Antylus
2010-10-06, 18:17
Hi all,
Yesterday, I noticed that my computer had slowed down and that Windows Media Player, in particular, had ground to a halt. I attempted to update Spybot and realised that something was blocking my access. Downloading various anti-malware utilities, I discovered that the infection was also preventing these programs from opening – a problem sometimes remedied by altering their file names. Finally, in the Windows Security Centre, AVG’s virus protection was described as ‘off’ and this could not be corrected.
So far, I have run Spybot, SuperAntiSpyware and Malwarebyte’s Anti-Malware. I have attached the removal logs along with those requested. The computer is now performing better (programs can update and AVG has recommenced virus and malware protection) but certain files are still being prevented from opening.
Thanks in advance for your assistance,
Antylus
DDS log:
DDS (Ver_10-10-05.01) - NTFSx86
Run by Adam at 15:44:33.72 on 06/10/2010
Internet Explorer: 9.0.7930.16406 BrowserJavaVersion: 1.6.0_21
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2038.877 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Macrium\Reflect\ReflectService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\sttray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Adam\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uWindow Title = Internet Explorer provided by Dell
mDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=3070906
uInternet Connection Wizard,ShellNext = yes
uInternet Connection Wizard,ShellNext = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=3070906
uInternet Connection Wizard,ShellNext = \0\0
uInternet Connection Wizard,ShellNext = about:NoAdd-ons
uInternet Connection Wizard,ShellNext = about:SecurityRisk
uInternet Connection Wizard,ShellNext = yes
uInternet Connection Wizard,ShellNext = 0a000000
uInternet Connection Wizard,ShellNext = yes
uInternet Connection Wizard,ShellNext = 01000000
uInternet Connection Wizard,ShellNext = yes
uInternet Connection Wizard,ShellNext = 1a000000
uInternet Connection Wizard,ShellNext = 1a000000
uInternet Connection Wizard,ShellNext = yes
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: PodcastBHO Class: {65134fdf-f8a5-4b3d-91d9-cdf273cfd578} - c:\program files\common files\doubletwist\IEPodcastPlugin.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\adam\appdata\roaming\microsoft\windows\start menu\programs\startup\HotSync Manager.lnk.disabled
StartupFolder: c:\users\adam\appdata\roaming\microsoft\windows\start menu\programs\startup\OneNote 2007 Screen Clipper and Launcher.lnk.disabled
StartupFolder: c:\users\adam\appdata\roaming\microsoft\windows\start menu\programs\startup\OneNote Table Of Contents.onetoc2
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Adobe Gamma Loader.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Adobe Reader Speed Launch.lnk.disabled
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Dataviz Messenger.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Digital Line Detect.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\HP Digital Imaging Monitor.lnk.disabled
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Privoxy.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\QuickSet.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\VPN Client.lnk.disabled
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll c:\progra~1\google\google~1\GOEC62~1.DLL
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
STS: Deskscapes Class: {ec654325-1273-c2a9-2b7c-45d29bce68fb} - c:\program files\stardock\object desktop\deskscapes\deskscapes.dll
STS: Stardock Vista ControlPanel Extension: {ec654325-1273-c2a9-2b7c-45d29bce68fd} - c:\program files\stardock\object desktop\deskscapes\DesktopControlPanel.dll
STS: StardockDreamController: {ec654325-1273-c2a9-2b7c-45d29bce68ff} - c:\program files\stardock\object desktop\deskscapes\DreamControl.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\adam\appdata\roaming\mozilla\firefox\profiles\nuhnsxic.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\users\adam\appdata\roaming\mozilla\firefox\profiles\nuhnsxic.default\extensions\piclens@cooliris.com\components\cooliris.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npaudio.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npavi32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npbeatnk.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npchime.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\NPDocBox.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npnul32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\NPOFF12.DLL
