Hi all,
Started with Google selections redirected to other locations, then other search engines started doing it too. Lately browser itself seemed unstable (one time rapidly opening new windows almost as fast as I could close them).
Tried Kaspersky online scanner and Malawarebytes, then installed Norton 360. Infection still there. Thank you in advance, however this goes! Logs to follow:
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16457
Run by Parents at 17:45:39 on 2013-01-28
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.1917 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\SLsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\IB Updater\ExtensionUpdaterService.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Norton 360\Engine\20.2.1.22\ccSvcHst.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Norton 360\Engine\20.2.1.22\ccSvcHst.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\System32\CTXFIHLP.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_5_502_146_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.drudgereport.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
BHO: Deal Vault: {11111111-1111-1111-1111-110111981166} - c:\program files\deal vault\Deal Vault.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton 360\engine\20.2.1.22\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton 360\engine\20.2.1.22\ips\ipsbho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton 360\engine\20.2.1.22\coieplg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe
uRun: [Hewlett-Packard] rundll32 "c:\users\parents\appdata\local\hp\hewlett-packard\ticle.dll",NVCoInstallerW
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [CTXFIREG] CTxfiReg.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRunOnce: [Launcher] c:\windows\sminst\launcher.exe
dRunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy'
StartupFolder: c:\users\parents\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\users\parents\appdata\roaming\micros~1\windows\startm~1\programs\startup\monito~1.lnk - c:\windows\system32\RunDll32.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpconn~1.lnk - c:\program files\hp connections\6811507\program\HP Connections.exe
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{927B7D6A-1939-4D25-93D7-E2F8D36D8DDB} : DHCPNameServer = 192.168.1.1
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\1402010.016\symds.sys [2013-1-25 368288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\1402010.016\symefa.sys [2013-1-25 927904]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.0.24\definitions\bashdefs\20130116.013\BHDrvx86.sys [2013-1-16 997464]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\1402010.016\ccsetx86.sys [2013-1-25 134304]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.0.24\definitions\ipsdefs\20130124.001\IDSvix86.sys [2013-1-24 386720]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\1402010.016\ironx86.sys [2013-1-25 175264]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\1402010.016\symtdiv.sys [2013-1-25 350368]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2012-11-10 21504]
R2 IB Updater;IB Updater;c:\program files\ib updater\ExtensionUpdaterService.exe [2013-1-24 188760]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-1-24 398184]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-1-24 682344]
R2 N360;Norton 360;c:\program files\norton 360\engine\20.2.1.22\ccsvchst.exe [2013-1-25 143928]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2012-11-11 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2013-1-24 106656]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-1-24 21104]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2013-01-25 05:25:47 350368 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symtdiv.sys
2013-01-25 05:25:47 338592 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symnets.sys
2013-01-25 05:25:47 21400 ----a-r- c:\windows\system32\drivers\n360\1402010.016\symelam.sys
2013-01-25 05:25:46 927904 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symefa.sys
