I have encountered windows command processor virus in my computer and have followed the 5-step Viruses/Spyware/Malware Preliminary Removal Instructions. But my gmer.exe. doesn't seems to be worked because i can't enable the Avira free antivirus. These are the Malwarebytes Anti-Malware log,DDS.txt and Attach.txt
your help is much appreciated.
Malwarebytes Anti-Malware log
-------------------------------------------
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.13.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Asus :: ASUS-PC [administrator]
Protection: Disabled
2/14/2012 12:08:40 PM
mbam-log-2012-02-14 (12-08-40).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 179707
Time elapsed: 2 minute(s), 49 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Users\Asus\AppData\Local\Temp\0.35632900847195625fdrgs.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
(end)
DDS.txt
-----------
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
Run by Asus at 12:22:21 on 2012-02-14
Microsoft Windows 7 Home Premium 6.1.7601.1.936.86.1033.18.4073.2498 [GMT 8:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\FBAgent.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Elantech\ETDCtrl.exe
D:\PPS.tv\PPStream\PPSAP.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\svchost.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://asus.msn.com
uDefault_Page_URL = hxxp://asus.msn.com
mStart Page = hxxp://asus.msn.com
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: CIESpeechBHO Class: {8d10f6c4-0e01-4bd4-8601-11ac1fdf8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [PPS Accelerator] D:\PPS.tv\PPStream\PPSAP.exe
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [RjiIrifq] C:\Users\Asus\AppData\Local\jdqvhivd\rjiirifq.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rjiirifq.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 10.84.0.1
TCP: Interfaces\{5E8D9AC1-633D-482F-AF18-6096465A8DD6} : DhcpNameServer = 10.84.0.1
TCP: Interfaces\{8D16FBAD-0FAE-498A-8BE9-BF6C48167C00} : DhcpNameServer = 10.0.1.1
TCP: Interfaces\{8D16FBAD-0FAE-498A-8BE9-BF6C48167C00}\175716E6775696 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{8D16FBAD-0FAE-498A-8BE9-BF6C48167C00}\C696D66616D696C697 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{8D16FBAD-0FAE-498A-8BE9-BF6C48167C00}\D4163624F6F6B60527F6723702745756374702E4564777F627B6 : DhcpNameServer = 172.16.42.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO-X64: IESpeakDoc - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO-X64: Google Dictionary Compression sdch: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
BHO-X64: Google Dictionary Compression sdch - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun-x64: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun-x64: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun-x64: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun-x64: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun-x64: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\j9c4ciuy.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Tencent\QQMusic\npQzoneMusic.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-5-26 17536]
R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys --> C:\Windows\system32\DRIVERS\avkmgr.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AFBAgent;AFBAgent;"C:\Windows\system32\FBAgent.exe" --> C:\Windows\system32\FBAgent.exe [?]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-1-6 86224]
R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-1-6 110032]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-14 138400]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-14 74912]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-2-14 652360]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-6-5 378472]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
R2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-4-17 134928]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\system32\DRIVERS\asmthub3.sys --> C:\Windows\system32\DRIVERS\asmthub3.sys [?]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\system32\DRIVERS\asmtxhci.sys --> C:\Windows\system32\DRIVERS\asmtxhci.sys [?]
R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\system32\DRIVERS\btath_flt.sys --> C:\Windows\system32\DRIVERS\btath_flt.sys [?]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\system32\drivers\btath_a2dp.sys --> C:\Windows\system32\drivers\btath_a2dp.sys [?]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\system32\DRIVERS\btath_bus.sys --> C:\Windows\system32\DRIVERS\btath_bus.sys [?]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\system32\DRIVERS\btath_hcrp.sys --> C:\Windows\system32\DRIVERS\btath_hcrp.sys [?]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\system32\DRIVERS\btath_lwflt.sys --> C:\Windows\system32\DRIVERS\btath_lwflt.sys [?]
R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\system32\DRIVERS\btath_rcp.sys --> C:\Windows\system32\DRIVERS\btath_rcp.sys [?]
