jchirch
2012-08-22, 05:55
Problem has plagued me for 6 days now. Spybot S&D clears it for a short time, then it reappears. The only other program I've tried was Hitman Pro--which did no good. (That was before I found this forum).
Registry is now backed up w/erunt.
DDS Log:
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by jack at 13:16:58 on 2012-08-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3319.1229 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\HitmanPro\hmpsched.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\OpenDNS Updater\OpenDNS Updater.exe
C:\Program Files\Macrium\Reflect\ReflectService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\system32\schtasks.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZtray.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHVA.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\Common Files\Triple Doppler Weather Warn\TrueWeather.exe
C:\Users\jack\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Users\jack\Documents\Desktop\aswMBR.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: LastPass Vault: {95d9ecf5-2a4d-4550-be49-70d42f71296e} - c:\program files\lastpass\LPToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - c:\program files\lastpass\LPToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [EPLTarget\P0000000000000001] c:\windows\system32\spool\drivers\w32x86\3\e_tatihva.exe /ept "epltarget\P0000000000000001" /M "WorkForce 645"
uRun: [Help] rundll32.exe "c:\users\jack\appdata\local\hewlett-packard\help\ssmqu.dll",CreateInstance
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_3_300_270_Plugin.exe -update plugin
mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [BackupNowEZtray] "c:\program files\nti\nti backup now ez\BackupNowEZtray.exe" -k
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRunOnce: [PCDrProfiler] "c:\program files\pc-doctor for windows\RunProfiler.exe" -r
dRun: [Help] rundll32.exe "c:\users\jack\appdata\local\hewlett-packard\help\ssmqu.dll",CreateInstance
StartupFolder: c:\users\jack\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\jack\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\jack\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\triple~1.lnk - c:\program files\common files\triple doppler weather warn\TrueWeather.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: LastPass - file://c:\users\jack\appdata\locallow\lastpass\context.html?cmd=lastpass
IE: LastPass Fill Forms - file://c:\users\jack\appdata\locallow\lastpass\context.html?cmd=fillforms
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - c:\program files\lastpass\LPToolbar.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
LSP: mswsock.dll
Trusted Zone: sagepub.com\online
Trusted Zone: taxactonline.com\www
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://site.ebrary.com/lib/mhebooks/support/plugins/ebraryRdr.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.caminova.net/en/downloads/getmodule.aspx?lang=en
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/e/38.09/f-6tcHDGwoY/uploader2.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://pfaff.webex.com/client/T27LD/webex/ieatgpc1.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{93724569-BC9A-43B9-978E-303B500EC209} : DhcpNameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jack\appdata\roaming\mozilla\firefox\profiles\rxw5wzzl.default\
FF - prefs.js: browser.startup.homepage - hxxp://news.google.com/nwshp?hl=en&tab=wn
FF - prefs.js: network.proxy.type - 0
FF - component: c:\users\jack\appdata\roaming\mozilla\firefox\profiles\rxw5wzzl.default\extensions\support@lastpass.com\platform\winnt_x86-msvc\components\lpxpcom.dll
FF - component: c:\users\jack\appdata\roaming\mozilla\firefox\profiles\rxw5wzzl.default\extensions\zoterowinwordintegration@zotero.org\components\zoteroWinWordIntegration.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-12 64160]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2012-6-12 16064]
R2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);c:\program files\common files\epson\epw!3 ssrp\E_JT50RP.EXE [2012-3-14 130944]
R2 HitmanProScheduler;HitmanPro Scheduler;c:\program files\hitmanpro\hmpsched.exe [2012-8-14 105832]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 NTI BackupNowEZSvr;NTI BackupNowEZSvr;c:\program files\nti\nti backup now ez\BackupNowEZSvr.exe [2011-9-23 45592]
R2 OpenDNS Updater.exe;OpenDNS Updater;c:\program files\opendns updater\opendns updater.exe --run --> c:\program files\opendns updater\OpenDNS Updater.exe --run [?]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
S2 CFUACProxy_boxsoftware;CFUACProxy_boxsoftware;"c:\programdata\clickfree\boxsoftware\uacproxy.exe" -s "-pc:\programdata\clickfree\boxsoftware" --> c:\programdata\clickfree\boxsoftware\UACProxy.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-25 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-7-14 250056]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2009-1-29 6016]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-3-25 136176]
S3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\drivers\motoandroid.sys [2009-7-10 25856]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2010-6-18 19968]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-1-29 8320]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2010-4-1 23424]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2010-6-18 23936]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2010-1-25 9472]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-3 113120]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 74112]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-3-26 214952]
S3 rsvcdwdr;rsvcdwdr;c:\windows\system32\drivers\rsvcdwdr.sys [2012-4-2 35944]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-5-24 52224]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2009-7-13 266752]
S4 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\common files\abbyy\finereadersprint\9.00\licensing\NetworkLicenseServer.exe [2009-5-14 759048]
S4 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\epson\epsoncustomerparticipation\EPCP.exe [2011-6-9 521600]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
.
