Hello,
I'm working on my nephew's HP Pavilion dv6700 laptop running Windows Vista Home Premium. Intermittently, he is unable to access the internet (is connected, but IE says there's no connection/doesn't display any pages). He's been doing system restores to work around this.
Yesterday, I was not able to access the internet via IE. I ran Avira free antivirus scan and an MBAM scan. It appeared to detect and quarantine several viruses/malware. Today I was able to access the internet via IE. I updated both applications and scanned again. I'd appreciate it if someone could review the results of the scans as outlined in the 8 steps post to make sure the computer is virus/malware free now. Following are the log files.
Thanks for your help!
Chris B.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6043
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019
3/13/2011 4:49:38 PM
mbam-log-2011-03-13 (16-49-38).txt
Scan type: Quick scan
Objects scanned: 153613
Time elapsed: 5 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-03-13 17:14:28
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 ST9200827AS rev.3.BHA
Running: kzdiecp2.exe; Driver: C:\Users\Travis\AppData\Local\Temp\pwryipob.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Travis at 17:21:34.58 on Sun 03/13/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.1990 [GMT -5:00]
.
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Travis\Desktop\Travis\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
============= SERVICES / DRIVERS ===============
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-3-12 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-3-12 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-3-12 61960]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-03-12 19:20:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-12 19:20:04 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-12 19:14:54 -------- d-----w- c:\users\travis\appdata\roaming\Avira
2011-03-12 19:12:20 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-03-12 19:12:18 -------- d-----w- c:\program files\Avira
2011-03-12 19:12:18 -------- d-----w- c:\progra~2\Avira
2011-03-10 20:40:49 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-03-10 20:40:01 304128 ----a-w- c:\windows\system32\drivers\srv.sys
2011-03-10 20:40:01 17920 ----a-w- c:\windows\system32\netevent.dll
2011-03-10 20:40:00 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-03-10 20:40:00 125952 ----a-w- c:\windows\system32\srvsvc.dll
2011-03-10 20:40:00 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-03-10 20:39:07 66048 ----a-w- c:\program files\windows mail\wabmig.exe
2011-03-10 20:39:07 515584 ----a-w- c:\program files\windows mail\wab.exe
2011-03-10 20:39:07 33280 ----a-w- c:\program files\windows mail\wabfind.dll
2011-03-10 20:37:07 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-03-10 20:37:07 57344 ----a-w- c:\program files\common files\system\msadc\msadcs.dll
2011-03-10 20:37:07 253952 ----a-w- c:\program files\common files\system\ado\msadox.dll
2011-03-10 20:37:07 241664 ----a-w- c:\program files\common files\system\ado\msadomd.dll
2011-03-10 20:37:07 180224 ----a-w- c:\program files\common files\system\msadc\msadco.dll
2011-03-10 20:36:42 2039808 ----a-w- c:\windows\system32\win32k.sys
2011-03-10 20:36:16 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-03-10 20:36:15 3602320 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-03-10 20:35:49 1616384 ----a-w- c:\program files\windows mail\msoe.dll
2011-03-10 20:35:25 81920 ----a-w- c:\windows\system32\iccvid.dll
2011-03-10 20:33:39 420352 ----a-w- c:\windows\system32\vbscript.dll
2011-03-10 20:33:16 67072 ----a-w- c:\windows\system32\asycfilt.dll
2011-03-10 20:32:52 339968 ----a-w- c:\program files\windows nt\accessories\wordpad.exe
2011-03-10 20:31:50 128000 ----a-w- c:\windows\system32\spoolsv.exe
2011-03-10 20:31:26 157184 ----a-w- c:\windows\system32\t2embed.dll
2011-03-10 20:30:15 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-03-10 20:28:49 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe
2011-03-10 20:28:47 10926592 ----a-w- c:\program files\movie maker\MOVIEMK.dll
2011-03-10 20:27:54 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-03-10 20:27:53 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-03-10 20:27:53 1696256 ----a-w- c:\windows\system32\gameux.dll
2011-03-10 20:27:30 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2011-03-10 20:25:28 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-03-10 20:25:27 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-03-10 20:21:20 62464 ----a-w- c:\windows\system32\l3codeca.acm
2011-03-10 20:21:20 220672 ----a-w- c:\windows\system32\l3codecp.acm
2011-03-10 15:12:14 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-03-10 15:12:14 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-03-10 15:12:14 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-03-10 15:12:14 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-03-10 15:12:14 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-03-10 15:10:16 601600 ----a-w- c:\windows\system32\schedsvc.dll
2011-03-10 15:10:16 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-03-10 15:10:16 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-03-10 15:10:16 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-03-10 15:10:07 81920 ----a-w- c:\windows\system32\consent.exe
2011-03-10 15:09:20 2048 ----a-w- c:\windows\system32\tzres.dll
2011-03-10 15:08:46 72704 ----a-w- c:\windows\system32\fontsub.dll
2011-03-10 15:08:46 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-03-10 15:08:46 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-03-10 15:07:10 24064 ----a-w- c:\windows\system32\nshhttp.dll
2011-03-10 15:07:08 411648 ----a-w- c:\windows\system32\drivers\http.sys
2011-03-10 15:06:56 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-03-10 15:06:50 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-10 15:05:17 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-03-09 22:08:32 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-03-09 22:08:20 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-03-09 22:08:19 322560 ----a-w- c:\windows\system32\sbe.dll
2011-03-09 22:08:19 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-09 22:08:19 153088 ----a-w- c:\windows\system32\sbeio.dll
2011-03-09 22:08:17 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-03-09 22:08:17 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-03-09 17:01:55 98304 ----a-w- c:\windows\system32\cabview.dll
2011-03-04 04:24:26 247808 ----a-w- c:\windows\system32\shsvcs(1482).dll
.
==================== Find3M ====================
.
2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(967).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(625).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(625)(966).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(625)(1329).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(615).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(615)(1327).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(460).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(460)(965).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(460)(1326).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(1331).dll
2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(973).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(629).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(629)(972).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(629)(1339).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(619).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(619)(1337).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(464).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(464)(971).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(464)(1336).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(1341).dll
2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 ----a-w- c:\windows\system32\FntCache.dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(648).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(413).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1073).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1073)(647).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1073)(412).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1073)(1003).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1004).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(722).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(722)(1570).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(722)(1080).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(712).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(712)(1568).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(556).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(556)(1566).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(556)(1079).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(1574).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(1082).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(706).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(706)(1524).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(706)(1056).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(696).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(696)(1522).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(540).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(540)(1520).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(540)(1055).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(1528).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(1058).dll
2010-12-18 05:25:26 385024 ----a-w- c:\windows\system32\html.iec
2010-12-18 04:48:39 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-12-18 04:47:11 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 17:22:03.54 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 2/3/2009 1:34:00 PM
System Uptime: 3/13/2011 4:38:58 PM (1 hours ago)
.
Motherboard: Quanta | | 30CF
Processor: AMD Turion(tm) 64 X2 Mobile Technology TL-60 | Socket S1 | 1800/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 175 GiB total, 112.432 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 2.016 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.0
Adobe Shockwave Player
AIM 6
Atheros Driver Installation Program
Avira AntiVir Personal - Free Antivirus
BlackBerry Desktop Software 4.3
Cards_Calendar_OrderGift_DoMorePlugout
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CyberLink YouCam
Driver Detective
DVD Suite
EA Link
GEAR driver installer for x86 and x64
Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
HDAUDIO Soft Data Fax Modem with SmartCP
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Easy Setup - Frontend
HP Help and Support
HP Photosmart Essential 2.5
HP Quick Launch Buttons 6.30 E1
HP QuickPlay 3.6
HP QuickTouch 1.00 C4
HP Smart Web Printing
HP Total Care Advisor
HP Update
HP User Guides 0087
HP Wireless Assistant
HPNetworkAssistant
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabel_Tattoo
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookHolidayPack1
HPPhotoSmartPhotobookModernPack1
HPPhotoSmartPhotobookPlayfulPack1
HPPhotoSmartPhotobookScrapbookPack1
HPPhotoSmartPhotobookWebPack1
Java(TM) 6 Update 13
Java(TM) 6 Update 2
Junk Mail filter update
LabelPrint
LightScribe System Software 1.10.13.1
Malwarebytes' Anti-Malware
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
My HP Games
NetWaiting
NVIDIA Drivers
OGA Notifier 2.0.0048.0
Power2Go
PowerDirector
PSSWCORE
QuickPlay SlingPlayer 0.4.6
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
Roxio Media Manager
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Slingbox Flash Tour
SlingPlayer
Synaptics Pointing Device Driver
The Sims™ Life Stories
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VideoToolkit01
Viewpoint Media Player
WeatherBug Gadget
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
.
==== End Of File ===========================
I'm working on my nephew's HP Pavilion dv6700 laptop running Windows Vista Home Premium. Intermittently, he is unable to access the internet (is connected, but IE says there's no connection/doesn't display any pages). He's been doing system restores to work around this.
Yesterday, I was not able to access the internet via IE. I ran Avira free antivirus scan and an MBAM scan. It appeared to detect and quarantine several viruses/malware. Today I was able to access the internet via IE. I updated both applications and scanned again. I'd appreciate it if someone could review the results of the scans as outlined in the 8 steps post to make sure the computer is virus/malware free now. Following are the log files.
Thanks for your help!
Chris B.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6043
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019
3/13/2011 4:49:38 PM
mbam-log-2011-03-13 (16-49-38).txt
Scan type: Quick scan
Objects scanned: 153613
Time elapsed: 5 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-03-13 17:14:28
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 ST9200827AS rev.3.BHA
Running: kzdiecp2.exe; Driver: C:\Users\Travis\AppData\Local\Temp\pwryipob.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Travis at 17:21:34.58 on Sun 03/13/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.1990 [GMT -5:00]
.
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Travis\Desktop\Travis\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Print Clips: {ffffffff-ff12-44c5-91ec-068e3aa1b2d7} - c:\program files\hp\smart web printing\hpswp_framework.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\1.0"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [WAWifiMessage] c:\program files\hewlett-packard\hp wireless assistant\WiFiMsg.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
============= SERVICES / DRIVERS ===============
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-3-12 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-3-12 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-3-12 61960]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-03-12 19:20:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-12 19:20:04 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-12 19:14:54 -------- d-----w- c:\users\travis\appdata\roaming\Avira
2011-03-12 19:12:20 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-03-12 19:12:18 -------- d-----w- c:\program files\Avira
2011-03-12 19:12:18 -------- d-----w- c:\progra~2\Avira
2011-03-10 20:40:49 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-03-10 20:40:01 304128 ----a-w- c:\windows\system32\drivers\srv.sys
2011-03-10 20:40:01 17920 ----a-w- c:\windows\system32\netevent.dll
2011-03-10 20:40:00 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-03-10 20:40:00 125952 ----a-w- c:\windows\system32\srvsvc.dll
2011-03-10 20:40:00 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-03-10 20:39:07 66048 ----a-w- c:\program files\windows mail\wabmig.exe
2011-03-10 20:39:07 515584 ----a-w- c:\program files\windows mail\wab.exe
2011-03-10 20:39:07 33280 ----a-w- c:\program files\windows mail\wabfind.dll
2011-03-10 20:37:07 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-03-10 20:37:07 57344 ----a-w- c:\program files\common files\system\msadc\msadcs.dll
2011-03-10 20:37:07 253952 ----a-w- c:\program files\common files\system\ado\msadox.dll
2011-03-10 20:37:07 241664 ----a-w- c:\program files\common files\system\ado\msadomd.dll
2011-03-10 20:37:07 180224 ----a-w- c:\program files\common files\system\msadc\msadco.dll
2011-03-10 20:36:42 2039808 ----a-w- c:\windows\system32\win32k.sys
2011-03-10 20:36:16 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-03-10 20:36:15 3602320 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-03-10 20:35:49 1616384 ----a-w- c:\program files\windows mail\msoe.dll
2011-03-10 20:35:25 81920 ----a-w- c:\windows\system32\iccvid.dll
2011-03-10 20:33:39 420352 ----a-w- c:\windows\system32\vbscript.dll
2011-03-10 20:33:16 67072 ----a-w- c:\windows\system32\asycfilt.dll
2011-03-10 20:32:52 339968 ----a-w- c:\program files\windows nt\accessories\wordpad.exe
2011-03-10 20:31:50 128000 ----a-w- c:\windows\system32\spoolsv.exe
2011-03-10 20:31:26 157184 ----a-w- c:\windows\system32\t2embed.dll
2011-03-10 20:30:15 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-03-10 20:28:49 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe
2011-03-10 20:28:47 10926592 ----a-w- c:\program files\movie maker\MOVIEMK.dll
2011-03-10 20:27:54 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-03-10 20:27:53 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-03-10 20:27:53 1696256 ----a-w- c:\windows\system32\gameux.dll
2011-03-10 20:27:30 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2011-03-10 20:25:28 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-03-10 20:25:27 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-03-10 20:21:20 62464 ----a-w- c:\windows\system32\l3codeca.acm
2011-03-10 20:21:20 220672 ----a-w- c:\windows\system32\l3codecp.acm
2011-03-10 15:12:14 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-03-10 15:12:14 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-03-10 15:12:14 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-03-10 15:12:14 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-03-10 15:12:14 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-03-10 15:10:16 601600 ----a-w- c:\windows\system32\schedsvc.dll
2011-03-10 15:10:16 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-03-10 15:10:16 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-03-10 15:10:16 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-03-10 15:10:07 81920 ----a-w- c:\windows\system32\consent.exe
2011-03-10 15:09:20 2048 ----a-w- c:\windows\system32\tzres.dll
2011-03-10 15:08:46 72704 ----a-w- c:\windows\system32\fontsub.dll
2011-03-10 15:08:46 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-03-10 15:08:46 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-03-10 15:07:10 24064 ----a-w- c:\windows\system32\nshhttp.dll
2011-03-10 15:07:08 411648 ----a-w- c:\windows\system32\drivers\http.sys
2011-03-10 15:06:56 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-03-10 15:06:50 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-10 15:05:17 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-03-09 22:08:32 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-03-09 22:08:20 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-03-09 22:08:19 322560 ----a-w- c:\windows\system32\sbe.dll
2011-03-09 22:08:19 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-09 22:08:19 153088 ----a-w- c:\windows\system32\sbeio.dll
2011-03-09 22:08:17 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-03-09 22:08:17 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-03-09 17:01:55 98304 ----a-w- c:\windows\system32\cabview.dll
2011-03-04 04:24:26 247808 ----a-w- c:\windows\system32\shsvcs(1482).dll
.
==================== Find3M ====================
.
2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(967).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(625).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(625)(966).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(625)(1329).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(615).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(615)(1327).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(460).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(460)(965).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(460)(1326).dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf(1331).dll
2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(973).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(629).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(629)(972).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(629)(1339).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(619).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(619)(1337).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(464).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(464)(971).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(464)(1336).dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat(1341).dll
2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 ----a-w- c:\windows\system32\FntCache.dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(648).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(413).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1073).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1073)(647).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1073)(412).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1073)(1003).dll
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32(1004).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(722).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(722)(1570).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(722)(1080).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(712).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(712)(1568).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(556).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(556)(1566).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(556)(1079).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(1574).dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet(1082).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(706).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(706)(1524).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(706)(1056).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(696).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(696)(1522).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(540).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(540)(1520).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(540)(1055).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(1528).dll
2010-12-18 06:26:50 1210880 ----a-w- c:\windows\system32\urlmon(1058).dll
2010-12-18 05:25:26 385024 ----a-w- c:\windows\system32\html.iec
2010-12-18 04:48:39 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-12-18 04:47:11 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 17:22:03.54 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 2/3/2009 1:34:00 PM
System Uptime: 3/13/2011 4:38:58 PM (1 hours ago)
.
Motherboard: Quanta | | 30CF
Processor: AMD Turion(tm) 64 X2 Mobile Technology TL-60 | Socket S1 | 1800/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 175 GiB total, 112.432 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 2.016 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.0
Adobe Shockwave Player
AIM 6
Atheros Driver Installation Program
Avira AntiVir Personal - Free Antivirus
BlackBerry Desktop Software 4.3
Cards_Calendar_OrderGift_DoMorePlugout
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CyberLink YouCam
Driver Detective
DVD Suite
EA Link
GEAR driver installer for x86 and x64
Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
HDAUDIO Soft Data Fax Modem with SmartCP
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Easy Setup - Frontend
HP Help and Support
HP Photosmart Essential 2.5
HP Quick Launch Buttons 6.30 E1
HP QuickPlay 3.6
HP QuickTouch 1.00 C4
HP Smart Web Printing
HP Total Care Advisor
HP Update
HP User Guides 0087
HP Wireless Assistant
HPNetworkAssistant
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabel_Tattoo
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookHolidayPack1
HPPhotoSmartPhotobookModernPack1
HPPhotoSmartPhotobookPlayfulPack1
HPPhotoSmartPhotobookScrapbookPack1
HPPhotoSmartPhotobookWebPack1
Java(TM) 6 Update 13
Java(TM) 6 Update 2
Junk Mail filter update
LabelPrint
LightScribe System Software 1.10.13.1
Malwarebytes' Anti-Malware
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
My HP Games
NetWaiting
NVIDIA Drivers
OGA Notifier 2.0.0048.0
Power2Go
PowerDirector
PSSWCORE
QuickPlay SlingPlayer 0.4.6
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
Roxio Media Manager
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Slingbox Flash Tour
SlingPlayer
Synaptics Pointing Device Driver
The Sims™ Life Stories
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VideoToolkit01
Viewpoint Media Player
WeatherBug Gadget
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
.
==== End Of File ===========================