douglasvjohnson
New member
Hello and please be patient, as I am not used to this format and process.
The machine is a HP G62 laptop runniing IE 9 and Windows 7 home premium.
Searches in google, and other browsers end up opening multiple unsolicited web pages. I am getting AVG multiple trojan alerts with warnings that deleting the file might crash the system.
Pasted below are the DDS log, the aswMBR log, and an AVG threat log.
Your assistance is greatly appreciated.
Thank you
DDS:
..
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
Run by doug at 18:54:55 on 2012-07-24
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2811.1208 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxducoms.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe
C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduMsdMon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
C:\Program Files\Realtek\RtVOsd\RtVOsd.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Users\doug\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG2012\avgui.exe
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\splwow64.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://kidshealth.org/teen/sexual_health/girls/menstruation.html
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Google Update] "C:\Users\doug\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\doug\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Video Converter... - C:\Program Files (x86)\Media Player Utilities 5.22\AVIConverter\grab.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\OFFICE11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{63125ED7-4121-4BD2-9811-309F5E911E4E} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{63125ED7-4121-4BD2-9811-309F5E911E4E}\2375942554432323 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{63125ED7-4121-4BD2-9811-309F5E911E4E}\342465D23547166666 : DhcpNameServer = 192.168.0.20 192.168.0.41
TCP: Interfaces\{63125ED7-4121-4BD2-9811-309F5E911E4E}\C696E6B6379737 : DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{C05AD519-926E-46DA-A286-D6B3A0E85834} : DhcpNameServer = 40.6.1.100
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO-X64: 0x1 - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Lexmark Printable Web: {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO-X64: Ask Toolbar BHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\doug\AppData\Roaming\Mozilla\Firefox\Profiles\7o6nkz82.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=109936&tt=060612_8_&babsrc=HP_ss&mntrId=e24b91780000000000006e0f6e310db9
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B04ae27d3-b243-48bd-b214-db703be9693b%7D&mid=dd937770430147d6914ab57816bfae0c-41703a7d52e139f598cda7297c5bbf77f1c1caa4&ds=AVG&v=11.1.0.7&lang=en&pr=fr&d=2011-09-27%2019%3A08%3A03&sap=ku&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\doug\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Users\doug\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\doug\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109936&tt=060612_8_
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - e24b91780000000000006e0f6e310db9
FF - user.js: extensions.BabylonToolbar_i.hardId - e24b91780000000000006e0f6e310db9
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15503
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.176:57:16
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 64952]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2010-10-18 98208]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776]
R2 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2010-5-21 140272]
R2 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
R2 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-6-18 103992]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-9 26680]
R2 lxdu_device;lxdu_device;C:\Windows\system32\lxducoms.exe -service --> C:\Windows\system32\lxducoms.exe -service [?]
