NoHotAshes
Topic Starter
I just noticed my log for my firewall activity and it is blocking thousands of IPs constantly, my first guess is im infected with something. Hopefully someone can help me clean my comp or put my mind at rest. here are my logs.
Malwarebytes' Anti-Malware 1.43
Database version: 3498
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
1/5/2010 2:03:57 PM
mbam-log-2010-01-05 (14-03-57).txt
Scan type: Quick Scan
Objects scanned: 95893
Time elapsed: 3 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
——————————————————–
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-05 14:53:53
Windows 6.0.6002 Service Pack 2
Running: gmer.exe
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a50a3d5
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xE2 0x4E 0xAF 0x8B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5A 0x1F 0xBF 0xE4 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x63 0xCB 0x96 0xA9 …
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000a3a50a3d5 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xE2 0x4E 0xAF 0x8B …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5A 0x1F 0xBF 0xE4 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x63 0xCB 0x96 0xA9 …
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-12-01.01) - NTFSX64
Run by [removed] at 15:20:08.38 on Tue 01/05/2010
Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.3062.1170 [GMT -8:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\DesktopX.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\dlbccoms.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
C:\Windows\System32\mobsync.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10d.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\msfeedssync.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Dones\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = about:blank
mLocal Page = c:\windows\syswow64\blank.htm
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files (x86)\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\16.5.0.135\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\16.5.0.135\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\16.5.0.135\coIEPlg.dll
uRun: [DAEMON Tools Lite] "c:\program files (x86)\daemon tools lite\daemon.exe" -autorun
uRun: [DesktopX] "c:\program files (x86)\stardock\object desktop\desktopx\desktopx.exe"
mRun: [DiscWizardMonitor.exe] c:\program files (x86)\seagate\discwizard\DiscWizardMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files (x86)\seagate\discwizard\TimounterMonitor.exe
mRun: [D-Link Network USB Utility] c:\program files (x86)\d-link\shareport\SharePort Network USB Utility.exe -mini
mRunOnce: [Malwarebytes' Anti-Malware] "c:\program files (x86)\malwarebytes' anti-malware\mbamgui.exe" /install /silent
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files (x86)\belkin\bluetooth software\btsendto_ie_ctx.htm
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files (x86)\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
Trusted Zone: trymedia.com\fe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.27.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/gom/receiver/tc/FMSI.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files (x86)\norton internet security\engine\16.5.0.135\CoIEPlg.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~2\common~1\stardock\mcpcore.dll
LSA: Authentication Packages = msv1_0 relog_ap
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun-x64: [Seagate Scheduler2 Service] "c:\program files (x86)\common files\seagate\schedule2\schedhlp.exe"
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe
