This morning I started my computer and this FBI lockout screen came up prompting me to pay $300 to get my computer unlocked. I restarted the computer and it came up what seemed to be normally. Avira then popped up saying D:/Users/Jacobs Family/wgsdgsdgdsgsd.dll was infected with Meredrop. When I clicked to remove it Avira would attempt to scan and would just disappear. I opened a manual removal thread on this forum and the registry keys it suggested were not modified. I downloaded Spybot and ran it. Fixed all the things that it found. Avira continued to pop up with the warning, so I tried to delete the wgsdgsdgdsgsd.dll file and it would not let me. I restarted the computer in safe mode and the FBI lockout came back. Restarted the computer running Windows XP (have installed on another partition) and removed the wgsdgsdgdsgsd.dll file. Now the Avira warning is gone but Windows Security Center wont start. I was trying not to have to post here but I need your help. Thank you.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
Run by Jacobs Family at 15:19:45 on 2012-12-28
.
============== Running Processes ================
.
D:\Windows\system32\wininit.exe
D:\Windows\system32\lsm.exe
D:\Windows\system32\atiesrxx.exe
D:\Windows\system32\atieclxx.exe
D:\Windows\System32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Windows\system32\taskhost.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
D:\Windows\system32\Dwm.exe
D:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
D:\Windows\Explorer.EXE
D:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
D:\Windows\system32\taskeng.exe
D:\Program Files\PC Tools Firewall Plus\FWService.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\Program Files\Kodak\KODAK Share Button App\Listener.exe
D:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
D:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
D:\Program Files\Real\RealPlayer\Update\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
D:\Program Files\Steam\steam.exe
D:\Program Files\Google\Drive\googledrivesync.exe
D:\LGMobileUpgrade\LGMOBILEAX\BYR_Client\VZWNotiAgent.exe
D:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
D:\Program Files\Google\Drive\googledrivesync.exe
D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
D:\Windows\system32\conhost.exe
D:\Windows\system32\SearchIndexer.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Common Files\Steam\SteamService.exe
D:\Program Files\Windows Media Player\wmpnetwk.exe
D:\Windows\system32\taskeng.exe
D:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Windows\system32\taskhost.exe
D:\Windows\system32\conhost.exe
D:\Windows\system32\svchost.exe -k DcomLaunch
D:\Windows\system32\svchost.exe -k RPCSS
D:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
D:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
D:\Windows\system32\svchost.exe -k netsvcs
D:\Windows\system32\svchost.exe -k LocalService
D:\Windows\system32\svchost.exe -k NetworkService
D:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
D:\Windows\system32\svchost.exe -k imgsvc
D:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
D:\Windows\System32\svchost.exe -k LocalServicePeerNet
D:\Windows\system32\svchost.exe -k WindowsMobile
D:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - d:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - d:\program files\java\jre7\bin\ssv.dll
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - d:\program files\ask.com\GenericAskToolbar.dll
BHO: WeCareReminder Class: {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - d:\programdata\wecarereminder\IEHelperv2.5.0.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - d:\program files\java\jre7\bin\jp2ssv.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - d:\program files\ask.com\GenericAskToolbar.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - d:\program files\ask.com\GenericAskToolbar.dll
uRun: [Steam] "d:\program files\steam\steam.exe" -silent
uRun: [KGShareApp] d:\program files\kodak\kodak share button app\KGShare_App.exe
uRun: [GoogleDriveSync] "d:\program files\google\drive\googledrivesync.exe" /autostart
uRun: [EPSON NX300 Series] d:\windows\system32\spool\drivers\w32x86\3\e_fatieja.exe /fu "d:\windows\temp\E_S5270.tmp" /EF "HKCU"
uRun: [BYR_AGENT] d:\lgmobileupgrade\lgmobileax\byr_client\VZWNotiAgent.exe
uRun: [Spybot-S&D Cleaning] "d:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [avgnt] "d:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [00PCTFW] "d:\program files\pc tools firewall plus\FirewallGUI.exe" -s
mRun: [Adobe ARM] "d:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [APSDaemon] "d:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Monitor] "d:\program files\leapfrog\leapfrog connect\Monitor.exe"
