jasonburnaby
New member
Hello,
I have a message from Windows that my computer has a virus: Win32/Adload/DA
So far I haven't noticed anything unusual but according to Windows it stopped my computer from running 1 time (two days ago)
Before seeking help from you I ran HitMan, OTL, TDSSkiller, aswMBR and the Avast boot-up scan. None of them found any infections.
I've followed your prepost instructions- did the registry and ran DDS and aswMBR (again). I've attached the DDS file and below I'm pasting the DDS and aswMBR logs.
I'd greatly appreciate any help you can give me!
Here's the DDS log:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by Jason at 11:03:31 on 2012-09-13
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2038.721 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\AsusService.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
C:\windows\system32\EscSvc.exe
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\ASUS\LivCam\LivCam.exe
C:\Program Files\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Users\Jason\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIIBA.EXE
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3225826
uDefault_Page_URL = hxxp://asus.msn.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: BitTorrentControl_v12 Toolbar: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - c:\program files\bittorrentcontrol_v12\prxtbBitT.dll
mURLSearchHooks: BitTorrentControl_v12 Toolbar: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - c:\program files\bittorrentcontrol_v12\prxtbBitT.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: BitTorrentControl_v12 Toolbar: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - c:\program files\bittorrentcontrol_v12\prxtbBitT.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: BitTorrentControl_v12 Toolbar: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - c:\program files\bittorrentcontrol_v12\prxtbBitT.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\jason\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [EPLTarget\P0000000000000000] c:\windows\system32\spool\drivers\w32x86\3\e_fatiiba.exe /ept "epltarget\P0000000000000000" /M "XP-400 Series"
uRun: [BitTorrent] "c:\program files\bittorrent\BitTorrent.exe" /MINIMIZED
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [HotkeyMon] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotKeyMon.exe
mRun: [HotkeyService] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotkeyService.exe
mRun: [SuperHybridEngine] AsusSender.exe c:\program files\eeepc\she\SuperHybridEngine.exe
mRun: [EeeStorageBackup] c:\program files\asus\asus webstorage\service\AsusWSService.exe MySyncFolder
mRun: [Eee Docking] c:\program files\asus\eee docking\Eee Docking.exe autorun
mRun: [LiveUpdate] AsusSender.exe c:\program files\asus\liveupdate\LiveUpdate.exe auto
mRun: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [IgfxExt] c:\windows\system32\IgfxExt.exe /RegServer
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [LivCam] "c:\program files\asus\livcam\LivCam.exe"
mRun: [ASUSWebStorage] c:\program files\asus\asus webstorage\3.0.108.222\AsusWSPanel.exe /S
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [CLMLServer] "c:\program files\cyberlink\power2go\CLMLSvc.exe"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [LGODDFU] "c:\program files\lg_fwupdate\fwupdate.exe" blrun
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
mRun: [LTCM Client] c:\program files\ltcm client\ltcmClient.exe /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\jason\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\asusvi~1.lnk - c:\program files\asus\asusvibe\AsusVibeLauncher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BCB96184-E700-4D7A-A71C-E0FC5352A65B} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\14D6472716B634F6E6E65636473547164796F6E6 : DhcpNameServer = 208.67.222.222 208.67.220.220
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\3416275737F68323 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\34369616076693 : DhcpNameServer = 192.168.27.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\45865602245616E6 : DhcpNameServer = 10.0.1.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\54C625F626C6566556274656 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\861607079786F6D656D27657563747 : DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.33.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\A5978554C40274D253730335 : DhcpNameServer = 212.142.144.66 212.142.144.98
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
============= SERVICES / DRIVERS ===============
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2009-12-21 11832]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-29 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-9-29 355632]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AsusService;Asus Launcher Service;c:\windows\system32\AsusService.exe [2009-12-21 219136]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-9-29 21256]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-9-29 58680]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-9-5 44808]
R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-10-13 249648]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\common files\epson\epw!3 ssrp\E_S50ST7.EXE [2012-8-27 167520]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\common files\epson\epw!3 ssrp\E_S50RP7.EXE [2012-8-27 142432]
R2 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\epson\epsoncustomerparticipation\EPCP.exe [2011-6-9 521600]
R2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\escsvc.exe [2012-8-27 122000]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-11-16 43944]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2009-12-21 29472]
R3 igd;igd;c:\windows\system32\drivers\igdkmd32.sys [2009-11-16 635168]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-11-16 51712]
S2 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-10-21 196176]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-29 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-9-8 250568]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-9-28 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-29 136176]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-10-1 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-9-30 1343400]
.