mRun-x64: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe
================= FIREFOX ===================
FF - ProfilePath - c:\users\dones\appdata\roaming\mozilla\firefox\profiles\i2cgbi12.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files (x86)\download manager\npfpdlm.dll
FF - plugin: c:\program files (x86)\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files (x86)\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\onlive\firefoxplugin\npolgdet.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - plugin: c:\users\dones\appdata\roaming\mozilla\firefox\profiles\i2cgbi12.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 pe3ah4nb;DiRT Environment Driver (pe3ah4nb);c:\windows\system32\drivers\pe3ah4nb.sys [2007-7-19 72296]
R0 ps6ah4nb;DiRT Synchronization Driver (ps6ah4nb);c:\windows\system32\drivers\ps6ah4nb.sys [2007-7-19 102000]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1005000.087\SymEFA64.sys [2009-3-19 402992]
R1 BHDrvx64;Symantec Heuristics Driver;c:\windows\system32\drivers\nisx64\1005000.087\BHDrvx64.sys [2009-3-19 332848]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1005000.087\cchpx64.sys [2009-3-19 582704]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091230.004\IDSviA64.sys [2010-1-4 466992]
R2 dlbc_device;dlbc_device;c:\windows\system32\dlbccoms.exe -service –> c:\windows\system32\dlbccoms.exe -service [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\logmein hamachi\hamachi-2.exe [2009-10-29 1767816]
R2 Norton Internet Security;Norton Internet Security;c:\program files (x86)\norton internet security\engine\16.5.0.135\ccSvcHst.exe [2009-3-19 115560]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\common files\seagate\schedule2\schedul2.exe [2008-6-24 605464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-9-27 240232]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-26 132656]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nisx64\1005000.087\symndisv.sys [2009-3-19 46640]
S2 pr2ah4nb;DiRT Drivers Auto Removal (pr2ah4nb);c:\windows\system32\pr2ah4nb.exe svc –> c:\windows\system32\pr2ah4nb.exe svc [?]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-5-29 89920]
S3 ENTECH64;ENTECH64;c:\windows\system32\drivers\Entech64.sys [2009-1-17 12744]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys [2009-4-6 50072]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]
S4 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2009-12-18 135664]
============== File Associations ===============
JSEFile=c:\windows\syswow64\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-01-05 21:57:44 0 d—–w- C:\Cleaning Tools
2010-01-05 11:21:37 0 d—–w- c:\users\dones\appdata\roaming\Braid
2010-01-05 07:19:24 540688 —-a-w- c:\windows\system32\d3dx10_39.dll
2010-01-05 07:19:24 1942552 —-a-w- c:\windows\system32\D3DCompiler_39.dll
2010-01-05 07:19:22 4992520 —-a-w- c:\windows\system32\D3DX9_39.dll
2010-01-04 19:59:41 0 d—–w- C:\Braid
2009-12-26 11:27:17 0 d—–w- c:\windows\E4D153288C89484BB9AAF5BE9EA6D01C.TMP
2009-12-26 10:47:33 0 d—–w- c:\program files (x86)\Trine
2009-12-17 06:49:07 839680 —-a-w- c:\windows\syswow64\mkl_vml_p4.dll
2009-12-17 06:49:07 532480 —-a-w- c:\windows\syswow64\mkl_vml_p3.dll
2009-12-17 06:49:07 512000 —-a-w- c:\windows\syswow64\mkl_vml_def.dll
2009-12-17 06:49:07 3485696 —-a-w- c:\windows\syswow64\mkl_p4.dll
2009-12-17 06:49:07 2793472 —-a-w- c:\windows\syswow64\mkl_p3.dll
2009-12-17 06:49:06 2441216 —-a-w- c:\windows\syswow64\mkl_def.dll
2009-12-17 06:49:06 2174976 —-a-w- c:\windows\syswow64\mkl_lapack32.dll
2009-12-17 06:49:06 2125824 —-a-w- c:\windows\syswow64\mkl_lapack64.dll
