This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google search brings up wrong webpages

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had a trojan the other day I removed it using Avg and run a scan with Spybot and also removed it with that. When I use google search for example say if I wanted to get onto Wikipedia i would click the first link google gives me but the search sometimes diverts me to a different website, usually search engines such as Britanniasearch, is there anyway you could help me fix this
heres my log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:05:38, on 09/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Vtune\TBPanel.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe /A
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Comrade.exe] C:\Program Files\GameSpy\Comrade\Comrade.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1201162107984
O17 - HKLM\System\CCS\Services\Tcpip\..\{60D251E4-B862-469B-A1B4-7554C9CDF31A}: NameServer = 192.168.0.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Performance Driver Service - Unknown owner - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 7911 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through the instructions before starting to follow them to amek sure you understand everything you have to do.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


You need to disable TeaTimer, so that it doesn't interfere with our fix.

This is a two step process.
First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, click once on Resident Protection, then right-click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For both versions :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go to the bottom of the vertical panel on the left, click Tools
  • Then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

Thanks.
The Malwarebytes log: Malwarebytes' Anti-Malware 1.33 Database version: 1739 Windows 5.1.2600 Service Pack 2 09/02/2009 13:58:14 mbam-log-2009-02-09 (13-58-14).txt Scan type: Quick Scan Objects scanned: 47352 Time elapsed: 4 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) DDS: DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 13:58:59.84 on 09/02/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1460 [GMT 0:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Vtune\TBPanel.exe C:\Program Files\DNA\btdna.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\RALINK\Common\RaUI.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.uk/ uInternet Settings,ProxyOverride = *.local BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [TBPanel] c:\program files\vtune\TBPanel.exe /A uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [Comrade.exe] c:\program files\gamespy\comrade\Comrade.exe uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201162107984 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab TCP: {60D251E4-B862-469B-A1B4-7554C9CDF31A} = 192.168.0.1 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\n7xx419v.default\ FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava11.dll FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava12.dll FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava13.dll FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava14.dll FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava32.dll FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPOJI610.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-17 96520] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-8-17 26824] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-8-17 873752] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-17 231192] R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-8-17 76040] R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2008-12-11 3575808] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] =============== Created Last 30 ================ 2009-02-08 21:44 -cd—– c:\docume~1\admini~1\applic~1\Malwarebytes 2009-02-08 21:44 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-02-08 21:44 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-08 21:44 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-02-08 21:44 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-02-08 18:55 –d—– c:\program files\Spybot - Search & Destroy 2009-02-08 18:55 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-02-08 16:21 67,584 a——- c:\windows\system32\drivers\senekaxmlygwff.sys.vir 2009-02-08 16:17 –d—– c:\program files\Trojan Remover 2009-02-08 16:00 -cd—– C:\VundoFix Backups 2009-02-07 17:57 -cd—– c:\temp\sTMP3 2009-02-07 17:57 –d—– c:\windows\system32\wp2 2009-02-07 17:57 -cd—– C:\Temp 2009-02-07 17:56 68,096 a——- c:\windows\system32\nkmmmhgq.dll.vir 2009-02-07 17:55 236,032 a——- c:\windows\system32\khfEXNDw.dll.vir 2009-02-07 17:51 -cd-h— C:\$AVG8.VAULT$ 2009-01-26 12:35 –d—– c:\docume~1\alluse~1\applic~1\Electronic Arts 2009-01-20 19:37 –d—– c:\program files\Bethesda Softworks 2009-01-20 19:35 –d—– c:\windows\system32\xlive 2009-01-20 01:30 –d—– c:\program files\Mozilla ActiveX Control v1.7.12 2009-01-20 01:06 -cd—– c:\docume~1\admini~1\applic~1\Graboid Inc 2009-01-16 16:31 268 ac–h— C:\sqmdata01.sqm 2009-01-16 16:31 244 ac–h— C:\sqmnoopt01.sqm 2009-01-14 22:25 –d—– c:\program files\Activision 2009-01-14 22:00 –dsh— c:\windows\ftpcache 2009-01-14 21:44 –d—– c:\program files\PowerISO 2009-01-14 21:42 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Pro 2009-01-14 21:41 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite 2009-01-14 21:40 –d—– c:\program files\DAEMON Tools Lite 2009-01-14 21:22 717,296 a——- c:\windows\system32\drivers\sptd.sys 2009-01-14 21:22 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Lite 2009-01-12 18:49 -cd—– c:\docume~1\admini~1\applic~1\DNA 2009-01-12 18:49 –d—– c:\program files\DNA 2009-01-11 15:13 1,456 a——- c:\windows\system32\ealregsnapshot1.reg ==================== Find3M ==================== 2009-01-25 03:11 98,304 a——- c:\windows\system32\CmdLineExt.dll 2009-01-25 02:17 138,464 a——- c:\windows\system32\drivers\PnkBstrK.sys 2009-01-25 02:17 111,928 a——- c:\windows\system32\PnkBstrB.exe 2009-01-14 22:40 22,328 ac—— c:\docume~1\admini~1\applic~1\PnkBstrK.sys 2009-01-14 22:40 682,280 a——- c:\windows\system32\pbsvc.exe 2009-01-14 22:40 66,872 a——- c:\windows\system32\PnkBstrA.exe 2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf 2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf 2008-12-23 21:58 453,152 a——- c:\windows\system32\NVUNINST.EXE 2008-11-21 21:47 524,288 a——- c:\windows\system32\DivXsm.exe 2008-11-21 21:47 3,596,288 a——- c:\windows\system32\qt-dx331.dll 2008-11-21 21:47 129,784 a——- c:\windows\system32\pxafs.dll 2008-11-21 21:47 120,056 a——- c:\windows\system32\pxcpyi64.exe 2008-11-21 21:47 118,520 a——- c:\windows\system32\pxinsi64.exe 2008-11-21 21:46 1,044,480 a——- c:\windows\system32\libdivx.dll 2008-11-21 21:46 200,704 a——- c:\windows\system32\ssldivx.dll 2008-11-21 21:44 161,096 a——- c:\windows\system32\DivXCodecVersionChecker.exe 2008-11-21 21:44 12,288 a——- c:\windows\system32\DivXWMPExtType.dll 2008-08-17 14:28 87,608 ac—— c:\docume~1\admini~1\applic~1\inst.exe 2008-08-17 14:28 47,360 ac—— c:\docume~1\admini~1\applic~1\pcouffin.sys ============= FINISH: 13:59:27.12 ===============

Attachments:

Hi,

Please make sure Spybot is still disabled.

