Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:37:32 PM, on 6/6/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16483)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-06 12:52:38
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST350041 rev.CC46 465.76GB
Running: abc.exe; Driver: C:\Users\Terry\AppData\Local\Temp\fgtyrpob.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff80002ff0000 34 bytes [00, 00, 0C, 02, 46, 4D, 73, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 595 fffff80002ff0023 64 bytes [04, A0, F8, FF, FF, 10, 60, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe[3368] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe[3368] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe[2420] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe[2420] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe[6588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe[6588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files\Sony\VAIO Care\listener.exe[2184] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 0000000077a3000c 1 byte [C3]
.text C:\Program Files\Sony\VAIO Care\listener.exe[2184] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 0000000077abf85a 5 bytes JMP 0000000177a6d571
.text C:\Program Files\Sony\VAIO Care\listener.exe[2184] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files\Sony\VAIO Care\listener.exe[2184] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe[5732] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 0000000077a3000c 1 byte [C3]
.text C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe[5732] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 0000000077abf85a 5 bytes JMP 0000000177a6d571
.text C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe[5732] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe[5732] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\WININET.dll!HttpSendRequestW 000000007770d1e8 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\WININET.dll!HttpSendRequestA 0000000077789dd0 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefd837490 9 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\ole32.dll!CoCreateInstance + 11 000007fefd83749b 3 bytes [00, 00, 00]
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\ole32.dll!CoGetClassObject 000007fefd842e18 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\ws2_32.dll!GetAddrInfoW + 1 000007fefd4623c1 13 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\winmm.dll!waveOutOpen 000007fefaec38d0 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\dsound.dll!DirectSoundCreate 0000000000ec5a84 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!EnableWindow 0000000076e62da4 5 bytes JMP 000000016d0d9ebc
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 0000000076e7cbf3 5 bytes JMP 000000016d2291b6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000076e7cfca 5 bytes JMP 000000016d03189b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 0000000076e9cb0c 5 bytes JMP 000000016d229151
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 0000000076e9ce64 5 bytes JMP 000000016d22921b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 0000000076eafbd1 5 bytes JMP 000000016d2290d8
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 0000000076eafc9d 5 bytes JMP 000000016d22905f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!MessageBoxExA 0000000076eafcd6 5 bytes JMP 000000016d228ffb
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!MessageBoxExW 0000000076eafcfa 5 bytes JMP 000000016d228f97
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000075fa93ec 5 bytes JMP 000000016d2293d0
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheetW 000000007376388e 5 bytes JMP 000000016d229280
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheet 0000000073807922 5 bytes JMP 000000016d229328
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000075db2694 5 bytes JMP 000000016d2295c8
? C:\Windows\system32\mssprxy.dll [6328] entry point in ".rdata" section 00000000733371e6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077a525fd 6 bytes JMP 000000016d0f8054
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077a62a63 6 bytes JMP 000000016d09980d
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\kernel32.dll!CreateThread 00000000753e34b5 5 bytes JMP 000000016d0975e3
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076e58a29 5 bytes JMP 000000016d1003df
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!CreateWindowExA 0000000076e5d22e 5 bytes JMP 000000016d0a3643
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!EnableWindow 0000000076e62da4 5 bytes JMP 000000016d0d9ebc
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!CallNextHookEx 0000000076e66285 5 bytes JMP 000000016d0f7ff1
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076e67603 5 bytes JMP 000000016d0d25b4
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 0000000076e7cbf3 5 bytes JMP 000000016d2291b6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000076e7cfca 5 bytes JMP 000000016d03189b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076e7f52b 5 bytes JMP 000000016d11ed14
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 0000000076e9cb0c 5 bytes JMP 000000016d229151
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 0000000076e9ce64 5 bytes JMP 000000016d22921b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 0000000076eafbd1 5 bytes JMP 000000016d2290d8
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 0000000076eafc9d 5 bytes JMP 000000016d22905f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!MessageBoxExA 0000000076eafcd6 5 bytes JMP 000000016d228ffb
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!MessageBoxExW 0000000076eafcfa 5 bytes JMP 000000016d228f97
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\ole32.dll!OleLoadFromStream 0000000075546143 5 bytes JMP 000000016d229984
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString 0000000075f43e59 5 bytes JMP 000000016d229a7c
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!VariantClear 0000000075f43eae 5 bytes JMP 000000016d229afa
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen 0000000075f44731 5 bytes JMP 000000016d2299ee
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType 0000000075f45dee 5 bytes JMP 000000016d229a9a
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000075fa93ec 5 bytes JMP 000000016d2293d0