=============== Created Last 30 ================
.
2012-08-20 21:51:11 6891424 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8664f8fd-464a-4543-a7b2-9f9162f75e03}\mpengine.dll
2012-08-18 21:44:14 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-08-18 21:44:06 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-08-17 03:22:00 6891424 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-08-15 01:16:53 12872 ----a-w- c:\windows\system32\bootdelete.exe
2012-08-14 23:56:46 -------- d-----w- c:\program files\HitmanPro
2012-08-14 23:54:17 -------- d-----w- c:\programdata\HitmanPro
2012-08-14 23:44:24 -------- d-----w- C:\!KillBox
2012-08-14 12:34:40 713784 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{4390017a-4e1e-4c5c-8c70-e589c9f2ba9d}\gapaengine.dll
2012-08-14 11:58:13 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-13 05:45:13 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-08-08 11:34:58 -------- d-----w- C:\TDSSKiller_Quarantine
2012-07-31 11:56:17 -------- d-----w- C:\Removable Disk
.
==================== Find3M ====================
.
2012-08-14 11:39:46 259072 ----a-w- c:\windows\system32\services.exe
2012-08-08 02:42:06 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-08 02:42:06 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-12 10:19:18 12992 ----a-w- c:\windows\system32\drivers\PSVolAcc.sys
2012-06-12 10:19:07 16064 ----a-w- c:\windows\system32\drivers\pssnap.sys
2012-06-12 10:19:01 53952 ----a-w- c:\windows\system32\drivers\psmounter.sys
2012-06-12 02:40:48 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-06-06 05:05:52 1390080 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- c:\windows\system32\cdosys.dll
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 08:33:25 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-06-02 04:45:04 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45:03 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40:59 369336 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 04:40:39 225280 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- c:\windows\system32\ncrypt.dll
.
============= FINISH: 13:19:17.38 ==============
asw MBR log:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-18 19:46:03
-----------------------------
19:46:03.809 OS Version: Windows 6.1.7601 Service Pack 1
19:46:03.810 Number of processors: 2 586 0xF0B
19:46:03.812 ComputerName: ISHTAR UserName: jack
19:46:05.390 Initialize success
19:52:20.624 AVAST engine defs: 12081801
19:53:43.583 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
19:53:43.587 Disk 0 Vendor: SAMSUNG_HD250HJ FH100-05 Size: 238475MB BusType: 3
19:53:43.662 Disk 0 MBR read successfully
19:53:43.665 Disk 0 MBR scan
19:53:43.764 Disk 0 Windows 7 default MBR code
19:53:43.770 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 228918 MB offset 63
19:53:43.854 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 9554 MB offset 468824895
19:53:43.876 Disk 0 scanning sectors +488392065
19:53:43.973 Disk 0 scanning C:\Windows\system32\drivers
19:54:07.039 Service scanning
19:54:30.832 Service MpKslce660a33 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C84E4C51-9A00-4863-8BC6-88AB31DDD7D0}\MpKslce660a33.sys **LOCKED** 32
19:54:54.951 Modules scanning
19:55:02.055 Disk 0 trace - called modules:
19:55:02.085 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys dxgmms1.sys
19:55:02.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8631b030]
19:55:02.103 3 CLASSPNP.SYS[8bdc859e] -> nt!IofCallDriver -> [0x85e77408]
19:55:02.112 5 ACPI.sys[8bac73d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85e78030]
19:55:02.819 AVAST engine scan C:\Windows
19:55:08.343 AVAST engine scan C:\Windows\system32
20:00:30.583 AVAST engine scan C:\Windows\system32\drivers
20:00:58.726 AVAST engine scan C:\Users\jack
20:07:06.013 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
20:07:06.128 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-18 19:46:03
-----------------------------
19:46:03.809 OS Version: Windows 6.1.7601 Service Pack 1
