Chris17
2011-10-26, 18:40
I think my computer is infected with spyware. Every time I browse with Firefox (http://forums.spybot.info/vbglossar.php?do=showentry&item=Firefox) and Internet explorer via Google I am redirected to completely irrelevant adverts. This happens approximately 50% of the time while I am browsing. I have ran Firefox (http://forums.spybot.info/vbglossar.php?do=showentry&item=Firefox) in safe mode and scanned with various anti-virus/malware programs but the problem still persists. Strangely though, I have not been redirected whilst using Google Chrome. At first I though this may have been an issue with some of the web browsers I have been using however I was using the internet on my mobile phone and I got redirected to a similar ad site on my home network. Perhaps the problem lies with my service provider? I have also tried countless reinstalls of my operating system (Windows 7) but unfortunately this hasn't solved the problem to my surprise. I'm getting very frustrated now as Firefox (http://forums.spybot.info/vbglossar.php?do=showentry&item=Firefox) is the browser I like to use for every day tasks. Any help would be greatly appreciated, I have much respect for what you experts on here do!
(I have a Dell Inspiron 1750 Laptop, if this helps)
http://forums.spybot.info/showthread.php?t=64250
---------------------------------------------------------
Sorry for not reading the rules. Here is my DDS log. I have also attached the other file in a zip folder, thank you.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by Chris at 16:29:25 on 2011-10-26
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.2008.815 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
mWinlogon: Userinit=userinit.exe
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Chris\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 95.168.162.12 95.168.162.22
TCP: Interfaces\{BDEE6F1F-8F31-4AF6-8FB7-810E5F8AC142} : DhcpNameServer = 95.168.162.12 95.168.162.22
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe [2011-10-26 89600]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-9-12 5265248]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-10-26 12:46:10 -------- d-----w- C:\Windows\en
2011-10-26 12:44:56 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-10-26 12:43:09 -------- d-----w- C:\Windows\PCHEALTH
2011-10-26 12:42:18 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-10-26 12:42:18 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-10-26 12:42:17 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
2011-10-26 12:42:17 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-10-26 12:41:37 4398360 ----a-w- C:\Windows\System32\d3dx9_32.dll
2011-10-26 12:41:37 3426072 ----a-w- C:\Windows\SysWow64\d3dx9_32.dll
2011-10-26 12:41:03 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\858239b41cc93dc03\DSETUP.dll
2011-10-26 12:41:03 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\858239b41cc93dc03\DXSETUP.exe
2011-10-26 12:41:03 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\858239b41cc93dc03\dsetup32.dll
2011-10-26 12:40:59 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\81687adb1cc93dc02\DSETUP.dll
2011-10-26 12:40:59 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\81687adb1cc93dc02\DXSETUP.exe
2011-10-26 12:40:59 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\81687adb1cc93dc02\dsetup32.dll
2011-10-26 12:40:28 -------- d-----w- C:\Users\Chris\AppData\Local\Windows Live
2011-10-26 12:40:24 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-10-26 12:36:44 -------- d-----w- C:\Program Files\PeerBlock
