2 problems

  1. #1
    gbaromman is offline Newbie

    2 problems

    ok big problem seems that my hotmail email is sending some spam to people on my account and ive changed the password and getting a email sending failed ive changed my password since and doing a full anti-virus scan using comodo


    secound problem comodo just asked about a program called ask.com trying to access something forgot what it was couldnt find it in the uninstall manager and i dont want to just right click delete it just yet

    scan is still part way through not sure how to upload a report thing through this anti virus though any help on this would be aprecciated

  2. #2
    broni is offline Senior Member
    Welcome aboard

    Please, complete all steps listed here: HERE

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.


    ================================================== ==================================

  3. #3
    gbaromman is offline Newbie
    Malwarebytes' Anti-Malware 1.50.1.1100
    Malwarebytes

    Database version: 6173

    Windows 6.1.7601 Service Pack 1
    Internet Explorer 8.0.7601.17514

    26/03/2011 08:24:38
    mbam-log-2011-03-26 (08-24-38).txt

    Scan type: Quick scan
    Objects scanned: 154607
    Time elapsed: 5 minute(s), 11 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

  4. #4
    gbaromman is offline Newbie
    GMER 1.0.15.15570 - GMER - Rootkit Detector and Remover
    Rootkit quick scan 2011-03-26 08:50:06
    Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Scsi\mv91xx1Port4Path0Target1Lun0 GB0750EA rev.HPG1
    Running: 1h5e34hf.exe; Driver: C:\Users\Billy\AppData\Local\Temp\fgloqpod.sys


    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
    AttachedDevice \FileSystem\fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
    AttachedDevice \Driver\tdx \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
    AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\tdx \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
    AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\tdx \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
    AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
    AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    ---- EOF - GMER 1.0.15 ----