2009-12-17 06:49:06 184320 —-a-w- c:\windows\syswow64\libguide40.dll
2009-12-17 06:48:35 809560 —-a-r- c:\windows\syswow64\tmpC5A6.tmp
2009-12-17 06:45:57 809560 —-a-r- c:\windows\syswow64\tmpC576.tmp
2009-12-16 22:22:43 0 d—–w- c:\program files (x86)\OnLive
2009-12-16 01:18:34 0 d—–w- c:\users\dones\appdata\roaming\GetRightToGo
2009-12-16 00:46:27 411368 —-a-w- c:\windows\syswow64\deploytk.dll
2009-12-16 00:46:18 149280 —-a-w- c:\windows\syswow64\javaws.exe
2009-12-16 00:46:09 145184 —-a-w- c:\windows\syswow64\javaw.exe
2009-12-16 00:45:57 145184 —-a-w- c:\windows\syswow64\java.exe
2009-12-15 20:07:28 0 d—–w- C:\DSFTP
2009-12-13 06:41:51 0 d—–w- c:\users\dones\appdata\roaming\Command and Conquer 4 Beta
2009-12-12 21:04:55 0 d—–w- c:\programdata\Electronic Arts Inc
2009-12-09 17:50:06 0 d—–w- c:\users\dones\appdata\roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
2009-12-09 08:40:15 467984 —-a-w- c:\windows\syswow64\d3dx10_39.dll
2009-12-09 08:40:15 1493528 —-a-w- c:\windows\syswow64\D3DCompiler_39.dll
2009-12-09 08:39:58 3851784 —-a-w- c:\windows\syswow64\D3DX9_39.dll
2009-12-09 08:30:34 0 d—–w- C:\Riot Games
2009-12-09 05:39:45 1347 —-a-w- c:\users\dones\AppData.lnk
2009-12-09 04:47:00 442368 —-a-w- c:\windows\system32\winhttp.dll
2009-12-09 04:44:50 620032 —-a-w- c:\windows\system32\drivers\http.sys
2009-12-09 04:44:49 33792 —-a-w- c:\windows\system32\httpapi.dll
2009-12-09 04:44:49 32768 —-a-w- c:\windows\system32\nshhttp.dll
2009-12-09 04:44:49 30720 —-a-w- c:\windows\syswow64\httpapi.dll
2009-12-09 04:44:46 24064 —-a-w- c:\windows\syswow64\nshhttp.dll
2009-12-09 01:48:56 0 d—–w- c:\users\dones\appdata\roaming\Stella
==================== Find3M ====================
2010-01-05 19:11:11 108677 —-a-w- c:\programdata\nvModes.dat
2010-01-02 10:53:11 189184 —-a-w- c:\windows\syswow64\PnkBstrB.exe
2009-12-30 22:55:06 22104 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 06:48:35 466520 —-a-w- c:\windows\system32\wrap_oal.dll
2009-12-17 06:48:35 445016 —-a-w- c:\windows\syswow64\wrap_oal.dll
2009-12-17 06:48:35 122968 —-a-w- c:\windows\system32\OpenAL32.dll
2009-12-17 06:48:35 109144 —-a-w- c:\windows\syswow64\OpenAL32.dll
2009-12-02 04:20:46 51200 —-a-w- c:\windows\inf\infpub.dat
2009-12-02 04:20:46 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-12-02 04:20:44 86016 —-a-w- c:\windows\inf\infstor.dat
2009-12-01 02:02:40 171144 —-a-w- c:\windows\syswow64\xliveinstall.dll
2009-12-01 02:02:38 72840 —-a-w- c:\windows\syswow64\xliveinstallhost.exe
2009-11-21 06:52:02 1147904 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:46:36 77312 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:46:36 132096 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:40:20 916480 —-a-w- c:\windows\syswow64\wininet.dll
2009-11-21 06:40:03 1208832 —-a-w- c:\windows\syswow64\urlmon.dll
2009-11-21 06:38:17 206848 —-a-w- c:\windows\syswow64\occache.dll
2009-11-21 06:35:43 5940736 —-a-w- c:\windows\syswow64\mshtml.dll
2009-11-21 06:35:38 594432 —-a-w- c:\windows\syswow64\msfeeds.dll
2009-11-21 06:35:38 55296 —-a-w- c:\windows\syswow64\msfeedsbs.dll
2009-11-21 06:34:58 25600 —-a-w- c:\windows\syswow64\jsproxy.dll
2009-11-21 06:34:39 71680 —-a-w- c:\windows\syswow64\iesetup.dll
2009-11-21 06:34:39 1985536 —-a-w- c:\windows\syswow64\iertutil.dll
2009-11-21 06:34:39 164352 —-a-w- c:\windows\syswow64\ieui.dll
2009-11-21 06:34:39 109056 —-a-w- c:\windows\syswow64\iesysprep.dll
2009-11-21 06:34:38 55808 —-a-w- c:\windows\syswow64\iernonce.dll
2009-11-21 06:34:38 184320 —-a-w- c:\windows\syswow64\iepeers.dll
2009-11-21 06:34:38 11069952 —-a-w- c:\windows\syswow64\ieframe.dll
2009-11-21 06:34:33 387584 —-a-w- c:\windows\syswow64\iedkcs32.dll