2013-01-25 05:25:46 586400 ----a-w- c:\windows\system32\drivers\n360\1402010.016\srtsp.sys
2013-01-25 05:25:46 368288 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symds.sys
2013-01-25 05:25:46 32888 ----a-r- c:\windows\system32\drivers\n360\1402010.016\srtspx.sys
2013-01-25 05:25:46 175264 ----a-w- c:\windows\system32\drivers\n360\1402010.016\ironx86.sys
2013-01-25 05:25:45 134304 ----a-w- c:\windows\system32\drivers\n360\1402010.016\ccsetx86.sys
2013-01-25 05:24:58 9103 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symvtcer.dat
2013-01-25 05:24:58 -------- d-----w- c:\windows\system32\drivers\n360\1402010.016
2013-01-25 02:20:25 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2013-01-25 02:20:25 -------- d-----w- c:\program files\Symantec
2013-01-25 02:18:42 -------- d-----w- c:\windows\system32\drivers\N360
2013-01-25 02:18:28 -------- d-----w- c:\program files\Norton 360
2013-01-25 02:18:27 -------- d-----w- c:\programdata\Norton
2013-01-25 02:14:04 -------- d-----w- c:\programdata\NortonInstaller
2013-01-25 02:14:04 -------- d-----w- c:\program files\NortonInstaller
2013-01-24 23:46:22 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-24 23:46:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-24 23:46:02 -------- d-----w- c:\users\parents\appdata\local\Threat Expert
2013-01-24 23:45:46 -------- d-----w- c:\users\parents\appdata\local\Deal Vault
2013-01-24 23:45:34 632656 ----a-w- c:\windows\system32\msvcr80.dll
2013-01-24 23:45:34 554832 ----a-w- c:\windows\system32\msvcp80.dll
2013-01-24 23:45:34 479232 ----a-w- c:\windows\system32\msvcm80.dll
2013-01-24 23:45:34 28160 ----a-w- c:\windows\system32\ImHttpComm.dll
2013-01-24 23:45:34 -------- d-----w- c:\windows\system32\ARFC
2013-01-24 23:45:33 -------- d-----w- c:\windows\system32\WNLT
2013-01-24 23:45:33 -------- d-----w- c:\users\parents\appdata\local\Updater19866
2013-01-24 23:45:29 -------- d-----w- c:\program files\IB Updater
2013-01-24 23:45:18 -------- d-----w- c:\program files\Deal Vault
2013-01-24 23:03:56 -------- d-----w- c:\program files\PC Tools
2013-01-24 22:59:24 202280 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2013-01-24 22:59:24 -------- d-----w- c:\program files\common files\PC Tools
2013-01-24 22:58:59 -------- d-----w- c:\users\parents\appdata\roaming\TestApp
2013-01-24 22:58:59 -------- d-----w- c:\programdata\PC Tools
2013-01-24 01:09:35 -------- d-----w- c:\program files\Citrix
2013-01-24 01:09:19 60864 ----a-w- c:\users\parents\g2mdlhlpx.exe
2013-01-22 13:21:15 6991832 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{0725835c-8f22-40e4-bb69-b835b8a30434}\mpengine.dll
2013-01-09 02:26:17 2048000 ----a-w- c:\windows\system32\win32k.sys
2013-01-09 02:25:59 204288 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-09 02:25:58 1400832 ----a-w- c:\windows\system32\msxml6.dll
.
==================== Find3M ====================
.
2013-01-09 00:02:16 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-09 00:02:16 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-16 13:12:54 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 10:50:29 293376 ----a-w- c:\windows\system32\atmfd.dll
2012-11-14 02:09:22 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-13 01:29:51 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-11 13:36:58 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-11-11 13:36:58 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-11-10 23:57:41 98816 ----a-w- c:\windows\system32\mfps.dll
2012-11-10 14:11:57 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2012-11-10 14:11:57 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2012-11-10 12:46:50 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-11-10 12:46:48 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-11-10 08:34:15 61440 ----a-w- c:\windows\system32\winipsec.dll
2012-11-10 08:34:15 272896 ----a-w- c:\windows\system32\polstore.dll
