shinychrome0
Posts: 10 +0
i started trying to diagnose my internet problems here
https://www.techspot.com/vb/topic155505.html
and they think i have a virus causing issues on my system. I run AVG antivirus and it has not detected anything. So i also ran scans with Avast, Avira, and Kaspersky, and Kaspersy was the only one to detect anything. Here is the log from its scan.
Detected (2)
10/29/2010 8:50:52 PM Detected legal software that can be used by criminals for damaging your computer or personal data PDM.Invader (loader) C:\PROGRAM FILES (X86)\PRESONUS\STUDIO ONE\STUDIO ONE.EXE Low
10/30/2010 12:33:32 AM Detected legal software that can be used by criminals for damaging your computer or personal data PDM.Invader (loader)
C:\USERS\BRIAN CARRIGG\APPDATA\LOCAL\TEMP\IS-VIU15.TMP\SETUP_BUGBOPPER.TMP Low
Not found (1)
10/29/2010 9:23:46 PM Not found Trojan program Trojan-Dropper.Win32.VB.aopu C:\Documents and Settings\Brian Carrigg\Documents\Downloads\Programs\audio-converter-pack.exe//data0038 High
I'm not really sure why it picked up studio one as a virus.
MBAM did not detect anything.
And scratch that...AVG just found this but access was denied to remove it.
"";"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\AVP";"Found Adware.Generic";"Potentially dangerous object"
GMER log:
GMER 1.0.15.15477 - http://www.gmer.net
Rootkit scan 2010-10-31 15:11:16
Windows 6.1.7600
Running: pibmduhj.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250@0017d54ae696 0xAE 0x95 0xA2 0xC9 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250@002608d75365 0x66 0xEE 0x7F 0x50 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250@0017d54ae696 0xAE 0x95 0xA2 0xC9 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250@002608d75365 0x66 0xEE 0x7F 0x50 ...
---- EOF - GMER 1.0.15 ----
DDS log
DDS (Ver_10-10-31.01) - NTFS_AMD64
Run by Brian Carrigg at 15:12:42.20 on Sun 10/31/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.7935.5109 [GMT -4:00]
============== Running Processes ===============
C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\lxdxcoms.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxmon.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Nuance\NaturallySpeaking10\Program\natspeak.exe
C:\Program Files (x86)\Stardock\Impulse\Now\ImpulseNow.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking10\dgnuiasvr.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe
C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking10\dgnuiasvr_x64.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtblfs.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Brian Carrigg\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Bar = Preserve
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
uRun: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [BSDAppUpdater] C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SSBkgdUpdate] "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking10\Ereg.ini
mRun: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A
mRun: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
mRun: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
mRun: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"
mRunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\BRIANC~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DRAGON~1.LNK - C:\Program Files (x86)\Nuance\NaturallySpeaking10\Program\natspeak.exe
StartupFolder: C:\Users\BRIANC~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\IMPULS~1.LNK - C:\Program Files (x86)\Stardock\Impulse\Now\ImpulseNow.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
LSP: C:\Windows\system32\idmmbc.dll
Trusted Zone: ccuniversity.edu\www.my
Trusted Zone: line6.net
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll
BHO-X64: IEVkbdBHO - No File
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll
BHO-X64: link filter bho - No File
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [lxdxmon.exe] "C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxmon.exe"
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
================= FIREFOX ===================
FF - ProfilePath - C:\Users\BRIANC~1\AppData\Roaming\Mozilla\Firefox\Profiles\cawgg8ez.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?
FF - prefs.js: network.proxy.type - 4
FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - component: C:\Users\Brian Carrigg\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Brian Carrigg\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288]
R0 johci;JMicron 1394 Filter Driver;C:\Windows\System32\drivers\johci.sys [2009-7-28 20392]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-9-7 305232]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-9-7 381008]
R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736]
R1 VWiFiFlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/08/13 00:16:59];C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-3-13 146928]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2010/07/22 22:35:04];C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl [2010-1-12 146928]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-3-3 203264]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-10-11 6104656]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-9-10 265400]
R2 lxdx_device;lxdx_device;C:\Windows\system32\lxdxcoms.exe -service --> C:\Windows\system32\lxdxcoms.exe -service [?]