=============== Created Last 30 ================
.
2012-09-13 13:57:47 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{7f8b6eca-3b33-41f3-97ab-b5de15393c45}\offreg.dll
2012-09-13 05:25:10 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-13 05:25:09 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 05:24:47 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-13 05:24:47 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-13 05:24:46 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 05:20:23 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-13 01:12:21 -------- d-----w- c:\programdata\HitmanPro
2012-09-13 00:38:17 -------- d-----w- c:\users\jason\appdata\roaming\Malwarebytes
2012-09-13 00:37:55 -------- d-----w- c:\programdata\Malwarebytes
2012-09-13 00:37:49 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-13 00:37:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-12 01:57:05 -------- d-----w- c:\windows\system32\SPReview
2012-09-12 01:54:57 -------- d-----w- c:\windows\system32\EventProviders
2012-09-11 12:33:35 7022536 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{7f8b6eca-3b33-41f3-97ab-b5de15393c45}\mpengine.dll
2012-09-09 03:05:41 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-06 03:50:10 -------- d-----w- c:\users\jason\Tambien la Lluvia [dvdrip][spanish][AC3 5.1][www.lokotorrents.com]
2012-09-06 03:49:51 -------- d-----w- c:\users\jason\Azul.Oscuro.Casi.Negro.[Dvdrip][Spanish][www.FanCluBT.com]
2012-09-06 03:35:03 -------- d-----w- c:\users\jason\{www.scenetime.com}Princesas (2005) Fernando Leon de Aranoa
2012-09-06 02:51:31 -------- d-----w- c:\users\jason\Cell.211.2009.BDRip.XviD-NODLABS
2012-09-06 02:43:30 -------- d-----w- c:\users\jason\Pa.Negre.(Pan.Negro).2010.ORIGINAL.DVDRip.AC3.HORiZON-ArtSubs
2012-09-06 02:40:58 -------- d-----w- c:\users\jason\No Habra Paz Para Los Malvados [dvdrip][spanish][AC3-5.1][www.lokotorrents.com]
2012-09-06 02:37:58 -------- d-----w- c:\users\jason\La Voz Dormida [dvdrip][sapnish][AC3-5.1][www.lokotorrents.com]
2012-09-05 12:04:28 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-05 11:59:32 -------- d-----w- c:\program files\eMule
2012-09-05 11:27:00 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-09-04 15:25:52 -------- d-----w- c:\users\jason\appdata\roaming\EndNote
2012-09-04 15:25:00 -------- d-----w- c:\program files\common files\Risxtd
2012-09-04 15:24:49 -------- d-----w- c:\program files\common files\ResearchSoft
2012-09-04 15:22:23 -------- d-----w- c:\program files\EndNote X6
2012-09-04 15:21:02 -------- d-----w- c:\programdata\Thomson.ResearchSoft.Installers
2012-09-04 15:13:11 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2012-09-04 02:54:41 -------- d-----w- c:\users\jason\Rebirth
2012-09-04 02:53:58 -------- d-----w- c:\users\jason\In Rainbows
2012-09-04 02:52:04 -------- d-----w- c:\users\jason\Radiohead OK Computer
2012-09-04 02:40:05 -------- d-----w- c:\program files\BitTorrentControl_v12
2012-08-28 12:50:47 -------- d-----w- c:\users\jason\appdata\roaming\Leader Technologies
2012-08-27 22:50:11 -------- d-----w- c:\program files\common files\EPSON
2012-08-27 22:41:13 -------- d-----w- c:\program files\LTCM Client
2012-08-27 22:31:11 -------- d-----w- c:\program files\Epson Software
2012-08-27 22:26:25 95232 ----a-w- c:\windows\system32\E_FLBIBA.DLL
2012-08-27 22:26:16 81408 ----a-w- c:\windows\system32\E_FD4BIBA.DLL
2012-08-27 22:25:33 -------- d-----w- c:\programdata\EPSON
2012-08-27 22:24:35 342016 ----a-w- c:\windows\system32\esw2ud.dll
2012-08-27 22:24:35 122000 ----a-w- c:\windows\system32\escsvc.exe
2012-08-27 22:23:53 -------- d-----w- c:\program files\epson