2009-11-21 05:07:24 162816 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-21 04:59:58 133632 —-a-w- c:\windows\syswow64\ieUnatt.exe
2009-11-21 04:59:52 173056 —-a-w- c:\windows\syswow64\ie4uinit.exe
2009-11-21 04:59:14 13312 —-a-w- c:\windows\syswow64\msfeedssync.exe
2009-11-19 02:11:56 1347584 —-a-w- c:\windows\syswow64\rapture3d_oal.dll
2009-11-06 18:59:54 15406728 —-a-w- c:\windows\syswow64\xlive.dll
2009-11-06 18:59:54 13642888 —-a-w- c:\windows\syswow64\xlivefnt.dll
2009-11-01 21:11:20 17686528 —-a-w- c:\windows\syswow64\mkl_blueripple.dll
2009-10-30 08:45:30 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-10-29 09:36:50 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-29 09:17:42 2048 —-a-w- c:\windows\syswow64\tzres.dll
2009-10-28 19:32:32 809560 —-a-r- c:\windows\syswow64\tmpE3D8.tmp
2009-10-28 19:32:32 809560 —-a-r- c:\windows\syswow64\tmpE3B8.tmp
2009-10-23 18:45:43 75064 —-a-w- c:\windows\syswow64\PnkBstrA.exe
2009-10-23 18:45:43 2395944 —-a-w- c:\windows\syswow64\pbsvc_heroes.exe
2009-10-08 21:08:04 736256 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08:01 555520 —-a-w- c:\windows\syswow64\UIAutomationCore.dll
2009-10-08 21:08:01 234496 —-a-w- c:\windows\syswow64\oleacc.dll
2009-10-08 21:07:59 4096 —-a-w- c:\windows\syswow64\oleaccrc.dll
2009-10-08 21:07:58 315904 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07:54 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2008-01-21 03:18:21 174 –sha-w- c:\program files\desktop.ini
2008-01-21 03:18:21 174 –sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:10:25 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:10:25 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:10:25 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:10:25 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 15:21:11.41 ===============
Malwarebytes' Anti-Malware 1.43
Database version: 3498
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
1/5/2010 2:03:57 PM
mbam-log-2010-01-05 (14-03-57).txt
Scan type: Quick Scan
Objects scanned: 95893
Time elapsed: 3 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
——————————————————–
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-05 14:53:53
Windows 6.0.6002 Service Pack 2
Running: gmer.exe
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000a3a50a3d5
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xE2 0x4E 0xAF 0x8B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5A 0x1F 0xBF 0xE4 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x63 0xCB 0x96 0xA9 …
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000a3a50a3d5 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xE2 0x4E 0xAF 0x8B …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5A 0x1F 0xBF 0xE4 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x63 0xCB 0x96 0xA9 …
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-12-01.01) - NTFSX64
Run by [removed] at 15:20:08.38 on Tue 01/05/2010
Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.3062.1170 [GMT -8:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
C:\Program Files (x86)\Stardock\Object Desktop\DesktopX\DesktopX.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files (x86)\D-Link\SharePort\SharePort Network USB Utility.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\dlbccoms.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
C:\Windows\System32\mobsync.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10d.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\msfeedssync.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Dones\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = about:blank