2012-11-10 08:32:25 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2012-11-10 08:32:25 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2012-11-10 08:32:25 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2012-11-10 08:32:25 19968 ----a-w- c:\windows\system32\ARP.EXE
2012-11-10 08:32:25 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2012-11-10 08:32:25 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2012-11-10 08:32:25 105984 ----a-w- c:\windows\system32\netiohlp.dll
2012-11-10 08:32:25 10240 ----a-w- c:\windows\system32\finger.exe
2012-11-10 08:30:56 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2012-11-10 08:30:55 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2012-11-10 08:30:55 65024 ----a-w- c:\windows\system32\wlanapi.dll
2012-11-10 08:30:55 513536 ----a-w- c:\windows\system32\wlansvc.dll
2012-11-10 08:30:55 302592 ----a-w- c:\windows\system32\wlansec.dll
2012-11-10 08:30:55 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2012-11-10 08:30:54 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2012-11-10 08:30:16 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-11-10 08:30:15 2048 ----a-w- c:\windows\system32\msxml6r.dll
2012-11-10 08:29:34 218624 ----a-w- c:\windows\system32\msv1_0.dll
2012-11-10 08:28:14 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2012-11-10 08:28:14 24576 ----a-w- c:\windows\system32\mfpmp.exe
2012-11-10 08:28:14 2048 ----a-w- c:\windows\system32\mferror.dll
2012-11-10 08:24:32 71680 ----a-w- c:\windows\system32\atl.dll
2012-11-10 08:21:37 160256 ----a-w- c:\windows\system32\wkssvc.dll
2012-11-10 08:20:57 53248 ----a-w- c:\windows\system32\tsgqec.dll
2012-11-10 08:20:57 136192 ----a-w- c:\windows\system32\aaclient.dll
2012-11-10 08:14:09 499712 ----a-w- c:\windows\system32\kerberos.dll
2012-11-10 08:14:09 175104 ----a-w- c:\windows\system32\wdigest.dll
2012-11-10 08:12:36 6656 ----a-w- c:\windows\system32\kbd106n.dll
2012-11-10 08:11:29 62464 ----a-w- c:\windows\system32\l3codeca.acm
2012-11-10 08:11:29 220672 ----a-w- c:\windows\system32\l3codecp.acm
2012-11-10 08:10:54 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-11-10 08:10:54 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2012-11-10 08:10:54 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-11-10 08:10:54 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2012-11-10 08:09:54 98304 ----a-w- c:\windows\system32\cabview.dll
2012-11-10 08:09:39 37888 ----a-w- c:\windows\system32\printcom.dll
2012-11-10 08:09:11 14848 ----a-w- c:\windows\system32\wshrm.dll
2012-11-10 08:08:53 43520 ----a-w- c:\windows\system32\msdxm.tlb
2012-11-10 08:08:53 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2012-11-10 08:08:53 18432 ----a-w- c:\windows\system32\amcompat.tlb
2012-11-10 08:08:52 7680 ----a-w- c:\windows\system32\spwmp.dll
2012-11-10 08:08:52 4096 ----a-w- c:\windows\system32\msdxm.ocx
2012-11-10 08:08:52 4096 ----a-w- c:\windows\system32\dxmasf.dll
2012-11-10 08:07:17 84480 ----a-w- c:\windows\system32\INETRES.dll
2012-11-10 08:06:56 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2012-11-10 08:06:28 411648 ----a-w- c:\windows\system32\drivers\http.sys
2012-11-10 08:06:28 30720 ----a-w- c:\windows\system32\httpapi.dll
2012-11-10 08:06:28 24064 ----a-w- c:\windows\system32\nshhttp.dll
2012-11-10 08:05:10 243712 ----a-w- c:\windows\system32\rastls.dll
2012-11-10 08:04:56 355328 ----a-w- c:\windows\system32\WSDApi.dll
2012-11-10 08:04:11 91136 ----a-w- c:\windows\system32\avifil32.dll
2012-11-10 08:04:11 82944 ----a-w- c:\windows\system32\mciavi32.dll
2012-11-10 08:04:11 65024 ----a-w- c:\windows\system32\avicap32.dll
2012-11-10 08:04:11 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2012-11-10 08:04:11 31744 ----a-w- c:\windows\system32\msvidc32.dll
2012-11-10 08:04:11 22528 ----a-w- c:\windows\system32\msyuv.dll
2012-11-10 08:04:11 13312 ----a-w- c:\windows\system32\msrle32.dll
2012-11-10 08:04:11 123904 ----a-w- c:\windows\system32\msvfw32.dll
2012-11-10 08:04:11 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2012-11-02 10:18:17 376320 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26:06 23040 ----a-w- c:\windows\system32\dpnsvr.exe
.