19:46:03.810 Number of processors: 2 586 0xF0B
19:46:03.812 ComputerName: ISHTAR UserName: jack
19:46:05.390 Initialize success
19:52:20.624 AVAST engine defs: 12081801
19:53:43.583 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
19:53:43.587 Disk 0 Vendor: SAMSUNG_HD250HJ FH100-05 Size: 238475MB BusType: 3
19:53:43.662 Disk 0 MBR read successfully
19:53:43.665 Disk 0 MBR scan
19:53:43.764 Disk 0 Windows 7 default MBR code
19:53:43.770 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 228918 MB offset 63
19:53:43.854 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 9554 MB offset 468824895
19:53:43.876 Disk 0 scanning sectors +488392065
19:53:43.973 Disk 0 scanning C:\Windows\system32\drivers
19:54:07.039 Service scanning
19:54:30.832 Service MpKslce660a33 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C84E4C51-9A00-4863-8BC6-88AB31DDD7D0}\MpKslce660a33.sys **LOCKED** 32
19:54:54.951 Modules scanning
19:55:02.055 Disk 0 trace - called modules:
19:55:02.085 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys dxgmms1.sys
19:55:02.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8631b030]
19:55:02.103 3 CLASSPNP.SYS[8bdc859e] -> nt!IofCallDriver -> [0x85e77408]
19:55:02.112 5 ACPI.sys[8bac73d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85e78030]
19:55:02.819 AVAST engine scan C:\Windows
19:55:08.343 AVAST engine scan C:\Windows\system32
20:00:30.583 AVAST engine scan C:\Windows\system32\drivers
20:00:58.726 AVAST engine scan C:\Users\jack
20:07:06.013 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
20:07:06.128 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
20:51:18.646 AVAST engine scan C:\ProgramData
20:54:04.982 Scan finished successfully
22:46:06.024 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
22:46:06.131 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-18 19:46:03
-----------------------------
19:46:03.809 OS Version: Windows 6.1.7601 Service Pack 1
19:46:03.810 Number of processors: 2 586 0xF0B
19:46:03.812 ComputerName: ISHTAR UserName: jack
19:46:05.390 Initialize success
19:52:20.624 AVAST engine defs: 12081801
19:53:43.583 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
19:53:43.587 Disk 0 Vendor: SAMSUNG_HD250HJ FH100-05 Size: 238475MB BusType: 3
19:53:43.662 Disk 0 MBR read successfully
19:53:43.665 Disk 0 MBR scan
19:53:43.764 Disk 0 Windows 7 default MBR code
19:53:43.770 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 228918 MB offset 63
19:53:43.854 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 9554 MB offset 468824895
19:53:43.876 Disk 0 scanning sectors +488392065
19:53:43.973 Disk 0 scanning C:\Windows\system32\drivers
19:54:07.039 Service scanning
19:54:30.832 Service MpKslce660a33 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C84E4C51-9A00-4863-8BC6-88AB31DDD7D0}\MpKslce660a33.sys **LOCKED** 32
19:54:54.951 Modules scanning
19:55:02.055 Disk 0 trace - called modules:
19:55:02.085 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys dxgmms1.sys
19:55:02.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8631b030]
19:55:02.103 3 CLASSPNP.SYS[8bdc859e] -> nt!IofCallDriver -> [0x85e77408]
19:55:02.112 5 ACPI.sys[8bac73d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85e78030]
19:55:02.819 AVAST engine scan C:\Windows
19:55:08.343 AVAST engine scan C:\Windows\system32
20:00:30.583 AVAST engine scan C:\Windows\system32\drivers
20:00:58.726 AVAST engine scan C:\Users\jack
20:07:06.013 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
20:07:06.128 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
20:51:18.646 AVAST engine scan C:\ProgramData
20:54:04.982 Scan finished successfully
22:46:06.024 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
22:46:06.131 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
22:44:49.056 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
22:44:49.385 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
Attach.zip is attached.
Thanks for any help you can give me. I'm a teacher, and I can't imagine working without Google searches.