mLocal Page = c:\windows\syswow64\blank.htm
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files (x86)\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\16.5.0.135\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\16.5.0.135\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\16.5.0.135\coIEPlg.dll
uRun: [DAEMON Tools Lite] "c:\program files (x86)\daemon tools lite\daemon.exe" -autorun
uRun: [DesktopX] "c:\program files (x86)\stardock\object desktop\desktopx\desktopx.exe"
mRun: [DiscWizardMonitor.exe] c:\program files (x86)\seagate\discwizard\DiscWizardMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files (x86)\seagate\discwizard\TimounterMonitor.exe
mRun: [D-Link Network USB Utility] c:\program files (x86)\d-link\shareport\SharePort Network USB Utility.exe -mini
mRunOnce: [Malwarebytes' Anti-Malware] "c:\program files (x86)\malwarebytes' anti-malware\mbamgui.exe" /install /silent
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files (x86)\belkin\bluetooth software\btsendto_ie_ctx.htm
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files (x86)\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
Trusted Zone: trymedia.com\fe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.27.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/gom/receiver/tc/FMSI.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files (x86)\norton internet security\engine\16.5.0.135\CoIEPlg.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~2\common~1\stardock\mcpcore.dll
LSA: Authentication Packages = msv1_0 relog_ap
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun-x64: [Seagate Scheduler2 Service] "c:\program files (x86)\common files\seagate\schedule2\schedhlp.exe"
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe
mRun-x64: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe
================= FIREFOX ===================
FF - ProfilePath - c:\users\dones\appdata\roaming\mozilla\firefox\profiles\i2cgbi12.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files (x86)\download manager\npfpdlm.dll
FF - plugin: c:\program files (x86)\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files (x86)\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\onlive\firefoxplugin\npolgdet.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - plugin: c:\users\dones\appdata\roaming\mozilla\firefox\profiles\i2cgbi12.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 pe3ah4nb;DiRT Environment Driver (pe3ah4nb);c:\windows\system32\drivers\pe3ah4nb.sys [2007-7-19 72296]
R0 ps6ah4nb;DiRT Synchronization Driver (ps6ah4nb);c:\windows\system32\drivers\ps6ah4nb.sys [2007-7-19 102000]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1005000.087\SymEFA64.sys [2009-3-19 402992]
R1 BHDrvx64;Symantec Heuristics Driver;c:\windows\system32\drivers\nisx64\1005000.087\BHDrvx64.sys [2009-3-19 332848]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1005000.087\cchpx64.sys [2009-3-19 582704]
R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091230.004\IDSviA64.sys [2010-1-4 466992]
R2 dlbc_device;dlbc_device;c:\windows\system32\dlbccoms.exe -service –> c:\windows\system32\dlbccoms.exe -service [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\logmein hamachi\hamachi-2.exe [2009-10-29 1767816]
R2 Norton Internet Security;Norton Internet Security;c:\program files (x86)\norton internet security\engine\16.5.0.135\ccSvcHst.exe [2009-3-19 115560]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\common files\seagate\schedule2\schedul2.exe [2008-6-24 605464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-9-27 240232]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-26 132656]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nisx64\1005000.087\symndisv.sys [2009-3-19 46640]