============= FINISH: 17:46:33.87 ===============
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-01-28 18:04:03
-----------------------------
18:04:03.933 OS Version: Windows 6.0.6002 Service Pack 2
18:04:03.933 Number of processors: 2 586 0xF02
18:04:03.933 ComputerName: HPVISTA-PC UserName: Parents
18:04:08.254 Initialize success
18:06:00.495 AVAST engine defs: 13012800
18:06:04.317 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-0
18:06:04.317 Disk 0 Vendor: Hitachi_HDS721050CLA362 JP2OA50E Size: 476940MB BusType: 3
18:06:04.333 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-4
18:06:04.333 Disk 1 Vendor: Hitachi_HDT725032VLA360 V54OA52A Size: 305245MB BusType: 3
18:06:04.349 Disk 0 MBR read successfully
18:06:04.349 Disk 0 MBR scan
18:06:04.364 Disk 0 unknown MBR code
18:06:04.364 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 459640 MB offset 63
18:06:04.411 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 17296 MB offset 941344740
18:06:04.442 Disk 0 scanning sectors +976768065
18:06:04.583 Disk 0 scanning C:\Windows\system32\drivers
18:06:18.108 Service scanning
18:06:44.269 Modules scanning
18:06:53.067 Disk 0 trace - called modules:
18:06:53.083 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
18:06:53.099 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86013ac8]
18:06:53.114 3 CLASSPNP.SYS[8b1a38b3] -> nt!IofCallDriver -> [0x856d2918]
18:06:53.114 5 acpi.sys[822a26bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-0[0x856d5030]
18:06:54.487 AVAST engine scan C:\Windows
18:06:57.389 AVAST engine scan C:\Windows\system32
18:09:52.903 AVAST engine scan C:\Windows\system32\drivers
18:10:07.302 AVAST engine scan C:\Users\Parents
18:10:10.999 File: C:\Users\Parents\AppData\Local\HP\Hewlett-Packard\ticle.dll **INFECTED** Win32:BHO-AJG [Trj]
18:11:23.305 Disk 0 MBR has been saved successfully to "C:\Users\Parents\Desktop\MBR.dat"
18:11:23.320 The log file has been saved successfully to "C:\Users\Parents\Desktop\aswMBRlog.txt"
Started with Google selections redirected to other locations, then other search engines started doing it too. Lately browser itself seemed unstable (one time rapidly opening new windows almost as fast as I could close them).
Tried Kaspersky online scanner and Malawarebytes, then installed Norton 360. Infection still there. Thank you in advance, however this goes! Logs to follow:
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16457
Run by Parents at 17:45:39 on 2013-01-28
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.1917 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\SLsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\IB Updater\ExtensionUpdaterService.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Norton 360\Engine\20.2.1.22\ccSvcHst.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Norton 360\Engine\20.2.1.22\ccSvcHst.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\System32\CTXFIHLP.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_5_502_146_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.drudgereport.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop
BHO: Deal Vault: {11111111-1111-1111-1111-110111981166} - c:\program files\deal vault\Deal Vault.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton 360\engine\20.2.1.22\coieplg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton 360\engine\20.2.1.22\ips\ipsbho.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton 360\engine\20.2.1.22\coieplg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe
uRun: [Hewlett-Packard] rundll32 "c:\users\parents\appdata\local\hp\hewlett-packard\ticle.dll",NVCoInstallerW
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [CTXFIREG] CTxfiReg.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRunOnce: [Launcher] c:\windows\sminst\launcher.exe
dRunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy'
StartupFolder: c:\users\parents\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\users\parents\appdata\roaming\micros~1\windows\startm~1\programs\startup\monito~1.lnk - c:\windows\system32\RunDll32.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpconn~1.lnk - c:\program files\hp connections\6811507\program\HP Connections.exe
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{927B7D6A-1939-4D25-93D7-E2F8D36D8DDB} : DHCPNameServer = 192.168.1.1
