I have read "BEFORE you POST" instructions.
I have tried everything to remove Conduit. So now I am here.
1). Here is the DDS Log:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by Rob Caldwell at 15:43:56 on 2012-07-26
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3573.1589 [GMT -4:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
C:\Users\Rob Caldwell\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\HMA! Pro VPN\bin\HMA! Pro VPN.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Tweet Adder 3\TweetAdder3.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\FileZilla FTP Client\filezilla.exe
C:\Program Files\HMA! Pro VPN\bin\openvpnserv.exe
C:\Program Files\HMA! Pro VPN\bin\openvpn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uWindow Title = Internet Explorer provided by Dell
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {9D0F7EB2-452D-4766-B535-8D23E36C300E} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [iCloudServices] c:\program files\common files\apple\internet services\iCloudServices.exe
uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil11e_Plugin.exe -update plugin
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [MS Word Extract Email Addresses From Documents Software.exe]
StartupFolder: c:\users\robcal~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\rob caldwell\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\robcal~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\users\robcal~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\hmapro~1.lnk - c:\program files\hma! pro vpn\bin\HMA! Pro VPN.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 208.67.222.222 208.67.220.220
TCP: Interfaces\{198900CA-A070-4EDA-8188-257334FEFBBE} : DhcpNameServer = 216.136.95.2 64.132.94.250 8.8.8.8
TCP: Interfaces\{2EA65902-CA22-4DE2-8E45-5E441FE41949} : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{873AD3DD-6988-42D0-977C-742927A8EE92} : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{FE0B6538-7289-4A7B-A423-6DC932A236D7} : DhcpNameServer = 208.67.222.222 208.67.220.220
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\rob caldwell\appdata\roaming\mozilla\firefox\profiles\jhvud1s7.default\
FF - prefs.js: browser.startup.homepage - hxxp://drudgereport.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\rob caldwell\appdata\roaming\mozilla\firefox\profiles\jhvud1s7.default\extensions\{9d0f7eb2-452d-4766-b535-8d23e36c300e}\plugins\np-mswmp.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113959&tt=2912_4
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - c041301e000000000000001a73afe439
FF - user.js: extensions.BabylonToolbar_i.hardId - c041301e000000000000001a73afe439
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15541
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:00:44
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-7-10 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-7-10 353688]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-7-10 21256]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-7-10 57656]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-7-10 44808]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-23 21504]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-8-12 1153368]
R3 BackLogAFK;BackLogA Keyboard Class Upper Filter Driver;c:\windows\system32\drivers\BackLogAFK.sys [2010-3-22 12800]
R3 BackLogAFM;BackLogA Mouse Class Upper Filter Driver;c:\windows\system32\drivers\BackLogAFM.sys [2010-3-22 12288]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-10-21 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-10-21 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-26 113120]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-9-23 16896]
.
=============== Created Last 30 ================
.
