Hello again. this morning my comp was getting weird error;
"Error loading hpvcp.dll The specific module could not be found."
So I left malwarebytes running while I was away and it seems to have picked whatever it was. I scanned with everything again just to be safe. could you take a look at the logs please?
Malwarebytes' Anti-Malware 1.46
Malwarebytes
Database version: 4234
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/23/2010 7:02:38 AM
mbam-log-2010-07-23 (07-02-38).txt
Scan type: Full scan (C:\|)
Objects scanned: 393415
Time elapsed: 2 hour(s), 40 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 8
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adgj.aghlp (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adgj.aghlp.1 (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93179be5-9cdb-4ce4-94e2-42ff4b929a5c} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{93179be5-9cdb-4ce4-94e2-42ff4b929a5c} (Adware.AdRotator) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mchk (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\LocalService\Application Data\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\Street-Ads\sta (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Paradox Entertainment\Crusader Kings\Crusaders.exe (Rogue.Crusader) -> Not selected for removal.
C:\System Volume Information\_restore{F8796A5D-162E-472F-9610-50B325A26B99}\RP26\A0004227.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8796A5D-162E-472F-9610-50B325A26B99}\RP26\A0004229.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8796A5D-162E-472F-9610-50B325A26B99}\RP19\A0003427.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Update\seupd.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$\zrpt.xml (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpvcp.dll (Adware.AdRotator) -> Quarantined and deleted successfully.
logs
ComboFix 10-07-22.06 - Mike 07/23/2010 14:58:16.15.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.404 [GMT -4:00]
Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.
2010-07-23 11:53 . 2004-08-07 00:17 4224 -c--a-w- c:\windows\system32\dllcache\rdpcdd.sys
2010-07-23 11:53 . 2004-08-07 00:17 4224 ----a-w- c:\windows\system32\drivers\RDPCDD.sys
2010-07-23 03:09 . 2010-07-23 03:09 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2010-07-23 03:07 . 2010-07-23 19:07 766976 ----a-w- c:\windows\system32\drivers\gdwqaj.sys
2010-07-23 03:07 . 2010-07-23 11:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Update
2010-07-23 03:06 . 2010-07-23 03:11 -------- d-----w- c:\documents and settings\Mike\Application Data\C8687F969A494E736FF0EDE49A00E961
2010-07-22 02:57 . 2010-07-23 03:18 -------- d-----w- c:\program files\The Guild 2 - Demo
2010-07-21 12:58 . 2010-07-21 12:58 1615200 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssie.dll
2010-07-21 12:58 . 2010-07-21 12:58 4368224 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-07-21 12:58 . 2010-07-21 12:58 1373536 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssff.dll
2010-07-21 12:58 . 2010-07-21 12:58 1107296 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgxpl.dll
2010-07-16 13:56 . 2010-07-16 13:56 2332000 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-07-14 12:56 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-01 01:55 . 2010-07-01 01:55 -------- d-----w- c:\program files\iPod
2010-07-01 01:54 . 2010-07-01 01:56 -------- d-----w- c:\program files\iTunes
2010-07-01 01:47 . 2010-07-01 01:47 -------- d-----w- c:\program files\Bonjour
2010-07-01 01:40 . 2010-07-01 01:40 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-29 14:37 . 2010-06-29 14:37 1039712 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 18:55 . 2010-06-19 11:52 0 ----a-w- c:\documents and settings\Mike\Local Settings\Application Data\prvlcl.dat
2010-07-16 15:16 . 2008-02-12 00:55 -------- d-----w- c:\documents and settings\Mike\Application Data\uTorrent
2010-07-01 01:55 . 2008-03-15 15:16 -------- d-----w- c:\program files\Common Files\Apple
2010-06-30 04:15 . 2009-02-14 01:26 -------- d-----w- c:\documents and settings\Mike\Application Data\mIRC
2010-06-29 20:11 . 2009-02-14 01:26 -------- d-----w- c:\program files\mIRC
2010-06-24 22:25 . 2008-09-13 01:06 -------- d-----w- c:\program files\Paradox Entertainment
