DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 10.0.9200.16660 Run by [removed] at 14:22:39 on 2013-08-21 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2046.1159 [GMT -4:00] . AV: AVG Internet Security 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: AVG Internet Security 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} FW: AVG Internet Security 2013 *Disabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\nvvsvc.exe C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Program Files\Tablet\Wacom\WTabletServicePro.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\Dwm.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\system32\taskhost.exe C:\Program Files\AVG\AVG2013\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\SearchProtect\bin\CltMngSvc.exe C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE C:\Program Files\AVG\AVG2013\avgui.exe C:\Program Files\NETGEAR Genie\bin\NETGEARGenie.exe C:\Windows\System32\spool\drivers\w32x86\3\E_FATICUA.EXE C:\Program Files\NETGEAR Genie\bin\NETGEARGenieDaemon.exe C:\Program Files\NETGEAR Genie\bin\genie2_tray.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe C:\Program Files\Tablet\Wacom\WacomHost.exe C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Windows\System32\WUDFHost.exe C:\Windows\explorer.exe C:\Program Files\AVG\AVG2013\avgcfgex.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\svchost.exe -k HPService C:\Windows\System32\svchost.exe -k WerSvcGroup . ============== Pseudo HJT Report =============== . uStart Page = hxxp://msn.com/ BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - uRun: [NETGEARGenie] "c:\program files\netgear genie\bin\NETGEARGenie.exe" -mini -redirect uRun: [EPSON Stylus Photo R1900 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticua.exe /fu "c:\windows\temp\E_S2DF8.tmp" /EF "HKCU" mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY dRun: [SearchProtect] \SearchProtect\bin\cltmng.exe mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Lookup on Merriam Webster - c:\program files\iespell\Merriam Webster.HTM IE: Lookup on Wikipedia - c:\program files\iespell\wikipedia.HTM IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab TCP: NameServer = 192.168.1.1 TCP: Interfaces\{B7E0A25E-29FC-4F75-B750-BA0CAC543E17} : DHCPNameServer = 192.168.1.1 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - SSODL: WebCheck - . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2013-7-20 60216] R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2013-7-20 246072] R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2013-7-1 96568] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2013-7-10 39224] R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2011-5-23 50296] R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2013-7-20 208184] R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2013-3-1 22328] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2013-7-20 171320] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2013-3-21 182072] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2013-7-23 283136] R2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\searchprotect\bin\CltMngSvc.exe [2013-4-11 93984] R2 NETGEARGenieDaemon;NETGEARGenieDaemon;c:\program files\netgear genie\bin\NETGEARGenieDaemon.exe [2012-9-25 195400] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2013-1-18 383264] R2 WTabletServicePro;Wacom Professional Service;c:\program files\tablet\wacom\WTabletServicePro.exe [2013-2-11 520576] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416] R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096] R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360] R3 hidkmdf;KMDF Driver;c:\windows\system32\drivers\hidkmdf.sys [2012-6-27 11680] R3 WacHidRouter;Wacom Hid Router;c:\windows\system32\drivers\wachidrouter.sys [2012-6-27 69024] R3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\drivers\wacomrouterfilter.sys [2012-6-27 13728] S2 avgfws;AVG Firewall;c:\program files\avg\avg2013\avgfws.exe [2013-7-25 1432080] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2013-7-4 4939312] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2012-6-6 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2012-6-6 79360] S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096] S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952] S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952] S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360] S3 Spyder4;Datacolor Spyder4;c:\windows\system32\drivers\dccmtr.sys [2011-7-12 12288] S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224] S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-7-19 1343400] S4 WiselinkPro;SAMSUNG WiselinkPro Service;c:\program files\samsung\pc auto backup\WiselinkPro.exe [2012-1-18 7262263] . =============== File Associations =============== . ShellExec: PortraitProfessional.exe: open="c:\program files\portrait professional studio 10\PortraitProfessionalStudio.exe" /P "%1" . =============== Created Last 30 ================ . 2013-08-14 20:41:33 652800 ----a-w- c:\windows\system32\rpcrt4.dll 2013-08-14 20:41:23 175104 ----a-w- c:\windows\system32\wintrust.dll 2013-08-14 20:41:23 140288 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-14 20:41:23 1166848 ----a-w- c:\windows\system32\crypt32.dll 2013-08-14 20:41:23 103936 ----a-w- c:\windows\system32\cryptnet.dll 2013-08-14 20:41:12 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-08-14 20:41:11 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-08-14 20:41:11 1289096 ----a-w- c:\windows\system32\ntdll.dll 2013-08-14 20:41:08 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-14 20:41:05 2048 ----a-w- c:\windows\system32\tzres.dll 2013-08-14 20:41:01 31232 ----a-w- c:\windows\system32\drivers\tssecsrv.sys 2013-08-14 20:41:00 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-25 21:08:42 -------- d-----w- c:\users\benny\appdata\local\join.me . ==================== Find3M ==================== . 2013-08-06 19:43:21 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-08-06 19:43:21 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-07-26 03:13:24 1767936 ----a-w- c:\windows\system32\wininet.dll 2013-07-26 03:12:04 2877440 ----a-w- c:\windows\system32\jscript9.dll 2013-07-26 03:12:00 61440 ----a-w- c:\windows\system32\iesetup.dll 2013-07-26 03:12:00 109056 ----a-w- c:\windows\system32\iesysprep.dll 2013-07-26 02:49:14 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-07-26 01:59:38 71680 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-07-20 05:51:00 246072 ----a-w- c:\windows\system32\drivers\avglogx.sys 2013-07-20 05:50:56 60216 ----a-w- c:\windows\system32\drivers\avgidshx.sys 2013-07-20 05:50:56 208184 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys 2013-07-20 05:50:50 171320 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2013-07-10 05:32:40 39224 ----a-w- c:\windows\system32\drivers\avgrkx86.sys 2013-06-05 03:05:09 2347520 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 04:53:07 509440 ----a-w- c:\windows\system32\qedit.dll . ============= FINISH: 14:22:57.82 ===============