt; C:\Windows\system32\DRIVERS\hcwD1xcd.sys [?]<br />
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --&gt; C:\Windows\system32\drivers\mbam.sys [?]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --&gt; C:\Windows\system32\DRIVERS\Rt64win7.sys [?]<br />
S1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120402.001\BHDrvx64.sys [2012-4-2 1160824]<br />
S2 CLKMSVC10_173EB256;CyberLink Product - 2011/12/03 20:30:17;E:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-11-23 240112]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 N360;Norton Security Suite;&quot;E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\ccSvcHst.exe&quot; /s &quot;N360&quot; /m &quot;E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\diMaster.dll&quot; /prefetch:1 --&gt; E:\Program Files (x86)\Norton Security Suite\Engine\5.2.0.13\ccSvcHst.exe [?]<br />
S2 SBSDWSCService;SBSD Security Center Service;E:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe [2011-9-11 1153368]<br />
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-27 253088]<br />
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --&gt; C:\Windows\system32\drivers\dmvsc.sys [?]<br />
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-2-4 138360]<br />
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --&gt; C:\Windows\system32\DRIVERS\fssfltr.sys [?]<br />
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]<br />
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-11 136176]<br />
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --&gt; C:\Windows\system32\drivers\rdpvideominiport.sys [?]<br />
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --&gt; C:\Windows\system32\drivers\synth3dvsc.sys [?]<br />
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --&gt; C:\Windows\system32\drivers\terminpt.sys [?]<br />
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --&gt; C:\Windows\system32\drivers\tsusbflt.sys [?]<br />
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --&gt; C:\Windows\system32\drivers\TsUsbGD.sys [?]<br />
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --&gt; C:\Windows\system32\drivers\tsusbhub.sys [?]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --&gt; C:\Windows\system32\Wat\WatAdminSvc.exe [?]<br />
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --&gt; C:\Windows\system32\DRIVERS\WSDPrint.sys [?]<br />
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-04-27 23:31:38    24904    ----a-w-    C:\Windows\System32\drivers\mbam.sys<br />
2012-04-27 22:19:53    5559152    ----a-w-    C:\Windows\System32\ntoskrnl.exe<br />
2012-04-27 22:19:52    3968368    ----a-w-    C:\Windows\SysWow64\ntkrnlpa.exe<br />
2012-04-27 22:19:52    3913072    ----a-w-    C:\Windows\SysWow64\ntoskrnl.exe<br />
2012-04-27 22:17:06    418464    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe<br />
2012-04-27 19:31:23    --------    d-----w-    C:\Users\Vik\AppData\Roaming\Malwarebytes<br />
2012-04-27 19:31:18    --------    d-----w-    C:\ProgramData\Malwarebytes<br />
2012-04-27 19:15:02    --------    d-----w-    C:\Users\Vik\AppData\Local\NPE<br />
2012-04-14 01:08:47    --------    d-----w-    C:\Users\Vik\AppData\Local\{5987E7C4-5813-46E1-B9AE-F4B9D046FD0C}<br />
2012-04-13 13:08:06    --------    d-----w-    C:\Users\Vik\AppData\Local\{4784D39C-0335-4A6B-A64F-6B9059C77D35}<br />
2012-04-13 13:07:56    --------    d-----w-    C:\Users\Vik\AppData\Local\{A55FD31E-B714-431E-85AE-DE4A86D35D3D}<br />
2012-04-13 13:03:05    --------    d-----w-    C:\Windows\en<br />