2010-06-22 13:49 . 2010-06-14 23:12 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 13:49 . 2010-06-14 23:12 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 13:49 . 2010-06-14 23:12 25168 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-06-22 13:48 . 2010-06-14 23:12 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-21 03:32 . 2010-03-21 23:03 -------- d-----w- c:\documents and settings\Mike\Application Data\Skype
2010-06-21 02:27 . 2008-01-23 17:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-20 20:03 . 2010-03-21 23:06 -------- d-----w- c:\documents and settings\Mike\Application Data\skypePM
2010-06-18 17:18 . 2009-10-06 23:49 -------- d-----w- c:\documents and settings\Mike\Application Data\gtk-2.0
2010-06-16 19:56 . 2010-06-16 19:26 -------- d-----w- c:\documents and settings\Mike\Application Data\DAEMON Tools Lite
2010-06-16 19:29 . 2010-06-16 19:26 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-06-16 19:27 . 2008-02-05 19:16 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-06-16 19:26 . 2010-06-16 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-06-14 23:26 . 2010-06-14 23:12 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-06-14 23:12 . 2010-06-14 23:12 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-06-14 23:10 . 2010-06-14 23:10 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-06-14 23:10 . 2010-06-14 23:10 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-06-14 23:09 . 2010-06-14 23:09 -------- d-----w- c:\program files\AVG
2010-06-14 23:09 . 2010-03-05 18:30 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-06-14 14:31 . 2008-01-23 16:40 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-11 19:15 . 2009-03-01 01:02 -------- d-----w- c:\documents and settings\Mike\Application Data\Malwarebytes
2010-06-11 19:15 . 2010-06-11 19:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-11 19:15 . 2009-03-01 01:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-11 18:33 . 2008-03-29 12:20 -------- d-----w- c:\program files\Google
2010-06-11 18:08 . 2008-02-02 02:51 -------- d-----w- c:\program files\SpeedFan
2010-06-11 18:07 . 2008-04-09 00:43 -------- d-----w- c:\program files\Strategy First
2010-06-11 18:05 . 2009-10-23 05:01 -------- d-----w- c:\program files\PokerStars
2010-06-11 18:04 . 2009-10-30 18:46 -------- d-----w- c:\documents and settings\Mike\Application Data\runic games
2010-06-11 17:48 . 2008-07-09 17:22 -------- d-----w- c:\program files\Digital Guitar Tuner 2.3
2010-06-11 17:46 . 2010-06-11 12:40 1217 ----a-w- c:\windows\system32\eappgfui.dat
2010-06-11 17:46 . 2010-06-11 12:40 1008 ----a-w- c:\windows\system32\mspbdel0.dat
2010-06-11 17:41 . 2010-06-11 12:40 0 ----a-w- c:\windows\system32\unaczv2c.dat
2010-06-11 17:34 . 2010-06-11 12:45 585 ----a-w- c:\windows\system32\cfgbkend.dat
2010-06-11 17:34 . 2010-06-11 12:45 896 ----a-w- c:\windows\system32\iaspolcu.dat
2010-06-11 17:33 . 2010-06-11 12:45 0 ----a-w- c:\windows\system32\mf321y.dat
2010-06-11 17:10 . 2010-06-11 12:40 318 ----a-w- c:\windows\system32\adptihps.dat
2010-06-05 03:17 . 2008-01-23 18:14 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-28 22:57 . 2009-12-12 04:43 -------- d-----w- c:\program files\Free Easy Burner
2010-05-28 21:31 . 2010-01-10 03:39 -------- d-----w- c:\program files\Children of the Nile - Enhanced Edition
2010-05-28 20:04 . 2010-05-28 20:04 -------- d-----w- c:\program files\Cheetah Burner
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-09 21:23 . 2010-04-23 13:32 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-09 20:52 . 2010-04-23 13:31 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-05-06 10:41 . 2004-08-04 04:56 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 03:17 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-06-11 19:15 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-06-11 19:15 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-25 17:33 . 2010-04-25 17:33 262144 ----a-w- C:\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= c:\documents and settings\Mike\Desktop\frontpage.swf