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheetW 000000007376388e 5 bytes JMP 000000016d229280
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheet 0000000073807922 5 bytes JMP 000000016d229328
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000075db2694 5 bytes JMP 000000016d2295c8
? C:\Windows\system32\mssprxy.dll [3504] entry point in ".rdata" section 00000000733371e6
.text C:\Users\Terry\Desktop\HijackThis.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Users\Terry\Desktop\HijackThis.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077a525fd 6 bytes JMP 000000016d0f8054
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077a62a63 6 bytes JMP 000000016d09980d
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\kernel32.dll!CreateThread 00000000753e34b5 5 bytes JMP 000000016d0975e3
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076e58a29 5 bytes JMP 000000016d1003df
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!CreateWindowExA 0000000076e5d22e 5 bytes JMP 000000016d0a3643
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!EnableWindow 0000000076e62da4 5 bytes JMP 000000016d0d9ebc
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!CallNextHookEx 0000000076e66285 5 bytes JMP 000000016d0f7ff1
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076e67603 5 bytes JMP 000000016d0d25b4
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 0000000076e7cbf3 5 bytes JMP 000000016d2291b6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000076e7cfca 5 bytes JMP 000000016d03189b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076e7f52b 5 bytes JMP 000000016d11ed14
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 0000000076e9cb0c 5 bytes JMP 000000016d229151
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 0000000076e9ce64 5 bytes JMP 000000016d22921b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 0000000076eafbd1 5 bytes JMP 000000016d2290d8
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 0000000076eafc9d 5 bytes JMP 000000016d22905f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!MessageBoxExA 0000000076eafcd6 5 bytes JMP 000000016d228ffb
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!MessageBoxExW 0000000076eafcfa 5 bytes JMP 000000016d228f97
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\ole32.dll!OleLoadFromStream 0000000075546143 5 bytes JMP 000000016d229984
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString 0000000075f43e59 5 bytes JMP 000000016d229a7c
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!VariantClear 0000000075f43eae 5 bytes JMP 000000016d229afa
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen 0000000075f44731 5 bytes JMP 000000016d2299ee
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType 0000000075f45dee 5 bytes JMP 000000016d229a9a
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000075fa93ec 5 bytes JMP 000000016d2293d0
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheetW 000000007376388e 5 bytes JMP 000000016d229280
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheet 0000000073807922 5 bytes JMP 000000016d229328
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000075db2694 5 bytes JMP 000000016d2295c8
---- Kernel IAT/EAT - GMER 2.1 ----
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD3Transition] [fffff80000bc1808] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD0Transition] [fffff80000bc17fc] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdReceivePacket] [fffff80000bc1844] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSendPacket] [fffff80000bc1838] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdRestore] [fffff80000bc182c] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSave] [fffff80000bc1820] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize0] [fffff80000bc1814] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize1] [fffff80000bc11a0] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\hal.dll[KDCOM.dll!KdRestore] [fffff80000bc182c] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!HalPrivateDispatchTable] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!atol] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KeFindConfigurationEntry] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!MmMapIoSpace] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!_strupr] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!InbvDisplayString] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KdDebuggerNotPresent] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!strstr] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KeBugCheckEx] [?]
IAT C:\Windows\system32\kdcom.dll[HAL.dll!HalQueryRealTimeClock] [?]
IAT C:\Windows\system32\kdcom.dll[HAL.dll!KdComPortInUse] [?]
---- Devices - GMER 2.1 ----
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 fffffa80065510a8
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\90004eacc110
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\90004ebd26ee
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\90004eacc110 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\90004ebd26ee (not active ControlSet)
---- EOF - GMER 2.1 ----
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Terry\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sn127w.snt127.mail.live.com/d...x?n=1140128836
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKLM\..\RunOnce: [OTL] "C:\Users\Terry\Desktop\OTL.exe"
O4 - HKCU\..\Run: [Google] rundll32 "C:\Users\Terry\AppData\Local\Adobe\Google\ngcooj.dll",ReportInitModule
O4 - HKCU\..\Run: [Wal-Mart] RunDLL32.exe C:\Users\Terry\AppData\Local\Wal-Mart\knhbmzwl.dll,cpwqyxppnyclrw
O4 - Startup: PalTalk.lnk = C:\Program Files (x86)\Paltalk Messenger\paltalk.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files (x86)\Paltalk Messenger\Paltalk.exe
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Oasis2Service - Digital Delivery Networks, Inc. - C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater15.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11451 bytes
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16483 BrowserJavaVersion: 10.5.0
Run by Terry at 12:34:52 on 2013-06-06
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3943.2358 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe
C:\Program Files\Sony\VAIO Care\VCPerfService.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
C:\Program Files\Sony\VAIO Power Management\SPMService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Sony\VAIO Care\VCService.exe
C:\Windows\System32\vds.exe
C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files (x86)\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe
C:\Windows\explorer.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
C:\Windows\system32\SearchFilterHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://sn127w.snt127.mail.live.com/default.aspx?rru=home&livecom=1#!/mail/InboxLight.aspx?n=1140128836
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [Google] rundll32 "C:\Users\Terry\AppData\Local\Adobe\Google\ngcooj.dll",ReportInitModule
uRun: [Wal-Mart] RunDLL32.exe C:\Users\Terry\AppData\Local\Wal-Mart\knhbmzwl.dll,cpwqyxppnyclrw
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRunOnce: [OTL] "C:\Users\Terry\Desktop\OTL.exe"
StartupFolder: C:\Users\Terry\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\P alTalk.lnk - C:\Program Files (x86)\Paltalk Messenger\paltalk.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files (x86)\Paltalk Messenger\Paltalk.exe
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{3F747C83-41C4-47E8-9CF0-8BBA4962DDBC} : DHCPNameServer = 10.100.94.2
TCP: Interfaces\{EB1B8362-52EB-4CE4-8682-12BD09942A38} : DHCPNameServer = 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-4-19 28480]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-1-31 36944]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-11-8 307040]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-12-23 47696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-4-11 384800]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-11-8 45856]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-8 73376]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-4-28 13336]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-13 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-13 701512]
R2 Oasis2Service;Oasis2Service;C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe [2012-11-13 60416]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]
R2 rimspci;rimspci;C:\Windows\System32\drivers\rimssne64.sys [2011-2-21 102400]
R2 risdsnpe;risdsnpe;C:\Windows\System32\drivers\risdsnxc64.sys [2011-2-21 98816]
R2 SampleCollector;VAIO Care Performance Service;C:\Program Files\Sony\VAIO Care\VCPerfService.exe [2011-4-28 259192]
R2 uCamMonitor;CamMonitor;C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2011-4-28 105024]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-4-28 2656280]
R2 VAIO Power Management;VAIO Power Management;C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2011-4-28 550080]
R2 VCFw;VAIO Content Folder Watcher;C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2011-1-20 887000]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2011-2-19 546608]
R2 VSNService;VSNService;C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [2011-4-28 852160]
R2 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [2013-5-20 1015984]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [2011-4-28 19968]
R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-8 36000]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-12-10 127328]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\avgidsfiltera.sys [2011-12-23 29776]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-8 259232]
R3 btath_avdt;Atheros Bluetooth AVDT Service;C:\Windows\System32\drivers\btath_avdt.sys [2011-3-8 109216]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-8 29344]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-8 166048]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-8 59040]
R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-8 283296]
R3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-8 286880]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-4-1 317440]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-8-8 25928]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-12-10 181248]
R3 NWLowRider;NextWindow LowRider Touch Screen;C:\Windows\System32\drivers\NWLowRider.sys [2011-2-21 26176]
R3 NWWakeFilterLR;NextWindow Remote Wake Blocker;C:\Windows\System32\drivers\NWWakeFilterLR.sys [2011-2-21 14400]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-2-21 413800]
R3 SFEP;Sony Firmware Extension Parser;C:\Windows\System32\drivers\SFEP.sys [2010-6-1 12032]
R3 SpfService;VAIO Entertainment Common Service;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [2011-1-20 286936]
R3 VCService;VCService;C:\Program Files\Sony\VAIO Care\VCService.exe [2011-4-28 44736]
R3 VUAgent;VUAgent;C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [2011-4-28 1021112]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-8 138400]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-11-2 5174392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 ATHDFU;Atheros Valkyrie USB BootROM;C:\Windows\System32\drivers\AthDfu.sys [2011-3-8 51872]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\System32\drivers\e1y60x64.sys [2009-6-10 281088]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-8-18 57280]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-7-28 1511872]
S3 hidkmdf;Microsoft HID Class Shim for KMDF;C:\Windows\System32\drivers\hidkmdf.sys [2011-2-21 14400]
S3 SOHCImp;VAIO Content Importer;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2011-2-21 113824]
S3 SOHDs;VAIO Device Searcher;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2011-2-21 67232]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2011-2-19 385336]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2011-2-19 99104]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-5-8 1255736]
.
=============== Created Last 30 ================
.
2013-06-06 17:14:39 -------- d-----w- C:\Windows\ERUNT
2013-06-06 17:14:26 -------- d-----w- C:\JRT
2013-06-06 17:05:14 -------- d-----w- C:\_OTL
2013-06-06 16:56:56 -------- d-sh--w- C:\$RECYCLE.BIN
2013-06-06 16:31:53 -------- d-s---w- C:\iexplore.exe
2013-06-05 14:38:34 -------- d-sh--w- C:\found.000
2013-05-18 03:09:44 -------- d-----w- C:\Users\Terry\AppData\Local\Programs
2013-05-16 08:02:14 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-05-16 08:02:13 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
==================== Find3M ====================
.