mRun: [Windows Mobile Device Center] d:\windows\windowsmobile\wmdc.exe
mRun: [TkBellExe] "d:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [BYR_AGENT] d:\programdata\lgmobileax\byr_client\VZWNotiAgent.exe
mRun: [Launch PC Probe II] "d:\program files\asus\pc probe ii\Probe2.exe" 1
mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "d:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SDTray] "d:\program files\spybot - search & destroy 2\SDTray.exe"
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - d:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - d:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{337AE17F-5C22-4479-9234-0E7582AA9796} : DHCPNameServer = 192.168.1.1
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - d:\users\jacobs family\appdata\roaming\mozilla\firefox\profiles\monq11y0.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=100486&babsrc=KW_ss&mntrId=04be9d2c0000000000008000600fe800&q=
FF - plugin: d:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: d:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: d:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: d:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprpplugin.dll
FF - plugin: d:\program files\virtools\3d life player\npvirtools.dll
FF - plugin: d:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: d:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: d:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: d:\users\jacobs family\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: d:\windows\system32\adobe\director\np32dsw_1168638.dll
FF - plugin: d:\windows\system32\macromed\flash\NPSWF32_11_5_502_135.dll
FF - plugin: d:\windows\system32\npdeployJava1.dll
FF - plugin: d:\windows\system32\npmproxy.dll
FF - ExtSQL: 2012-11-04 17:21; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=100486
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 04be9d2c0000000000008000600fe800
FF - user.js: extensions.BabylonToolbar_i.hardId - 04be9d2c0000000000008000600fe800
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15450
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:16:54
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? dmvsc;dmvsc
R? EagleXNt;EagleXNt
R? SDWSCService;Spybot-S&D 2 Security Center Service
R? StorSvc;Storage Service
R? TsUsbFlt;TsUsbFlt
R? TsUsbGD;Remote Desktop Generic USB Device
R? WatAdminSvc;Windows Activation Technologies Service
S? AMD External Events Utility;AMD External Events Utility
S? AntiVirSchedulerService;Avira Scheduler
S? AntiVirService;Avira Realtime Protection
S? avgntflt;avgntflt
S? avkmgr;avkmgr
S? PCTAppEvent;PCTAppEvent Driver
S? PCTFW-DNS;PCTools Firewall - DNS driver
S? PCTFW-PacketFilter;PCTools Firewall - Packet filter driver
S? pctgntdi;pctgntdi
S? pctNDIS;PC Tools Driver
S? PCToolsFirewallPlus;PC Tools Firewall Plus
S? pctplfw;pctplfw
S? RTL8167;Realtek 8167 NT Driver
S? SDScannerService;Spybot-S&D 2 Scanner Service
S? SDUpdateService;Spybot-S&D 2 Updating Service
.
=============== Created Last 30 ================
.
2012-12-28 19:08:16 -------- d-----w- D:\sh4ldr
2012-12-28 19:08:16 -------- d-----w- d:\program files\Enigma Software Group
2012-12-28 19:07:56 -------- d-----w- d:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP
2012-12-28 19:07:55 -------- d-----w- d:\program files\common files\Wise Installation Wizard
2012-12-28 18:27:36 -------- d-----w- d:\windows\pss
2012-12-28 17:32:01 -------- d-----w- d:\programdata\Spybot - Search & Destroy
2012-12-28 17:31:53 15224 ----a-w- d:\windows\system32\sdnclean.exe
2012-12-28 17:31:51 -------- d-----w- d:\program files\Spybot - Search & Destroy 2
2012-12-28 17:30:59 -------- d-----w- d:\users\jacobs family\appdata\local\Programs
2012-12-28 09:26:19 6812136 ----a-w- d:\programdata\microsoft\windows defender\definition updates\{931999c0-0505-4800-af8c-39443d5449f7}\mpengine.dll
2012-12-21 09:00:25 34304 ----a-w- d:\windows\system32\atmlib.dll
2012-12-21 09:00:25 295424 ----a-w- d:\windows\system32\atmfd.dll
2012-12-11 19:33:39 2345984 ----a-w- d:\windows\system32\win32k.sys
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin7.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin6.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin5.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin4.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin3.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin2.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin.dll
2012-12-05 19:25:09 93672 ----a-w- d:\windows\system32\WindowsAccessBridge.dll
.
==================== Find3M ====================
.
