To start off with you guys are a beast! Years back someone here who was made of pure awesomeness saved both me and my dying computer. So thank you for you hard work.
";"D:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx";"Virus identified Worm/Downadup";"Moved to Virus Vault"
DDS log that was previously requested due to my lack of investigation:
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 2:12:43 on 2012-07-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1918.985 [GMT -7:00]
.
AV: AVG Internet Security Business Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security Business Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Internet Security Business Edition 2012 *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\TRENDnet\TEW-421PC_TEW-423PI\WlanCU.exe
C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG2012\avgui.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
mWinlogon: Userinit=userinit.exe
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WIRELE~1.LNK - C:\Program Files\TRENDnet\TEW-421PC_TEW-423PI\WlanCU.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
TCP: DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{1EEDA798-E924-4A11-BB2F-A76B7ADF9AD1} : DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{2B34A124-1301-48A1-9D9D-472578B6EFCD} : DhcpNameServer = 192.168.0.1 [removed]
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys --> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgfwfd;AVG network filter service;C:\Windows\system32\DRIVERS\avgfwd6a.sys --> C:\Windows\system32\DRIVERS\avgfwd6a.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2012\avgfws.exe [2012-6-13 2321560]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-6-13 5161080]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-6-29 654408]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys --> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys --> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 RTL85n64;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;C:\Windows\system32\DRIVERS\RTL85n64.sys --> C:\Windows\system32\DRIVERS\RTL85n64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-6-29 257224]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-07-03 02:21:22 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-07-03 02:20:19 -------- d-----w- C:\Users\Esc\AppData\Roaming\uTorrent
2012-07-02 02:35:02 -------- d-----w- C:\Users\Esc\AppData\Local\Diagnostics
2012-07-01 21:05:30 2061928 ----a-w- C:\Windows\System32\drivers\RTL85n64.sys
2012-07-01 21:05:30 -------- d-----w- C:\Program Files\TRENDnet
2012-06-30 08:51:34 -------- d-----w- C:\ProgramData\Blizzard Entertainment
2012-06-30 05:34:58 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2012-06-30 05:34:02 -------- d-----w- C:\ProgramData\Blizzard
2012-06-30 05:17:11 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-30 05:17:11 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-30 04:52:38 -------- d-----w- C:\Users\Esc\AppData\Roaming\AVG2012
2012-06-30 04:52:22 -------- d--h--w- C:\ProgramData\Common Files
2012-06-30 04:52:06 -------- d-----w- C:\Windows\SysWow64\drivers\AVG
2012-06-30 04:50:40 -------- d-----w- C:\Windows\System32\drivers\AVG
2012-06-30 04:50:40 -------- d-----w- C:\ProgramData\AVG2012
2012-06-30 04:50:31 -------- d-----w- C:\Users\Esc\AppData\Roaming\Malwarebytes
2012-06-30 04:50:17 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-30 04:50:17 -------- d-----w- C:\ProgramData\Malwarebytes
2012-06-30 04:50:17 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-30 04:49:18 -------- d-----w- C:\Program Files (x86)\AVG
2012-06-30 04:42:31 -------- d-----w- C:\ProgramData\MFAData
2012-06-30 03:59:59 -------- d-----w- C:\Windows\SysWow64\Wat
2012-06-30 03:59:58 -------- d-----w- C:\Windows\System32\Wat
2012-06-30 03:58:47 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2012-06-30 03:58:39 -------- d-----w- C:\Program Files\NVIDIA Corporation
2012-06-30 03:50:11 902656 ----a-w- C:\Windows\System32\d2d1.dll
2012-06-30 03:50:11 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2012-06-30 03:50:11 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2012-06-30 02:48:13 -------- d-----w- C:\Windows\Panther
2012-06-30 02:38:59 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-06-30 02:38:59 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-06-30 02:38:59 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-06-30 02:38:59 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-06-30 02:38:59 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-06-30 02:38:59 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-06-30 02:38:59 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-06-30 02:33:49 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-06-30 02:32:39 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-06-30 02:31:57 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-06-30 02:30:58 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-06-30 02:30:58 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-06-30 02:30:46 723456 ----a-w- C:\Windows\System32\EncDec.dll
2012-06-30 02:30:45 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2012-06-30 02:30:42 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2012-06-30 02:30:41 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-06-30 02:30:40 974336 ----a-w- C:\Windows\System32\WFS.exe