  5. #5
    gbaromman is offline Newbie
    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Billy at 8:51:23.10 on 26/03/2011
    Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_24
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3572.2092 [GMT 0:00]
    .
    AV: COMODO Antivirus *Enabled/Updated* {675CEE69-9702-A524-3989-6D7CC8BF3695}
    AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: COMODO Defense+ *Enabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\AVG\AVG10\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
    C:\Windows\system32\PnkBstrA.exe
    C:\Program Files\Microsoft\BingBar\SeaPort.EXE
    C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    C:\Program Files\AVG\AVG10\avgtray.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Real\RealPlayer\Update\realsched.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Logitech\SetPointP\SetPoint.exe
    C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    C:\Program Files\AVG\AVG10\avgnsx.exe
    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files\AVG\AVG10\avgemcx.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
    C:\Program Files\CyberLink\Shared files\brs.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    C:\Program Files\COMODO\COMODO GeekBuddy\CLPS.exe
    C:\Program Files\AVG\AVG10\avgrsx.exe
    C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
    C:\Program Files\AVG\AVG10\avgchsvx.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Logitech Gaming Software\LCore.exe
    C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-1.00.027\Applets\x86\LCDClock.exe
    C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-1.00.027\Applets\x86\LCDCountdown.exe
    C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-1.00.027\Applets\x86\LCDMedia.exe
    C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-1.00.027\Applets\x86\LCDPop3.exe
    C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-1.00.027\Applets\x86\LCDRSS.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Billy\Downloads\dds.scr
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyServer = http=;ftp=;https=;
    uInternet Settings,ProxyOverride = *.local
    mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin \ie\rpbrowserrecordplugin.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\mif5ba~1\office14\GROOVEEX.DLL
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
    BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mif5ba~1\office14\URLREDIR.DLL
    BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
    BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
    uRun: [Steam] "c:\program files\steam\steam.exe" -silent
    uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.e xe"
    mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
    mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.ex e" -launchedbylogin
    mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
    mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
    mRun: [TaskTray]
    mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
    mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
    mRun: [NUSB3MON] "c:\program files\renesas electronics\usb 3.0 host controller driver\application\nusb3mon.exe"
    mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
    mRun: [RemoteControl10] "c:\program files\cyberlink\powerdvd10\PDVD10Serv.exe"
    mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
    mRun: [COMODO] c:\program files\comodo\comodo geekbuddy\CLPSLA.exe
    mRun: [CPA] c:\program files\comodo\comodo geekbuddy\VALA.exe
    mRun: [Launch LCore] "c:\program files\logitech gaming software\LCore.exe" /minimized
    mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~1\mif5ba~1\office14\ONBttnIE.dll/105
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: {E6B9833B-9EB5-4E7C-AC0E-785E8AE0D97B} = 156.154.70.22,156.154.71.22
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
    Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    AppInit_DLLs: c:\windows\system32\guard32.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\mif5ba~1\office14\GROOVEEX.DLL
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\billy\appdata\roaming\mozilla\firefox\pro files\z1png2nk.default\
    FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4d6feb5c&v=6.011.025.001&i=23&tp=ab&iy=&ychte=u k&lng=en-GB&q=
    FF - prefs.js: network.proxy.type - 0
    FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
    FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\compon ents\IGeared_tavgp_xputils3.dll
    FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\compon ents\IGeared_tavgp_xputils35.dll
    FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\compon ents\xpavgtbapi.dll
    FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
    FF - component: c:\programdata\real\realplayer\browserrecordplugin \firefox\ext\components\nprpffbrowserrecordext.dll
    FF - component: c:\programdata\real\realplayer\browserrecordplugin \firefox\ext\components\nprpffbrowserrecordlegacye xt.dll
    FF - plugin: c:\progra~1\mif5ba~1\office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\mif5ba~1\office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.d ll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
    FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\programdata\real\realplayer\browserrecordplugin \mozillaplugins\nprphtml5videoshim.dll
    FF - plugin: c:\users\billy\appdata\locallow\unity\webplayer\lo ader\npUnity3D32.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg10\Firefox
    FF - Ext: AVG Security Toolbar em:version=6.103.018.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\avg\avg10\toolbar\firefox\avg@igeared
    FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\real\realplayer\browserrecordplugin \firefox\Ext
    FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    FF - Ext: Element Hiding Helper for Adblock Plus: elemhidehelper@adblockplus.org - %profile%\extensions\elemhidehelper@adblockplus.or g
    FF - Ext: Adblock Plus Pop-up Addon: adblockpopups@jessehakanen.net - %profile%\extensions\adblockpopups@jessehakanen.ne t
    FF - Ext: Real Hide IP: support@real-hide-ip.com - %profile%\extensions\support@real-hide-ip.com
    FF - Ext: Ask Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGI DSEH.sys [2010-9-13 25680]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
    R0 mv91xx;mv91xx;c:\windows\system32\drivers\mv91xx.s ys [2010-8-6 257064]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
    R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2011-1-6 17256]
    R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-1-6 236600]
    R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-1-6 35768]
    R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/03/17 22:01:51];c:\program files\cyberlink\powerdvd10\navfilter\000.fcl [2010-3-13 87536]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
    R2 CLPSLS;COMODO livePCsupport Service;c:\program files\comodo\comodo geekbuddy\CLPSLS.exe [2011-3-2 156576]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-12-21 378984]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\driv ers\AVGIDSDriver.sys [2010-8-3 123472]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\driv ers\AVGIDSFilter.sys [2010-8-3 30288]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\ AVGIDSShim.sys [2010-8-3 27216]
    R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2011-3-25 19720]
    R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2011-3-25 14856]
    R3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECI.sys [2011-3-3 41088]
    R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [2010-12-2 25600]
    R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2010-12-10 62336]
    R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2010-12-10 141440]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-3-11 122984]
    R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [2010-12-12 106728]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\ v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-3-7 136176]
    S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-3-3 517448]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
    S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-2-28 183560]
    S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssflt r.sys [2011-3-5 39272]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]
    S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EX E [2010-1-9 4640000]
    S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
    S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUs bFlt.sys [2011-3-5 52224]
    S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-3-4 1343400]
    S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
    .
    =============== Created Last 30 ================
    .
    2011-03-26 08:18:22 -------- d-----w- c:\users\billy\appdata\roaming\Malwarebytes
    2011-03-26 08:18:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-03-26 08:18:07 -------- d-----w- c:\progra~2\Malwarebytes
    2011-03-26 08:18:04 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-03-26 08:18:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-03-25 21:15:19 -------- d-----w- c:\users\billy\appdata\local\{2853DC6F-37D9-4942-A9DE-255B8822BCA2}
    2011-03-25 17:23:23 -------- d-----w- c:\users\billy\appdata\local\EA Games
    2011-03-25 16:54:52 -------- d-----w- c:\users\billy\appdata\local\Logitech
    2011-03-25 16:53:43 341000 ----a-w- c:\windows\system32\drivers\umdf\lgSSQVGA.dll
    2011-03-25 16:53:43 140808 ----a-w- c:\windows\system32\drivers\umdf\lgSSBW.dll
    2011-03-25 16:53:41 19720 ----a-w- c:\windows\system32\drivers\LGBusEnum.sys
    2011-03-25 16:53:41 14856 ----a-w- c:\windows\system32\drivers\LGVirHid.sys
    2011-03-25 16:53:26 -------- d-----w- c:\program files\Logitech Gaming Software
    2011-03-25 10:24:50 -------- d-----w- c:\users\billy\appdata\local\MediaMonkey
    2011-03-25 10:24:49 -------- d-----w- c:\program files\MediaMonkey
    2011-03-25 09:09:03 -------- d-----w- c:\progra~2\Solidshield
    2011-03-24 21:14:42 -------- d-----w- c:\users\billy\appdata\local\{A4C3710A-7F30-40C5-B635-7018537034F1}
    2011-03-24 20:55:02 -------- d-----w- c:\users\billy\appdata\local\COMODO
    2011-03-24 09:14:17 -------- d-----w- c:\users\billy\appdata\local\{822811AD-B396-4E67-A452-288319DDA062}
    2011-03-23 20:30:57 -------- d-----w- c:\users\billy\appdata\local\{24592503-8C04-4603-8E78-9775517541CF}
