I removed a number of malware infections from this Old XP system using spybot, malwarebytes anti malware and superAntiSpyware. After removal the system is still a little slow and still hangs occasionally. Request dumps follow:
Thanks so much for your help....
Regards,
Roger
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.17.2
Run by Owner at 0:57:30 on 2013-03-19
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.118 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\DAILYB~2\bar\1.bin\2vbrmon.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.msn.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/?fr=fp-reg
mDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-reg
uProxyOverride = <local>;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: <No Name>: {f15ff29f-85a1-43cd-9674-e5ba40016c97} - c:\program files\dailybibleguide\bar\1.bin\2vSrcAs.dll
uURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - <orphaned>
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Search Assistant BHO: {0631bff0-6846-48ca-982d-d62d7f376e97} - c:\program files\dailybibleguide\bar\1.bin\2vSrcAs.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
TB: DailyBibleGuide: {2A942AB7-2073-49BC-A7E1-77E93835889A} - c:\program files\dailybibleguide\bar\1.bin\2vbar.dll
TB: DailyBibleGuide: {2a942ab7-2073-49bc-a7e1-77e93835889a} - c:\program files\dailybibleguide\bar\1.bin\2vbar.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
EB: Real.com: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [DailyBibleGuide Browser Plugin Loader] c:\progra~1\dailyb~2\bar\1.bin\2vbrmon.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRun: [OE] c:\program files\trend micro\internet security\tmas_oe\TMAS_OEMon.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: &Search - http://tbedits.dailybibleguide.com/...0280-403C-83A5-BEC48B101D31&n=2011081714&cv=1
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1183158141578
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1363115980328
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} - hxxp://www.iolo.com/app/ocx/UpgradeVerify.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{761A3CB6-7D73-448C-95E5-FFBC61A7A38C} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{7920C8EB-C091-494F-ACC1-87906D4CCDA4} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{809C77B1-840A-41C1-BB73-C54246D4BE71} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{DEE8850C-9EF6-4F98-9470-C638C1031ABA} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{F216FC57-6B39-435F-8C98-D3501C351548} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - <orphaned>
LSA: Authentication Packages = msv1_0 c:\windows\system32\fcccDWnn
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\ujmir2r4.default\
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\dailybibleguide\bar\1.bin\NP2vStub.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1200112.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2013-03-12 23:07; wrc@avast.com; c:\program files\avast software\avast\webrep\FF
FF - ExtSQL: !HIDDEN! 2011-09-21 17:28; smartwebprinting@hp.com; c:\program files\hp\digital imaging\smart web printing\MozillaAddOn3
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-3-12 49248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-3-12 765736]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-3-12 368176]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-3-12 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-3-12 66336]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-3-12 45248]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2007-10-9 38144]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2008-6-6 22528]
S1 acapobnt;acapobnt;\??\c:\windows\system32\drivers\acapobnt.sys --> c:\windows\system32\drivers\acapobnt.sys [?]
S1 aooqzfkv;aooqzfkv;\??\c:\windows\system32\drivers\aooqzfkv.sys --> c:\windows\system32\drivers\aooqzfkv.sys [?]
S1 bhyfjttu;bhyfjttu;\??\c:\windows\system32\drivers\bhyfjttu.sys --> c:\windows\system32\drivers\bhyfjttu.sys [?]
S1 bidduafb;bidduafb;\??\c:\windows\system32\drivers\bidduafb.sys --> c:\windows\system32\drivers\bidduafb.sys [?]
S1 btqencwd;btqencwd;\??\c:\windows\system32\drivers\btqencwd.sys --> c:\windows\system32\drivers\btqencwd.sys [?]
S1 cobfbjwl;cobfbjwl;\??\c:\windows\system32\drivers\cobfbjwl.sys --> c:\windows\system32\drivers\cobfbjwl.sys [?]
S1 cotjizqd;cotjizqd;\??\c:\windows\system32\drivers\cotjizqd.sys --> c:\windows\system32\drivers\cotjizqd.sys [?]
S1 cpkxgqkd;cpkxgqkd;\??\c:\windows\system32\drivers\cpkxgqkd.sys --> c:\windows\system32\drivers\cpkxgqkd.sys [?]
S1 dnvnfsqq;dnvnfsqq;\??\c:\windows\system32\drivers\dnvnfsqq.sys --> c:\windows\system32\drivers\dnvnfsqq.sys [?]
S1 dpfsnadk;dpfsnadk;\??\c:\windows\system32\drivers\dpfsnadk.sys --> c:\windows\system32\drivers\dpfsnadk.sys [?]
S1 efababwt;efababwt;\??\c:\windows\system32\drivers\efababwt.sys --> c:\windows\system32\drivers\efababwt.sys [?]
