ok….here are the logs…took a while because it doesn't help that my internet itself has been up and down like a yoyo over the last couple of days.
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000017c
Kernel Drivers (total 132):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E4000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F79000 ACPI.sys
0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB9F68000 pci.sys
0xBA0A8000 isapnp.sys
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xBA0B8000 MountMgr.sys
0xB9F49000 ftdisk.sys
0xBA5AC000 dmload.sys
0xB9F23000 dmio.sys
0xBA330000 PartMgr.sys
0xBA0C8000 VolSnap.sys
0xB9F0B000 atapi.sys
0xBA0D8000 disk.sys
0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB9EEB000 fltMgr.sys
0xB9ED9000 sr.sys
0xB9EC2000 KSecDD.sys
0xB9EAF000 WudfPf.sys
0xB9E22000 Ntfs.sys
0xB9DF5000 NDIS.sys
0xBA0F8000 ohci1394.sys
0xBA108000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xB9DDB000 Mup.sys
0xBA118000 avgrkx86.sys
0xBA128000 AVGIDSxx.sys
0xBA148000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xB95B6000 \SystemRoot\system32\DRIVERS\SMBios.sys
0xBA158000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB942E000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xB941A000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB93F2000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xBA428000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB93CE000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA430000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB93A7000 \SystemRoot\system32\DRIVERS\e100b325.sys
0xB9393000 \SystemRoot\system32\DRIVERS\parport.sys
0xBA168000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xBA438000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xBA178000 \SystemRoot\system32\DRIVERS\serial.sys
0xBA598000 \SystemRoot\system32\DRIVERS\serenum.sys
0xBA188000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA198000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xBA1A8000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB9370000 \SystemRoot\system32\DRIVERS\ks.sys
0xBA440000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0xBA6B3000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA1B8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA5A0000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB9359000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA1C8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA1D8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xBA448000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB9348000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA1E8000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xBA450000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xBA458000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB9318000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xBA1F8000 \SystemRoot\system32\DRIVERS\termdd.sys
0xBA460000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xB92FB000 \SystemRoot\system32\DRIVERS\mcdbus.sys
0xB92E3000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0xBA5E6000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB9285000 \SystemRoot\system32\DRIVERS\update.sys
0xB9D8E000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xBA208000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA9114000 \SystemRoot\system32\drivers\sthda.sys
0xA90F0000 \SystemRoot\system32\drivers\portcls.sys
0xBA238000 \SystemRoot\system32\drivers\drmk.sys
0xBA248000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xBA5EC000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xBA5EE000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA723000 \SystemRoot\System32\Drivers\Null.SYS
0xBA5F0000 \SystemRoot\System32\Drivers\Beep.SYS
0xBA480000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xBA488000 \SystemRoot\System32\drivers\vga.sys
0xBA5F2000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xBA5F4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xBA490000 \SystemRoot\System32\Drivers\Msfs.SYS
0xBA498000 \SystemRoot\System32\Drivers\Npfs.SYS
0xBA54C000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xA9095000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xA903C000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xA9002000 \SystemRoot\System32\Drivers\avgtdix.sys
0xA8F3C000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xBA268000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xBA4B0000 \SystemRoot\System32\Drivers\StMp3Rec.sys
0xBA278000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xBA560000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xBA288000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xBA564000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xA8E8C000 \SystemRoot\system32\DRIVERS\netbt.sys
