Robertomac
New member
Hi,
I've picked up a virus claiming to be from the Metropolitan Police saying it has detect illegal activity on my machine and I have to pay a £100 fine to get rid of it! This virus brings up a screen immediately after the machines starts up which I am unable to remove.
The only way I can now access my machine is if I start windows in safe mode.
Hope someone can help!
------ DDS Log -----
.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.7.2
Run by Rob at 9:41:29 on 2012-10-03
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3039.2326 [GMT 1:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SimpleGatewayService\service\SimpleService.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=SNYT
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Google Update] "c:\users\rob\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [vtvdbveczjsvtfv] c:\programdata\vtvdbvec.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - c:\microgaming\poker\ladbrokesmpp\MPPoker.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.90
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C} : DhcpNameServer = 192.168.0.90
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\0554455425D20534F52456C6B696E6 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\244575966496 : DhcpNameServer = 192.168.22.22 192.168.22.23
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\35F4E495C4140545F40523F5E4564777F627B6 : DhcpNameServer = 193.36.79.100 193.36.79.101
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\35F4E495C4140545F40523F5E4564777F627B6F513 : DhcpNameServer = 193.36.79.101 193.36.79.100
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\4586560234C6F65746 : DhcpNameServer = 87.236.128.54 91.143.64.59
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\C696E6B6379737 : DhcpNameServer = 193.36.79.100 193.36.79.101
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: VESWinlogon - VESWinlogon.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\rob\appdata\roaming\mozilla\firefox\profiles\oewn5vwf.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=113&systemid=406&sr=0&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\users\rob\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_278.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R2 SimpleGateway Service;SimpleGateway Service;c:\program files\simplegatewayservice\service\SimpleService.exe [2009-7-16 88656]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2009-4-22 1768376]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2009-9-8 4231680]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2009-5-15 9344]
S2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-26 176128]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-25 136176]
S2 Mezzmo;Mezzmo;c:\program files\conceiva\mezzmo\MezzmoMediaServer.exe [2011-8-29 2664784]
S2 NSUService;NSUService;c:\program files\sony\network utility\NSUService.exe [2009-12-17 303104]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-18 11032]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2009-6-26 362992]
S2 RtkAudioService;Realtek Audio Service;c:\program files\realtek\audio\hda\RtkAudioService.exe [2009-12-17 133664]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-20 1153368]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S2 SOHCImp;VAIO Media plus Content Importer;c:\program files\common files\sony shared\sohlib\SOHCImp.exe [2009-12-17 120104]
S2 SOHDBSvr;VAIO Media plus Database Manager;c:\program files\common files\sony shared\sohlib\SOHDBSvr.exe [2009-12-17 70952]
S2 SOHDms;VAIO Media plus Digital Media Server;c:\program files\common files\sony shared\sohlib\SOHDms.exe [2009-12-17 427304]
S2 SOHDs;VAIO Media plus Device Searcher;c:\program files\common files\sony shared\sohlib\SOHDs.exe [2009-12-17 75048]
S2 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files\common files\sony shared\sohlib\SOHPlMgr.exe [2009-12-17 91432]
S2 uCamMonitor;CamMonitor;c:\program files\arcsoft\magic-i visual effects 2\uCamMonitor.exe [2009-6-18 104960]
S2 VAIO Power Management;VAIO Power Management;c:\program files\sony\vaio power management\SPMService.exe [2009-12-17 415592]
S2 VCFw;VAIO Content Folder Watcher;c:\program files\common files\sony shared\vaio content folder watcher\VCFw.exe [2009-1-14 5184872]
S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2009-12-17 468264]
S2 yksvc;Marvell Yukon Service;c:\windows\system32\svchost.exe -k yksvcs [2009-7-14 20992]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-2 250288]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\drivers\ArcSoftKsUFilter.sys [2009-6-18 17920]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2009-5-15 29736]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-11-18 23888]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-9-27 106656]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-25 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-7-25 114144]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2009-6-26 313840]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-7 52224]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2009-12-17 83240]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-5-25 1343400]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
.
=============== Created Last 30 ================
.