2012-04-13 12:58:43    48488    ----a-w-    C:\Windows\System32\drivers\fssfltr.sys<br />
2012-04-13 12:55:33    --------    d-----w-    C:\Users\Vik\AppData\Local\Windows Live<br />
2012-04-13 12:55:31    --------    d-----w-    C:\Program Files (x86)\Common Files\Windows Live<br />
2012-04-13 12:46:02    --------    d-----w-    C:\Users\Vik\AppData\Local\AVer MediaCenter<br />
2012-04-12 07:00:59    81408    ----a-w-    C:\Windows\System32\imagehlp.dll<br />
2012-04-12 07:00:59    23408    ----a-w-    C:\Windows\System32\drivers\fs_rec.sys<br />
2012-04-12 07:00:59    159232    ----a-w-    C:\Windows\SysWow64\imagehlp.dll<br />
2012-04-12 07:00:58    5120    ----a-w-    C:\Windows\SysWow64\wmi.dll<br />
2012-04-12 07:00:58    5120    ----a-w-    C:\Windows\System32\wmi.dll<br />
2012-04-12 07:00:58    220672    ----a-w-    C:\Windows\System32\wintrust.dll<br />
2012-04-12 07:00:58    172544    ----a-w-    C:\Windows\SysWow64\wintrust.dll<br />
2012-04-10 04:27:18    --------    d-----w-    C:\Users\Vik\AppData\Roaming\Tific<br />
2012-04-10 04:27:14    --------    d-----w-    C:\Users\Vik\AppData\Local\Symantec<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-04-27 22:17:06    70304    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2012-03-08 22:50:28    49016    ----a-w-    C:\Windows\SysWow64\sirenacm.dll<br />
2012-03-08 22:37:20    302448    ----a-w-    C:\Windows\WLXPGSS.SCR<br />
2012-02-28 06:56:48    2311168    ----a-w-    C:\Windows\System32\jscript9.dll<br />
2012-02-28 06:49:56    1390080    ----a-w-    C:\Windows\System32\wininet.dll<br />
2012-02-28 06:48:57    1493504    ----a-w-    C:\Windows\System32\inetcpl.cpl<br />
2012-02-28 06:42:55    2382848    ----a-w-    C:\Windows\System32\mshtml.tlb<br />
2012-02-28 01:18:55    1799168    ----a-w-    C:\Windows\SysWow64\jscript9.dll<br />
2012-02-28 01:11:21    1427456    ----a-w-    C:\Windows\SysWow64\inetcpl.cpl<br />
2012-02-28 01:11:07    1127424    ----a-w-    C:\Windows\SysWow64\wininet.dll<br />
2012-02-28 01:03:16    2382848    ----a-w-    C:\Windows\SysWow64\mshtml.tlb<br />
2012-02-17 06:38:27    1112064    ----a-w-    C:\Windows\System32\rdpcorets.dll<br />
2012-02-17 06:38:26    1031680    ----a-w-    C:\Windows\System32\rdpcore.dll<br />
2012-02-17 05:34:22    826880    ----a-w-    C:\Windows\SysWow64\rdpcore.dll<br />
2012-02-17 04:58:24    210944    ----a-w-    C:\Windows\System32\drivers\rdpwd.sys<br />
2012-02-17 04:57:32    23552    ----a-w-    C:\Windows\System32\drivers\tdtcp.sys<br />
2012-02-10 06:36:07    1544192    ----a-w-    C:\Windows\System32\DWrite.dll<br />
2012-02-10 05:38:43    1077248    ----a-w-    C:\Windows\SysWow64\DWrite.dll<br />
2012-02-07 15:02:40    1070352    ----a-w-    C:\Windows\SysWow64\MSCOMCTL.OCX<br />
2012-02-03 04:34:34    3145728    ----a-w-    C:\Windows\System32\win32k.sys<br />
.<br />
============= FINISH: 20:05:20.18 ===============<br />
<br />
Please find the attach.zip file from the dds tool attached.</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9471&amp;d=1335571917">Attach.zip</a> (5.1 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>vikkid_x2</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65795</guid>
		</item>
		<item>
			<title>smitfraud-c.generic infection removal help</title>
			<link>http://forums.spybot.info/showthread.php?t=65794&amp;goto=newpost</link>
			<pubDate>Fri, 27 Apr 2012 23:45:10 GMT</pubDate>
			<description><![CDATA[I seem to have the smitfraud-c.generic trojan on my PC and cant seem to get rid of it using SpybotS&D,MalewareBytes, Norton;so I need your help. 