R2 RtVOsdService;RtVOsdService Installer;C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [2010-6-24 315392]
R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-7-9 935008]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atipmdag.sys --> C:\Windows\system32\DRIVERS\atipmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-8 136176]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-12 1153368]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-17 250056]
S3 CASprint;Sprint Con App Svc;"C:\Program Files (x86)\Sprint\Sprint SmartView\ConAppsSvc.exe" /n "CASprint" --> C:\Program Files (x86)\Sprint\Sprint SmartView\ConAppsSvc.exe [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-8 136176]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-07-24 23:04:53 -------- d-----w- C:\Users\doug\AppData\Local\{55F822EA-D35E-4E87-B15B-0193FB2A6CC0}
2012-07-24 23:04:23 -------- d-----w- C:\Users\doug\AppData\Local\{ACC1CCF6-A046-4A1B-85CF-D722D692E01D}
2012-07-23 23:00:33 -------- d-----w- C:\Users\doug\AppData\Local\{D4A858C2-51C3-4FE0-88B6-C355DB6D7E8C}
2012-07-23 23:00:08 -------- d-----w- C:\Users\doug\AppData\Local\{D4D9214B-C67A-4624-9B83-F539DDB0F396}
2012-07-23 22:59:51 -------- d-----w- C:\Users\doug\AppData\Roaming\PerformerSoft
2012-07-21 02:31:10 -------- d-----w- C:\ProgramData\IBUpdaterService
2012-07-21 02:31:01 550048 ----a-w- C:\Program Files (x86)\Uninstall Information\ib_uninst_514\uninstall.exe
2012-07-21 02:30:34 550048 ----a-w- C:\Program Files (x86)\Uninstall Information\ib_uninst_358\uninstall.exe
2012-07-21 02:30:29 -------- d-----w- C:\Program Files (x86)\Conduit
2012-07-21 02:30:27 19000 ----a-w- C:\Windows\System32\roboot64.exe
2012-07-21 02:26:42 -------- d-sh--w- C:\Windows\SysWow64\AI_RecycleBin
2012-07-21 02:26:41 -------- d-----w- C:\ProgramData\W3i
2012-07-21 02:26:41 -------- d-----w- C:\Program Files (x86)\W3i
2012-07-21 02:26:13 -------- d-----w- C:\Program Files (x86)\Yahoo!
2012-07-15 18:20:53 -------- d-----w- C:\Users\doug\AppData\Local\Macromedia
2012-07-15 17:56:42 -------- d-----w- C:\Users\doug\AppData\Local\{5B699BC4-7578-4233-85FD-1EF2C2AF6E69}
2012-07-15 17:56:26 -------- d-----w- C:\Users\doug\AppData\Local\{BFD953BA-4EE5-45CD-8006-5712BD3D1507}
2012-07-14 17:29:49 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2012-07-14 15:11:26 -------- d-----w- C:\Users\doug\AppData\Local\{06CEC55E-9177-437B-8FBB-E51C0DEADD93}
2012-07-13 21:27:24 -------- d-----w- C:\Users\doug\AppData\Local\{E97DF82E-E9FF-4C74-9C1D-DD1C3C665AAB}
2012-07-13 01:56:59 -------- d-----w- C:\Users\doug\AppData\Local\{E5E13261-2BE0-44A5-A47D-61ABA06EA83F}
2012-07-13 01:56:46 -------- d-----w- C:\Users\doug\AppData\Local\{D5782E74-ABEB-41C5-BDF9-040D2CB898B3}
2012-07-12 10:59:21 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-12 10:48:35 -------- d-----w- C:\Users\doug\AppData\Local\{CC8A390E-10EE-4BC4-854A-C685EE40DC99}