2012-10-03 07:35:12 -------- d-----w- c:\programdata\qopbtyuczalkedw
2012-10-03 07:35:11 107520 ----a-w- c:\programdata\vtvdbvec.exe
2012-10-03 07:35:05 107520 ----a-w- c:\users\rob\ms.exe
2012-10-02 21:47:14 -------- d-----w- c:\users\rob\appdata\local\{040F02F8-44B4-4B39-AB8F-8D192A3B18CF}
2012-10-02 09:04:52 -------- d-----w- c:\users\rob\appdata\local\{2AC3CCA3-BEDB-4A90-8E1A-C6A27F059346}
2012-10-01 21:04:28 -------- d-----w- c:\users\rob\appdata\local\{71AF728C-BD16-476F-BC5D-1AB577AA1E7E}
2012-10-01 09:04:03 -------- d-----w- c:\users\rob\appdata\local\{9F370336-4325-46E9-A7DE-BEC7C948E6CA}
2012-09-30 09:03:28 -------- d-----w- c:\users\rob\appdata\local\{16706077-772C-434F-B4CA-E10335309AF8}
2012-09-29 09:02:53 -------- d-----w- c:\users\rob\appdata\local\{52459947-7EA2-4B80-B6E0-C3FBF400AD1E}
2012-09-28 21:01:46 -------- d-----w- c:\users\rob\appdata\local\{EA097D24-FAC6-4378-B952-0D7C8B3A080A}
2012-09-28 07:48:19 -------- d-----w- c:\users\rob\appdata\local\{8100F575-16B4-4175-A04E-001525712A15}
2012-09-27 07:39:58 -------- d-----w- c:\users\rob\appdata\local\{3D59D889-A4F6-4E81-BD6B-8A9C1DBA00AA}
2012-09-26 08:41:30 -------- d-----w- c:\users\rob\appdata\local\{52F64F1E-6CCA-4F6A-8325-8F96ACE638F0}
2012-09-25 20:41:03 -------- d-----w- c:\users\rob\appdata\local\{922F5A16-D9D2-4EC9-B710-5B0AE54747B6}
2012-09-25 08:40:40 -------- d-----w- c:\users\rob\appdata\local\{FC79D61D-E983-47AE-B83B-C754DFE97A84}
2012-09-24 20:40:15 -------- d-----w- c:\users\rob\appdata\local\{5B4AC3E7-494D-403C-81E9-564B9E619789}
2012-09-24 08:39:51 -------- d-----w- c:\users\rob\appdata\local\{19202510-FF5E-4FB3-80E9-F22D133455C8}
2012-09-23 20:39:26 -------- d-----w- c:\users\rob\appdata\local\{34436A24-819D-450C-BD24-10323F31F780}
2012-09-23 08:39:00 -------- d-----w- c:\users\rob\appdata\local\{DB995933-193D-43C3-93CE-FECA0D2376D6}
2012-09-22 20:38:39 -------- d-----w- c:\users\rob\appdata\local\{FEBA4E6B-B47B-4B6E-A5F4-FCCEF202631B}
2012-09-22 08:53:59 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-09-22 08:38:00 -------- d-----w- c:\users\rob\appdata\local\{99D0396F-39B7-48DF-9097-8081F151F34F}
2012-09-21 20:05:26 -------- d-----w- c:\users\rob\appdata\local\{51003E27-0814-4A7D-A0AD-CF7661691BB7}
2012-09-21 08:05:01 -------- d-----w- c:\users\rob\appdata\local\{19F122B1-92DF-47C8-AEEE-832717E64A27}
2012-09-20 20:04:37 -------- d-----w- c:\users\rob\appdata\local\{0D2F0303-8FF3-46F9-A40E-6CBFC690415C}
2012-09-20 08:04:13 -------- d-----w- c:\users\rob\appdata\local\{0CE7F19C-0AEB-4225-BA5A-07383FE25446}
2012-09-19 20:03:49 -------- d-----w- c:\users\rob\appdata\local\{C6AD761F-0A75-4091-8DBC-EBB5D88A558C}
2012-09-19 08:03:24 -------- d-----w- c:\users\rob\appdata\local\{2F43E508-8D30-4063-B70E-C97201F5C832}
2012-09-18 20:03:01 -------- d-----w- c:\users\rob\appdata\local\{A0D1BEDE-2FBC-42ED-A39F-DE1D1C91F3F4}
2012-09-18 08:02:03 -------- d-----w- c:\users\rob\appdata\local\{CC2B2B9E-1E33-4BF4-8A3F-59543D4CB330}
2012-09-17 19:31:07 -------- d-----w- c:\users\rob\appdata\local\{2470794C-3B51-4AA7-9707-1EE24CC34880}