S1 ektsmhwj;ektsmhwj;\??\c:\windows\system32\drivers\ektsmhwj.sys --> c:\windows\system32\drivers\ektsmhwj.sys [?]
S1 fdcrelxp;fdcrelxp;\??\c:\windows\system32\drivers\fdcrelxp.sys --> c:\windows\system32\drivers\fdcrelxp.sys [?]
S1 fkxyoehu;fkxyoehu;\??\c:\windows\system32\drivers\fkxyoehu.sys --> c:\windows\system32\drivers\fkxyoehu.sys [?]
S1 gebzlrlk;gebzlrlk;\??\c:\windows\system32\drivers\gebzlrlk.sys --> c:\windows\system32\drivers\gebzlrlk.sys [?]
S1 gedwlpgw;gedwlpgw;\??\c:\windows\system32\drivers\gedwlpgw.sys --> c:\windows\system32\drivers\gedwlpgw.sys [?]
S1 gpzpzghy;gpzpzghy;\??\c:\windows\system32\drivers\gpzpzghy.sys --> c:\windows\system32\drivers\gpzpzghy.sys [?]
S1 gvqjuowd;gvqjuowd;\??\c:\windows\system32\drivers\gvqjuowd.sys --> c:\windows\system32\drivers\gvqjuowd.sys [?]
S1 gxdpbakh;gxdpbakh;\??\c:\windows\system32\drivers\gxdpbakh.sys --> c:\windows\system32\drivers\gxdpbakh.sys [?]
S1 hndsgtav;hndsgtav;\??\c:\windows\system32\drivers\hndsgtav.sys --> c:\windows\system32\drivers\hndsgtav.sys [?]
S1 igsctoce;igsctoce;\??\c:\windows\system32\drivers\igsctoce.sys --> c:\windows\system32\drivers\igsctoce.sys [?]
S1 ivhxmuji;ivhxmuji;\??\c:\windows\system32\drivers\ivhxmuji.sys --> c:\windows\system32\drivers\ivhxmuji.sys [?]
S1 jmhoyzku;jmhoyzku;\??\c:\windows\system32\drivers\jmhoyzku.sys --> c:\windows\system32\drivers\jmhoyzku.sys [?]
S1 jrgsvfah;jrgsvfah;\??\c:\windows\system32\drivers\jrgsvfah.sys --> c:\windows\system32\drivers\jrgsvfah.sys [?]
S1 jvdkoect;jvdkoect;\??\c:\windows\system32\drivers\jvdkoect.sys --> c:\windows\system32\drivers\jvdkoect.sys [?]
S1 jwywzfus;jwywzfus;\??\c:\windows\system32\drivers\jwywzfus.sys --> c:\windows\system32\drivers\jwywzfus.sys [?]
S1 kksrsxsu;kksrsxsu;\??\c:\windows\system32\drivers\kksrsxsu.sys --> c:\windows\system32\drivers\kksrsxsu.sys [?]
S1 kmwsavhf;kmwsavhf;\??\c:\windows\system32\drivers\kmwsavhf.sys --> c:\windows\system32\drivers\kmwsavhf.sys [?]
S1 kpvdewvl;kpvdewvl;\??\c:\windows\system32\drivers\kpvdewvl.sys --> c:\windows\system32\drivers\kpvdewvl.sys [?]
S1 kqooxgfm;kqooxgfm;\??\c:\windows\system32\drivers\kqooxgfm.sys --> c:\windows\system32\drivers\kqooxgfm.sys [?]
S1 krgdkxtt;krgdkxtt;\??\c:\windows\system32\drivers\krgdkxtt.sys --> c:\windows\system32\drivers\krgdkxtt.sys [?]
S1 mgdhinqs;mgdhinqs;\??\c:\windows\system32\drivers\mgdhinqs.sys --> c:\windows\system32\drivers\mgdhinqs.sys [?]
S1 moheurgu;moheurgu;\??\c:\windows\system32\drivers\moheurgu.sys --> c:\windows\system32\drivers\moheurgu.sys [?]
S1 mzdhocmu;mzdhocmu;\??\c:\windows\system32\drivers\mzdhocmu.sys --> c:\windows\system32\drivers\mzdhocmu.sys [?]
S1 nhbmzbqi;nhbmzbqi;\??\c:\windows\system32\drivers\nhbmzbqi.sys --> c:\windows\system32\drivers\nhbmzbqi.sys [?]
S1 nnytfnut;nnytfnut;\??\c:\windows\system32\drivers\nnytfnut.sys --> c:\windows\system32\drivers\nnytfnut.sys [?]
S1 ntxuocjj;ntxuocjj;\??\c:\windows\system32\drivers\ntxuocjj.sys --> c:\windows\system32\drivers\ntxuocjj.sys [?]
S1 omsohsgh;omsohsgh;\??\c:\windows\system32\drivers\omsohsgh.sys --> c:\windows\system32\drivers\omsohsgh.sys [?]