A...]]></description>
			<content:encoded><![CDATA[<div>I seem to have the smitfraud-c.generic trojan on my PC and cant seem to get rid of it using SpybotS&amp;D,MalewareBytes, Norton;so I need your help.<br />
A little backround on the troubelshooting I did on my end- The issue started yesterday when I was having trouble logging into windows-screen freeze on the credentials step(and very slow post login). After mucking around with the hw(ram); I was able to start windows and ran Spybot S&amp;D. This is when I realized that I had the smitfraud. I proceeded to try and remove it Spybot; but it seemed to return on a restart.  When spybot dint do the trick,I downloaded &amp; tried Malware Bytes; and finally I tried this tool called Norton Power Eraser - Neither did the job.<br />
<br />
I need your inputs on getting this resolved. Please help!!<br />
<br />
One observation - the PC occasionally is superfast(almost like for a few hours block); then it becomes super slow(again for a few hours continiously). Why is that? Why isnt it consitantly slow?</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>vikkid_x2</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65794</guid>
		</item>
		<item>
			<title>Infected?</title>
			<link>http://forums.spybot.info/showthread.php?t=65784&amp;goto=newpost</link>
			<pubDate>Thu, 26 Apr 2012 03:11:16 GMT</pubDate>
			<description>Hello, 
 
I have just resurrected my pc after about 4 months in hibernation.  The first thing I did was bring all anti-virus, OS and malware s/w up...</description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
I have just resurrected my pc after about 4 months in hibernation.  The first thing I did was bring all anti-virus, OS and malware s/w up to current releases and ran all available scans.<br />
<br />
Nothing bad was found (Spybot found some items and they were all successfully removed).  <br />
<br />
However, the pc is incredibly slow and often freezes causing me to have to do a hard reboot.<br />
<br />
Any help you can provide is greatly appreciated.<br />
<br />
Thanks,  Steve.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>stevew</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65784</guid>
		</item>
		<item>
			<title>Happili.com and other browser redirects</title>
			<link>http://forums.spybot.info/showthread.php?t=65783&amp;goto=newpost</link>
			<pubDate>Wed, 25 Apr 2012 23:43:50 GMT</pubDate>
			<description><![CDATA[Thanks for your help! Here's my DDS file. Attached is the Attach.zip (I hope). 
 
. 
DDS (Ver_2011-08-26.01) - NTFSx86  
Internet Explorer:...]]></description>
			<content:encoded><![CDATA[<div>Thanks for your help! Here's my DDS file. Attached is the Attach.zip (I hope).<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 7.0.5730.11  BrowserJavaVersion: 1.6.0_29<br />
Run by Randall England at 19:36:33 on 2012-04-25<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1015.388 [GMT -7:00]<br />
.<br />
AV: Norton AntiVirus *Enabled/Updated* {B5510F6F-87E1-47F7-A411-360BC453007C}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\WINDOWS\system32\svchost.exe -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\system32\spoolsv.exe<br />
svchost.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br />
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe<br />
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\QuickTime\QTTask.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\program files\real\realplayer\update\realsched.exe<br />
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe<br />
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe<br />
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt<br />
C:\WINDOWS\system32\svchost.exe -k HPService<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\System32\svchost.exe -k HPZ12<br />
C:\WINDOWS\System32\svchost.exe -k HPZ12<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe<br />
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe<br />
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe<br />
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe<br />
C:\Program Files\Canon\CAL\CALMAIN.exe<br />
C:\WINDOWS\system32\fxssvc.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Common Files\Java\Java Update\jucheck.exe<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE<br />
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.microsoft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uStart Page = hxxp://www.google.com/<br />