R3 BtFilter;BtFilter;C:\Windows\system32\DRIVERS\btfilter.sys --> C:\Windows\system32\DRIVERS\btfilter.sys [?]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUVStor.sys --> C:\Windows\system32\Drivers\RtsUVStor.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-4-13 135664]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-1-31 158856]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-4-13 135664]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSG664.sys --> C:\Windows\system32\DRIVERS\SiSG664.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-02-14 04:08:06 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-02-14 04:08:06 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-02-13 21:36:06 -------- d-----w- C:\Users\Asus\AppData\Roaming\Malwarebytes
2012-02-13 21:36:02 -------- d-----w- C:\ProgramData\Malwarebytes
2012-02-13 20:05:14 -------- d-----w- C:\Users\Asus\AppData\Roaming\Ycko
2012-02-13 20:05:14 -------- d-----w- C:\Users\Asus\AppData\Roaming\Inte
2012-02-13 18:30:22 -------- d-----w- C:\Users\Asus\AppData\Local\{2D407FEF-1C93-4E6E-B936-353A061E999C}
2012-02-13 18:30:12 -------- d-----w- C:\Users\Asus\AppData\Local\{9BB31DBA-A29A-409D-A06C-169CA200E189}
2012-02-13 13:10:04 -------- d-----w- C:\Users\Asus\AppData\Roaming\WinZip
2012-02-13 13:07:32 -------- d-----w- C:\Users\Asus\AppData\Local\WinZip
2012-02-13 12:23:20 -------- d-----r- C:\Program Files (x86)\Skype
2012-02-13 02:22:50 -------- d-----w- C:\Users\Asus\AppData\Local\{71015250-4221-48D8-83C2-B57DDD6F266E}
2012-02-13 02:22:37 -------- d-----w- C:\Users\Asus\AppData\Local\{96F7AA3C-F0C2-4FD1-8FF9-9830C2489DD2}
2012-02-13 01:22:57 -------- d-----w- C:\Users\Asus\AppData\Local\CrashDumps
2012-02-13 01:18:06 -------- d-----w- C:\Users\Asus\AppData\Local\jdqvhivd
2012-02-12 08:19:09 -------- d-----w- C:\Users\Asus\AppData\Local\{FAB4A53D-23BC-4F13-A458-FA2784064EC3}
2012-02-12 08:18:59 -------- d-----w- C:\Users\Asus\AppData\Local\{DBE8D854-8BE2-4FEB-8336-B123407E6982}
2012-02-11 19:16:19 -------- d-----w- C:\Users\Asus\AppData\Local\{8258CBA1-7367-4794-AFB9-94EA464F54C2}
2012-02-11 19:16:09 -------- d-----w- C:\Users\Asus\AppData\Local\{9589C50B-CA07-4734-82C5-7967B05D13F2}
2012-02-11 07:15:33 -------- d-----w- C:\Users\Asus\AppData\Local\{E7E4035B-064E-43DB-945B-2031FA6BB967}
2012-02-11 07:15:22 -------- d-----w- C:\Users\Asus\AppData\Local\{ABEABE08-9F6B-48CA-A80B-3AED3E2C7D5B}
2012-02-11 00:02:40 8602168 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{54FA2A28-2CC3-44EE-9493-D61C0301AAA9}\mpengine.dll
2012-02-10 18:06:07 -------- d-----w- C:\Users\Asus\AppData\Local\{B7A946F7-8769-4668-9392-1316F1120180}
2012-02-10 18:05:56 -------- d-----w- C:\Users\Asus\AppData\Local\{48D26241-03FA-47A1-A07B-421DCD526103}
2012-02-10 15:35:38 -------- d-----w- C:\Users\Asus\AppData\Local\{E2A8C179-5FC9-4EF4-93FD-DE0D4472F17F}
2012-02-08 16:02:06 -------- d-----w- C:\Users\Asus\AppData\Local\{6E1FEDD6-0620-403F-AE05-56178A8D3A49}
2012-02-08 16:01:54 -------- d-----w- C:\Users\Asus\AppData\Local\{AC49F560-4169-4CE1-A8F4-07C0842FFF53}
2012-02-08 04:01:10 -------- d-----w- C:\Users\Asus\AppData\Local\{7A78C3E0-7C0C-40C7-8E89-DC383E4A9E42}
2012-02-08 04:00:58 -------- d-----w- C:\Users\Asus\AppData\Local\{C237499F-BA96-420F-9FD3-0E6CC0EC5B65}
2012-02-06 16:32:10 -------- d-----w- C:\Users\Asus\AppData\Local\{38F0EC44-3124-4FCF-AA6F-80BD0F624676}
2012-02-06 16:31:58 -------- d-----w- C:\Users\Asus\AppData\Local\{68B6B019-25B0-4B32-83A8-722E157C7270}
2012-02-05 17:42:17 -------- d-----w- C:\Users\Asus\AppData\Local\{A19D5F75-C3E9-48B3-AF37-2C669D4CC8A9}
2012-02-05 17:42:04 -------- d-----w- C:\Users\Asus\AppData\Local\{78E8898C-D9E1-468E-AE37-2267D23F24A3}
2012-02-05 02:52:59 -------- d-----w- C:\Users\Asus\AppData\Local\{B0949521-4E38-4B93-9EFC-2D060761F184}
2012-02-05 02:52:47 -------- d-----w- C:\Users\Asus\AppData\Local\{0EAEFFDB-A0C9-488E-8FB4-BE8C8225F1B4}
2012-02-04 12:28:13 -------- d-----w- C:\Users\Asus\AppData\Local\{E1EB2EE0-A3AA-436D-A621-0CECCC0DE3F3}