S1 phtiekcm;phtiekcm;\??\c:\windows\system32\drivers\phtiekcm.sys --> c:\windows\system32\drivers\phtiekcm.sys [?]
S1 psyzlqbb;psyzlqbb;\??\c:\windows\system32\drivers\psyzlqbb.sys --> c:\windows\system32\drivers\psyzlqbb.sys [?]
S1 pvahfsge;pvahfsge;\??\c:\windows\system32\drivers\pvahfsge.sys --> c:\windows\system32\drivers\pvahfsge.sys [?]
S1 qzgvgiis;qzgvgiis;\??\c:\windows\system32\drivers\qzgvgiis.sys --> c:\windows\system32\drivers\qzgvgiis.sys [?]
S1 rkakihbx;rkakihbx;\??\c:\windows\system32\drivers\rkakihbx.sys --> c:\windows\system32\drivers\rkakihbx.sys [?]
S1 rninkmgf;rninkmgf;\??\c:\windows\system32\drivers\rninkmgf.sys --> c:\windows\system32\drivers\rninkmgf.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\superantispyware\sasdifsv.sys --> c:\program files\superantispyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\superantispyware\saskutil.sys --> c:\program files\superantispyware\SASKUTIL.sys [?]
S1 scdqwdil;scdqwdil;\??\c:\windows\system32\drivers\scdqwdil.sys --> c:\windows\system32\drivers\scdqwdil.sys [?]
S1 tanbdmrv;tanbdmrv;\??\c:\windows\system32\drivers\tanbdmrv.sys --> c:\windows\system32\drivers\tanbdmrv.sys [?]
S1 ttdsztdz;ttdsztdz;\??\c:\windows\system32\drivers\ttdsztdz.sys --> c:\windows\system32\drivers\ttdsztdz.sys [?]
S1 uawagoej;uawagoej;\??\c:\windows\system32\drivers\uawagoej.sys --> c:\windows\system32\drivers\uawagoej.sys [?]
S1 uezbgkmd;uezbgkmd;\??\c:\windows\system32\drivers\uezbgkmd.sys --> c:\windows\system32\drivers\uezbgkmd.sys [?]
S1 ufifbxdk;ufifbxdk;\??\c:\windows\system32\drivers\ufifbxdk.sys --> c:\windows\system32\drivers\ufifbxdk.sys [?]
S1 uhaiwvop;uhaiwvop;\??\c:\windows\system32\drivers\uhaiwvop.sys --> c:\windows\system32\drivers\uhaiwvop.sys [?]
S1 uibqjwsm;uibqjwsm;\??\c:\windows\system32\drivers\uibqjwsm.sys --> c:\windows\system32\drivers\uibqjwsm.sys [?]
S1 utnfmtab;utnfmtab;\??\c:\windows\system32\drivers\utnfmtab.sys --> c:\windows\system32\drivers\utnfmtab.sys [?]
S1 uuszovga;uuszovga;\??\c:\windows\system32\drivers\uuszovga.sys --> c:\windows\system32\drivers\uuszovga.sys [?]
S1 uxoezycr;uxoezycr;\??\c:\windows\system32\drivers\uxoezycr.sys --> c:\windows\system32\drivers\uxoezycr.sys [?]
S1 uynchbdx;uynchbdx;\??\c:\windows\system32\drivers\uynchbdx.sys --> c:\windows\system32\drivers\uynchbdx.sys [?]
S1 vwuypbxr;vwuypbxr;\??\c:\windows\system32\drivers\vwuypbxr.sys --> c:\windows\system32\drivers\vwuypbxr.sys [?]
S1 wasxpmgw;wasxpmgw;\??\c:\windows\system32\drivers\wasxpmgw.sys --> c:\windows\system32\drivers\wasxpmgw.sys [?]
S1 whjbtbls;whjbtbls;\??\c:\windows\system32\drivers\whjbtbls.sys --> c:\windows\system32\drivers\whjbtbls.sys [?]
S1 wjsetgzq;wjsetgzq;\??\c:\windows\system32\drivers\wjsetgzq.sys --> c:\windows\system32\drivers\wjsetgzq.sys [?]
S1 xkyflovj;xkyflovj;\??\c:\windows\system32\drivers\xkyflovj.sys --> c:\windows\system32\drivers\xkyflovj.sys [?]
S1 yahtalmn;yahtalmn;\??\c:\windows\system32\drivers\yahtalmn.sys --> c:\windows\system32\drivers\yahtalmn.sys [?]
S1 ywpgxnsc;ywpgxnsc;\??\c:\windows\system32\drivers\ywpgxnsc.sys --> c:\windows\system32\drivers\ywpgxnsc.sys [?]
S1 zjztvedg;zjztvedg;\??\c:\windows\system32\drivers\zjztvedg.sys --> c:\windows\system32\drivers\zjztvedg.sys [?]