2013-05-20 15:43:25 45856 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys
2013-05-15 15:40:54 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-15 15:40:54 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-11 08:18:40 384800 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-04-05 01:08:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-04-05 01:00:30 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-04-05 00:59:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-04-05 00:56:16 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-04-05 00:55:47 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-04-04 22:11:34 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-04-04 22:02:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-04-04 22:02:17 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-04-04 21:58:51 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-04-04 21:57:45 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-04-04 19:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-03-19 05:53:58 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
2013-03-19 05:53:58 230400 ----a-w- C:\Windows\System32\wwansvc.dll
2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe
.
============= FINISH: 12:35:25.59 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 5/6/2012 10:20:23 AM
System Uptime: 6/6/2013 11:56:00 AM (1 hours ago)
.
Motherboard: Sony Corporation | | VAIO
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz | N/A | 2100/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 455 GiB total, 408.85 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP74: 5/10/2013 12:25:22 AM - Scheduled Checkpoint
RP75: 5/16/2013 3:00:26 AM - Windows Update
RP76: 5/23/2013 8:19:56 AM - Scheduled Checkpoint
RP77: 6/1/2013 7:38:30 AM - Scheduled Checkpoint
RP78: 6/6/2013 11:32:28 AM - ComboFix created restore point
.
==== Installed Programs ======================
.
4500_G510af_Help
4500G510af
4500G510af_Software_Min
64 Bit HP CIO Components Installer
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X MUI
Application Manager for VAIO
ArcSoft Family Paint
ArcSoft Magic-i Visual Effects 2
ArcSoft PhotoImpression 5
ArcSoft WebCam Companion 4
ArcSoft WebCam Message Board
AVG 2012
AVG Security Toolbar
Bing Maps 3D
Bluetooth Win7 Suite (64)
BufferChm
D3DX10
Destinations
DeviceDiscovery
DocMgr
DocProc
FastStone Image Viewer 4.6
Fax
Google Earth
GPBaseService2
HP Customer Participation Program 13.0
HP Document Manager 2.0
HP Imaging Device Functions 13.0
HP Officejet 4500 G510a-f
HP Smart Web Printing 4.5
HP Solution Center 13.0
HP Update
HPProductAssistant
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Java Auto Updater
Java(TM) 6 Update 22
Java(TM) 6 Update 22 (64-bit)
Java(TM) 7 Update 5
Java(TM) 7 Update 5 (64-bit)
Junk Mail filter update
Malwarebytes Anti-Malware version 1.75.0.1300
MarketResearch
Media Gallery
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft SkyDrive
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft Touch Pack for Windows 7
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft XNA Framework Redistributable 3.0
Movie Maker
MSVCRT
MSVCRT_amd64
MSVCRT110
MSVCRT110_amd64
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2721691)
MSXML 4.0 SP3 Parser (KB2758694)
MSXML 4.0 SP3 Parser (KB973685)
Oasis2Service
OCR Software by I.R.I.S. 13.0
OOBE
Paltalk Messenger 10.3
Photo Common
Photo Gallery
PlayReady PC Runtime amd64
PMB
PMB VAIO Edition Guide
PMB VAIO Edition Plug-in
Realtek High Definition Audio Driver
Remote Keyboard
Remote Play with PlayStation 3
Renesas Electronics USB 3.0 Host Controller Driver
Scan
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
SmartWebPrinting
SolutionCenter
Sony Corporation
SSLx64
SSLx86
Status
Toolbox
TrayApp
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VAIO - Media Gallery
VAIO - PMB VAIO Edition Guide
VAIO - PMB VAIO Edition Plug-in
VAIO - Remote Keyboard
VAIO - Remote Play with PlayStation®3
VAIO Care
VAIO Control Center
VAIO Data Restore Tool
VAIO Easy Connect
VAIO Event Service
VAIO Gate
VAIO Gate Default
VAIO Hardware Diagnostics
VAIO Help and Support
VAIO Improvement
VAIO Manual
VAIO Messenger
VAIO Quick Web Access
VAIO Sample Contents
VAIO Satisfaction Survey.
VAIO Smart Network
VAIO Touch Portal
VAIO Transfer Support
VAIO Update
VCCx86
VESx64
VESx86
Visual Studio 2008 x64 Redistributables
Visual Studio 2010 x64 Redistributables
VIx64
VIx86
VPMx64
VSNx64
VTPX86
VWSTx86
WebReg
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
6/6/2013 12:30:06 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
6/6/2013 12:30:06 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error: An instance of the service is already running.
6/6/2013 12:29:06 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7034] - The Application Information service terminated unexpectedly. It has done this 1 time(s).
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Secondary Logon service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Remote Access Connection Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7000] - The Computer Browser service failed to start due to the following error: The pipe has been ended.
.