2011-10-26 12:23:28 -------- d-----w- C:\Users\Chris\AppData\Roaming\Azureus
2011-10-26 12:22:57 -------- d-----w- C:\Program Files (x86)\Vuze
2011-10-26 12:22:07 -------- d-----w- C:\Windows\SysWow64\Adobe
2011-10-26 12:21:15 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-26 12:19:42 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-26 11:46:53 -------- d-----w- C:\Program Files\CCleaner
2011-10-26 11:36:27 -------- d--h--w- C:\$AVG
2011-10-26 10:39:32 -------- d-----w- C:\Windows\Panther
2011-10-26 02:33:53 -------- d-----w- C:\Program Files\Synaptics
2011-10-26 02:33:33 206120 ----a-w- C:\Windows\SysWow64\SynCtrl.dll
2011-10-26 02:33:33 169256 ----a-w- C:\Windows\SysWow64\SynCOM.dll
2011-10-26 02:33:33 147752 ----a-w- C:\Windows\System32\SynTPCo4.dll
2011-10-26 02:33:33 1436920 ----a-w- C:\Windows\System32\WdfCoInstaller01009.dll
2011-10-26 02:33:33 107816 ----a-w- C:\Windows\SysWow64\SynTPCOM.dll
2011-10-26 02:33:32 395048 ----a-w- C:\Windows\System32\SynCOM.dll
2011-10-26 02:33:32 273456 ----a-w- C:\Windows\System32\drivers\SynTP.sys
2011-10-26 02:33:32 260904 ----a-w- C:\Windows\System32\SynCtrl.dll
2011-10-26 02:33:32 203560 ----a-w- C:\Windows\System32\SynTPAPI.dll
2011-10-26 02:30:20 68608 ----a-w- C:\Windows\System32\AESTAR64.dll
2011-10-26 02:30:20 601088 ----a-w- C:\Windows\System32\ctapo64.dll
2011-10-26 02:30:20 524288 ----a-w- C:\Windows\System32\ctapo32.dll
2011-10-26 02:30:20 442368 ----a-w- C:\Windows\System32\AESTEC64.dll
2011-10-26 02:30:20 162304 ----a-w- C:\Windows\System32\AESTAC64.dll
2011-10-26 02:30:19 90624 ----a-w- C:\Windows\System32\AESTCo64.dll
2011-10-26 02:30:19 57856 ----a-w- C:\Windows\System32\ctppld64.dll
2011-10-26 02:30:19 564224 ----a-w- C:\Windows\System32\idt64mp1.exe
2011-10-26 02:30:19 3345408 ----a-w- C:\Windows\System32\stlang64.dll
2011-10-26 02:30:19 12605952 ----a-w- C:\Windows\System32\idtcpl64.cpl
2011-10-26 02:30:17 -------- d-----w- C:\Windows\System32\SRSLabs
2011-10-26 02:29:45 644608 ------w- C:\Windows\System32\stapi64.dll
2011-10-26 02:29:45 505856 ----a-w- C:\Windows\System32\drivers\stwrt64.sys
2011-10-26 02:29:45 431616 ----a-w- C:\Windows\System32\stcplx64.dll
2011-10-26 02:29:45 209920 ----a-w- C:\Windows\System32\st646272.dll
2011-10-26 02:29:45 1472000 ----a-w- C:\Windows\System32\stapo64.dll
2011-10-26 02:29:44 524288 ----a-w- C:\Windows\SysWow64\ctapo32.dll
2011-10-26 02:29:43 -------- d-----w- C:\Program Files\IDT
2011-10-26 02:26:02 -------- d-----w- C:\Program Files\Dell
2011-10-26 02:20:59 92216 ----a-w- C:\Windows\SysWow64\igfcg500m.bin
2011-10-26 02:18:20 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2011-10-26 02:16:58 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
2011-10-26 02:15:17 -------- d-----w- C:\Program Files (x86)\Dell
2011-10-26 02:14:14 -------- d-----w- C:\Users\Chris\AppData\Roaming\AVG2012
2011-10-26 02:13:40 -------- d-----w- C:\dell
2011-10-26 02:13:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2011-10-26 02:13:07 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-10-26 02:13:07 367616 ----a-w- C:\Windows\System32\atmfd.dll
2011-10-26 02:13:07 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-10-26 02:13:07 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-10-26 02:13:07 100864 ----a-w- C:\Windows\System32\fontsub.dll
2011-10-26 02:12:56 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-10-26 02:12:56 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-10-26 02:12:56 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-10-26 02:12:30 -------- d-----w- C:\Windows\SysWow64\drivers\AVG