2012-12-11 22:22:43 73656 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-11 22:22:43 697272 ----a-w- d:\windows\system32\FlashPlayerApp.exe
2012-12-05 19:24:41 821736 ----a-w- d:\windows\system32\npdeployJava1.dll
2012-12-05 19:24:41 746984 ----a-w- d:\windows\system32\deployJava1.dll
2012-11-14 02:09:22 1800704 ----a-w- d:\windows\system32\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- d:\windows\system32\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- d:\windows\system32\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- d:\windows\system32\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- d:\windows\system32\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- d:\windows\system32\mshtml.tlb
2012-11-09 04:42:49 2048 ----a-w- d:\windows\system32\tzres.dll
2012-11-02 05:11:31 376832 ----a-w- d:\windows\system32\dpnet.dll
2012-10-25 09:12:26 94208 ----a-w- d:\windows\system32\QuickTimeVR.qtx
2012-10-25 09:12:26 69632 ----a-w- d:\windows\system32\QuickTime.qts
2012-10-16 07:39:52 561664 ----a-w- d:\windows\apppatch\AcLayers.dll
2012-10-09 17:40:31 44032 ----a-w- d:\windows\system32\dhcpcsvc6.dll
2012-10-09 17:40:31 193536 ----a-w- d:\windows\system32\dhcpcore6.dll
2012-10-04 16:47:18 169984 ----a-w- d:\windows\system32\winsrv.dll
2012-10-04 16:43:05 293376 ----a-w- d:\windows\system32\KernelBase.dll
2012-10-04 14:57:58 271360 ----a-w- d:\windows\system32\conhost.exe
2012-10-04 14:41:50 6144 ---ha-w- d:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-10-04 14:41:50 4608 ---ha-w- d:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-10-04 14:41:50 3584 ---ha-w- d:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-10-04 14:41:50 3072 ---ha-w- d:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-10-03 16:58:30 1293680 ----a-w- d:\windows\system32\drivers\tcpip.sys
2012-10-03 16:42:26 52224 ----a-w- d:\windows\system32\nlaapi.dll
2012-10-03 16:42:26 242176 ----a-w- d:\windows\system32\nlasvc.dll
2012-10-03 16:42:24 18944 ----a-w- d:\windows\system32\netevent.dll
2012-10-03 16:42:24 175104 ----a-w- d:\windows\system32\netcorehc.dll
2012-10-03 16:42:23 156672 ----a-w- d:\windows\system32\ncsi.dll
2012-10-03 16:40:35 499712 ----a-w- d:\windows\system32\iphlpsvc.dll
2012-10-03 15:21:38 35328 ----a-w- d:\windows\system32\drivers\tcpipreg.sys
.
============= FINISH: 15:20:42.94 ===============
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-28 15:38:48
-----------------------------
15:38:48.293 OS Version: Windows 6.1.7601 Service Pack 1
15:38:48.293 Number of processors: 4 586 0x402
15:38:48.293 ComputerName: JACOBSFAMILY-PC UserName: Jacobs Family
15:38:57.637 Initialize success
15:39:08.401 AVAST engine defs: 12122800
15:39:11.677 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000069
15:39:11.677 Disk 0 Vendor: AMD_____ 1.10 Size: 610490MB BusType: 8
15:39:11.693 Disk 0 MBR read successfully
15:39:11.693 Disk 0 MBR scan
15:39:11.724 Disk 0 Windows 7 default MBR code
15:39:11.724 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 300002 MB offset 63
15:39:11.724 Disk 0 Partition - 00 0F Extended LBA 310474 MB offset 614405925
15:39:11.739 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 310474 MB offset 614405988
15:39:11.739 Disk 0 scanning sectors +1250258625
15:39:11.802 Disk 0 scanning D:\Windows\system32\drivers
15:39:22.832 Service scanning
15:39:43.112 Modules scanning
15:39:46.934 Disk 0 trace - called modules:
15:39:47.497 ntkrnlpa.exe CLASSPNP.SYS disk.sys storport.sys halmacpi.dll amdsbs.sys
15:39:47.512 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8617d030]
15:39:47.528 3 CLASSPNP.SYS[8bb9759e] -> nt!IofCallDriver -> \Device\00000069[0x85e69b78]
15:39:48.729 AVAST engine scan D:\Windows
15:39:51.225 AVAST engine scan D:\Windows\system32
15:44:08.062 AVAST engine scan D:\Windows\system32\drivers
15:44:30.917 AVAST engine scan D:\Users\Jacobs Family
15:46:59.153 Disk 0 MBR has been saved successfully to "D:\Users\Jacobs Family\Desktop\MBR.dat"
15:46:59.159 The log file has been saved successfully to "D:\Users\Jacobs Family\Desktop\aswMBR.txt"
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
Run by Jacobs Family at 15:19:45 on 2012-12-28
.