2012-09-17 07:10:29 -------- d-----w- c:\users\rob\appdata\local\{5C07CF4C-1ABF-443E-976E-6CBFAAA54D8A}
2012-09-16 12:41:29 -------- d-----w- c:\users\rob\appdata\local\{2B68FD9D-9BF3-4A54-936F-0856532EC12A}
2012-09-15 22:59:38 -------- d-----w- c:\users\rob\appdata\local\{58C80EA9-FB1A-4F1C-9D8C-CA897AA1850F}
2012-09-15 10:59:23 -------- d-----w- c:\users\rob\appdata\local\{28DB2DE8-27D4-420C-9710-80BD17FB6188}
2012-09-14 20:21:03 -------- d-----w- c:\users\rob\appdata\local\{920CABBB-E926-4754-AB78-4EF59D7807D2}
2012-09-14 08:20:33 -------- d-----w- c:\users\rob\appdata\local\{13DF5660-03EC-4E74-ABE0-15EAB8EDFD30}
2012-09-13 20:19:53 -------- d-----w- c:\users\rob\appdata\local\{4DACBD7A-5913-4125-A838-187B70C82F4F}
2012-09-13 20:07:33 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-13 20:06:31 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-13 08:19:28 -------- d-----w- c:\users\rob\appdata\local\{499D18A5-68FA-4597-867E-B2E7BA103222}
2012-09-12 20:19:04 -------- d-----w- c:\users\rob\appdata\local\{A49748B8-6E9D-4281-8575-7F9954343AB9}
2012-09-12 17:00:22 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 17:00:22 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 17:00:22 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 08:18:40 -------- d-----w- c:\users\rob\appdata\local\{572FC6E9-32CF-4804-8124-1A05B4193A0B}
2012-09-11 20:18:17 -------- d-----w- c:\users\rob\appdata\local\{D68E13FD-CFF7-46FD-97C6-FBAF2FE8E169}
2012-09-11 08:17:52 -------- d-----w- c:\users\rob\appdata\local\{9DFB23E8-81DD-4916-A6C9-AD94F2215F02}
2012-09-10 20:17:29 -------- d-----w- c:\users\rob\appdata\local\{52BD13D4-A793-4B13-8C7D-164D8D5ACE22}
2012-09-10 08:16:29 -------- d-----w- c:\users\rob\appdata\local\{F6A14C0F-105E-45D9-86EA-6E398193247E}
2012-09-09 19:06:00 -------- d-----w- c:\users\rob\appdata\local\{94DB305B-1534-4C79-AC47-C88D10E1D43D}
2012-09-09 07:03:44 -------- d-----w- c:\users\rob\appdata\local\{4762145C-1576-4EAC-A0BA-27354F892E7E}
2012-09-08 20:03:48 -------- d-----w- c:\users\rob\appdata\local\{55E890D8-45A6-48B8-9391-E5C0F1C0A3CD}
2012-09-08 08:03:24 -------- d-----w- c:\users\rob\appdata\local\{7F6E943E-2037-41FC-AAA7-A866B40DC5C6}
2012-09-07 20:03:00 -------- d-----w- c:\users\rob\appdata\local\{3F17E31A-5476-4C00-8CF6-D96F06AAF9CD}
2012-09-07 08:02:04 -------- d-----w- c:\users\rob\appdata\local\{AEA81D40-5A85-4BB4-9119-6E54F8402911}
2012-09-06 19:57:44 -------- d-----w- c:\users\rob\appdata\local\{5206B994-AC1B-456A-A4A6-5283D7449627}
2012-09-06 07:57:19 -------- d-----w- c:\users\rob\appdata\local\{D3AD8FF4-0A5D-4E48-9899-A6A59E8AD16A}
2012-09-05 08:29:03 -------- d-----w- c:\users\rob\appdata\local\{650D655B-850B-4A56-BA75-1E0AA93B93AB}
2012-09-04 20:28:38 -------- d-----w- c:\users\rob\appdata\local\{54F53F3C-87F7-4202-B745-7C3E43AA7C62}
2012-09-04 08:28:18 -------- d-----w- c:\users\rob\appdata\local\{C9E8A9DA-D817-41B9-8A32-D5FBF35B98D7}
2012-09-03 19:54:43 -------- d-----w- c:\users\rob\appdata\local\{D65B1AE2-9352-427F-BCDD-BFF28166E3D5}
.
==================== Find3M ====================
.
