Tuomaaca
Topic Starter
Ok, so all of a sudden, IE began to not connect to the web (can still connect w/ firefox), and my AVG wouldn't update anymore. So I replaced AVG with Avira, and that too won't update. I've downloaded Malwarebytes' and that will not update. All the while, my computer's running sluggishly and often freezes… So, can you help me?
Thanks in advance!!!!
I've followed the instructions in the "Are you infected?" thread, and here are my results:
MBAM Log:
Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/27/2010 4:17:35 PM
mbam-log-2010-01-27 (16-17-35).txt
Scan type: Quick Scan
Objects scanned: 121606
Time elapsed: 5 minute(s), 19 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER Log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-27 19:17:30
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Aaron\LOCALS~1\Temp\kgroapog.sys
—- System - GMER 1.0.15 —-
SSDT F7D95466 ZwCreateKey
SSDT F7D9545C ZwCreateThread
SSDT F7D9546B ZwDeleteKey
SSDT F7D95475 ZwDeleteValueKey
SSDT splv.sys ZwEnumerateKey [0xF7470CA2]
SSDT splv.sys ZwEnumerateValueKey [0xF7471030]
SSDT F7D9547A ZwLoadKey
SSDT splv.sys ZwOpenKey [0xF74520C0]
SSDT F7D95448 ZwOpenProcess
SSDT F7D9544D ZwOpenThread
SSDT splv.sys ZwQueryKey [0xF7471108]
SSDT splv.sys ZwQueryValueKey [0xF7470F88]
SSDT F7D95484 ZwReplaceKey
SSDT F7D9547F ZwRestoreKey
SSDT F7D95470 ZwSetValueKey
SSDT F7D95457 ZwTerminateProcess
INT 0x62 ? 86F60BF8
INT 0x63 ? 86FD0BF8
INT 0x74 ? 86824BF8
INT 0x84 ? 86824BF8
INT 0x94 ? 86824BF8
INT 0xA4 ? 86824BF8
INT 0xB1 ? 86FD3BF8
INT 0xB1 ? 86FD3BF8
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 86F4B1F8
Device \Driver\usbuhci \Device\USBPDO-0 867D91F8
Device \Driver\usbuhci \Device\USBPDO-1 867D91F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86FD11F8
Device \Driver\dmio \Device\DmControl\DmConfig 86FD11F8
Device \Driver\dmio \Device\DmControl\DmPnP 86FD11F8
Device \Driver\dmio \Device\DmControl\DmInfo 86FD11F8
Device \Driver\usbuhci \Device\USBPDO-2 867D91F8
Device \Driver\usbuhci \Device\USBPDO-3 867D91F8
Device \Driver\usbehci \Device\USBPDO-4 868E91F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{8380A67C-4753-4C99-A779-143C7FA83892} 866051F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 86F621F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 86F621F8
Device \Driver\Cdrom \Device\CdRom0 8663A1F8
Device \Driver\iaStor \Device\Ide\iaStor0 [F7377440] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7333B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F7333B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F7333B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [F7377440] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 [F7377440] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 8663A1F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 86F621F8
Device \Driver\Cdrom \Device\CdRom2 8663A1F8
Device \Driver\Ftdisk \Device\HarddiskVolume4 86F621F8
Device \Driver\Ftdisk \Device\HarddiskVolume5 86F621F8
Device \Driver\Cdrom \Device\CdRom3 8663A1F8
Device \Driver\Cdrom \Device\CdRom4 8663A1F8
Device \Driver\Ftdisk \Device\HarddiskVolume6 86F621F8
Device \Driver\PCI_PNP2570 \Device\00000082 splv.sys
Device \Driver\sptd \Device\4067216320 splv.sys
Device \Driver\Cdrom \Device\CdRom5 8663A1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 866051F8
Device \Driver\PCI_PNP2570 \Device\00000083 splv.sys
Device \Driver\NetBT \Device\NetbiosSmb 866051F8
Device \Driver\sptd \Device\4067060070 splv.sys
Device \Driver\usbuhci \Device\USBFDO-0 867D91F8
Device \Driver\usbuhci \Device\USBFDO-1 867D91F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8582F500
Device \Driver\usbuhci \Device\USBFDO-2 867D91F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8582F500
Device \Driver\usbuhci \Device\USBFDO-3 867D91F8
Device \Driver\usbehci \Device\USBFDO-4 868E91F8
Device \Driver\Ftdisk \Device\FtControl 86F621F8
Device \Driver\a7k0e3qe \Device\Scsi\a7k0e3qe1 866181F8
Device \Driver\aizvzg32 \Device\Scsi\aizvzg321Port2Path0Target1Lun0 865F71F8
Device \Driver\aizvzg32 \Device\Scsi\aizvzg321 865F71F8