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :files
    c:\temp\sTMP3
    C:\windows\system32\wp2
    C:\Temp
    c:\windows\system32\nkmmmhgq.dll.vir
    c:\windows\system32\khfEXNDw.dll.vir
    c:\windows\system32\drivers\senekaxmlygwff.sys.vir

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 12.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 12, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop.
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u12-windowsi586.exe to install the newest version.

Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
How's the computer running now, still getting redirects?. Please also include a fresh HijackThis log in your next reply.

Thanks.
========== FILES ==========
c:\temp\sTMP3 moved successfully.
C:\windows\system32\wp2 moved successfully.
C:\Temp moved successfully.
c:\windows\system32\nkmmmhgq.dll.vir moved successfully.
c:\windows\system32\khfEXNDw.dll.vir moved successfully.
c:\windows\system32\drivers\senekaxmlygwff.sys.vir moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\\ deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_prSddKhuLm2EWmZIduaD scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFCF4A.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFCF74.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFB08.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFBA9.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Error: Unable to interpret <[Reboot> in the current context!

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02092009_142349

Files moved on Reboot…
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_prSddKhuLm2EWmZIduaD not found!
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFCF4A.tmp not found!
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFCF74.tmp not found!
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFB08.tmp not found!
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFBA9.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\n7xx419v.default\XUL.mfl moved successfully.





Kaspersky:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, February 9, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, February 09, 2009 14:39:20
Records in database: 1774405
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 59925
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 02:25:56


File name / Threat name / Threats count
C:\_OTMoveIt\MovedFiles\02092009_142349\windows\system32\nkmmmhgq.dll.vir Infected: Trojan.Win32.Monder.awcj 1

The selected area was scanned.



Hijack This:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:24:26, on 09/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Vtune\TBPanel.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\iTunes\iTunes.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe /A
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Comrade.exe] C:\Program Files\GameSpy\Comrade\Comrade.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1201162107984
O17 - HKLM\System\CCS\Services\Tcpip\..\{60D251E4-B862-469B-A1B4-7554C9CDF31A}: NameServer = 192.168.0.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Performance Driver Service - Unknown owner - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 7993 bytes


Im still getting redirects :(
Hi,

Are you getting the redirect in Firefox, Internet Explorer or both?


Please download SystemLook and save it to your Desktop.
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :reg
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found at on your Desktop entitled SystemLook.txt


Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

Please also run DDS again and post the first log (DDS.txt).

Thanks.
Its just firefox thats redirecting

System Look:

SystemLook v1.0bb by jpshortstuff
Log created at 17:35 on 09/02/2009 by Administrator

========== reg ==========

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi"="wdmaud.drv"
"MIDI1"="SYNCOR11.DLL"
"midi2"="wdmaud.drv"
"midimapper"="midimap.dll"
"mixer"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm"
"msacm.msadpcm"="msadp32.acm"
"msacm.msaudio1"="msaud32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msg723"="msg723.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.siren"="sirenacm.dll"
"msacm.sl_anet"="sl_anet.acm"
"msacm.trspch"="tssoft32.acm"
"MSVideo8"="VfWWDM32.dll"
"vidc.cvid"="iccvid.dll"
"vidc.DIVX"="DivX.dll"
"VIDC.FPS1"="frapsvid.dll"
"VIDC.I420"="msh263.drv"
"vidc.iv31"="ir32_32.dll"
"vidc.iv32"="ir32_32.dll"
"vidc.iv41"="ir41_32.ax"
"vidc.iv50"="ir50_32.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.M261"="msh261.drv"
"vidc.M263"="msh263.drv"
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"vidc.yv12"="DivX.dll"
"VIDC.YVU9"="tsbyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"wave"="wdmaud.drv"
"wave1"="wdmaud.drv"
"wavemapper"="msacm32.drv"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server]


-=End Of File=-


GMER:

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-02-09 17:56:24
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT spbc.sys ZwCreateKey [0xF74D70E0]
SSDT spbc.sys ZwEnumerateKey [0xF74F5CA2]
SSDT spbc.sys ZwEnumerateValueKey [0xF74F6030]
SSDT spbc.sys ZwOpenKey [0xF74D70C0]
SSDT spbc.sys ZwQueryKey [0xF74F6108]
SSDT spbc.sys ZwQueryValueKey [0xF74F5F88]
SSDT spbc.sys ZwSetValueKey [0xF74F619A]

INT 0x62 ? 89BBABF8
INT 0x63 ? 89BBABF8
INT 0x82 ? 89BBABF8
INT 0x84 ? 89B47BF8
INT 0x94 ? 89B47BF8
INT 0xA4 ? 89B47BF8
INT 0xB4 ? 89B47BF8

—- Kernel code sections - GMER 1.0.14 —-

? spbc.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload BA12462C 5 Bytes JMP 89B471D8
.text az1ovc67.SYS B9F2D386 35 Bytes [ 00, 00, 00, 00, 00, 00, 20, … ]
.text az1ovc67.SYS B9F2D3AA 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text az1ovc67.SYS B9F2D3C4 3 Bytes [ 00, 70, 02 ]
.text az1ovc67.SYS B9F2D3C9 1 Byte [ 2E ]
.text az1ovc67.SYS B9F2D3CB 9 Bytes [ 00, 00, 5C, 02, 00, 00, 00, … ]
.text …