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\1402010.016\symds.sys [2013-1-25 368288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\1402010.016\symefa.sys [2013-1-25 927904]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.0.24\definitions\bashdefs\20130116.013\BHDrvx86.sys [2013-1-16 997464]
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\1402010.016\ccsetx86.sys [2013-1-25 134304]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.0.24\definitions\ipsdefs\20130124.001\IDSvix86.sys [2013-1-24 386720]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\1402010.016\ironx86.sys [2013-1-25 175264]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\1402010.016\symtdiv.sys [2013-1-25 350368]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2012-11-10 21504]
R2 IB Updater;IB Updater;c:\program files\ib updater\ExtensionUpdaterService.exe [2013-1-24 188760]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-1-24 398184]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-1-24 682344]
R2 N360;Norton 360;c:\program files\norton 360\engine\20.2.1.22\ccsvchst.exe [2013-1-25 143928]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2012-11-11 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2013-1-24 106656]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-1-24 21104]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2013-01-25 05:25:47 350368 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symtdiv.sys
2013-01-25 05:25:47 338592 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symnets.sys
2013-01-25 05:25:47 21400 ----a-r- c:\windows\system32\drivers\n360\1402010.016\symelam.sys
2013-01-25 05:25:46 927904 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symefa.sys
2013-01-25 05:25:46 586400 ----a-w- c:\windows\system32\drivers\n360\1402010.016\srtsp.sys
2013-01-25 05:25:46 368288 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symds.sys
2013-01-25 05:25:46 32888 ----a-r- c:\windows\system32\drivers\n360\1402010.016\srtspx.sys
2013-01-25 05:25:46 175264 ----a-w- c:\windows\system32\drivers\n360\1402010.016\ironx86.sys
2013-01-25 05:25:45 134304 ----a-w- c:\windows\system32\drivers\n360\1402010.016\ccsetx86.sys
2013-01-25 05:24:58 9103 ----a-w- c:\windows\system32\drivers\n360\1402010.016\symvtcer.dat
2013-01-25 05:24:58 -------- d-----w- c:\windows\system32\drivers\n360\1402010.016
2013-01-25 02:20:25 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2013-01-25 02:20:25 -------- d-----w- c:\program files\Symantec
2013-01-25 02:18:42 -------- d-----w- c:\windows\system32\drivers\N360
2013-01-25 02:18:28 -------- d-----w- c:\program files\Norton 360
2013-01-25 02:18:27 -------- d-----w- c:\programdata\Norton
2013-01-25 02:14:04 -------- d-----w- c:\programdata\NortonInstaller
2013-01-25 02:14:04 -------- d-----w- c:\program files\NortonInstaller
2013-01-24 23:46:22 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-24 23:46:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-24 23:46:02 -------- d-----w- c:\users\parents\appdata\local\Threat Expert
2013-01-24 23:45:46 -------- d-----w- c:\users\parents\appdata\local\Deal Vault
2013-01-24 23:45:34 632656 ----a-w- c:\windows\system32\msvcr80.dll
2013-01-24 23:45:34 554832 ----a-w- c:\windows\system32\msvcp80.dll
2013-01-24 23:45:34 479232 ----a-w- c:\windows\system32\msvcm80.dll
2013-01-24 23:45:34 28160 ----a-w- c:\windows\system32\ImHttpComm.dll
2013-01-24 23:45:34 -------- d-----w- c:\windows\system32\ARFC
2013-01-24 23:45:33 -------- d-----w- c:\windows\system32\WNLT
2013-01-24 23:45:33 -------- d-----w- c:\users\parents\appdata\local\Updater19866
2013-01-24 23:45:29 -------- d-----w- c:\program files\IB Updater
2013-01-24 23:45:18 -------- d-----w- c:\program files\Deal Vault
2013-01-24 23:03:56 -------- d-----w- c:\program files\PC Tools
2013-01-24 22:59:24 202280 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2013-01-24 22:59:24 -------- d-----w- c:\program files\common files\PC Tools
2013-01-24 22:58:59 -------- d-----w- c:\users\parents\appdata\roaming\TestApp
2013-01-24 22:58:59 -------- d-----w- c:\programdata\PC Tools
2013-01-24 01:09:35 -------- d-----w- c:\program files\Citrix
2013-01-24 01:09:19 60864 ----a-w- c:\users\parents\g2mdlhlpx.exe
2013-01-22 13:21:15 6991832 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{0725835c-8f22-40e4-bb69-b835b8a30434}\mpengine.dll
2013-01-09 02:26:17 2048000 ----a-w- c:\windows\system32\win32k.sys
2013-01-09 02:25:59 204288 ----a-w- c:\windows\system32\ncrypt.dll
2013-01-09 02:25:58 1400832 ----a-w- c:\windows\system32\msxml6.dll
.
