.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_33
Run by McKenzie at 23:02:57 on 2012-07-18
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\McKenzie\Desktop\dds.scr
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page =
https://isearch.avg.com/?cid={43243...2ba39aee3&lang=en&ds=lw011&pr=sa&d=2012-07-01 00:35:22&v=11.1.1.7&sap=hp
uWindow Title = Internet Explorer provided by Dell
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [COMODO] c:\program files\comodo\comodo geekbuddy\CLPSLA.exe
mRun: [CPA] c:\program files\comodo\comodo geekbuddy\VALA.exe
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRunOnce: [AvgUninstallURL] cmd.exe /c start
http://www.avg.com/ww.special-unins...gBGAEcAUgBSAC0AOAA2ADQAMABIAC0AVQBWAFgAVQBGAA"&"inst=NwA2AC0ANwA4ADUANwA2ADkAMgA5ADAALQBVADkAMAArADEALQBUAFAAKwAxAC0AWABPADMANgArADEALQBUAEIAOQArADIALQBOADEARAArADEALQBQAEwAKwA5AC0AQwBJAEEAOQAwACsAMgAtAEQARABUACsAMAA"&"prod=92"&"ver=9.0.894
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {682C59F5-478C-4421-9070-AD170D143B77} - hxxp://
www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} - hxxp://xserv.dell.com/DellDriverScanner/DellSystem.CAB
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
TCP: DhcpNameServer = 192.168.2.1 192.168.254.254
TCP: Interfaces\{6B450408-F9C2-4D7F-81A9-2DE27D4713D5} : NameServer = 8.26.56.26,156.154.70.22
TCP: Interfaces\{D34CB892-5A03-48BA-BD56-853A116E64D9} : NameServer = 8.26.56.26,156.154.70.22
TCP: Interfaces\{D34CB892-5A03-48BA-BD56-853A116E64D9} : DhcpNameServer = 192.168.2.1 192.168.254.254
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\guard32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\mckenzie\appdata\roaming\mozilla\firefox\profiles\8nx5ar5e.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://
www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bcb6930fc-fdb2-407c-ae3f-dce348820aff%7D&mid=caa1aa7ce3ba8fd1219eb0364abbb1a4-f5d3a8f2cdf5a91096a0cff57baf0392ba39aee3&ds=AVG&v=11.1.0.12&lang=en&pr=pr&d=2012-07-16%2017%3A03%3A15&sap=ku&q=
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\mckenzie\appdata\roaming\mozilla\firefox\profiles\8nx5ar5e.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\plugins\np-mswmp.dll
FF - plugin: c:\users\mckenzie\appdata\roaming\mozilla\firefox\profiles\8nx5ar5e.default\extensions\
devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R? AdobeARMservice;Adobe Acrobat Update Service
R? AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service
R? AESTFilters;Andrea ST Filters Service
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? DockLoginService;Dock Login Service
R? EPSON_EB_RPCV4_04;EPSON V5 Service4(04)
R? EPSON_PM_RPCV4_04;EPSON V3 Service4(04)
R? EpsonCustomerParticipation;EpsonCustomerParticipation
R? fssfltr;fssfltr
R? fsssvc;Windows Live Family Safety Service
R? McAfee SiteAdvisor Service;McAfee SiteAdvisor Service
R? MozillaMaintenance;Mozilla Maintenance Service
R? NielsenUpdate;Nielsen Update
R? nnfwdk;Nielsen WFP Driver
R? PanelSvc;PanelSvc
R? PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver
R? SftService;SoftThinks Agent Service
R? wlcrasvc;Windows Live Mesh remote connections service
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
R? yksvc;Marvell Yukon Service
S? AdvancedSystemCareService5;Advanced SystemCare Service 5
S? CLPSLS;COMODO livePCsupport Service
S? cmderd;COMODO Internet Security Eradication Driver
S? cmdGuard;COMODO Internet Security Sandbox Driver
S? cmdHlp;COMODO Internet Security Helper Driver
S? ElRawDisk;ElRawDisk
S? FontCache;Windows Font Cache Service
S? pwlyqkow;pwlyqkow
.
=============== File Associations ===============
.
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2012-07-19 03:40:28 100864 ----a-w- C:\pwlyqkow.sys
2012-07-19 03:16:55 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-19 03:16:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-19 03:02:16 -------- d-----w- c:\programdata\CPA_VA
2012-07-19 03:00:51 363489 ----a-w- c:\windows\system32\drivers\sfi.dat
2012-07-19 02:58:16 -------- d-----w- c:\programdata\Comodo
2012-07-19 02:58:14 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2012-07-19 02:58:14 -------- d-----w- c:\program files\COMODO
2012-07-17 07:06:11 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{4cc15876-59fc-45cf-b9fb-7eb84feb2eba}\offreg.dll
2012-07-17 06:50:07 6891424 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{4cc15876-59fc-45cf-b9fb-7eb84feb2eba}\mpengine.dll
2012-07-16 18:21:01 -------- d-----w- c:\users\mckenzie\appdata\roaming\Tific
2012-07-16 18:21:00 -------- d-----w- c:\users\mckenzie\appdata\local\tific
2012-07-15 07:56:42 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-15 07:56:42 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-15 07:56:30 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-15 07:56:30 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-15 07:56:30 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-15 07:56:08 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-07-15 07:55:38 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2012-07-09 06:32:24 -------- d-sh--w- C:\found.000
2012-07-01 05:35:52 -------- d-----w- c:\users\mckenzie\appdata\roaming\FIXIO PC Utilities
2012-06-30 17:50:57 -------- d-----w- c:\users\mckenzie\appdata\roaming\PCDr
2012-06-30 17:22:04 74703 ----a-w- c:\windows\system32\mfc45.dll
.
==================== Find3M ====================
.
2012-07-15 07:57:11 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-07-15 07:57:10 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-07-15 07:57:10 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-07-15 07:57:10 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-07-15 07:57:09 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-07-15 07:37:36 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-15 07:37:36 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-16 19:54:25 476936 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-06-16 19:54:25 472840 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 20:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 20:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-05-31 17:25:14 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-05-24 15:48:02 21888 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-05-12 02:51:37 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-12 02:51:37 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-12 02:51:27 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-05-12 02:51:15 914304 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-05-12 02:51:15 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-05-12 02:46:01 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-05-12 02:46:00 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-05-12 02:46:00 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-05-12 02:46:00 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-05-12 02:46:00 1069056 ----a-w- c:\windows\system32\DWrite.dll
2012-05-01 14:03:49 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-23 16:00:53 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-04-23 16:00:53 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-04-23 16:00:53 133120 ----a-w- c:\windows\system32\cryptsvc.dll
.
============= FINISH: 23:03:50.90 ===============