2012-09-30 17:03:24 174056 ----a-w- c:\windows\system32\drivers\WpsHelper.sys
2012-09-21 12:06:12 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-21 12:06:12 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-13 20:05:48 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-24 16:57:48 981504 ----a-w- c:\windows\system32\wininet.dll
2012-07-18 17:47:53 2345984 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 9:42:58.66 ===============
------ aswMBRLog -----
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-03 09:47:31
-----------------------------
09:47:31.697 OS Version: Windows 6.1.7601 Service Pack 1
09:47:31.697 Number of processors: 2 586 0x170A
09:47:31.697 ComputerName: SONYLAPTOP2 UserName: Rob
09:47:32.789 Initialize success
09:48:19.168 AVAST engine defs: 12100300
09:49:21.662 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:49:21.677 Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
09:49:21.677 Disk 1 \Device\Harddisk1\DR1 -> \Device\0000007e
09:49:21.677 Disk 1 Vendor: RICOH 01 Size: 3777MB BusType: 0
09:49:21.677 Disk 2 \Device\Harddisk2\DR2 -> \Device\0000007f
09:49:21.677 Disk 2 Vendor: RICOH 02 Size: 3777MB BusType: 0
09:49:21.708 Disk 0 MBR read successfully
09:49:21.724 Disk 0 MBR scan
09:49:21.724 Disk 0 Windows 7 default MBR code
09:49:21.740 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 10508 MB offset 2048
09:49:21.755 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 466430 MB offset 21522432
09:49:21.786 Disk 0 scanning sectors +976771120
09:49:21.864 Disk 0 scanning C:\Windows\system32\drivers
09:49:34.625 Service scanning
09:50:07.073 Service Teefer2 C:\Windows\system32\DRIVERS\teefer2.sys **LOCKED** 32
09:50:14.499 Service WPS C:\Windows\system32\drivers\wpsdrvnt.sys **LOCKED** 32
09:50:14.608 Service WpsHelper C:\Windows\system32\drivers\WpsHelper.sys **LOCKED** 32
09:50:16.449 Modules scanning
09:50:27.400 Disk 0 trace - called modules:
09:50:27.447 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys
09:50:27.447 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8628e618]
09:50:27.447 3 CLASSPNP.SYS[8b0bb59e] -> nt!IofCallDriver -> [0x85846848]
09:50:27.478 5 ACPI.sys[8a89b3d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85da6028]
09:50:28.601 AVAST engine scan C:\Windows
09:50:31.893 AVAST engine scan C:\Windows\system32
09:53:28.033 AVAST engine scan C:\Windows\system32\drivers
09:53:54.662 AVAST engine scan C:\Users\Rob
09:55:06.157 Disk 0 MBR has been saved successfully to "C:\Users\Rob\Desktop\MBR.dat"
09:55:06.173 The log file has been saved successfully to "C:\Users\Rob\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-03 09:47:31
-----------------------------
09:47:31.697 OS Version: Windows 6.1.7601 Service Pack 1
09:47:31.697 Number of processors: 2 586 0x170A
09:47:31.697 ComputerName: SONYLAPTOP2 UserName: Rob
09:47:32.789 Initialize success
09:48:19.168 AVAST engine defs: 12100300
09:49:21.662 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:49:21.677 Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
09:49:21.677 Disk 1 \Device\Harddisk1\DR1 -> \Device\0000007e
09:49:21.677 Disk 1 Vendor: RICOH 01 Size: 3777MB BusType: 0
09:49:21.677 Disk 2 \Device\Harddisk2\DR2 -> \Device\0000007f
09:49:21.677 Disk 2 Vendor: RICOH 02 Size: 3777MB BusType: 0
09:49:21.708 Disk 0 MBR read successfully
09:49:21.724 Disk 0 MBR scan
09:49:21.724 Disk 0 Windows 7 default MBR code
09:49:21.740 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 10508 MB offset 2048
09:49:21.755 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 466430 MB offset 21522432
09:49:21.786 Disk 0 scanning sectors +976771120
09:49:21.864 Disk 0 scanning C:\Windows\system32\drivers
09:49:34.625 Service scanning
09:50:07.073 Service Teefer2 C:\Windows\system32\DRIVERS\teefer2.sys **LOCKED** 32
09:50:14.499 Service WPS C:\Windows\system32\drivers\wpsdrvnt.sys **LOCKED** 32
09:50:14.608 Service WpsHelper C:\Windows\system32\drivers\WpsHelper.sys **LOCKED** 32
09:50:16.449 Modules scanning
09:50:27.400 Disk 0 trace - called modules:
09:50:27.447 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys
09:50:27.447 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8628e618]
09:50:27.447 3 CLASSPNP.SYS[8b0bb59e] -> nt!IofCallDriver -> [0x85846848]
09:50:27.478 5 ACPI.sys[8a89b3d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85da6028]
09:50:28.601 AVAST engine scan C:\Windows
09:50:31.893 AVAST engine scan C:\Windows\system32
09:53:28.033 AVAST engine scan C:\Windows\system32\drivers
09:53:54.662 AVAST engine scan C:\Users\Rob
09:55:06.157 Disk 0 MBR has been saved successfully to "C:\Users\Rob\Desktop\MBR.dat"
09:55:06.173 The log file has been saved successfully to "C:\Users\Rob\Desktop\aswMBR.txt"
10:17:51.956 Disk 0 MBR has been saved successfully to "C:\Users\Rob\Desktop\MBR.dat"
10:17:51.956 The log file has been saved successfully to "C:\Users\Rob\Desktop\aswMBR.txt"
I've picked up a virus claiming to be from the Metropolitan Police saying it has detect illegal activity on my machine and I have to pay a £100 fine to get rid of it! This virus brings up a screen immediately after the machines starts up which I am unable to remove.