2012-07-11 21:57:07 -------- d-----w- C:\Users\doug\AppData\Local\{5B000D8A-BE94-42C2-99FD-2486B2573DA2}
2012-07-11 01:01:42 -------- d-----w- C:\Users\doug\AppData\Local\{F9778629-1A0E-448B-BC25-967C86DC4781}
2012-07-11 01:01:31 -------- d-----w- C:\Users\doug\AppData\Local\{279B1882-91A9-4F9D-895B-317A90EB5998}
2012-07-10 12:07:14 -------- d-----w- C:\Users\doug\AppData\Local\{458D767A-FAE3-4FB7-8B1D-0B54D788DA89}
2012-07-09 19:17:58 -------- d-----w- C:\Users\doug\AppData\Local\{546AEAB3-A202-404B-980F-87E39C2FE882}
2012-07-09 01:28:27 -------- d-----w- C:\Users\doug\AppData\Local\{1FBB05D5-05D7-42C0-B7CB-F44E973D0D35}
2012-07-08 13:27:39 -------- d-----w- C:\Users\doug\AppData\Local\{8C411B5B-31B0-488D-8922-E0261DE37AD7}
2012-07-08 00:42:25 -------- d-----w- C:\Users\doug\AppData\Local\{8ED515BE-FF8F-4E70-85E0-B186A11FB9B9}
2012-07-07 01:25:32 -------- d-----w- C:\Users\doug\AppData\Local\{378BB4DB-89F3-4646-916E-E674AEC5B127}
2012-07-06 11:38:46 -------- d-----w- C:\Users\doug\AppData\Local\{0223F3E8-CD14-4637-A9B9-2989652BF20B}
2012-07-05 19:52:37 -------- d-----w- C:\Users\doug\AppData\Local\{6F16E5E3-89DB-4B4E-8FC5-7D0F0BA25CAE}
2012-07-05 00:43:15 -------- d-----w- C:\Users\doug\AppData\Local\{0F7774C4-816B-4D2B-9273-FBB6BDA8BD80}
2012-07-05 00:43:04 -------- d-----w- C:\Users\doug\AppData\Local\{882C83F4-A053-4C2A-B2C2-49EAB22ADDF8}
2012-07-04 18:01:52 -------- d-----w- C:\Users\doug\AppData\Local\{16181CC8-B138-4FFC-9C34-F52C8AF08243}
2012-07-03 17:01:55 -------- d-----w- C:\Users\doug\AppData\Local\{F955B9EA-5422-41EB-8606-A991F2A98EE4}
2012-07-03 03:14:56 -------- d-----w- C:\Users\doug\AppData\Local\{56A7419B-45FD-43B5-BFDB-F96F01886E43}
2012-07-01 21:51:30 -------- d-----w- C:\Users\doug\AppData\Local\{A11D69F4-F8A7-4344-A664-920E8A809497}
2012-06-30 14:08:43 -------- d-----w- C:\Users\doug\AppData\Local\{CF5AAC20-81D4-4028-9878-3DF108C7F42B}
2012-06-29 21:34:09 -------- d-----w- C:\Users\doug\AppData\Local\{A61BA08F-415D-4372-A46C-3B016C0B21AE}
2012-06-29 00:21:59 -------- d-----w- C:\Users\doug\AppData\Local\{571471A4-40AA-423A-9AA4-BB51F2EE5B2D}
2012-06-28 10:35:09 -------- d-----w- C:\Users\doug\AppData\Local\{C5CED7BA-64F4-4171-8A1F-60BD0001AD91}
2012-06-28 10:34:58 -------- d-----w- C:\Users\doug\AppData\Local\{A0A623C1-56F8-456F-916E-B4A3FA947C3B}
2012-06-27 22:34:27 -------- d-----w- C:\Users\doug\AppData\Local\{DBF84FF5-E4AB-46E8-BCF4-DC04893706D6}
2012-06-27 22:34:17 -------- d-----w- C:\Users\doug\AppData\Local\{0CFF0F1B-40EC-451D-A64F-C6D8A747ABE8}
.
==================== Find3M ====================
.
2012-07-12 00:58:27 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-12 00:58:27 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 20:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 20:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
.