==== End Of File ===========================
Scan saved at 12:37:32 PM, on 6/6/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16483)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-06 12:52:38
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST350041 rev.CC46 465.76GB
Running: abc.exe; Driver: C:\Users\Terry\AppData\Local\Temp\fgtyrpob.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff80002ff0000 34 bytes [00, 00, 0C, 02, 46, 4D, 73, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 595 fffff80002ff0023 64 bytes [04, A0, F8, FF, FF, 10, 60, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe[3368] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe[3368] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe[2420] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe[2420] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe[6588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe[6588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files\Sony\VAIO Care\listener.exe[2184] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 0000000077a3000c 1 byte [C3]
.text C:\Program Files\Sony\VAIO Care\listener.exe[2184] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 0000000077abf85a 5 bytes JMP 0000000177a6d571
.text C:\Program Files\Sony\VAIO Care\listener.exe[2184] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files\Sony\VAIO Care\listener.exe[2184] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe[5732] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 0000000077a3000c 1 byte [C3]
.text C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe[5732] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 0000000077abf85a 5 bytes JMP 0000000177a6d571
.text C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe[5732] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe[5732] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\WININET.dll!HttpSendRequestW 000000007770d1e8 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\WININET.dll!HttpSendRequestA 0000000077789dd0 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefd837490 9 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\ole32.dll!CoCreateInstance + 11 000007fefd83749b 3 bytes [00, 00, 00]
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\ole32.dll!CoGetClassObject 000007fefd842e18 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\ws2_32.dll!GetAddrInfoW + 1 000007fefd4623c1 13 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\winmm.dll!waveOutOpen 000007fefaec38d0 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[1784] C:\Windows\system32\dsound.dll!DirectSoundCreate 0000000000ec5a84 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!EnableWindow 0000000076e62da4 5 bytes JMP 000000016d0d9ebc
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 0000000076e7cbf3 5 bytes JMP 000000016d2291b6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000076e7cfca 5 bytes JMP 000000016d03189b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 0000000076e9cb0c 5 bytes JMP 000000016d229151
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 0000000076e9ce64 5 bytes JMP 000000016d22921b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 0000000076eafbd1 5 bytes JMP 000000016d2290d8
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 0000000076eafc9d 5 bytes JMP 000000016d22905f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!MessageBoxExA 0000000076eafcd6 5 bytes JMP 000000016d228ffb
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\USER32.dll!MessageBoxExW 0000000076eafcfa 5 bytes JMP 000000016d228f97
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000075fa93ec 5 bytes JMP 000000016d2293d0
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheetW 000000007376388e 5 bytes JMP 000000016d229280
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheet 0000000073807922 5 bytes JMP 000000016d229328
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[6328] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000075db2694 5 bytes JMP 000000016d2295c8
? C:\Windows\system32\mssprxy.dll [6328] entry point in ".rdata" section 00000000733371e6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077a525fd 6 bytes JMP 000000016d0f8054
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077a62a63 6 bytes JMP 000000016d09980d
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\kernel32.dll!CreateThread 00000000753e34b5 5 bytes JMP 000000016d0975e3
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076e58a29 5 bytes JMP 000000016d1003df
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!CreateWindowExA 0000000076e5d22e 5 bytes JMP 000000016d0a3643
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!EnableWindow 0000000076e62da4 5 bytes JMP 000000016d0d9ebc
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!CallNextHookEx 0000000076e66285 5 bytes JMP 000000016d0f7ff1
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076e67603 5 bytes JMP 000000016d0d25b4
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 0000000076e7cbf3 5 bytes JMP 000000016d2291b6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000076e7cfca 5 bytes JMP 000000016d03189b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076e7f52b 5 bytes JMP 000000016d11ed14
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 0000000076e9cb0c 5 bytes JMP 000000016d229151
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 0000000076e9ce64 5 bytes JMP 000000016d22921b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 0000000076eafbd1 5 bytes JMP 000000016d2290d8
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 0000000076eafc9d 5 bytes JMP 000000016d22905f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!MessageBoxExA 0000000076eafcd6 5 bytes JMP 000000016d228ffb
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\USER32.dll!MessageBoxExW 0000000076eafcfa 5 bytes JMP 000000016d228f97
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\ole32.dll!OleLoadFromStream 0000000075546143 5 bytes JMP 000000016d229984
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString 0000000075f43e59 5 bytes JMP 000000016d229a7c
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!VariantClear 0000000075f43eae 5 bytes JMP 000000016d229afa
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen 0000000075f44731 5 bytes JMP 000000016d2299ee
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType 0000000075f45dee 5 bytes JMP 000000016d229a9a
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000075fa93ec 5 bytes JMP 000000016d2293d0