—- Kernel IAT/EAT - GMER 1.0.14 —-

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89BBF2D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F7508C4C] spbc.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7508CA0] spbc.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74D8040] spbc.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74D813C] spbc.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74D80BE] spbc.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74D87FC] spbc.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74D86D2] spbc.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89B472D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74E8048] spbc.sys
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlInitUnicodeString] 0975013E
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!swprintf] 1B42E853
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeSetEvent] C4830000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoCreateSymbolicLink] B05E5F04
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoGetConfigurationInformation] E58B5B01
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] CCCCC35D
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmFreeMappingAddress] CCCCCCCC
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 53EC8B55
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 08758B56
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmUnmapIoSpace] 0214BE83
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 57000000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IofCompleteRequest] 45C60674
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 1EEB010B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IofCallDriver] 020C868B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmAllocateMappingAddress] C0850000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 808A1074
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoConnectInterrupt] 00000804
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoDetachDevice] A03CF024
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeWaitForSingleObject] 0B45950F
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeInitializeEvent] 45C604EB
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 458A000B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlInitAnsiString] 88C0840B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 840F0946
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoQueueWorkItem] 000000C1
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmMapIoSpace] 14B30E8B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 1C8286C6
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoReportDetectedDevice] 88010000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoReportResourceForDetection] 001C859E
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] A19E8800
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!NlsMbCodePageTag] C600001C
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!PoRequestPowerIrp] 001C8686
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 86C60100
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 00001CA2
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!sprintf] 70518B01
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 8D52006A
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ObfDereferenceObject] 001C8886
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 55E85000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 8B000023
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ZwClose] 70518B0E
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 8D52016A
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 001CA486
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 41E85000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 8B000023
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!PoCallDriver] 18C4830E
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoCreateDevice] 1C8D9E88
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 9E880000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 00001CA9
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ZwOpenKey] 0E798366
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 74AAB000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoStartTimer] 8186C636
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeInitializeTimer] 1A00001C
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoInitializeTimer] 1C8386C6
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeInitializeDpc] C6020000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeInitializeSpinLock] 001C8E86
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoInitializeIrp] 86C60200
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ZwCreateKey] 00001CAA
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 959E8802
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 8800001C
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ZwSetValueKey] 001CB19E
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeInsertQueueDpc] 96868800
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 8800001C
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoStartPacket] 001CB286
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] C61AEB00
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 001C8186
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoFreeMdl] 86C61200
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmUnlockPages] 00001C83
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 8E868801
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 8800001C
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 001CAA86
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 80968B00
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeSynchronizeExecution] 8900001C
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoStartNextPacket] 001C9C96
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeBugCheckEx] C6168B00
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 001CB986
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeSetTimer] 428A0A00
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeCancelTimer] BA86880C
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!_allmul] 8B00001C
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmProbeAndLockPages] 24A48DFA
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!_except_handler3] 00000000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!PoSetPowerState] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 8D3F0304
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlWriteRegistryValue] CB033043
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!_aulldiv] 0673C13B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!strstr] C13B0003
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!_strupr] 8366FA72
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeQuerySystemTime] 75000E7B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 0B7D80E3
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!KeTickCount] 307B8D00
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 00AA840F
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoDeleteDevice] 83660000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 6A000E7A
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoAllocateWorkItem] C6647400
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoAllocateIrp] 001CBB86
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoAllocateMdl] 4F8B0200
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 968D5140
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmLockPagableDataSection] 00001C90
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 2266E852
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 478B0000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!ExFreePoolWithTag] 50016A40
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoFreeIrp] 1CAC8E8D
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!IoFreeWorkItem] E8510000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!InitSafeBootMode] 00002254
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlCompareMemory] 6A18538B
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 868D5200
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!memmove] 00001C98
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[ntoskrnl.exe!MmHighestUserAddress] 2242E850
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!KfAcquireSpinLock] 8A000002
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!READ_PORT_UCHAR] 83880846
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!KeGetCurrentIrql] 000001C0
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!KfRaiseIrql] 2C4EB70F
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!KfLowerIrql] 8303C183
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!HalGetInterruptVector] D103FCE1
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!HalTranslateBusAddress] 2E7E8366
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!KeStallExecutionProcessor] 8D1C7400
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!KfReleaseSpinLock] 83893204
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00000218
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!READ_PORT_USHORT] 2E4EB70F
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 021C8B89
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[HAL.dll!WRITE_PORT_UCHAR] B70F0000
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[WMILIB.SYS!WmiSystemControl] 03D00304
IAT \SystemRoot\System32\Drivers\az1ovc67.SYS[WMILIB.SYS!WmiCompleteRequest] 0CB389F2

—- Devices - GMER 1.0.14 —-

Device \FileSystem\Ntfs \Ntfs 89BB81F8
Device \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\usbuhci \Device\USBPDO-0 89A8F1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 89BBB1F8
Device \Driver\dmio \Device\DmControl\DmConfig 89BBB1F8
Device \Driver\dmio \Device\DmControl\DmPnP 89BBB1F8
Device \Driver\dmio \Device\DmControl\DmInfo 89BBB1F8
Device \Driver\usbuhci \Device\USBPDO-1 89A8F1F8
Device \Driver\usbuhci \Device\USBPDO-2 89A8F1F8
Device \Driver\PCI_PNP9196 \Device\00000046 spbc.sys
Device \Driver\PCI_PNP9196 \Device\00000046 spbc.sys
Device \Driver\sptd \Device\1062285446 spbc.sys
Device \Driver\usbuhci \Device\USBPDO-3 89A8F1F8
Device \Driver\usbehci \Device\USBPDO-4 89A5B500
Device \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\NetBT \Device\NetBT_Tcpip_{9F4EBF80-EF6E-43AA-B1AA-A836B18B535E} 89824500
Device \Driver\Ftdisk \Device\HarddiskVolume1 89BBC1F8
Device \Driver\Cdrom \Device\CdRom0 89A49500
Device \Driver\Cdrom \Device\CdRom1 89A49500
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 89BBA1F8
Device \Driver\atapi \Device\Ide\IdePort0 89BBA1F8
Device \Driver\atapi \Device\Ide\IdePort1 89BBA1F8
Device \Driver\atapi \Device\Ide\IdePort2 89BBA1F8
Device \Driver\atapi \Device\Ide\IdePort3 89BBA1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e 89BBA1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{60D251E4-B862-469B-A1B4-7554C9CDF31A} 89824500
Device \Driver\NetBT \Device\NetBt_Wins_Export 89824500
Device \Driver\NetBT \Device\NetbiosSmb 89824500
Device \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\usbuhci \Device\USBFDO-0 89A8F1F8
Device \Driver\usbuhci \Device\USBFDO-1 89A8F1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8970A1F8
Device \Driver\Tcpip \Device\IPMULTICAST avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\usbuhci \Device\USBFDO-2 89A8F1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8970A1F8
Device \Driver\usbuhci \Device\USBFDO-3 89A8F1F8
Device \Driver\usbehci \Device\USBFDO-4 89A5B500
Device \Driver\Ftdisk \Device\FtControl 89BBC1F8
Device \Driver\az1ovc67 \Device\Scsi\az1ovc671Port4Path0Target0Lun0 89A3C1F8
Device \Driver\az1ovc67 \Device\Scsi\az1ovc671 89A3C1F8
Device \FileSystem\Cdfs \Cdfs 89737500