The only way I can now access my machine is if I start windows in safe mode.
Hope someone can help!
------ DDS Log -----
.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.7.2
Run by Rob at 9:41:29 on 2012-10-03
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3039.2326 [GMT 1:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SimpleGatewayService\service\SimpleService.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=SNYT
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Google Update] "c:\users\rob\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [vtvdbveczjsvtfv] c:\programdata\vtvdbvec.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - c:\microgaming\poker\ladbrokesmpp\MPPoker.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.90
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C} : DhcpNameServer = 192.168.0.90
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\0554455425D20534F52456C6B696E6 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\244575966496 : DhcpNameServer = 192.168.22.22 192.168.22.23
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\35F4E495C4140545F40523F5E4564777F627B6 : DhcpNameServer = 193.36.79.100 193.36.79.101
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\35F4E495C4140545F40523F5E4564777F627B6F513 : DhcpNameServer = 193.36.79.101 193.36.79.100
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\4586560234C6F65746 : DhcpNameServer = 87.236.128.54 91.143.64.59
TCP: Interfaces\{ABE96790-4686-40BD-8E31-EC2D5119169C}\C696E6B6379737 : DhcpNameServer = 193.36.79.100 193.36.79.101
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: VESWinlogon - VESWinlogon.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\rob\appdata\roaming\mozilla\firefox\profiles\oewn5vwf.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=113&systemid=406&sr=0&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\users\rob\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_278.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R2 SimpleGateway Service;SimpleGateway Service;c:\program files\simplegatewayservice\service\SimpleService.exe [2009-7-16 88656]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2009-4-22 1768376]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2009-9-8 4231680]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2009-5-15 9344]
S2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-14 20992]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-26 176128]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-25 136176]
S2 Mezzmo;Mezzmo;c:\program files\conceiva\mezzmo\MezzmoMediaServer.exe [2011-8-29 2664784]
S2 NSUService;NSUService;c:\program files\sony\network utility\NSUService.exe [2009-12-17 303104]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-18 11032]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2009-6-26 362992]
S2 RtkAudioService;Realtek Audio Service;c:\program files\realtek\audio\hda\RtkAudioService.exe [2009-12-17 133664]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-20 1153368]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S2 SOHCImp;VAIO Media plus Content Importer;c:\program files\common files\sony shared\sohlib\SOHCImp.exe [2009-12-17 120104]
S2 SOHDBSvr;VAIO Media plus Database Manager;c:\program files\common files\sony shared\sohlib\SOHDBSvr.exe [2009-12-17 70952]
S2 SOHDms;VAIO Media plus Digital Media Server;c:\program files\common files\sony shared\sohlib\SOHDms.exe [2009-12-17 427304]
S2 SOHDs;VAIO Media plus Device Searcher;c:\program files\common files\sony shared\sohlib\SOHDs.exe [2009-12-17 75048]
S2 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files\common files\sony shared\sohlib\SOHPlMgr.exe [2009-12-17 91432]
S2 uCamMonitor;CamMonitor;c:\program files\arcsoft\magic-i visual effects 2\uCamMonitor.exe [2009-6-18 104960]
S2 VAIO Power Management;VAIO Power Management;c:\program files\sony\vaio power management\SPMService.exe [2009-12-17 415592]
S2 VCFw;VAIO Content Folder Watcher;c:\program files\common files\sony shared\vaio content folder watcher\VCFw.exe [2009-1-14 5184872]
S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2009-12-17 468264]
S2 yksvc;Marvell Yukon Service;c:\windows\system32\svchost.exe -k yksvcs [2009-7-14 20992]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-2 250288]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\drivers\ArcSoftKsUFilter.sys [2009-6-18 17920]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2009-5-15 29736]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-11-18 23888]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-9-27 106656]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-25 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-7-25 114144]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2009-6-26 313840]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-7 52224]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2009-12-17 83240]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-5-25 1343400]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
.
=============== Created Last 30 ================
.