2012-02-04 12:28:01 -------- d-----w- C:\Users\Asus\AppData\Local\{C8C9740C-3C46-49E5-8FDD-EB6462FA3FD1}
2012-02-04 10:22:11 -------- d-----w- C:\Users\Asus\AppData\Local\{291EB5F5-221D-43FB-842B-AACFF7B8C69D}
2012-02-03 06:44:37 -------- d-----w- C:\Program Files\CCleaner
2012-02-03 06:06:51 -------- d-----w- C:\Program Files\iTunes
2012-02-03 06:06:51 -------- d-----w- C:\Program Files\iPod
2012-02-03 04:07:35 -------- d-----w- C:\Users\Asus\AppData\Local\{CB121D4F-D7D8-4D7F-95A8-BBC2F68CB52E}
2012-02-03 04:07:13 -------- d-----w- C:\Users\Asus\AppData\Local\{31C04942-989B-47BE-95EC-20EBC3E318ED}
2012-02-02 17:52:35 308600 ----a-w- C:\Windows\SysWow64\MMInstaller.dll
2012-02-02 17:52:31 -------- d-----w- C:\Program Files (x86)\Tencent
2012-02-02 17:52:31 -------- d-----w- C:\Program Files (x86)\Common Files\Tencent
2012-02-02 17:52:24 -------- d-----w- C:\ProgramData\Tencent
2012-02-02 17:52:23 -------- d-----w- C:\Users\Asus\AppData\Roaming\Tencent
2012-02-02 16:06:40 -------- d-----w- C:\Users\Asus\AppData\Local\{EFBEB083-7DAD-49F9-8BFA-7DD16587A823}
2012-02-02 03:17:27 -------- d-----w- C:\Users\Asus\AppData\Local\{DA8005F0-80C4-4FEB-89F8-21B993D32CBA}
2012-02-02 03:17:16 -------- d-----w- C:\Users\Asus\AppData\Local\{2782086D-63BE-420F-BB15-7EE4F4985BC8}
2012-02-01 06:41:42 -------- d-----w- C:\Users\Asus\AppData\Local\{B8FC68BA-1D66-41C5-BB73-F8F6ED9B8AD5}
2012-02-01 06:41:30 -------- d-----w- C:\Users\Asus\AppData\Local\{78491E83-C6F1-478F-B7FB-B95BC6B0427E}
2012-01-31 16:23:58 -------- d-----w- C:\Users\Asus\AppData\Local\{7407A54F-B2B0-4092-BECC-576ACE94A982}
2012-01-31 16:23:46 -------- d-----w- C:\Users\Asus\AppData\Local\{8020D09A-8041-4980-8C76-53D74FF4EA3F}
2012-01-29 04:02:20 -------- d-----w- C:\Users\Asus\AppData\Local\{24DCE46A-F271-49C0-95BA-80D3704DA8F8}
2012-01-29 04:01:51 -------- d-----w- C:\Users\Asus\AppData\Local\{0E71D4F3-660F-46A6-B35D-BB50345F1A3E}
2012-01-27 17:08:46 -------- d-----w- C:\Users\Asus\AppData\Local\{FE045D66-437F-4FF6-BFF4-FFC07D119747}
2012-01-27 17:08:34 -------- d-----w- C:\Users\Asus\AppData\Local\{D6796BC2-CD49-4CD0-AFE6-053D6536B616}
2012-01-25 08:48:16 -------- d-----w- C:\Users\Asus\AppData\Local\{68BBD1F7-4A0F-4FB6-8FCA-A2A8201C98B1}
2012-01-25 08:48:03 -------- d-----w- C:\Users\Asus\AppData\Local\{D91F7664-395F-47CE-9621-A1DDF59E55C5}
2012-01-20 11:42:18 -------- d-----w- C:\Users\Asus\AppData\Local\{1C5A01A5-63EE-473C-8657-A58BE51AF6CA}
2012-01-20 11:42:05 -------- d-----w- C:\Users\Asus\AppData\Local\{D558A982-0517-4D2B-9F40-829ABBE8DBA6}
2012-01-19 03:01:56 -------- d-----w- C:\Users\Asus\AppData\Local\{E472A9A3-29C9-4C17-9A41-6ADBE8B7D5C1}
2012-01-19 03:01:43 -------- d-----w- C:\Users\Asus\AppData\Local\{B6B28B19-478D-4098-8554-43B56BF342FC}
2012-01-17 14:32:55 -------- d-----w- C:\Users\Asus\AppData\Local\{09D19D2A-7CD0-40B1-ADD3-581D99C0EBF6}
2012-01-17 14:32:42 -------- d-----w- C:\Users\Asus\AppData\Local\{50175454-F4A7-4498-99C7-99B14ED4AF26}
2012-01-16 15:01:11 -------- d-----w- C:\Windows\en
2012-01-16 14:59:57 -------- d-----w- C:\Windows\ar
2012-01-16 14:59:51 -------- d-----w- C:\Windows\es
2012-01-16 14:59:45 -------- d-----w- C:\Windows\fr
2012-01-16 14:59:40 -------- d-----w- C:\Windows\th
2012-01-16 14:59:35 -------- d-----w- C:\Windows\tr
2012-01-16 14:55:50 18328 ----a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-01-16 14:52:47 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\8323a0f31ccd45e02\MeshBetaRemover.exe
2012-01-16 14:50:19 -------- d-----w- C:\Users\Asus\AppData\Local\{8A8D34DE-4601-46BC-A6BD-C3F888F12A0D}
2012-01-16 14:50:07 -------- d-----w- C:\Users\Asus\AppData\Local\{589DA7BE-0263-4FB9-861D-A7AAE5D7FFAF}
2012-01-16 13:37:58 -------- d-----w- C:\Users\Asus\AppData\Local\{E5F2F281-DABE-4C10-B7C9-9EBDA480685E}
2012-01-16 13:37:43 -------- d-----w- C:\Users\Asus\AppData\Local\{CBE35672-F5C7-4D7D-80A0-CD404F7A1B50}
.
==================== Find3M ====================
.