    2011-03-23 17:38:53 -------- d--h--w- C:\VritualRoot
    2011-03-23 17:37:49 272 ----a-w- c:\windows\system32\drivers\sfi.dat
    2011-03-23 17:24:09 -------- d-----w- c:\progra~2\Comodo
    2011-03-23 17:24:07 -------- d-----w- c:\program files\COMODO
    2011-03-23 17:24:06 1700352 ----a-w- c:\windows\system32\gdiplus.dll
    2011-03-23 17:24:06 1060864 ----a-w- c:\windows\system32\mfc71.dll
    2011-03-23 08:53:34 -------- d-----w- c:\users\billy\appdata\local\Apple Computer
    2011-03-23 08:53:18 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2011-03-23 08:53:18 107368 ----a-w- c:\windows\system32\GEARAspi.dll
    2011-03-23 08:53:05 -------- d-----w- c:\program files\iTunes
    2011-03-23 08:53:05 -------- d-----w- c:\program files\iPod
    2011-03-23 08:53:05 -------- d-----w- c:\progra~2\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    2011-03-23 08:51:55 -------- d-----w- c:\users\billy\appdata\local\Apple
    2011-03-23 08:51:30 -------- d-----w- c:\program files\Bonjour
    2011-03-23 08:30:11 -------- d-----w- c:\users\billy\appdata\local\{56C4B94B-B4AF-4FB0-B7D7-2A4A820B90CF}
    2011-03-22 16:15:25 -------- d-----w- c:\users\billy\appdata\local\{5C9A97FA-000F-400F-BAC4-FAA566855D67}
    2011-03-21 13:41:37 -------- d-----w- c:\program files\Dyyno
    2011-03-20 21:08:20 -------- d-----w- c:\program files\Combined Community Codec Pack
    2011-03-19 12:05:16 -------- d-----w- c:\users\billy\appdata\roaming\.mcpkg
    2011-03-18 16:13:46 -------- d-----w- c:\users\billy\appdata\local\{7336EAED-0406-4DBA-8BBF-AE7872BD8B92}
    2011-03-18 11:15:54 -------- d-----w- c:\users\billy\appdata\local\Diagnostics
    2011-03-17 22:04:11 -------- d-----w- c:\users\billy\appdata\local\Cyberlink
    2011-03-17 22:01:38 -------- d-----w- c:\program files\common files\CyberLink
    2011-03-17 22:00:30 29480 ----a-w- c:\windows\system32\msxml3a.dll
    2011-03-17 21:45:31 -------- d-----w- c:\users\billy\appdata\roaming\NVIDIA 3D Vision Video Player
    2011-03-17 21:29:03 7428200 ----a-w- c:\windows\system32\NVStWiz.exe
    2011-03-17 21:26:04 57960 ----a-w- c:\windows\system32\OpenCL.dll
    2011-03-17 21:26:04 5653096 ----a-w- c:\windows\system32\nvwgf2um.dll
    2011-03-17 21:26:04 4941928 ----a-w- c:\windows\system32\nvcuda.dll
    2011-03-17 21:26:04 2895976 ----a-w- c:\windows\system32\nvcuvid.dll
    2011-03-17 21:26:04 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
    2011-03-17 21:26:04 15047272 ----a-w- c:\windows\system32\nvoglv32.dll
    2011-03-17 21:26:04 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
    2011-03-17 21:26:04 10466408 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
    2011-03-17 20:51:30 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
    2011-03-17 20:51:30 602244 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
    2011-03-17 20:51:30 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
    2011-03-17 20:51:30 221184 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
    2011-03-17 20:51:30 221184 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
    2011-03-17 20:43:20 -------- d-----w- c:\program files\SystemRequirementsLab
    2011-03-17 17:48:27 -------- d-----w- c:\users\billy\appdata\local\{906889D2-BEE0-468B-8F98-AE9014C0C30D}
    2011-03-16 22:34:12 -------- d-----w- c:\users\billy\appdata\roaming\.minecraft
    2011-03-16 09:06:56 -------- d-----w- c:\users\billy\appdata\local\{67CC6D7F-9535-43E5-9921-6BEFB2809C86}
    2011-03-15 21:43:47 -------- d-----w- c:\users\billy\appdata\roaming\Minecrafter
    2011-03-15 16:53:17 -------- d-----w- c:\users\billy\appdata\local\Oblivion
    2011-03-15 13:46:03 -------- d-----w- c:\users\billy\appdata\local\{8613EAE5-0A50-43CF-BAF4-F3DEF0692946}
    2011-03-15 13:22:18 -------- d-----w- c:\users\billy\appdata\roaming\AtomZombieData
    2011-03-15 01:45:51 -------- d-----w- c:\users\billy\appdata\local\{A6E231A4-6EFC-4725-B406-FB17D4176B96}
    2011-03-14 13:45:24 -------- d-----w- c:\users\billy\appdata\local\{A165F397-B75C-4881-B7F9-449EADDB87F4}
    2011-03-13 19:27:25 -------- d-----w- c:\program files\GameSpy Arcade
    2011-03-13 19:24:09 -------- d-----w- c:\program files\LucasArts
    2011-03-13 19:04:40 749568 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\int el32\iKernel.dll
    2011-03-13 19:04:40 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\int el32\ctor.dll
    2011-03-13 19:04:40 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\int el32\DotNetInstaller.exe
    2011-03-13 19:04:40 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\int el32\iscript.dll
    2011-03-13 19:04:40 192644 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\int el32\iGdi.dll
    2011-03-13 19:04:40 180224 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\int el32\iuser.dll
    2011-03-13 19:04:39 323716 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\int el32\setup.dll
    2011-03-13 10:24:27 -------- d-----w- c:\program files\Microsoft LifeCam
    2011-03-13 09:10:19 -------- d-----w- c:\users\billy\appdata\local\{5B0B06B5-D425-4E26-AC39-70A509C5269B}
    2011-03-11 21:09:27 -------- d-----w- c:\users\billy\appdata\local\{05A16F61-4603-44B2-888A-7CDF3E7BAD3F}
    2011-03-11 13:37:21 -------- d-----w- c:\program files\Marvell