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDD 0xDE 0xBD 0x87 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF6 0x9B 0x08 0xBE …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEE 0x03 0xB7 0xFE …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDD 0xDE 0xBD 0x87 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF6 0x9B 0x08 0xBE …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xEE 0x03 0xB7 0xFE …

—- EOF - GMER 1.0.14 —-



DDS:


DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 17:56:53.15 on 09/02/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1187 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Vtune\TBPanel.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [TBPanel] c:\program files\vtune\TBPanel.exe /A
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [Comrade.exe] c:\program files\gamespy\comrade\Comrade.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201162107984
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
TCP: {60D251E4-B862-469B-A1B4-7554C9CDF31A} = 192.168.0.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\n7xx419v.default\

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-17 96520]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-8-17 26824]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-8-17 873752]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-17 231192]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-8-17 76040]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2008-12-11 3575808]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]

=============== Created Last 30 ================

2009-02-09 17:36 250 a——- c:\windows\gmer.ini
2009-02-09 14:40 73,728 a——- c:\windows\system32\javacpl.cpl
2009-02-09 14:40 410,984 a——- c:\windows\system32\deploytk.dll
2009-02-09 14:23 -cd—– C:\_OTMoveIt
2009-02-08 21:44 -cd—– c:\docume~1\admini~1\applic~1\Malwarebytes
2009-02-08 21:44 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-02-08 21:44 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-08 21:44 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-02-08 21:44 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-08 18:55 –d—– c:\program files\Spybot - Search & Destroy
2009-02-08 18:55 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-02-08 16:17 –d—– c:\program files\Trojan Remover
2009-02-08 16:00 -cd—– C:\VundoFix Backups
2009-02-07 17:51 -cd-h— C:\$AVG8.VAULT$
2009-01-26 12:35 –d—– c:\docume~1\alluse~1\applic~1\Electronic Arts
2009-01-20 19:37 –d—– c:\program files\Bethesda Softworks
2009-01-20 19:35 –d—– c:\windows\system32\xlive
2009-01-20 01:30 –d—– c:\program files\Mozilla ActiveX Control v1.7.12
2009-01-20 01:06 -cd—– c:\docume~1\admini~1\applic~1\Graboid Inc
2009-01-16 16:31 268 ac–h— C:\sqmdata01.sqm
2009-01-16 16:31 244 ac–h— C:\sqmnoopt01.sqm
2009-01-14 22:25 –d—– c:\program files\Activision
2009-01-14 22:00 –dsh— c:\windows\ftpcache
2009-01-14 21:44 –d—– c:\program files\PowerISO
2009-01-14 21:42 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Pro
2009-01-14 21:41 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2009-01-14 21:40 –d—– c:\program files\DAEMON Tools Lite
2009-01-14 21:22 717,296 a——- c:\windows\system32\drivers\sptd.sys
2009-01-14 21:22 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Lite
2009-01-12 18:49 -cd—– c:\docume~1\admini~1\applic~1\DNA
2009-01-12 18:49 –d—– c:\program files\DNA
2009-01-11 15:13 1,456 a——- c:\windows\system32\ealregsnapshot1.reg

==================== Find3M ====================

2009-01-25 03:11 98,304 a——- c:\windows\system32\CmdLineExt.dll
2009-01-25 02:17 138,464 a——- c:\windows\system32\drivers\PnkBstrK.sys
2009-01-25 02:17 111,928 a——- c:\windows\system32\PnkBstrB.exe
2009-01-14 22:40 22,328 ac—— c:\docume~1\admini~1\applic~1\PnkBstrK.sys
2009-01-14 22:40 682,280 a——- c:\windows\system32\pbsvc.exe
2009-01-14 22:40 66,872 a——- c:\windows\system32\PnkBstrA.exe
2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf
2008-12-23 21:58 453,152 a——- c:\windows\system32\NVUNINST.EXE
2008-11-21 21:47 524,288 a——- c:\windows\system32\DivXsm.exe
2008-11-21 21:47 3,596,288 a——- c:\windows\system32\qt-dx331.dll
2008-11-21 21:47 129,784 a——- c:\windows\system32\pxafs.dll
2008-11-21 21:47 120,056 a——- c:\windows\system32\pxcpyi64.exe
2008-11-21 21:47 118,520 a——- c:\windows\system32\pxinsi64.exe
2008-11-21 21:46 1,044,480 a——- c:\windows\system32\libdivx.dll
2008-11-21 21:46 200,704 a——- c:\windows\system32\ssldivx.dll
2008-11-21 21:44 161,096 a——- c:\windows\system32\DivXCodecVersionChecker.exe
2008-11-21 21:44 12,288 a——- c:\windows\system32\DivXWMPExtType.dll
2008-08-17 14:28 87,608 ac—— c:\docume~1\admini~1\applic~1\inst.exe
2008-08-17 14:28 47,360 ac—— c:\docume~1\admini~1\applic~1\pcouffin.sys

============= FINISH: 17:57:10.35 ===============

Still getting redirects
Hi,

Please click Start >> Run and then copy/paste the following into the Run Box:
"C:\Documents and Settings\Administrator\Desktop\dds.scr" /ihatewhitelists

Post the resulting log.