uInternet Settings,ProxyOverride = *.local<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_printenhancer.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll<br />
TB: &amp;Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll<br />
TB: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [Google Update] &quot;c:\documents and settings\randall england\local settings\application data\google\update\GoogleUpdate.exe&quot; /c<br />
mRun: [&lt;NO NAME&gt;] <br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [APSDaemon] &quot;c:\program files\common files\apple\apple application support\APSDaemon.exe&quot;<br />
mRun: [EEventManager] c:\progra~1\epsons~1\eventm~1\EEventManager.exe<br />
mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe<br />
mRun: [hpqSRMon] c:\program files\hewlett-packard\digital imaging\bin\hpqSRMon.exe<br />
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup<br />
mRun: [ISUSScheduler] &quot;c:\program files\common files\installshield\updateservice\issch.exe&quot; -start<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\common files\java\java update\jusched.exe&quot;<br />
mRun: [TkBellExe] &quot;c:\program files\real\realplayer\update\realsched.exe&quot;  -osboot<br />
StartupFolder: c:\docume~1\randal~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL<br />
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll<br />
DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab<br />
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab<br />
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
TCP: DhcpNameServer = 192.168.1.1<br />
TCP: Interfaces\{3D26F10A-C044-406C-BC70-9BAD1BBB187A} : DhcpNameServer = 192.168.1.1<br />
Hosts: 127.0.0.1	<a href="http://www.spywareinfo.com" target="_blank">www.spywareinfo.com</a><br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\documents and settings\randall england\application data\mozilla\firefox\profiles\u1gyrest.default\<br />
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&amp;ie=UTF-8&amp;oe=UTF-8&amp;q=<br />
FF - prefs.js: browser.search.selectedEngine - Google<br />
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll<br />
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll<br />
FF - component: c:\documents and settings\randall england\application data\mozilla\firefox\profiles\u1gyrest.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll<br />
FF - component: c:\documents and settings\randall england\application data\mozilla\firefox\profiles\u1gyrest.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll<br />
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll<br />
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll<br />
FF - plugin: c:\documents and settings\randall england\application data\facebook\npfbplugin_1_0_3.dll<br />
FF - plugin: c:\documents and settings\randall england\local settings\application data\google\update\1.3.21.111\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll<br />
FF - plugin: c:\program files\logitech\harmony remote driver\NprtHarmonyPlugin.dll<br />
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R2 WDDMService;WDDMService;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2010-9-8 237056]<br />
R2 WDFME;WD File Management Engine;c:\program files\western digital\wd smartware\front parlor\wdfme\WDFME.exe [2010-9-8 1034752]<br />
R2 WDSC;WD File Management Shadow Engine;c:\program files\western digital\wd smartware\front parlor\WDSC.exe [2010-9-8 484352]<br />
S2 gupdate1c9f6e5768bb8f0;Google Update Service (gupdate1c9f6e5768bb8f0);c:\program files\google\update\GoogleUpdate.exe [2009-6-26 133104]<br />
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-6-26 133104]<br />
S3 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2009-3-13 34760]<br />
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [2009-3-13 29584]<br />
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-5-13 121064]<br />
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-5-13 12776]<br />
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-5-13 136808]<br />
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2010-11-7 11520]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-04-23 23:28:16	--------	d-----w-	c:\documents and settings\all users\application data\ClubSanDisk<br />
2012-04-09 07:33:39	97328	----a-w-	c:\windows\system32\vetredir.dll<br />
2012-04-09 07:33:39	202064	----a-w-	c:\windows\system32\Isafprod.dll<br />
2012-04-09 07:33:39	130096	----a-w-	c:\windows\system32\isafeif.dll<br />
2012-04-09 07:27:05	7	----a-w-	c:\windows\system32\mkghj.dll<br />