R2 regi;regi;C:\Windows\System32\drivers\regi.sys [2010-8-12 14112]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-8-4 7451648]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-8-4 268288]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-19 157264]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920]
R3 cxpl_mhd;CX23885/7 PCI-E AvStream Video Capture (PalomarMHD);C:\Windows\System32\drivers\y_cx88x.sys [2009-6-22 714752]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]
R3 RTL85n64;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;C:\Windows\System32\drivers\RTL85n64.sys [2010-3-23 2061856]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264]
S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-3 136176]
S3 L6PODLV;PODxt Live Service;C:\Windows\System32\drivers\L6PODLV64.sys [2010-9-7 770816]
S3 L6PODX3;L6 POD X3 Service;C:\Windows\System32\drivers\L6PODX364.sys [2010-3-9 894336]
S3 MADFUFTU8R;Service for M-Audio FastTrackUltra8R DFU;C:\Windows\System32\drivers\MAudioFastTrackUltra8R_DFU.sys [2009-10-6 45832]
S3 MAUSBFASTTRACK;Service for M-Audio FastTrack;C:\Windows\System32\drivers\MAudioFastTrack.sys [2009-10-2 187912]
S3 MAUSBFASTTRACKULTRA8R;Service for M-Audio Fast Track Ultra 8R;C:\Windows\System32\drivers\MAudioFastTrackUltra8R.sys [2009-10-6 195592]
S3 netr7364;Netopia RT73 Wireless Driver for Vista;C:\Windows\System32\drivers\netr7364.sys [2009-6-10 707072]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-6 1255736]
=============== Created Last 30 ================
2010-10-31 18:16:27 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\Malwarebytes
2010-10-31 18:16:18 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-10-31 18:16:17 24664 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-10-31 18:16:17 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-10-31 18:16:17 -------- d-----w- C:\PROGRA~3\Malwarebytes
2010-10-30 16:15:54 150200 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2010-10-29 21:15:53 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab
2010-10-29 21:15:53 -------- d-----w- C:\PROGRA~3\Kaspersky Lab
2010-10-29 21:14:50 -------- d-----w- C:\PROGRA~3\Alwil Software
2010-10-29 21:13:06 -------- d-----w- C:\PROGRA~3\Kaspersky Lab Setup Files
2010-10-26 19:34:45 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2010-10-26 19:34:45 641536 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2010-10-26 19:34:45 552960 ----a-w- C:\Windows\System32\msdri.dll
2010-10-26 19:34:45 288256 ----a-w- C:\Windows\System32\MSNP.ax
2010-10-26 19:34:45 258560 ----a-w- C:\Windows\System32\mpg2splt.ax
2010-10-26 19:34:45 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2010-10-26 19:34:45 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2010-10-26 19:34:40 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2010-10-26 02:22:15 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\OpenDNS Updater
2010-10-25 01:32:30 -------- d-----w- C:\Program Files (x86)\Auto Clicker
2010-10-25 01:26:57 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\GetRightToGo
2010-10-25 00:04:57 679936 ----a-w- C:\Windows\SysWow64\D3DX81ab.dll
2010-10-25 00:04:57 1970176 ----a-w- C:\Windows\SysWow64\d3dx9.dll
2010-10-25 00:04:57 -------- d-----w- C:\Program Files (x86)\Cheat Engine
2010-10-22 09:00:31 8006480 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{2BE0D37A-5F07-4ADF-802B-5778F4AE2DCF}\mpengine.dll
2010-10-15 20:07:55 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\ChaosPro 4.0
2010-10-14 17:10:13 148992 ----a-w- C:\Windows\System32\t2embed.dll
2010-10-14 17:09:43 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2010-10-14 17:09:43 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2010-10-14 17:09:42 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2010-10-14 17:09:42 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-10-14 17:09:40 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-10-14 17:09:40 463360 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-10-14 17:09:40 402944 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-10-14 17:09:40 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2010-10-14 17:09:40 161792 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-10-14 17:09:38 3123712 ----a-w- C:\Windows\System32\win32k.sys
