Results 1 to 3 of 3

Thread: Malware/Computer Problems

  1. #1
    Junior Member
    Join Date
    Dec 2011
    Posts
    1

    Default Malware/Computer Problems

    Unfortunately I do not keep up to date with my computer and running virus scans and such as much as I should. In recent weeks my laptop has been having extremely slow startups (like 10 minutes to startup), and I have detected some malware (specifically Opachki.ru trojan that I can't seem to remove with Spybot S&D). I figured that malware and other viruses may be slowing my entire system down, because I have countless programs that I've installed and basically my computer is a mess. Anyway, I was hoping I could get some help with removing any threats or potential threats. I did read the "before you post" thread, so I hope I'm not missing anything that it told me to do. Thanks in advance for your time and patience.

    DDS.txt
    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 8.0.6001.19154 BrowserJavaVersion: 1.6.0_26
    Run by Jon at 13:26:19 on 2011-12-03
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4092.1501 [GMT -6:00]
    .
    AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
    C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\STacSV64.exe
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\Hpservice.exe
    C:\Windows\system32\vfsFPService.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\AESTSr64.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\system32\lxdicoms.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
    C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
    C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
    C:\Windows\SMINST\BLService.exe
    C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
    C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files (x86)\DigitalPersona\Bin\x64\DPAgent.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
    C:\Program Files\IDT\WDM\sttray64.exe
    C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
    C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
    C:\Windows\ehome\ehtray.exe
    C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
    C:\Program Files (x86)\AVG Secure Search\vprot.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\SearchProtocolHost.exe
    c:\program files\windows defender\MpCmdRun.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = my.daemon-search.com
    uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uWindow Title = Windows Internet Explorer provided by Comcast
    mStart Page = hxxp://www.comcast.net/
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
    mWindow Title = Windows Internet Explorer provided by Comcast
    uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    mURLSearchHooks: H - No File
    mWinlogon: Userinit=userinit.exe
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
    BHO: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - No File
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
    BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    BHO: {BD08A9D5-0E5C-4f42-99A3-C0CB5E860557} - No File
    BHO: LimeWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    TB: LimeWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
    TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
    TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
    uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    uRun: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
    uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    uRun: [Google Update] "C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
    mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
    mRun: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe
    mRun: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
    mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    mRun: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [FaxCenterServer] "C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe" /s
    mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
    mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer
    mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DFXAudioPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DFXAudioPlugin.dll",DllRegisterServer
    mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll",DllRegisterServer
    mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll",DllRegisterServer
    mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer
    mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer
    mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer
    mRunOnce: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer
    dRunOnce: [<NO NAME>] OSK.exe
    StartupFolder: C:\Users\Jon\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files\Logitech\SetPoint\SetPoint.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOLREC~1.LNK - C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} - hxxp://www.acclaim.com/cabs/acclaim_v4.cab
    DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} - hxxp://www.playwhat.com/solidPlugin/solidstateion.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} - hxxp://www.webmap.niu.edu/campus/ACGM/Acgm.cab
    TCP: DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{2CC1F9B0-2B3C-4112-A992-FA5EB299B05F} : DhcpNameServer = 192.168.1.1
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    LSA: Notification Packages = scecli DPPWDFLT
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
    BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    BHO-X64: 0x1 - No File
    BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    BHO-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
    BHO-X64: Conduit Engine - No File
    BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
    BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
    BHO-X64: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - No File
    BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
    BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
    BHO-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    BHO-X64: Vuze Remote - No File
    BHO-X64: {BD08A9D5-0E5C-4f42-99A3-C0CB5E860557} - No File
    BHO-X64: Solid State Networks IE Browser Plugin - No File
    BHO-X64: LimeWire Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    BHO-X64: Ask Toolbar BHO - No File
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    BHO-X64: HP Smart BHO Class - No File
    TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    TB-X64: LimeWire Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    TB-X64: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll
    TB-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
    TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
    TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
    TB-X64: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
    mRun-x64: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
    mRun-x64: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe
    mRun-x64: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
    mRun-x64: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    mRun-x64: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [FaxCenterServer] "C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe" /s
    mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
    mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
    mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRunOnce-x64: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer
    mRunOnce-x64: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DFXAudioPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DFXAudioPlugin.dll",DllRegisterServer
    mRunOnce-x64: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll",DllRegisterServer
    mRunOnce-x64: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll",DllRegisterServer
    mRunOnce-x64: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer
    mRunOnce-x64: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer
    mRunOnce-x64: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer
    mRunOnce-x64: [B Register C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer
    IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\35j857r7.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
    FF - prefs.js: browser.search.selectedEngine - DAEMON Search
    FF - prefs.js: browser.startup.homepage - hxxp://my.daemon-search.com/|http://flvtubesearch.co/?tmp=toolbar...58d04a3&subid=
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
    FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
    FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
    R0 Lbd;Lbd;C:\Windows\system32\DRIVERS\Lbd.sys --> C:\Windows\system32\DRIVERS\Lbd.sys [?]
    R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
    R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\system32\Drivers\SmartDefragDriver.sys --> C:\Windows\system32\Drivers\SmartDefragDriver.sys [?]
    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
    R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
    R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
    R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\AESTSr64.exe --> C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\AESTSr64.exe [?]
    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776]
    R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-8-18 2152152]
    R2 lxdi_device;lxdi_device;C:\Windows\system32\lxdicoms.exe -service --> C:\Windows\system32\lxdicoms.exe -service [?]
    R2 Recovery Service for Windows;Recovery Service for Windows;C:\Windows\SMINST\BLService.exe [2008-7-1 341328]
    R2 vfsFPService;Validity Fingerprint Service;C:\Windows\System32\vfsFPService.exe [2008-3-26 595248]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe [2008-8-12 24652]
    R2 vToolbarUpdater;vToolbarUpdater;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-9-19 246600]
    R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
    R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
    R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-7-1 193840]
    R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys --> C:\Windows\system32\DRIVERS\enecir.sys [?]
    R3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
    R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-10-17 17152]
    R3 NETwNv64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\NETwNv64.sys --> C:\Windows\system32\DRIVERS\NETwNv64.sys [?]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
    R3 vfs101a;vfs101a;C:\Windows\system32\drivers\vfs101a.sys --> C:\Windows\system32\drivers\vfs101a.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-4-13 135664]
    S2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;C:\Windows\System32\spool\drivers\x64\3\lxdiserv.exe [2007-4-26 33712]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-4-13 135664]
    S3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;C:\Windows\system32\DRIVERS\NETw5v64.sys --> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
    S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
    S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
    S3 Point64;Microsoft IntelliPoint Filter Driver;C:\Windows\system32\DRIVERS\point64k.sys --> C:\Windows\system32\DRIVERS\point64k.sys [?]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
    S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-8-18 89920]
    .
    =============== File Associations ===============
    .
    JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
    .
    =============== Created Last 30 ================
    .
    2011-12-03 19:06:28 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5CAC50C5-628D-4BEE-BCFD-00C4EEC80FC1}\offreg.dll
    2011-12-03 19:06:26 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5CAC50C5-628D-4BEE-BCFD-00C4EEC80FC1}\mpengine.dll
    2011-12-03 18:13:46 -------- d-----w- C:\Users\Jon\AppData\Local\{A05EF2E3-D94E-401A-ABA0-759ECD794023}