2012-02-14 04:12:57 45056 ----a-w- C:\Windows\System32\acovcnt.exe
2012-01-26 16:52:58 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-01-08 15:30:45 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-06 12:04:28 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-01-06 02:51:15 80512 ----a-w- C:\Windows\ASUS K3 Series ScreenSaver Uninstaller.exe
2012-01-06 02:51:14 3058304 ----a-w- C:\Windows\AsScrPro.exe
2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-11-19 14:58:00 77312 ----a-w- C:\Windows\System32\packager.dll
2011-11-19 14:01:00 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2011-11-17 06:49:14 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2011-11-17 06:49:14 152432 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2011-11-17 06:44:43 459232 ----a-w- C:\Windows\System32\drivers\cng.sys
2011-11-17 06:41:18 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2011-11-17 06:35:28 395776 ----a-w- C:\Windows\System32\webio.dll
2011-11-17 06:35:26 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2011-11-17 06:35:26 136192 ----a-w- C:\Windows\System32\sspicli.dll
2011-11-17 06:35:25 340992 ----a-w- C:\Windows\System32\schannel.dll
2011-11-17 06:35:25 28160 ----a-w- C:\Windows\System32\secur32.dll
2011-11-17 06:35:19 1447936 ----a-w- C:\Windows\System32\lsasrv.dll
2011-11-17 06:33:55 31232 ----a-w- C:\Windows\System32\lsass.exe
2011-11-17 05:38:39 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2011-11-17 05:35:02 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2011-11-17 05:34:52 224768 ----a-w- C:\Windows\SysWow64\schannel.dll
2011-11-17 05:34:52 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2011-11-17 05:28:48 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
.
============= FINISH: 12:22:51.53 ===============
Attach.txt
------------
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 1/6/2012 1:05:47 PM
System Uptime: 2/14/2012 12:12:23 PM (0 hours ago)
.
Motherboard: ASUSTeK Computer Inc. | | K43SJ
Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz | CPU 1 | 2401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 259 GiB total, 205.618 GiB free.
D: is FIXED (NTFS) - 312 GiB total, 308.544 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP34: 2/1/2012 12:27:45 AM - Windows Update
RP35: 2/8/2012 12:04:28 PM - Windows Update
RP37: 2/13/2012 8:12:25 PM - Removed Skype Click to Call
RP39: 2/13/2012 9:06:45 PM - Installed WinZip 16.0
RP40: 2/14/2012 11:23:23 AM - 2/11/2012
RP41: 2/14/2012 11:25:57 AM - Restore Operation
.
==== Installed Programs ======================
.
???? ??? Windows Live
???? ???? ActiveX ????? ?? Windows Live Mesh ????????? ???????
???? Windows Live
????????? ActiveX ?? Windows Live Mesh ????????????????????????? (???)
Adobe Flash Player 10 ActiveX
Apple Application Support
Apple Software Update
Asmedia ASM104x USB 3.0 Host Controller Driver
ASUS AI Recovery
ASUS FancyStart
ASUS K3 Series ScreenSaver
ASUS LifeFrame3
ASUS Live Update
ASUS SmartLogon
ASUS Splendid Video Enhancement Technology
ASUS Virtual Camera
ASUS WebStorage
AsusVibe2.0
Atheros Client Installation Program
ATK Package
Avira Free Antivirus
Bookworm Deluxe
Contr?le ActiveX Windows Live Mesh pour connexions à distance
Control ActiveX de Windows Live Mesh para conexiones remotas
Controle ActiveX do Windows Live Mesh para Conex?es Remotas
Cooking Dash
CyberLink LabelPrint
CyberLink Power2Go
D3DX10
Galería fotográfica de Windows Live
Galerie de photos Windows Live
Game Park Console
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Governor of Poker
Hotel Dash Suite Success
Java Auto Updater
Java(TM) 6 Update 22
Jewel Quest 3
Junk Mail filter update
Luxor 3
Mahjongg dimensions
Malwarebytes Anti-Malware version 1.60.1.1000
Mesh Runtime
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 10.0.1 (x86 en-US)
MSVCRT
MSVCRT_amd64
Nuance PDF Reader
NVIDIA Stereoscopic 3D Driver
OpenOffice.org 3.3
Plants vs Zombies
PPS影音 V2.7.0.1364 正式版
QQ音乐 2012
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Reader Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Skype? 5.8
Sonic Focus
syncables desktop SE
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Uzak Ba?lant?lar ??in Windows Live Mesh ActiveX Denetimi
Windows Live
Windows Live Communications Platform
Windows Live Essentials
Windows Live Foto?raf Galerisi
Windows Live Galeria de Fotos
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Temel Par?alar
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Live 影像中心
Windows Live 照片库
Windows Live 程式集
Windows Live 软件包
WinFlash
Wireless Console 3
World of Goo
用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文)
適用遠端連線的 Windows Live Mesh ActiveX 控制項
.
==== Event Viewer Messages From Past Week ========
.
2/14/2012 4:19:15 AM, Error: NetBT [4321] - The name "WORKGROUP :1d" could not be registered on the interface with IP address 10.84.2.188. The computer with the IP address 10.84.1.216 did not allow the name to be claimed by this computer.