2012-10-03 07:35:12 -------- d-----w- c:\programdata\qopbtyuczalkedw
2012-10-03 07:35:11 107520 ----a-w- c:\programdata\vtvdbvec.exe
2012-10-03 07:35:05 107520 ----a-w- c:\users\rob\ms.exe
2012-10-02 21:47:14 -------- d-----w- c:\users\rob\appdata\local\{040F02F8-44B4-4B39-AB8F-8D192A3B18CF}
2012-10-02 09:04:52 -------- d-----w- c:\users\rob\appdata\local\{2AC3CCA3-BEDB-4A90-8E1A-C6A27F059346}
2012-10-01 21:04:28 -------- d-----w- c:\users\rob\appdata\local\{71AF728C-BD16-476F-BC5D-1AB577AA1E7E}
2012-10-01 09:04:03 -------- d-----w- c:\users\rob\appdata\local\{9F370336-4325-46E9-A7DE-BEC7C948E6CA}
2012-09-30 09:03:28 -------- d-----w- c:\users\rob\appdata\local\{16706077-772C-434F-B4CA-E10335309AF8}
2012-09-29 09:02:53 -------- d-----w- c:\users\rob\appdata\local\{52459947-7EA2-4B80-B6E0-C3FBF400AD1E}
2012-09-28 21:01:46 -------- d-----w- c:\users\rob\appdata\local\{EA097D24-FAC6-4378-B952-0D7C8B3A080A}
2012-09-28 07:48:19 -------- d-----w- c:\users\rob\appdata\local\{8100F575-16B4-4175-A04E-001525712A15}
2012-09-27 07:39:58 -------- d-----w- c:\users\rob\appdata\local\{3D59D889-A4F6-4E81-BD6B-8A9C1DBA00AA}
2012-09-26 08:41:30 -------- d-----w- c:\users\rob\appdata\local\{52F64F1E-6CCA-4F6A-8325-8F96ACE638F0}
2012-09-25 20:41:03 -------- d-----w- c:\users\rob\appdata\local\{922F5A16-D9D2-4EC9-B710-5B0AE54747B6}
2012-09-25 08:40:40 -------- d-----w- c:\users\rob\appdata\local\{FC79D61D-E983-47AE-B83B-C754DFE97A84}
2012-09-24 20:40:15 -------- d-----w- c:\users\rob\appdata\local\{5B4AC3E7-494D-403C-81E9-564B9E619789}
2012-09-24 08:39:51 -------- d-----w- c:\users\rob\appdata\local\{19202510-FF5E-4FB3-80E9-F22D133455C8}
2012-09-23 20:39:26 -------- d-----w- c:\users\rob\appdata\local\{34436A24-819D-450C-BD24-10323F31F780}
2012-09-23 08:39:00 -------- d-----w- c:\users\rob\appdata\local\{DB995933-193D-43C3-93CE-FECA0D2376D6}
2012-09-22 20:38:39 -------- d-----w- c:\users\rob\appdata\local\{FEBA4E6B-B47B-4B6E-A5F4-FCCEF202631B}
2012-09-22 08:53:59 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-09-22 08:38:00 -------- d-----w- c:\users\rob\appdata\local\{99D0396F-39B7-48DF-9097-8081F151F34F}
2012-09-21 20:05:26 -------- d-----w- c:\users\rob\appdata\local\{51003E27-0814-4A7D-A0AD-CF7661691BB7}
2012-09-21 08:05:01 -------- d-----w- c:\users\rob\appdata\local\{19F122B1-92DF-47C8-AEEE-832717E64A27}
2012-09-20 20:04:37 -------- d-----w- c:\users\rob\appdata\local\{0D2F0303-8FF3-46F9-A40E-6CBFC690415C}
2012-09-20 08:04:13 -------- d-----w- c:\users\rob\appdata\local\{0CE7F19C-0AEB-4225-BA5A-07383FE25446}
2012-09-19 20:03:49 -------- d-----w- c:\users\rob\appdata\local\{C6AD761F-0A75-4091-8DBC-EBB5D88A558C}
2012-09-19 08:03:24 -------- d-----w- c:\users\rob\appdata\local\{2F43E508-8D30-4063-B70E-C97201F5C832}
2012-09-18 20:03:01 -------- d-----w- c:\users\rob\appdata\local\{A0D1BEDE-2FBC-42ED-A39F-DE1D1C91F3F4}
2012-09-18 08:02:03 -------- d-----w- c:\users\rob\appdata\local\{CC2B2B9E-1E33-4BF4-8A3F-59543D4CB330}
2012-09-17 19:31:07 -------- d-----w- c:\users\rob\appdata\local\{2470794C-3B51-4AA7-9707-1EE24CC34880}