2012-08-22 16:59:08 393728 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-08-16 12:26:13 262656 ----a-w- c:\windows\system32\rstrui.exe
2012-08-16 12:26:12 400896 ----a-w- c:\windows\system32\srcore.dll
2012-08-16 12:25:59 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-08-16 12:25:48 492032 ----a-w- c:\windows\system32\win32spl.dll
2012-08-16 12:25:46 317440 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-16 12:25:23 41984 ----a-w- c:\windows\system32\browcli.dll
2012-08-16 12:25:21 102912 ----a-w- c:\windows\system32\browser.dll
2012-08-16 12:25:12 769024 ----a-w- c:\windows\system32\localspl.dll
2012-08-16 12:25:09 30208 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\winprint.dll
.
==================== Find3M ====================
.
2012-09-12 02:18:45 152576 ----a-w- c:\windows\system32\msclmd.dll
2012-09-09 03:05:41 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-05 12:03:58 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-05 12:03:58 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13:14 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
2012-06-29 00:16:58 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09:01 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08:59 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04:43 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00:45 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-06-25 14:04:24 1394248 ----a-w- c:\windows\system32\msxml4.dll
.
============= FINISH: 11:07:15,48 ===============
And the aswMBR log:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-13 11:16:25
-----------------------------
11:16:25.722 OS Version: Windows 6.1.7601 Service Pack 1
11:16:25.723 Number of processors: 2 586 0x1C02
11:16:25.732 ComputerName: JASON-PC UserName: Jason
11:16:29.396 Initialize success
11:16:31.143 AVAST engine defs: 12091300
11:16:35.823 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
11:16:35.839 Disk 0 Vendor: Hitachi_HTS545025B9A300 PB2OC60N Size: 238475MB BusType: 3
11:16:35.901 Disk 0 MBR read successfully
11:16:35.917 Disk 0 MBR scan
11:16:35.932 Disk 0 Windows 7 default MBR code
11:16:35.963 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 102400 MB offset 2048
11:16:36.026 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 125815 MB offset 209717248
11:16:36.057 Disk 0 Partition 3 00 1B Hidd FAT32 MSDOS5.0 10240 MB offset 467386368
11:16:36.104 Disk 0 Partition 4 00 EF EFI FAT A1451 16 MB offset 488357888
11:16:36.166 Disk 0 scanning sectors +488392065
11:16:36.307 Disk 0 scanning C:\windows\system32\drivers
11:17:02.727 Service scanning
11:17:48.791 Modules scanning
11:18:17.881 Disk 0 trace - called modules:
11:18:17.951 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
11:18:17.976 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85a31648]
11:18:18.004 3 CLASSPNP.SYS[88db259e] -> nt!IofCallDriver -> [0x84c9a640]
11:18:18.029 5 ACPI.sys[888af3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8594c030]
11:18:19.038 AVAST engine scan C:\windows
11:18:22.661 AVAST engine scan C:\windows\system32
11:24:14.745 AVAST engine scan C:\windows\system32\drivers
11:24:39.476 AVAST engine scan C:\Users\Jason
11:40:44.589 AVAST engine scan C:\ProgramData
11:41:31.446 Scan finished successfully
12:14:00.433 Disk 0 MBR has been saved successfully to "C:\Users\Jason\Desktop\MBR.dat"
12:14:00.501 The log file has been saved successfully to "C:\Users\Jason\Desktop\aswMBR.txt"
I have a message from Windows that my computer has a virus: Win32/Adload/DA
So far I haven't noticed anything unusual but according to Windows it stopped my computer from running 1 time (two days ago)
Before seeking help from you I ran HitMan, OTL, TDSSkiller, aswMBR and the Avast boot-up scan. None of them found any infections.