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheetW 000000007376388e 5 bytes JMP 000000016d229280
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheet 0000000073807922 5 bytes JMP 000000016d229328
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[7484] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000075db2694 5 bytes JMP 000000016d2295c8
? C:\Windows\system32\mssprxy.dll [3504] entry point in ".rdata" section 00000000733371e6
.text C:\Users\Terry\Desktop\HijackThis.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Users\Terry\Desktop\HijackThis.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077a525fd 6 bytes JMP 000000016d0f8054
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077a62a63 6 bytes JMP 000000016d09980d
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\kernel32.dll!CreateThread 00000000753e34b5 5 bytes JMP 000000016d0975e3
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076e58a29 5 bytes JMP 000000016d1003df
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!CreateWindowExA 0000000076e5d22e 5 bytes JMP 000000016d0a3643
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!EnableWindow 0000000076e62da4 5 bytes JMP 000000016d0d9ebc
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!CallNextHookEx 0000000076e66285 5 bytes JMP 000000016d0f7ff1
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076e67603 5 bytes JMP 000000016d0d25b4
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamW 0000000076e7cbf3 5 bytes JMP 000000016d2291b6
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 0000000076e7cfca 5 bytes JMP 000000016d03189b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076e7f52b 5 bytes JMP 000000016d11ed14
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!DialogBoxParamA 0000000076e9cb0c 5 bytes JMP 000000016d229151
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!DialogBoxIndirectParamA 0000000076e9ce64 5 bytes JMP 000000016d22921b
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA 0000000076eafbd1 5 bytes JMP 000000016d2290d8
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW 0000000076eafc9d 5 bytes JMP 000000016d22905f
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!MessageBoxExA 0000000076eafcd6 5 bytes JMP 000000016d228ffb
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\USER32.dll!MessageBoxExW 0000000076eafcfa 5 bytes JMP 000000016d228f97
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\ole32.dll!OleLoadFromStream 0000000075546143 5 bytes JMP 000000016d229984
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString 0000000075f43e59 5 bytes JMP 000000016d229a7c
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!VariantClear 0000000075f43eae 5 bytes JMP 000000016d229afa
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen 0000000075f44731 5 bytes JMP 000000016d2299ee
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType 0000000075f45dee 5 bytes JMP 000000016d229a9a
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\OLEAUT32.dll!OleCreatePropertyFrameIndirect 0000000075fa93ec 5 bytes JMP 000000016d2293d0
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b51465 2 bytes [B5, 75]
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b514bb 2 bytes [B5, 75]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheetW 000000007376388e 5 bytes JMP 000000016d229280
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll !PropertySheet 0000000073807922 5 bytes JMP 000000016d229328
.text C:\Program Files (x86)\Internet Explorer\iexplore.exe[5364] C:\Windows\syswow64\comdlg32.dll!PageSetupDlgW 0000000075db2694 5 bytes JMP 000000016d2295c8
---- Kernel IAT/EAT - GMER 2.1 ----
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD3Transition] [fffff80000bc1808] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD0Transition] [fffff80000bc17fc] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdReceivePacket] [fffff80000bc1844] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSendPacket] [fffff80000bc1838] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdRestore] [fffff80000bc182c] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSave] [fffff80000bc1820] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize0] [fffff80000bc1814] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize1] [fffff80000bc11a0] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\hal.dll[KDCOM.dll!KdRestore] [fffff80000bc182c] \SystemRoot\system32\kdcom.dll [.text]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!HalPrivateDispatchTable] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!atol] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KeFindConfigurationEntry] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!MmMapIoSpace] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!_strupr] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!InbvDisplayString] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KdDebuggerNotPresent] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!strstr] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KeBugCheckEx] [?]
IAT C:\Windows\system32\kdcom.dll[HAL.dll!HalQueryRealTimeClock] [?]
IAT C:\Windows\system32\kdcom.dll[HAL.dll!KdComPortInUse] [?]
---- Devices - GMER 2.1 ----
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 fffffa80065510a8
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\90004eacc110
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\90004ebd26ee
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\90004eacc110 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\90004ebd26ee (not active ControlSet)
---- EOF - GMER 2.1 ----
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Terry\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sn127w.snt127.mail.live.com/d...x?n=1140128836
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKLM\..\RunOnce: [OTL] "C:\Users\Terry\Desktop\OTL.exe"
O4 - HKCU\..\Run: [Google] rundll32 "C:\Users\Terry\AppData\Local\Adobe\Google\ngcooj.dll",ReportInitModule
O4 - HKCU\..\Run: [Wal-Mart] RunDLL32.exe C:\Users\Terry\AppData\Local\Wal-Mart\knhbmzwl.dll,cpwqyxppnyclrw
O4 - Startup: PalTalk.lnk = C:\Program Files (x86)\Paltalk Messenger\paltalk.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files (x86)\Paltalk Messenger\Paltalk.exe
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Oasis2Service - Digital Delivery Networks, Inc. - C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater15.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11451 bytes
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16483 BrowserJavaVersion: 10.5.0
Run by Terry at 12:34:52 on 2013-06-06