2011-10-26 02:12:27 605552 ----a-w- C:\Windows\System32\winload.exe
2011-10-26 02:12:27 566208 ----a-w- C:\Windows\System32\winresume.efi
2011-10-26 02:12:26 642944 ----a-w- C:\Windows\System32\winload.efi
2011-10-26 02:12:26 518672 ----a-w- C:\Windows\System32\winresume.exe
2011-10-26 02:12:26 20352 ----a-w- C:\Windows\System32\kdusb.dll
2011-10-26 02:12:26 19328 ----a-w- C:\Windows\System32\kd1394.dll
2011-10-26 02:12:26 17792 ----a-w- C:\Windows\System32\kdcom.dll
2011-10-26 02:10:21 -------- d-----w- C:\Program Files (x86)\AVG
2011-10-26 02:09:48 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-10-26 02:09:47 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-10-26 02:09:47 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-10-26 02:09:07 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-10-26 02:09:02 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2594575D-C885-43D6-BEB1-315BA4297F57}\mpengine.dll
2011-10-26 02:06:41 -------- d-----w- C:\Users\Chris\AppData\Local\Google
2011-10-26 02:06:05 -------- d-----w- C:\Users\Chris\AppData\Local\Apps
2011-10-26 02:06:04 -------- d-----w- C:\Users\Chris\AppData\Local\Deployment
2011-10-26 02:04:27 -------- d-sh--w- C:\Windows\Installer
2011-10-26 02:04:16 -------- d--h--w- C:\ProgramData\Common Files
2011-10-26 02:04:04 -------- d-----w- C:\ProgramData\MFAData
2011-10-26 01:52:11 -------- d-----w- C:\Windows\SysWow64\Wat
2011-10-26 01:52:11 -------- d-----w- C:\Windows\System32\Wat
2011-10-26 01:51:05 -------- d-sh--w- C:\Recovery
.
==================== Find3M ====================
.
2011-10-26 01:52:27 14848 ----a-w- C:\Windows\System32\slwga.dll
2011-10-26 01:52:27 13824 ----a-w- C:\Windows\SysWow64\slwga.dll
2011-10-26 01:52:26 419840 ----a-w- C:\Windows\System32\systemcpl.dll
2011-10-26 01:52:26 1008640 ----a-w- C:\Windows\System32\user32.dll
2011-10-26 01:52:25 833024 ----a-w- C:\Windows\SysWow64\user32.dll
2011-09-13 05:30:08 37456 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
2011-09-06 03:03:17 3138048 ----a-w- C:\Windows\System32\win32k.sys
2011-08-27 05:37:49 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-08-27 05:37:48 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-08-27 04:26:27 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:26:27 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-08-08 05:08:58 46672 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
.
============= FINISH: 16:30:00.27 ===============
(I have a Dell Inspiron 1750 Laptop, if this helps)
http://forums.spybot.info/showthread.php?t=64250
---------------------------------------------------------
Sorry for not reading the rules. Here is my DDS log. I have also attached the other file in a zip folder, thank you.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by Chris at 16:29:25 on 2011-10-26
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.2008.815 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
mWinlogon: Userinit=userinit.exe
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Chris\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 95.168.162.12 95.168.162.22
TCP: Interfaces\{BDEE6F1F-8F31-4AF6-8FB7-810E5F8AC142} : DhcpNameServer = 95.168.162.12 95.168.162.22
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe [2011-10-26 89600]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-9-12 5265248]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-10-26 12:46:10 -------- d-----w- C:\Windows\en
2011-10-26 12:44:56 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-10-26 12:43:09 -------- d-----w- C:\Windows\PCHEALTH
2011-10-26 12:42:18 69464 ----a-w- C:\Windows\SysWow64\XAPOFX1_3.dll