============= FINISH: 18:56:39.27 ===============
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-24 18:12:31
-----------------------------
18:12:31.122 OS Version: Windows x64 6.1.7601 Service Pack 1
18:12:31.122 Number of processors: 2 586 0x603
18:12:31.123 ComputerName: DOUG-HP UserName: doug
18:12:37.902 Initialize success
18:13:30.384 AVAST engine defs: 12072401
18:13:45.204 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005e
18:13:45.219 Disk 0 Vendor: ST932032 0005 Size: 305245MB BusType: 11
18:13:45.235 Disk 0 MBR read successfully
18:13:45.251 Disk 0 MBR scan
18:13:45.251 Disk 0 unknown MBR code
18:13:45.266 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
18:13:45.297 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287180 MB offset 409600
18:13:45.329 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17761 MB offset 588554240
18:13:45.360 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768
18:13:45.422 Disk 0 scanning C:\Windows\system32\drivers
18:14:03.440 Service scanning
18:14:42.690 Modules scanning
18:14:42.714 Disk 0 trace - called modules:
18:14:42.758 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys
18:14:42.770 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031de060]
18:14:42.780 3 CLASSPNP.SYS[fffff8800196b43f] -> nt!IofCallDriver -> [0xfffffa8003184040]
18:14:42.791 5 amdxata.sys[fffff880011227a8] -> nt!IofCallDriver -> \Device\0000005e[0xfffffa800317e060]
18:14:45.770 AVAST engine scan C:\Windows
18:14:49.435 AVAST engine scan C:\Windows\system32
18:19:17.563 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
18:19:25.948 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
18:22:35.555 AVAST engine scan C:\Windows\system32\drivers
18:23:02.971 AVAST engine scan C:\Users\doug
18:24:04.521 Disk 0 MBR has been saved successfully to "C:\Users\doug\Desktop\MBR.dat"
18:24:04.537 The log file has been saved successfully to "C:\Users\doug\Desktop\aswMBR.txt"
END OF FILE
=================
AVG Threat log
Resident Shield detection
Infection;"Object";"Result";"Detection time";"Object Type";"Process"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/24/2012, 6:33:14 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Generic28.ANIC;"c:\Windows\assembly\GAC_64\Desktop.ini";"Infected";"7/24/2012, 6:19:25 PM";"file";"C:\Users\doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XSI4IK5\aswMBR.exe"
Trojan horse BackDoor.Generic15.AXLA;"c:\Windows\assembly\GAC_32\Desktop.ini";"Infected";"7/24/2012, 6:19:17 PM";"file";"C:\Users\doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XSI4IK5\aswMBR.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/24/2012, 6:17:30 PM";"file";"C:\Users\doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XSI4IK5\aswMBR.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/24/2012, 6:03:06 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 7:09:03 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 6:55:44 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse FakeAV_s.EP;"c:\Users\doug\AppData\Local\Temp\124kkk290347.exe";"Moved to Virus Vault";"7/23/2012, 6:42:55 PM";"file";"C:\Program Files (x86)\Java\jre6\bin\java.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 6:38:51 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 6:27:56 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 5:58:20 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/20/2012, 9:36:43 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/20/2012, 9:04:21 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/19/2012, 10:26:38 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/19/2012, 10:17:37 PM";"file";"C:\Windows\System32\taskmgr.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/17/2012, 10:33:31 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/16/2012, 9:53:31 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/16/2012, 9:09:37 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/16/2012, 6:52:24 AM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/15/2012, 11:05:13 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/15/2012, 10:24:39 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/15/2012, 6:54:05 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/15/2012, 1:24:04 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 4:03:40 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 3:31:21 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 3:08:50 PM";"file";"C:\Windows\System32\taskmgr.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 3:00:01 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 1:41:27 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 12:34:03 PM";"file";"C:\Windows\System32\svchost.exe"
The file is signed by an untrusted certificate, issued by: Generic.B89.;"c:\Users\doug\AppData\Local\Temp\STWSetup-IE.exe";"Potentially dangerous object";"11/16/2011, 11:01:40 PM";"file";"C:\Users\doug\Downloads\ooVooSetup.exe"
Virus identified Worm/AutoRun.BR;"f:\autorun.inf";"Infected";"6/29/2011, 10:16:59 PM";"file";"C:\Windows\System32\svchost.exe"
Virus identified Worm/AutoRun.BR;"f:\autorun.inf";"Infected";"6/29/2011, 9:53:20 PM";"file";"C:\Windows\System32\svchost.exe"
Adware Generic4.BHOW;"c:\Users\doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2HX28HTN\SetupPlaySushi[2].exe";"Potentially dangerous object";"4/11/2011, 10:01:20 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
The machine is a HP G62 laptop runniing IE 9 and Windows 7 home premium.
Searches in google, and other browsers end up opening multiple unsolicited web pages. I am getting AVG multiple trojan alerts with warnings that deleting the file might crash the system.