    2011-12-03 18:13:13 -------- d-----w- C:\Users\Jon\AppData\Local\{5D5B72F8-A6AF-4160-A5D3-418FD68A09FC}
    2011-12-02 23:45:44 -------- d-----w- C:\Users\Jon\AppData\Local\{FD54D50C-2956-4E8C-9DA7-01BE5B0A9236}
    2011-12-02 23:45:22 -------- d-----w- C:\Users\Jon\AppData\Local\{9F6F6CFE-C95D-4E97-9813-EDE620042A64}
    2011-12-02 11:45:11 -------- d-----w- C:\Users\Jon\AppData\Local\{7A4D873D-E193-4B03-BE97-83755B96BCB9}
    2011-12-02 11:44:50 -------- d-----w- C:\Users\Jon\AppData\Local\{E2828D91-5C5B-45AA-8772-2B3F34633B5D}
    2011-12-01 23:44:38 -------- d-----w- C:\Users\Jon\AppData\Local\{DAFEF29C-C78C-4C91-80D5-709747523CDE}
    2011-12-01 23:44:16 -------- d-----w- C:\Users\Jon\AppData\Local\{3981E060-92D3-4397-A3F4-3C3C527ED06E}
    2011-12-01 11:44:05 -------- d-----w- C:\Users\Jon\AppData\Local\{E2CC8EF2-707B-4425-A0AE-F45863F0A35B}
    2011-12-01 11:43:43 -------- d-----w- C:\Users\Jon\AppData\Local\{3355F48C-3769-4341-8F0F-B96595B4424C}
    2011-11-30 23:43:30 -------- d-----w- C:\Users\Jon\AppData\Local\{91CF9F3C-C23A-48D6-A64F-528B0E38882C}
    2011-11-30 23:43:09 -------- d-----w- C:\Users\Jon\AppData\Local\{54B0C0FD-E372-4B91-8012-3AE0E4183758}
    2011-11-30 19:41:17 -------- d-----w- C:\Users\Jon\AppData\Roaming\Tibiacast
    2011-11-30 11:42:58 -------- d-----w- C:\Users\Jon\AppData\Local\{2316882D-63DA-43E6-AE44-A6BE83F3394A}
    2011-11-30 11:42:37 -------- d-----w- C:\Users\Jon\AppData\Local\{94056EFA-F177-4A00-8642-C549DEE485EC}
    2011-11-29 23:42:25 -------- d-----w- C:\Users\Jon\AppData\Local\{3FA557F6-759B-4E84-9619-4F71385C6162}
    2011-11-29 23:42:03 -------- d-----w- C:\Users\Jon\AppData\Local\{5D4DEBFF-9CCE-4FEA-A69F-D8922C0F5433}
    2011-11-29 11:41:52 -------- d-----w- C:\Users\Jon\AppData\Local\{500F31CA-586B-4947-A286-F0B101EB33F7}
    2011-11-29 11:41:30 -------- d-----w- C:\Users\Jon\AppData\Local\{117116BB-C214-4DC0-A8A2-055B38FDF1E8}
    2011-11-28 23:41:18 -------- d-----w- C:\Users\Jon\AppData\Local\{494F7B98-1852-4CC8-9D4D-75339E167589}
    2011-11-28 23:40:56 -------- d-----w- C:\Users\Jon\AppData\Local\{9CE6038E-6364-406F-BF37-6F8DCB6373F0}
    2011-11-28 11:40:44 -------- d-----w- C:\Users\Jon\AppData\Local\{04CBD559-7C77-4528-BA67-879FA9BEF6A7}
    2011-11-28 11:40:24 -------- d-----w- C:\Users\Jon\AppData\Local\{4BBB3022-E5B3-488E-99FD-4BF49CE93BF8}
    2011-11-28 01:06:34 654928 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
    2011-11-28 01:06:34 42064 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
    2011-11-28 01:06:34 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
    2011-11-28 01:04:51 -------- d-----w- C:\Program Files\Microsoft IntelliPoint
    2011-11-28 01:02:10 -------- d-----w- C:\Program Files\Microsoft IntelliType Pro
    2011-11-27 23:39:51 -------- d-----w- C:\Users\Jon\AppData\Local\{01DA8DAA-FB27-45A6-AB2D-8C96864B5C69}
    2011-11-27 23:36:12 -------- d-----w- C:\Users\Jon\AppData\Local\{5E90309E-D1CA-48F6-80B1-E1CCEE3F2BFC}
    2011-11-26 19:51:31 -------- d-----w- C:\Users\Jon\AppData\Local\{FBC14CBA-708D-4E6B-8EE8-05A56AF3FFE4}
    2011-11-26 19:50:26 -------- d-----w- C:\Users\Jon\AppData\Local\{2135AD44-EE1A-4D35-B1BE-19DB67286AC8}
    2011-11-26 07:50:06 -------- d-----w- C:\Users\Jon\AppData\Local\{028DB259-DD64-4402-82A7-71AE0CC473D2}
    2011-11-26 07:49:47 -------- d-----w- C:\Users\Jon\AppData\Local\{39DDD8A6-6B92-40F9-862A-4E48DA1B333F}
    2011-11-25 19:49:09 -------- d-----w- C:\Users\Jon\AppData\Local\{007EFFD6-CFAA-4087-8360-01B3F5A9B794}
    2011-11-25 19:48:44 -------- d-----w- C:\Users\Jon\AppData\Local\{7FCD1CB6-78D1-49E5-B8CB-F95B2F435C3F}
    2011-11-22 02:16:24 -------- d-----w- C:\Users\Jon\AppData\Local\Skyrim
    2011-11-22 01:54:56 5425496 ----a-w- C:\Windows\System32\D3DX9_41.dll
    2011-11-22 01:53:59 409960 ----a-w- C:\Windows\System32\xactengine2_8.dll
    2011-11-21 19:35:47 -------- d-----w- C:\Users\Jon\AppData\Local\{E30AEEC7-444E-4B86-8BF0-C26D1309C3D0}