0xA8E6A000 \SystemRoot\System32\drivers\afd.sys
0xBA2A8000 \SystemRoot\system32\DRIVERS\netbios.sys
0xBA340000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0xA8E3F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xBA7DF000 \SystemRoot\System32\Drivers\PQNTDrv.SYS
0xA80E7000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xBA2B8000 \SystemRoot\System32\Drivers\Fips.SYS
0xBA368000 \SystemRoot\System32\Drivers\avgmfx86.sys
0xA80A2000 \SystemRoot\System32\Drivers\avgldx86.sys
0xB95F6000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xA8062000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xBA640000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB9281000 \SystemRoot\System32\drivers\Dxapi.sys
0xBA3C0000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA72C000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF054000 \SystemRoot\System32\ati2cqag.dll
0xBF08E000 \SystemRoot\System32\atikvmag.dll
0xBF0C4000 \SystemRoot\System32\ati3duag.dll
0xBF32B000 \SystemRoot\System32\ativvaxx.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xA5E5E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA5D62000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys
0xB9606000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys
0xA5CA2000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys
0xA5A6D000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xBA654000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xA58FD000 \SystemRoot\system32\DRIVERS\srv.sys
0xBA618000 \??\C:\WINDOWS\system32\drivers\SIODRV.SYS
0xA5320000 \SystemRoot\system32\drivers\wdmaud.sys
0xA5575000 \SystemRoot\system32\drivers\sysaudio.sys
0xA4BF6000 \SystemRoot\System32\Drivers\HTTP.sys
0xA47C2000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 49):
0 System Idle Process
4 System
1312 C:\WINDOWS\system32\smss.exe
1632 csrss.exe
1708 C:\WINDOWS\system32\winlogon.exe
1768 C:\WINDOWS\system32\services.exe
1780 C:\WINDOWS\system32\lsass.exe
1992 C:\WINDOWS\system32\ati2evxx.exe
2008 C:\WINDOWS\system32\svchost.exe
228 svchost.exe
416 C:\WINDOWS\system32\svchost.exe
464 C:\WINDOWS\system32\svchost.exe
492 C:\Program Files\AVG\AVG9\avgchsvx.exe
500 C:\Program Files\AVG\AVG9\avgrsx.exe
620 C:\Program Files\AVG\AVG9\avgcsrvx.exe
796 svchost.exe
856 svchost.exe
1060 C:\WINDOWS\system32\spoolsv.exe
1112 C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
940 svchost.exe
972 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
1032 C:\Program Files\AVG\AVG9\avgwdsvc.exe
1352 C:\Program Files\Bonjour\mDNSResponder.exe
1440 C:\WINDOWS\system32\CTSVCCDA.EXE
1676 C:\Program Files\Java\jre6\bin\jqs.exe
384 C:\Program Files\Net Nanny\NNSvc.exe
1540 C:\WINDOWS\system32\IoctlSvc.exe
1864 C:\WINDOWS\system32\HPZipm12.exe
2232 C:\Program Files\AVG\AVG9\avgam.exe
2284 C:\Program Files\AVG\AVG9\avgnsx.exe
2764 C:\WINDOWS\system32\svchost.exe
2840 C:\WINDOWS\system32\searchindexer.exe
3796 alg.exe
2428 C:\Program Files\Net Nanny\nntray.exe
2732 C:\WINDOWS\system32\wscntfy.exe
4076 C:\WINDOWS\system32\ati2evxx.exe
1600 C:\WINDOWS\explorer.exe
1920 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
2864 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
2820 C:\PROGRA~1\AVG\AVG9\avgtray.exe
3864 C:\Program Files\AVG\AVG9\avgcsrvx.exe
700 C:\WINDOWS\system32\svchost.exe
3452 C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
3684 C:\Program Files\Mozilla Firefox\firefox.exe
3396 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
1644 C:\Program Files\Mozilla Firefox\plugin-container.exe
3580 C:\WINDOWS\system32\searchprotocolhost.exe
3884 searchfilterhost.exe
4020 C:\Documents and Settings\zacr\My Documents\Downloads\New Folder\MBRCheck.exe
\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: –> \\.\PhysicalDrive1 at offset 0x00000000`007e0000 (NTFS)
\\.\E: –> \\.\PhysicalDrive2 at offset 0x00000000`00007e00 (NTFS)
\\.\I: –> \\.\PhysicalDrive3 at offset 0x00000001`384cf800 (NTFS)
PhysicalDrive0 Model Number: WDCWD600JB-00CRA1, Rev: 17.07W17
PhysicalDrive1 Model Number: WDCWD1600JD-22HBB0, Rev: 08.02D08
PhysicalDrive2 Model Number: HitachiHDS721616PLA380, Rev: P22OABEA
PhysicalDrive3 Model Number: ST9160821AS
Size Device Name MBR Status
——————————————–
55 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
149 GB \\.\PhysicalDrive1 Gateway MBR code detected
SHA1: 007DADCB3671462B53686F6996D328CFD544ABBD
149 GB \\.\PhysicalDrive2 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
149 GB \\.\PhysicalDrive3 Unknown MBR code
SHA1: 6A37CCD118436B688B51F6BD4C2B47A895EBDF7F
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done!