S2 pr2ah4nb;DiRT Drivers Auto Removal (pr2ah4nb);c:\windows\system32\pr2ah4nb.exe svc –> c:\windows\system32\pr2ah4nb.exe svc [?]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-5-29 89920]
S3 ENTECH64;ENTECH64;c:\windows\system32\drivers\Entech64.sys [2009-1-17 12744]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys [2009-4-6 50072]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]
S4 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2009-12-18 135664]
============== File Associations ===============
JSEFile=c:\windows\syswow64\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-01-05 21:57:44 0 d—–w- C:\Cleaning Tools
2010-01-05 11:21:37 0 d—–w- c:\users\dones\appdata\roaming\Braid
2010-01-05 07:19:24 540688 —-a-w- c:\windows\system32\d3dx10_39.dll
2010-01-05 07:19:24 1942552 —-a-w- c:\windows\system32\D3DCompiler_39.dll
2010-01-05 07:19:22 4992520 —-a-w- c:\windows\system32\D3DX9_39.dll
2010-01-04 19:59:41 0 d—–w- C:\Braid
2009-12-26 11:27:17 0 d—–w- c:\windows\E4D153288C89484BB9AAF5BE9EA6D01C.TMP
2009-12-26 10:47:33 0 d—–w- c:\program files (x86)\Trine
2009-12-17 06:49:07 839680 —-a-w- c:\windows\syswow64\mkl_vml_p4.dll
2009-12-17 06:49:07 532480 —-a-w- c:\windows\syswow64\mkl_vml_p3.dll
2009-12-17 06:49:07 512000 —-a-w- c:\windows\syswow64\mkl_vml_def.dll
2009-12-17 06:49:07 3485696 —-a-w- c:\windows\syswow64\mkl_p4.dll
2009-12-17 06:49:07 2793472 —-a-w- c:\windows\syswow64\mkl_p3.dll
2009-12-17 06:49:06 2441216 —-a-w- c:\windows\syswow64\mkl_def.dll
2009-12-17 06:49:06 2174976 —-a-w- c:\windows\syswow64\mkl_lapack32.dll
2009-12-17 06:49:06 2125824 —-a-w- c:\windows\syswow64\mkl_lapack64.dll
2009-12-17 06:49:06 184320 —-a-w- c:\windows\syswow64\libguide40.dll
2009-12-17 06:48:35 809560 —-a-r- c:\windows\syswow64\tmpC5A6.tmp
2009-12-17 06:45:57 809560 —-a-r- c:\windows\syswow64\tmpC576.tmp
2009-12-16 22:22:43 0 d—–w- c:\program files (x86)\OnLive
2009-12-16 01:18:34 0 d—–w- c:\users\dones\appdata\roaming\GetRightToGo
2009-12-16 00:46:27 411368 —-a-w- c:\windows\syswow64\deploytk.dll
2009-12-16 00:46:18 149280 —-a-w- c:\windows\syswow64\javaws.exe
2009-12-16 00:46:09 145184 —-a-w- c:\windows\syswow64\javaw.exe
2009-12-16 00:45:57 145184 —-a-w- c:\windows\syswow64\java.exe
2009-12-15 20:07:28 0 d—–w- C:\DSFTP
2009-12-13 06:41:51 0 d—–w- c:\users\dones\appdata\roaming\Command and Conquer 4 Beta
2009-12-12 21:04:55 0 d—–w- c:\programdata\Electronic Arts Inc
2009-12-09 17:50:06 0 d—–w- c:\users\dones\appdata\roaming\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
2009-12-09 08:40:15 467984 —-a-w- c:\windows\syswow64\d3dx10_39.dll
2009-12-09 08:40:15 1493528 —-a-w- c:\windows\syswow64\D3DCompiler_39.dll
2009-12-09 08:39:58 3851784 —-a-w- c:\windows\syswow64\D3DX9_39.dll
2009-12-09 08:30:34 0 d—–w- C:\Riot Games
2009-12-09 05:39:45 1347 —-a-w- c:\users\dones\AppData.lnk
2009-12-09 04:47:00 442368 —-a-w- c:\windows\system32\winhttp.dll
2009-12-09 04:44:50 620032 —-a-w- c:\windows\system32\drivers\http.sys
2009-12-09 04:44:49 33792 —-a-w- c:\windows\system32\httpapi.dll
2009-12-09 04:44:49 32768 —-a-w- c:\windows\system32\nshhttp.dll
2009-12-09 04:44:49 30720 —-a-w- c:\windows\syswow64\httpapi.dll
2009-12-09 04:44:46 24064 —-a-w- c:\windows\syswow64\nshhttp.dll
2009-12-09 01:48:56 0 d—–w- c:\users\dones\appdata\roaming\Stella
==================== Find3M ====================
2010-01-05 19:11:11 108677 —-a-w- c:\programdata\nvModes.dat
2010-01-02 10:53:11 189184 —-a-w- c:\windows\syswow64\PnkBstrB.exe