    2011-03-11 13:34:03 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
    2011-03-11 13:34:03 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
    2011-03-11 13:34:03 837224 ----a-w- c:\windows\system32\nvgenco32hda.dll
    2011-03-11 13:34:03 26216 ----a-w- c:\windows\system32\nvhdap32.dll
    2011-03-11 13:34:03 122984 ----a-w- c:\windows\system32\drivers\nvhda32v.sys
    2011-03-11 13:33:06 -------- d-----w- C:\NVIDIA
    2011-03-11 13:30:00 -------- d-----w- c:\program files\Renesas Electronics
    2011-03-11 13:28:55 -------- d-----w- c:\progra~2\Downloaded Installations
    2011-03-11 13:22:24 53248 ----a-r- c:\users\billy\appdata\roaming\microsoft\installer \{3ee9bcae-e9a9-45e5-9b1c-83a4d357e05c}\ARPPRODUCTICON.exe
    2011-03-11 13:22:03 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
    2011-03-11 13:18:59 69224 ----a-w- c:\windows\system32\RtkCoInst.dll
    2011-03-11 13:17:27 -------- d--h--w- c:\program files\Temp
    2011-03-11 13:17:21 1251944 ----a-w- c:\windows\RtlExUpd.dll
    2011-03-11 13:17:14 204800 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\int el32\iuser.dll
    2011-03-11 13:17:13 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\int el32\ctor.dll
    2011-03-11 13:17:13 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\int el32\DotNetInstaller.exe
    2011-03-11 13:17:13 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\int el32\iscript.dll
    2011-03-11 13:17:11 757760 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\int el32\iKernel.dll
    2011-03-11 13:17:11 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\int el32\iGdi.dll
    2011-03-11 13:17:10 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\int el32\setup.dll
    2011-03-11 12:49:14 -------- d-----w- c:\program files\Driver-Soft
    2011-03-11 12:14:18 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
    2011-03-11 12:14:18 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
    2011-03-11 12:14:18 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
    2011-03-11 12:14:18 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
    2011-03-11 12:14:18 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
    2011-03-11 12:14:18 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
    2011-03-11 12:14:18 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
    2011-03-11 12:14:16 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
    2011-03-11 12:14:16 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
    2011-03-11 12:14:16 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
    2011-03-11 12:14:16 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
    2011-03-11 12:14:16 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
    2011-03-11 08:30:36 -------- d-----w- c:\users\billy\appdata\local\{5D2318D6-2136-44CD-B73E-4FCB98DE58EA}
    2011-03-10 03:20:00 -------- d-----w- c:\users\billy\appdata\local\{2CDE467E-62F9-4CCD-85D0-BE38AB8DCA6E}
    2011-03-09 13:59:23 805376 ----a-w- c:\windows\system32\FntCache.dll
    2011-03-09 13:59:23 739840 ----a-w- c:\windows\system32\d2d1.dll
    2011-03-09 13:59:23 1076736 ----a-w- c:\windows\system32\DWrite.dll
    2011-03-09 13:59:22 850944 ----a-w- c:\windows\system32\sbe.dll
    2011-03-09 13:59:22 642048 ----a-w- c:\windows\system32\CPFilters.dll
    2011-03-09 13:59:22 534528 ----a-w- c:\windows\system32\EncDec.dll
    2011-03-09 13:59:22 199680 ----a-w- c:\windows\system32\mpg2splt.ax
    2011-03-08 23:30:57 -------- d-----w- c:\users\billy\appdata\local\{D167FE87-D842-4DE7-A939-F6A1329561A3}
    2011-03-08 11:30:34 -------- d-----w- c:\users\billy\appdata\local\{F3BC7831-1D27-46AF-855E-3B1F626109C7}
    2011-03-08 11:30:33 -------- d-----w- c:\users\billy\appdata\local\{F4F04066-7999-4885-ACB7-FB787820242E}
    2011-03-08 09:01:06 -------- d-----w- c:\program files\VideoLAN
    2011-03-07 23:54:53 -------- d-----w- c:\users\billy\appdata\roaming\Unity
    2011-03-07 23:39:50 -------- d-----w- c:\users\billy\appdata\local\Unity
    2011-03-07 15:35:52 2337865 ----a-w- c:\windows\system32\pbsvc.exe
    2011-03-07 13:03:51 -------- d-----w- c:\program files\Microsoft Synchronization Services
    2011-03-07 13:03:07 -------- d-----w- c:\program files\Microsoft Visual Studio 8
    2011-03-07 13:02:12 -------- d-----w- c:\program files\Microsoft Analysis Services
    2011-03-07 13:01:44 -------- d-----w- c:\users\billy\appdata\local\Microsoft Help
    2011-03-07 08:19:51 -------- d-----w- c:\users\billy\appdata\local\Real
    2011-03-07 08:19:45 11776 ----a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
    2011-03-07 08:19:38 -------- d-----w- c:\program files\common files\xing shared
    2011-03-07 08:19:35 150712 ----a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
    2011-03-07 08:19:32 100864 ----a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
    2011-03-07 08:19:26 505128 ----a-w- c:\windows\system32\msvcp71.dll
    2011-03-07 08:18:53 -------- d-----w- c:\users\billy\appdata\local\Google
    2011-03-06 20:31:27 -------- d-----w- c:\progra~2\Media Center Programs
    2011-03-06 20:20:34 -------- d-----w- c:\program files\Flagship Studios
    2011-03-06 12:18:28 -------- d-----w- c:\users\billy\appdata\roaming\RealHideIP
    2011-03-06 12:18:28 -------- d-----w- c:\progra~2\RealHideIP