Close all Firefox windows and wait for a few seconds. Click Start >> All Programs >> Mozilla Firefox >> Mozilla Firefox (Safe Mode). Please check if you still get redirects from this. Let me know.

Thanks.
DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 20:04:54.56 on 09/02/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1295 [GMT 0:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Vtune\TBPanel.exe C:\Program Files\DNA\btdna.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\RALINK\Common\RaUI.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\iTunes\iTunes.exe C:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.uk/ uInternet Settings,ProxyOverride = *.local BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [TBPanel] c:\program files\vtune\TBPanel.exe /A uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [Comrade.exe] c:\program files\gamespy\comrade\Comrade.exe uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201162107984 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab TCP: {60D251E4-B862-469B-A1B4-7554C9CDF31A} = 192.168.0.1 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\n7xx419v.default\ ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-17 96520] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-8-17 26824] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-8-17 873752] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-17 231192] R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-8-17 76040] R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2008-12-11 3575808] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] =============== Created Last 30 ================ 2009-02-09 17:36 250 a——- c:\windows\gmer.ini 2009-02-09 14:40 73,728 a——- c:\windows\system32\javacpl.cpl 2009-02-09 14:40 410,984 a——- c:\windows\system32\deploytk.dll 2009-02-09 14:23 -cd—– C:\_OTMoveIt 2009-02-08 21:44 -cd—– c:\docume~1\admini~1\applic~1\Malwarebytes 2009-02-08 21:44 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-02-08 21:44 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-08 21:44 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-02-08 21:44 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-02-08 18:55 –d—– c:\program files\Spybot - Search & Destroy 2009-02-08 18:55 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-02-08 16:17 –d—– c:\program files\Trojan Remover 2009-02-08 16:00 -cd—– C:\VundoFix Backups 2009-02-07 17:51 -cd-h— C:\$AVG8.VAULT$ 2009-01-26 12:35 –d—– c:\docume~1\alluse~1\applic~1\Electronic Arts 2009-01-20 19:37 –d—– c:\program files\Bethesda Softworks 2009-01-20 19:35 –d—– c:\windows\system32\xlive 2009-01-20 01:30 –d—– c:\program files\Mozilla ActiveX Control v1.7.12 2009-01-20 01:06 -cd—– c:\docume~1\admini~1\applic~1\Graboid Inc 2009-01-16 16:31 268 ac–h— C:\sqmdata01.sqm 2009-01-16 16:31 244 ac–h— C:\sqmnoopt01.sqm 2009-01-14 22:25 –d—– c:\program files\Activision 2009-01-14 22:00 –dsh— c:\windows\ftpcache 2009-01-14 21:44 –d—– c:\program files\PowerISO 2009-01-14 21:42 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Pro 2009-01-14 21:41 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite 2009-01-14 21:40 –d—– c:\program files\DAEMON Tools Lite 2009-01-14 21:22 717,296 a——- c:\windows\system32\drivers\sptd.sys 2009-01-14 21:22 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Lite 2009-01-12 18:49 -cd—– c:\docume~1\admini~1\applic~1\DNA 2009-01-12 18:49 –d—– c:\program files\DNA 2009-01-11 15:13 1,456 a——- c:\windows\system32\ealregsnapshot1.reg ==================== Find3M ==================== 2009-01-25 03:11 98,304 a——- c:\windows\system32\CmdLineExt.dll 2009-01-25 02:17 138,464 a——- c:\windows\system32\drivers\PnkBstrK.sys 2009-01-25 02:17 111,928 a——- c:\windows\system32\PnkBstrB.exe 2009-01-14 22:40 22,328 ac—— c:\docume~1\admini~1\applic~1\PnkBstrK.sys 2009-01-14 22:40 682,280 a——- c:\windows\system32\pbsvc.exe 2009-01-14 22:40 66,872 a——- c:\windows\system32\PnkBstrA.exe 2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf 2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf 2008-12-23 21:58 453,152 a——- c:\windows\system32\NVUNINST.EXE 2008-11-21 21:47 524,288 a——- c:\windows\system32\DivXsm.exe 2008-11-21 21:47 3,596,288 a——- c:\windows\system32\qt-dx331.dll 2008-11-21 21:47 129,784 a——- c:\windows\system32\pxafs.dll 2008-11-21 21:47 120,056 a——- c:\windows\system32\pxcpyi64.exe 2008-11-21 21:47 118,520 a——- c:\windows\system32\pxinsi64.exe 2008-11-21 21:46 1,044,480 a——- c:\windows\system32\libdivx.dll 2008-11-21 21:46 200,704 a——- c:\windows\system32\ssldivx.dll 2008-11-21 21:44 161,096 a——- c:\windows\system32\DivXCodecVersionChecker.exe 2008-11-21 21:44 12,288 a——- c:\windows\system32\DivXWMPExtType.dll 2008-08-17 14:28 87,608 ac—— c:\docume~1\admini~1\applic~1\inst.exe 2008-08-17 14:28 47,360 ac—— c:\docume~1\admini~1\applic~1\pcouffin.sys ============= FINISH: 20:05:11.14 =============== No redirects in safe mode
Hi,

Have a look at your Firefox extensions and see if there is anything there that you don't recognize.


DDS run didn't seem to run right. Let's do this a different way.

1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

@echo off
Start DDS.scr /ihatewhitelists
del /Q %0

3. Save the file to your DESKTOP as "run.bat". Make sure to save it with the quotes. Once saved, the icon to click should look like this on your desktop: [external image: Posted Image]

4. Double click run.bat.


Please open SystemLook. Copy and paste the following code into the main box and then hit Look
:reg
HKLM\Software\Mozilla /s
:dir
c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\n7xx419v.default /s

Post the resulting log.