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3943.2358 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe
C:\Program Files\Sony\VAIO Care\VCPerfService.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
C:\Program Files\Sony\VAIO Power Management\SPMService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Sony\VAIO Care\VCService.exe
C:\Windows\System32\vds.exe
C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files (x86)\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe
C:\Windows\explorer.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
C:\Windows\system32\SearchFilterHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://sn127w.snt127.mail.live.com/default.aspx?rru=home&livecom=1#!/mail/InboxLight.aspx?n=1140128836
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [Google] rundll32 "C:\Users\Terry\AppData\Local\Adobe\Google\ngcooj.dll",ReportInitModule
uRun: [Wal-Mart] RunDLL32.exe C:\Users\Terry\AppData\Local\Wal-Mart\knhbmzwl.dll,cpwqyxppnyclrw
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRunOnce: [OTL] "C:\Users\Terry\Desktop\OTL.exe"
StartupFolder: C:\Users\Terry\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\P alTalk.lnk - C:\Program Files (x86)\Paltalk Messenger\paltalk.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files (x86)\Paltalk Messenger\Paltalk.exe
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{3F747C83-41C4-47E8-9CF0-8BBA4962DDBC} : DHCPNameServer = 10.100.94.2
TCP: Interfaces\{EB1B8362-52EB-4CE4-8682-12BD09942A38} : DHCPNameServer = 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
x64-BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-4-19 28480]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-1-31 36944]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-11-8 307040]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-12-23 47696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-4-11 384800]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-11-8 45856]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-8 73376]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-4-28 13336]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-13 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-13 701512]
R2 Oasis2Service;Oasis2Service;C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe [2012-11-13 60416]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]
R2 rimspci;rimspci;C:\Windows\System32\drivers\rimssne64.sys [2011-2-21 102400]
R2 risdsnpe;risdsnpe;C:\Windows\System32\drivers\risdsnxc64.sys [2011-2-21 98816]
R2 SampleCollector;VAIO Care Performance Service;C:\Program Files\Sony\VAIO Care\VCPerfService.exe [2011-4-28 259192]
R2 uCamMonitor;CamMonitor;C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2011-4-28 105024]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-4-28 2656280]
R2 VAIO Power Management;VAIO Power Management;C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2011-4-28 550080]
R2 VCFw;VAIO Content Folder Watcher;C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2011-1-20 887000]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2011-2-19 546608]
R2 VSNService;VSNService;C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [2011-4-28 852160]
R2 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [2013-5-20 1015984]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [2011-4-28 19968]
R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-8 36000]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-12-10 127328]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\avgidsfiltera.sys [2011-12-23 29776]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-8 259232]
R3 btath_avdt;Atheros Bluetooth AVDT Service;C:\Windows\System32\drivers\btath_avdt.sys [2011-3-8 109216]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-8 29344]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-8 166048]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-8 59040]
R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-8 283296]
R3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-8 286880]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-4-1 317440]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-8-8 25928]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-12-10 181248]
R3 NWLowRider;NextWindow LowRider Touch Screen;C:\Windows\System32\drivers\NWLowRider.sys [2011-2-21 26176]
R3 NWWakeFilterLR;NextWindow Remote Wake Blocker;C:\Windows\System32\drivers\NWWakeFilterLR.sys [2011-2-21 14400]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-2-21 413800]
R3 SFEP;Sony Firmware Extension Parser;C:\Windows\System32\drivers\SFEP.sys [2010-6-1 12032]
R3 SpfService;VAIO Entertainment Common Service;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [2011-1-20 286936]
R3 VCService;VCService;C:\Program Files\Sony\VAIO Care\VCService.exe [2011-4-28 44736]
R3 VUAgent;VUAgent;C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [2011-4-28 1021112]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-8 138400]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-11-2 5174392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 ATHDFU;Atheros Valkyrie USB BootROM;C:\Windows\System32\drivers\AthDfu.sys [2011-3-8 51872]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\System32\drivers\e1y60x64.sys [2009-6-10 281088]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-8-18 57280]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-7-28 1511872]
S3 hidkmdf;Microsoft HID Class Shim for KMDF;C:\Windows\System32\drivers\hidkmdf.sys [2011-2-21 14400]
S3 SOHCImp;VAIO Content Importer;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2011-2-21 113824]
S3 SOHDs;VAIO Device Searcher;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2011-2-21 67232]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2011-2-19 385336]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2011-2-19 99104]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-5-8 1255736]
.
=============== Created Last 30 ================
.
2013-06-06 17:14:39 -------- d-----w- C:\Windows\ERUNT
2013-06-06 17:14:26 -------- d-----w- C:\JRT
2013-06-06 17:05:14 -------- d-----w- C:\_OTL
2013-06-06 16:56:56 -------- d-sh--w- C:\$RECYCLE.BIN
2013-06-06 16:31:53 -------- d-s---w- C:\iexplore.exe
2013-06-05 14:38:34 -------- d-sh--w- C:\found.000
2013-05-18 03:09:44 -------- d-----w- C:\Users\Terry\AppData\Local\Programs
2013-05-16 08:02:14 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-05-16 08:02:13 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
==================== Find3M ====================
.