S2 DailyBibleGuideService;DailyBibleGuideService;c:\progra~1\dailyb~2\bar\1.bin\2vbarsvc.exe [2011-8-17 42504]
S3 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-3-12 164736]
S3 AX88172;NETGEAR FA120 USB 2.0 Fast Ethernet Adapter;c:\windows\system32\drivers\FA120.sys [2008-1-15 14048]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2010-3-31 342784]
S3 SASENUM;SASENUM;\??\c:\program files\superantispyware\sasenum.sys --> c:\program files\superantispyware\SASENUM.SYS [?]
.
=============== File Associations ===============
.
FileExt: .vbe: VBEFile=NOTEPAD.EXE %1
FileExt: .vbs: VBSFile=NOTEPAD.EXE %1
FileExt: .js: JSFile=NOTEPAD.EXE %1
FileExt: .jse: JSEFile=NOTEPAD.EXE %1
FileExt: .wsf: WSFFile=NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2013-03-15 23:57:14 -------- d-----w- c:\documents and settings\owner\local settings\application data\Sun
2013-03-13 07:43:48 -------- d-----w- c:\program files\Bonjour
2013-03-13 06:08:01 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-03-13 06:08:01 49248 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-03-13 06:08:01 164736 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-03-13 06:08:00 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-03-13 06:06:39 41664 ----a-w- c:\windows\avastSS.scr
2013-03-13 06:05:59 -------- d-----w- c:\program files\AVAST Software
2013-03-13 06:05:21 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2013-03-12 22:31:33 -------- d-----w- c:\windows\system32\Adobe
2013-03-12 22:15:09 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-12 22:15:09 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-12 22:15:08 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-03-12 22:14:58 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-12 21:49:09 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-03-12 21:49:02 865744 ----a-w- c:\program files\mozilla firefox\uninstall\helper.exe
2013-03-12 21:49:02 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2013-03-12 19:21:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-03-12 19:21:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-03-12 10:45:35 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
2013-03-12 07:07:24 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-12 07:07:24 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-12 06:45:41 -------- d-----w- C:\Computer
2013-03-12 06:41:41 -------- d-----w- c:\program files\CCleaner
2013-03-12 05:29:25 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2013-03-12 05:29:25 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2013-03-12 05:29:18 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2013-03-12 05:29:18 21504 ----a-w- c:\windows\system32\hidserv.dll
2013-03-12 05:03:08 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2013-03-12 05:03:08 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2013-02-21 01:42:25 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
.
==================== Find3M ====================
.
2013-02-12 00:32:23 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-12 00:32:23 12928 ------w- c:\windows\system32\drivers\usb8023x.sys
2013-02-05 20:05:47 916480 ----a-w- c:\windows\system32\wininet.dll
2013-02-05 20:05:46 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-02-05 20:05:46 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-02-05 05:53:57 385024 ----a-w- c:\windows\system32\html.iec
2013-01-30 10:53:21 232336 ------w- c:\windows\system32\MpSigStub.exe
2013-01-26 03:55:44 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-07 01:16:02 2193024 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:36:58 2069760 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20:00 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49:10 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49:10 1292288 ----a-w- c:\windows\system32\quartz.dll
.
============= FINISH: 0:58:33.43 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-03-19 01:02:57
-----------------------------
01:02:57.078 OS Version: Windows 5.1.2600 Service Pack 3
01:02:57.078 Number of processors: 1 586 0xA00
01:02:57.078 ComputerName: OFFICE UserName: Owner
01:02:58.046 Initialize success
01:02:59.328 AVAST engine defs: 13031801
01:03:09.187 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000074
01:03:09.187 Disk 0 Vendor: ST3160215A 3.AAC Size: 152627MB BusType: 3
01:03:09.343 Disk 0 MBR read successfully
01:03:09.343 Disk 0 MBR scan
01:03:09.343 Disk 0 Windows XP default MBR code
01:03:09.343 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152617 MB offset 63
01:03:09.359 Disk 0 scanning sectors +312560640
01:03:09.562 Disk 0 scanning C:\WINDOWS\system32\drivers
01:03:29.234 Service scanning
01:04:01.812 Modules scanning
01:04:21.046 Disk 0 trace - called modules:
01:04:21.078 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll nvatabus.sys
01:04:21.078 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8575fab8]
01:04:21.078 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\00000076[0x85760f18]
01:04:21.078 5 ACPI.sys[f743e620] -> nt!IofCallDriver -> \Device\00000074[0x857616e8]
01:04:21.437 AVAST engine scan C:\WINDOWS
01:04:29.546 AVAST engine scan C:\WINDOWS\system32
01:07:11.625 AVAST engine scan C:\WINDOWS\system32\drivers
01:07:33.765 AVAST engine scan C:\Documents and Settings\Owner
01:08:22.484 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
01:08:22.484 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
Thanks so much for your help....