2012-06-30 02:30:40 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2012-06-30 02:30:39 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2012-06-30 02:30:39 31232 ----a-w- C:\Windows\System32\prevhost.exe
2012-06-30 02:29:06 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-06-30 02:29:06 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-06-30 02:26:49 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-06-30 02:26:49 2164224 ----a-w- C:\Program Files\Windows Journal\Journal.exe
2012-06-30 02:26:49 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2012-06-30 02:26:49 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-06-30 02:26:48 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2012-06-30 02:26:48 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2012-06-30 02:21:26 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-06-30 02:21:26 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2012-06-30 02:21:26 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2012-06-30 02:21:25 288640 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-06-30 02:20:26 77312 ----a-w- C:\Windows\System32\packager.dll
2012-06-30 02:20:25 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-06-30 02:19:16 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-06-30 02:19:16 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-06-30 02:19:16 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-06-30 02:15:25 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-30 02:15:19 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-30 02:15:13 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-30 02:15:13 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-30 02:10:12 -------- d-----w- C:\Program Files (x86)\TRENDnet
2012-06-30 02:09:42 -------- d-sh--w- C:\Windows\Installer
2012-06-29 16:24:40 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-06-29 16:24:40 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-06-29 15:47:09 -------- d-----w- C:\Windows\System32\SPReview
2012-06-29 15:43:58 98304 ----a-w- C:\Windows\SysWow64\nslookup.exe
2012-06-29 15:40:41 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2012-06-29 15:39:56 501248 ----a-w- C:\Windows\System32\WinSATAPI.dll
2012-06-29 15:38:59 156160 ----a-w- C:\Windows\System32\prntvpt.dll
2012-06-29 15:37:59 89088 ----a-w- C:\Windows\System32\amstream.dll
2012-06-29 14:11:26 -------- d-----w- C:\Windows\System32\EventProviders
2012-06-29 13:49:59 849920 ----a-w- C:\Windows\System32\qmgr.dll
2012-06-29 13:48:59 769536 ----a-w- C:\Windows\System32\sud.dll
2012-06-29 13:47:59 457216 ----a-w- C:\Windows\System32\imkr80.ime
2012-06-29 13:45:18 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2012-06-29 13:45:13 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2012-06-29 13:21:10 2565632 ----a-w- C:\Windows\System32\esent.dll
2012-06-29 13:21:10 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-06-29 13:21:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2012-06-29 13:21:08 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2012-06-29 13:21:08 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2012-06-29 13:21:07 96768 ----a-w- C:\Windows\System32\fsutil.exe
2012-06-29 13:21:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2012-06-29 13:21:07 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2012-06-29 13:21:07 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2012-06-29 13:21:07 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2012-06-29 13:21:07 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2012-06-29 13:12:52 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2012-06-29 13:12:51 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2012-06-29 13:12:51 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2012-06-29 13:12:51 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2012-06-29 13:12:51 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2012-06-29 13:12:51 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2012-06-29 13:12:51 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2012-06-23 04:43:28 -------- d--h--w- C:\$AVG
2012-06-21 21:38:57 -------- d-sh--w- C:\Recovery
.
==================== Find3M ====================
.
2012-06-29 15:54:41 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2012-06-29 15:54:40 175616 ----a-w- C:\Windows\System32\msclmd.dll
2012-05-15 01:32:33 3146752 ----a-w- C:\Windows\System32\win32k.sys
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2012-04-19 11:50:26 28480 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
2012-04-07 12:31:40 3216384 ----a-w- C:\Windows\System32\msi.dll
2012-04-07 11:26:29 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
.
============= FINISH: 2:13:46.52 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 6/29/2012 7:05:35 PM
System Uptime: 7/4/2012 11:05:01 PM (3 hours ago)
.
Motherboard: Dell Inc. | | 0YP696
Processor: AMD Athlon(tm) Processor 1640B | Socket M2 | 2705/1000mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 149 GiB total, 106.241 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP13: 7/1/2012 2:03:48 PM - Configured TRENDnet TEW-421PC&TEW-423PI Wireless Adapter Vista D©gP¥¿Ì®˜_
RP14: 7/1/2012 2:05:21 PM - Installed TRENDnet 802.11g Wireless CardBus/PCI Adapter
.