2009-12-30 22:55:06 22104 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 06:48:35 466520 —-a-w- c:\windows\system32\wrap_oal.dll
2009-12-17 06:48:35 445016 —-a-w- c:\windows\syswow64\wrap_oal.dll
2009-12-17 06:48:35 122968 —-a-w- c:\windows\system32\OpenAL32.dll
2009-12-17 06:48:35 109144 —-a-w- c:\windows\syswow64\OpenAL32.dll
2009-12-02 04:20:46 51200 —-a-w- c:\windows\inf\infpub.dat
2009-12-02 04:20:46 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-12-02 04:20:44 86016 —-a-w- c:\windows\inf\infstor.dat
2009-12-01 02:02:40 171144 —-a-w- c:\windows\syswow64\xliveinstall.dll
2009-12-01 02:02:38 72840 —-a-w- c:\windows\syswow64\xliveinstallhost.exe
2009-11-21 06:52:02 1147904 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:46:36 77312 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:46:36 132096 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:40:20 916480 —-a-w- c:\windows\syswow64\wininet.dll
2009-11-21 06:40:03 1208832 —-a-w- c:\windows\syswow64\urlmon.dll
2009-11-21 06:38:17 206848 —-a-w- c:\windows\syswow64\occache.dll
2009-11-21 06:35:43 5940736 —-a-w- c:\windows\syswow64\mshtml.dll
2009-11-21 06:35:38 594432 —-a-w- c:\windows\syswow64\msfeeds.dll
2009-11-21 06:35:38 55296 —-a-w- c:\windows\syswow64\msfeedsbs.dll
2009-11-21 06:34:58 25600 —-a-w- c:\windows\syswow64\jsproxy.dll
2009-11-21 06:34:39 71680 —-a-w- c:\windows\syswow64\iesetup.dll
2009-11-21 06:34:39 1985536 —-a-w- c:\windows\syswow64\iertutil.dll
2009-11-21 06:34:39 164352 —-a-w- c:\windows\syswow64\ieui.dll
2009-11-21 06:34:39 109056 —-a-w- c:\windows\syswow64\iesysprep.dll
2009-11-21 06:34:38 55808 —-a-w- c:\windows\syswow64\iernonce.dll
2009-11-21 06:34:38 184320 —-a-w- c:\windows\syswow64\iepeers.dll
2009-11-21 06:34:38 11069952 —-a-w- c:\windows\syswow64\ieframe.dll
2009-11-21 06:34:33 387584 —-a-w- c:\windows\syswow64\iedkcs32.dll
2009-11-21 05:07:24 162816 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-21 04:59:58 133632 —-a-w- c:\windows\syswow64\ieUnatt.exe
2009-11-21 04:59:52 173056 —-a-w- c:\windows\syswow64\ie4uinit.exe
2009-11-21 04:59:14 13312 —-a-w- c:\windows\syswow64\msfeedssync.exe
2009-11-19 02:11:56 1347584 —-a-w- c:\windows\syswow64\rapture3d_oal.dll
2009-11-06 18:59:54 15406728 —-a-w- c:\windows\syswow64\xlive.dll
2009-11-06 18:59:54 13642888 —-a-w- c:\windows\syswow64\xlivefnt.dll
2009-11-01 21:11:20 17686528 —-a-w- c:\windows\syswow64\mkl_blueripple.dll
2009-10-30 08:45:30 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-10-29 09:36:50 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-29 09:17:42 2048 —-a-w- c:\windows\syswow64\tzres.dll
2009-10-28 19:32:32 809560 —-a-r- c:\windows\syswow64\tmpE3D8.tmp
2009-10-28 19:32:32 809560 —-a-r- c:\windows\syswow64\tmpE3B8.tmp
2009-10-23 18:45:43 75064 —-a-w- c:\windows\syswow64\PnkBstrA.exe
2009-10-23 18:45:43 2395944 —-a-w- c:\windows\syswow64\pbsvc_heroes.exe
2009-10-08 21:08:04 736256 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08:01 555520 —-a-w- c:\windows\syswow64\UIAutomationCore.dll
2009-10-08 21:08:01 234496 —-a-w- c:\windows\syswow64\oleacc.dll
2009-10-08 21:07:59 4096 —-a-w- c:\windows\syswow64\oleaccrc.dll
2009-10-08 21:07:58 315904 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07:54 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2008-01-21 03:18:21 174 –sha-w- c:\program files\desktop.ini
2008-01-21 03:18:21 174 –sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:10:25 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:10:25 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:10:25 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:10:25 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 15:21:11.41 ===============