FF - plugin: c:\program files\netscape\communicator\program\plugins\nppdf32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nppl3260.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprfxins.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprjplug.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprpjplug.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npswf32.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - plugin: c:\users\adam\appdata\roaming\mozilla\firefox\profiles\nuhnsxic.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\users\adam\appdata\roaming\mozilla\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
============= SERVICES / DRIVERS ===============
R0 hotcore3;Hotcore helper;c:\windows\system32\drivers\hotcore3.sys [2009-12-21 40496]
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2008-5-20 15328]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-18 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-6-18 29584]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-31 243024]
R1 PSMounter;PSMounter;c:\windows\system32\drivers\psmounter.sys [2008-7-8 31712]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-3-2 390528]
R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2010-7-1 59240]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-7-1 166632]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\common files\abbyy\finereader\9.00\licensing\pe\NetworkLicenseServer.exe [2007-12-6 660768]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-16 921952]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-16 308136]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2010-3-10 6656]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-7-1 840936]
R2 ReflectService;Macrium Reflect Scheduling Services;c:\program files\macrium\reflect\ReflectService.exe [2008-8-10 252896]
R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 52\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-12-17 497856]
R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-11 21504]
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\photoshopelementsfileagent.exe --> c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-27 135664]
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\photoshopelementsdeviceconnect.exe --> c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-9-6 30192]
S3 hwmobilehsn;High Speed USB Modem and USB Serial For Normal;c:\windows\system32\drivers\hwmob01.sys [2010-4-19 106240]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-3-19 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-3-19 8320]
S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2007-9-6 23232]
S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2007-9-6 19008]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2010-10-06 11:43:43 -------- d-----w- c:\users\adam\appdata\roaming\SUPERAntiSpyware.com
2010-10-06 11:43:43 -------- d-----w- c:\progra~2\SUPERAntiSpyware.com
2010-10-06 11:40:21 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-10-06 11:37:05 2400229 ----a-w- C:\MGtools.exe
2010-10-06 11:23:16 6291456 ---ha-w- c:\users\adam\appdata\local\IconCache.db
2010-10-06 11:21:58 20 ----a-w- c:\users\adam\defogger_reenable
2010-10-06 00:20:27 -------- d-----w- c:\users\adam\appdata\roaming\Malwarebytes
2010-10-06 00:17:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-06 00:17:01 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-06 00:17:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-06 00:17:01 -------- d-----w- c:\progra~2\Malwarebytes
2010-09-29 08:33:40 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 16:39:03 -------- d-----w- C:\Hotspot Shield
2010-09-27 16:38:57 -------- d-----w- c:\program files\Hotspot Shield
2010-09-27 02:25:10 -------- d-----w- c:\program files\Windows Portable Devices
2010-09-27 02:24:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-09-27 02:22:38 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-09-27 02:06:07 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2010-09-27 02:06:06 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2010-09-27 02:06:06 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-09-27 02:03:52 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-09-27 02:03:52 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-09-27 02:03:52 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-09-25 18:34:01 -------- d-----w- c:\progra~2\DivX
2010-09-25 18:00:53 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2010-09-25 18:00:53 797184 ----a-w- c:\windows\system32\FntCache.dll
2010-09-25 18:00:53 680960 ----a-w- c:\windows\system32\d2d1.dll