2012-09-17 07:10:29 -------- d-----w- c:\users\rob\appdata\local\{5C07CF4C-1ABF-443E-976E-6CBFAAA54D8A}
2012-09-16 12:41:29 -------- d-----w- c:\users\rob\appdata\local\{2B68FD9D-9BF3-4A54-936F-0856532EC12A}
2012-09-15 22:59:38 -------- d-----w- c:\users\rob\appdata\local\{58C80EA9-FB1A-4F1C-9D8C-CA897AA1850F}
2012-09-15 10:59:23 -------- d-----w- c:\users\rob\appdata\local\{28DB2DE8-27D4-420C-9710-80BD17FB6188}
2012-09-14 20:21:03 -------- d-----w- c:\users\rob\appdata\local\{920CABBB-E926-4754-AB78-4EF59D7807D2}
2012-09-14 08:20:33 -------- d-----w- c:\users\rob\appdata\local\{13DF5660-03EC-4E74-ABE0-15EAB8EDFD30}
2012-09-13 20:19:53 -------- d-----w- c:\users\rob\appdata\local\{4DACBD7A-5913-4125-A838-187B70C82F4F}
2012-09-13 20:07:33 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-13 20:06:31 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-13 08:19:28 -------- d-----w- c:\users\rob\appdata\local\{499D18A5-68FA-4597-867E-B2E7BA103222}
2012-09-12 20:19:04 -------- d-----w- c:\users\rob\appdata\local\{A49748B8-6E9D-4281-8575-7F9954343AB9}
2012-09-12 17:00:22 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-12 17:00:22 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-12 17:00:22 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-12 08:18:40 -------- d-----w- c:\users\rob\appdata\local\{572FC6E9-32CF-4804-8124-1A05B4193A0B}
2012-09-11 20:18:17 -------- d-----w- c:\users\rob\appdata\local\{D68E13FD-CFF7-46FD-97C6-FBAF2FE8E169}
2012-09-11 08:17:52 -------- d-----w- c:\users\rob\appdata\local\{9DFB23E8-81DD-4916-A6C9-AD94F2215F02}
2012-09-10 20:17:29 -------- d-----w- c:\users\rob\appdata\local\{52BD13D4-A793-4B13-8C7D-164D8D5ACE22}
2012-09-10 08:16:29 -------- d-----w- c:\users\rob\appdata\local\{F6A14C0F-105E-45D9-86EA-6E398193247E}
2012-09-09 19:06:00 -------- d-----w- c:\users\rob\appdata\local\{94DB305B-1534-4C79-AC47-C88D10E1D43D}
2012-09-09 07:03:44 -------- d-----w- c:\users\rob\appdata\local\{4762145C-1576-4EAC-A0BA-27354F892E7E}
2012-09-08 20:03:48 -------- d-----w- c:\users\rob\appdata\local\{55E890D8-45A6-48B8-9391-E5C0F1C0A3CD}
2012-09-08 08:03:24 -------- d-----w- c:\users\rob\appdata\local\{7F6E943E-2037-41FC-AAA7-A866B40DC5C6}
2012-09-07 20:03:00 -------- d-----w- c:\users\rob\appdata\local\{3F17E31A-5476-4C00-8CF6-D96F06AAF9CD}
2012-09-07 08:02:04 -------- d-----w- c:\users\rob\appdata\local\{AEA81D40-5A85-4BB4-9119-6E54F8402911}
2012-09-06 19:57:44 -------- d-----w- c:\users\rob\appdata\local\{5206B994-AC1B-456A-A4A6-5283D7449627}
2012-09-06 07:57:19 -------- d-----w- c:\users\rob\appdata\local\{D3AD8FF4-0A5D-4E48-9899-A6A59E8AD16A}
2012-09-05 08:29:03 -------- d-----w- c:\users\rob\appdata\local\{650D655B-850B-4A56-BA75-1E0AA93B93AB}
2012-09-04 20:28:38 -------- d-----w- c:\users\rob\appdata\local\{54F53F3C-87F7-4202-B745-7C3E43AA7C62}
2012-09-04 08:28:18 -------- d-----w- c:\users\rob\appdata\local\{C9E8A9DA-D817-41B9-8A32-D5FBF35B98D7}
2012-09-03 19:54:43 -------- d-----w- c:\users\rob\appdata\local\{D65B1AE2-9352-427F-BCDD-BFF28166E3D5}
.
==================== Find3M ====================
.