Pasted below are the DDS log, the aswMBR log, and an AVG threat log.
Your assistance is greatly appreciated.
Thank you
DDS:
..
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
Run by doug at 18:54:55 on 2012-07-24
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2811.1208 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxducoms.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe
C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduMsdMon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
C:\Program Files\Realtek\RtVOsd\RtVOsd.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Users\doug\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG2012\avgui.exe
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\splwow64.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://kidshealth.org/teen/sexual_health/girls/menstruation.html
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [Google Update] "C:\Users\doug\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\doug\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Video Converter... - C:\Program Files (x86)\Media Player Utilities 5.22\AVIConverter\grab.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\OFFICE11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{63125ED7-4121-4BD2-9811-309F5E911E4E} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{63125ED7-4121-4BD2-9811-309F5E911E4E}\2375942554432323 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{63125ED7-4121-4BD2-9811-309F5E911E4E}\342465D23547166666 : DhcpNameServer = 192.168.0.20 192.168.0.41
TCP: Interfaces\{63125ED7-4121-4BD2-9811-309F5E911E4E}\C696E6B6379737 : DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{C05AD519-926E-46DA-A286-D6B3A0E85834} : DhcpNameServer = 40.6.1.100
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO-X64: 0x1 - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Lexmark Printable Web: {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO-X64: Ask Toolbar BHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\doug\AppData\Roaming\Mozilla\Firefox\Profiles\7o6nkz82.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=109936&tt=060612_8_&babsrc=HP_ss&mntrId=e24b91780000000000006e0f6e310db9
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B04ae27d3-b243-48bd-b214-db703be9693b%7D&mid=dd937770430147d6914ab57816bfae0c-41703a7d52e139f598cda7297c5bbf77f1c1caa4&ds=AVG&v=11.1.0.7&lang=en&pr=fr&d=2011-09-27%2019%3A08%3A03&sap=ku&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\doug\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Users\doug\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\doug\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109936&tt=060612_8_
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - e24b91780000000000006e0f6e310db9
FF - user.js: extensions.BabylonToolbar_i.hardId - e24b91780000000000006e0f6e310db9
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15503
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.176:57:16
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 64952]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2010-10-18 98208]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-8-2 192776]
R2 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2010-5-21 140272]
R2 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
R2 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-6-18 103992]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-9 26680]
R2 lxdu_device;lxdu_device;C:\Windows\system32\lxducoms.exe -service --> C:\Windows\system32\lxducoms.exe -service [?]
R2 RtVOsdService;RtVOsdService Installer;C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [2010-6-24 315392]
R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-7-9 935008]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atipmdag.sys --> C:\Windows\system32\DRIVERS\atipmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-8 136176]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-12 1153368]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-17 250056]
S3 CASprint;Sprint Con App Svc;"C:\Program Files (x86)\Sprint\Sprint SmartView\ConAppsSvc.exe" /n "CASprint" --> C:\Program Files (x86)\Sprint\Sprint SmartView\ConAppsSvc.exe [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-8 136176]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-07-24 23:04:53 -------- d-----w- C:\Users\doug\AppData\Local\{55F822EA-D35E-4E87-B15B-0193FB2A6CC0}
2012-07-24 23:04:23 -------- d-----w- C:\Users\doug\AppData\Local\{ACC1CCF6-A046-4A1B-85CF-D722D692E01D}
2012-07-23 23:00:33 -------- d-----w- C:\Users\doug\AppData\Local\{D4A858C2-51C3-4FE0-88B6-C355DB6D7E8C}
2012-07-23 23:00:08 -------- d-----w- C:\Users\doug\AppData\Local\{D4D9214B-C67A-4624-9B83-F539DDB0F396}
2012-07-23 22:59:51 -------- d-----w- C:\Users\doug\AppData\Roaming\PerformerSoft
2012-07-21 02:31:10 -------- d-----w- C:\ProgramData\IBUpdaterService
2012-07-21 02:31:01 550048 ----a-w- C:\Program Files (x86)\Uninstall Information\ib_uninst_514\uninstall.exe
2012-07-21 02:30:34 550048 ----a-w- C:\Program Files (x86)\Uninstall Information\ib_uninst_358\uninstall.exe
2012-07-21 02:30:29 -------- d-----w- C:\Program Files (x86)\Conduit
2012-07-21 02:30:27 19000 ----a-w- C:\Windows\System32\roboot64.exe
2012-07-21 02:26:42 -------- d-sh--w- C:\Windows\SysWow64\AI_RecycleBin
2012-07-21 02:26:41 -------- d-----w- C:\ProgramData\W3i
2012-07-21 02:26:41 -------- d-----w- C:\Program Files (x86)\W3i
2012-07-21 02:26:13 -------- d-----w- C:\Program Files (x86)\Yahoo!