I've followed your prepost instructions- did the registry and ran DDS and aswMBR (again). I've attached the DDS file and below I'm pasting the DDS and aswMBR logs.
I'd greatly appreciate any help you can give me!
Here's the DDS log:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by Jason at 11:03:31 on 2012-09-13
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2038.721 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\AsusService.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
C:\windows\system32\EscSvc.exe
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\ASUS\LivCam\LivCam.exe
C:\Program Files\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Users\Jason\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIIBA.EXE
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3225826
uDefault_Page_URL = hxxp://asus.msn.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: BitTorrentControl_v12 Toolbar: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - c:\program files\bittorrentcontrol_v12\prxtbBitT.dll
mURLSearchHooks: BitTorrentControl_v12 Toolbar: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - c:\program files\bittorrentcontrol_v12\prxtbBitT.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: BitTorrentControl_v12 Toolbar: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - c:\program files\bittorrentcontrol_v12\prxtbBitT.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: BitTorrentControl_v12 Toolbar: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - c:\program files\bittorrentcontrol_v12\prxtbBitT.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\users\jason\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [EPLTarget\P0000000000000000] c:\windows\system32\spool\drivers\w32x86\3\e_fatiiba.exe /ept "epltarget\P0000000000000000" /M "XP-400 Series"
uRun: [BitTorrent] "c:\program files\bittorrent\BitTorrent.exe" /MINIMIZED
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [HotkeyMon] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotKeyMon.exe
mRun: [HotkeyService] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotkeyService.exe
mRun: [SuperHybridEngine] AsusSender.exe c:\program files\eeepc\she\SuperHybridEngine.exe
mRun: [EeeStorageBackup] c:\program files\asus\asus webstorage\service\AsusWSService.exe MySyncFolder
mRun: [Eee Docking] c:\program files\asus\eee docking\Eee Docking.exe autorun
mRun: [LiveUpdate] AsusSender.exe c:\program files\asus\liveupdate\LiveUpdate.exe auto
mRun: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [IgfxExt] c:\windows\system32\IgfxExt.exe /RegServer
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [LivCam] "c:\program files\asus\livcam\LivCam.exe"
mRun: [ASUSWebStorage] c:\program files\asus\asus webstorage\3.0.108.222\AsusWSPanel.exe /S
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [CLMLServer] "c:\program files\cyberlink\power2go\CLMLSvc.exe"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [LGODDFU] "c:\program files\lg_fwupdate\fwupdate.exe" blrun
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
mRun: [LTCM Client] c:\program files\ltcm client\ltcmClient.exe /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\jason\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\asusvi~1.lnk - c:\program files\asus\asusvibe\AsusVibeLauncher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BCB96184-E700-4D7A-A71C-E0FC5352A65B} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\14D6472716B634F6E6E65636473547164796F6E6 : DhcpNameServer = 208.67.222.222 208.67.220.220
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\3416275737F68323 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\34369616076693 : DhcpNameServer = 192.168.27.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\45865602245616E6 : DhcpNameServer = 10.0.1.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\54C625F626C6566556274656 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\861607079786F6D656D27657563747 : DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.33.1
TCP: Interfaces\{EC4A7E58-6C5C-45AD-8DB5-60F6C2CD1BF5}\A5978554C40274D253730335 : DhcpNameServer = 212.142.144.66 212.142.144.98
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
============= SERVICES / DRIVERS ===============
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2009-12-21 11832]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-29 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-9-29 355632]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AsusService;Asus Launcher Service;c:\windows\system32\AsusService.exe [2009-12-21 219136]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-9-29 21256]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-9-29 58680]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-9-5 44808]
R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-10-13 249648]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\common files\epson\epw!3 ssrp\E_S50ST7.EXE [2012-8-27 167520]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\common files\epson\epw!3 ssrp\E_S50RP7.EXE [2012-8-27 142432]
R2 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\epson\epsoncustomerparticipation\EPCP.exe [2011-6-9 521600]
R2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\escsvc.exe [2012-8-27 122000]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-11-16 43944]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2009-12-21 29472]
R3 igd;igd;c:\windows\system32\drivers\igdkmd32.sys [2009-11-16 635168]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-11-16 51712]
S2 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-10-21 196176]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-29 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-9-8 250568]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-9-28 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-29 136176]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-10-1 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-9-30 1343400]
.