Device \Driver\aizvzg32 \Device\Scsi\aizvzg321Port2Path0Target0Lun0 865F71F8
Device \Driver\aizvzg32 \Device\Scsi\aizvzg321Port2Path0Target2Lun0 865F71F8
Device \Driver\a7k0e3qe \Device\Scsi\a7k0e3qe1Port3Path0Target0Lun0 866181F8
Device \FileSystem\Fastfat \Fat 865851F8
Device \FileSystem\Fastfat \Fat A347A297
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 854E31F8
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4E 0x6C 0xF9 0x75 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x4C 0x82 0xA8 0xC8 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x8D 0x20 0x15 0x16 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA2 0xA3 0x45 0xC1 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x0D 0x84 0xBA 0x58 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x92 0x50 0xF7 0x98 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x76 0x41 0xF2 0xDF …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x88 0xA3 0x12 0x52 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4E 0x6C 0xF9 0x75 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x4C 0x82 0xA8 0xC8 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x8D 0x20 0x15 0x16 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA2 0xA3 0x45 0xC1 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x0D 0x84 0xBA 0x58 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x92 0x50 0xF7 0x98 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x76 0x41 0xF2 0xDF …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x88 0xA3 0x12 0x52 …
—- EOF - GMER 1.0.15 —-
DDS:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:14:03.71 on Wed 01/27/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.513 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\MATLAB701\webserver\bin\win32\matlabserver.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\OpenSSH\bin\cygrunsrv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\OpenSSH\usr\sbin\sshd.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\NETGEAR\WG311v3\WinDomainlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Aaron\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
mSearchAssistant = hxxp://www.google.com
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [mount.exe] c:\program files\gipo@utilities\fileutilities.3\mount.exe /z
uRun: [Aim6]
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
mRun: [IAAnotif] c:\program files\intel\intel application accelerator\iaanotif.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [CTSysVol] c:\program files\creative\sbaudigy2zs\surround mixer\CTSysVol.exe /r
mRun: [CTDVDDET] "c:\program files\creative\sbaudigy2zs\dvdaudio\CTDVDDET.EXE"
mRun: [CTHelper] CTHELPER.EXE
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230712901437
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244723116875
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, mcenspc.dll, digiwet.dll
LSA: Notification Packages = scecli c:\windows\system32\tuhemasa.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\aaron\applic~1\mozilla\firefox\profiles\ud41wctg.default\
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdjvu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XUL Cache: {16D0D025-9262-4C3E-A4E0-2187CE32B908} - c:\documents and settings\aaron\local settings\application data\{16d0d025-9262-4c3e-a4e0-2187ce32b908}\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2009-6-10 3968]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-1-27 11608]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-1-27 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-1-27 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-1-25 55656]
R2 OpenSSHd;OpenSSH Server;c:\program files\openssh\bin\cygrunsrv.exe [2004-4-18 36864]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-9-18 24652]
S0 hiffhx;hiffhx;c:\windows\system32\drivers\ynwc.sys –> c:\windows\system32\drivers\ynwc.sys [?]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S0 mfnom;mfnom;c:\windows\system32\drivers\nqdiweu.sys –> c:\windows\system32\drivers\nqdiweu.sys [?]
S0 uuqw;uuqw;c:\windows\system32\drivers\sjalsn.sys –> c:\windows\system32\drivers\sjalsn.sys [?]