    2011-11-21 19:35:24 -------- d-----w- C:\Users\Jon\AppData\Local\{22AF8FF6-5FE3-4209-B64E-496A4DC10BB2}
    2011-11-21 07:00:50 -------- d-----w- C:\Users\Jon\AppData\Local\{D80C0CAA-FE7C-405C-9F5D-B95986BAB32E}
    2011-11-21 07:00:29 -------- d-----w- C:\Users\Jon\AppData\Local\{F937856E-786A-4950-8866-79272221F99F}
    2011-11-20 19:00:17 -------- d-----w- C:\Users\Jon\AppData\Local\{2FCC5F10-0DEC-4DCA-8B5B-574EAD78832C}
    2011-11-20 18:59:55 -------- d-----w- C:\Users\Jon\AppData\Local\{5A25B822-1FE2-4BCF-B987-3BC475451D5E}
    2011-11-20 06:59:42 -------- d-----w- C:\Users\Jon\AppData\Local\{AC3B020C-56D2-47E7-8267-7EC185DB6F1E}
    2011-11-20 06:59:21 -------- d-----w- C:\Users\Jon\AppData\Local\{E0A616AC-FCC5-4CCE-AACB-A0303EB76230}
    2011-11-19 18:59:09 -------- d-----w- C:\Users\Jon\AppData\Local\{0738E520-5636-4537-BDE6-0DC685403ECD}
    2011-11-19 18:58:48 -------- d-----w- C:\Users\Jon\AppData\Local\{C9FDBA2E-BBCD-4738-BDB6-A28378FC2131}
    2011-11-19 06:58:36 -------- d-----w- C:\Users\Jon\AppData\Local\{913E3F95-4C9F-42BC-8D87-46B518E54F3A}
    2011-11-19 06:58:14 -------- d-----w- C:\Users\Jon\AppData\Local\{4CB9D097-20F8-4562-B9C4-2D21797C2C11}
    2011-11-18 18:58:01 -------- d-----w- C:\Users\Jon\AppData\Local\{A99DF582-4BEB-46C3-8FC6-B42443BAE66B}
    2011-11-18 18:57:39 -------- d-----w- C:\Users\Jon\AppData\Local\{D59C978F-0603-4780-BAD7-52D14CAEC494}
    2011-11-18 06:57:27 -------- d-----w- C:\Users\Jon\AppData\Local\{9F644063-AF41-41DE-B108-B87119768C15}
    2011-11-18 06:57:05 -------- d-----w- C:\Users\Jon\AppData\Local\{4FD453D8-E70E-4F45-A79C-24C4253EF6C3}
    2011-11-17 18:56:53 -------- d-----w- C:\Users\Jon\AppData\Local\{232A2D63-133B-4E57-BDEB-B44B87B072ED}
    2011-11-17 18:56:32 -------- d-----w- C:\Users\Jon\AppData\Local\{75486AF6-01EB-4A6D-B9EE-15185EF56A23}
    2011-11-15 15:04:34 -------- d-----w- C:\Users\Jon\AppData\Local\{02E37102-FC97-4EB3-9BA6-1101E7260999}
    2011-11-15 15:04:13 -------- d-----w- C:\Users\Jon\AppData\Local\{CA7617E1-7DE6-485E-AF4C-8A32B0FD5B8E}
    2011-11-15 03:04:01 -------- d-----w- C:\Users\Jon\AppData\Local\{1C036A46-552A-4B5B-BBEB-BF1908135E40}
    2011-11-15 03:03:39 -------- d-----w- C:\Users\Jon\AppData\Local\{513EC047-41C2-4947-ACCF-E45A7C32934E}
    2011-11-14 15:03:28 -------- d-----w- C:\Users\Jon\AppData\Local\{257A69A2-C964-4B11-BD90-A651C67EC0B3}
    2011-11-14 15:03:06 -------- d-----w- C:\Users\Jon\AppData\Local\{FAA468E3-9A79-421A-A4B0-848A90DD3333}
    2011-11-14 03:01:54 -------- d-----w- C:\Users\Jon\AppData\Local\{EBE5A68B-36EC-4155-BD2B-A43A5804B7CE}
    2011-11-14 03:00:43 -------- d-----w- C:\Users\Jon\AppData\Local\{F1533D84-7F5C-46DF-8211-979407B9DA4F}
    2011-11-13 15:00:32 -------- d-----w- C:\Users\Jon\AppData\Local\{74144813-21E2-4D1B-8192-E2AD76F60ABB}
    2011-11-13 15:00:10 -------- d-----w- C:\Users\Jon\AppData\Local\{F89BFFB7-8048-4ACD-B8DD-0CF931D9EA5C}
    2011-11-13 02:59:58 -------- d-----w- C:\Users\Jon\AppData\Local\{206861E6-8FCD-449B-8E7D-F60A7373BAC4}
    2011-11-13 02:59:36 -------- d-----w- C:\Users\Jon\AppData\Local\{2B2AFBE7-FBC5-445E-ABB5-9BFFCA73027A}
    2011-11-12 15:01:34 -------- d-----w- C:\Users\Jon\AppData\Local\{1472C4DA-3F42-48B1-85C5-C9D4D93F4626}
    2011-11-12 03:01:22 -------- d-----w- C:\Users\Jon\AppData\Local\{19832597-4D7D-442F-8580-8E2FB4F70B8D}
    2011-11-12 03:01:00 -------- d-----w- C:\Users\Jon\AppData\Local\{01EB6B6A-2449-4DFD-9027-986883CE914C}
    2011-11-11 15:00:49 -------- d-----w- C:\Users\Jon\AppData\Local\{12B1A95B-A484-4B68-BEBD-C4C057206AEF}
    2011-11-11 15:00:28 -------- d-----w- C:\Users\Jon\AppData\Local\{26B0F1EF-83FC-4C5F-A864-B8F9996C9EF7}
    2011-11-11 03:00:15 -------- d-----w- C:\Users\Jon\AppData\Local\{42D07167-AA70-41A5-850B-01CF95C9F621}
    2011-11-11 02:59:54 -------- d-----w- C:\Users\Jon\AppData\Local\{BEB1A28A-8FAA-4F5E-B5AA-9053483ED2F6}
    2011-11-10 14:59:41 -------- d-----w- C:\Users\Jon\AppData\Local\{6F78696D-B62E-4492-B3CD-4223168A2460}
    2011-11-10 14:59:19 -------- d-----w- C:\Users\Jon\AppData\Local\{61AC96E6-38EE-40E4-81EF-CA5BDF89CAE0}