Regards,
Roger
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.17.2
Run by Owner at 0:57:30 on 2013-03-19
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.118 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\DAILYB~2\bar\1.bin\2vbrmon.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.msn.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/?fr=fp-reg
mDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-reg
uProxyOverride = <local>;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: <No Name>: {f15ff29f-85a1-43cd-9674-e5ba40016c97} - c:\program files\dailybibleguide\bar\1.bin\2vSrcAs.dll
uURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - <orphaned>
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Search Assistant BHO: {0631bff0-6846-48ca-982d-d62d7f376e97} - c:\program files\dailybibleguide\bar\1.bin\2vSrcAs.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
TB: DailyBibleGuide: {2A942AB7-2073-49BC-A7E1-77E93835889A} - c:\program files\dailybibleguide\bar\1.bin\2vbar.dll
TB: DailyBibleGuide: {2a942ab7-2073-49bc-a7e1-77e93835889a} - c:\program files\dailybibleguide\bar\1.bin\2vbar.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
EB: Real.com: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [DailyBibleGuide Browser Plugin Loader] c:\progra~1\dailyb~2\bar\1.bin\2vbrmon.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRun: [OE] c:\program files\trend micro\internet security\tmas_oe\TMAS_OEMon.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: &Search - http://tbedits.dailybibleguide.com/...0280-403C-83A5-BEC48B101D31&n=2011081714&cv=1
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1183158141578
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1363115980328
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} - hxxp://www.iolo.com/app/ocx/UpgradeVerify.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{761A3CB6-7D73-448C-95E5-FFBC61A7A38C} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{7920C8EB-C091-494F-ACC1-87906D4CCDA4} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{809C77B1-840A-41C1-BB73-C54246D4BE71} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{DEE8850C-9EF6-4F98-9470-C638C1031ABA} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
TCP: Interfaces\{F216FC57-6B39-435F-8C98-D3501C351548} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - <orphaned>
LSA: Authentication Packages = msv1_0 c:\windows\system32\fcccDWnn
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\ujmir2r4.default\
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\dailybibleguide\bar\1.bin\NP2vStub.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1200112.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2013-03-12 23:07; wrc@avast.com; c:\program files\avast software\avast\webrep\FF
FF - ExtSQL: !HIDDEN! 2011-09-21 17:28; smartwebprinting@hp.com; c:\program files\hp\digital imaging\smart web printing\MozillaAddOn3
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-3-12 49248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-3-12 765736]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-3-12 368176]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-3-12 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-3-12 66336]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-3-12 45248]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2007-10-9 38144]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2008-6-6 22528]
S1 acapobnt;acapobnt;\??\c:\windows\system32\drivers\acapobnt.sys --> c:\windows\system32\drivers\acapobnt.sys [?]
S1 aooqzfkv;aooqzfkv;\??\c:\windows\system32\drivers\aooqzfkv.sys --> c:\windows\system32\drivers\aooqzfkv.sys [?]
S1 bhyfjttu;bhyfjttu;\??\c:\windows\system32\drivers\bhyfjttu.sys --> c:\windows\system32\drivers\bhyfjttu.sys [?]
S1 bidduafb;bidduafb;\??\c:\windows\system32\drivers\bidduafb.sys --> c:\windows\system32\drivers\bidduafb.sys [?]
S1 btqencwd;btqencwd;\??\c:\windows\system32\drivers\btqencwd.sys --> c:\windows\system32\drivers\btqencwd.sys [?]
S1 cobfbjwl;cobfbjwl;\??\c:\windows\system32\drivers\cobfbjwl.sys --> c:\windows\system32\drivers\cobfbjwl.sys [?]
S1 cotjizqd;cotjizqd;\??\c:\windows\system32\drivers\cotjizqd.sys --> c:\windows\system32\drivers\cotjizqd.sys [?]
S1 cpkxgqkd;cpkxgqkd;\??\c:\windows\system32\drivers\cpkxgqkd.sys --> c:\windows\system32\drivers\cpkxgqkd.sys [?]
S1 dnvnfsqq;dnvnfsqq;\??\c:\windows\system32\drivers\dnvnfsqq.sys --> c:\windows\system32\drivers\dnvnfsqq.sys [?]
S1 dpfsnadk;dpfsnadk;\??\c:\windows\system32\drivers\dpfsnadk.sys --> c:\windows\system32\drivers\dpfsnadk.sys [?]
S1 efababwt;efababwt;\??\c:\windows\system32\drivers\efababwt.sys --> c:\windows\system32\drivers\efababwt.sys [?]
S1 ektsmhwj;ektsmhwj;\??\c:\windows\system32\drivers\ektsmhwj.sys --> c:\windows\system32\drivers\ektsmhwj.sys [?]