2012-07-26 19:09:47 -------- d-----w- c:\users\rob caldwell\appdata\roaming\DriverCure
2012-07-26 19:09:46 -------- d-----w- c:\users\rob caldwell\appdata\roaming\ParetoLogic
2012-07-26 19:09:33 -------- d-----w- c:\programdata\ParetoLogic
2012-07-26 19:09:33 -------- d-----w- c:\program files\ParetoLogic
2012-07-26 05:58:21 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{0e24d655-f31e-4aa0-8227-cfc945ed8b85}\offreg.dll
2012-07-25 18:43:18 -------- d-----w- c:\users\rob caldwell\appdata\local\Conduit
2012-07-24 12:07:47 -------- d-----w- c:\program files\HMA! Pro VPN
2012-07-24 05:59:26 6891424 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{0e24d655-f31e-4aa0-8227-cfc945ed8b85}\mpengine.dll
2012-07-20 20:03:14 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2012-07-20 20:03:14 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2012-07-20 20:03:12 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2012-07-20 20:03:12 -------- d-----w- c:\program files\PDFCreator
2012-07-20 14:44:22 -------- d-----w- c:\users\rob caldwell\appdata\roaming\Nvu
2012-07-18 18:20:24 -------- d-----w- c:\programdata\Magic Submitter
2012-07-18 18:20:24 -------- d-----w- c:\program files\Alexandr Krulik
2012-07-15 19:17:12 -------- d-----w- c:\program files\Tweet Adder 3
2012-07-11 17:08:14 -------- d-----w- c:\program files\OnlyWire
2012-07-11 13:02:05 -------- d-----w- c:\users\rob caldwell\appdata\local\Seesmic
2012-07-11 13:01:05 -------- d-----w- c:\program files\Seesmic Ping
2012-07-11 07:08:07 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-07-10 23:05:23 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-07-10 23:05:22 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-07-10 23:05:22 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-07-10 23:05:14 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2012-07-10 23:04:15 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-10 23:04:14 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-10 23:04:13 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-10 23:04:13 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-10 23:04:13 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-08 19:02:21 -------- d-----w- c:\users\rob caldwell\appdata\roaming\TweetAdder3
2012-07-05 16:53:46 -------- d-----w- c:\program files\MS Word Extract Email Addresses From Documents Software
.
==================== Find3M ====================
.
2012-07-03 16:21:53 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21:53 57656 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21:32 41224 ----a-w- c:\windows\avastSS.scr
2012-06-23 14:44:09 286720 ------w- c:\windows\Setup1.exe
2012-06-08 14:58:52 1110476 ----a-w- c:\users\rob caldwell\7z920.exe
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 08:33:25 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-31 16:25:14 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-05-01 14:03:49 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 15:44:31.11 ===============
2). I am not sure why I have to Zip the ATTACH file as it is only 9kb and I do not have a ZIP program.
3). Here is the aswMBR Log:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-26 15:52:23
-----------------------------
15:52:23.316 OS Version: Windows 6.0.6002 Service Pack 2
15:52:23.316 Number of processors: 2 586 0xF0D
15:52:23.318 ComputerName: ROBCALDWELL-PC UserName: Rob Caldwell
15:52:33.352 Initialize success
15:52:33.437 AVAST engine defs: 12072601
15:53:02.022 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
15:53:02.025 Disk 0 Vendor: Hitachi_ SB2O Size: 76319MB BusType: 3
15:53:02.050 Disk 0 MBR read successfully
15:53:02.053 Disk 0 MBR scan
15:53:02.058 Disk 0 Windows VISTA default MBR code
15:53:02.063 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 78 MB offset 63
15:53:02.076 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 161792
15:53:02.094 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 63439 MB offset 21133312
15:53:02.099 Disk 0 Partition - 00 0F Extended LBA 2560 MB offset 151056384
15:53:02.136 Disk 0 Partition 4 00 DD MSDOS5.0 2559 MB offset 151058432
15:53:02.144 Disk 0 scanning sectors +156299264
15:53:02.207 Disk 0 scanning C:\Windows\system32\drivers
15:53:14.734 Service scanning
15:53:39.875 Modules scanning
15:53:49.505 Disk 0 trace - called modules:
15:53:49.578 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
15:53:49.585 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f98780]
15:53:49.592 3 CLASSPNP.SYS[8c7a68b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x86495030]
15:53:50.120 AVAST engine scan C:\Windows
15:53:52.801 AVAST engine scan C:\Windows\system32
15:56:24.670 AVAST engine scan C:\Windows\system32\drivers
15:56:45.545 AVAST engine scan C:\Users\Rob Caldwell
16:03:56.010 AVAST engine scan C:\ProgramData
16:06:49.729 Scan finished successfully
16:09:32.179 Disk 0 MBR has been saved successfully to "C:\Users\Rob Caldwell\Desktop\Utility Programs\Virus Files\MBR.dat"
16:09:32.186 The log file has been saved successfully to "C:\Users\Rob Caldwell\Desktop\Utility Programs\Virus Files\aswMBR.txt"
Thank you in advance for your help!