2011-10-26 12:42:18 515416 ----a-w- C:\Windows\SysWow64\XAudio2_5.dll
2011-10-26 12:42:17 523088 ----a-w- C:\Windows\System32\d3dx10_42.dll
2011-10-26 12:42:17 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-10-26 12:41:37 4398360 ----a-w- C:\Windows\System32\d3dx9_32.dll
2011-10-26 12:41:37 3426072 ----a-w- C:\Windows\SysWow64\d3dx9_32.dll
2011-10-26 12:41:03 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\858239b41cc93dc03\DSETUP.dll
2011-10-26 12:41:03 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\858239b41cc93dc03\DXSETUP.exe
2011-10-26 12:41:03 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\858239b41cc93dc03\dsetup32.dll
2011-10-26 12:40:59 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\81687adb1cc93dc02\DSETUP.dll
2011-10-26 12:40:59 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\81687adb1cc93dc02\DXSETUP.exe
2011-10-26 12:40:59 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\81687adb1cc93dc02\dsetup32.dll
2011-10-26 12:40:28 -------- d-----w- C:\Users\Chris\AppData\Local\Windows Live
2011-10-26 12:40:24 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-10-26 12:36:44 -------- d-----w- C:\Program Files\PeerBlock
2011-10-26 12:23:28 -------- d-----w- C:\Users\Chris\AppData\Roaming\Azureus
2011-10-26 12:22:57 -------- d-----w- C:\Program Files (x86)\Vuze
2011-10-26 12:22:07 -------- d-----w- C:\Windows\SysWow64\Adobe
2011-10-26 12:21:15 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-26 12:19:42 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-26 11:46:53 -------- d-----w- C:\Program Files\CCleaner
2011-10-26 11:36:27 -------- d--h--w- C:\$AVG
2011-10-26 10:39:32 -------- d-----w- C:\Windows\Panther
2011-10-26 02:33:53 -------- d-----w- C:\Program Files\Synaptics
2011-10-26 02:33:33 206120 ----a-w- C:\Windows\SysWow64\SynCtrl.dll
2011-10-26 02:33:33 169256 ----a-w- C:\Windows\SysWow64\SynCOM.dll
2011-10-26 02:33:33 147752 ----a-w- C:\Windows\System32\SynTPCo4.dll
2011-10-26 02:33:33 1436920 ----a-w- C:\Windows\System32\WdfCoInstaller01009.dll
2011-10-26 02:33:33 107816 ----a-w- C:\Windows\SysWow64\SynTPCOM.dll
2011-10-26 02:33:32 395048 ----a-w- C:\Windows\System32\SynCOM.dll
2011-10-26 02:33:32 273456 ----a-w- C:\Windows\System32\drivers\SynTP.sys
2011-10-26 02:33:32 260904 ----a-w- C:\Windows\System32\SynCtrl.dll
2011-10-26 02:33:32 203560 ----a-w- C:\Windows\System32\SynTPAPI.dll
2011-10-26 02:30:20 68608 ----a-w- C:\Windows\System32\AESTAR64.dll
2011-10-26 02:30:20 601088 ----a-w- C:\Windows\System32\ctapo64.dll
2011-10-26 02:30:20 524288 ----a-w- C:\Windows\System32\ctapo32.dll
2011-10-26 02:30:20 442368 ----a-w- C:\Windows\System32\AESTEC64.dll
2011-10-26 02:30:20 162304 ----a-w- C:\Windows\System32\AESTAC64.dll
2011-10-26 02:30:19 90624 ----a-w- C:\Windows\System32\AESTCo64.dll
2011-10-26 02:30:19 57856 ----a-w- C:\Windows\System32\ctppld64.dll
2011-10-26 02:30:19 564224 ----a-w- C:\Windows\System32\idt64mp1.exe
2011-10-26 02:30:19 3345408 ----a-w- C:\Windows\System32\stlang64.dll
2011-10-26 02:30:19 12605952 ----a-w- C:\Windows\System32\idtcpl64.cpl
2011-10-26 02:30:17 -------- d-----w- C:\Windows\System32\SRSLabs
2011-10-26 02:29:45 644608 ------w- C:\Windows\System32\stapi64.dll
2011-10-26 02:29:45 505856 ----a-w- C:\Windows\System32\drivers\stwrt64.sys
2011-10-26 02:29:45 431616 ----a-w- C:\Windows\System32\stcplx64.dll
2011-10-26 02:29:45 209920 ----a-w- C:\Windows\System32\st646272.dll
2011-10-26 02:29:45 1472000 ----a-w- C:\Windows\System32\stapo64.dll
2011-10-26 02:29:44 524288 ----a-w- C:\Windows\SysWow64\ctapo32.dll
2011-10-26 02:29:43 -------- d-----w- C:\Program Files\IDT