S2 ClipSrvodserv;ClipBook ClipSrvodserv;c:\windows\system32\12520437x.exe srv –> c:\windows\system32\12520437x.exe srv [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-9-27 133104]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
=============== Created Last 30 ================
2010-01-27 08:39 –d—– c:\program files\Avira
2010-01-27 08:39 –d—– c:\docume~1\alluse~1\applic~1\Avira
2010-01-25 22:39 4,934,174 a——- c:\windows\{00000004-00000000-00000002-00001102-00000004-20061102}.BAK
2010-01-25 22:10 55,656 a——- c:\windows\system32\drivers\avgntflt.sys
2010-01-25 22:04 –d—– c:\windows\ie8updates
2010-01-25 19:53 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2010-01-25 19:53 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2010-01-25 01:18 –dsh— c:\documents and settings\aaron\IECompatCache
2010-01-25 01:16 –dsh— c:\documents and settings\aaron\PrivacIE
2010-01-25 01:12 –dsh— c:\documents and settings\aaron\IETldCache
2010-01-25 00:55 -cd-h— c:\windows\ie8
2010-01-19 15:20 –d—– c:\windows\system32\Adobe
2010-01-13 19:19 60,052 a—h— c:\windows\system32\mlfcache.dat
2010-01-13 18:41 1,654,869 a——- c:\docume~1\alluse~1\applic~1\DynuEncrypt.dll
2010-01-13 17:51 –d—– c:\docume~1\aaron\applic~1\com.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1
2010-01-13 17:32 158,952 a——- c:\windows\system32\PubPlugin.dll
2010-01-13 17:22 –d—– C:\ijji
2010-01-12 19:19 471,552 ——– c:\windows\system32\dllcache\aclayers.dll
2010-01-11 18:53 –d—– c:\docume~1\alluse~1\applic~1\ElectricSheep
2010-01-11 18:53 –d—– c:\program files\Electricsheep Screensaver
2010-01-03 01:52 –d—– c:\program files\iPod
2010-01-03 01:52 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-03 01:51 –d—– c:\program files\Bonjour
2010-01-03 01:48 2,065,696 a——- c:\windows\system32\usbaaplrc.dll
==================== Find3M ====================
2010-01-07 16:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-05 05:00 133,120 ——– c:\windows\system32\dllcache\extmgr.dll
2009-12-31 10:33 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-12-21 14:14 1,208,832 a——- c:\windows\system32\dllcache\urlmon.dll
2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-21 14:14 916,480 a——- c:\windows\system32\dllcache\wininet.dll
2009-12-21 14:14 5,942,784 a——- c:\windows\system32\dllcache\mshtml.dll
2009-12-21 14:14 206,848 a——- c:\windows\system32\dllcache\occache.dll
2009-12-21 14:14 1,985,536 a——- c:\windows\system32\dllcache\iertutil.dll
2009-12-21 14:14 594,432 a——- c:\windows\system32\dllcache\msfeeds.dll
2009-12-21 14:14 184,320 a——- c:\windows\system32\dllcache\iepeers.dll
2009-12-21 14:14 55,296 a——- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-21 14:14 25,600 a——- c:\windows\system32\dllcache\jsproxy.dll
2009-12-21 14:14 11,070,464 a——- c:\windows\system32\dllcache\ieframe.dll
2009-12-21 14:14 387,584 a——- c:\windows\system32\dllcache\iedkcs32.dll
2009-12-21 08:19 173,056 a——- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-17 17:30 103,535 a——- c:\windows\hpoins04.dat
2009-12-15 17:21 427,008 a——- c:\windows\system32\uc_wepic_launching.dll
2009-12-02 03:28 1,561,600 a——- c:\windows\ElectricSheep_2_7b21.scr
2009-11-26 03:06 9,820,160 a——- c:\windows\avcodec-52.dll
2009-11-26 03:06 791,040 a——- c:\windows\avformat-52.dll
2009-11-26 03:06 221,696 a——- c:\windows\swscale-0.dll
2009-11-26 03:06 77,312 a——- c:\windows\avutil-50.dll
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-09-02 22:04 19,284 a——- c:\program files\common files\fejusyc.dl
2009-09-02 22:04 13,195 a——- c:\docume~1\alluse~1\applic~1\olylam.exe