Rob Caldwell
I have tried everything to remove Conduit. So now I am here.
1). Here is the DDS Log:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by Rob Caldwell at 15:43:56 on 2012-07-26
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3573.1589 [GMT -4:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
C:\Users\Rob Caldwell\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\HMA! Pro VPN\bin\HMA! Pro VPN.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Tweet Adder 3\TweetAdder3.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\FileZilla FTP Client\filezilla.exe
C:\Program Files\HMA! Pro VPN\bin\openvpnserv.exe
C:\Program Files\HMA! Pro VPN\bin\openvpn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uWindow Title = Internet Explorer provided by Dell
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {9D0F7EB2-452D-4766-B535-8D23E36C300E} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [iCloudServices] c:\program files\common files\apple\internet services\iCloudServices.exe
uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil11e_Plugin.exe -update plugin
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [MS Word Extract Email Addresses From Documents Software.exe]
StartupFolder: c:\users\robcal~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\rob caldwell\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\robcal~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\users\robcal~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\hmapro~1.lnk - c:\program files\hma! pro vpn\bin\HMA! Pro VPN.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 208.67.222.222 208.67.220.220
TCP: Interfaces\{198900CA-A070-4EDA-8188-257334FEFBBE} : DhcpNameServer = 216.136.95.2 64.132.94.250 8.8.8.8
TCP: Interfaces\{2EA65902-CA22-4DE2-8E45-5E441FE41949} : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{873AD3DD-6988-42D0-977C-742927A8EE92} : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{FE0B6538-7289-4A7B-A423-6DC932A236D7} : DhcpNameServer = 208.67.222.222 208.67.220.220
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\rob caldwell\appdata\roaming\mozilla\firefox\profiles\jhvud1s7.default\
FF - prefs.js: browser.startup.homepage - hxxp://drudgereport.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\rob caldwell\appdata\roaming\mozilla\firefox\profiles\jhvud1s7.default\extensions\{9d0f7eb2-452d-4766-b535-8d23e36c300e}\plugins\np-mswmp.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113959&tt=2912_4
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - c041301e000000000000001a73afe439
FF - user.js: extensions.BabylonToolbar_i.hardId - c041301e000000000000001a73afe439
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15541
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:00:44
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-7-10 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-7-10 353688]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-7-10 21256]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-7-10 57656]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-7-10 44808]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-23 21504]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-8-12 1153368]
R3 BackLogAFK;BackLogA Keyboard Class Upper Filter Driver;c:\windows\system32\drivers\BackLogAFK.sys [2010-3-22 12800]
R3 BackLogAFM;BackLogA Mouse Class Upper Filter Driver;c:\windows\system32\drivers\BackLogAFM.sys [2010-3-22 12288]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-10-21 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-10-21 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-26 113120]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-9-23 16896]
.
=============== Created Last 30 ================
.
