Deleted Member
Topic Starter
Okay, so it hasn't started yet, but that's because I just restarted my computer, as it was becoming completely nonresponsive. I swear, my computer has picked up so many problems in the last few days I wouldn't know where to begin listing them. Oh! Wait, there it is! Ping just started again.
You know, you guys really are like exorcists of the modern day - except with science. Thank you so much for dedicating your time, knowledge & skills to the unenlightened
Here's my dds.txt log from DDS. Tell me what other information you need, & I'll get it for you right away.
—
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 23:21:23 on 2011-11-21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.986 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\svcs.exe
C:\Program Files\Soluto\SolutoService.exe
C:\Program Files\Soluto\soluto.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\TCB Networks\StrokeIt\StrokeIt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 4\firefox.exe
E:\Program files\CintaNotes_1_3\CintaNotes.exe
c:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 4\plugin-container.exe
c:\windows\bricopacks\vista inspirat 2\yzshadow\yzshadow.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\taskmgr.exe
E:\PROGRA~1\BXNEWF~1\bxExpHelper.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\ping.exe
c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
mURLSearchHooks: H - No File
mWinlogon: UIHost=c:\documents and settings\all users\application data\tuneup software\tu2011\winstyler\tu_logonui.exe
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: bxNewFolder: {51c8bca8-2524-4523-bf09-738c4eebfc58} - e:\progra~1\bxnewf~1\BXNEWF~1.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: WinAVI FLVSense: {e8df67a1-b618-4f3f-9e7c-cbe175adef5b} - c:\program files\winavi flv converter\FLVTune.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [StrokeIt] c:\program files\tcb networks\strokeit\StrokeIt.exe
uRun: [Creative Detector] "c:\program files\creative\mediasource\detector\CTDetect.exe" /R
mRun: []
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RCSystem] "c:\program files\creative\shared files\module loader\DLLML.exe" RCSystem * -Startup
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dseplugins\Direct3DVideoOutput.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dseplugins\DivXDeinterlaceFilter.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dpxplugins\DPXBannerAdPlugin.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dpxplugins\DPXMediaManagerPlugin.dll",DllRegisterServer
StartupFolder: c:\docume~1\user\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ultramon.lnk - c:\windows\installer\{83cccbdc-3a56-4f3b-89df-69386c3b7d62}\IcoUltraMon.ico
IE: &Download FLV by WinAVI… - c:\program files\winavi flv converter\flv_link.htm
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Download with Mipony - file://j:\my documents\mipony\browser\IEContext.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - {EC83A912-7EF4-410D-9CC7-3BDAA709CA71} - c:\program files\winavi flv converter\FLVTune.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{3634A0A4-30C1-4E77-BF1E-5CE737B10AE9} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{826FFF1D-08E9-4276-BE9F-4A4934983662} : DhcpNameServer = 208.67.220.220,208.67.222.222
TCP: Interfaces\{CA811296-C351-41D1-B9BB-83BB876B590D} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{E7AB7A7F-3159-4C46-95C2-CAD4E3FE3211} : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: FencesShlExt Class: {1984dd45-52cf-49cd-ab77-18f378fea264} - e:\program files\stardock\fences\FencesMenu.dll
STS: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - No File
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
IFEO: itunes.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: lightscribecontrolpanel.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: lslauncher.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: quickcam.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: softwareupdate.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
.
Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\do7cd2nb.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - prefs.js: keyword.URL - hxxp://google.com/search?btnI=1&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\user\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\documents and settings\user\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
FF - plugin: e:\program files\tracker software\pdf viewer\npPDFXCviewNPPlugin.dll
FF - plugin: e:\program files\videolan\vlc\npvlc.dll
.
—- FIREFOX POLICIES —-
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.max-persistent-connections-per-server - 4
.
============= SERVICES / DRIVERS ===============
.
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2010-6-7 39472]
R0 Soluto;Soluto;c:\windows\system32\drivers\Soluto.sys [2011-9-8 51144]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl18972ba1;MpKsl18972ba1;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\MpKsl18972ba1.sys [2011-11-21 28752]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [2001-12-19 8576]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\common files\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2008-11-14 17184]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [2010-12-22 642432]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-7 10064]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S1 MpKsl0cbd2938;MpKsl0cbd2938;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6f8a70c2-a5d4-49fc-ae57-e098b9c8c738}\mpksl0cbd2938.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6f8a70c2-a5d4-49fc-ae57-e098b9c8c738}\MpKsl0cbd2938.sys [?]
S1 MpKslacca5ef1;MpKslacca5ef1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d8f66e22-081f-48cc-870d-fc2b231a8030}\mpkslacca5ef1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d8f66e22-081f-48cc-870d-fc2b231a8030}\MpKslacca5ef1.sys [?]
