Hello _silver_,
First off, Id like to thank you for the assistance. When I visited the link, I do not recall getting any popups or any kind of prompt with Firefox. I used DrWeb's Cureit and everything came up clean.
Heres the DSS log.
Deckard's System Scanner v20070729.57
Run by Guolin Wang on 2007-07-30 at 12:40:22
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
16: 2007-07-29 03:36:04 UTC - RP147 - Removed Halo 2 for Windows Vista
15: 2007-07-29 03:18:10 UTC - RP146 - Removed LIVE gaming on Windows Runtime Version 1.0.6027
14: 2007-07-29 03:11:11 UTC - RP145 - Restore Operation
13: 2007-07-28 11:45:39 UTC - RP144 - Removed ATLAS Translation Double Pack V13.0 Trial Version
12: 2007-07-28 11:21:06 UTC - RP143 - Removed Microsoft AppLocale
-- First Restore Point --
1: 2007-07-28 05:42:14 UTC - RP128 - ???????? PRODUCT_NAME
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-07-30 12:41:24
Platform: Windows Vista (6.00.6000)
MSIE: Internet Explorer (7.00.6000.16386)
Running processes:
C:\Windows\System32\taskeng.exe
C:\Windows\System32\dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Windows\System32\mobsync.exe
C:\Users\Guolin Wang\Desktop\utorrent.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Guolin Wang\Desktop\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
O4 - HKEY_LOCAL_MACHINE\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKEY_LOCAL_MACHINE\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKEY_LOCAL_MACHINE\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKEY_LOCAL_MACHINE\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKEY_LOCAL_MACHINE\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKEY_LOCAL_MACHINE\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKEY_LOCAL_MACHINE\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) -
http://support.f-sec...m/ols/fscax.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\system32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 AvgWFP (AVG7 Firewall Driver x86) - c:\windows\system32\drivers\avgwfp.sys
R3 pgfilter - \??\c:\program files\peerguardian2\pgfilter.sys
S3 ENTECH - \??\c:\windows\system32\drivers\entech.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Scheduled Tasks -------------------------------------------------------------
2007-07-30 06:05:33 430 --ah----- C:\Windows\Tasks\User_Feed_Synchronization-{E76537CB-C56F-4DFE-9E6F-166AF3A2B80A}.job
-- Files created between 2007-06-30 and 2007-07-30 -----------------------------
2007-07-30 11:11:33 0 d-------- C:\Users\Guolin Wang\DoctorWeb
2007-07-29 20:49:34 2379 --a------ C:\Windows\mozver.dat
2007-07-28 22:12:22 0 d-------- C:\Users\Guolin Wang\.housecall6.6
2007-07-25 15:21:01 0 d-------- C:\Windows\Internet Logs
2007-07-24 03:59:00 0 d-------- C:\Users\All Users\Microsoft Games
-- Find3M Report ---------------------------------------------------------------
2007-07-30 12:41:33 0 d-------- C:\Program Files\PeerGuardian2
2007-07-30 12:41:32 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\uTorrent
2007-07-30 11:04:33 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\AVG7
2007-07-30 08:56:00 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\LimeWire
2007-07-29 22:59:30 0 d-------- C:\Program Files\Warcraft III
2007-07-28 23:37:26 0 d-------- C:\Program Files\Microsoft Games
2007-07-28 23:13:20 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\Winamp
2007-07-28 23:13:20 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\Ventrilo
2007-07-28 02:53:27 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-07-28 01:42:06 0 d-------- C:\Program Files\Common Files\InstallShield
2007-07-27 22:59:08 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\Microsoft Game Studios
2007-07-23 15:12:54 0 d-------- C:\Program Files\World of Warcraft
2007-07-23 15:12:30 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\WowAceUpdater
2007-07-23 02:19:46 0 d-------- C:\Program Files\Combined Community Codec Pack
2007-07-22 07:45:40 24227 --a------ C:\Users\Guolin Wang\AppData\Roaming\UserTile.png
2007-07-16 18:11:18 0 d-------- C:\Program Files\WC3Banlist
2007-07-11 11:54:45 0 d-------- C:\Program Files\Windows Mail
2007-07-09 21:33:02 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\WinRAR
2007-07-04 00:04:17 0 d-------- C:\Program Files\DivX
2007-06-29 14:53:59 0 d-------- C:\Program Files\Analog Devices
2007-06-15 03:08:23 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\Sun
2007-06-11 16:26:10 0 d-------- C:\Program Files\LimeWire
2007-06-11 16:26:03 0 d-------- C:\Program Files\Java
2007-06-11 16:24:53 0 d-------- C:\Program Files\Common Files
2007-06-11 16:24:53 0 d-------- C:\Program Files\Common Files\Java
2007-06-11 16:17:36 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\Sony
2007-06-11 16:08:39 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\Publish Providers
2007-06-11 15:29:08 0 d-------- C:\Program Files\Vstplugins
2007-06-11 15:28:47 0 d-------- C:\Program Files\Sony
2007-06-11 15:27:13 0 d-------- C:\Program Files\Sony Setup
2007-06-09 16:47:35 0 d-------- C:\Users\Guolin Wang\AppData\Roaming\Apple Computer
2007-06-09 16:45:42 0 d-------- C:\Program Files\QuickTime
2007-06-07 21:15:56 530 --a------ C:\Windows\eReg.dat
2007-06-05 18:40:14 0 d-------- C:\Program Files\Common Files\Invictus
2007-06-05 18:37:30 0 d-------- C:\Program Files\DAEMON Tools
2007-05-31 09:28:26 0 d-------- C:\Program Files\Starcraft
2007-05-30 18:16:42 33926 --a------ C:\Windows\scunin.dat
2007-05-30 18:16:41 967 --a------ C:\Windows\ScUnin.pif
2007-05-30 18:16:41 70656 --a------ C:\Windows\ScUnin.exe <Not Verified; Blizzard Entertainment; Starcraft Uninstaller>
2007-05-21 16:34:51 76604 --a------ C:\Windows\War3Unin.dat
2007-05-21 16:30:57 2829 --a------ C:\Windows\War3Unin.pif
2007-05-21 16:30:57 139264 --a------ C:\Windows\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2007-05-21 15:37:31 335 --a------ C:\Windows\nsreg.dat
2007-05-15 17:40:07 0 -rahs---- C:\MSDOS.SYS
2007-05-15 17:40:07 0 -rahs---- C:\IO.SYS
2007-05-14 20:09:00 262144 --a------ C:\Windows\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2007-05-14 20:09:00 86016 --a------ C:\Windows\system32\OpenAL32.dll <Not Verified; Portions © Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL Library>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [05/14/2007 03:25 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [05/23/2007 10:09 AM]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [04/26/2007 04:17 PM]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [04/26/2007 04:17 PM]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [04/26/2007 04:17 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/27/2007 09:41 AM]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [12/18/2006 09:34 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 08:34 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 05/23/2007 10:10 AM 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0b11ec4a-024e-11dc-9d18-806e6f6e6963}]
AutoRun\command- D:\autoplay.exe
*Newly Created Service* - F-SECURE_STANDALONE_MINIFILTER
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2007-07-30 at 12:41:59 ---------