==== Installed Programs ======================
.
µTorrent
Adobe Flash Player 11 ActiveX
Malwarebytes Anti-Malware version 1.61.0.1400
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
TRENDnet 802.11g Wireless CardBus/PCI Adapter
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Visual Studio 2008 x64 Redistributables
World of Warcraft
.
==== Event Viewer Messages From Past Week ========
.
7/4/2012 11:05:44 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom
7/2/2012 1:00:32 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the AVG Firewall service to connect.
7/2/2012 1:00:32 PM, Error: Service Control Manager [7000] - The AVG Firewall service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/2/2012 1:00:01 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the AVGIDSAgent service to connect.
7/2/2012 1:00:01 PM, Error: Service Control Manager [7000] - The AVGIDSAgent service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/1/2012 1:46:22 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff800029e4372, 0xfffff88002f93698, 0xfffff88002f92ef0). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 070112-34897-01.
6/29/2012 9:28:13 AM, Error: Service Control Manager [7023] - The Windows Modules Installer service terminated with the following error: The process cannot access the file because it is being used by another process.
6/29/2012 8:48:04 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Windows 7 for x64-based Systems (KB2703157).
6/29/2012 8:48:04 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Internet Explorer 8 Compatibility View List for Windows 7 for x64-based Systems (KB2598845).
6/29/2012 8:48:04 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2544521).
6/29/2012 8:46:25 PM, Error: Service Control Manager [7023] -
6/29/2012 8:41:15 PM, Error: Service Control Manager [7043] - The Windows Modules Installer service did not shut down properly after receiving a preshutdown control.
6/29/2012 8:12:56 AM, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: %%-2147416365
6/29/2012 8:07:51 AM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control.
6/29/2012 7:53:17 AM, Error: Service Control Manager [7043] - The AVGIDSAgent service did not shut down properly after receiving a preshutdown control.
6/29/2012 7:19:45 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070020: Windows 7 Service Pack 1 for x64-based Systems (KB976932).
.
==== End Of File ===========================
";"D:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx";"Virus identified Worm/Downadup";"Moved to Virus Vault"
DDS log that was previously requested due to my lack of investigation:
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 2:12:43 on 2012-07-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1918.985 [GMT -7:00]
.
AV: AVG Internet Security Business Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security Business Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Internet Security Business Edition 2012 *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\TRENDnet\TEW-421PC_TEW-423PI\WlanCU.exe
C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\AVG\AVG2012\avgui.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
mWinlogon: Userinit=userinit.exe
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WIRELE~1.LNK - C:\Program Files\TRENDnet\TEW-421PC_TEW-423PI\WlanCU.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
TCP: DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{1EEDA798-E924-4A11-BB2F-A76B7ADF9AD1} : DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{2B34A124-1301-48A1-9D9D-472578B6EFCD} : DhcpNameServer = 192.168.0.1 [removed]
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys --> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgfwfd;AVG network filter service;C:\Windows\system32\DRIVERS\avgfwd6a.sys --> C:\Windows\system32\DRIVERS\avgfwd6a.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2012\avgfws.exe [2012-6-13 2321560]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-6-13 5161080]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-6-29 654408]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys --> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys --> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 RTL85n64;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;C:\Windows\system32\DRIVERS\RTL85n64.sys --> C:\Windows\system32\DRIVERS\RTL85n64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-6-29 257224]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-07-03 02:21:22 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-07-03 02:20:19 -------- d-----w- C:\Users\Esc\AppData\Roaming\uTorrent
2012-07-02 02:35:02 -------- d-----w- C:\Users\Esc\AppData\Local\Diagnostics
2012-07-01 21:05:30 2061928 ----a-w- C:\Windows\System32\drivers\RTL85n64.sys
2012-07-01 21:05:30 -------- d-----w- C:\Program Files\TRENDnet
2012-06-30 08:51:34 -------- d-----w- C:\ProgramData\Blizzard Entertainment
2012-06-30 05:34:58 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2012-06-30 05:34:02 -------- d-----w- C:\ProgramData\Blizzard
2012-06-30 05:17:11 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-30 05:17:11 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-30 04:52:38 -------- d-----w- C:\Users\Esc\AppData\Roaming\AVG2012
2012-06-30 04:52:22 -------- d--h--w- C:\ProgramData\Common Files
2012-06-30 04:52:06 -------- d-----w- C:\Windows\SysWow64\drivers\AVG
2012-06-30 04:50:40 -------- d-----w- C:\Windows\System32\drivers\AVG
2012-06-30 04:50:40 -------- d-----w- C:\ProgramData\AVG2012
2012-06-30 04:50:31 -------- d-----w- C:\Users\Esc\AppData\Roaming\Malwarebytes
2012-06-30 04:50:17 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-30 04:50:17 -------- d-----w- C:\ProgramData\Malwarebytes
2012-06-30 04:50:17 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-30 04:49:18 -------- d-----w- C:\Program Files (x86)\AVG