S1 MpKsld2d1e502;MpKsld2d1e502;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2072dbf-068b-48d6-9170-2709b9ba2992}\mpksld2d1e502.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2072dbf-068b-48d6-9170-2709b9ba2992}\MpKsld2d1e502.sys [?]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
S3 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-14 136176]
S3 gUSBSTOi;gUSBSTOi;\??\c:\docume~1\user\locals~1\temp\gusbstoi.sys –> c:\docume~1\user\locals~1\temp\gUSBSTOi.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2010-12-22 50704]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-11-4 27064]
.
=============== File Associations ===============
.
.txt=
.
=============== Created Last 30 ================
.
2011-11-22 04:10:17 28752 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\MpKsl18972ba1.sys
2011-11-22 04:10:12 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\offreg.dll
2011-11-20 05:55:03 6668624 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\mpengine.dll
2011-11-19 02:34:13 ——– d—–w- c:\program files\3DO
2011-11-17 13:58:56 508928 —-a-w- c:\windows\svcs.exe
2011-11-16 21:25:39 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-11-16 21:25:39 ——– d—–w- c:\windows\system32\wbem\Repository
2011-11-16 21:02:37 ——– d—–w- c:\documents and settings\user\application data\2890A
2011-11-16 21:02:36 ——– d—–w- c:\program files\LP
2011-11-15 15:28:17 ——– d—–w- c:\program files\common files\xing shared
2011-11-10 01:52:34 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-11-06 21:46:18 6668624 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-11-05 21:43:59 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-11-05 21:43:59 215920 —-a-w- c:\windows\system32\muweb.dll
2011-11-05 21:43:59 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
2011-11-05 04:03:05 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-11-05 03:58:27 ——– d—–w- c:\program files\Microsoft Security Client
2011-11-05 02:11:25 27064 —-a-w- c:\windows\system32\drivers\revoflt.sys
2011-11-05 02:11:23 ——– d—–w- c:\program files\VS Revo Group
.
==================== Find3M ====================
.
2011-11-15 15:27:35 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-11-15 15:27:35 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-10-18 04:35:59 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-11 20:33:24 51144 —-a-w- c:\windows\system32\drivers\Soluto.sys
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32(3).dll
2011-09-07 19:53:30 60304 —-a-w- c:\documents and settings\user\g2mdlhlpx.exe
2011-09-06 23:07:42 240592 —-a-w- c:\windows\system32\nvdrsdb0.bin
2011-09-06 23:07:42 1 —-a-w- c:\windows\system32\nvdrssel.bin
2011-09-06 23:07:41 240592 —-a-w- c:\windows\system32\nvdrsdb1.bin
2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 23:23:19.76 ===============
Thanks again.
You know, you guys really are like exorcists of the modern day - except with science. Thank you so much for dedicating your time, knowledge & skills to the unenlightened
Here's my dds.txt log from DDS. Tell me what other information you need, & I'll get it for you right away.
—
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 23:21:23 on 2011-11-21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.986 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\svcs.exe
C:\Program Files\Soluto\SolutoService.exe
C:\Program Files\Soluto\soluto.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\TCB Networks\StrokeIt\StrokeIt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 4\firefox.exe
E:\Program files\CintaNotes_1_3\CintaNotes.exe
c:\windows\bricopacks\vista inspirat 2\ubericon\ubericon manager.exe
C:\Program Files\Mozilla Firefox 4.0 Beta 4\plugin-container.exe
c:\windows\bricopacks\vista inspirat 2\yzshadow\yzshadow.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\taskmgr.exe
E:\PROGRA~1\BXNEWF~1\bxExpHelper.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\ping.exe
c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
mURLSearchHooks: H - No File
mWinlogon: UIHost=c:\documents and settings\all users\application data\tuneup software\tu2011\winstyler\tu_logonui.exe
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: bxNewFolder: {51c8bca8-2524-4523-bf09-738c4eebfc58} - e:\progra~1\bxnewf~1\BXNEWF~1.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: WinAVI FLVSense: {e8df67a1-b618-4f3f-9e7c-cbe175adef5b} - c:\program files\winavi flv converter\FLVTune.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [StrokeIt] c:\program files\tcb networks\strokeit\StrokeIt.exe
uRun: [Creative Detector] "c:\program files\creative\mediasource\detector\CTDetect.exe" /R
mRun: []
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RCSystem] "c:\program files\creative\shared files\module loader\DLLML.exe" RCSystem * -Startup
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dseplugins\Direct3DVideoOutput.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dseplugins\DivXDeinterlaceFilter.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dpxplugins\DPXBannerAdPlugin.dll",DllRegisterServer
mRunOnce: "c:\windows\system32\rundll32.exe" "c:\program files\divx\divx plus player\dpxplugins\DPXMediaManagerPlugin.dll",DllRegisterServer
StartupFolder: c:\docume~1\user\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ultramon.lnk - c:\windows\installer\{83cccbdc-3a56-4f3b-89df-69386c3b7d62}\IcoUltraMon.ico
IE: &Download FLV by WinAVI… - c:\program files\winavi flv converter\flv_link.htm
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Download with Mipony - file://j:\my documents\mipony\browser\IEContext.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - {EC83A912-7EF4-410D-9CC7-3BDAA709CA71} - c:\program files\winavi flv converter\FLVTune.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{3634A0A4-30C1-4E77-BF1E-5CE737B10AE9} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{826FFF1D-08E9-4276-BE9F-4A4934983662} : DhcpNameServer = 208.67.220.220,208.67.222.222
TCP: Interfaces\{CA811296-C351-41D1-B9BB-83BB876B590D} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{E7AB7A7F-3159-4C46-95C2-CAD4E3FE3211} : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: FencesShlExt Class: {1984dd45-52cf-49cd-ab77-18f378fea264} - e:\program files\stardock\fences\FencesMenu.dll
STS: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - No File
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
IFEO: itunes.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: lightscribecontrolpanel.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: lslauncher.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: quickcam.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
IFEO: softwareupdate.exe - "c:\program files\tuneup utilities 2011\TUAutoReactivator32.exe"
.
Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\do7cd2nb.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - prefs.js: keyword.URL - hxxp://google.com/search?btnI=1&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\user\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\documents and settings\user\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
FF - plugin: e:\program files\tracker software\pdf viewer\npPDFXCviewNPPlugin.dll
FF - plugin: e:\program files\videolan\vlc\npvlc.dll
.
—- FIREFOX POLICIES —-
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.max-persistent-connections-per-server - 4
.
============= SERVICES / DRIVERS ===============
.
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2010-6-7 39472]
R0 Soluto;Soluto;c:\windows\system32\drivers\Soluto.sys [2011-9-8 51144]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl18972ba1;MpKsl18972ba1;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\MpKsl18972ba1.sys [2011-11-21 28752]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [2001-12-19 8576]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\common files\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2008-11-14 17184]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [2010-12-22 642432]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-7 10064]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S1 MpKsl0cbd2938;MpKsl0cbd2938;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6f8a70c2-a5d4-49fc-ae57-e098b9c8c738}\mpksl0cbd2938.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{6f8a70c2-a5d4-49fc-ae57-e098b9c8c738}\MpKsl0cbd2938.sys [?]
S1 MpKslacca5ef1;MpKslacca5ef1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d8f66e22-081f-48cc-870d-fc2b231a8030}\mpkslacca5ef1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{d8f66e22-081f-48cc-870d-fc2b231a8030}\MpKslacca5ef1.sys [?]
S1 MpKsld2d1e502;MpKsld2d1e502;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2072dbf-068b-48d6-9170-2709b9ba2992}\mpksld2d1e502.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b2072dbf-068b-48d6-9170-2709b9ba2992}\MpKsld2d1e502.sys [?]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
S3 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-14 136176]
S3 gUSBSTOi;gUSBSTOi;\??\c:\docume~1\user\locals~1\temp\gusbstoi.sys –> c:\docume~1\user\locals~1\temp\gUSBSTOi.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2010-12-22 50704]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-11-4 27064]
.
=============== File Associations ===============
.
.txt=
.
=============== Created Last 30 ================
.
2011-11-22 04:10:17 28752 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\MpKsl18972ba1.sys
2011-11-22 04:10:12 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\offreg.dll
2011-11-20 05:55:03 6668624 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bd988f07-5b6d-47c1-b468-71be844bcce3}\mpengine.dll
2011-11-19 02:34:13 ——– d—–w- c:\program files\3DO
2011-11-17 13:58:56 508928 —-a-w- c:\windows\svcs.exe
2011-11-16 21:25:39 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-11-16 21:25:39 ——– d—–w- c:\windows\system32\wbem\Repository
2011-11-16 21:02:37 ——– d—–w- c:\documents and settings\user\application data\2890A
2011-11-16 21:02:36 ——– d—–w- c:\program files\LP
2011-11-15 15:28:17 ——– d—–w- c:\program files\common files\xing shared
2011-11-10 01:52:34 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-11-06 21:46:18 6668624 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-11-05 21:43:59 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-11-05 21:43:59 215920 —-a-w- c:\windows\system32\muweb.dll
2011-11-05 21:43:59 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
2011-11-05 04:03:05 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-11-05 03:58:27 ——– d—–w- c:\program files\Microsoft Security Client
2011-11-05 02:11:25 27064 —-a-w- c:\windows\system32\drivers\revoflt.sys
2011-11-05 02:11:23 ——– d—–w- c:\program files\VS Revo Group
.
==================== Find3M ====================
.
2011-11-15 15:27:35 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-11-15 15:27:35 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-10-18 04:35:59 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-11 20:33:24 51144 —-a-w- c:\windows\system32\drivers\Soluto.sys
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32(3).dll
2011-09-07 19:53:30 60304 —-a-w- c:\documents and settings\user\g2mdlhlpx.exe
2011-09-06 23:07:42 240592 —-a-w- c:\windows\system32\nvdrsdb0.bin
2011-09-06 23:07:42 1 —-a-w- c:\windows\system32\nvdrssel.bin
2011-09-06 23:07:41 240592 —-a-w- c:\windows\system32\nvdrsdb1.bin
2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 23:23:19.76 ===============
Thanks again.