2012-07-15 18:20:53 -------- d-----w- C:\Users\doug\AppData\Local\Macromedia
2012-07-15 17:56:42 -------- d-----w- C:\Users\doug\AppData\Local\{5B699BC4-7578-4233-85FD-1EF2C2AF6E69}
2012-07-15 17:56:26 -------- d-----w- C:\Users\doug\AppData\Local\{BFD953BA-4EE5-45CD-8006-5712BD3D1507}
2012-07-14 17:29:49 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2012-07-14 15:11:26 -------- d-----w- C:\Users\doug\AppData\Local\{06CEC55E-9177-437B-8FBB-E51C0DEADD93}
2012-07-13 21:27:24 -------- d-----w- C:\Users\doug\AppData\Local\{E97DF82E-E9FF-4C74-9C1D-DD1C3C665AAB}
2012-07-13 01:56:59 -------- d-----w- C:\Users\doug\AppData\Local\{E5E13261-2BE0-44A5-A47D-61ABA06EA83F}
2012-07-13 01:56:46 -------- d-----w- C:\Users\doug\AppData\Local\{D5782E74-ABEB-41C5-BDF9-040D2CB898B3}
2012-07-12 10:59:21 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-12 10:48:35 -------- d-----w- C:\Users\doug\AppData\Local\{CC8A390E-10EE-4BC4-854A-C685EE40DC99}
2012-07-11 21:57:07 -------- d-----w- C:\Users\doug\AppData\Local\{5B000D8A-BE94-42C2-99FD-2486B2573DA2}
2012-07-11 01:01:42 -------- d-----w- C:\Users\doug\AppData\Local\{F9778629-1A0E-448B-BC25-967C86DC4781}
2012-07-11 01:01:31 -------- d-----w- C:\Users\doug\AppData\Local\{279B1882-91A9-4F9D-895B-317A90EB5998}
2012-07-10 12:07:14 -------- d-----w- C:\Users\doug\AppData\Local\{458D767A-FAE3-4FB7-8B1D-0B54D788DA89}
2012-07-09 19:17:58 -------- d-----w- C:\Users\doug\AppData\Local\{546AEAB3-A202-404B-980F-87E39C2FE882}
2012-07-09 01:28:27 -------- d-----w- C:\Users\doug\AppData\Local\{1FBB05D5-05D7-42C0-B7CB-F44E973D0D35}
2012-07-08 13:27:39 -------- d-----w- C:\Users\doug\AppData\Local\{8C411B5B-31B0-488D-8922-E0261DE37AD7}
2012-07-08 00:42:25 -------- d-----w- C:\Users\doug\AppData\Local\{8ED515BE-FF8F-4E70-85E0-B186A11FB9B9}
2012-07-07 01:25:32 -------- d-----w- C:\Users\doug\AppData\Local\{378BB4DB-89F3-4646-916E-E674AEC5B127}
2012-07-06 11:38:46 -------- d-----w- C:\Users\doug\AppData\Local\{0223F3E8-CD14-4637-A9B9-2989652BF20B}
2012-07-05 19:52:37 -------- d-----w- C:\Users\doug\AppData\Local\{6F16E5E3-89DB-4B4E-8FC5-7D0F0BA25CAE}
2012-07-05 00:43:15 -------- d-----w- C:\Users\doug\AppData\Local\{0F7774C4-816B-4D2B-9273-FBB6BDA8BD80}
2012-07-05 00:43:04 -------- d-----w- C:\Users\doug\AppData\Local\{882C83F4-A053-4C2A-B2C2-49EAB22ADDF8}
2012-07-04 18:01:52 -------- d-----w- C:\Users\doug\AppData\Local\{16181CC8-B138-4FFC-9C34-F52C8AF08243}
2012-07-03 17:01:55 -------- d-----w- C:\Users\doug\AppData\Local\{F955B9EA-5422-41EB-8606-A991F2A98EE4}
2012-07-03 03:14:56 -------- d-----w- C:\Users\doug\AppData\Local\{56A7419B-45FD-43B5-BFDB-F96F01886E43}
2012-07-01 21:51:30 -------- d-----w- C:\Users\doug\AppData\Local\{A11D69F4-F8A7-4344-A664-920E8A809497}
2012-06-30 14:08:43 -------- d-----w- C:\Users\doug\AppData\Local\{CF5AAC20-81D4-4028-9878-3DF108C7F42B}
2012-06-29 21:34:09 -------- d-----w- C:\Users\doug\AppData\Local\{A61BA08F-415D-4372-A46C-3B016C0B21AE}
2012-06-29 00:21:59 -------- d-----w- C:\Users\doug\AppData\Local\{571471A4-40AA-423A-9AA4-BB51F2EE5B2D}
2012-06-28 10:35:09 -------- d-----w- C:\Users\doug\AppData\Local\{C5CED7BA-64F4-4171-8A1F-60BD0001AD91}