2013-05-20 15:43:25 45856 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys
2013-05-15 15:40:54 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-15 15:40:54 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-11 08:18:40 384800 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-04-05 01:08:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-04-05 01:00:30 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-04-05 00:59:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-04-05 00:56:16 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-04-05 00:55:47 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-04-04 22:11:34 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-04-04 22:02:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-04-04 22:02:17 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-04-04 21:58:51 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-04-04 21:57:45 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-04-04 19:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-03-19 05:53:58 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
2013-03-19 05:53:58 230400 ----a-w- C:\Windows\System32\wwansvc.dll
2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe
.
============= FINISH: 12:35:25.59 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 5/6/2012 10:20:23 AM
System Uptime: 6/6/2013 11:56:00 AM (1 hours ago)
.
Motherboard: Sony Corporation | | VAIO
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz | N/A | 2100/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 455 GiB total, 408.85 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP74: 5/10/2013 12:25:22 AM - Scheduled Checkpoint
RP75: 5/16/2013 3:00:26 AM - Windows Update
RP76: 5/23/2013 8:19:56 AM - Scheduled Checkpoint
RP77: 6/1/2013 7:38:30 AM - Scheduled Checkpoint
RP78: 6/6/2013 11:32:28 AM - ComboFix created restore point
.
==== Installed Programs ======================
.
4500_G510af_Help
4500G510af
4500G510af_Software_Min
64 Bit HP CIO Components Installer
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X MUI
Application Manager for VAIO
ArcSoft Family Paint
ArcSoft Magic-i Visual Effects 2
ArcSoft PhotoImpression 5
ArcSoft WebCam Companion 4
ArcSoft WebCam Message Board
AVG 2012
AVG Security Toolbar
Bing Maps 3D
Bluetooth Win7 Suite (64)
BufferChm
D3DX10
Destinations
DeviceDiscovery
DocMgr
DocProc
FastStone Image Viewer 4.6
Fax
Google Earth
GPBaseService2
HP Customer Participation Program 13.0
HP Document Manager 2.0
HP Imaging Device Functions 13.0
HP Officejet 4500 G510a-f
HP Smart Web Printing 4.5
HP Solution Center 13.0
HP Update
HPProductAssistant
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Java Auto Updater
Java(TM) 6 Update 22
Java(TM) 6 Update 22 (64-bit)
Java(TM) 7 Update 5
Java(TM) 7 Update 5 (64-bit)
Junk Mail filter update
Malwarebytes Anti-Malware version 1.75.0.1300
MarketResearch
Media Gallery
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft SkyDrive
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft Touch Pack for Windows 7
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft XNA Framework Redistributable 3.0
Movie Maker
MSVCRT
MSVCRT_amd64
MSVCRT110
MSVCRT110_amd64
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2721691)
MSXML 4.0 SP3 Parser (KB2758694)
MSXML 4.0 SP3 Parser (KB973685)
Oasis2Service
OCR Software by I.R.I.S. 13.0
OOBE
Paltalk Messenger 10.3
Photo Common
Photo Gallery
PlayReady PC Runtime amd64
PMB
PMB VAIO Edition Guide
PMB VAIO Edition Plug-in
Realtek High Definition Audio Driver
Remote Keyboard
Remote Play with PlayStation 3
Renesas Electronics USB 3.0 Host Controller Driver
Scan
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
SmartWebPrinting
SolutionCenter
Sony Corporation
SSLx64
SSLx86
Status
Toolbox
TrayApp
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VAIO - Media Gallery
VAIO - PMB VAIO Edition Guide
VAIO - PMB VAIO Edition Plug-in
VAIO - Remote Keyboard
VAIO - Remote Play with PlayStation®3
VAIO Care
VAIO Control Center
VAIO Data Restore Tool
VAIO Easy Connect
VAIO Event Service
VAIO Gate
VAIO Gate Default
VAIO Hardware Diagnostics
VAIO Help and Support
VAIO Improvement
VAIO Manual
VAIO Messenger
VAIO Quick Web Access
VAIO Sample Contents
VAIO Satisfaction Survey.
VAIO Smart Network
VAIO Touch Portal
VAIO Transfer Support
VAIO Update
VCCx86
VESx64
VESx86
Visual Studio 2008 x64 Redistributables
Visual Studio 2010 x64 Redistributables
VIx64
VIx86
VPMx64
VSNx64
VTPX86
VWSTx86
WebReg
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
6/6/2013 12:30:06 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
6/6/2013 12:30:06 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error: An instance of the service is already running.
6/6/2013 12:29:06 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7034] - The Application Information service terminated unexpectedly. It has done this 1 time(s).
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Secondary Logon service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Remote Access Connection Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/6/2013 12:28:06 PM, Error: Service Control Manager [7000] - The Computer Browser service failed to start due to the following error: The pipe has been ended.
.
==== End Of File ===========================