2012-09-30 17:03:24 174056 ----a-w- c:\windows\system32\drivers\WpsHelper.sys
2012-09-21 12:06:12 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-21 12:06:12 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-13 20:05:48 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-24 16:57:48 981504 ----a-w- c:\windows\system32\wininet.dll
2012-07-18 17:47:53 2345984 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 9:42:58.66 ===============
------ aswMBRLog -----
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-03 09:47:31
-----------------------------
09:47:31.697 OS Version: Windows 6.1.7601 Service Pack 1
09:47:31.697 Number of processors: 2 586 0x170A
09:47:31.697 ComputerName: SONYLAPTOP2 UserName: Rob
09:47:32.789 Initialize success
09:48:19.168 AVAST engine defs: 12100300
09:49:21.662 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:49:21.677 Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
09:49:21.677 Disk 1 \Device\Harddisk1\DR1 -> \Device\0000007e
09:49:21.677 Disk 1 Vendor: RICOH 01 Size: 3777MB BusType: 0
09:49:21.677 Disk 2 \Device\Harddisk2\DR2 -> \Device\0000007f
09:49:21.677 Disk 2 Vendor: RICOH 02 Size: 3777MB BusType: 0
09:49:21.708 Disk 0 MBR read successfully
09:49:21.724 Disk 0 MBR scan
09:49:21.724 Disk 0 Windows 7 default MBR code
09:49:21.740 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 10508 MB offset 2048
09:49:21.755 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 466430 MB offset 21522432
09:49:21.786 Disk 0 scanning sectors +976771120
09:49:21.864 Disk 0 scanning C:\Windows\system32\drivers
09:49:34.625 Service scanning
09:50:07.073 Service Teefer2 C:\Windows\system32\DRIVERS\teefer2.sys **LOCKED** 32
09:50:14.499 Service WPS C:\Windows\system32\drivers\wpsdrvnt.sys **LOCKED** 32
09:50:14.608 Service WpsHelper C:\Windows\system32\drivers\WpsHelper.sys **LOCKED** 32
09:50:16.449 Modules scanning
09:50:27.400 Disk 0 trace - called modules:
09:50:27.447 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys
09:50:27.447 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8628e618]
09:50:27.447 3 CLASSPNP.SYS[8b0bb59e] -> nt!IofCallDriver -> [0x85846848]
09:50:27.478 5 ACPI.sys[8a89b3d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85da6028]
09:50:28.601 AVAST engine scan C:\Windows
09:50:31.893 AVAST engine scan C:\Windows\system32
09:53:28.033 AVAST engine scan C:\Windows\system32\drivers
09:53:54.662 AVAST engine scan C:\Users\Rob
09:55:06.157 Disk 0 MBR has been saved successfully to "C:\Users\Rob\Desktop\MBR.dat"
09:55:06.173 The log file has been saved successfully to "C:\Users\Rob\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-03 09:47:31
-----------------------------
09:47:31.697 OS Version: Windows 6.1.7601 Service Pack 1
09:47:31.697 Number of processors: 2 586 0x170A
09:47:31.697 ComputerName: SONYLAPTOP2 UserName: Rob
09:47:32.789 Initialize success
09:48:19.168 AVAST engine defs: 12100300
09:49:21.662 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:49:21.677 Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
09:49:21.677 Disk 1 \Device\Harddisk1\DR1 -> \Device\0000007e
09:49:21.677 Disk 1 Vendor: RICOH 01 Size: 3777MB BusType: 0
09:49:21.677 Disk 2 \Device\Harddisk2\DR2 -> \Device\0000007f
09:49:21.677 Disk 2 Vendor: RICOH 02 Size: 3777MB BusType: 0
09:49:21.708 Disk 0 MBR read successfully
09:49:21.724 Disk 0 MBR scan
09:49:21.724 Disk 0 Windows 7 default MBR code
09:49:21.740 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 10508 MB offset 2048
09:49:21.755 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 466430 MB offset 21522432
09:49:21.786 Disk 0 scanning sectors +976771120
09:49:21.864 Disk 0 scanning C:\Windows\system32\drivers
09:49:34.625 Service scanning
09:50:07.073 Service Teefer2 C:\Windows\system32\DRIVERS\teefer2.sys **LOCKED** 32
09:50:14.499 Service WPS C:\Windows\system32\drivers\wpsdrvnt.sys **LOCKED** 32
09:50:14.608 Service WpsHelper C:\Windows\system32\drivers\WpsHelper.sys **LOCKED** 32
09:50:16.449 Modules scanning
09:50:27.400 Disk 0 trace - called modules:
09:50:27.447 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys
09:50:27.447 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8628e618]
09:50:27.447 3 CLASSPNP.SYS[8b0bb59e] -> nt!IofCallDriver -> [0x85846848]
09:50:27.478 5 ACPI.sys[8a89b3d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85da6028]
09:50:28.601 AVAST engine scan C:\Windows
09:50:31.893 AVAST engine scan C:\Windows\system32
09:53:28.033 AVAST engine scan C:\Windows\system32\drivers
09:53:54.662 AVAST engine scan C:\Users\Rob
09:55:06.157 Disk 0 MBR has been saved successfully to "C:\Users\Rob\Desktop\MBR.dat"
09:55:06.173 The log file has been saved successfully to "C:\Users\Rob\Desktop\aswMBR.txt"
10:17:51.956 Disk 0 MBR has been saved successfully to "C:\Users\Rob\Desktop\MBR.dat"
10:17:51.956 The log file has been saved successfully to "C:\Users\Rob\Desktop\aswMBR.txt"