2010-09-25 18:00:53 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2010-09-25 18:00:53 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2010-09-25 18:00:53 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2010-09-25 18:00:53 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-09-25 18:00:53 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2010-09-25 18:00:53 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2010-09-25 18:00:53 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2010-09-25 18:00:53 1174528 ----a-w- c:\windows\system32\d3d10warp.dll
2010-09-25 18:00:53 1068032 ----a-w- c:\windows\system32\DWrite.dll
2010-09-25 17:58:46 -------- d-----w- c:\program files\Feedback Tool
2010-09-25 12:21:37 -------- d-----w- c:\windows\system32\eu-ES
2010-09-25 12:21:37 -------- d-----w- c:\windows\system32\ca-ES
2010-09-25 12:21:35 -------- d-----w- c:\windows\system32\vi-VN
2010-09-25 11:08:14 -------- d-----w- c:\windows\system32\EventProviders
2010-09-22 19:19:02 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2010-09-18 16:41:46 -------- d-----w- c:\users\adam\appdata\local\Amazon
2010-09-18 10:19:11 -------- d-----w- c:\users\adam\appdata\local\Cisco
2010-09-18 10:10:57 -------- d-----w- c:\program files\Cisco
2010-09-18 10:10:47 -------- d-----w- c:\progra~2\Cisco
2010-09-17 02:02:21 -------- d-----w- C:\52a3bb0b6e95a19f0af21e
2010-09-16 18:26:35 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-09-15 21:58:02 502272 ----a-w- c:\windows\system32\usp10.dll
2010-09-15 21:57:57 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-15 21:57:54 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-15 21:57:47 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-08 19:52:29 -------- d-----w- c:\users\adam\appdata\roaming\InfraRecorder
2010-09-08 19:50:28 -------- d-----w- c:\program files\InfraRecorder
==================== Find3M ====================
2010-10-06 11:11:55 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-31 23:46:36 1355264 ----a-w- c:\windows\system32\jscript9.dll
2010-08-31 23:44:32 367104 ----a-w- c:\windows\system32\html.iec
2010-08-31 23:44:30 1448448 ----a-w- c:\windows\system32\inetcpl.cpl
2010-08-31 23:44:24 1122304 ----a-w- c:\windows\system32\wininet.dll
2010-08-31 23:44:06 424960 ----a-w- c:\windows\system32\vbscript.dll
2010-08-31 23:43:22 23552 ----a-w- c:\windows\system32\licmgr10.dll
2010-08-31 23:43:12 72704 ----a-w- c:\windows\system32\SetDepNx.exe
2010-08-31 23:43:12 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2010-08-31 23:43:12 114176 ----a-w- c:\windows\system32\iesysprep.dll
2010-08-31 23:43:10 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2010-08-31 23:43:10 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2010-08-31 23:42:58 51200 ----a-w- c:\windows\system32\admparse.dll
2010-08-31 23:42:54 75264 ----a-w- c:\windows\system32\iesetup.dll
2010-08-31 23:42:48 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2010-08-31 23:42:42 150016 ----a-w- c:\windows\system32\iexpress.exe
2010-08-31 23:42:42 149504 ----a-w- c:\windows\system32\wextract.exe
2010-08-31 23:42:20 33280 ----a-w- c:\windows\system32\imgutil.dll
2010-08-31 23:42:16 48640 ----a-w- c:\windows\system32\mshtmler.dll
2010-08-31 23:42:12 11264 ----a-w- c:\windows\system32\mshta.exe
2010-08-31 23:42:10 2381824 ----a-w- c:\windows\system32\mshtml.tlb
2010-08-31 23:42:04 63488 ----a-w- c:\windows\system32\tdc.ocx
2010-08-31 23:41:46 160768 ----a-w- c:\windows\system32\msls31.dll
2010-08-20 09:35:22 339968 ----a-w- c:\windows\system32\RapportBuka.dll
2010-08-12 04:07:46 133616 ------w- c:\windows\system32\PxAFS.DLL
2010-08-12 04:07:46 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-08-12 04:07:46 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-07-16 17:47:55 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2005-02-22 16:55:02 81920 --sh--r- c:\windows\system32\aac_parser.ax
2005-08-12 09:04:06 606208 --sha-w- c:\windows\system32\CoreAAC.ax
2005-01-17 23:26:36 179200 --sh--r- c:\windows\system32\DiracSplitter.ax
2005-02-12 23:00:00 186880 --sh--r- c:\windows\system32\RLOgg.ax
2005-02-12 23:00:00 51712 --sh--r- c:\windows\system32\RLSpeexDec.ax
2005-02-12 23:00:00 67584 --sh--r- c:\windows\system32\RLTheoraDec.ax
2005-02-05 23:00:00 92672 --sh--r- c:\windows\system32\RLVorbisDec.ax
============= FINISH: 15:48:13.47 ===============
Yesterday, I noticed that my computer had slowed down and that Windows Media Player, in particular, had ground to a halt. I attempted to update Spybot and realised that something was blocking my access. Downloading various anti-malware utilities, I discovered that the infection was also preventing these programs from opening – a problem sometimes remedied by altering their file names. Finally, in the Windows Security Centre, AVG’s virus protection was described as ‘off’ and this could not be corrected.