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-06-22 13:49 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 05:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-06-15 17:37 47408 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 20:33 141624 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 20:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-01-12 03:17 13666408 ----a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-01-12 03:17 110696 ----a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 01:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2010-04-17 10:56 394984 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-03-09 14:02 26100520 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\kav\\kav7\\setup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\Bf2_w32ded.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\Anno4.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\tools\\Anno4Web.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCPxpsp2res.dll,-22009
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [6/14/2010 7:12 PM 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [6/14/2010 7:12 PM 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/14/2010 7:12 PM 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/14/2010 7:12 PM 243024]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [6/14/2010 7:10 PM 308136]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [6/14/2010 7:26 PM 2331032]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [11/15/2009 5:58 PM 2368]
R2 WUSB54GSv2SVC;WUSB54GSv2SVC;c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [2/5/2010 5:18 PM 41025]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [6/14/2010 7:10 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [6/14/2010 7:10 PM 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [6/14/2010 7:10 PM 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [6/14/2010 7:10 PM 26192]
S2 a2AntiMalware;a-squared Anti-Malware Service;"c:\program files\a-squared Anti-Malware\a2service.exe" --> c:\program files\a-squared Anti-Malware\a2service.exe [?]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [6/22/2010 9:49 AM 5897808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate1c9f7db41a482ee;Google Update Service (gupdate1c9f7db41a482ee);c:\program files\Google\Update\GoogleUpdate.exe [6/28/2009 6:29 AM 133104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [6/14/2010 7:10 PM 30104]
S3 cpuz130;cpuz130;\??\c:\docume~1\Mike\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\Mike\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [1/20/2010 12:15 PM 23456]
S3 lgusbsmodem;LGE Mobile USB Modem;c:\windows\system32\DRIVERS\lgusbsmodem.sys --> c:\windows\system32\DRIVERS\lgusbsmodem.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/5/2008 3:16 PM 691696]
"Error loading hpvcp.dll The specific module could not be found."
So I left malwarebytes running while I was away and it seems to have picked whatever it was. I scanned with everything again just to be safe. could you take a look at the logs please?
Malwarebytes' Anti-Malware 1.46
Malwarebytes
Database version: 4234
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/23/2010 7:02:38 AM
mbam-log-2010-07-23 (07-02-38).txt
Scan type: Full scan (C:\|)
Objects scanned: 393415
Time elapsed: 2 hour(s), 40 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 8
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adgj.aghlp (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adgj.aghlp.1 (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93179be5-9cdb-4ce4-94e2-42ff4b929a5c} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{93179be5-9cdb-4ce4-94e2-42ff4b929a5c} (Adware.AdRotator) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mchk (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\LocalService\Application Data\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\Street-Ads\sta (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Paradox Entertainment\Crusader Kings\Crusaders.exe (Rogue.Crusader) -> Not selected for removal.
C:\System Volume Information\_restore{F8796A5D-162E-472F-9610-50B325A26B99}\RP26\A0004227.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8796A5D-162E-472F-9610-50B325A26B99}\RP26\A0004229.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8796A5D-162E-472F-9610-50B325A26B99}\RP19\A0003427.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Update\seupd.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$\zrpt.xml (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpvcp.dll (Adware.AdRotator) -> Quarantined and deleted successfully.
logs
ComboFix 10-07-22.06 - Mike 07/23/2010 14:58:16.15.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.404 [GMT -4:00]
Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.