============== Running Processes ================
.
D:\Windows\system32\wininit.exe
D:\Windows\system32\lsm.exe
D:\Windows\system32\atiesrxx.exe
D:\Windows\system32\atieclxx.exe
D:\Windows\System32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Windows\system32\taskhost.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
D:\Windows\system32\Dwm.exe
D:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
D:\Windows\Explorer.EXE
D:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
D:\Windows\system32\taskeng.exe
D:\Program Files\PC Tools Firewall Plus\FWService.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\Program Files\Kodak\KODAK Share Button App\Listener.exe
D:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
D:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
D:\Program Files\Real\RealPlayer\Update\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
D:\Program Files\Steam\steam.exe
D:\Program Files\Google\Drive\googledrivesync.exe
D:\LGMobileUpgrade\LGMOBILEAX\BYR_Client\VZWNotiAgent.exe
D:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
D:\Program Files\Google\Drive\googledrivesync.exe
D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
D:\Windows\system32\conhost.exe
D:\Windows\system32\SearchIndexer.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Common Files\Steam\SteamService.exe
D:\Program Files\Windows Media Player\wmpnetwk.exe
D:\Windows\system32\taskeng.exe
D:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Windows\system32\taskhost.exe
D:\Windows\system32\conhost.exe
D:\Windows\system32\svchost.exe -k DcomLaunch
D:\Windows\system32\svchost.exe -k RPCSS
D:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
D:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
D:\Windows\system32\svchost.exe -k netsvcs
D:\Windows\system32\svchost.exe -k LocalService
D:\Windows\system32\svchost.exe -k NetworkService
D:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
D:\Windows\system32\svchost.exe -k imgsvc
D:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
D:\Windows\System32\svchost.exe -k LocalServicePeerNet
D:\Windows\system32\svchost.exe -k WindowsMobile
D:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - d:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - d:\program files\java\jre7\bin\ssv.dll
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - d:\program files\ask.com\GenericAskToolbar.dll
BHO: WeCareReminder Class: {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - d:\programdata\wecarereminder\IEHelperv2.5.0.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - d:\program files\java\jre7\bin\jp2ssv.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - d:\program files\ask.com\GenericAskToolbar.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - d:\program files\ask.com\GenericAskToolbar.dll
uRun: [Steam] "d:\program files\steam\steam.exe" -silent
uRun: [KGShareApp] d:\program files\kodak\kodak share button app\KGShare_App.exe
uRun: [GoogleDriveSync] "d:\program files\google\drive\googledrivesync.exe" /autostart
uRun: [EPSON NX300 Series] d:\windows\system32\spool\drivers\w32x86\3\e_fatieja.exe /fu "d:\windows\temp\E_S5270.tmp" /EF "HKCU"
uRun: [BYR_AGENT] d:\lgmobileupgrade\lgmobileax\byr_client\VZWNotiAgent.exe
uRun: [Spybot-S&D Cleaning] "d:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [avgnt] "d:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [00PCTFW] "d:\program files\pc tools firewall plus\FirewallGUI.exe" -s
mRun: [Adobe ARM] "d:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [APSDaemon] "d:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Monitor] "d:\program files\leapfrog\leapfrog connect\Monitor.exe"
mRun: [Windows Mobile Device Center] d:\windows\windowsmobile\wmdc.exe
mRun: [TkBellExe] "d:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [BYR_AGENT] d:\programdata\lgmobileax\byr_client\VZWNotiAgent.exe
mRun: [Launch PC Probe II] "d:\program files\asus\pc probe ii\Probe2.exe" 1
mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "d:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SDTray] "d:\program files\spybot - search & destroy 2\SDTray.exe"