So far, I have run Spybot, SuperAntiSpyware and Malwarebyte’s Anti-Malware. I have attached the removal logs along with those requested. The computer is now performing better (programs can update and AVG has recommenced virus and malware protection) but certain files are still being prevented from opening.
Thanks in advance for your assistance,
Antylus
DDS log:
DDS (Ver_10-10-05.01) - NTFSx86
Run by Adam at 15:44:33.72 on 06/10/2010
Internet Explorer: 9.0.7930.16406 BrowserJavaVersion: 1.6.0_21
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2038.877 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Macrium\Reflect\ReflectService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\sttray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Adam\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uWindow Title = Internet Explorer provided by Dell
mDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=3070906
uInternet Connection Wizard,ShellNext = yes
uInternet Connection Wizard,ShellNext = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=3070906
uInternet Connection Wizard,ShellNext = \0\0
uInternet Connection Wizard,ShellNext = about:NoAdd-ons
uInternet Connection Wizard,ShellNext = about:SecurityRisk
uInternet Connection Wizard,ShellNext = yes
uInternet Connection Wizard,ShellNext = 0a000000
uInternet Connection Wizard,ShellNext = yes
uInternet Connection Wizard,ShellNext = 01000000
uInternet Connection Wizard,ShellNext = yes
uInternet Connection Wizard,ShellNext = 1a000000
uInternet Connection Wizard,ShellNext = 1a000000
uInternet Connection Wizard,ShellNext = yes
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: PodcastBHO Class: {65134fdf-f8a5-4b3d-91d9-cdf273cfd578} - c:\program files\common files\doubletwist\IEPodcastPlugin.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\adam\appdata\roaming\microsoft\windows\start menu\programs\startup\HotSync Manager.lnk.disabled
StartupFolder: c:\users\adam\appdata\roaming\microsoft\windows\start menu\programs\startup\OneNote 2007 Screen Clipper and Launcher.lnk.disabled
StartupFolder: c:\users\adam\appdata\roaming\microsoft\windows\start menu\programs\startup\OneNote Table Of Contents.onetoc2
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Adobe Gamma Loader.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Adobe Reader Speed Launch.lnk.disabled
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Dataviz Messenger.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Digital Line Detect.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\HP Digital Imaging Monitor.lnk.disabled
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\Privoxy.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\QuickSet.lnk.disabled
StartupFolder: c:\programdata\microsoft\windows\start menu\programs\startup\VPN Client.lnk.disabled
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll c:\progra~1\google\google~1\GOEC62~1.DLL
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
STS: Deskscapes Class: {ec654325-1273-c2a9-2b7c-45d29bce68fb} - c:\program files\stardock\object desktop\deskscapes\deskscapes.dll
STS: Stardock Vista ControlPanel Extension: {ec654325-1273-c2a9-2b7c-45d29bce68fd} - c:\program files\stardock\object desktop\deskscapes\DesktopControlPanel.dll
STS: StardockDreamController: {ec654325-1273-c2a9-2b7c-45d29bce68ff} - c:\program files\stardock\object desktop\deskscapes\DreamControl.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\adam\appdata\roaming\mozilla\firefox\profiles\nuhnsxic.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\users\adam\appdata\roaming\mozilla\firefox\profiles\nuhnsxic.default\extensions\piclens@cooliris.com\components\cooliris.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npaudio.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npavi32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npbeatnk.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npchime.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\NPDocBox.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npnul32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\NPOFF12.DLL
