talis
Topic Starter
I have the 2nd DDS log on my desktop if required..
Thanks
Mbam
Malwarebytes' Anti-Malware 1.44
Database version: 3596
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/18/2010 7:47:48 PM
mbam-log-2010-01-18 (19-47-41).txt
Scan type: Quick Scan
Objects scanned: 118520
Time elapsed: 5 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\krl32mainweq.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\system32\H8SRTmfgxfwwnxh.dat (Rootkit.TDSS) -> No action taken.
GMER
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-18 20:00:23
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Me\LOCALS~1\Temp\kfdyrkog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwAssignProcessToJobObject [0xF6F2F1CC]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwCreateThread [0xF6F2F206]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenProcess [0xF6F2F51A]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenThread [0xF6F2F3F6]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwProtectVirtualMemory [0xF6F2F292]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwSetContextThread [0xF6F2F18E]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateProcess [0xF6F2F64E]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateThread [0xF6F2F316]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwWriteVirtualMemory [0xF6F2F34E]
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Tcp pxrts.sys (Prevx Realtime Security/Prevx)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTyrmnaawnmi.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTyrmnaawnmi.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTfusbnievfq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTmfgxfwwnxh.dat
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTvkkvfxbuqu.dll
—- EOF - GMER 1.0.15 —-
DDS
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 20:03:05.20 on Mon 01/18/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.759.439 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Me\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.fubar.com/imgs/ImageUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1262078484046
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1262078470031
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\me\applic~1\mozilla\firefox\profiles\bj7bypjk.default\
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-12-29 30280]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-12-16 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-12-16 74480]
R2 CSIScanner;CSIScanner;c:\program files\prevx\prevx.exe [2009-12-29 6224896]
R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2009-12-29 47664]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-23 24652]
R3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2009-12-29 24496]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-16 135664]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [2006-3-20 1452032]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-12-16 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-4-6 23064]
=============== Created Last 30 ================
2010-01-19 00:34:01 0 d—–w- c:\docume~1\me\applic~1\Malwarebytes
2010-01-19 00:33:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-19 00:33:44 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-10 18:49:40 0 d—–w- c:\windows\system32\wbem\Repository
2009-12-29 17:04:35 53136 —-a-w- c:\windows\system32\PxSecure.dll
2009-12-29 17:04:34 47664 —-a-w- c:\windows\system32\drivers\pxrts.sys
2009-12-29 17:04:34 30280 —-a-w- c:\windows\system32\drivers\pxscan.sys
2009-12-29 17:04:33 24496 —-a-w- c:\windows\system32\drivers\pxkbf.sys
2009-12-29 17:04:33 0 d—–w- c:\program files\Prevx
2009-12-29 17:04:28 0 d—–w- c:\docume~1\alluse~1\applic~1\PrevxCSI
2009-12-29 14:47:46 202 —-a-w- c:\windows\system32\srcr.dat
2009-12-29 13:34:57 0 d—–w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-12-29 12:08:39 0 d—–w- c:\windows\system32\XPSViewer
2009-12-29 12:07:10 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-29 12:07:10 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-12-29 12:07:10 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-29 12:07:10 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-12-29 12:07:10 117760 ——w- c:\windows\system32\prntvpt.dll
2009-12-29 12:07:09 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-12-29 12:07:09 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-12-29 12:07:08 0 d—–w- C:\c906abf2c5710191ddc4