DDS (Ver_10-11-26.01) - NTFSx86
Run by [removed] at 10:00:10.15 on 26/11/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2322 [GMT -7:00]
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Net Nanny\nnsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Net Nanny\nntray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\zacr\My Documents\Downloads\New Folder\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [NNTray] c:\program files\net nanny\nnstart.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - d:\utilit~1\micros~1\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\utilit~1\micros~1\office11\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256943299296
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} -
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} -
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\zacr\applic~1\mozilla\firefox\profiles\c5tway0f.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: c:\documents and settings\zacr\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\documents and settings\zacr\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npkanevapatch.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-8-4 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-8-4 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-8-4 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-8-4 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-8-4 243024]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-8-4 308136]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-8-4 5897808]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-8-4 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-8-4 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-8-4 26192]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-3 135664]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-10-26 517448]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-7-14 19720]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-3-29 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-3-29 8320]
=============== Created Last 30 ================
2010-11-23 06:25:22 ——– d—–w- c:\docume~1\zacr\locals~1\applic~1\Scansoft
2010-11-22 04:16:28 ——– d—–w- c:\program files\SSBkgd Update Removal Tool
2010-11-21 21:14:15 ——– d—–w- c:\docume~1\zacr\applic~1\Nuance
2010-11-21 21:10:00 ——– d—–w- c:\docume~1\alluse~1.win\applic~1\Nuance
2010-11-21 16:38:11 ——– d—–w- c:\windows\system32\wbem\repository\FS
2010-11-21 16:38:11 ——– d—–w- c:\windows\system32\wbem\Repository
2010-11-08 05:10:51 ——– d—–w- c:\program files\MSN Messenger
==================== Find3M ====================
2010-09-18 18:23:26 974848 ——w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ——w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ——w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ——w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51:14 285824 —-a-w- c:\windows\system32\atmfd.dll
============= FINISH: 10:01:26.28 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-11-26.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 30/10/2009 3:08:36 PM
System Uptime: 26/11/2010 7:09:52 AM (3 hours ago)
Motherboard: Intel Corporation | | D945GTP
Processor: Intel® Pentium® 4 CPU 3.00GHz | LGA 775 | 3000/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 56 GiB total, 21.681 GiB free.
D: is FIXED (NTFS) - 149 GiB total, 139.636 GiB free.
E: is FIXED (NTFS) - 149 GiB total, 58.489 GiB free.
F: is CDROM ()
G: is CDROM ()
I: is FIXED (NTFS) - 144 GiB total, 61.042 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia Windows Portable Device Driver
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 6085
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
==== System Restore Points ===================
RP79: 18/10/2010 7:52:22 PM - System Checkpoint
RP80: 20/10/2010 10:49:23 PM - System Checkpoint
RP81: 22/10/2010 6:49:26 AM - System Checkpoint
RP82: 23/10/2010 7:17:01 PM - System Checkpoint
RP83: 24/10/2010 8:30:17 AM - Install CloneDVD
RP84: 24/10/2010 8:50:10 AM - Remove CloneDVD
RP85: 25/10/2010 6:44:54 PM - System Checkpoint
RP86: 26/10/2010 9:06:06 AM - Avg Update
RP87: 26/10/2010 6:02:12 PM - Removed Intel® Desktop Utilities
RP88: 27/10/2010 10:49:17 AM - Configured Microsoft Flight Simulator X
RP89: 27/10/2010 12:15:51 PM - Removed QuickTax 2008.