FF - plugin: c:\program files\netscape\communicator\program\plugins\nppdf32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nppl3260.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprfxins.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprjplug.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprpjplug.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npswf32.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - plugin: c:\users\adam\appdata\roaming\mozilla\firefox\profiles\nuhnsxic.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\users\adam\appdata\roaming\mozilla\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
============= SERVICES / DRIVERS ===============
R0 hotcore3;Hotcore helper;c:\windows\system32\drivers\hotcore3.sys [2009-12-21 40496]
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2008-5-20 15328]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-18 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-6-18 29584]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-31 243024]
R1 PSMounter;PSMounter;c:\windows\system32\drivers\psmounter.sys [2008-7-8 31712]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-3-2 390528]
R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2010-7-1 59240]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-7-1 166632]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\common files\abbyy\finereader\9.00\licensing\pe\NetworkLicenseServer.exe [2007-12-6 660768]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-16 921952]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-16 308136]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2010-3-10 6656]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-7-1 840936]
R2 ReflectService;Macrium Reflect Scheduling Services;c:\program files\macrium\reflect\ReflectService.exe [2008-8-10 252896]
R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 52\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-12-17 497856]
R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-11 21504]
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\photoshopelementsfileagent.exe --> c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-27 135664]
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\photoshopelementsdeviceconnect.exe --> c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [?]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-9-6 30192]
S3 hwmobilehsn;High Speed USB Modem and USB Serial For Normal;c:\windows\system32\drivers\hwmob01.sys [2010-4-19 106240]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-3-19 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-3-19 8320]
S3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2007-9-6 23232]
S3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2007-9-6 19008]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2010-10-06 11:43:43 -------- d-----w- c:\users\adam\appdata\roaming\SUPERAntiSpyware.com
2010-10-06 11:43:43 -------- d-----w- c:\progra~2\SUPERAntiSpyware.com
2010-10-06 11:40:21 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-10-06 11:37:05 2400229 ----a-w- C:\MGtools.exe
2010-10-06 11:23:16 6291456 ---ha-w- c:\users\adam\appdata\local\IconCache.db
2010-10-06 11:21:58 20 ----a-w- c:\users\adam\defogger_reenable
2010-10-06 00:20:27 -------- d-----w- c:\users\adam\appdata\roaming\Malwarebytes
2010-10-06 00:17:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-06 00:17:01 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-06 00:17:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-06 00:17:01 -------- d-----w- c:\progra~2\Malwarebytes
2010-09-29 08:33:40 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 16:39:03 -------- d-----w- C:\Hotspot Shield
2010-09-27 16:38:57 -------- d-----w- c:\program files\Hotspot Shield
2010-09-27 02:25:10 -------- d-----w- c:\program files\Windows Portable Devices
2010-09-27 02:24:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-09-27 02:22:38 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-09-27 02:06:07 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2010-09-27 02:06:06 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2010-09-27 02:06:06 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-09-27 02:03:52 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-09-27 02:03:52 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-09-27 02:03:52 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-09-25 18:34:01 -------- d-----w- c:\progra~2\DivX
2010-09-25 18:00:53 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2010-09-25 18:00:53 797184 ----a-w- c:\windows\system32\FntCache.dll