2010-10-14 16:57:24 -------- d-----w- C:\PROGRA~3\Comodo
2010-10-14 16:39:26 -------- d-----w- C:\PROGRA~3\BugBopper
2010-10-14 04:41:09 -------- d-----w- C:\audio-power-settings
2010-10-13 12:42:57 -------- d-----w- C:\Program Files\PreSonus
2010-10-13 02:35:21 -------- d-----w- C:\Program Files (x86)\ASIO4ALL v2
2010-10-13 01:24:00 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\MakeMusic
2010-10-13 01:22:54 -------- d-----w- C:\Program Files (x86)\Finale NotePad 2011
2010-10-13 01:22:54 -------- d-----w- C:\PROGRA~3\MakeMusic
2010-10-13 00:53:42 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\AVG10
2010-10-13 00:49:49 -------- d--h--w- C:\PROGRA~3\Common Files
2010-10-13 00:48:42 -------- d-----w- C:\Windows\System32\drivers\AVG
2010-10-13 00:48:42 -------- d-----w- C:\PROGRA~3\AVG10
2010-10-13 00:38:27 -------- d-----w- C:\PROGRA~3\MFAData
2010-10-13 00:35:53 -------- d-----w- C:\Program Files\iPod
2010-10-13 00:35:52 -------- d-----w- C:\Program Files\iTunes
2010-10-13 00:35:52 -------- d-----w- C:\Program Files (x86)\iTunes
2010-10-13 00:33:49 -------- d-----w- C:\Program Files\Bonjour
2010-10-13 00:33:49 -------- d-----w- C:\Program Files (x86)\Bonjour
==================== Find3M ====================
2010-10-19 15:41:44 270720 ------w- C:\Windows\System32\MpSigStub.exe
2010-10-13 18:58:06 1139200 ----a-w- C:\Windows\bsdsetup.dll
2010-09-29 18:31:28 210272 ----a-w- C:\Windows\SysWow64\idmmbc.dll
2010-09-13 20:28:00 27216 ----a-w- C:\Windows\System32\drivers\AVGIDSEH.sys
2010-09-13 02:38:03 737280 ----a-w- C:\Windows\iun6002.exe
2010-09-10 05:35:44 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-09-10 05:35:43 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-09-08 15:17:46 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2010-09-08 15:17:46 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2010-09-08 05:36:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 05:34:34 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2010-09-08 04:30:04 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38 482816 ----a-w- C:\Windows\System32\html.iec
2010-09-08 03:35:30 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2010-09-08 03:22:31 386048 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-08 02:48:16 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-09-07 22:45:04 770816 ----a-w- C:\Windows\System32\drivers\L6PODLV64.sys
2010-09-07 22:45:02 218112 ----a-w- C:\Windows\System32\l6podlv_x64.dll
2010-09-07 22:45:02 180224 ----a-w- C:\Windows\SysWow64\l6podlv.dll
2010-09-07 07:48:58 381008 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2010-09-07 07:48:56 41040 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
2010-09-07 07:48:52 305232 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
2010-09-07 07:48:50 30288 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
2010-08-31 04:32:30 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-08-26 04:39:58 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-08-21 06:38:47 1024512 ----a-w- C:\Windows\System32\wmpmde.dll
2010-08-21 06:36:49 340992 ----a-w- C:\Windows\System32\schannel.dll
2010-08-21 06:31:06 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-08-21 06:29:47 558592 ----a-w- C:\Windows\System32\spoolsv.exe
2010-08-21 05:36:33 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-08-21 05:36:24 224256 ----a-w- C:\Windows\SysWow64\schannel.dll
2010-08-21 05:33:24 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2010-08-20 01:42:38 35920 ----a-w- C:\Windows\System32\drivers\AVGIDSFilter.sys
2010-08-20 01:42:38 157264 ----a-w- C:\Windows\System32\drivers\AVGIDSDriver.sys
2010-08-13 04:15:23 505128 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2010-08-13 04:15:23 29480 ----a-w- C:\Windows\SysWow64\msxml3a.dll