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - d:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - d:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{337AE17F-5C22-4479-9234-0E7582AA9796} : DHCPNameServer = 192.168.1.1
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - d:\users\jacobs family\appdata\roaming\mozilla\firefox\profiles\monq11y0.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=100486&babsrc=KW_ss&mntrId=04be9d2c0000000000008000600fe800&q=
FF - plugin: d:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: d:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: d:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: d:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: d:\program files\real\realplayer\netscape6\nprpplugin.dll
FF - plugin: d:\program files\virtools\3d life player\npvirtools.dll
FF - plugin: d:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: d:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: d:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: d:\users\jacobs family\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: d:\windows\system32\adobe\director\np32dsw_1168638.dll
FF - plugin: d:\windows\system32\macromed\flash\NPSWF32_11_5_502_135.dll
FF - plugin: d:\windows\system32\npdeployJava1.dll
FF - plugin: d:\windows\system32\npmproxy.dll
FF - ExtSQL: 2012-11-04 17:21; {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}; d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=100486
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 04be9d2c0000000000008000600fe800
FF - user.js: extensions.BabylonToolbar_i.hardId - 04be9d2c0000000000008000600fe800
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15450
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:16:54
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? dmvsc;dmvsc
R? EagleXNt;EagleXNt
R? SDWSCService;Spybot-S&D 2 Security Center Service
R? StorSvc;Storage Service
R? TsUsbFlt;TsUsbFlt
R? TsUsbGD;Remote Desktop Generic USB Device
R? WatAdminSvc;Windows Activation Technologies Service
S? AMD External Events Utility;AMD External Events Utility
S? AntiVirSchedulerService;Avira Scheduler
S? AntiVirService;Avira Realtime Protection
S? avgntflt;avgntflt
S? avkmgr;avkmgr
S? PCTAppEvent;PCTAppEvent Driver
S? PCTFW-DNS;PCTools Firewall - DNS driver
S? PCTFW-PacketFilter;PCTools Firewall - Packet filter driver
S? pctgntdi;pctgntdi
S? pctNDIS;PC Tools Driver
S? PCToolsFirewallPlus;PC Tools Firewall Plus
S? pctplfw;pctplfw
S? RTL8167;Realtek 8167 NT Driver
S? SDScannerService;Spybot-S&D 2 Scanner Service
S? SDUpdateService;Spybot-S&D 2 Updating Service
.
=============== Created Last 30 ================
.
2012-12-28 19:08:16 -------- d-----w- D:\sh4ldr
2012-12-28 19:08:16 -------- d-----w- d:\program files\Enigma Software Group
2012-12-28 19:07:56 -------- d-----w- d:\windows\DDABC66756B3412282B02F5782EA2F9A.TMP
2012-12-28 19:07:55 -------- d-----w- d:\program files\common files\Wise Installation Wizard
2012-12-28 18:27:36 -------- d-----w- d:\windows\pss
2012-12-28 17:32:01 -------- d-----w- d:\programdata\Spybot - Search & Destroy
2012-12-28 17:31:53 15224 ----a-w- d:\windows\system32\sdnclean.exe
2012-12-28 17:31:51 -------- d-----w- d:\program files\Spybot - Search & Destroy 2
2012-12-28 17:30:59 -------- d-----w- d:\users\jacobs family\appdata\local\Programs
2012-12-28 09:26:19 6812136 ----a-w- d:\programdata\microsoft\windows defender\definition updates\{931999c0-0505-4800-af8c-39443d5449f7}\mpengine.dll
2012-12-21 09:00:25 34304 ----a-w- d:\windows\system32\atmlib.dll
2012-12-21 09:00:25 295424 ----a-w- d:\windows\system32\atmfd.dll
2012-12-11 19:33:39 2345984 ----a-w- d:\windows\system32\win32k.sys
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin7.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin6.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin5.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin4.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin3.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin2.dll
2012-12-05 19:39:31 159744 ----a-w- d:\program files\internet explorer\plugins\npqtplugin.dll
2012-12-05 19:25:09 93672 ----a-w- d:\windows\system32\WindowsAccessBridge.dll
.
==================== Find3M ====================
.