2010-09-25 18:00:53 680960 ----a-w- c:\windows\system32\d2d1.dll
2010-09-25 18:00:53 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2010-09-25 18:00:53 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2010-09-25 18:00:53 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2010-09-25 18:00:53 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-09-25 18:00:53 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2010-09-25 18:00:53 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2010-09-25 18:00:53 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2010-09-25 18:00:53 1174528 ----a-w- c:\windows\system32\d3d10warp.dll
2010-09-25 18:00:53 1068032 ----a-w- c:\windows\system32\DWrite.dll
2010-09-25 17:58:46 -------- d-----w- c:\program files\Feedback Tool
2010-09-25 12:21:37 -------- d-----w- c:\windows\system32\eu-ES
2010-09-25 12:21:37 -------- d-----w- c:\windows\system32\ca-ES
2010-09-25 12:21:35 -------- d-----w- c:\windows\system32\vi-VN
2010-09-25 11:08:14 -------- d-----w- c:\windows\system32\EventProviders
2010-09-22 19:19:02 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2010-09-18 16:41:46 -------- d-----w- c:\users\adam\appdata\local\Amazon
2010-09-18 10:19:11 -------- d-----w- c:\users\adam\appdata\local\Cisco
2010-09-18 10:10:57 -------- d-----w- c:\program files\Cisco
2010-09-18 10:10:47 -------- d-----w- c:\progra~2\Cisco
2010-09-17 02:02:21 -------- d-----w- C:\52a3bb0b6e95a19f0af21e
2010-09-16 18:26:35 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-09-15 21:58:02 502272 ----a-w- c:\windows\system32\usp10.dll
2010-09-15 21:57:57 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-15 21:57:54 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-15 21:57:47 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-08 19:52:29 -------- d-----w- c:\users\adam\appdata\roaming\InfraRecorder
2010-09-08 19:50:28 -------- d-----w- c:\program files\InfraRecorder
==================== Find3M ====================
2010-10-06 11:11:55 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-31 23:46:36 1355264 ----a-w- c:\windows\system32\jscript9.dll
2010-08-31 23:44:32 367104 ----a-w- c:\windows\system32\html.iec
2010-08-31 23:44:30 1448448 ----a-w- c:\windows\system32\inetcpl.cpl
2010-08-31 23:44:24 1122304 ----a-w- c:\windows\system32\wininet.dll
2010-08-31 23:44:06 424960 ----a-w- c:\windows\system32\vbscript.dll
2010-08-31 23:43:22 23552 ----a-w- c:\windows\system32\licmgr10.dll
2010-08-31 23:43:12 72704 ----a-w- c:\windows\system32\SetDepNx.exe
2010-08-31 23:43:12 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2010-08-31 23:43:12 114176 ----a-w- c:\windows\system32\iesysprep.dll
2010-08-31 23:43:10 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2010-08-31 23:43:10 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2010-08-31 23:42:58 51200 ----a-w- c:\windows\system32\admparse.dll
2010-08-31 23:42:54 75264 ----a-w- c:\windows\system32\iesetup.dll
2010-08-31 23:42:48 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2010-08-31 23:42:42 150016 ----a-w- c:\windows\system32\iexpress.exe
2010-08-31 23:42:42 149504 ----a-w- c:\windows\system32\wextract.exe
2010-08-31 23:42:20 33280 ----a-w- c:\windows\system32\imgutil.dll
2010-08-31 23:42:16 48640 ----a-w- c:\windows\system32\mshtmler.dll
2010-08-31 23:42:12 11264 ----a-w- c:\windows\system32\mshta.exe
2010-08-31 23:42:10 2381824 ----a-w- c:\windows\system32\mshtml.tlb
2010-08-31 23:42:04 63488 ----a-w- c:\windows\system32\tdc.ocx
2010-08-31 23:41:46 160768 ----a-w- c:\windows\system32\msls31.dll
2010-08-20 09:35:22 339968 ----a-w- c:\windows\system32\RapportBuka.dll
2010-08-12 04:07:46 133616 ------w- c:\windows\system32\PxAFS.DLL
2010-08-12 04:07:46 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-08-12 04:07:46 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-07-16 17:47:55 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2005-02-22 16:55:02 81920 --sh--r- c:\windows\system32\aac_parser.ax
2005-08-12 09:04:06 606208 --sha-w- c:\windows\system32\CoreAAC.ax
2005-01-17 23:26:36 179200 --sh--r- c:\windows\system32\DiracSplitter.ax
2005-02-12 23:00:00 186880 --sh--r- c:\windows\system32\RLOgg.ax
2005-02-12 23:00:00 51712 --sh--r- c:\windows\system32\RLSpeexDec.ax
2005-02-12 23:00:00 67584 --sh--r- c:\windows\system32\RLTheoraDec.ax
2005-02-05 23:00:00 92672 --sh--r- c:\windows\system32\RLVorbisDec.ax
============= FINISH: 15:48:13.47 ===============