2010-08-13 03:17:16 2828 --sha-w- C:\PROGRA~3\KGyGaAvL.sys
2010-08-13 03:17:00 88 --sh--r- C:\PROGRA~3\CA9AFEA1AF.sys
2010-08-11 15:17:57 368640 ----a-w- C:\Windows\SysWow64\ReWire.dll
2010-08-11 15:17:57 233472 ----a-w- C:\Windows\SysWow64\REX Shared Library.dll
2010-08-04 06:22:38 7451648 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2010-08-04 06:07:14 20817408 ----a-w- C:\Windows\System32\atio6axx.dll
2010-08-04 05:55:02 143360 ----a-w- C:\Windows\System32\atiapfxx.exe
2010-08-04 05:54:52 519680 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2010-08-04 05:54:02 598528 ----a-w- C:\Windows\System32\aticfx64.dll
2010-08-04 05:52:06 450560 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2010-08-04 05:51:56 461824 ----a-w- C:\Windows\System32\atieclxx.exe
2010-08-04 05:51:22 203264 ----a-w- C:\Windows\System32\atiesrxx.exe
2010-08-04 05:50:16 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2010-08-04 05:49:58 421376 ----a-w- C:\Windows\System32\atipdl64.dll
2010-08-04 05:49:52 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2010-08-04 05:49:50 15845888 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2010-08-04 05:49:42 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2010-08-04 05:49:38 12288 ----a-w- C:\Windows\System32\atimuixx.dll
2010-08-04 05:49:34 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2010-08-04 05:49:28 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2010-08-04 05:46:34 3899392 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2010-08-04 05:37:48 4554240 ----a-w- C:\Windows\System32\atidxx64.dll
2010-08-04 05:28:32 3077120 ----a-w- C:\Windows\System32\atiumd6a.dll
2010-08-04 05:28:28 4021760 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2010-08-04 05:26:04 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2010-08-04 05:26:02 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2010-08-04 05:25:56 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2010-08-04 05:25:52 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2010-08-04 05:25:44 5394432 ----a-w- C:\Windows\System32\aticaldd64.dll
2010-08-04 05:24:36 4341248 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2010-08-04 05:23:46 56832 ----a-w- C:\Windows\System32\coinst.dll
2010-08-04 05:22:36 5167104 ----a-w- C:\Windows\System32\atiumd64.dll
2010-08-04 05:21:40 3324416 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2010-08-04 05:16:16 337920 ----a-w- C:\Windows\System32\atiadlxx.dll
2010-08-04 05:16:08 241664 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2010-08-04 05:16:00 14848 ----a-w- C:\Windows\System32\atig6pxx.dll
2010-08-04 05:15:56 12800 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2010-08-04 05:15:56 12800 ----a-w- C:\Windows\System32\atiglpxx.dll
2010-08-04 05:15:54 18432 ----a-w- C:\Windows\System32\atig6txx.dll
2010-08-04 05:15:50 16896 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2010-08-04 05:15:46 268288 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2010-08-04 05:15:10 39424 ----a-w- C:\Windows\System32\atiuxp64.dll
2010-08-04 05:15:04 30208 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2010-08-04 05:14:58 36864 ----a-w- C:\Windows\System32\atiu9p64.dll
2010-08-04 05:14:50 27648 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2010-08-04 05:14:14 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2010-08-04 05:09:30 54784 ----a-w- C:\Windows\System32\atimpc64.dll
2010-08-04 05:09:30 54784 ----a-w- C:\Windows\System32\amdpcom64.dll
2010-08-04 05:09:24 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2010-08-04 05:09:24 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2010-08-04 05:04:04 1071104 ----a-w- C:\Windows\System32\L6DriverControlPanel.cpl
============= FINISH: 15:13:12.64 ===============
https://www.techspot.com/vb/topic155505.html
and they think i have a virus causing issues on my system. I run AVG antivirus and it has not detected anything. So i also ran scans with Avast, Avira, and Kaspersky, and Kaspersy was the only one to detect anything. Here is the log from its scan.