2012-04-09 07:26:30	200704	----a-w-	c:\windows\system32\ssleay32.dll<br />
2012-04-09 07:26:26	--------	d-----w-	c:\windows\rnapxs<br />
2012-04-09 04:05:25	--------	d-----w-	c:\program files\iPod<br />
2012-04-08 19:19:58	--------	d-----w-	c:\program files\Spybot - Search &amp; Destroy<br />
2012-04-02 09:30:37	--------	d-----w-	c:\documents and settings\randall england\local settings\application data\{5BCB26F1-7C8D-11E1-826D-B8AC6F996F26}<br />
2012-04-02 09:30:15	--------	d-----w-	c:\documents and settings\randall england\local settings\application data\MSRebar<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-03-01 01:25:04	832512	----a-w-	c:\windows\system32\wininet.dll<br />
2012-03-01 01:25:03	78336	----a-w-	c:\windows\system32\ieencode.dll<br />
2012-03-01 01:25:03	1830912	----a-w-	c:\windows\system32\inetcpl.cpl<br />
2012-03-01 01:25:03	17408	----a-w-	c:\windows\system32\corpol.dll<br />
2012-02-29 14:10:16	177664	----a-w-	c:\windows\system32\wintrust.dll<br />
2012-02-29 14:10:16	148480	----a-w-	c:\windows\system32\imagehlp.dll<br />
2012-02-29 07:38:27	404640	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2012-02-15 18:01:50	4547944	----a-w-	c:\windows\system32\usbaaplrc.dll<br />
2012-02-15 18:01:50	43520	----a-w-	c:\windows\system32\drivers\usbaapl.sys<br />
2012-02-03 09:22:18	1860096	----a-w-	c:\windows\system32\win32k.sys<br />
.<br />
============= FINISH: 19:37:27.46 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9455&amp;d=1335397286">attach.zip</a> (5.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>rengland</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65783</guid>
		</item>
		<item>
			<title>Re: W3i.IQ5.fraud Removal</title>
			<link>http://forums.spybot.info/showthread.php?t=65781&amp;goto=newpost</link>
			<pubDate>Wed, 25 Apr 2012 20:43:34 GMT</pubDate>
			<description><![CDATA[Hey i am sorry for my tardy response but i was traveling and managed to fix this problem just by running S&D in administrator mode. The scans do not...]]></description>
			<content:encoded><![CDATA[<div>Hey i am sorry for my tardy response but i was traveling and managed to fix this problem just by running S&amp;D in administrator mode. The scans do not appear to show any problems but nevertheless i will be posting what was recommended just to see if my system is as clean as i think it is.<br />
The thread i am referring to is <br />
<a href="http://forums.spybot.info/showthread.php?p=424150#post424150" target="_blank">http://forums.spybot.info/showthread...150#post424150</a><br />
<br />
<br />
Regards,<br />
Faizan</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9451&amp;d=1335386487">ckfiles.txt</a> (1.5 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9452&amp;d=1335386501">aswMBR.txt</a> (2.0 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9453&amp;d=1335386520">ComboFix.txt</a> (28.9 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>Faizan</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65781</guid>
		</item>
		<item>
			<title>XP Antispyware 2012 virus</title>
			<link>http://forums.spybot.info/showthread.php?t=65778&amp;goto=newpost</link>
			<pubDate>Wed, 25 Apr 2012 11:34:08 GMT</pubDate>
			<description>I have XP antispyware 2012/Internet Security 2012 on my laptop. It boots up when i run internet explorer (try to access internet)I think? via jjv.eve...</description>
			<content:encoded><![CDATA[<div>I have XP antispyware 2012/Internet Security 2012 on my laptop. It boots up when i run internet explorer (try to access internet)I think? via jjv.eve file, so not able to access web. Not possible to download a fix. Have managed to load Superantispyware Portable via memory stick and run quick scan, lots of malware found and deleted but not one listed above:sad: Not able to start up in anything but Normal Mode.<br />
Obviously not been able to run any kind of back up requiring a web link. This post sent via another laptop.<br />
Any ideas spring to mind on a possible fix?</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>Bread</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65778</guid>
		</item>
		<item>
			<title><![CDATA[IDP.Trojan.1C8D1A13 & Crypt.AQLW]]></title>
			<link>http://forums.spybot.info/showthread.php?t=65762&amp;goto=newpost</link>
			<pubDate>Wed, 25 Apr 2012 03:30:44 GMT</pubDate>
			<description><![CDATA[G'day Guys I'm not a techo & new here. Was pointed in this direction to run ERUNT (this wouldn't run due to no internet access on pc) & DDS log.  