Thanks.
DDS: DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 20:30:47.09 on 09/02/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_12 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1361 [GMT 0:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\PowerISO\PWRISOVM.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Vtune\TBPanel.exe C:\Program Files\DNA\btdna.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\RALINK\Common\RaUI.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\iTunes\iTunes.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.co.uk/ uSearch Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch mDefault_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 mDefault_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 mSearch Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 mLocal Page = %SystemRoot%\system32\blank.htm mStart Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 uInternet Connection Wizard,ShellNext = hxxp://windowsupdate.microsoft.com/ uInternet Settings,ProxyOverride = *.local mSearchAssistant = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm mCustomizeSearch = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm uURLSearchHooks: Microsoft Url Search Hook: {cfbfae00-17a6-11d0-99cb-00c04fd64497} - c:\windows\system32\ieframe.dll mWinlogon: Shell=Explorer.exe mWinlogon: Userinit=c:\windows\system32\userinit.exe, mWinlogon: UIHost=logonui.exe mWinlogon: SFCDisable=0 (0x0) BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll EB: &Tip; of the Day: {4d5c8c25-d075-11d0-b416-00c04fb90376} - %SystemRoot%\system32\shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [TBPanel] c:\program files\vtune\TBPanel.exe /A uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [Comrade.exe] c:\program files\gamespy\comrade\Comrade.exe uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe uPolicies-explorer: NoDriveTypeAutoRun = 145 (0x91) mPolicies-system: dontdisplaylastusername = 0 (0x0) mPolicies-system: legalnoticecaption = mPolicies-system: legalnoticetext = mPolicies-system: shutdownwithoutlogon = 1 (0x1) mPolicies-system: undockwithoutlogon = 1 (0x1) dPolicies-explorer: NoDriveTypeAutoRun = 145 (0x91) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: %SystemRoot%\system32\mswsock.dll LSP: %SystemRoot%\system32\rsvpsp.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201162107984 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab TCP: {60D251E4-B862-469B-A1B4-7554C9CDF31A} = 192.168.0.1 Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - c:\windows\system32\mscoree.dll Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - c:\windows\system32\mscoree.dll Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - c:\windows\system32\mscoree.dll Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - c:\windows\system32\urlmon.dll Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - c:\windows\system32\urlmon.dll Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - c:\windows\system32\msvidctl.dll Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - c:\progra~1\wi1f86~1\messen~1\MSGRAP~1.DLL Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\common~1\system\oledb~1\MSDAIPP.DLL Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - c:\progra~1\wi1f86~1\messen~1\MSGRAP~1.DLL Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - c:\windows\system32\msvidctl.dll Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - c:\windows\system32\wiascr.dll Name-Space Handler: mk\* - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll Notify: crypt32chain - crypt32.dll Notify: cryptnet - cryptnet.dll Notify: cscdll - cscdll.dll Notify: igfxcui - igfxdev.dll Notify: ScCertProp - wlnotify.dll Notify: Schedule - wlnotify.dll Notify: sclgntfy - sclgntfy.dll Notify: SensLogn - WlNotify.dll Notify: termsrv - wlnotify.dll Notify: WgaLogon - WgaLogon.dll Notify: wlballoon - wlnotify.dll AppInit_DLLs: avgrsstx.dll SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - c:\windows\system32\webcheck.dll SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - c:\windows\system32\stobject.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll STS: Browseui preloader: {438755c2-a8ba-11d1-b96b-00a0c90312e1} - %SystemRoot%\system32\browseui.dll STS: Component Categories cache daemon: {8c7461ef-2b13-11d2-be35-3078302c2030} - %SystemRoot%\system32\browseui.dll SEH: URL Exec Hook: {aeb6717e-7e19-11d0-97ee-00c04fd91972} - shell32.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll LSA: Authentication Packages = msv1_0 LSA: Notification Packages = scecli SubSystems: Windows = basesrv ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\n7xx419v.default\ FF - component: c:\program files\mozilla firefox\components\browserdirprovider.dll FF - component: c:\program files\mozilla firefox\components\brwsrcmp.dll FF - plugin: c:\program files\divx\divx player\npDivxPlayerPlugin.dll FF - plugin: c:\program files\divx\divx web player\npdivx32.dll FF - plugin: c:\program files\dna\plugins\npbtdna.dll FF - plugin: c:\program files\itunes\mozilla plugins\npitunes.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeploytk.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeploytk.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdivx32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npDivxPlayerPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npLegitCheckPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npnul32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin3.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin4.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin5.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin6.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin7.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin2.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin3.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin4.