    2011-03-06 12:18:04 -------- d-----w- c:\program files\Ask.com
    2011-03-06 12:17:58 -------- d-----w- c:\program files\RealHideIP
    2011-03-06 12:04:28 -------- d-----w- c:\progra~2\regid.1986-12.com.adobe
    2011-03-06 10:58:51 -------- d-----w- c:\users\billy\appdata\local\Adobe
    2011-03-06 10:46:54 -------- d-----w- c:\program files\Adobe Photoshop CS5 Extended Edition
    2011-03-06 09:44:55 -------- d-----w- c:\users\billy\appdata\local\{A4F56F7B-94EB-4FBE-94D7-7FAEBDF345C6}
    2011-03-05 18:55:45 -------- d-----w- c:\progra~2\xml_param
    2011-03-05 18:50:55 158720 ----a-w- c:\windows\system32\WS_VideoConverterContextMenu.d ll
    2011-03-05 18:50:54 892928 ----a-w- c:\windows\system32\iconv.dll
    2011-03-05 18:50:54 675840 ----a-w- c:\windows\system32\ac3filter.ax
    2011-03-05 18:50:54 496640 ----a-w- c:\windows\system32\xvid.ax
    2011-03-05 18:50:53 -------- d-----w- c:\program files\Wondershare
    2011-03-05 17:48:11 -------- d-----w- c:\program files\Total Video Converter
    2011-03-05 17:38:23 -------- d-----w- c:\users\billy\appdata\local\{81D919E6-5BD6-44CE-9552-21B2BB67EB7D}
    2011-03-05 17:38:09 -------- d-----w- c:\users\billy\Tracing
    2011-03-05 17:32:08 -------- d-----w- c:\windows\en
    2011-03-05 17:31:29 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
    2011-03-05 17:30:38 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
    2011-03-05 17:29:06 -------- d-----w- c:\windows\PCHEALTH
    2011-03-05 17:26:41 -------- d-----w- c:\program files\Microsoft
    2011-03-05 17:23:25 469256 ----a-w- c:\program files\common files\windows live\.cache\831f2161cbdb5a05\InstallManager_WLE_WL E.exe
    2011-03-05 17:23:16 15712 ----a-w- c:\program files\common files\windows live\.cache\386cf161cbdb5a04\MeshBetaRemover.exe
    2011-03-05 17:23:11 94040 ----a-w- c:\program files\common files\windows live\.cache\173df51cbdb5a03\DSETUP.dll
    2011-03-05 17:23:11 525656 ----a-w- c:\program files\common files\windows live\.cache\173df51cbdb5a03\DXSETUP.exe
    2011-03-05 17:23:11 1691480 ----a-w- c:\program files\common files\windows live\.cache\173df51cbdb5a03\dsetup32.dll
    2011-03-05 17:23:09 94040 ----a-w- c:\program files\common files\windows live\.cache\fd32148b1cbdb5902\DSETUP.dll
    2011-03-05 17:23:09 525656 ----a-w- c:\program files\common files\windows live\.cache\fd32148b1cbdb5902\DXSETUP.exe
    2011-03-05 17:23:09 1691480 ----a-w- c:\program files\common files\windows live\.cache\fd32148b1cbdb5902\dsetup32.dll
    2011-03-05 17:22:56 6260088 ----a-w- c:\program files\common files\windows live\.cache\f757bbea1cbdb5901\Silverlight.4.0.exe
    2011-03-05 17:22:38 -------- d-----w- c:\users\billy\appdata\local\Windows Live
    2011-03-05 17:22:37 -------- d-----w- c:\program files\common files\Windows Live
    2011-03-05 15:47:17 -------- d-----w- c:\users\billy\appdata\roaming\NVIDIA
    2011-03-05 15:47:03 -------- d-----w- c:\users\billy\appdata\roaming\Xilisoft
    2011-03-05 15:44:13 -------- d-----w- c:\program files\Xilisoft
    2011-03-05 15:44:13 -------- d-----w- c:\progra~2\Xilisoft
    2011-03-05 14:45:24 -------- d-----w- c:\windows\system32\SPReview
    2011-03-05 14:44:39 -------- d-----w- c:\windows\system32\EventProviders
    2011-03-05 14:42:59 750592 ----a-w- c:\windows\system32\schedsvc.dll
    2011-03-05 14:41:54 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
    2011-03-05 14:41:54 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
    2011-03-05 14:41:54 363008 ----a-w- c:\windows\system32\wbemcomn.dll
    2011-03-05 14:41:54 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
    2011-03-05 14:41:51 697344 ----a-w- c:\windows\system32\SmiEngine.dll
    2011-03-05 14:41:48 209920 ----a-w- c:\windows\system32\PkgMgr.exe
    2011-03-05 14:41:48 189952 ----a-w- c:\windows\system32\wdscore.dll
    2011-03-05 14:41:38 323072 ----a-w- c:\windows\system32\drvstore.dll
    2011-03-05 14:41:38 257024 ----a-w- c:\windows\system32\dpx.dll
    2011-03-05 12:38:54 266400 ----a-w- c:\windows\system32\PnkBstrB.xtr
    2011-03-05 12:38:51 -------- d-----w- c:\users\billy\appdata\local\PunkBuster
    2011-03-05 12:38:19 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
    2011-03-05 12:38:19 22328 ----a-w- c:\users\billy\appdata\roaming\PnkBstrK.sys
    2011-03-04 13:22:37 -------- d-----w- c:\program files\Ace Utilities
    2011-03-04 12:51:36 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
    2011-03-04 11:16:03 -------- d-----w- c:\windows\system32\Wat
    2011-03-04 11:04:39 293376 ----a-w- c:\windows\system32\browserchoice.exe
    2011-03-04 11:00:05 -------- d-----w- c:\windows\system32\AGEIA
    2011-03-04 10:59:44 219136 ----a-w- c:\windows\system32\d3d10_1core.dll
    2011-03-04 10:59:43 161792 ----a-w- c:\windows\system32\d3d10_1.dll
    2011-03-04 10:55:56 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
    2011-03-04 05:16:43 -------- d-----w- c:\windows\Panther
    2011-03-04 05:09:06 -------- d--h--w- C:\$WINDOWS.~Q
    2011-03-04 05:08:39 -------- d--h--w- C:\$INPLACE.~TR
    2011-03-04 04:39:22 2330624 ----a-w- c:\windows\system32\win32k.sys
    2011-03-04 04:39:13 542208 ----a-w- c:\windows\system32\kerberos.dll