...]]></description>
			<content:encoded><![CDATA[<div>G'day Guys I'm not a techo &amp; new here. Was pointed in this direction to run ERUNT (this wouldn't run due to no internet access on pc) &amp; DDS log. <br />
<br />
First can I say before I found your site &amp; had discovered the virus (see notes below) I had tried to run Combofix but it didn't work (i think, as I have lost internet access on my PC) <br />
<br />
I hope I've done it right so far??<br />
<br />
--------------------------------------------------------------------------<br />
My 7 year old son mainly uses our pc for playing games &amp; printing out coloring in pages etc.<br />
<br />
I run AVG &amp; it's now coming up with following;<br />
IDP.Trojan.1C8D1A13 &amp; Crypt.AQLW<br />
<br />
I've tried to find a tool to remove it (as avg cant get rid of it) but can't find anything. Don't really know what else to do?<br />
<br />
If you can an help me I would really appreciate it (fyi the pc runs xppro). <br />
<br />
Cheers Andy<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 8.0.6001.18702<br />
Run by Cameron at 11:05:22 on 2012-04-25<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2037.1410 [GMT 8:00]<br />
.<br />
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe<br />
C:\Program Files\AVG\AVG2012\avgcsrvx.exe<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\AVG\AVG2012\avgtray.exe<br />
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\WINDOWS\RTHDCPL.EXE<br />
C:\WINDOWS\system32\igfxtray.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\FingerPrint\FingerPrint.exe<br />
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\acs.exe<br />
C:\Program Files\AVG\AVG2012\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe<br />
C:\Program Files\CyberLink\Shared Files\RichVideo.exe<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.com.au/<br />
uInternet Settings,ProxyOverride = *.local<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll<br />
BHO: RewardsArcade: {597a9974-8cb0-4f41-b61f-ed065738a397} - c:\program files\rewardsarcade\RewardsArcade.dll<br />
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll<br />
BHO: Help the General-Search Project: {ca4520f3-ae13-4fb1-a513-58e23991c86d} - c:\docume~1\cameron\applic~1\mediaf~1\extens~1\GENCRA~1.DLL<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\18.0.1025.162\npchrome_frame.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll<br />
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
mRun: [AVG_TRAY] &quot;c:\program files\avg\avg2012\avgtray.exe&quot;<br />
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br />
mRun: [LogitechQuickCamRibbon] &quot;c:\program files\logitech\logitech webcam software\LWS.exe&quot; /hide<br />
mRun: [UpdatePDRShortCut] &quot;c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe&quot; &quot;c:\program files\cyberlink\powerdirector&quot; updatewithcreateonce &quot;software\cyberlink\powerdirector\9.0&quot;<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\qttask.exe&quot; -atboottime<br />
mRun: [APSDaemon] &quot;c:\program files\common files\apple\apple application support\APSDaemon.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\common files\java\java update\jusched.exe&quot;<br />
mRun: [Adobe Reader Speed Launcher] &quot;c:\program files\adobe\reader 9.0\reader\Reader_sl.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [RTHDCPL] RTHDCPL.EXE<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon<br />
mRun: [CanonSolutionMenuEx] c:\program files\canon\solution menu ex\CNSEMAIN.EXE /logon<br />
mRun: [uipre] rundll32.exe &quot;c:\docume~1\cameron\locals~1\temp\uipre.dll&quot;,Vec3TransformCoord<br />
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE<br />
StartupFolder: c:\docume~1\cameron\startm~1\programs\startup\myprog~1.lnk - c:\program files\fingerprint\FingerPrint.exe<br />
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg311t\wlancfg5.exe<br />
IE: Download with &amp;Media Finder - c:\program files\media finder\hook.html<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
LSP: mswsock.dll<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab<br />