2012-07-26 19:09:47 -------- d-----w- c:\users\rob caldwell\appdata\roaming\DriverCure
2012-07-26 19:09:46 -------- d-----w- c:\users\rob caldwell\appdata\roaming\ParetoLogic
2012-07-26 19:09:33 -------- d-----w- c:\programdata\ParetoLogic
2012-07-26 19:09:33 -------- d-----w- c:\program files\ParetoLogic
2012-07-26 05:58:21 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{0e24d655-f31e-4aa0-8227-cfc945ed8b85}\offreg.dll
2012-07-25 18:43:18 -------- d-----w- c:\users\rob caldwell\appdata\local\Conduit
2012-07-24 12:07:47 -------- d-----w- c:\program files\HMA! Pro VPN
2012-07-24 05:59:26 6891424 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{0e24d655-f31e-4aa0-8227-cfc945ed8b85}\mpengine.dll
2012-07-20 20:03:14 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2012-07-20 20:03:14 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2012-07-20 20:03:12 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2012-07-20 20:03:12 -------- d-----w- c:\program files\PDFCreator
2012-07-20 14:44:22 -------- d-----w- c:\users\rob caldwell\appdata\roaming\Nvu
2012-07-18 18:20:24 -------- d-----w- c:\programdata\Magic Submitter
2012-07-18 18:20:24 -------- d-----w- c:\program files\Alexandr Krulik
2012-07-15 19:17:12 -------- d-----w- c:\program files\Tweet Adder 3
2012-07-11 17:08:14 -------- d-----w- c:\program files\OnlyWire
2012-07-11 13:02:05 -------- d-----w- c:\users\rob caldwell\appdata\local\Seesmic
2012-07-11 13:01:05 -------- d-----w- c:\program files\Seesmic Ping
2012-07-11 07:08:07 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-07-10 23:05:23 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-07-10 23:05:22 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-07-10 23:05:22 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-07-10 23:05:14 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2012-07-10 23:04:15 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-10 23:04:14 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-10 23:04:13 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-10 23:04:13 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-10 23:04:13 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-08 19:02:21 -------- d-----w- c:\users\rob caldwell\appdata\roaming\TweetAdder3
2012-07-05 16:53:46 -------- d-----w- c:\program files\MS Word Extract Email Addresses From Documents Software
.
==================== Find3M ====================
.
2012-07-03 16:21:53 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21:53 57656 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21:32 41224 ----a-w- c:\windows\avastSS.scr
2012-06-23 14:44:09 286720 ------w- c:\windows\Setup1.exe
2012-06-08 14:58:52 1110476 ----a-w- c:\users\rob caldwell\7z920.exe
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 08:33:25 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-31 16:25:14 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-05-01 14:03:49 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 15:44:31.11 ===============
2). I am not sure why I have to Zip the ATTACH file as it is only 9kb and I do not have a ZIP program.
3). Here is the aswMBR Log:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-26 15:52:23
-----------------------------
15:52:23.316 OS Version: Windows 6.0.6002 Service Pack 2
15:52:23.316 Number of processors: 2 586 0xF0D
15:52:23.318 ComputerName: ROBCALDWELL-PC UserName: Rob Caldwell
15:52:33.352 Initialize success
15:52:33.437 AVAST engine defs: 12072601
15:53:02.022 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
15:53:02.025 Disk 0 Vendor: Hitachi_ SB2O Size: 76319MB BusType: 3
15:53:02.050 Disk 0 MBR read successfully
15:53:02.053 Disk 0 MBR scan
15:53:02.058 Disk 0 Windows VISTA default MBR code
15:53:02.063 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 78 MB offset 63
15:53:02.076 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 161792
15:53:02.094 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 63439 MB offset 21133312
15:53:02.099 Disk 0 Partition - 00 0F Extended LBA 2560 MB offset 151056384
15:53:02.136 Disk 0 Partition 4 00 DD MSDOS5.0 2559 MB offset 151058432
15:53:02.144 Disk 0 scanning sectors +156299264
15:53:02.207 Disk 0 scanning C:\Windows\system32\drivers
15:53:14.734 Service scanning
15:53:39.875 Modules scanning
15:53:49.505 Disk 0 trace - called modules:
15:53:49.578 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
15:53:49.585 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f98780]
15:53:49.592 3 CLASSPNP.SYS[8c7a68b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x86495030]
15:53:50.120 AVAST engine scan C:\Windows
15:53:52.801 AVAST engine scan C:\Windows\system32
15:56:24.670 AVAST engine scan C:\Windows\system32\drivers
15:56:45.545 AVAST engine scan C:\Users\Rob Caldwell
16:03:56.010 AVAST engine scan C:\ProgramData
16:06:49.729 Scan finished successfully
16:09:32.179 Disk 0 MBR has been saved successfully to "C:\Users\Rob Caldwell\Desktop\Utility Programs\Virus Files\MBR.dat"
16:09:32.186 The log file has been saved successfully to "C:\Users\Rob Caldwell\Desktop\Utility Programs\Virus Files\aswMBR.txt"
Thank you in advance for your help!
Rob Caldwell