2012-06-30 04:42:31 -------- d-----w- C:\ProgramData\MFAData
2012-06-30 03:59:59 -------- d-----w- C:\Windows\SysWow64\Wat
2012-06-30 03:59:58 -------- d-----w- C:\Windows\System32\Wat
2012-06-30 03:58:47 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2012-06-30 03:58:39 -------- d-----w- C:\Program Files\NVIDIA Corporation
2012-06-30 03:50:11 902656 ----a-w- C:\Windows\System32\d2d1.dll
2012-06-30 03:50:11 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2012-06-30 03:50:11 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2012-06-30 02:48:13 -------- d-----w- C:\Windows\Panther
2012-06-30 02:38:59 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-06-30 02:38:59 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-06-30 02:38:59 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-06-30 02:38:59 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-06-30 02:38:59 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-06-30 02:38:59 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-06-30 02:38:59 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-06-30 02:33:49 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-06-30 02:32:39 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-06-30 02:31:57 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-06-30 02:30:58 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-06-30 02:30:58 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-06-30 02:30:46 723456 ----a-w- C:\Windows\System32\EncDec.dll
2012-06-30 02:30:45 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2012-06-30 02:30:42 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2012-06-30 02:30:41 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-06-30 02:30:40 974336 ----a-w- C:\Windows\System32\WFS.exe
2012-06-30 02:30:40 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2012-06-30 02:30:39 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2012-06-30 02:30:39 31232 ----a-w- C:\Windows\System32\prevhost.exe
2012-06-30 02:29:06 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-06-30 02:29:06 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-06-30 02:26:49 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-06-30 02:26:49 2164224 ----a-w- C:\Program Files\Windows Journal\Journal.exe
2012-06-30 02:26:49 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2012-06-30 02:26:49 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-06-30 02:26:48 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2012-06-30 02:26:48 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2012-06-30 02:21:26 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-06-30 02:21:26 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2012-06-30 02:21:26 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2012-06-30 02:21:25 288640 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-06-30 02:20:26 77312 ----a-w- C:\Windows\System32\packager.dll
2012-06-30 02:20:25 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-06-30 02:19:16 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-06-30 02:19:16 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-06-30 02:19:16 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-06-30 02:15:25 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-30 02:15:19 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-30 02:15:13 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-30 02:15:13 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-30 02:10:12 -------- d-----w- C:\Program Files (x86)\TRENDnet
2012-06-30 02:09:42 -------- d-sh--w- C:\Windows\Installer
2012-06-29 16:24:40 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-06-29 16:24:40 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-06-29 15:47:09 -------- d-----w- C:\Windows\System32\SPReview
2012-06-29 15:43:58 98304 ----a-w- C:\Windows\SysWow64\nslookup.exe
2012-06-29 15:40:41 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2012-06-29 15:39:56 501248 ----a-w- C:\Windows\System32\WinSATAPI.dll
2012-06-29 15:38:59 156160 ----a-w- C:\Windows\System32\prntvpt.dll
2012-06-29 15:37:59 89088 ----a-w- C:\Windows\System32\amstream.dll
2012-06-29 14:11:26 -------- d-----w- C:\Windows\System32\EventProviders
2012-06-29 13:49:59 849920 ----a-w- C:\Windows\System32\qmgr.dll
2012-06-29 13:48:59 769536 ----a-w- C:\Windows\System32\sud.dll
2012-06-29 13:47:59 457216 ----a-w- C:\Windows\System32\imkr80.ime
2012-06-29 13:45:18 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2012-06-29 13:45:13 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2012-06-29 13:21:10 2565632 ----a-w- C:\Windows\System32\esent.dll
2012-06-29 13:21:10 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-06-29 13:21:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2012-06-29 13:21:08 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2012-06-29 13:21:08 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2012-06-29 13:21:07 96768 ----a-w- C:\Windows\System32\fsutil.exe
2012-06-29 13:21:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2012-06-29 13:21:07 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2012-06-29 13:21:07 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2012-06-29 13:21:07 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2012-06-29 13:21:07 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2012-06-29 13:12:52 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2012-06-29 13:12:51 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2012-06-29 13:12:51 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2012-06-29 13:12:51 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2012-06-29 13:12:51 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2012-06-29 13:12:51 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2012-06-29 13:12:51 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2012-06-23 04:43:28 -------- d--h--w- C:\$AVG
2012-06-21 21:38:57 -------- d-sh--w- C:\Recovery
.