S1 fdcrelxp;fdcrelxp;\??\c:\windows\system32\drivers\fdcrelxp.sys --> c:\windows\system32\drivers\fdcrelxp.sys [?]
S1 fkxyoehu;fkxyoehu;\??\c:\windows\system32\drivers\fkxyoehu.sys --> c:\windows\system32\drivers\fkxyoehu.sys [?]
S1 gebzlrlk;gebzlrlk;\??\c:\windows\system32\drivers\gebzlrlk.sys --> c:\windows\system32\drivers\gebzlrlk.sys [?]
S1 gedwlpgw;gedwlpgw;\??\c:\windows\system32\drivers\gedwlpgw.sys --> c:\windows\system32\drivers\gedwlpgw.sys [?]
S1 gpzpzghy;gpzpzghy;\??\c:\windows\system32\drivers\gpzpzghy.sys --> c:\windows\system32\drivers\gpzpzghy.sys [?]
S1 gvqjuowd;gvqjuowd;\??\c:\windows\system32\drivers\gvqjuowd.sys --> c:\windows\system32\drivers\gvqjuowd.sys [?]
S1 gxdpbakh;gxdpbakh;\??\c:\windows\system32\drivers\gxdpbakh.sys --> c:\windows\system32\drivers\gxdpbakh.sys [?]
S1 hndsgtav;hndsgtav;\??\c:\windows\system32\drivers\hndsgtav.sys --> c:\windows\system32\drivers\hndsgtav.sys [?]
S1 igsctoce;igsctoce;\??\c:\windows\system32\drivers\igsctoce.sys --> c:\windows\system32\drivers\igsctoce.sys [?]
S1 ivhxmuji;ivhxmuji;\??\c:\windows\system32\drivers\ivhxmuji.sys --> c:\windows\system32\drivers\ivhxmuji.sys [?]
S1 jmhoyzku;jmhoyzku;\??\c:\windows\system32\drivers\jmhoyzku.sys --> c:\windows\system32\drivers\jmhoyzku.sys [?]
S1 jrgsvfah;jrgsvfah;\??\c:\windows\system32\drivers\jrgsvfah.sys --> c:\windows\system32\drivers\jrgsvfah.sys [?]
S1 jvdkoect;jvdkoect;\??\c:\windows\system32\drivers\jvdkoect.sys --> c:\windows\system32\drivers\jvdkoect.sys [?]
S1 jwywzfus;jwywzfus;\??\c:\windows\system32\drivers\jwywzfus.sys --> c:\windows\system32\drivers\jwywzfus.sys [?]
S1 kksrsxsu;kksrsxsu;\??\c:\windows\system32\drivers\kksrsxsu.sys --> c:\windows\system32\drivers\kksrsxsu.sys [?]
S1 kmwsavhf;kmwsavhf;\??\c:\windows\system32\drivers\kmwsavhf.sys --> c:\windows\system32\drivers\kmwsavhf.sys [?]
S1 kpvdewvl;kpvdewvl;\??\c:\windows\system32\drivers\kpvdewvl.sys --> c:\windows\system32\drivers\kpvdewvl.sys [?]
S1 kqooxgfm;kqooxgfm;\??\c:\windows\system32\drivers\kqooxgfm.sys --> c:\windows\system32\drivers\kqooxgfm.sys [?]
S1 krgdkxtt;krgdkxtt;\??\c:\windows\system32\drivers\krgdkxtt.sys --> c:\windows\system32\drivers\krgdkxtt.sys [?]
S1 mgdhinqs;mgdhinqs;\??\c:\windows\system32\drivers\mgdhinqs.sys --> c:\windows\system32\drivers\mgdhinqs.sys [?]
S1 moheurgu;moheurgu;\??\c:\windows\system32\drivers\moheurgu.sys --> c:\windows\system32\drivers\moheurgu.sys [?]
S1 mzdhocmu;mzdhocmu;\??\c:\windows\system32\drivers\mzdhocmu.sys --> c:\windows\system32\drivers\mzdhocmu.sys [?]
S1 nhbmzbqi;nhbmzbqi;\??\c:\windows\system32\drivers\nhbmzbqi.sys --> c:\windows\system32\drivers\nhbmzbqi.sys [?]
S1 nnytfnut;nnytfnut;\??\c:\windows\system32\drivers\nnytfnut.sys --> c:\windows\system32\drivers\nnytfnut.sys [?]
S1 ntxuocjj;ntxuocjj;\??\c:\windows\system32\drivers\ntxuocjj.sys --> c:\windows\system32\drivers\ntxuocjj.sys [?]
S1 omsohsgh;omsohsgh;\??\c:\windows\system32\drivers\omsohsgh.sys --> c:\windows\system32\drivers\omsohsgh.sys [?]