Jack Chirch
Gloucester, VA
Registry is now backed up w/erunt.
DDS Log:
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by jack at 13:16:58 on 2012-08-21
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3319.1229 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\HitmanPro\hmpsched.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\OpenDNS Updater\OpenDNS Updater.exe
C:\Program Files\Macrium\Reflect\ReflectService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\system32\schtasks.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZtray.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHVA.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\Common Files\Triple Doppler Weather Warn\TrueWeather.exe
C:\Users\jack\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Users\jack\Documents\Desktop\aswMBR.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: LastPass Vault: {95d9ecf5-2a4d-4550-be49-70d42f71296e} - c:\program files\lastpass\LPToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - c:\program files\lastpass\LPToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [EPLTarget\P0000000000000001] c:\windows\system32\spool\drivers\w32x86\3\e_tatihva.exe /ept "epltarget\P0000000000000001" /M "WorkForce 645"
uRun: [Help] rundll32.exe "c:\users\jack\appdata\local\hewlett-packard\help\ssmqu.dll",CreateInstance
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_3_300_270_Plugin.exe -update plugin
mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [BackupNowEZtray] "c:\program files\nti\nti backup now ez\BackupNowEZtray.exe" -k
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRunOnce: [PCDrProfiler] "c:\program files\pc-doctor for windows\RunProfiler.exe" -r
dRun: [Help] rundll32.exe "c:\users\jack\appdata\local\hewlett-packard\help\ssmqu.dll",CreateInstance
StartupFolder: c:\users\jack\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\jack\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\jack\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\triple~1.lnk - c:\program files\common files\triple doppler weather warn\TrueWeather.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: LastPass - file://c:\users\jack\appdata\locallow\lastpass\context.html?cmd=lastpass
IE: LastPass Fill Forms - file://c:\users\jack\appdata\locallow\lastpass\context.html?cmd=fillforms
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - c:\program files\lastpass\LPToolbar.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
LSP: mswsock.dll
Trusted Zone: sagepub.com\online
Trusted Zone: taxactonline.com\www
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://site.ebrary.com/lib/mhebooks/support/plugins/ebraryRdr.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.caminova.net/en/downloads/getmodule.aspx?lang=en
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/e/38.09/f-6tcHDGwoY/uploader2.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://pfaff.webex.com/client/T27LD/webex/ieatgpc1.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{93724569-BC9A-43B9-978E-303B500EC209} : DhcpNameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jack\appdata\roaming\mozilla\firefox\profiles\rxw5wzzl.default\
FF - prefs.js: browser.startup.homepage - hxxp://news.google.com/nwshp?hl=en&tab=wn
FF - prefs.js: network.proxy.type - 0
FF - component: c:\users\jack\appdata\roaming\mozilla\firefox\profiles\rxw5wzzl.default\extensions\support@lastpass.com\platform\winnt_x86-msvc\components\lpxpcom.dll
FF - component: c:\users\jack\appdata\roaming\mozilla\firefox\profiles\rxw5wzzl.default\extensions\zoterowinwordintegration@zotero.org\components\zoteroWinWordIntegration.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-12 64160]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2012-6-12 16064]
R2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);c:\program files\common files\epson\epw!3 ssrp\E_JT50RP.EXE [2012-3-14 130944]
R2 HitmanProScheduler;HitmanPro Scheduler;c:\program files\hitmanpro\hmpsched.exe [2012-8-14 105832]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 NTI BackupNowEZSvr;NTI BackupNowEZSvr;c:\program files\nti\nti backup now ez\BackupNowEZSvr.exe [2011-9-23 45592]
R2 OpenDNS Updater.exe;OpenDNS Updater;c:\program files\opendns updater\opendns updater.exe --run --> c:\program files\opendns updater\OpenDNS Updater.exe --run [?]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
S2 CFUACProxy_boxsoftware;CFUACProxy_boxsoftware;"c:\programdata\clickfree\boxsoftware\uacproxy.exe" -s "-pc:\programdata\clickfree\boxsoftware" --> c:\programdata\clickfree\boxsoftware\UACProxy.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-25 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-7-14 250056]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2009-1-29 6016]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-3-25 136176]
S3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\drivers\motoandroid.sys [2009-7-10 25856]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2010-6-18 19968]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-1-29 8320]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2010-4-1 23424]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2010-6-18 23936]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2010-1-25 9472]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-3 113120]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 74112]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-3-26 214952]
S3 rsvcdwdr;rsvcdwdr;c:\windows\system32\drivers\rsvcdwdr.sys [2012-4-2 35944]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-5-24 52224]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2009-7-13 266752]
S4 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\common files\abbyy\finereadersprint\9.00\licensing\NetworkLicenseServer.exe [2009-5-14 759048]
S4 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\epson\epsoncustomerparticipation\EPCP.exe [2011-6-9 521600]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
.