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin5.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin6.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin7.dll FF - plugin: c:\program files\windows media player\npdrmv2.dll FF - plugin: c:\program files\windows media player\npdsplay.dll FF - plugin: c:\program files\windows media player\npwmsdrm.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32.dll —- Add-ons/Extensions Installed —- Default Java Console Java Quick Starter XUL Cache ============= SERVICES / DRIVERS =============== R0 ACPI;Microsoft ACPI Driver;c:\windows\system32\drivers\acpi.sys [2004-8-4 187776] R0 atapi;Standard IDE/ESDI Hard Disk Controller;c:\windows\system32\drivers\atapi.sys [2004-8-4 95360] R0 Disk;Disk Driver;c:\windows\system32\drivers\disk.sys [2004-8-4 36352] R0 dmio;Logical Disk Manager Driver;c:\windows\system32\drivers\dmio.sys [2004-8-4 153344] R0 dmload;dmload;c:\windows\system32\drivers\dmload.sys [2001-8-17 5888] R0 FltMgr;FltMgr;c:\windows\system32\drivers\fltmgr.sys [2004-8-4 128896] R0 Ftdisk;Volume Manager Driver;c:\windows\system32\drivers\ftdisk.sys [2001-8-17 125056] R0 isapnp;PnP ISA/EISA Bus Driver;c:\windows\system32\drivers\isapnp.sys [2001-8-17 35840] R0 KSecDD;KSecDD;c:\windows\system32\drivers\ksecdd.sys [2008-1-24 92032] R0 MountMgr;MountMgr;c:\windows\system32\drivers\mountmgr.sys [2004-8-4 42240] R0 Mup;Mup;c:\windows\system32\drivers\mup.sys [2004-8-4 107904] R0 NDIS;NDIS System Driver;c:\windows\system32\drivers\ndis.sys [2004-8-4 182912] R0 PartMgr;PartMgr;c:\windows\system32\drivers\partmgr.sys [2001-8-18 18688] R0 PCI;PCI Bus Driver;c:\windows\system32\drivers\pci.sys [2004-8-4 68224] R0 PCIIde;PCIIde;c:\windows\system32\drivers\pciide.sys [2001-8-17 3328] R0 PxHelp20;PxHelp20;c:\windows\system32\drivers\PxHelp20.sys [2008-12-20 43528] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-1-14 717296] R0 sr;System Restore Filter Driver;c:\windows\system32\drivers\sr.sys [2004-8-4 73472] R0 VolSnap;VolSnap;c:\windows\system32\drivers\volsnap.sys [2004-8-4 52352] R1 AFD;AFD;c:\windows\system32\drivers\afd.sys [2004-8-4 138368] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-17 96520] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-8-17 26824] R1 Beep;Beep;c:\windows\system32\drivers\beep.sys [2001-8-17 4224] R1 Cdrom;CD-ROM Driver;c:\windows\system32\drivers\cdrom.sys [2004-8-4 49536] R1 Fips;Fips;c:\windows\system32\drivers\fips.sys [2001-8-18 34944] R1 i8042prt;i8042 Keyboard and PS/2 Mouse Port Driver;c:\windows\system32\drivers\i8042prt.sys [2004-8-4 52736] R1 intelppm;Intel Processor Driver;c:\windows\system32\drivers\intelppm.sys [2004-8-4 36096] R1 IPSec;IPSEC driver;c:\windows\system32\drivers\ipsec.sys [2004-8-4 74752] R1 Kbdclass;Keyboard Class Driver;c:\windows\system32\drivers\kbdclass.sys [2004-8-4 24576] R1 mnmdd;mnmdd;c:\windows\system32\drivers\mnmdd.sys [2001-8-17 4224] R1 Mouclass;Mouse Class Driver;c:\windows\system32\drivers\mouclass.sys [2004-8-4 23040] R1 MRxSmb;MRXSMB;c:\windows\system32\drivers\mrxsmb.sys [2004-8-4 453632] R1 Msfs;Msfs;c:\windows\system32\drivers\msfs.sys [2004-8-4 19072] R1 NetBIOS;NetBIOS Interface;c:\windows\system32\drivers\netbios.sys [2004-8-4 34560] R1 NetBT;NetBios over Tcpip;c:\windows\system32\drivers\netbt.sys [2004-8-4 162816] R1 Npfs;Npfs;c:\windows\system32\drivers\npfs.sys [2004-8-4 30848] R1 Null;Null;c:\windows\system32\drivers\null.sys [2001-8-17 2944] R1 RasAcd;Remote Access Auto Connection Driver;c:\windows\system32\drivers\rasacd.sys [2001-8-17 8832] R1 Rdbss;Rdbss;c:\windows\system32\drivers\rdbss.sys [2004-8-4 174592] R1 RDPCDD;RDPCDD;c:\windows\system32\drivers\rdpcdd.sys [2001-8-17 4224] R1 redbook;Digital CD Audio Playback Filter Driver;c:\windows\system32\drivers\redbook.sys [2008-1-24 57472] R1 SCDEmu;SCDEmu;c:\windows\system32\drivers\scdemu.sys [2008-11-2 56572] R1 Serial;Serial port driver;c:\windows\system32\drivers\serial.sys [2004-8-4 64896] R1 Tcpip;TCP/IP Protocol Driver;c:\windows\system32\drivers\tcpip.sys [2004-8-4 360320] R1 TermDD;Terminal Device Driver;c:\windows\system32\drivers\termdd.sys [2004-8-4 40840] R1 VgaSave;VgaSave;c:\windows\system32\drivers\vga.sys [2004-8-4 20992] R1 WmiAcpi;Microsoft Windows Management Interface for ACPI;c:\windows\system32\drivers\wmiacpi.sys [2008-1-24 8832] R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0;c:\windows\system32\drivers\AegisP.sys [2008-8-14 21275] R2 Apple Mobile Device;Apple Mobile Device;c:\program files\common files\apple\mobile device support\bin\AppleMobileDeviceService.exe [2008-11-7 132424] R2 AudioSrv;Windows Audio;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-8-17 873752] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-17 231192] R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-8-17 76040] R2 Bonjour Service;Bonjour Service;c:\program files\bonjour\mDNSResponder.exe [2008-8-29 238888] R2 CryptSvc;Cryptographic Services;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 DcomLaunch;DCOM Server Process Launcher;c:\windows\system32\svchost -k dcomlaunch –> c:\windows\system32\svchost -k DcomLaunch [?] R2 Dhcp;DHCP Client;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 dmserver;Logical Disk Manager;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 Dnscache;DNS Client;c:\windows\system32\svchost.exe -k NetworkService [2004-8-4 14336] R2 ERSvc;Error Reporting Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 Eventlog;Event Log;c:\windows\system32\services.exe [2004-8-4 108032] R2 helpsvc;Help and Support;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 HidServ;HID Input Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 JavaQuickStarterService;Java Quick Starter;c:\program files\java\jre6\bin\jqs.exe [2009-2-9 152984] R2 lanmanserver;Server;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 lanmanworkstation;Workstation;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 