=============== Created Last 30 ================
.
2012-09-13 13:57:47 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{7f8b6eca-3b33-41f3-97ab-b5de15393c45}\offreg.dll
2012-09-13 05:25:10 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-13 05:25:09 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-13 05:24:47 240496 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-13 05:24:47 1292144 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-13 05:24:46 187760 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-13 05:20:23 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-13 01:12:21 -------- d-----w- c:\programdata\HitmanPro
2012-09-13 00:38:17 -------- d-----w- c:\users\jason\appdata\roaming\Malwarebytes
2012-09-13 00:37:55 -------- d-----w- c:\programdata\Malwarebytes
2012-09-13 00:37:49 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-13 00:37:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-12 01:57:05 -------- d-----w- c:\windows\system32\SPReview
2012-09-12 01:54:57 -------- d-----w- c:\windows\system32\EventProviders
2012-09-11 12:33:35 7022536 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{7f8b6eca-3b33-41f3-97ab-b5de15393c45}\mpengine.dll
2012-09-09 03:05:41 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-06 03:50:10 -------- d-----w- c:\users\jason\Tambien la Lluvia [dvdrip][spanish][AC3 5.1][www.lokotorrents.com]
2012-09-06 03:49:51 -------- d-----w- c:\users\jason\Azul.Oscuro.Casi.Negro.[Dvdrip][Spanish][www.FanCluBT.com]
2012-09-06 03:35:03 -------- d-----w- c:\users\jason\{www.scenetime.com}Princesas (2005) Fernando Leon de Aranoa
2012-09-06 02:51:31 -------- d-----w- c:\users\jason\Cell.211.2009.BDRip.XviD-NODLABS
2012-09-06 02:43:30 -------- d-----w- c:\users\jason\Pa.Negre.(Pan.Negro).2010.ORIGINAL.DVDRip.AC3.HORiZON-ArtSubs
2012-09-06 02:40:58 -------- d-----w- c:\users\jason\No Habra Paz Para Los Malvados [dvdrip][spanish][AC3-5.1][www.lokotorrents.com]
2012-09-06 02:37:58 -------- d-----w- c:\users\jason\La Voz Dormida [dvdrip][sapnish][AC3-5.1][www.lokotorrents.com]
2012-09-05 12:04:28 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-05 11:59:32 -------- d-----w- c:\program files\eMule
2012-09-05 11:27:00 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-09-04 15:25:52 -------- d-----w- c:\users\jason\appdata\roaming\EndNote
2012-09-04 15:25:00 -------- d-----w- c:\program files\common files\Risxtd
2012-09-04 15:24:49 -------- d-----w- c:\program files\common files\ResearchSoft
2012-09-04 15:22:23 -------- d-----w- c:\program files\EndNote X6
2012-09-04 15:21:02 -------- d-----w- c:\programdata\Thomson.ResearchSoft.Installers
2012-09-04 15:13:11 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2012-09-04 02:54:41 -------- d-----w- c:\users\jason\Rebirth
2012-09-04 02:53:58 -------- d-----w- c:\users\jason\In Rainbows
2012-09-04 02:52:04 -------- d-----w- c:\users\jason\Radiohead OK Computer
2012-09-04 02:40:05 -------- d-----w- c:\program files\BitTorrentControl_v12
2012-08-28 12:50:47 -------- d-----w- c:\users\jason\appdata\roaming\Leader Technologies
2012-08-27 22:50:11 -------- d-----w- c:\program files\common files\EPSON
2012-08-27 22:41:13 -------- d-----w- c:\program files\LTCM Client
2012-08-27 22:31:11 -------- d-----w- c:\program files\Epson Software
2012-08-27 22:26:25 95232 ----a-w- c:\windows\system32\E_FLBIBA.DLL
2012-08-27 22:26:16 81408 ----a-w- c:\windows\system32\E_FD4BIBA.DLL
2012-08-27 22:25:33 -------- d-----w- c:\programdata\EPSON
2012-08-27 22:24:35 342016 ----a-w- c:\windows\system32\esw2ud.dll