S1 phtiekcm;phtiekcm;\??\c:\windows\system32\drivers\phtiekcm.sys --> c:\windows\system32\drivers\phtiekcm.sys [?]
S1 psyzlqbb;psyzlqbb;\??\c:\windows\system32\drivers\psyzlqbb.sys --> c:\windows\system32\drivers\psyzlqbb.sys [?]
S1 pvahfsge;pvahfsge;\??\c:\windows\system32\drivers\pvahfsge.sys --> c:\windows\system32\drivers\pvahfsge.sys [?]
S1 qzgvgiis;qzgvgiis;\??\c:\windows\system32\drivers\qzgvgiis.sys --> c:\windows\system32\drivers\qzgvgiis.sys [?]
S1 rkakihbx;rkakihbx;\??\c:\windows\system32\drivers\rkakihbx.sys --> c:\windows\system32\drivers\rkakihbx.sys [?]
S1 rninkmgf;rninkmgf;\??\c:\windows\system32\drivers\rninkmgf.sys --> c:\windows\system32\drivers\rninkmgf.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\superantispyware\sasdifsv.sys --> c:\program files\superantispyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\superantispyware\saskutil.sys --> c:\program files\superantispyware\SASKUTIL.sys [?]
S1 scdqwdil;scdqwdil;\??\c:\windows\system32\drivers\scdqwdil.sys --> c:\windows\system32\drivers\scdqwdil.sys [?]
S1 tanbdmrv;tanbdmrv;\??\c:\windows\system32\drivers\tanbdmrv.sys --> c:\windows\system32\drivers\tanbdmrv.sys [?]
S1 ttdsztdz;ttdsztdz;\??\c:\windows\system32\drivers\ttdsztdz.sys --> c:\windows\system32\drivers\ttdsztdz.sys [?]
S1 uawagoej;uawagoej;\??\c:\windows\system32\drivers\uawagoej.sys --> c:\windows\system32\drivers\uawagoej.sys [?]
S1 uezbgkmd;uezbgkmd;\??\c:\windows\system32\drivers\uezbgkmd.sys --> c:\windows\system32\drivers\uezbgkmd.sys [?]
S1 ufifbxdk;ufifbxdk;\??\c:\windows\system32\drivers\ufifbxdk.sys --> c:\windows\system32\drivers\ufifbxdk.sys [?]
S1 uhaiwvop;uhaiwvop;\??\c:\windows\system32\drivers\uhaiwvop.sys --> c:\windows\system32\drivers\uhaiwvop.sys [?]
S1 uibqjwsm;uibqjwsm;\??\c:\windows\system32\drivers\uibqjwsm.sys --> c:\windows\system32\drivers\uibqjwsm.sys [?]
S1 utnfmtab;utnfmtab;\??\c:\windows\system32\drivers\utnfmtab.sys --> c:\windows\system32\drivers\utnfmtab.sys [?]
S1 uuszovga;uuszovga;\??\c:\windows\system32\drivers\uuszovga.sys --> c:\windows\system32\drivers\uuszovga.sys [?]
S1 uxoezycr;uxoezycr;\??\c:\windows\system32\drivers\uxoezycr.sys --> c:\windows\system32\drivers\uxoezycr.sys [?]
S1 uynchbdx;uynchbdx;\??\c:\windows\system32\drivers\uynchbdx.sys --> c:\windows\system32\drivers\uynchbdx.sys [?]
S1 vwuypbxr;vwuypbxr;\??\c:\windows\system32\drivers\vwuypbxr.sys --> c:\windows\system32\drivers\vwuypbxr.sys [?]
S1 wasxpmgw;wasxpmgw;\??\c:\windows\system32\drivers\wasxpmgw.sys --> c:\windows\system32\drivers\wasxpmgw.sys [?]
S1 whjbtbls;whjbtbls;\??\c:\windows\system32\drivers\whjbtbls.sys --> c:\windows\system32\drivers\whjbtbls.sys [?]
S1 wjsetgzq;wjsetgzq;\??\c:\windows\system32\drivers\wjsetgzq.sys --> c:\windows\system32\drivers\wjsetgzq.sys [?]
S1 xkyflovj;xkyflovj;\??\c:\windows\system32\drivers\xkyflovj.sys --> c:\windows\system32\drivers\xkyflovj.sys [?]
S1 yahtalmn;yahtalmn;\??\c:\windows\system32\drivers\yahtalmn.sys --> c:\windows\system32\drivers\yahtalmn.sys [?]
S1 ywpgxnsc;ywpgxnsc;\??\c:\windows\system32\drivers\ywpgxnsc.sys --> c:\windows\system32\drivers\ywpgxnsc.sys [?]
S1 zjztvedg;zjztvedg;\??\c:\windows\system32\drivers\zjztvedg.sys --> c:\windows\system32\drivers\zjztvedg.sys [?]