2/14/2012 12:13:57 PM, Error: Application Popup [1060] - \??\C:\Users\Asus\AppData\Local\Temp\yugpufxg.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
.
==== End Of File ===========================
your help is much appreciated.
Malwarebytes Anti-Malware log
-------------------------------------------
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.13.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Asus :: ASUS-PC [administrator]
Protection: Disabled
2/14/2012 12:08:40 PM
mbam-log-2012-02-14 (12-08-40).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 179707
Time elapsed: 2 minute(s), 49 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Users\Asus\AppData\Local\Temp\0.35632900847195625fdrgs.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
(end)
DDS.txt
-----------
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
Run by Asus at 12:22:21 on 2012-02-14
Microsoft Windows 7 Home Premium 6.1.7601.1.936.86.1033.18.4073.2498 [GMT 8:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\FBAgent.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Elantech\ETDCtrl.exe
D:\PPS.tv\PPStream\PPSAP.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\svchost.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://asus.msn.com
uDefault_Page_URL = hxxp://asus.msn.com
mStart Page = hxxp://asus.msn.com
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: CIESpeechBHO Class: {8d10f6c4-0e01-4bd4-8601-11ac1fdf8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [PPS Accelerator] D:\PPS.tv\PPStream\PPSAP.exe
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [RjiIrifq] C:\Users\Asus\AppData\Local\jdqvhivd\rjiirifq.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rjiirifq.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 10.84.0.1
TCP: Interfaces\{5E8D9AC1-633D-482F-AF18-6096465A8DD6} : DhcpNameServer = 10.84.0.1
TCP: Interfaces\{8D16FBAD-0FAE-498A-8BE9-BF6C48167C00} : DhcpNameServer = 10.0.1.1
TCP: Interfaces\{8D16FBAD-0FAE-498A-8BE9-BF6C48167C00}\175716E6775696 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{8D16FBAD-0FAE-498A-8BE9-BF6C48167C00}\C696D66616D696C697 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{8D16FBAD-0FAE-498A-8BE9-BF6C48167C00}\D4163624F6F6B60527F6723702745756374702E4564777F627B6 : DhcpNameServer = 172.16.42.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO-X64: IESpeakDoc - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO-X64: Google Dictionary Compression sdch: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
BHO-X64: Google Dictionary Compression sdch - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun-x64: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun-x64: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun-x64: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun-x64: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun-x64: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\j9c4ciuy.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Tencent\QQMusic\npQzoneMusic.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-5-26 17536]
R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys --> C:\Windows\system32\DRIVERS\avkmgr.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AFBAgent;AFBAgent;"C:\Windows\system32\FBAgent.exe" --> C:\Windows\system32\FBAgent.exe [?]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-1-6 86224]
R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-1-6 110032]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-14 138400]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-14 74912]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-2-14 652360]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-6-5 378472]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
R2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-4-17 134928]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\system32\DRIVERS\asmthub3.sys --> C:\Windows\system32\DRIVERS\asmthub3.sys [?]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\system32\DRIVERS\asmtxhci.sys --> C:\Windows\system32\DRIVERS\asmtxhci.sys [?]
R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\system32\DRIVERS\btath_flt.sys --> C:\Windows\system32\DRIVERS\btath_flt.sys [?]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\system32\drivers\btath_a2dp.sys --> C:\Windows\system32\drivers\btath_a2dp.sys [?]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\system32\DRIVERS\btath_bus.sys --> C:\Windows\system32\DRIVERS\btath_bus.sys [?]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\system32\DRIVERS\btath_hcrp.sys --> C:\Windows\system32\DRIVERS\btath_hcrp.sys [?]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\system32\DRIVERS\btath_lwflt.sys --> C:\Windows\system32\DRIVERS\btath_lwflt.sys [?]
R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\system32\DRIVERS\btath_rcp.sys --> C:\Windows\system32\DRIVERS\btath_rcp.sys [?]