2012-08-27 22:24:35 122000 ----a-w- c:\windows\system32\escsvc.exe
2012-08-27 22:23:53 -------- d-----w- c:\program files\epson
2012-08-22 16:59:08 393728 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-08-16 12:26:13 262656 ----a-w- c:\windows\system32\rstrui.exe
2012-08-16 12:26:12 400896 ----a-w- c:\windows\system32\srcore.dll
2012-08-16 12:25:59 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-08-16 12:25:48 492032 ----a-w- c:\windows\system32\win32spl.dll
2012-08-16 12:25:46 317440 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-16 12:25:23 41984 ----a-w- c:\windows\system32\browcli.dll
2012-08-16 12:25:21 102912 ----a-w- c:\windows\system32\browser.dll
2012-08-16 12:25:12 769024 ----a-w- c:\windows\system32\localspl.dll
2012-08-16 12:25:09 30208 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\winprint.dll
.
==================== Find3M ====================
.
2012-09-12 02:18:45 152576 ----a-w- c:\windows\system32\msclmd.dll
2012-09-09 03:05:41 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-05 12:03:58 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-05 12:03:58 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13:14 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
2012-06-29 00:16:58 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09:01 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08:59 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04:43 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00:45 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-06-25 14:04:24 1394248 ----a-w- c:\windows\system32\msxml4.dll
.
============= FINISH: 11:07:15,48 ===============
And the aswMBR log:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-13 11:16:25
-----------------------------
11:16:25.722 OS Version: Windows 6.1.7601 Service Pack 1
11:16:25.723 Number of processors: 2 586 0x1C02
11:16:25.732 ComputerName: JASON-PC UserName: Jason
11:16:29.396 Initialize success
11:16:31.143 AVAST engine defs: 12091300
11:16:35.823 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
11:16:35.839 Disk 0 Vendor: Hitachi_HTS545025B9A300 PB2OC60N Size: 238475MB BusType: 3
11:16:35.901 Disk 0 MBR read successfully
11:16:35.917 Disk 0 MBR scan
11:16:35.932 Disk 0 Windows 7 default MBR code
11:16:35.963 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 102400 MB offset 2048
11:16:36.026 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 125815 MB offset 209717248
11:16:36.057 Disk 0 Partition 3 00 1B Hidd FAT32 MSDOS5.0 10240 MB offset 467386368
11:16:36.104 Disk 0 Partition 4 00 EF EFI FAT A1451 16 MB offset 488357888
11:16:36.166 Disk 0 scanning sectors +488392065
11:16:36.307 Disk 0 scanning C:\windows\system32\drivers
11:17:02.727 Service scanning
11:17:48.791 Modules scanning
11:18:17.881 Disk 0 trace - called modules:
11:18:17.951 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
11:18:17.976 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85a31648]
11:18:18.004 3 CLASSPNP.SYS[88db259e] -> nt!IofCallDriver -> [0x84c9a640]
11:18:18.029 5 ACPI.sys[888af3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8594c030]
11:18:19.038 AVAST engine scan C:\windows
11:18:22.661 AVAST engine scan C:\windows\system32
11:24:14.745 AVAST engine scan C:\windows\system32\drivers
11:24:39.476 AVAST engine scan C:\Users\Jason
11:40:44.589 AVAST engine scan C:\ProgramData
11:41:31.446 Scan finished successfully
12:14:00.433 Disk 0 MBR has been saved successfully to "C:\Users\Jason\Desktop\MBR.dat"
12:14:00.501 The log file has been saved successfully to "C:\Users\Jason\Desktop\aswMBR.txt"