Detected (2)
10/29/2010 8:50:52 PM Detected legal software that can be used by criminals for damaging your computer or personal data PDM.Invader (loader) C:\PROGRAM FILES (X86)\PRESONUS\STUDIO ONE\STUDIO ONE.EXE Low
10/30/2010 12:33:32 AM Detected legal software that can be used by criminals for damaging your computer or personal data PDM.Invader (loader)
C:\USERS\BRIAN CARRIGG\APPDATA\LOCAL\TEMP\IS-VIU15.TMP\SETUP_BUGBOPPER.TMP Low
Not found (1)
10/29/2010 9:23:46 PM Not found Trojan program Trojan-Dropper.Win32.VB.aopu C:\Documents and Settings\Brian Carrigg\Documents\Downloads\Programs\audio-converter-pack.exe//data0038 High
I'm not really sure why it picked up studio one as a virus.
MBAM did not detect anything.
And scratch that...AVG just found this but access was denied to remove it.
"";"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\AVP";"Found Adware.Generic";"Potentially dangerous object"
GMER log:
GMER 1.0.15.15477 - http://www.gmer.net
Rootkit scan 2010-10-31 15:11:16
Windows 6.1.7600
Running: pibmduhj.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250@0017d54ae696 0xAE 0x95 0xA2 0xC9 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250@002608d75365 0x66 0xEE 0x7F 0x50 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250@0017d54ae696 0xAE 0x95 0xA2 0xC9 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250@002608d75365 0x66 0xEE 0x7F 0x50 ...
---- EOF - GMER 1.0.15 ----
DDS log
DDS (Ver_10-10-31.01) - NTFS_AMD64
Run by Brian Carrigg at 15:12:42.20 on Sun 10/31/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.7935.5109 [GMT -4:00]
============== Running Processes ===============
C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\lxdxcoms.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxmon.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Nuance\NaturallySpeaking10\Program\natspeak.exe
C:\Program Files (x86)\Stardock\Impulse\Now\ImpulseNow.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking10\dgnuiasvr.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe
C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking10\dgnuiasvr_x64.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtblfs.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Brian Carrigg\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Bar = Preserve
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
uRun: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
uRun: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [BSDAppUpdater] C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SSBkgdUpdate] "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun: [DNS7reminder] "C:\Program Files (x86)\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking10\Ereg.ini
mRun: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A
mRun: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
mRun: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
mRun: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe"
mRunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\BRIANC~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DRAGON~1.LNK - C:\Program Files (x86)\Nuance\NaturallySpeaking10\Program\natspeak.exe
StartupFolder: C:\Users\BRIANC~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\IMPULS~1.LNK - C:\Program Files (x86)\Stardock\Impulse\Now\ImpulseNow.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
LSP: C:\Windows\system32\idmmbc.dll
Trusted Zone: ccuniversity.edu\www.my
Trusted Zone: line6.net
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll
BHO-X64: IEVkbdBHO - No File
BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll
BHO-X64: link filter bho - No File
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [lxdxmon.exe] "C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxmon.exe"
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
================= FIREFOX ===================
FF - ProfilePath - C:\Users\BRIANC~1\AppData\Roaming\Mozilla\Firefox\Profiles\cawgg8ez.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?
FF - prefs.js: network.proxy.type - 4
FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - component: C:\Users\Brian Carrigg\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Brian Carrigg\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288]
R0 johci;JMicron 1394 Filter Driver;C:\Windows\System32\drivers\johci.sys [2009-7-28 20392]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-9-7 305232]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-9-7 381008]
R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736]
R1 VWiFiFlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/08/13 00:16:59];C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-3-13 146928]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2010/07/22 22:35:04];C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl [2010-1-12 146928]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-3-3 203264]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-10-11 6104656]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-9-10 265400]
R2 lxdx_device;lxdx_device;C:\Windows\system32\lxdxcoms.exe -service --> C:\Windows\system32\lxdxcoms.exe -service [?]