2009-09-02 21:59 16,707 a——- c:\program files\common files\uhixud.scr
2009-09-02 21:59 11,734 a——- c:\docume~1\aaron\applic~1\ohapiv.dat
2009-09-02 21:59 14,680 a——- c:\docume~1\alluse~1\applic~1\wyjabydi.bat
2009-09-02 21:36 14,787 a——- c:\docume~1\alluse~1\applic~1\hijofugen.bin
2009-09-02 16:32 19,492 a——- c:\docume~1\alluse~1\applic~1\xiheb.vbs
2009-09-02 07:45 18,114 a——- c:\docume~1\aaron\applic~1\iwuwutywi.dll
2009-09-02 07:45 15,460 a——- c:\program files\common files\eqafap.lib
2009-09-02 07:45 14,272 a——- c:\docume~1\aaron\applic~1\tuqybuviky.sys
2009-09-01 19:46 17,085 a——- c:\program files\common files\yjaqe._sy
2009-08-31 22:26 11,784 a——- c:\program files\common files\lohed._sy
2009-08-31 22:26 10,928 a——- c:\docume~1\aaron\applic~1\ubibypuhu.bin
2009-08-31 22:26 10,303 a——- c:\program files\common files\icajyna.reg
2009-08-31 19:04 13,848 a——- c:\docume~1\aaron\applic~1\izifa.dat
2009-08-31 19:04 13,252 a——- c:\docume~1\alluse~1\applic~1\sipoj.com
2009-08-31 19:04 11,703 a——- c:\program files\common files\evygi._sy
2009-08-31 19:04 11,413 a——- c:\docume~1\aaron\applic~1\lesomyti.sys
2007-05-24 15:58 249,856 a——- c:\windows\inf\wg311v3\InsDrv2k.exe
2006-12-04 12:38 212,992 a——- c:\windows\inf\wg311v3\CopyWHQLDriver.exe
2005-12-29 19:07 282,624 a—-r– c:\windows\inf\wg311v3\WG311v3XP.sys
============= FINISH: 20:14:28.85 ===============
Thanks in advance!!!!
I've followed the instructions in the "Are you infected?" thread, and here are my results:
MBAM Log:
Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/27/2010 4:17:35 PM
mbam-log-2010-01-27 (16-17-35).txt
Scan type: Quick Scan
Objects scanned: 121606
Time elapsed: 5 minute(s), 19 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER Log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-27 19:17:30
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Aaron\LOCALS~1\Temp\kgroapog.sys
—- System - GMER 1.0.15 —-
SSDT F7D95466 ZwCreateKey
SSDT F7D9545C ZwCreateThread
SSDT F7D9546B ZwDeleteKey
SSDT F7D95475 ZwDeleteValueKey
SSDT splv.sys ZwEnumerateKey [0xF7470CA2]
SSDT splv.sys ZwEnumerateValueKey [0xF7471030]
SSDT F7D9547A ZwLoadKey
SSDT splv.sys ZwOpenKey [0xF74520C0]
SSDT F7D95448 ZwOpenProcess
SSDT F7D9544D ZwOpenThread
SSDT splv.sys ZwQueryKey [0xF7471108]
SSDT splv.sys ZwQueryValueKey [0xF7470F88]
SSDT F7D95484 ZwReplaceKey
SSDT F7D9547F ZwRestoreKey
SSDT F7D95470 ZwSetValueKey
SSDT F7D95457 ZwTerminateProcess
INT 0x62 ? 86F60BF8
INT 0x63 ? 86FD0BF8
INT 0x74 ? 86824BF8
INT 0x84 ? 86824BF8
INT 0x94 ? 86824BF8
INT 0xA4 ? 86824BF8
INT 0xB1 ? 86FD3BF8
INT 0xB1 ? 86FD3BF8
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 86F4B1F8
Device \Driver\usbuhci \Device\USBPDO-0 867D91F8
Device \Driver\usbuhci \Device\USBPDO-1 867D91F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86FD11F8
Device \Driver\dmio \Device\DmControl\DmConfig 86FD11F8
Device \Driver\dmio \Device\DmControl\DmPnP 86FD11F8
Device \Driver\dmio \Device\DmControl\DmInfo 86FD11F8
Device \Driver\usbuhci \Device\USBPDO-2 867D91F8
Device \Driver\usbuhci \Device\USBPDO-3 867D91F8
Device \Driver\usbehci \Device\USBPDO-4 868E91F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{8380A67C-4753-4C99-A779-143C7FA83892} 866051F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 86F621F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 86F621F8
Device \Driver\Cdrom \Device\CdRom0 8663A1F8