==================== Find3M ====================
.
2012-06-29 15:54:41 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2012-06-29 15:54:40 175616 ----a-w- C:\Windows\System32\msclmd.dll
2012-05-15 01:32:33 3146752 ----a-w- C:\Windows\System32\win32k.sys
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2012-04-19 11:50:26 28480 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
2012-04-07 12:31:40 3216384 ----a-w- C:\Windows\System32\msi.dll
2012-04-07 11:26:29 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
.
============= FINISH: 2:13:46.52 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 6/29/2012 7:05:35 PM
System Uptime: 7/4/2012 11:05:01 PM (3 hours ago)
.
Motherboard: Dell Inc. | | 0YP696
Processor: AMD Athlon(tm) Processor 1640B | Socket M2 | 2705/1000mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 149 GiB total, 106.241 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP13: 7/1/2012 2:03:48 PM - Configured TRENDnet TEW-421PC&TEW-423PI Wireless Adapter Vista D©gP¥¿Ì®˜_
RP14: 7/1/2012 2:05:21 PM - Installed TRENDnet 802.11g Wireless CardBus/PCI Adapter
.
==== Installed Programs ======================
.
µTorrent
Adobe Flash Player 11 ActiveX
Malwarebytes Anti-Malware version 1.61.0.1400
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
TRENDnet 802.11g Wireless CardBus/PCI Adapter
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Visual Studio 2008 x64 Redistributables
World of Warcraft
.
==== Event Viewer Messages From Past Week ========
.
7/4/2012 11:05:44 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom
7/2/2012 1:00:32 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the AVG Firewall service to connect.
7/2/2012 1:00:32 PM, Error: Service Control Manager [7000] - The AVG Firewall service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/2/2012 1:00:01 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the AVGIDSAgent service to connect.
7/2/2012 1:00:01 PM, Error: Service Control Manager [7000] - The AVGIDSAgent service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/1/2012 1:46:22 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff800029e4372, 0xfffff88002f93698, 0xfffff88002f92ef0). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 070112-34897-01.
6/29/2012 9:28:13 AM, Error: Service Control Manager [7023] - The Windows Modules Installer service terminated with the following error: The process cannot access the file because it is being used by another process.
6/29/2012 8:48:04 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Windows 7 for x64-based Systems (KB2703157).
6/29/2012 8:48:04 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Internet Explorer 8 Compatibility View List for Windows 7 for x64-based Systems (KB2598845).
6/29/2012 8:48:04 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Internet Explorer 8 for Windows 7 for x64-based Systems (KB2544521).
6/29/2012 8:46:25 PM, Error: Service Control Manager [7023] -
6/29/2012 8:41:15 PM, Error: Service Control Manager [7043] - The Windows Modules Installer service did not shut down properly after receiving a preshutdown control.
6/29/2012 8:12:56 AM, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: %%-2147416365
6/29/2012 8:07:51 AM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control.
6/29/2012 7:53:17 AM, Error: Service Control Manager [7043] - The AVGIDSAgent service did not shut down properly after receiving a preshutdown control.
6/29/2012 7:19:45 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070020: Windows 7 Service Pack 1 for x64-based Systems (KB976932).
.
==== End Of File ===========================