==================== Find3M ====================
.
2013-01-09 00:02:16 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-09 00:02:16 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-16 13:12:54 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 10:50:29 293376 ----a-w- c:\windows\system32\atmfd.dll
2012-11-14 02:09:22 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-13 01:29:51 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-11 13:36:58 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-11-11 13:36:58 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-11-10 23:57:41 98816 ----a-w- c:\windows\system32\mfps.dll
2012-11-10 14:11:57 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2012-11-10 14:11:57 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2012-11-10 12:46:50 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-11-10 12:46:48 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-11-10 08:34:15 61440 ----a-w- c:\windows\system32\winipsec.dll
2012-11-10 08:34:15 272896 ----a-w- c:\windows\system32\polstore.dll
2012-11-10 08:32:25 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2012-11-10 08:32:25 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2012-11-10 08:32:25 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2012-11-10 08:32:25 19968 ----a-w- c:\windows\system32\ARP.EXE
2012-11-10 08:32:25 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2012-11-10 08:32:25 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2012-11-10 08:32:25 105984 ----a-w- c:\windows\system32\netiohlp.dll
2012-11-10 08:32:25 10240 ----a-w- c:\windows\system32\finger.exe
2012-11-10 08:30:56 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2012-11-10 08:30:55 68096 ----a-w- c:\windows\system32\wlanhlp.dll
2012-11-10 08:30:55 65024 ----a-w- c:\windows\system32\wlanapi.dll
2012-11-10 08:30:55 513536 ----a-w- c:\windows\system32\wlansvc.dll
2012-11-10 08:30:55 302592 ----a-w- c:\windows\system32\wlansec.dll
2012-11-10 08:30:55 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2012-11-10 08:30:54 15181 ----a-w- c:\windows\system32\gatherWirelessInfo.vbs
2012-11-10 08:30:16 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-11-10 08:30:15 2048 ----a-w- c:\windows\system32\msxml6r.dll
2012-11-10 08:29:34 218624 ----a-w- c:\windows\system32\msv1_0.dll
2012-11-10 08:28:14 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2012-11-10 08:28:14 24576 ----a-w- c:\windows\system32\mfpmp.exe
2012-11-10 08:28:14 2048 ----a-w- c:\windows\system32\mferror.dll
2012-11-10 08:24:32 71680 ----a-w- c:\windows\system32\atl.dll
2012-11-10 08:21:37 160256 ----a-w- c:\windows\system32\wkssvc.dll
2012-11-10 08:20:57 53248 ----a-w- c:\windows\system32\tsgqec.dll
2012-11-10 08:20:57 136192 ----a-w- c:\windows\system32\aaclient.dll
2012-11-10 08:14:09 499712 ----a-w- c:\windows\system32\kerberos.dll
2012-11-10 08:14:09 175104 ----a-w- c:\windows\system32\wdigest.dll
2012-11-10 08:12:36 6656 ----a-w- c:\windows\system32\kbd106n.dll
2012-11-10 08:11:29 62464 ----a-w- c:\windows\system32\l3codeca.acm
2012-11-10 08:11:29 220672 ----a-w- c:\windows\system32\l3codecp.acm
2012-11-10 08:10:54 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-11-10 08:10:54 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2012-11-10 08:10:54 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-11-10 08:10:54 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2012-11-10 08:09:54 98304 ----a-w- c:\windows\system32\cabview.dll
2012-11-10 08:09:39 37888 ----a-w- c:\windows\system32\printcom.dll
2012-11-10 08:09:11 14848 ----a-w- c:\windows\system32\wshrm.dll