Device \Driver\iaStor \Device\Ide\iaStor0 [F7377440] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7333B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F7333B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F7333B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [F7377440] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-1 [F7377440] iaStor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 8663A1F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 86F621F8
Device \Driver\Cdrom \Device\CdRom2 8663A1F8
Device \Driver\Ftdisk \Device\HarddiskVolume4 86F621F8
Device \Driver\Ftdisk \Device\HarddiskVolume5 86F621F8
Device \Driver\Cdrom \Device\CdRom3 8663A1F8
Device \Driver\Cdrom \Device\CdRom4 8663A1F8
Device \Driver\Ftdisk \Device\HarddiskVolume6 86F621F8
Device \Driver\PCI_PNP2570 \Device\00000082 splv.sys
Device \Driver\sptd \Device\4067216320 splv.sys
Device \Driver\Cdrom \Device\CdRom5 8663A1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 866051F8
Device \Driver\PCI_PNP2570 \Device\00000083 splv.sys
Device \Driver\NetBT \Device\NetbiosSmb 866051F8
Device \Driver\sptd \Device\4067060070 splv.sys
Device \Driver\usbuhci \Device\USBFDO-0 867D91F8
Device \Driver\usbuhci \Device\USBFDO-1 867D91F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8582F500
Device \Driver\usbuhci \Device\USBFDO-2 867D91F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8582F500
Device \Driver\usbuhci \Device\USBFDO-3 867D91F8
Device \Driver\usbehci \Device\USBFDO-4 868E91F8
Device \Driver\Ftdisk \Device\FtControl 86F621F8
Device \Driver\a7k0e3qe \Device\Scsi\a7k0e3qe1 866181F8
Device \Driver\aizvzg32 \Device\Scsi\aizvzg321Port2Path0Target1Lun0 865F71F8
Device \Driver\aizvzg32 \Device\Scsi\aizvzg321 865F71F8
Device \Driver\aizvzg32 \Device\Scsi\aizvzg321Port2Path0Target0Lun0 865F71F8
Device \Driver\aizvzg32 \Device\Scsi\aizvzg321Port2Path0Target2Lun0 865F71F8
Device \Driver\a7k0e3qe \Device\Scsi\a7k0e3qe1Port3Path0Target0Lun0 866181F8
Device \FileSystem\Fastfat \Fat 865851F8
Device \FileSystem\Fastfat \Fat A347A297
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 854E31F8
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4E 0x6C 0xF9 0x75 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x4C 0x82 0xA8 0xC8 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x8D 0x20 0x15 0x16 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA2 0xA3 0x45 0xC1 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x0D 0x84 0xBA 0x58 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x92 0x50 0xF7 0x98 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x76 0x41 0xF2 0xDF …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x88 0xA3 0x12 0x52 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4E 0x6C 0xF9 0x75 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x4C 0x82 0xA8 0xC8 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x8D 0x20 0x15 0x16 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA2 0xA3 0x45 0xC1 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x0D 0x84 0xBA 0x58 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x92 0x50 0xF7 0x98 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x76 0x41 0xF2 0xDF …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x88 0xA3 0x12 0x52 …
—- EOF - GMER 1.0.15 —-
DDS:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:14:03.71 on Wed 01/27/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.513 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\MATLAB701\webserver\bin\win32\matlabserver.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\OpenSSH\bin\cygrunsrv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\OpenSSH\usr\sbin\sshd.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\NETGEAR\WG311v3\WinDomainlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Aaron\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