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.fujifilmimagine.com/imagine/ax/ImageUploader5.cab<br />
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
TCP: Interfaces\{A4A02AAB-A392-4FBC-8929-A0CB65998009} : DhcpNameServer = 10.1.1.1<br />
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\18.0.1025.162\npchrome_frame.dll<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL<br />
Notify: igfxcui - igfxdev.dll<br />
AppInit_DLLs:   <br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 23120]<br />
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]<br />
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 230608]<br />
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 40016]<br />
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 295248]<br />
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]<br />
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]<br />
R2 CinemaNow Service;CinemaNow Service;c:\program files\cinemanow\cinemanow media manager\CinemaNowSvc.exe [2009-6-23 127352]<br />
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134608]<br />
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24272]<br />
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 16720]<br />
S2 antivirservice;Ctljystk;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 FingerPrint;FingerPrint Service;c:\program files\fingerprint\fingerprintservice.exe -start --&gt; c:\program files\fingerprint\FingerPrintService.exe -start [?]<br />
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-3-28 116648]<br />
S2 mcvsrte;Roxmediadb;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S2 mks_scan;Z525obex;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S2 nod32krn;Kerbkey;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S2 ofcpfwsvc;Websensecpmcommunicationagent;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S2 pavdrv;Pnp680r;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S2 symantecantibotdriver;Tmesrv3;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S2 symantecantibotshim;Oracle%oracle_home_service%clientcache80;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S2 vsdatant;HFACSVC;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]<br />
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-6 253088]<br />
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-5-10 1691480]<br />
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-3-28 116648]<br />
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-12-15 18432]<br />
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]<br />
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-04-24 05:19:22    --------    d-----w-    c:\documents and settings\cameron\local settings\application data\NPE<br />
2012-04-24 05:19:22    --------    d-----w-    c:\documents and settings\all users.windows\application data\Norton<br />
2012-04-24 05:08:19    --------    d-----w-    c:\documents and settings\all users.windows\application data\COMODO<br />
2012-04-24 05:08:10    --------    d-----w-    c:\documents and settings\cameron\application data\Comodo<br />
2012-04-23 00:07:36    --------    d-----w-    c:\documents and settings\cameron\application data\Uqycux<br />
2012-04-23 00:07:36    --------    d-----w-    c:\documents and settings\cameron\application data\Rofeen<br />
2012-04-22 15:48:12    --------    d-----w-    c:\documents and settings\cameron\local settings\application data\Identities<br />
2012-04-22 15:47:58    --------    d-----w-    c:\documents and settings\cameron\application data\Ypaxad<br />
2012-04-22 15:47:58    --------    d-----w-    c:\documents and settings\cameron\application data\Ydod<br />
2012-04-20 00:23:16    --------    d-----w-    C:\sh4ldr<br />
2012-04-20 00:23:16    --------    d-----w-    c:\program files\Enigma Software Group<br />
2012-04-20 00:21:59    --------    d-----w-    c:\windows\4E0C6314A8B84026AC15084E8B63AFB5.TMP<br />
2012-04-20 00:21:30    --------    d-----w-    c:\program files\common files\Wise Installation Wizard<br />
2012-04-19 23:49:31    0    --sha-w-    c:\windows\system32\dds_trash_log.cmd<br />
2012-04-19 23:48:04    --------    d-----w-    c:\documents and settings\all users.windows\application data\F4D55F2C000BBBB74E027CC6D151FC4E<br />