2012-11-10 08:08:53 43520 ----a-w- c:\windows\system32\msdxm.tlb
2012-11-10 08:08:53 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2012-11-10 08:08:53 18432 ----a-w- c:\windows\system32\amcompat.tlb
2012-11-10 08:08:52 7680 ----a-w- c:\windows\system32\spwmp.dll
2012-11-10 08:08:52 4096 ----a-w- c:\windows\system32\msdxm.ocx
2012-11-10 08:08:52 4096 ----a-w- c:\windows\system32\dxmasf.dll
2012-11-10 08:07:17 84480 ----a-w- c:\windows\system32\INETRES.dll
2012-11-10 08:06:56 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2012-11-10 08:06:28 411648 ----a-w- c:\windows\system32\drivers\http.sys
2012-11-10 08:06:28 30720 ----a-w- c:\windows\system32\httpapi.dll
2012-11-10 08:06:28 24064 ----a-w- c:\windows\system32\nshhttp.dll
2012-11-10 08:05:10 243712 ----a-w- c:\windows\system32\rastls.dll
2012-11-10 08:04:56 355328 ----a-w- c:\windows\system32\WSDApi.dll
2012-11-10 08:04:11 91136 ----a-w- c:\windows\system32\avifil32.dll
2012-11-10 08:04:11 82944 ----a-w- c:\windows\system32\mciavi32.dll
2012-11-10 08:04:11 65024 ----a-w- c:\windows\system32\avicap32.dll
2012-11-10 08:04:11 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2012-11-10 08:04:11 31744 ----a-w- c:\windows\system32\msvidc32.dll
2012-11-10 08:04:11 22528 ----a-w- c:\windows\system32\msyuv.dll
2012-11-10 08:04:11 13312 ----a-w- c:\windows\system32\msrle32.dll
2012-11-10 08:04:11 123904 ----a-w- c:\windows\system32\msvfw32.dll
2012-11-10 08:04:11 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2012-11-02 10:18:17 376320 ----a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26:06 23040 ----a-w- c:\windows\system32\dpnsvr.exe
.
============= FINISH: 17:46:33.87 ===============
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-01-28 18:04:03
-----------------------------
18:04:03.933 OS Version: Windows 6.0.6002 Service Pack 2
18:04:03.933 Number of processors: 2 586 0xF02
18:04:03.933 ComputerName: HPVISTA-PC UserName: Parents
18:04:08.254 Initialize success
18:06:00.495 AVAST engine defs: 13012800
18:06:04.317 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-0
18:06:04.317 Disk 0 Vendor: Hitachi_HDS721050CLA362 JP2OA50E Size: 476940MB BusType: 3
18:06:04.333 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-4
18:06:04.333 Disk 1 Vendor: Hitachi_HDT725032VLA360 V54OA52A Size: 305245MB BusType: 3
18:06:04.349 Disk 0 MBR read successfully
18:06:04.349 Disk 0 MBR scan
18:06:04.364 Disk 0 unknown MBR code
18:06:04.364 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 459640 MB offset 63
18:06:04.411 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 17296 MB offset 941344740
18:06:04.442 Disk 0 scanning sectors +976768065
18:06:04.583 Disk 0 scanning C:\Windows\system32\drivers
18:06:18.108 Service scanning
18:06:44.269 Modules scanning
18:06:53.067 Disk 0 trace - called modules:
18:06:53.083 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
18:06:53.099 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86013ac8]
18:06:53.114 3 CLASSPNP.SYS[8b1a38b3] -> nt!IofCallDriver -> [0x856d2918]
18:06:53.114 5 acpi.sys[822a26bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-0[0x856d5030]
18:06:54.487 AVAST engine scan C:\Windows
18:06:57.389 AVAST engine scan C:\Windows\system32
18:09:52.903 AVAST engine scan C:\Windows\system32\drivers
18:10:07.302 AVAST engine scan C:\Users\Parents
18:10:10.999 File: C:\Users\Parents\AppData\Local\HP\Hewlett-Packard\ticle.dll **INFECTED** Win32:BHO-AJG [Trj]
18:11:23.305 Disk 0 MBR has been saved successfully to "C:\Users\Parents\Desktop\MBR.dat"
18:11:23.320 The log file has been saved successfully to "C:\Users\Parents\Desktop\aswMBRlog.txt"