mSearchAssistant = hxxp://www.google.com
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [mount.exe] c:\program files\gipo@utilities\fileutilities.3\mount.exe /z
uRun: [Aim6]
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
mRun: [IAAnotif] c:\program files\intel\intel application accelerator\iaanotif.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [CTSysVol] c:\program files\creative\sbaudigy2zs\surround mixer\CTSysVol.exe /r
mRun: [CTDVDDET] "c:\program files\creative\sbaudigy2zs\dvdaudio\CTDVDDET.EXE"
mRun: [CTHelper] CTHELPER.EXE
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230712901437
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244723116875
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, mcenspc.dll, digiwet.dll
LSA: Notification Packages = scecli c:\windows\system32\tuhemasa.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\aaron\applic~1\mozilla\firefox\profiles\ud41wctg.default\
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdjvu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XUL Cache: {16D0D025-9262-4C3E-A4E0-2187CE32B908} - c:\documents and settings\aaron\local settings\application data\{16d0d025-9262-4c3e-a4e0-2187ce32b908}\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2009-6-10 3968]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-1-27 11608]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-1-27 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-1-27 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-1-25 55656]
R2 OpenSSHd;OpenSSH Server;c:\program files\openssh\bin\cygrunsrv.exe [2004-4-18 36864]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-9-18 24652]
S0 hiffhx;hiffhx;c:\windows\system32\drivers\ynwc.sys –> c:\windows\system32\drivers\ynwc.sys [?]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S0 mfnom;mfnom;c:\windows\system32\drivers\nqdiweu.sys –> c:\windows\system32\drivers\nqdiweu.sys [?]
S0 uuqw;uuqw;c:\windows\system32\drivers\sjalsn.sys –> c:\windows\system32\drivers\sjalsn.sys [?]
S2 ClipSrvodserv;ClipBook ClipSrvodserv;c:\windows\system32\12520437x.exe srv –> c:\windows\system32\12520437x.exe srv [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-9-27 133104]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
=============== Created Last 30 ================
2010-01-27 08:39 –d—– c:\program files\Avira
2010-01-27 08:39 –d—– c:\docume~1\alluse~1\applic~1\Avira
2010-01-25 22:39 4,934,174 a——- c:\windows\{00000004-00000000-00000002-00001102-00000004-20061102}.BAK
2010-01-25 22:10 55,656 a——- c:\windows\system32\drivers\avgntflt.sys
2010-01-25 22:04 –d—– c:\windows\ie8updates
2010-01-25 19:53 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2010-01-25 19:53 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2010-01-25 01:18 –dsh— c:\documents and settings\aaron\IECompatCache
2010-01-25 01:16 –dsh— c:\documents and settings\aaron\PrivacIE
2010-01-25 01:12 –dsh— c:\documents and settings\aaron\IETldCache
2010-01-25 00:55 -cd-h— c:\windows\ie8
2010-01-19 15:20 –d—– c:\windows\system32\Adobe
2010-01-13 19:19 60,052 a—h— c:\windows\system32\mlfcache.dat
2010-01-13 18:41 1,654,869 a——- c:\docume~1\alluse~1\applic~1\DynuEncrypt.dll
2010-01-13 17:51 –d—– c:\docume~1\aaron\applic~1\com.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1
2010-01-13 17:32 158,952 a——- c:\windows\system32\PubPlugin.dll
2010-01-13 17:22 –d—– C:\ijji