RP90: 27/10/2010 12:53:49 PM - Removed QuickTax 2009.
RP91: 29/10/2010 10:53:58 PM - System Checkpoint
RP92: 30/10/2010 11:13:21 PM - System Checkpoint
RP93: 02/11/2010 7:15:27 PM - Installed TRS2006
RP94: 03/11/2010 9:30:45 PM - System Checkpoint
RP95: 05/11/2010 6:50:44 PM - System Checkpoint
RP96: 06/11/2010 11:16:51 PM - System Checkpoint
RP97: 07/11/2010 10:10:49 PM - Installed MSN Messenger 7.0
RP98: 08/11/2010 9:42:38 PM - Installed Norton PartitionMagic
RP99: 09/11/2010 9:19:30 AM - Avg Update
RP100: 09/11/2010 9:19:54 AM - Avg Update
RP101: 10/11/2010 8:23:24 PM - System Checkpoint
RP102: 10/11/2010 11:20:27 PM - Software Distribution Service 3.0
RP103: 12/11/2010 3:17:16 PM - System Checkpoint
RP104: 18/11/2010 8:11:25 AM - System Checkpoint
RP105: 19/11/2010 10:20:11 AM - System Checkpoint
RP106: 20/11/2010 11:35:31 PM - Restore Operation
RP107: 21/11/2010 3:00:21 AM - Software Distribution Service 3.0
RP108: 21/11/2010 4:58:05 AM - Avg Update
RP109: 21/11/2010 4:59:09 AM - Avg Update
RP110: 21/11/2010 9:09:00 AM - Restore Operation
RP111: 21/11/2010 9:30:36 AM - Restore Operation
RP112: 21/11/2010 2:05:35 PM - Installed Visual C++ Runtime for Dragon NaturallySpeaking.
RP113: 21/11/2010 2:09:36 PM - Installed Dragon NaturallySpeaking 10.
RP114: 23/11/2010 12:05:24 AM - System Checkpoint
RP115: 23/11/2010 8:55:58 PM - Removed Dragon NaturallySpeaking 10.
RP116: 24/11/2010 8:33:51 AM - Avg Update
RP117: 24/11/2010 8:34:31 AM - Avg Update
RP118: 25/11/2010 9:39:24 AM - System Checkpoint
RP119: 26/11/2010 9:44:05 AM - System Checkpoint
==== Installed Programs ======================
"Nero SoundTrax Help
Activision®
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2
Adobe Shockwave Player 11.5
AiO_Scan_CDA
AiOSoftwareNPI
Alberta Divorce Forms
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATI HYDRAVISION
ATI Problem Report Wizard
AVG 9.0
Bonjour
Cloudy with a Chance of Meatballs™
ClueFinders 3rd Grade Adventures
Dogz (remove only)
Driver Genius Professional Edition
Fax_CDA
Free Audio Converter version 1.2
gBurner
Ghostbusters ™: The Video Game
Google Chrome
Google Earth
Google Update Helper
HiJackThis
HijackThis 2.0.2
Hot Wheels® Stunt Track Driver 2 - GET'N DIRTY™
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Photosmart, Officejet and Deskjet 7.0.A
ImagXpress
Intel® Graphics Media Accelerator Driver
Intel® Network Connections [removed]
iTunes
Java Auto Updater
Java™ 6 Update 20
JumpStart 3rd Grade
Knight Rider
Knight Rider 2
LEGO Island 2
LEGO Star Wars II
LEGO® Batman™
LEGO® Harry Potter™: Years 1-4
LEGO® Indiana Jones™
LEGO® Indiana Jones™ 2
LEGO® Indiana Jones™ 2: The Adventure Continues
LEGO® Star Wars™: The Complete Saga
Lernout & Hauspie TruVoice American English TTS Engine
LucasArts' X-Wing
LucasArts' XvT: Flight School
Magic ISO Maker v5.4 (build 0239)
MagicDisc 2.7.106
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Professional Edition 2003
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.7
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Web Publishing Wizard 1.52
Microsoft Windows Media Video 9 VCM
Microsoft WSE 3.0 Runtime
Microsoft XML Parser
Mozilla Firefox (3.6.12)
MSN
MSN Messenger 7.0
MSVC80_x86_v2
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nero 7 Ultra Edition
Nero BurningROM
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero CoverDesigner Help
Nero Disc Copy Gadget
Nero Disc Copy Gadget Help
Nero DiscSpeed
Nero DriveSpeed
Nero Express
Nero InfoTool
Nero Live
Nero Live Help
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero Rescue Agent
Nero RescueAgent Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero WaveEditor
Nero WaveEditor Help
NeroBurningROM
NeroExpress
neroxml
Net Nanny 5 (Remove Only)
NewCopy_CDA
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia Software Updater
Norton PartitionMagic
Norton PartitionMagic 8.0
OpenAL
PC Connectivity Solution
Photo Viewer V208G2
PowerISO
QFolder
QuickTime
Reader Rabbit 2nd Grade
Reader Rabbit Learn To Read With Phonics
Readme
Scan
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Shockwave