R3 BtFilter;BtFilter;C:\Windows\system32\DRIVERS\btfilter.sys --> C:\Windows\system32\DRIVERS\btfilter.sys [?]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUVStor.sys --> C:\Windows\system32\Drivers\RtsUVStor.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-4-13 135664]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-1-31 158856]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-4-13 135664]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSG664.sys --> C:\Windows\system32\DRIVERS\SiSG664.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-02-14 04:08:06 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-02-14 04:08:06 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-02-13 21:36:06 -------- d-----w- C:\Users\Asus\AppData\Roaming\Malwarebytes
2012-02-13 21:36:02 -------- d-----w- C:\ProgramData\Malwarebytes
2012-02-13 20:05:14 -------- d-----w- C:\Users\Asus\AppData\Roaming\Ycko
2012-02-13 20:05:14 -------- d-----w- C:\Users\Asus\AppData\Roaming\Inte
2012-02-13 18:30:22 -------- d-----w- C:\Users\Asus\AppData\Local\{2D407FEF-1C93-4E6E-B936-353A061E999C}
2012-02-13 18:30:12 -------- d-----w- C:\Users\Asus\AppData\Local\{9BB31DBA-A29A-409D-A06C-169CA200E189}
2012-02-13 13:10:04 -------- d-----w- C:\Users\Asus\AppData\Roaming\WinZip
2012-02-13 13:07:32 -------- d-----w- C:\Users\Asus\AppData\Local\WinZip
2012-02-13 12:23:20 -------- d-----r- C:\Program Files (x86)\Skype
2012-02-13 02:22:50 -------- d-----w- C:\Users\Asus\AppData\Local\{71015250-4221-48D8-83C2-B57DDD6F266E}
2012-02-13 02:22:37 -------- d-----w- C:\Users\Asus\AppData\Local\{96F7AA3C-F0C2-4FD1-8FF9-9830C2489DD2}
2012-02-13 01:22:57 -------- d-----w- C:\Users\Asus\AppData\Local\CrashDumps
2012-02-13 01:18:06 -------- d-----w- C:\Users\Asus\AppData\Local\jdqvhivd
2012-02-12 08:19:09 -------- d-----w- C:\Users\Asus\AppData\Local\{FAB4A53D-23BC-4F13-A458-FA2784064EC3}
2012-02-12 08:18:59 -------- d-----w- C:\Users\Asus\AppData\Local\{DBE8D854-8BE2-4FEB-8336-B123407E6982}
2012-02-11 19:16:19 -------- d-----w- C:\Users\Asus\AppData\Local\{8258CBA1-7367-4794-AFB9-94EA464F54C2}
2012-02-11 19:16:09 -------- d-----w- C:\Users\Asus\AppData\Local\{9589C50B-CA07-4734-82C5-7967B05D13F2}
2012-02-11 07:15:33 -------- d-----w- C:\Users\Asus\AppData\Local\{E7E4035B-064E-43DB-945B-2031FA6BB967}
2012-02-11 07:15:22 -------- d-----w- C:\Users\Asus\AppData\Local\{ABEABE08-9F6B-48CA-A80B-3AED3E2C7D5B}
2012-02-11 00:02:40 8602168 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{54FA2A28-2CC3-44EE-9493-D61C0301AAA9}\mpengine.dll
2012-02-10 18:06:07 -------- d-----w- C:\Users\Asus\AppData\Local\{B7A946F7-8769-4668-9392-1316F1120180}
2012-02-10 18:05:56 -------- d-----w- C:\Users\Asus\AppData\Local\{48D26241-03FA-47A1-A07B-421DCD526103}
2012-02-10 15:35:38 -------- d-----w- C:\Users\Asus\AppData\Local\{E2A8C179-5FC9-4EF4-93FD-DE0D4472F17F}
2012-02-08 16:02:06 -------- d-----w- C:\Users\Asus\AppData\Local\{6E1FEDD6-0620-403F-AE05-56178A8D3A49}
2012-02-08 16:01:54 -------- d-----w- C:\Users\Asus\AppData\Local\{AC49F560-4169-4CE1-A8F4-07C0842FFF53}
2012-02-08 04:01:10 -------- d-----w- C:\Users\Asus\AppData\Local\{7A78C3E0-7C0C-40C7-8E89-DC383E4A9E42}
2012-02-08 04:00:58 -------- d-----w- C:\Users\Asus\AppData\Local\{C237499F-BA96-420F-9FD3-0E6CC0EC5B65}
2012-02-06 16:32:10 -------- d-----w- C:\Users\Asus\AppData\Local\{38F0EC44-3124-4FCF-AA6F-80BD0F624676}
2012-02-06 16:31:58 -------- d-----w- C:\Users\Asus\AppData\Local\{68B6B019-25B0-4B32-83A8-722E157C7270}
2012-02-05 17:42:17 -------- d-----w- C:\Users\Asus\AppData\Local\{A19D5F75-C3E9-48B3-AF37-2C669D4CC8A9}
2012-02-05 17:42:04 -------- d-----w- C:\Users\Asus\AppData\Local\{78E8898C-D9E1-468E-AE37-2267D23F24A3}
2012-02-05 02:52:59 -------- d-----w- C:\Users\Asus\AppData\Local\{B0949521-4E38-4B93-9EFC-2D060761F184}
2012-02-05 02:52:47 -------- d-----w- C:\Users\Asus\AppData\Local\{0EAEFFDB-A0C9-488E-8FB4-BE8C8225F1B4}
2012-02-04 12:28:13 -------- d-----w- C:\Users\Asus\AppData\Local\{E1EB2EE0-A3AA-436D-A621-0CECCC0DE3F3}