    2011-11-10 02:57:25 -------- d-----w- C:\Users\Jon\AppData\Local\{3E51428C-55AB-4C95-B0C8-B92B63D8D2AE}
    2011-11-10 02:57:02 -------- d-----w- C:\Users\Jon\AppData\Local\{6A16CF37-5030-47B7-8F04-97B522239B01}
    2011-11-09 14:56:51 -------- d-----w- C:\Users\Jon\AppData\Local\{98C7DEC4-19DF-4143-A7E2-005D3441328F}
    2011-11-09 14:56:29 -------- d-----w- C:\Users\Jon\AppData\Local\{AE7ADCCD-E8B5-430A-9418-C37420B7D8CF}
    2011-11-09 12:55:52 1426304 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2011-11-09 12:55:48 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
    2011-11-09 12:55:48 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
    2011-11-09 12:55:38 893440 ----a-w- C:\Program Files\Common Files\System\wab32.dll
    2011-11-09 12:55:38 707584 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
    2011-11-09 12:55:38 50688 ----a-w- C:\Program Files\Windows Mail\wabimp.dll
    2011-11-09 02:56:17 -------- d-----w- C:\Users\Jon\AppData\Local\{427494A3-EA62-4185-B89A-E5E0B72458D2}
    2011-11-09 02:55:55 -------- d-----w- C:\Users\Jon\AppData\Local\{CCDC42A7-395F-442A-AB97-208CEE240978}
    2011-11-08 14:55:40 -------- d-----w- C:\Users\Jon\AppData\Local\{642B16C6-F1DA-4680-AE07-A82433E57FFA}
    2011-11-08 14:55:18 -------- d-----w- C:\Users\Jon\AppData\Local\{A2E866F6-523A-4166-92DF-C6CE7AF1C2FA}
    2011-11-08 02:54:36 -------- d-----w- C:\Users\Jon\AppData\Local\{51245FF2-8C74-469E-9305-09068708BCF6}
    2011-11-08 02:54:07 -------- d-----w- C:\Users\Jon\AppData\Local\{A5026119-43AE-4AAD-86D2-EB04D7286A73}
    2011-11-08 02:53:33 -------- d-----w- C:\Windows\en
    2011-11-08 02:51:00 18328 ----a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    .
    ==================== Find3M ====================
    .
    2011-10-17 20:53:13 55384 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys
    2011-10-17 20:53:11 16432 ----a-w- C:\Windows\System32\lsdelete.exe
    2011-10-07 11:23:46 283728 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
    2011-10-01 21:01:29 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-09-30 23:25:35 1147904 ----a-w- C:\Windows\System32\wininet.dll
    2011-09-30 23:21:20 56832 ----a-w- C:\Windows\System32\licmgr10.dll
    2011-09-30 23:21:00 1538560 ----a-w- C:\Windows\System32\inetcpl.cpl
    2011-09-30 23:20:40 132096 ----a-w- C:\Windows\System32\iesysprep.dll
    2011-09-30 23:20:39 77312 ----a-w- C:\Windows\System32\iesetup.dll
    2011-09-30 23:06:24 916480 ----a-w- C:\Windows\SysWow64\wininet.dll
    2011-09-30 23:02:06 43520 ----a-w- C:\Windows\SysWow64\licmgr10.dll
    2011-09-30 23:01:51 1469440 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2011-09-30 23:01:34 71680 ----a-w- C:\Windows\SysWow64\iesetup.dll
    2011-09-30 23:01:34 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
    2011-09-30 22:29:23 479232 ----a-w- C:\Windows\System32\html.iec
    2011-09-30 22:07:25 385024 ----a-w- C:\Windows\SysWow64\html.iec
    2011-09-30 21:48:19 162816 ----a-w- C:\Windows\System32\ieUnatt.exe
    2011-09-30 21:47:04 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
    2011-09-30 21:29:54 133632 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2011-09-30 21:28:36 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2011-09-13 11:30:08 37456 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
    2011-09-06 13:56:50 2764288 ----a-w- C:\Windows\System32\win32k.sys
    .
    ============= FINISH: 13:28:40.35 ===============

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.


    LimeWire
    Vuze
    Vuze Remote Toolbar


    I'd like you to read this thread.

    Uninstall the programs listed above (in red) + Ask Toolbar that got installed with Limewire.

    When done, post fresh dds logs.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Due to inactivity, this thread will now be closed.

    Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

    If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •