I have had a virus on my computer and I have got rid of most of it, but there still lies one problem. There were two Files one JJK.exe and JJH.exe. I started my computer in 'Safe Mode' then deleted both. Also I ran MAlwarebytes on my computer and it found some infections, I deleted the infections. But I am still having this problem with my browsers (its happening with Firefox and IE9)
1. When I do a search in Google, then get the results, as I click on the link it diverts me to different pages of advertisement and 'Win' so and so.
2. I can not turn ON my Windows Security Center Service. I tried doing it through going to its properties box and resetting it so its on AUTOMATIC, then clicking START. But nothing happend
3. Also I have pasted the DDS log.
4. I ran the GMER Log (I could only select the check boxes for: Services, Registry, Files, C drive, D Drive and F Drive, also 'ADS') and I got a message saying 'No changes were found'
.
DDS (Ver_2011-06-12.02) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by Ahmed at 23:10:51 on 2011-06-12
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.3893.2198 [GMT -4:00]
.
AV: AVG Anti-Virus *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
C:\Windows\system32\lsm.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
C:\Program Files (x86)\AVG\AVG9\avgfws9.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\AVG\AVG9\avgam.exe
C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
C:\Program Files (x86)\AVG\AVG9\avgemc.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Freecorder\FLVSrvc.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\prevhost.exe
C:\PROGRA~2\MIF5BA~1\Office12\WINWORD.EXE
C:\Windows\splwow64.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {B3E32D88-8E7F-468F-B0E2-3A300FD4A82C} - hxxp://myitlab.pearsoned.com/Pegasus/Modules/SIMIntegration/Resources/ax/stub.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{49E48787-C35D-4A41-ABAF-6AF8EE70AC2D} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{49E48787-C35D-4A41-ABAF-6AF8EE70AC2D}\35B4951323037313 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{49E48787-C35D-4A41-ABAF-6AF8EE70AC2D}\449636B656E637F6E6 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{49E48787-C35D-4A41-ABAF-6AF8EE70AC2D}\46C696E6B6 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{49E48787-C35D-4A41-ABAF-6AF8EE70AC2D}\A416E6963656 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{49E48787-C35D-4A41-ABAF-6AF8EE70AC2D}\D49636B6569744 : DhcpNameServer = 192.168.0.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64: Search Helper - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: AVG Security Toolbar BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
BHO-X64: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO-X64: Ask Toolbar BHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: AVG Security Toolbar: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
TB-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun-x64: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ahmed\AppData\Roaming\Mozilla\Firefox\Profiles\jfvmrt42.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4bf6a19b&v=6.010.006.004&i=26&tp=ab&iy=&ychte=ca&lng=en-GB&q=
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSErHrw7a;AVG9IDSErHr;C:\Windows\system32\Drivers\AVGIDSwa.sys --> C:\Windows\system32\Drivers\AVGIDSwa.sys [?]
R0 AvgRkx64;avgrkx64.sys;C:\Windows\system32\Drivers\avgrkx64.sys --> C:\Windows\system32\Drivers\avgrkx64.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 Avgfwfd;AVG network filter service;C:\Windows\system32\DRIVERS\avgfwd6a.sys --> C:\Windows\system32\DRIVERS\avgfwd6a.sys [?]
R1 AvgLdx64;AVG AVI Loader Driver x64;C:\Windows\system32\Drivers\avgldx64.sys --> C:\Windows\system32\Drivers\avgldx64.sys [?]
R1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;C:\Windows\system32\Drivers\avgmfx64.sys --> C:\Windows\system32\Drivers\avgmfx64.sys [?]
R1 AvgTdiA;AVG Network Redirector x64;C:\Windows\system32\Drivers\avgtdia.sys --> C:\Windows\system32\Drivers\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
R2 avg9emc;AVG E-mail Scanner;C:\Program Files (x86)\AVG\AVG9\avgemc.exe [2010-6-22 921952]
R2 avg9wd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe [2010-6-22 308136]
R2 avgfws9;AVG Firewall;C:\Program Files (x86)\AVG\AVG9\avgfws9.exe [2010-6-22 2331544]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-6-12 366640]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-5-13 2320920]
R3 AVGIDSDriverw7a;AVG9IDSDriver;C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN764\AVGIDSDriver.sys [2010-5-21 132688]
R3 AVGIDSFilterw7a;AVG9IDSFilter;C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN764\AVGIDSFilter.sys [2010-5-21 35920]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 AVGIDSAgent;AVG9IDSAgent;C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-6-22 5897808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-10-26 947528]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-06-12 23:35:25 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-06-12 23:35:22 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-06-12 23:25:50 -------- d-----w- C:\Users\Ahmed\AppData\Roaming\Malwarebytes
2011-06-12 23:25:40 -------- d-----w- C:\ProgramData\Malwarebytes
2011-06-12 23:25:37 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-06-12 15:33:21 -------- d-----w- C:\Users\Ahmed\AppData\Local\{37F211FB-F26C-4D39-8705-C0FB34E8025E}
2011-06-11 21:19:52 151552 --sha-r- C:\Windows\SysWow64\btpanui4.dll
2011-06-11 17:12:50 -------- d-----w- C:\Users\Ahmed\AppData\Local\{6AF67B61-5639-4E26-9BFE-C60BC361582A}
2011-06-11 04:50:26 -------- d-----w- C:\Users\Ahmed\AppData\Local\{A5F6137B-8304-4DCD-B71F-FEC0230CCE12}
2011-06-10 12:03:42 -------- d-----w- C:\Users\Ahmed\AppData\Local\{46A2436E-06D2-4783-A498-631EA71D6CC8}
2011-06-09 23:26:17 -------- d-----w- C:\Users\Ahmed\AppData\Local\{235797D5-295F-4CED-98E4-2FDBA6741D8B}
2011-06-09 11:25:42 -------- d-----w- C:\Users\Ahmed\AppData\Local\{FF221A91-629F-4AA7-B166-5B6DD0C2CC81}
2011-06-08 11:44:20 -------- d-----w- C:\Users\Ahmed\AppData\Local\{ED290F63-6891-4BF7-A5CF-11CB3C6F85E0}
2011-06-07 21:47:42 -------- d-----w- C:\Program Files\iPod
2011-06-07 21:47:41 -------- d-----w- C:\Program Files\iTunes
2011-06-07 21:47:41 -------- d-----w- C:\Program Files (x86)\iTunes
2011-06-07 21:07:29 -------- d-----w- C:\Users\Ahmed\AppData\Local\{4BCEE479-365E-4351-96D6-A9C5EB188DC4}
2011-06-07 11:34:29 -------- d-----w- C:\Users\Ahmed\AppData\Local\{8262E306-8E60-4459-B780-D79FE5360C5C}
2011-06-06 17:38:13 -------- d-----w- C:\Users\Ahmed\AppData\Local\{AD6C8838-1D3D-4475-9E24-62606C9367DA}
2011-06-06 05:20:27 -------- d-----w- C:\Users\Ahmed\AppData\Local\{37645485-18B5-4B0D-84C4-F66748849A8B}
2011-06-05 17:28:38 55280 ------w- C:\Windows\System32\drivers\PxHlpa64.sys
2011-06-05 17:28:38 10224 ------w- C:\Windows\System32\drivers\cdralw2k.sys
2011-06-05 17:28:38 10224 ------w- C:\Windows\System32\drivers\cdr4_xp.sys
2011-06-05 17:28:37 -------- d-----w- C:\Program Files (x86)\Common Files\Sonic Shared
2011-06-05 17:28:37 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-06-05 17:28:35 -------- d-----w- C:\Program Files (x86)\Roxio
2011-06-05 17:27:36 -------- d-----w- C:\Users\Ahmed\AppData\Roaming\Roxio Log Files
2011-06-05 17:26:10 -------- d-----w- C:\Users\Ahmed\AppData\Roaming\Macrovision
2011-06-05 15:58:32 -------- d-----w- C:\Users\Ahmed\AppData\Local\{ACB5344F-F039-4144-961D-A0153B5973A6}
2011-06-04 15:20:08 -------- d-----w- C:\Users\Ahmed\AppData\Local\{8CDAA1CF-23E1-4C69-BDB5-84B0733CE1E8}
2011-06-03 11:52:39 -------- d-----w- C:\Users\Ahmed\AppData\Local\{C7A1480E-DDD5-425D-9572-9F862123C0DD}
2011-06-02 20:42:48 -------- d-----w- C:\Users\Ahmed\AppData\Local\{79A69CB0-0C6D-4325-AEE1-5CC95C5D84ED}
2011-06-02 01:44:58 -------- d-----w- C:\Users\Ahmed\AppData\Local\{66EC8D17-64D3-4CCB-B48E-4744BEBF0BF7}
2011-06-01 11:48:56 -------- d-----w- C:\Users\Ahmed\AppData\Local\{1EA16615-20BA-4862-B11E-3D74F6BFBFA6}
2011-05-31 20:13:00 -------- d-----w- C:\Users\Ahmed\AppData\Local\{50C1BEFE-EE59-4A05-A0C7-D08462345CC7}
2011-05-30 12:15:38 -------- d-----w- C:\Users\Ahmed\AppData\Local\{A133CEC6-AAEE-4C39-8979-32973A64B19B}
2011-05-29 17:09:41 -------- d-----w- C:\Users\Ahmed\AppData\Local\{CB60F71A-CCD4-4188-B52A-76E37C24EF25}
2011-05-28 21:18:30 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-05-28 16:34:13 -------- d-----w- C:\Users\Ahmed\AppData\Local\{59E1076E-C69A-4B6F-AD35-41FB844F3D6A}
2011-05-27 12:40:26 -------- d-----w- C:\Users\Ahmed\AppData\Local\{23FD539E-791B-4E88-BC4A-1DE443273C4D}
2011-05-26 17:17:44 -------- d-----w- C:\Users\Ahmed\AppData\Local\{AE3D8652-5DC0-4CF8-BA50-1EB4B2AE7689}
2011-05-26 13:21:46 -------- d-----w- C:\Windows\System32\SPReview
2011-05-26 13:20:30 -------- d-----w- C:\Windows\System32\EventProviders
2011-05-26 05:17:05 -------- d-----w- C:\Users\Ahmed\AppData\Local\{FC9FD987-DA59-450D-A36E-00C4ACD83033}
2011-05-25 17:11:59 1888256 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2011-05-25 17:10:59 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2011-05-25 17:09:59 65536 ----a-w- C:\Windows\System32\RpcRtRemote.dll
2011-05-25 17:08:59 721408 ----a-w- C:\Windows\System32\bthprops.cpl
2011-05-25 17:07:59 73216 ----a-w- C:\Windows\SysWow64\msiexec.exe
2011-05-25 17:06:59 7168 ----a-w- C:\Windows\SysWow64\KBDNEPR.DLL
2011-05-25 17:05:52 209920 ----a-w- C:\Windows\SysWow64\PkgMgr.exe
2011-05-25 17:05:52 189952 ----a-w- C:\Windows\SysWow64\wdscore.dll
2011-05-25 17:04:56 323072 ----a-w- C:\Windows\SysWow64\drvstore.dll
2011-05-25 17:04:55 257024 ----a-w- C:\Windows\SysWow64\dpx.dll
2011-05-25 17:04:26 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2011-05-25 17:04:25 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2011-05-25 17:00:21 -------- d-----w- C:\Users\Ahmed\AppData\Local\{0B33675B-4CDB-46E3-8813-4DD11CD2ACB5}
2011-05-25 16:54:46 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2011-05-25 16:54:46 524288 ----a-w- C:\Windows\System32\wmicmiplugin.dll
2011-05-25 16:54:46 1225216 ----a-w- C:\Windows\System32\wbem\wbemcore.dll
2011-05-25 16:54:34 933376 ----a-w- C:\Windows\System32\SmiEngine.dll
2011-05-25 16:54:29 199168 ----a-w- C:\Windows\System32\PkgMgr.exe
2011-05-25 16:52:59 422912 ----a-w- C:\Windows\System32\drvstore.dll
2011-05-25 16:52:59 399872 ----a-w- C:\Windows\System32\dpx.dll
2011-05-25 12:43:46 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-05-25 03:38:25 -------- d-----w- C:\Users\Ahmed\AppData\Local\{FE3A1321-B6D6-48F4-B119-CE752292DFC4}
2011-05-24 16:49:20 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-24 16:49:19 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-24 11:27:03 -------- d-----w- C:\Users\Ahmed\AppData\Local\{A80730ED-F022-4D0F-8E45-2BA213E7D539}
2011-05-23 17:31:56 -------- d-----w- C:\Users\Ahmed\AppData\Local\{A697AE7A-58CE-4E34-820B-7BA01A147796}
2011-05-23 02:14:24 -------- d-----w- C:\Users\Ahmed\AppData\Local\{08661D2E-FAD0-4002-8AF7-2387FCE5DA2A}
2011-05-22 04:08:23 -------- d-----w- C:\Users\Ahmed\AppData\Local\{AFAA46E3-439D-41C7-8DEB-69A325A6716D}
2011-05-21 14:59:43 -------- d-----w- C:\Users\Ahmed\AppData\Local\{D7F6FCC4-5618-4882-8E27-B22097EF26D6}
2011-05-20 18:24:41 -------- d-----w- C:\Users\Ahmed\AppData\Local\{B2E4C92C-EC06-453B-9166-AC1C979A1D43}
2011-05-20 00:53:32 -------- d-----w- C:\Users\Ahmed\AppData\Local\{71F82CE7-8AE7-4520-924D-EB6EAB7837E1}
2011-05-19 07:53:31 -------- d-----w- C:\Users\Ahmed\AppData\Local\{12268CF1-714C-4603-81E2-1EBC657AD7B5}
2011-05-18 09:02:07 -------- d-----w- C:\Users\Ahmed\AppData\Local\{9999E0D8-23D5-41B7-ACD2-19A082C9C65D}
2011-05-17 07:26:43 -------- d-----w- C:\Users\Ahmed\AppData\Local\{9803356E-ED7E-4725-BD39-7A175E3F2231}
2011-05-16 10:21:24 -------- d-----w- C:\Users\Ahmed\AppData\Local\{C5D95C8F-1AB4-4358-AB5B-84B68DCB167F}
2011-05-15 19:14:42 -------- d-----w- C:\Users\Ahmed\AppData\Local\FLVService
2011-05-15 19:14:35 -------- d-----w- C:\Windows\Freecorder
2011-05-15 19:14:35 -------- d-----w- C:\Program Files (x86)\Freecorder
2011-05-15 08:34:09 -------- d-----w- C:\Users\Ahmed\AppData\Local\{19723BB3-D14E-4368-BCCE-EF1DA6584F12}
2011-05-14 09:14:08 -------- d-----w- C:\Users\Ahmed\AppData\Local\{71BAD2EE-0C42-4102-A4A6-4EC7F5A32D6D}
.
==================== Find3M ====================
.
2011-05-26 13:36:43 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-05-26 13:36:43 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-05-06 12:04:40 317520 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2011-04-09 07:02:55 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-04-09 06:02:25 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-04-09 06:02:25 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-04-06 20:26:58 96544 ----a-w- C:\Windows\System32\dnssd.dll
2011-04-06 20:26:58 69408 ----a-w- C:\Windows\System32\jdns_sd.dll
2011-04-06 20:26:58 237856 ----a-w- C:\Windows\System32\dnssdX.dll
2011-04-06 20:26:58 119584 ----a-w- C:\Windows\System32\dns-sd.exe
2011-04-06 20:20:16 91424 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-04-06 20:20:16 75040 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
2011-04-06 20:20:16 197920 ----a-w- C:\Windows\SysWow64\dnssdX.dll
2011-04-06 20:20:16 107808 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-03-25 03:29:26 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-03-25 03:29:14 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-03-25 03:29:14 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-03-25 03:29:04 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-03-25 03:29:04 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-03-25 03:29:03 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-03-25 03:28:59 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
.
============= FINISH: 23:11:34.78 ===============
Attached File(s)
-
Attach.txt (17.8K)
Number of downloads: 0

Help
This topic is locked

Back to top