SoundTrax
Spelling Blaster Ages 6-9
SPIDERMAN 2 CRACKED
SpongeBob SquarePants Typing
Star Wars: Rogue Squadron™ 3D
Stunt Track Driver
System Requirements Lab for Intel
System47 Screen Saver
The Print Shop 22
Tonka Construction 2
TONKA Firefighter
TONKA Search & Rescue 2
Tonka Search and Rescue
Tonka® On the Job
Transformers™ - Revenge of the Fallen™
TRS2006
Unity Web Player
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB898461)
Update for Windows XP (KB943729)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VCRedistSetup
Visual C++ Runtime for Dragon NaturallySpeaking
Vuze
WBFS Manager 4.0
WebFldrs XP
WebReg
Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4)
Windows Driver Package - Nokia Modem (10/05/2009 4.2)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows PowerShell™ 1.0
Windows Search 4.0
Yahoo! BrowserPlus 2.9.8
Yahoo! Messenger
ZEN V Series Media Explorer
==== End Of File ===========================
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2010-11-26 13:09:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c WDC_WD600JB-00CRA1 rev.17.07W17
Running: wz84mhtu.exe; Driver: C:\DOCUME~1\zacr\LOCALS~1\Temp\ufldapod.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA5D64670]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xA5D64720]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA5D647C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA5D64860]
—- Kernel code sections - GMER 1.0.15 —-
? C:\DOCUME~1\zacr\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 014E2690 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!send 71AB4C27 5 Bytes JMP 014E24E0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 014E47D0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 014E2850 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 014E49A0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 014E2A00 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 10405CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!sendto 71AB2F51 5 Bytes JMP 063D2690 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!send 71AB4C27 5 Bytes JMP 063D24E0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 063D47D0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 063D2850 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 063D49A0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 063D2A00 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\WINDOWS\system32\SearchIndexer.exe[2840] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!sendto 71AB2F51 5 Bytes JMP 06B02690 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!send 71AB4C27 5 Bytes JMP 06B024E0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 06B047D0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 06B02850 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 06B049A0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 06B02A00 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 02832690 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!send 71AB4C27 5 Bytes JMP 028324E0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 028347D0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 02832850 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 028349A0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 02832A00 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat A45ADD20
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
—- Registry - GMER 1.0.15 —-
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\games\LEGO\xae Indiana Jones\x2122 2\Audio\Audio.CFG 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\games\LEGO\xae Indiana Jones\x2122 2\Audio\_CutScenes\AkatorHub_Intro.ogg 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\games\LEGO\xae Indiana Jones\x2122 2\Audio\_Music\1_0_HUB_1Nepal_Qui.ogg 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\games\LEGO\xae Indiana Jones\x2122 2\Movies\PC\attract.bik 1
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\Temp\fbdf5c1b-2a49-4503-96da-05cc8f31fc36.tmp 0 bytes
—- EOF - GMER 1.0.15 —-