2010-01-12 19:19 471,552 ——– c:\windows\system32\dllcache\aclayers.dll
2010-01-11 18:53 –d—– c:\docume~1\alluse~1\applic~1\ElectricSheep
2010-01-11 18:53 –d—– c:\program files\Electricsheep Screensaver
2010-01-03 01:52 –d—– c:\program files\iPod
2010-01-03 01:52 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-03 01:51 –d—– c:\program files\Bonjour
2010-01-03 01:48 2,065,696 a——- c:\windows\system32\usbaaplrc.dll
==================== Find3M ====================
2010-01-07 16:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-05 05:00 133,120 ——– c:\windows\system32\dllcache\extmgr.dll
2009-12-31 10:33 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-12-21 14:14 1,208,832 a——- c:\windows\system32\dllcache\urlmon.dll
2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-21 14:14 916,480 a——- c:\windows\system32\dllcache\wininet.dll
2009-12-21 14:14 5,942,784 a——- c:\windows\system32\dllcache\mshtml.dll
2009-12-21 14:14 206,848 a——- c:\windows\system32\dllcache\occache.dll
2009-12-21 14:14 1,985,536 a——- c:\windows\system32\dllcache\iertutil.dll
2009-12-21 14:14 594,432 a——- c:\windows\system32\dllcache\msfeeds.dll
2009-12-21 14:14 184,320 a——- c:\windows\system32\dllcache\iepeers.dll
2009-12-21 14:14 55,296 a——- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-21 14:14 25,600 a——- c:\windows\system32\dllcache\jsproxy.dll
2009-12-21 14:14 11,070,464 a——- c:\windows\system32\dllcache\ieframe.dll
2009-12-21 14:14 387,584 a——- c:\windows\system32\dllcache\iedkcs32.dll
2009-12-21 08:19 173,056 a——- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-17 17:30 103,535 a——- c:\windows\hpoins04.dat
2009-12-15 17:21 427,008 a——- c:\windows\system32\uc_wepic_launching.dll
2009-12-02 03:28 1,561,600 a——- c:\windows\ElectricSheep_2_7b21.scr
2009-11-26 03:06 9,820,160 a——- c:\windows\avcodec-52.dll
2009-11-26 03:06 791,040 a——- c:\windows\avformat-52.dll
2009-11-26 03:06 221,696 a——- c:\windows\swscale-0.dll
2009-11-26 03:06 77,312 a——- c:\windows\avutil-50.dll
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-09-02 22:04 19,284 a——- c:\program files\common files\fejusyc.dl
2009-09-02 22:04 13,195 a——- c:\docume~1\alluse~1\applic~1\olylam.exe
2009-09-02 21:59 16,707 a——- c:\program files\common files\uhixud.scr
2009-09-02 21:59 11,734 a——- c:\docume~1\aaron\applic~1\ohapiv.dat
2009-09-02 21:59 14,680 a——- c:\docume~1\alluse~1\applic~1\wyjabydi.bat
2009-09-02 21:36 14,787 a——- c:\docume~1\alluse~1\applic~1\hijofugen.bin
2009-09-02 16:32 19,492 a——- c:\docume~1\alluse~1\applic~1\xiheb.vbs
2009-09-02 07:45 18,114 a——- c:\docume~1\aaron\applic~1\iwuwutywi.dll
2009-09-02 07:45 15,460 a——- c:\program files\common files\eqafap.lib
2009-09-02 07:45 14,272 a——- c:\docume~1\aaron\applic~1\tuqybuviky.sys
2009-09-01 19:46 17,085 a——- c:\program files\common files\yjaqe._sy
2009-08-31 22:26 11,784 a——- c:\program files\common files\lohed._sy
2009-08-31 22:26 10,928 a——- c:\docume~1\aaron\applic~1\ubibypuhu.bin
2009-08-31 22:26 10,303 a——- c:\program files\common files\icajyna.reg
2009-08-31 19:04 13,848 a——- c:\docume~1\aaron\applic~1\izifa.dat
2009-08-31 19:04 13,252 a——- c:\docume~1\alluse~1\applic~1\sipoj.com
2009-08-31 19:04 11,703 a——- c:\program files\common files\evygi._sy
2009-08-31 19:04 11,413 a——- c:\docume~1\aaron\applic~1\lesomyti.sys
2007-05-24 15:58 249,856 a——- c:\windows\inf\wg311v3\InsDrv2k.exe
2006-12-04 12:38 212,992 a——- c:\windows\inf\wg311v3\CopyWHQLDriver.exe
2005-12-29 19:07 282,624 a—-r– c:\windows\inf\wg311v3\WG311v3XP.sys
============= FINISH: 20:14:28.85 ===============