2012-06-28 10:34:58 -------- d-----w- C:\Users\doug\AppData\Local\{A0A623C1-56F8-456F-916E-B4A3FA947C3B}
2012-06-27 22:34:27 -------- d-----w- C:\Users\doug\AppData\Local\{DBF84FF5-E4AB-46E8-BCF4-DC04893706D6}
2012-06-27 22:34:17 -------- d-----w- C:\Users\doug\AppData\Local\{0CFF0F1B-40EC-451D-A64F-C6D8A747ABE8}
.
==================== Find3M ====================
.
2012-07-12 00:58:27 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-12 00:58:27 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-02 20:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 20:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
.
============= FINISH: 18:56:39.27 ===============
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-24 18:12:31
-----------------------------
18:12:31.122 OS Version: Windows x64 6.1.7601 Service Pack 1
18:12:31.122 Number of processors: 2 586 0x603
18:12:31.123 ComputerName: DOUG-HP UserName: doug
18:12:37.902 Initialize success
18:13:30.384 AVAST engine defs: 12072401
18:13:45.204 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005e
18:13:45.219 Disk 0 Vendor: ST932032 0005 Size: 305245MB BusType: 11
18:13:45.235 Disk 0 MBR read successfully
18:13:45.251 Disk 0 MBR scan
18:13:45.251 Disk 0 unknown MBR code
18:13:45.266 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
18:13:45.297 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287180 MB offset 409600
18:13:45.329 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 17761 MB offset 588554240
18:13:45.360 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768
18:13:45.422 Disk 0 scanning C:\Windows\system32\drivers
18:14:03.440 Service scanning
18:14:42.690 Modules scanning
18:14:42.714 Disk 0 trace - called modules:
18:14:42.758 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys
18:14:42.770 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031de060]
18:14:42.780 3 CLASSPNP.SYS[fffff8800196b43f] -> nt!IofCallDriver -> [0xfffffa8003184040]
18:14:42.791 5 amdxata.sys[fffff880011227a8] -> nt!IofCallDriver -> \Device\0000005e[0xfffffa800317e060]
18:14:45.770 AVAST engine scan C:\Windows
18:14:49.435 AVAST engine scan C:\Windows\system32
18:19:17.563 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
18:19:25.948 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
18:22:35.555 AVAST engine scan C:\Windows\system32\drivers
18:23:02.971 AVAST engine scan C:\Users\doug
18:24:04.521 Disk 0 MBR has been saved successfully to "C:\Users\doug\Desktop\MBR.dat"
18:24:04.537 The log file has been saved successfully to "C:\Users\doug\Desktop\aswMBR.txt"
END OF FILE
=================
AVG Threat log
Resident Shield detection
Infection;"Object";"Result";"Detection time";"Object Type";"Process"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/24/2012, 6:33:14 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Generic28.ANIC;"c:\Windows\assembly\GAC_64\Desktop.ini";"Infected";"7/24/2012, 6:19:25 PM";"file";"C:\Users\doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XSI4IK5\aswMBR.exe"