2012-04-17 00:41:07    --------    d--h--w-    c:\documents and settings\all users.windows\application data\CanonIJFAX<br />
2012-04-17 00:40:16    315392    ----a-w-    c:\windows\system32\CNC410L.dll<br />
2012-04-17 00:40:16    1347584    ----a-w-    c:\windows\system32\CNC410C.dll<br />
2012-04-17 00:40:16    114688    ----a-w-    c:\windows\system32\CNC410I.dll<br />
2012-04-17 00:40:16    106496    ----a-w-    c:\windows\system32\CNC410U.dll<br />
2012-04-17 00:36:39    --------    d-----w-    c:\documents and settings\cameron\application data\Canon Easy-WebPrint EX<br />
2012-04-17 00:32:02    257024    ----a-w-    c:\windows\system32\CNCALAL.DLL<br />
2012-04-17 00:31:49    74752    ----a-w-    c:\windows\system32\spool\prtprocs\w32x86\CNMPPAL.DLL<br />
2012-04-17 00:31:49    303104    ----a-w-    c:\windows\system32\CNMLMAL.DLL<br />
2012-04-17 00:31:49    28672    ----a-w-    c:\windows\system32\spool\prtprocs\w32x86\CNMPDAL.DLL<br />
2012-04-17 00:31:42    94208    ----a-w-    c:\windows\system32\CNC410O.dll<br />
2012-04-17 00:31:39    180224    ----a-w-    c:\windows\system32\CNMIUAL.DLL<br />
2012-04-07 08:55:58    --------    d-sh--w-    C:\found.000<br />
2012-04-07 07:42:52    --------    d-----w-    C:\big w prints<br />
2012-04-07 07:07:12    --------    d-----w-    C:\Vuze<br />
2012-04-07 06:48:39    --------    d-----w-    C:\To Transfer<br />
2012-04-06 00:19:51    418464    ----a-w-    c:\windows\system32\FlashPlayerApp.exe<br />
2012-04-01 03:09:26    --------    d-----r-    C:\g on Home PC (B03f21ae66bf49c)<br />
2012-03-28 07:22:27    --------    d-----w-    c:\documents and settings\cameron\local settings\application data\Plex<br />
2012-03-28 07:22:20    --------    d-----w-    c:\documents and settings\cameron\local settings\application data\Deployment<br />
2012-03-28 07:19:19    --------    d-----w-    c:\documents and settings\all users.windows\application data\boost_interprocess<br />
2012-03-28 07:19:17    --------    d-----w-    c:\documents and settings\cameron\local settings\application data\Plex Media Server<br />
2012-03-28 07:19:01    2106216    ----a-w-    c:\windows\system32\D3DCompiler_43.dll<br />
2012-03-28 07:18:44    1998168    ----a-w-    c:\windows\system32\D3DX9_43.dll<br />
2012-03-28 07:18:33    --------    d-----w-    c:\windows\Logs<br />
2012-03-28 07:16:08    --------    d-----w-    c:\program files\Plex<br />
2012-03-26 11:07:43    --------    d-----w-    c:\documents and settings\cameron\application data\searchquband<br />
2012-03-26 11:07:43    --------    d-----w-    c:\documents and settings\cameron\AppData<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2012-04-14 15:02:10    70304    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2012-03-01 11:01:32    916992    ----a-w-    c:\windows\system32\wininet.dll<br />
2012-03-01 11:01:32    43520    ------w-    c:\windows\system32\licmgr10.dll<br />
2012-03-01 11:01:32    1469440    ----a-w-    c:\windows\system32\inetcpl.cpl<br />
2012-02-29 14:10:16    177664    ----a-w-    c:\windows\system32\wintrust.dll<br />
2012-02-29 14:10:16    148480    ------w-    c:\windows\system32\imagehlp.dll<br />
2012-02-29 12:17:40    385024    ------w-    c:\windows\system32\html.iec<br />
2012-02-15 03:01:50    4547944    ----a-w-    c:\windows\system32\usbaaplrc.dll<br />
2012-02-15 03:01:50    43520    ----a-w-    c:\windows\system32\drivers\usbaapl.sys<br />
2012-02-07 03:02:40    1070352    ----a-w-    c:\windows\system32\MSCOMCTL.OCX<br />
2012-02-03 09:22:18    1860096    ------w-    c:\windows\system32\win32k.sys<br />
.<br />
============= FINISH: 11:06:10.65 ===============</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9442&amp;d=1335324563">dds.txt</a> (14.9 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://forums.spybot.info/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://forums.spybot.info/attachment.php?attachmentid=9443&amp;d=1335324587">attach.zip</a> (13.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?f=23">Archives</category>
			<dc:creator>jacknjaspa</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?t=65762</guid>
		</item>
	</channel>
</rss>