2011-10-26 02:26:02 -------- d-----w- C:\Program Files\Dell
2011-10-26 02:20:59 92216 ----a-w- C:\Windows\SysWow64\igfcg500m.bin
2011-10-26 02:18:20 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2011-10-26 02:16:58 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
2011-10-26 02:15:17 -------- d-----w- C:\Program Files (x86)\Dell
2011-10-26 02:14:14 -------- d-----w- C:\Users\Chris\AppData\Roaming\AVG2012
2011-10-26 02:13:40 -------- d-----w- C:\dell
2011-10-26 02:13:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2011-10-26 02:13:07 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-10-26 02:13:07 367616 ----a-w- C:\Windows\System32\atmfd.dll
2011-10-26 02:13:07 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-10-26 02:13:07 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-10-26 02:13:07 100864 ----a-w- C:\Windows\System32\fontsub.dll
2011-10-26 02:12:56 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-10-26 02:12:56 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-10-26 02:12:56 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-10-26 02:12:30 -------- d-----w- C:\Windows\SysWow64\drivers\AVG
2011-10-26 02:12:27 605552 ----a-w- C:\Windows\System32\winload.exe
2011-10-26 02:12:27 566208 ----a-w- C:\Windows\System32\winresume.efi
2011-10-26 02:12:26 642944 ----a-w- C:\Windows\System32\winload.efi
2011-10-26 02:12:26 518672 ----a-w- C:\Windows\System32\winresume.exe
2011-10-26 02:12:26 20352 ----a-w- C:\Windows\System32\kdusb.dll
2011-10-26 02:12:26 19328 ----a-w- C:\Windows\System32\kd1394.dll
2011-10-26 02:12:26 17792 ----a-w- C:\Windows\System32\kdcom.dll
2011-10-26 02:10:21 -------- d-----w- C:\Program Files (x86)\AVG
2011-10-26 02:09:48 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-10-26 02:09:47 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-10-26 02:09:47 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-10-26 02:09:07 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-10-26 02:09:02 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2594575D-C885-43D6-BEB1-315BA4297F57}\mpengine.dll
2011-10-26 02:06:41 -------- d-----w- C:\Users\Chris\AppData\Local\Google
2011-10-26 02:06:05 -------- d-----w- C:\Users\Chris\AppData\Local\Apps
2011-10-26 02:06:04 -------- d-----w- C:\Users\Chris\AppData\Local\Deployment
2011-10-26 02:04:27 -------- d-sh--w- C:\Windows\Installer
2011-10-26 02:04:16 -------- d--h--w- C:\ProgramData\Common Files
2011-10-26 02:04:04 -------- d-----w- C:\ProgramData\MFAData
2011-10-26 01:52:11 -------- d-----w- C:\Windows\SysWow64\Wat
2011-10-26 01:52:11 -------- d-----w- C:\Windows\System32\Wat
2011-10-26 01:51:05 -------- d-sh--w- C:\Recovery
.
==================== Find3M ====================
.
2011-10-26 01:52:27 14848 ----a-w- C:\Windows\System32\slwga.dll
2011-10-26 01:52:27 13824 ----a-w- C:\Windows\SysWow64\slwga.dll
2011-10-26 01:52:26 419840 ----a-w- C:\Windows\System32\systemcpl.dll
2011-10-26 01:52:26 1008640 ----a-w- C:\Windows\System32\user32.dll
2011-10-26 01:52:25 833024 ----a-w- C:\Windows\SysWow64\user32.dll
2011-09-13 05:30:08 37456 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
2011-09-06 03:03:17 3138048 ----a-w- C:\Windows\System32\win32k.sys
2011-08-27 05:37:49 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-08-27 05:37:48 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-08-27 04:26:27 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:26:27 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-08-08 05:08:58 46672 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
.
============= FINISH: 16:30:00.27 ===============