Trojan horse BackDoor.Generic15.AXLA;"c:\Windows\assembly\GAC_32\Desktop.ini";"Infected";"7/24/2012, 6:19:17 PM";"file";"C:\Users\doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XSI4IK5\aswMBR.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/24/2012, 6:17:30 PM";"file";"C:\Users\doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2XSI4IK5\aswMBR.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/24/2012, 6:03:06 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 7:09:03 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 6:55:44 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse FakeAV_s.EP;"c:\Users\doug\AppData\Local\Temp\124kkk290347.exe";"Moved to Virus Vault";"7/23/2012, 6:42:55 PM";"file";"C:\Program Files (x86)\Java\jre6\bin\java.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 6:38:51 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 6:27:56 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/23/2012, 5:58:20 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/20/2012, 9:36:43 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/20/2012, 9:04:21 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/19/2012, 10:26:38 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/19/2012, 10:17:37 PM";"file";"C:\Windows\System32\taskmgr.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/17/2012, 10:33:31 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/16/2012, 9:53:31 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/16/2012, 9:09:37 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/16/2012, 6:52:24 AM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/15/2012, 11:05:13 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/15/2012, 10:24:39 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/15/2012, 6:54:05 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/15/2012, 1:24:04 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 4:03:40 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 3:31:21 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 3:08:50 PM";"file";"C:\Windows\System32\taskmgr.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 3:00:01 PM";"file";"C:\Windows\System32\wininit.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 1:41:27 PM";"file";"C:\Windows\System32\svchost.exe"
Trojan horse Dropper.Generic_c.MMI;"c:\Windows\System32\services.exe";"Object is white-listed (critical/system file that should not be removed)";"7/14/2012, 12:34:03 PM";"file";"C:\Windows\System32\svchost.exe"
The file is signed by an untrusted certificate, issued by: Generic.B89.;"c:\Users\doug\AppData\Local\Temp\STWSetup-IE.exe";"Potentially dangerous object";"11/16/2011, 11:01:40 PM";"file";"C:\Users\doug\Downloads\ooVooSetup.exe"
Virus identified Worm/AutoRun.BR;"f:\autorun.inf";"Infected";"6/29/2011, 10:16:59 PM";"file";"C:\Windows\System32\svchost.exe"
Virus identified Worm/AutoRun.BR;"f:\autorun.inf";"Infected";"6/29/2011, 9:53:20 PM";"file";"C:\Windows\System32\svchost.exe"
Adware Generic4.BHOW;"c:\Users\doug\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2HX28HTN\SetupPlaySushi[2].exe";"Potentially dangerous object";"4/11/2011, 10:01:20 PM";"file";"C:\Program Files (x86)\Internet Explorer\iexplore.exe"