2010-07-23 11:53 . 2004-08-07 00:17 4224 -c--a-w- c:\windows\system32\dllcache\rdpcdd.sys
2010-07-23 11:53 . 2004-08-07 00:17 4224 ----a-w- c:\windows\system32\drivers\RDPCDD.sys
2010-07-23 03:09 . 2010-07-23 03:09 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2010-07-23 03:07 . 2010-07-23 19:07 766976 ----a-w- c:\windows\system32\drivers\gdwqaj.sys
2010-07-23 03:07 . 2010-07-23 11:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Update
2010-07-23 03:06 . 2010-07-23 03:11 -------- d-----w- c:\documents and settings\Mike\Application Data\C8687F969A494E736FF0EDE49A00E961
2010-07-22 02:57 . 2010-07-23 03:18 -------- d-----w- c:\program files\The Guild 2 - Demo
2010-07-21 12:58 . 2010-07-21 12:58 1615200 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssie.dll
2010-07-21 12:58 . 2010-07-21 12:58 4368224 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-07-21 12:58 . 2010-07-21 12:58 1373536 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssff.dll
2010-07-21 12:58 . 2010-07-21 12:58 1107296 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgxpl.dll
2010-07-16 13:56 . 2010-07-16 13:56 2332000 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-07-14 12:56 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-01 01:55 . 2010-07-01 01:55 -------- d-----w- c:\program files\iPod
2010-07-01 01:54 . 2010-07-01 01:56 -------- d-----w- c:\program files\iTunes
2010-07-01 01:47 . 2010-07-01 01:47 -------- d-----w- c:\program files\Bonjour
2010-07-01 01:40 . 2010-07-01 01:40 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-29 14:37 . 2010-06-29 14:37 1039712 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 18:55 . 2010-06-19 11:52 0 ----a-w- c:\documents and settings\Mike\Local Settings\Application Data\prvlcl.dat
2010-07-16 15:16 . 2008-02-12 00:55 -------- d-----w- c:\documents and settings\Mike\Application Data\uTorrent
2010-07-01 01:55 . 2008-03-15 15:16 -------- d-----w- c:\program files\Common Files\Apple
2010-06-30 04:15 . 2009-02-14 01:26 -------- d-----w- c:\documents and settings\Mike\Application Data\mIRC
2010-06-29 20:11 . 2009-02-14 01:26 -------- d-----w- c:\program files\mIRC
2010-06-24 22:25 . 2008-09-13 01:06 -------- d-----w- c:\program files\Paradox Entertainment
2010-06-22 13:49 . 2010-06-14 23:12 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 13:49 . 2010-06-14 23:12 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 13:49 . 2010-06-14 23:12 25168 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-06-22 13:48 . 2010-06-14 23:12 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-21 03:32 . 2010-03-21 23:03 -------- d-----w- c:\documents and settings\Mike\Application Data\Skype
2010-06-21 02:27 . 2008-01-23 17:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-20 20:03 . 2010-03-21 23:06 -------- d-----w- c:\documents and settings\Mike\Application Data\skypePM
2010-06-18 17:18 . 2009-10-06 23:49 -------- d-----w- c:\documents and settings\Mike\Application Data\gtk-2.0
2010-06-16 19:56 . 2010-06-16 19:26 -------- d-----w- c:\documents and settings\Mike\Application Data\DAEMON Tools Lite
2010-06-16 19:29 . 2010-06-16 19:26 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-06-16 19:27 . 2008-02-05 19:16 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-06-16 19:26 . 2010-06-16 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-06-14 23:26 . 2010-06-14 23:12 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-06-14 23:12 . 2010-06-14 23:12 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-06-14 23:10 . 2010-06-14 23:10 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-06-14 23:10 . 2010-06-14 23:10 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-06-14 23:09 . 2010-06-14 23:09 -------- d-----w- c:\program files\AVG
2010-06-14 23:09 . 2010-03-05 18:30 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-06-14 14:31 . 2008-01-23 16:40 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-11 19:15 . 2009-03-01 01:02 -------- d-----w- c:\documents and settings\Mike\Application Data\Malwarebytes
2010-06-11 19:15 . 2010-06-11 19:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-11 19:15 . 2009-03-01 01:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-11 18:33 . 2008-03-29 12:20 -------- d-----w- c:\program files\Google
2010-06-11 18:08 . 2008-02-02 02:51 -------- d-----w- c:\program files\SpeedFan
2010-06-11 18:07 . 2008-04-09 00:43 -------- d-----w- c:\program files\Strategy First
2010-06-11 18:05 . 2009-10-23 05:01 -------- d-----w- c:\program files\PokerStars
2010-06-11 18:04 . 2009-10-30 18:46 -------- d-----w- c:\documents and settings\Mike\Application Data\runic games