R2 regi;regi;C:\Windows\System32\drivers\regi.sys [2010-8-12 14112]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-8-4 7451648]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-8-4 268288]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-19 157264]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920]
R3 cxpl_mhd;CX23885/7 PCI-E AvStream Video Capture (PalomarMHD);C:\Windows\System32\drivers\y_cx88x.sys [2009-6-22 714752]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]
R3 RTL85n64;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;C:\Windows\System32\drivers\RTL85n64.sys [2010-3-23 2061856]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264]
S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-3 136176]
S3 L6PODLV;PODxt Live Service;C:\Windows\System32\drivers\L6PODLV64.sys [2010-9-7 770816]
S3 L6PODX3;L6 POD X3 Service;C:\Windows\System32\drivers\L6PODX364.sys [2010-3-9 894336]
S3 MADFUFTU8R;Service for M-Audio FastTrackUltra8R DFU;C:\Windows\System32\drivers\MAudioFastTrackUltra8R_DFU.sys [2009-10-6 45832]
S3 MAUSBFASTTRACK;Service for M-Audio FastTrack;C:\Windows\System32\drivers\MAudioFastTrack.sys [2009-10-2 187912]
S3 MAUSBFASTTRACKULTRA8R;Service for M-Audio Fast Track Ultra 8R;C:\Windows\System32\drivers\MAudioFastTrackUltra8R.sys [2009-10-6 195592]
S3 netr7364;Netopia RT73 Wireless Driver for Vista;C:\Windows\System32\drivers\netr7364.sys [2009-6-10 707072]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-6 1255736]
=============== Created Last 30 ================
2010-10-31 18:16:27 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\Malwarebytes
2010-10-31 18:16:18 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-10-31 18:16:17 24664 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-10-31 18:16:17 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-10-31 18:16:17 -------- d-----w- C:\PROGRA~3\Malwarebytes
2010-10-30 16:15:54 150200 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2010-10-29 21:15:53 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab
2010-10-29 21:15:53 -------- d-----w- C:\PROGRA~3\Kaspersky Lab
2010-10-29 21:14:50 -------- d-----w- C:\PROGRA~3\Alwil Software
2010-10-29 21:13:06 -------- d-----w- C:\PROGRA~3\Kaspersky Lab Setup Files
2010-10-26 19:34:45 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2010-10-26 19:34:45 641536 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2010-10-26 19:34:45 552960 ----a-w- C:\Windows\System32\msdri.dll
2010-10-26 19:34:45 288256 ----a-w- C:\Windows\System32\MSNP.ax
2010-10-26 19:34:45 258560 ----a-w- C:\Windows\System32\mpg2splt.ax
2010-10-26 19:34:45 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2010-10-26 19:34:45 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2010-10-26 19:34:40 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2010-10-26 02:22:15 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\OpenDNS Updater
2010-10-25 01:32:30 -------- d-----w- C:\Program Files (x86)\Auto Clicker
2010-10-25 01:26:57 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\GetRightToGo
2010-10-25 00:04:57 679936 ----a-w- C:\Windows\SysWow64\D3DX81ab.dll
2010-10-25 00:04:57 1970176 ----a-w- C:\Windows\SysWow64\d3dx9.dll
2010-10-25 00:04:57 -------- d-----w- C:\Program Files (x86)\Cheat Engine
2010-10-22 09:00:31 8006480 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{2BE0D37A-5F07-4ADF-802B-5778F4AE2DCF}\mpengine.dll
2010-10-15 20:07:55 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\ChaosPro 4.0
2010-10-14 17:10:13 148992 ----a-w- C:\Windows\System32\t2embed.dll
2010-10-14 17:09:43 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2010-10-14 17:09:43 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2010-10-14 17:09:42 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2010-10-14 17:09:42 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-10-14 17:09:40 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2010-10-14 17:09:40 463360 ----a-w- C:\Windows\System32\drivers\srv.sys
2010-10-14 17:09:40 402944 ----a-w- C:\Windows\System32\drivers\srv2.sys
2010-10-14 17:09:40 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2010-10-14 17:09:40 161792 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2010-10-14 17:09:38 3123712 ----a-w- C:\Windows\System32\win32k.sys
2010-10-14 16:57:24 -------- d-----w- C:\PROGRA~3\Comodo
2010-10-14 16:39:26 -------- d-----w- C:\PROGRA~3\BugBopper
2010-10-14 04:41:09 -------- d-----w- C:\audio-power-settings
2010-10-13 12:42:57 -------- d-----w- C:\Program Files\PreSonus
2010-10-13 02:35:21 -------- d-----w- C:\Program Files (x86)\ASIO4ALL v2
2010-10-13 01:24:00 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\MakeMusic
2010-10-13 01:22:54 -------- d-----w- C:\Program Files (x86)\Finale NotePad 2011
2010-10-13 01:22:54 -------- d-----w- C:\PROGRA~3\MakeMusic
2010-10-13 00:53:42 -------- d-----w- C:\Users\BRIANC~1\AppData\Roaming\AVG10
2010-10-13 00:49:49 -------- d--h--w- C:\PROGRA~3\Common Files
2010-10-13 00:48:42 -------- d-----w- C:\Windows\System32\drivers\AVG
2010-10-13 00:48:42 -------- d-----w- C:\PROGRA~3\AVG10
2010-10-13 00:38:27 -------- d-----w- C:\PROGRA~3\MFAData
2010-10-13 00:35:53 -------- d-----w- C:\Program Files\iPod
2010-10-13 00:35:52 -------- d-----w- C:\Program Files\iTunes
2010-10-13 00:35:52 -------- d-----w- C:\Program Files (x86)\iTunes
2010-10-13 00:33:49 -------- d-----w- C:\Program Files\Bonjour
2010-10-13 00:33:49 -------- d-----w- C:\Program Files (x86)\Bonjour
==================== Find3M ====================
2010-10-19 15:41:44 270720 ------w- C:\Windows\System32\MpSigStub.exe
2010-10-13 18:58:06 1139200 ----a-w- C:\Windows\bsdsetup.dll
2010-09-29 18:31:28 210272 ----a-w- C:\Windows\SysWow64\idmmbc.dll
2010-09-13 20:28:00 27216 ----a-w- C:\Windows\System32\drivers\AVGIDSEH.sys
2010-09-13 02:38:03 737280 ----a-w- C:\Windows\iun6002.exe
2010-09-10 05:35:44 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-09-10 05:35:43 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-09-08 15:17:46 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2010-09-08 15:17:46 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2010-09-08 05:36:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 05:34:34 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2010-09-08 04:30:04 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38 482816 ----a-w- C:\Windows\System32\html.iec
2010-09-08 03:35:30 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2010-09-08 03:22:31 386048 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-08 02:48:16 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-09-07 22:45:04 770816 ----a-w- C:\Windows\System32\drivers\L6PODLV64.sys
2010-09-07 22:45:02 218112 ----a-w- C:\Windows\System32\l6podlv_x64.dll
2010-09-07 22:45:02 180224 ----a-w- C:\Windows\SysWow64\l6podlv.dll
2010-09-07 07:48:58 381008 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2010-09-07 07:48:56 41040 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
2010-09-07 07:48:52 305232 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
2010-09-07 07:48:50 30288 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
2010-08-31 04:32:30 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2010-08-26 04:39:58 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll
2010-08-21 06:38:47 1024512 ----a-w- C:\Windows\System32\wmpmde.dll
2010-08-21 06:36:49 340992 ----a-w- C:\Windows\System32\schannel.dll
2010-08-21 06:31:06 633856 ----a-w- C:\Windows\System32\comctl32.dll
2010-08-21 06:29:47 558592 ----a-w- C:\Windows\System32\spoolsv.exe
2010-08-21 05:36:33 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-08-21 05:36:24 224256 ----a-w- C:\Windows\SysWow64\schannel.dll
2010-08-21 05:33:24 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
2010-08-20 01:42:38 35920 ----a-w- C:\Windows\System32\drivers\AVGIDSFilter.sys