    2011-03-04 04:39:03 428032 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-04 04:38:47 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2011-03-04 04:38:41 870912 ----a-w- c:\windows\system32\XpsPrint.dll
    2011-03-04 04:38:40 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2011-03-04 04:38:38 70656 ----a-w- c:\windows\system32\fontsub.dll
    2011-03-04 04:38:38 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-03-04 04:38:38 294400 ----a-w- c:\windows\system32\atmfd.dll
    2011-03-04 04:38:05 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
    2011-03-04 04:38:05 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
    2011-03-04 04:38:05 107520 ----a-w- c:\windows\system32\cdd.dll
    2011-03-04 04:29:48 -------- d-sh--w- C:\Boot
    2011-03-04 00:32:01 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
    2011-03-04 00:32:01 303720 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
    2011-03-04 00:32:01 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
    2011-03-04 00:31:57 -------- d-----w- c:\program files\Realtek
    2011-03-04 00:31:05 -------- d-----w- c:\program files\ASUS
    2011-03-04 00:31:00 724992 ----a-w- c:\program files\common files\installshield\professional\runtime\09\00\int el32\iKernel.dll
    2011-03-04 00:31:00 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\09\00\int el32\ctor.dll
    2011-03-04 00:31:00 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\00\int el32\DotNetInstaller.exe
    2011-03-04 00:31:00 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps. dll
    2011-03-04 00:31:00 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\09\00\int el32\iscript.dll
    2011-03-04 00:31:00 192512 ----a-w- c:\program files\common files\installshield\professional\runtime\09\00\int el32\iuser.dll
    2011-03-04 00:31:00 184452 ----a-w- c:\program files\common files\installshield\professional\runtime\09\00\int el32\iGdi.dll
    2011-03-04 00:30:59 311428 ----a-w- c:\program files\common files\installshield\professional\runtime\09\00\int el32\Setup.dll
    2011-03-04 00:30:52 10296 ----a-w- c:\windows\system32\drivers\ASUSHWIO.SYS
    2011-03-03 22:22:24 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-03-03 22:22:24 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    2011-03-03 22:16:28 -------- d-----w- c:\users\billy\appdata\roaming\Raptr
    2011-03-03 22:16:28 -------- d-----w- c:\program files\Raptr
    2011-03-03 22:12:39 -------- d-----w- c:\users\billy\appdata\roaming\Azureus
    2011-03-03 22:12:14 -------- d-----w- c:\program files\Vuze
    2011-03-03 21:47:15 -------- d-----r- c:\program files\Skype
    2011-03-03 21:40:41 -------- d-----w- c:\windows\system32\wbem\Performance
    2011-03-03 21:37:49 -------- d-sh--w- C:\Recovery
    2011-03-03 21:19:45 -------- d-sh--w- c:\windows\Installer
    2011-03-03 21:19:41 -------- d-----w- c:\progra~2\NVIDIA Corporation
    2011-03-03 21:19:39 -------- d-----w- c:\program files\NVIDIA Corporation
    2011-03-03 20:45:01 -------- d-----w- c:\users\billy\appdata\local\VirtualStore
    2011-03-03 20:15:52 -------- d--h--w- C:\$AVG
    2011-03-03 19:58:25 -------- d-----w- C:\Fraps
    2011-03-03 19:57:20 -------- d-----w- c:\users\billy\appdata\local\AVG Security Toolbar
    2011-03-03 19:27:36 -------- d-----w- c:\users\billy\appdata\roaming\AVG10
    2011-03-03 19:26:30 -------- d--h--w- c:\progra~2\Common Files
    2011-03-03 19:26:19 -------- d-----w- c:\progra~2\AVG Security Toolbar
    2011-03-03 19:25:14 -------- d-----w- c:\windows\system32\drivers\AVG
    2011-03-03 19:25:14 -------- d-----w- c:\progra~2\AVG10
    2011-03-03 19:22:05 353304 ----a-w- c:\windows\system32\drivers\iaStor.sys
    2011-03-03 19:18:23 -------- d-----w- c:\program files\AVG
    2011-03-03 19:13:01 53248 ----a-w- c:\windows\system32\CSVer.dll
    2011-03-03 19:11:51 -------- d-----w- c:\program files\common files\Steam
    2011-03-03 19:11:32 -------- d-----w- c:\program files\Steam
    2011-03-03 19:08:29 -------- d-----w- c:\progra~2\MFAData
    2011-03-03 19:08:21 -------- d-----w- c:\users\billy\appdata\local\Mozilla
    2011-03-03 17:31:30 222080 ----a-w- c:\windows\system32\MpSigStub.exe
    2011-03-03 16:41:30 8192 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
    2011-03-03 16:41:04 -------- d-----w- C:\Intel
    2011-03-03 16:41:03 41088 ----a-w- c:\windows\system32\drivers\HECI.sys
    2011-03-01 07:26:44 86016 ----a-w- c:\windows\system32\frapsvid.dll
    .
    ==================== Find3M ====================
    .
    2011-03-23 12:37:31 266400 ----a-w- c:\windows\system32\PnkBstrB.ex0
    2011-03-07 18:48:23 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
    2011-03-07 16:20:44 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
    2011-03-05 14:48:51 152576 ----a-w- c:\windows\system32\msclmd.dll
    2011-03-05 12:37:52 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
    2011-02-18 16:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
    2011-01-07 21:06:08 2558568 ----a-w- c:\windows\system32\nvsvcr.dll
    2010-12-29 14:30:48 3794536 ----a-w- c:\windows\system32\RtkAPO.dll
    2010-12-29 01:42:04 285480 ----a-w- c:\windows\system32\guard32.dll
    2010-12-28 15:51:28 608768 ----a-w- c:\windows\system32\RCoRes.dat
    .
    ============= FINISH: 8:53:47.19 ===============