2010-06-11 17:48 . 2008-07-09 17:22 -------- d-----w- c:\program files\Digital Guitar Tuner 2.3
2010-06-11 17:46 . 2010-06-11 12:40 1217 ----a-w- c:\windows\system32\eappgfui.dat
2010-06-11 17:46 . 2010-06-11 12:40 1008 ----a-w- c:\windows\system32\mspbdel0.dat
2010-06-11 17:41 . 2010-06-11 12:40 0 ----a-w- c:\windows\system32\unaczv2c.dat
2010-06-11 17:34 . 2010-06-11 12:45 585 ----a-w- c:\windows\system32\cfgbkend.dat
2010-06-11 17:34 . 2010-06-11 12:45 896 ----a-w- c:\windows\system32\iaspolcu.dat
2010-06-11 17:33 . 2010-06-11 12:45 0 ----a-w- c:\windows\system32\mf321y.dat
2010-06-11 17:10 . 2010-06-11 12:40 318 ----a-w- c:\windows\system32\adptihps.dat
2010-06-05 03:17 . 2008-01-23 18:14 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-28 22:57 . 2009-12-12 04:43 -------- d-----w- c:\program files\Free Easy Burner
2010-05-28 21:31 . 2010-01-10 03:39 -------- d-----w- c:\program files\Children of the Nile - Enhanced Edition
2010-05-28 20:04 . 2010-05-28 20:04 -------- d-----w- c:\program files\Cheetah Burner
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-09 21:23 . 2010-04-23 13:32 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-09 20:52 . 2010-04-23 13:31 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-05-06 10:41 . 2004-08-04 04:56 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 03:17 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-06-11 19:15 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-06-11 19:15 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-25 17:33 . 2010-04-25 17:33 262144 ----a-w- C:\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= c:\documents and settings\Mike\Desktop\frontpage.swf
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-06-22 13:49 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 05:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-06-15 17:37 47408 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 20:33 141624 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 20:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-01-12 03:17 13666408 ----a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-01-12 03:17 110696 ----a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 01:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2010-04-17 10:56 394984 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-03-09 14:02 26100520 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\kav\\kav7\\setup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\Bf2_w32ded.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\Anno4.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\tools\\Anno4Web.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCPxpsp2res.dll,-22009
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [6/14/2010 7:12 PM 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [6/14/2010 7:12 PM 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/14/2010 7:12 PM 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/14/2010 7:12 PM 243024]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [6/14/2010 7:10 PM 308136]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [6/14/2010 7:26 PM 2331032]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [11/15/2009 5:58 PM 2368]
R2 WUSB54GSv2SVC;WUSB54GSv2SVC;c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [2/5/2010 5:18 PM 41025]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [6/14/2010 7:10 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [6/14/2010 7:10 PM 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [6/14/2010 7:10 PM 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [6/14/2010 7:10 PM 26192]
S2 a2AntiMalware;a-squared Anti-Malware Service;"c:\program files\a-squared Anti-Malware\a2service.exe" --> c:\program files\a-squared Anti-Malware\a2service.exe [?]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [6/22/2010 9:49 AM 5897808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate1c9f7db41a482ee;Google Update Service (gupdate1c9f7db41a482ee);c:\program files\Google\Update\GoogleUpdate.exe [6/28/2009 6:29 AM 133104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [6/14/2010 7:10 PM 30104]
S3 cpuz130;cpuz130;\??\c:\docume~1\Mike\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\Mike\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [1/20/2010 12:15 PM 23456]
S3 lgusbsmodem;LGE Mobile USB Modem;c:\windows\system32\DRIVERS\lgusbsmodem.sys --> c:\windows\system32\DRIVERS\lgusbsmodem.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/5/2008 3:16 PM 691696]