2010-08-20 01:42:38 157264 ----a-w- C:\Windows\System32\drivers\AVGIDSDriver.sys
2010-08-13 04:15:23 505128 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2010-08-13 04:15:23 29480 ----a-w- C:\Windows\SysWow64\msxml3a.dll
2010-08-13 03:17:16 2828 --sha-w- C:\PROGRA~3\KGyGaAvL.sys
2010-08-13 03:17:00 88 --sh--r- C:\PROGRA~3\CA9AFEA1AF.sys
2010-08-11 15:17:57 368640 ----a-w- C:\Windows\SysWow64\ReWire.dll
2010-08-11 15:17:57 233472 ----a-w- C:\Windows\SysWow64\REX Shared Library.dll
2010-08-04 06:22:38 7451648 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2010-08-04 06:07:14 20817408 ----a-w- C:\Windows\System32\atio6axx.dll
2010-08-04 05:55:02 143360 ----a-w- C:\Windows\System32\atiapfxx.exe
2010-08-04 05:54:52 519680 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2010-08-04 05:54:02 598528 ----a-w- C:\Windows\System32\aticfx64.dll
2010-08-04 05:52:06 450560 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2010-08-04 05:51:56 461824 ----a-w- C:\Windows\System32\atieclxx.exe
2010-08-04 05:51:22 203264 ----a-w- C:\Windows\System32\atiesrxx.exe
2010-08-04 05:50:16 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2010-08-04 05:49:58 421376 ----a-w- C:\Windows\System32\atipdl64.dll
2010-08-04 05:49:52 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2010-08-04 05:49:50 15845888 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2010-08-04 05:49:42 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2010-08-04 05:49:38 12288 ----a-w- C:\Windows\System32\atimuixx.dll
2010-08-04 05:49:34 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2010-08-04 05:49:28 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2010-08-04 05:46:34 3899392 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2010-08-04 05:37:48 4554240 ----a-w- C:\Windows\System32\atidxx64.dll
2010-08-04 05:28:32 3077120 ----a-w- C:\Windows\System32\atiumd6a.dll
2010-08-04 05:28:28 4021760 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2010-08-04 05:26:04 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2010-08-04 05:26:02 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2010-08-04 05:25:56 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2010-08-04 05:25:52 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2010-08-04 05:25:44 5394432 ----a-w- C:\Windows\System32\aticaldd64.dll
2010-08-04 05:24:36 4341248 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2010-08-04 05:23:46 56832 ----a-w- C:\Windows\System32\coinst.dll
2010-08-04 05:22:36 5167104 ----a-w- C:\Windows\System32\atiumd64.dll
2010-08-04 05:21:40 3324416 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2010-08-04 05:16:16 337920 ----a-w- C:\Windows\System32\atiadlxx.dll
2010-08-04 05:16:08 241664 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2010-08-04 05:16:00 14848 ----a-w- C:\Windows\System32\atig6pxx.dll
2010-08-04 05:15:56 12800 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2010-08-04 05:15:56 12800 ----a-w- C:\Windows\System32\atiglpxx.dll
2010-08-04 05:15:54 18432 ----a-w- C:\Windows\System32\atig6txx.dll
2010-08-04 05:15:50 16896 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2010-08-04 05:15:46 268288 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2010-08-04 05:15:10 39424 ----a-w- C:\Windows\System32\atiuxp64.dll
2010-08-04 05:15:04 30208 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2010-08-04 05:14:58 36864 ----a-w- C:\Windows\System32\atiu9p64.dll
2010-08-04 05:14:50 27648 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2010-08-04 05:14:14 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2010-08-04 05:09:30 54784 ----a-w- C:\Windows\System32\atimpc64.dll
2010-08-04 05:09:30 54784 ----a-w- C:\Windows\System32\amdpcom64.dll
2010-08-04 05:09:24 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2010-08-04 05:09:24 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2010-08-04 05:04:04 1071104 ----a-w- C:\Windows\System32\L6DriverControlPanel.cpl
============= FINISH: 15:13:12.64 ===============