2009-12-29 11:57:52 32 —-a-w- c:\windows\wininit.ini
2009-12-29 10:21:46 0 d—–w- C:\cd728dc701e6fd3f3dd7e8e79bd8
2009-12-29 10:21:41 0 d—–w- C:\fffa5f25c1195355eecdca3136a36ccd
2009-12-29 10:17:25 0 d—–w- c:\program files\SUPERAntiSpyware
2009-12-29 10:17:25 0 d—–w- c:\docume~1\me\applic~1\SUPERAntiSpyware.com
2009-12-29 10:17:14 0 d—–w- c:\program files\common files\Wise Installation Wizard
2009-12-29 10:15:06 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-29 10:06:55 0 d-sh–w- c:\documents and settings\me\PrivacIE
2009-12-29 10:05:17 0 d-sh–w- c:\documents and settings\me\IETldCache
2009-12-29 10:00:19 0 d—–w- c:\windows\system32\KB905474
2009-12-29 09:59:00 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-12-29 09:58:59 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-29 09:58:54 0 d—–w- c:\windows\ie8updates
2009-12-29 09:58:51 92160 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-12-29 09:56:58 0 dc-h–w- c:\windows\ie8
2009-12-29 09:51:44 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-12-29 09:45:12 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-12-29 09:45:02 128512 -c—-w- c:\windows\system32\dllcache\dhtmled.ocx
2009-12-29 09:44:44 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-12-29 09:40:54 0 d—–w- C:\cf68edeb05ee70d59eca5b55e5f98155
2009-12-29 09:21:44 15064 —-a-w- c:\windows\system32\wuapi.dll.mui
2009-12-29 09:15:54 0 d—–w- c:\program files\MozyHome
2009-12-29 08:41:48 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-29 07:24:25 0 d—–w- c:\program files\AVG
2009-12-29 07:24:24 0 d—–w- c:\docume~1\alluse~1\applic~1\avg9
2009-12-29 07:20:57 0 d—–w- c:\docume~1\me\applic~1\AVG8
==================== Find3M ====================
2009-12-22 01:10:46 69 —-a-w- c:\documents and settings\me\jagex_runescape_preferences2.dat
2009-12-22 01:03:13 39 —-a-w- c:\documents and settings\me\jagex_runescape_preferences.dat
2009-10-31 12:08:09 13836 —ha-w- c:\windows\system32\mlfcache.dat
2009-10-29 07:45:38 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 04:48:52 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-10-29 04:48:52 348160 —-a-w- c:\windows\system32\msvcr71.dll
============= FINISH: 20:03:37.75 ===============
Thanks
Mbam
Malwarebytes' Anti-Malware 1.44
Database version: 3596
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/18/2010 7:47:48 PM
mbam-log-2010-01-18 (19-47-41).txt
Scan type: Quick Scan
Objects scanned: 118520
Time elapsed: 5 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\krl32mainweq.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\system32\H8SRTmfgxfwwnxh.dat (Rootkit.TDSS) -> No action taken.
GMER
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-18 20:00:23
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Me\LOCALS~1\Temp\kfdyrkog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwAssignProcessToJobObject [0xF6F2F1CC]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwCreateThread [0xF6F2F206]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenProcess [0xF6F2F51A]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenThread [0xF6F2F3F6]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwProtectVirtualMemory [0xF6F2F292]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwSetContextThread [0xF6F2F18E]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateProcess [0xF6F2F64E]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateThread [0xF6F2F316]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwWriteVirtualMemory [0xF6F2F34E]
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Tcp pxrts.sys (Prevx Realtime Security/Prevx)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTyrmnaawnmi.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTyrmnaawnmi.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTfusbnievfq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTmfgxfwwnxh.dat
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTvkkvfxbuqu.dll
—- EOF - GMER 1.0.15 —-
DDS
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 20:03:05.20 on Mon 01/18/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.759.439 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Me\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.fubar.com/imgs/ImageUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1262078484046
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1262078470031