2012-12-11 22:22:43 73656 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-11 22:22:43 697272 ----a-w- d:\windows\system32\FlashPlayerApp.exe
2012-12-05 19:24:41 821736 ----a-w- d:\windows\system32\npdeployJava1.dll
2012-12-05 19:24:41 746984 ----a-w- d:\windows\system32\deployJava1.dll
2012-11-14 02:09:22 1800704 ----a-w- d:\windows\system32\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- d:\windows\system32\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- d:\windows\system32\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- d:\windows\system32\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- d:\windows\system32\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- d:\windows\system32\mshtml.tlb
2012-11-09 04:42:49 2048 ----a-w- d:\windows\system32\tzres.dll
2012-11-02 05:11:31 376832 ----a-w- d:\windows\system32\dpnet.dll
2012-10-25 09:12:26 94208 ----a-w- d:\windows\system32\QuickTimeVR.qtx
2012-10-25 09:12:26 69632 ----a-w- d:\windows\system32\QuickTime.qts
2012-10-16 07:39:52 561664 ----a-w- d:\windows\apppatch\AcLayers.dll
2012-10-09 17:40:31 44032 ----a-w- d:\windows\system32\dhcpcsvc6.dll
2012-10-09 17:40:31 193536 ----a-w- d:\windows\system32\dhcpcore6.dll
2012-10-04 16:47:18 169984 ----a-w- d:\windows\system32\winsrv.dll
2012-10-04 16:43:05 293376 ----a-w- d:\windows\system32\KernelBase.dll
2012-10-04 14:57:58 271360 ----a-w- d:\windows\system32\conhost.exe
2012-10-04 14:41:50 6144 ---ha-w- d:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-10-04 14:41:50 4608 ---ha-w- d:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-10-04 14:41:50 3584 ---ha-w- d:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-10-04 14:41:50 3072 ---ha-w- d:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-10-03 16:58:30 1293680 ----a-w- d:\windows\system32\drivers\tcpip.sys
2012-10-03 16:42:26 52224 ----a-w- d:\windows\system32\nlaapi.dll
2012-10-03 16:42:26 242176 ----a-w- d:\windows\system32\nlasvc.dll
2012-10-03 16:42:24 18944 ----a-w- d:\windows\system32\netevent.dll
2012-10-03 16:42:24 175104 ----a-w- d:\windows\system32\netcorehc.dll
2012-10-03 16:42:23 156672 ----a-w- d:\windows\system32\ncsi.dll
2012-10-03 16:40:35 499712 ----a-w- d:\windows\system32\iphlpsvc.dll
2012-10-03 15:21:38 35328 ----a-w- d:\windows\system32\drivers\tcpipreg.sys
.
============= FINISH: 15:20:42.94 ===============
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-28 15:38:48
-----------------------------
15:38:48.293 OS Version: Windows 6.1.7601 Service Pack 1
15:38:48.293 Number of processors: 4 586 0x402
15:38:48.293 ComputerName: JACOBSFAMILY-PC UserName: Jacobs Family
15:38:57.637 Initialize success
15:39:08.401 AVAST engine defs: 12122800
15:39:11.677 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000069
15:39:11.677 Disk 0 Vendor: AMD_____ 1.10 Size: 610490MB BusType: 8
15:39:11.693 Disk 0 MBR read successfully
15:39:11.693 Disk 0 MBR scan
15:39:11.724 Disk 0 Windows 7 default MBR code
15:39:11.724 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 300002 MB offset 63
15:39:11.724 Disk 0 Partition - 00 0F Extended LBA 310474 MB offset 614405925
15:39:11.739 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 310474 MB offset 614405988
15:39:11.739 Disk 0 scanning sectors +1250258625
15:39:11.802 Disk 0 scanning D:\Windows\system32\drivers
15:39:22.832 Service scanning
15:39:43.112 Modules scanning
15:39:46.934 Disk 0 trace - called modules:
15:39:47.497 ntkrnlpa.exe CLASSPNP.SYS disk.sys storport.sys halmacpi.dll amdsbs.sys
15:39:47.512 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8617d030]
15:39:47.528 3 CLASSPNP.SYS[8bb9759e] -> nt!IofCallDriver -> \Device\00000069[0x85e69b78]
15:39:48.729 AVAST engine scan D:\Windows
15:39:51.225 AVAST engine scan D:\Windows\system32
15:44:08.062 AVAST engine scan D:\Windows\system32\drivers
15:44:30.917 AVAST engine scan D:\Users\Jacobs Family
15:46:59.153 Disk 0 MBR has been saved successfully to "D:\Users\Jacobs Family\Desktop\MBR.dat"
15:46:59.159 The log file has been saved successfully to "D:\Users\Jacobs Family\Desktop\aswMBR.txt"