  6. #6
    gbaromman is offline Newbie
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_11-03-05.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 03/03/2011 21:37:50
    System Uptime: 25/03/2011 15:18:20 (17 hours ago)
    .
    Motherboard: ASUSTeK Computer INC. | | P8P67
    Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz | LGA1155 | 3301/100mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 699 GiB total, 367.871 GiB free.
    D: is CDROM (UDF)
    E: is FIXED (NTFS) - 298 GiB total, 156.755 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID:
    Description:
    Device ID: USB\VID_0CF3&PID_3000\6&F57D961&0&7
    Manufacturer:
    Name:
    PNP Device ID: USB\VID_0CF3&PID_3000\6&F57D961&0&7
    Service:
    .
    ==== System Restore Points ===================
    .
    RP77: 25/03/2011 03:00:24 - Windows Update
    RP79: 25/03/2011 09:08:41 - Installed DirectX
    RP81: 25/03/2011 1744 - Installed DirectX
    .
    ==== Installed Programs ======================
    .
    Ace Utilities
    Adobe AIR
    Adobe Community Help
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Media Player
    Adobe Photoshop CS5
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Ask Toolbar
    Atom Zombie Smasher
    AVG 2011
    Batman: Arkham Asylum GOTY Edition
    Battlefield 2142 Deluxe Edition
    Battlefield: Bad Company 2
    Bing Bar
    Bonjour
    Call of Duty: Modern Warfare 2 - Multiplayer
    Call of Juarez: Bound in Blood
    Combined Community Codec Pack 2010-10-10
    COMODO GeekBuddy
    COMODO Internet Security
    Counter-Strike: Source
    Crasher
    Crysis
    CyberLink PowerDVD 10
    D3DX10
    Darksiders
    Dead Space 2
    Definition update for Microsoft Office 2010 (KB982726)
    Driver Genius Professional Edition
    DUNGEONS - Steam Special Edition
    eReg
    Flora's Fruit Farm
    Fraps (remove only)
    GameSpy Arcade
    Google Chrome
    Google Update Helper
    Gyromancer
    Hacker Evolution
    Hellgate: London
    Hitman 2: Silent Assassin
    Hitman: Blood Money
    Hitman: Codename 47
    Infernal
    Intel(R) Control Center
    Intel(R) Management Engine Components
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 24
    Junk Mail filter update
    Just Cause 2
    Kane & Lynch 2: Dog Days
    Lara Croft and the Guardian of Light
    Left 4 Dead 2
    Logitech Gaming Software 7.00
    Logitech SetPoint 6.20
    Malwarebytes' Anti-Malware
    marvell 91xx driver
    MediaMonkey 3.2
    Mesh Runtime
    Messenger Companion
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Corporation
    Microsoft LifeCam
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Groove MUI (English) 2010
    Microsoft Office InfoPath MUI (English) 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Professional Plus 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft_VC80_ATL_x86
    Microsoft_VC80_CRT_x86
    Microsoft_VC80_MFC_x86
    Microsoft_VC80_MFCLOC_x86
    Microsoft_VC90_ATL_x86
    Microsoft_VC90_CRT_x86
    Microsoft_VC90_MFC_x86
    Mozilla Firefox (3.6.16)
    MSVCRT
    Notepad++
    NVIDIA 3D Vision Controller Driver
    NVIDIA 3D Vision Driver 266.58
    NVIDIA 3D Vision Video Player
    NVIDIA Control Panel 266.35
    NVIDIA Graphics Driver 266.35
    NVIDIA HD Audio Driver 1.1.13.1
    NVIDIA Install Application
    NVIDIA PhysX
    NVIDIA PhysX System Software 9.10.0514
    NVIDIA Stereoscopic 3D Driver
    PDF Settings CS5
    PunkBuster Services
    PVSonyDll
    QuickTime
    Real Hide IP
    RealNetworks - Microsoft Visual C++ 2008 Runtime
    RealPlayer
    Realtek Ethernet Controller Driver
    Realtek High Definition Audio Driver
    RealUpgrade 1.1
    Renesas Electronics USB 3.0 Host Controller Driver
    Rogue Trooper
    Skype Toolbars
    Skype™ 5.1
    Star Wars Battlefront
    Star Wars Republic Commando
    Star Wars: Knights of the Old Republic
    Steam
    System Requirements Lab
    The Elder Scrolls IV: Oblivion
    The Last Remnant
    Tom Clancy's Rainbow Six: Vegas 2
    Total Video Converter 3.71 100812
    Unity Web Player
    Update for Microsoft Office 2010 (KB2494150)
    Uplink
    Vampire: The Masquerade - Bloodlines
    Vuze
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live MIME IFilter
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live Remote Client
    Windows Live Remote Client Resources
    Windows Live Remote Service
    Windows Live Remote Service Resources
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    WinRAR 4.00 beta 7 (32-bit)
    Wondershare Video Converter Platinum(Build 5.1.1.0)
    Xilisoft Video Converter Platinum 6
    Zombie Panic Source
    .
    ==== Event Viewer Messages From Past Week ========
    .
    24/03/2011 17:33:14, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
    24/03/2011 17:33:14, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    .
    ==== End Of File ===========================

  7. #7
    gbaromman is offline Newbie
    thats all the logs is anything look infected from this list ?

  8. #8
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    You're running two AV programs, Comodo and AVG.
    One of them has to go.
    I strongly suggest, AVG goes.
    Use AVG Remover to uninstall it: AVG - Download tools

    ================================================== ===========

    Uninstall Ask Toolbar, typical foistware.

    ================================================== ==========

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"

    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: Uninstall & Remove McAfee, Symantec, Norton, AVG, Avast & More Antivirus and Security Applications and Programs
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.


    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

Closed Thread