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\me\applic~1\mozilla\firefox\profiles\bj7bypjk.default\
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-12-29 30280]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-12-16 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-12-16 74480]
R2 CSIScanner;CSIScanner;c:\program files\prevx\prevx.exe [2009-12-29 6224896]
R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2009-12-29 47664]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-23 24652]
R3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2009-12-29 24496]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-16 135664]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [2006-3-20 1452032]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-12-16 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-4-6 23064]
=============== Created Last 30 ================
2010-01-19 00:34:01 0 d—–w- c:\docume~1\me\applic~1\Malwarebytes
2010-01-19 00:33:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-19 00:33:44 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-10 18:49:40 0 d—–w- c:\windows\system32\wbem\Repository
2009-12-29 17:04:35 53136 —-a-w- c:\windows\system32\PxSecure.dll
2009-12-29 17:04:34 47664 —-a-w- c:\windows\system32\drivers\pxrts.sys
2009-12-29 17:04:34 30280 —-a-w- c:\windows\system32\drivers\pxscan.sys
2009-12-29 17:04:33 24496 —-a-w- c:\windows\system32\drivers\pxkbf.sys
2009-12-29 17:04:33 0 d—–w- c:\program files\Prevx
2009-12-29 17:04:28 0 d—–w- c:\docume~1\alluse~1\applic~1\PrevxCSI
2009-12-29 14:47:46 202 —-a-w- c:\windows\system32\srcr.dat
2009-12-29 13:34:57 0 d—–w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-12-29 12:08:39 0 d—–w- c:\windows\system32\XPSViewer
2009-12-29 12:07:10 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-29 12:07:10 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-12-29 12:07:10 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-29 12:07:10 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-12-29 12:07:10 117760 ——w- c:\windows\system32\prntvpt.dll
2009-12-29 12:07:09 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-12-29 12:07:09 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-12-29 12:07:08 0 d—–w- C:\c906abf2c5710191ddc4
2009-12-29 11:57:52 32 —-a-w- c:\windows\wininit.ini
2009-12-29 10:21:46 0 d—–w- C:\cd728dc701e6fd3f3dd7e8e79bd8
2009-12-29 10:21:41 0 d—–w- C:\fffa5f25c1195355eecdca3136a36ccd
2009-12-29 10:17:25 0 d—–w- c:\program files\SUPERAntiSpyware
2009-12-29 10:17:25 0 d—–w- c:\docume~1\me\applic~1\SUPERAntiSpyware.com
2009-12-29 10:17:14 0 d—–w- c:\program files\common files\Wise Installation Wizard
2009-12-29 10:15:06 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-29 10:06:55 0 d-sh–w- c:\documents and settings\me\PrivacIE
2009-12-29 10:05:17 0 d-sh–w- c:\documents and settings\me\IETldCache
2009-12-29 10:00:19 0 d—–w- c:\windows\system32\KB905474
2009-12-29 09:59:00 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-12-29 09:58:59 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-29 09:58:54 0 d—–w- c:\windows\ie8updates
2009-12-29 09:58:51 92160 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-12-29 09:56:58 0 dc-h–w- c:\windows\ie8
2009-12-29 09:51:44 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-12-29 09:45:12 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-12-29 09:45:02 128512 -c—-w- c:\windows\system32\dllcache\dhtmled.ocx
2009-12-29 09:44:44 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-12-29 09:40:54 0 d—–w- C:\cf68edeb05ee70d59eca5b55e5f98155
2009-12-29 09:21:44 15064 —-a-w- c:\windows\system32\wuapi.dll.mui
2009-12-29 09:15:54 0 d—–w- c:\program files\MozyHome
2009-12-29 08:41:48 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-29 07:24:25 0 d—–w- c:\program files\AVG
2009-12-29 07:24:24 0 d—–w- c:\docume~1\alluse~1\applic~1\avg9
2009-12-29 07:20:57 0 d—–w- c:\docume~1\me\applic~1\AVG8
==================== Find3M ====================
2009-12-22 01:10:46 69 —-a-w- c:\documents and settings\me\jagex_runescape_preferences2.dat
2009-12-22 01:03:13 39 —-a-w- c:\documents and settings\me\jagex_runescape_preferences.dat
2009-10-31 12:08:09 13836 —ha-w- c:\windows\system32\mlfcache.dat
2009-10-29 07:45:38 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 04:48:52 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-10-29 04:48:52 348160 —-a-w- c:\windows\system32\msvcr71.dll
============= FINISH: 20:03:37.75 ===============