2012-02-04 12:28:01 -------- d-----w- C:\Users\Asus\AppData\Local\{C8C9740C-3C46-49E5-8FDD-EB6462FA3FD1}
2012-02-04 10:22:11 -------- d-----w- C:\Users\Asus\AppData\Local\{291EB5F5-221D-43FB-842B-AACFF7B8C69D}
2012-02-03 06:44:37 -------- d-----w- C:\Program Files\CCleaner
2012-02-03 06:06:51 -------- d-----w- C:\Program Files\iTunes
2012-02-03 06:06:51 -------- d-----w- C:\Program Files\iPod
2012-02-03 04:07:35 -------- d-----w- C:\Users\Asus\AppData\Local\{CB121D4F-D7D8-4D7F-95A8-BBC2F68CB52E}
2012-02-03 04:07:13 -------- d-----w- C:\Users\Asus\AppData\Local\{31C04942-989B-47BE-95EC-20EBC3E318ED}
2012-02-02 17:52:35 308600 ----a-w- C:\Windows\SysWow64\MMInstaller.dll
2012-02-02 17:52:31 -------- d-----w- C:\Program Files (x86)\Tencent
2012-02-02 17:52:31 -------- d-----w- C:\Program Files (x86)\Common Files\Tencent
2012-02-02 17:52:24 -------- d-----w- C:\ProgramData\Tencent
2012-02-02 17:52:23 -------- d-----w- C:\Users\Asus\AppData\Roaming\Tencent
2012-02-02 16:06:40 -------- d-----w- C:\Users\Asus\AppData\Local\{EFBEB083-7DAD-49F9-8BFA-7DD16587A823}
2012-02-02 03:17:27 -------- d-----w- C:\Users\Asus\AppData\Local\{DA8005F0-80C4-4FEB-89F8-21B993D32CBA}
2012-02-02 03:17:16 -------- d-----w- C:\Users\Asus\AppData\Local\{2782086D-63BE-420F-BB15-7EE4F4985BC8}
2012-02-01 06:41:42 -------- d-----w- C:\Users\Asus\AppData\Local\{B8FC68BA-1D66-41C5-BB73-F8F6ED9B8AD5}
2012-02-01 06:41:30 -------- d-----w- C:\Users\Asus\AppData\Local\{78491E83-C6F1-478F-B7FB-B95BC6B0427E}
2012-01-31 16:23:58 -------- d-----w- C:\Users\Asus\AppData\Local\{7407A54F-B2B0-4092-BECC-576ACE94A982}
2012-01-31 16:23:46 -------- d-----w- C:\Users\Asus\AppData\Local\{8020D09A-8041-4980-8C76-53D74FF4EA3F}
2012-01-29 04:02:20 -------- d-----w- C:\Users\Asus\AppData\Local\{24DCE46A-F271-49C0-95BA-80D3704DA8F8}
2012-01-29 04:01:51 -------- d-----w- C:\Users\Asus\AppData\Local\{0E71D4F3-660F-46A6-B35D-BB50345F1A3E}
2012-01-27 17:08:46 -------- d-----w- C:\Users\Asus\AppData\Local\{FE045D66-437F-4FF6-BFF4-FFC07D119747}
2012-01-27 17:08:34 -------- d-----w- C:\Users\Asus\AppData\Local\{D6796BC2-CD49-4CD0-AFE6-053D6536B616}
2012-01-25 08:48:16 -------- d-----w- C:\Users\Asus\AppData\Local\{68BBD1F7-4A0F-4FB6-8FCA-A2A8201C98B1}
2012-01-25 08:48:03 -------- d-----w- C:\Users\Asus\AppData\Local\{D91F7664-395F-47CE-9621-A1DDF59E55C5}
2012-01-20 11:42:18 -------- d-----w- C:\Users\Asus\AppData\Local\{1C5A01A5-63EE-473C-8657-A58BE51AF6CA}
2012-01-20 11:42:05 -------- d-----w- C:\Users\Asus\AppData\Local\{D558A982-0517-4D2B-9F40-829ABBE8DBA6}
2012-01-19 03:01:56 -------- d-----w- C:\Users\Asus\AppData\Local\{E472A9A3-29C9-4C17-9A41-6ADBE8B7D5C1}
2012-01-19 03:01:43 -------- d-----w- C:\Users\Asus\AppData\Local\{B6B28B19-478D-4098-8554-43B56BF342FC}
2012-01-17 14:32:55 -------- d-----w- C:\Users\Asus\AppData\Local\{09D19D2A-7CD0-40B1-ADD3-581D99C0EBF6}
2012-01-17 14:32:42 -------- d-----w- C:\Users\Asus\AppData\Local\{50175454-F4A7-4498-99C7-99B14ED4AF26}
2012-01-16 15:01:11 -------- d-----w- C:\Windows\en
2012-01-16 14:59:57 -------- d-----w- C:\Windows\ar
2012-01-16 14:59:51 -------- d-----w- C:\Windows\es
2012-01-16 14:59:45 -------- d-----w- C:\Windows\fr
2012-01-16 14:59:40 -------- d-----w- C:\Windows\th
2012-01-16 14:59:35 -------- d-----w- C:\Windows\tr
2012-01-16 14:55:50 18328 ----a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-01-16 14:52:47 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\8323a0f31ccd45e02\MeshBetaRemover.exe
2012-01-16 14:50:19 -------- d-----w- C:\Users\Asus\AppData\Local\{8A8D34DE-4601-46BC-A6BD-C3F888F12A0D}
2012-01-16 14:50:07 -------- d-----w- C:\Users\Asus\AppData\Local\{589DA7BE-0263-4FB9-861D-A7AAE5D7FFAF}
2012-01-16 13:37:58 -------- d-----w- C:\Users\Asus\AppData\Local\{E5F2F281-DABE-4C10-B7C9-9EBDA480685E}
2012-01-16 13:37:43 -------- d-----w- C:\Users\Asus\AppData\Local\{CBE35672-F5C7-4D7D-80A0-CD404F7A1B50}
.
==================== Find3M ====================
.