=============== Created Last 30 ================
.
2012-08-20 21:51:11 6891424 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8664f8fd-464a-4543-a7b2-9f9162f75e03}\mpengine.dll
2012-08-18 21:44:14 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-08-18 21:44:06 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-08-17 03:22:00 6891424 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-08-15 01:16:53 12872 ----a-w- c:\windows\system32\bootdelete.exe
2012-08-14 23:56:46 -------- d-----w- c:\program files\HitmanPro
2012-08-14 23:54:17 -------- d-----w- c:\programdata\HitmanPro
2012-08-14 23:44:24 -------- d-----w- C:\!KillBox
2012-08-14 12:34:40 713784 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{4390017a-4e1e-4c5c-8c70-e589c9f2ba9d}\gapaengine.dll
2012-08-14 11:58:13 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-13 05:45:13 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-08-08 11:34:58 -------- d-----w- C:\TDSSKiller_Quarantine
2012-07-31 11:56:17 -------- d-----w- C:\Removable Disk
.
==================== Find3M ====================
.
2012-08-14 11:39:46 259072 ----a-w- c:\windows\system32\services.exe
2012-08-08 02:42:06 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-08 02:42:06 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-12 10:19:18 12992 ----a-w- c:\windows\system32\drivers\PSVolAcc.sys
2012-06-12 10:19:07 16064 ----a-w- c:\windows\system32\drivers\pssnap.sys
2012-06-12 10:19:01 53952 ----a-w- c:\windows\system32\drivers\psmounter.sys
2012-06-12 02:40:48 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-06-06 05:05:52 1390080 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- c:\windows\system32\cdosys.dll
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 08:33:25 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-06-02 04:45:04 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45:03 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40:59 369336 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 04:40:39 225280 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- c:\windows\system32\ncrypt.dll
.
============= FINISH: 13:19:17.38 ==============
asw MBR log:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-18 19:46:03
-----------------------------
19:46:03.809 OS Version: Windows 6.1.7601 Service Pack 1
19:46:03.810 Number of processors: 2 586 0xF0B
19:46:03.812 ComputerName: ISHTAR UserName: jack
19:46:05.390 Initialize success
19:52:20.624 AVAST engine defs: 12081801
19:53:43.583 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
19:53:43.587 Disk 0 Vendor: SAMSUNG_HD250HJ FH100-05 Size: 238475MB BusType: 3
19:53:43.662 Disk 0 MBR read successfully
19:53:43.665 Disk 0 MBR scan
19:53:43.764 Disk 0 Windows 7 default MBR code
19:53:43.770 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 228918 MB offset 63
19:53:43.854 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 9554 MB offset 468824895
19:53:43.876 Disk 0 scanning sectors +488392065
19:53:43.973 Disk 0 scanning C:\Windows\system32\drivers
19:54:07.039 Service scanning
19:54:30.832 Service MpKslce660a33 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C84E4C51-9A00-4863-8BC6-88AB31DDD7D0}\MpKslce660a33.sys **LOCKED** 32
19:54:54.951 Modules scanning
19:55:02.055 Disk 0 trace - called modules:
19:55:02.085 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys dxgmms1.sys
19:55:02.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8631b030]
19:55:02.103 3 CLASSPNP.SYS[8bdc859e] -> nt!IofCallDriver -> [0x85e77408]
19:55:02.112 5 ACPI.sys[8bac73d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85e78030]
19:55:02.819 AVAST engine scan C:\Windows
19:55:08.343 AVAST engine scan C:\Windows\system32
20:00:30.583 AVAST engine scan C:\Windows\system32\drivers
20:00:58.726 AVAST engine scan C:\Users\jack
20:07:06.013 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
20:07:06.128 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-18 19:46:03
-----------------------------
19:46:03.809 OS Version: Windows 6.1.7601 Service Pack 1
19:46:03.810 Number of processors: 2 586 0xF0B