S2 DailyBibleGuideService;DailyBibleGuideService;c:\progra~1\dailyb~2\bar\1.bin\2vbarsvc.exe [2011-8-17 42504]
S3 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-3-12 164736]
S3 AX88172;NETGEAR FA120 USB 2.0 Fast Ethernet Adapter;c:\windows\system32\drivers\FA120.sys [2008-1-15 14048]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2010-3-31 342784]
S3 SASENUM;SASENUM;\??\c:\program files\superantispyware\sasenum.sys --> c:\program files\superantispyware\SASENUM.SYS [?]
.
=============== File Associations ===============
.
FileExt: .vbe: VBEFile=NOTEPAD.EXE %1
FileExt: .vbs: VBSFile=NOTEPAD.EXE %1
FileExt: .js: JSFile=NOTEPAD.EXE %1
FileExt: .jse: JSEFile=NOTEPAD.EXE %1
FileExt: .wsf: WSFFile=NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2013-03-15 23:57:14 -------- d-----w- c:\documents and settings\owner\local settings\application data\Sun
2013-03-13 07:43:48 -------- d-----w- c:\program files\Bonjour
2013-03-13 06:08:01 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-03-13 06:08:01 49248 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-03-13 06:08:01 164736 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-03-13 06:08:00 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-03-13 06:06:39 41664 ----a-w- c:\windows\avastSS.scr
2013-03-13 06:05:59 -------- d-----w- c:\program files\AVAST Software
2013-03-13 06:05:21 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2013-03-12 22:31:33 -------- d-----w- c:\windows\system32\Adobe
2013-03-12 22:15:09 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-12 22:15:09 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-12 22:15:08 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-03-12 22:14:58 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-12 21:49:09 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-03-12 21:49:02 865744 ----a-w- c:\program files\mozilla firefox\uninstall\helper.exe
2013-03-12 21:49:02 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2013-03-12 19:21:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-03-12 19:21:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-03-12 10:45:35 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
2013-03-12 07:07:24 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-12 07:07:24 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-12 06:45:41 -------- d-----w- C:\Computer
2013-03-12 06:41:41 -------- d-----w- c:\program files\CCleaner
2013-03-12 05:29:25 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2013-03-12 05:29:25 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2013-03-12 05:29:18 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2013-03-12 05:29:18 21504 ----a-w- c:\windows\system32\hidserv.dll
2013-03-12 05:03:08 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2013-03-12 05:03:08 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2013-02-21 01:42:25 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
.
==================== Find3M ====================
.
2013-02-12 00:32:23 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-12 00:32:23 12928 ------w- c:\windows\system32\drivers\usb8023x.sys
2013-02-05 20:05:47 916480 ----a-w- c:\windows\system32\wininet.dll
2013-02-05 20:05:46 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-02-05 20:05:46 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-02-05 05:53:57 385024 ----a-w- c:\windows\system32\html.iec
2013-01-30 10:53:21 232336 ------w- c:\windows\system32\MpSigStub.exe
2013-01-26 03:55:44 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-07 01:16:02 2193024 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:36:58 2069760 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20:00 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49:10 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49:10 1292288 ----a-w- c:\windows\system32\quartz.dll
.
============= FINISH: 0:58:33.43 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-03-19 01:02:57
-----------------------------
01:02:57.078 OS Version: Windows 5.1.2600 Service Pack 3
01:02:57.078 Number of processors: 1 586 0xA00
01:02:57.078 ComputerName: OFFICE UserName: Owner
01:02:58.046 Initialize success
01:02:59.328 AVAST engine defs: 13031801
01:03:09.187 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000074
01:03:09.187 Disk 0 Vendor: ST3160215A 3.AAC Size: 152627MB BusType: 3
01:03:09.343 Disk 0 MBR read successfully
01:03:09.343 Disk 0 MBR scan
01:03:09.343 Disk 0 Windows XP default MBR code
01:03:09.343 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152617 MB offset 63
01:03:09.359 Disk 0 scanning sectors +312560640
01:03:09.562 Disk 0 scanning C:\WINDOWS\system32\drivers
01:03:29.234 Service scanning
01:04:01.812 Modules scanning
01:04:21.046 Disk 0 trace - called modules:
01:04:21.078 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll nvatabus.sys
01:04:21.078 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8575fab8]
01:04:21.078 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\00000076[0x85760f18]
01:04:21.078 5 ACPI.sys[f743e620] -> nt!IofCallDriver -> \Device\00000074[0x857616e8]
01:04:21.437 AVAST engine scan C:\WINDOWS
01:04:29.546 AVAST engine scan C:\WINDOWS\system32
01:07:11.625 AVAST engine scan C:\WINDOWS\system32\drivers
01:07:33.765 AVAST engine scan C:\Documents and Settings\Owner
01:08:22.484 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
01:08:22.484 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"