2012-02-14 04:12:57 45056 ----a-w- C:\Windows\System32\acovcnt.exe
2012-01-26 16:52:58 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-01-08 15:30:45 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-06 12:04:28 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-01-06 02:51:15 80512 ----a-w- C:\Windows\ASUS K3 Series ScreenSaver Uninstaller.exe
2012-01-06 02:51:14 3058304 ----a-w- C:\Windows\AsScrPro.exe
2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-11-19 14:58:00 77312 ----a-w- C:\Windows\System32\packager.dll
2011-11-19 14:01:00 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2011-11-17 06:49:14 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2011-11-17 06:49:14 152432 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2011-11-17 06:44:43 459232 ----a-w- C:\Windows\System32\drivers\cng.sys
2011-11-17 06:41:18 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2011-11-17 06:35:28 395776 ----a-w- C:\Windows\System32\webio.dll
2011-11-17 06:35:26 29184 ----a-w- C:\Windows\System32\sspisrv.dll
2011-11-17 06:35:26 136192 ----a-w- C:\Windows\System32\sspicli.dll
2011-11-17 06:35:25 340992 ----a-w- C:\Windows\System32\schannel.dll
2011-11-17 06:35:25 28160 ----a-w- C:\Windows\System32\secur32.dll
2011-11-17 06:35:19 1447936 ----a-w- C:\Windows\System32\lsasrv.dll
2011-11-17 06:33:55 31232 ----a-w- C:\Windows\System32\lsass.exe
2011-11-17 05:38:39 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2011-11-17 05:35:02 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2011-11-17 05:34:52 224768 ----a-w- C:\Windows\SysWow64\schannel.dll
2011-11-17 05:34:52 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2011-11-17 05:28:48 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
.
============= FINISH: 12:22:51.53 ===============
Attach.txt
------------
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 1/6/2012 1:05:47 PM
System Uptime: 2/14/2012 12:12:23 PM (0 hours ago)
.
Motherboard: ASUSTeK Computer Inc. | | K43SJ
Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz | CPU 1 | 2401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 259 GiB total, 205.618 GiB free.
D: is FIXED (NTFS) - 312 GiB total, 308.544 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP34: 2/1/2012 12:27:45 AM - Windows Update
RP35: 2/8/2012 12:04:28 PM - Windows Update
RP37: 2/13/2012 8:12:25 PM - Removed Skype Click to Call
RP39: 2/13/2012 9:06:45 PM - Installed WinZip 16.0
RP40: 2/14/2012 11:23:23 AM - 2/11/2012
RP41: 2/14/2012 11:25:57 AM - Restore Operation
.
==== Installed Programs ======================
.
???? ??? Windows Live
???? ???? ActiveX ????? ?? Windows Live Mesh ????????? ???????
???? Windows Live
????????? ActiveX ?? Windows Live Mesh ????????????????????????? (???)
Adobe Flash Player 10 ActiveX
Apple Application Support
Apple Software Update
Asmedia ASM104x USB 3.0 Host Controller Driver
ASUS AI Recovery
ASUS FancyStart
ASUS K3 Series ScreenSaver
ASUS LifeFrame3
ASUS Live Update
ASUS SmartLogon
ASUS Splendid Video Enhancement Technology
ASUS Virtual Camera
ASUS WebStorage
AsusVibe2.0
Atheros Client Installation Program
ATK Package
Avira Free Antivirus
Bookworm Deluxe
Contr?le ActiveX Windows Live Mesh pour connexions à distance
Control ActiveX de Windows Live Mesh para conexiones remotas
Controle ActiveX do Windows Live Mesh para Conex?es Remotas
Cooking Dash
CyberLink LabelPrint
CyberLink Power2Go
D3DX10
Galería fotográfica de Windows Live
Galerie de photos Windows Live
Game Park Console
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Governor of Poker
Hotel Dash Suite Success
Java Auto Updater
Java(TM) 6 Update 22
Jewel Quest 3
Junk Mail filter update
Luxor 3
Mahjongg dimensions
Malwarebytes Anti-Malware version 1.60.1.1000
Mesh Runtime
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 10.0.1 (x86 en-US)
MSVCRT
MSVCRT_amd64
Nuance PDF Reader
NVIDIA Stereoscopic 3D Driver
OpenOffice.org 3.3
Plants vs Zombies
PPS影音 V2.7.0.1364 正式版
QQ音乐 2012
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Reader Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Skype? 5.8
Sonic Focus
syncables desktop SE
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Uzak Ba?lant?lar ??in Windows Live Mesh ActiveX Denetimi
Windows Live
Windows Live Communications Platform
Windows Live Essentials
Windows Live Foto?raf Galerisi
Windows Live Galeria de Fotos
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Temel Par?alar
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Live 影像中心
Windows Live 照片库
Windows Live 程式集
Windows Live 软件包
WinFlash
Wireless Console 3
World of Goo
用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文)
適用遠端連線的 Windows Live Mesh ActiveX 控制項
.
==== Event Viewer Messages From Past Week ========
.
2/14/2012 4:19:15 AM, Error: NetBT [4321] - The name "WORKGROUP :1d" could not be registered on the interface with IP address 10.84.2.188. The computer with the IP address 10.84.1.216 did not allow the name to be claimed by this computer.
2/14/2012 12:13:57 PM, Error: Application Popup [1060] - \??\C:\Users\Asus\AppData\Local\Temp\yugpufxg.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
.
==== End Of File ===========================