19:46:03.812 ComputerName: ISHTAR UserName: jack
19:46:05.390 Initialize success
19:52:20.624 AVAST engine defs: 12081801
19:53:43.583 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
19:53:43.587 Disk 0 Vendor: SAMSUNG_HD250HJ FH100-05 Size: 238475MB BusType: 3
19:53:43.662 Disk 0 MBR read successfully
19:53:43.665 Disk 0 MBR scan
19:53:43.764 Disk 0 Windows 7 default MBR code
19:53:43.770 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 228918 MB offset 63
19:53:43.854 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 9554 MB offset 468824895
19:53:43.876 Disk 0 scanning sectors +488392065
19:53:43.973 Disk 0 scanning C:\Windows\system32\drivers
19:54:07.039 Service scanning
19:54:30.832 Service MpKslce660a33 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C84E4C51-9A00-4863-8BC6-88AB31DDD7D0}\MpKslce660a33.sys **LOCKED** 32
19:54:54.951 Modules scanning
19:55:02.055 Disk 0 trace - called modules:
19:55:02.085 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys dxgmms1.sys
19:55:02.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8631b030]
19:55:02.103 3 CLASSPNP.SYS[8bdc859e] -> nt!IofCallDriver -> [0x85e77408]
19:55:02.112 5 ACPI.sys[8bac73d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85e78030]
19:55:02.819 AVAST engine scan C:\Windows
19:55:08.343 AVAST engine scan C:\Windows\system32
20:00:30.583 AVAST engine scan C:\Windows\system32\drivers
20:00:58.726 AVAST engine scan C:\Users\jack
20:07:06.013 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
20:07:06.128 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
20:51:18.646 AVAST engine scan C:\ProgramData
20:54:04.982 Scan finished successfully
22:46:06.024 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
22:46:06.131 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-18 19:46:03
-----------------------------
19:46:03.809 OS Version: Windows 6.1.7601 Service Pack 1
19:46:03.810 Number of processors: 2 586 0xF0B
19:46:03.812 ComputerName: ISHTAR UserName: jack
19:46:05.390 Initialize success
19:52:20.624 AVAST engine defs: 12081801
19:53:43.583 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
19:53:43.587 Disk 0 Vendor: SAMSUNG_HD250HJ FH100-05 Size: 238475MB BusType: 3
19:53:43.662 Disk 0 MBR read successfully
19:53:43.665 Disk 0 MBR scan
19:53:43.764 Disk 0 Windows 7 default MBR code
19:53:43.770 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 228918 MB offset 63
19:53:43.854 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 9554 MB offset 468824895
19:53:43.876 Disk 0 scanning sectors +488392065
19:53:43.973 Disk 0 scanning C:\Windows\system32\drivers
19:54:07.039 Service scanning
19:54:30.832 Service MpKslce660a33 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C84E4C51-9A00-4863-8BC6-88AB31DDD7D0}\MpKslce660a33.sys **LOCKED** 32
19:54:54.951 Modules scanning
19:55:02.055 Disk 0 trace - called modules:
19:55:02.085 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys dxgmms1.sys
19:55:02.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8631b030]
19:55:02.103 3 CLASSPNP.SYS[8bdc859e] -> nt!IofCallDriver -> [0x85e77408]
19:55:02.112 5 ACPI.sys[8bac73d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85e78030]
19:55:02.819 AVAST engine scan C:\Windows
19:55:08.343 AVAST engine scan C:\Windows\system32
20:00:30.583 AVAST engine scan C:\Windows\system32\drivers
20:00:58.726 AVAST engine scan C:\Users\jack
20:07:06.013 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
20:07:06.128 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
20:51:18.646 AVAST engine scan C:\ProgramData
20:54:04.982 Scan finished successfully
22:46:06.024 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
22:46:06.131 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
22:44:49.056 Disk 0 MBR has been saved successfully to "C:\Users\jack\Documents\Desktop\MBR.dat"
22:44:49.385 The log file has been saved successfully to "C:\Users\jack\Documents\Desktop\aswMBR.txt"
Attach.zip is attached.
Thanks for any help you can give me. I'm a teacher, and I can't imagine working without Google searches.
Jack Chirch
Gloucester, VA