LmHosts;TCP/IP NetBIOS Helper;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R2 nvcap;nVidia WDM Video Capture (universal);c:\windows\system32\drivers\NVCAP.SYS [2008-12-3 141246] R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2008-12-11 3575808] R2 NVSvc;NVIDIA Display Driver Service;c:\windows\system32\nvsvc32.exe [2008-9-11 163908] R2 NVXBAR;nVidia WDM A/V Crossbar;c:\windows\system32\drivers\NVXBAR.SYS [2008-12-3 16176] R2 PlugPlay;Plug and Play;c:\windows\system32\services.exe [2004-8-4 108032] R2 PnkBstrA;PnkBstrA;c:\windows\system32\PnkBstrA.exe [2008-8-16 66872] R2 PolicyAgent;IPSEC Services;c:\windows\system32\lsass.exe [2004-8-4 13312] R2 ProtectedStorage;Protected Storage;c:\windows\system32\lsass.exe [2004-8-4 13312] R2 RemoteRegistry;Remote Registry;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R2 RpcSs;Remote Procedure Call (RPC);c:\windows\system32\svchost -k rpcss –> c:\windows\system32\svchost -k rpcss [?] R2 SamSs;Security Accounts Manager;c:\windows\system32\lsass.exe [2004-8-4 13312] R2 Schedule;Task Scheduler;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 seclogon;Secondary Logon;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 SENS;System Event Notification;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 SharedAccess;Windows Firewall/Internet Connection Sharing (ICS);c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 ShellHWDetection;Shell Hardware Detection;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 SoundMAX Agent Service (default);SoundMAX Agent Service;c:\program files\analog devices\soundmax\SMAgent.exe [2008-1-24 45056] R2 Spooler;Print Spooler;c:\windows\system32\spoolsv.exe [2004-8-4 57856] R2 srservice;System Restore Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 TBPanel;TBPanel;c:\windows\system32\drivers\TBPanel.sys [2008-12-2 12256] R2 Themes;Themes;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 TrkWks;Distributed Link Tracking Client;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 W32Time;Windows Time;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 WebClient;WebClient;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R2 winmgmt;Windows Management Instrumentation;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 wscsvc;Security Center;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 aeaudio;aeaudio;c:\windows\system32\drivers\aeaudio.sys [2008-1-24 100384] R3 ALG;Application Layer Gateway Service;c:\windows\system32\alg.exe [2004-8-4 44544] R3 AppMgmt;Application Management;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 audstub;Audio Stub Driver;c:\windows\system32\drivers\audstub.sys [2001-8-17 3072] R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet;c:\windows\system32\drivers\b57xp32.sys [2008-1-24 186112] R3 EventSystem;COM+ Event System;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 FastUserSwitchingCompatibility;Fast User Switching Compatibility;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 Fdc;Floppy Disk Controller Driver;c:\windows\system32\drivers\fdc.sys [2004-8-4 27392] R3 GEARAspiWDM;GEAR ASPI Filter Driver;c:\windows\system32\drivers\GEARAspiWDM.sys [2008-1-29 15464] R3 Gpc;Generic Packet Classifier;c:\windows\system32\drivers\msgpc.sys [2004-8-4 35072] R3 HidUsb;Microsoft HID Class Driver;c:\windows\system32\drivers\hidusb.sys [2008-1-24 9600] R3 HTTP;HTTP;c:\windows\system32\drivers\http.sys [2004-8-4 262784] R3 HTTPFilter;HTTP SSL;c:\windows\system32\svchost.exe -k HTTPFilter [2004-8-4 14336] R3 IpNat;IP Network Address Translator;c:\windows\system32\drivers\ipnat.sys [2004-8-4 134912] R3 iPod Service;iPod Service;c:\program files\ipod\bin\iPodService.exe [2008-11-20 536872] R3 kmixer;Microsoft Kernel Wave Audio Mixer;c:\windows\system32\drivers\kmixer.sys [2004-8-4 172416] R3 mouhid;Mouse HID Driver;c:\windows\system32\drivers\mouhid.sys [2008-1-24 12160] R3 MRxDAV;WebDav Client Redirector;c:\windows\system32\drivers\mrxdav.sys [2004-8-4 181248] R3 mssmbios;Microsoft System Management BIOS Driver;c:\windows\system32\drivers\mssmbios.sys [2004-8-4 15488] R3 NdisTapi;Remote Access NDIS TAPI Driver;c:\windows\system32\drivers\ndistapi.sys [2001-8-17 9600] R3 NdisWan;Remote Access NDIS WAN Driver;c:\windows\system32\drivers\ndiswan.sys [2004-8-4 91776] R3 NDProxy;NDIS Proxy;c:\windows\system32\drivers\ndproxy.sys [2001-8-17 38016] R3 Netman;Network Connections;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 Nla;Network Location Awareness (NLA);c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 nv;nv;c:\windows\system32\drivers\nv4_mini.sys [2008-9-11 6301344] R3 Parport;Parallel port driver;c:\windows\system32\drivers\parport.sys [2004-8-4 80128] R3 PptpMiniport;WAN Miniport (PPTP);c:\windows\system32\drivers\raspptp.sys [2004-8-4 48384] R3 PSched;QoS Packet Scheduler;c:\windows\system32\drivers\psched.sys [2004-8-4 69120] R3 Ptilink;Direct Parallel Link Driver;c:\windows\system32\drivers\ptilink.sys [2001-8-17 17792] R3 RasAuto;Remote Access Auto Connection Manager;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 Rasl2tp;WAN Miniport (L2TP);c:\windows\system32\drivers\rasl2tp.sys [2004-8-4 51328] R3 RasMan;Remote Access Connection Manager;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 RasPppoe;Remote Access PPPOE Driver;c:\windows\system32\drivers\raspppoe.sys [2004-8-4 41472] R3 Raspti;Direct Parallel;c:\windows\system32\drivers\raspti.sys [2001-8-17 16512] R3 rdpdr;Terminal Server Device Redirector Driver;c:\windows\system32\drivers\rdpdr.sys [2004-8-4 196864] R3 RT73;RT73 USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt73.sys [2008-8-14 344064] R3 serenum;Serenum Filter Driver;c:\windows\system32\drivers\serenum.sys [2004-8-4 15488] R3 smwdm;smwdm;c:\windows\system32\drivers\smwdm.sys [2008-1-24 612416] R3 Srv;Srv;c:\windows\system32\drivers\srv.sys [2004-8-4 333056] R3 SSDPSRV;SSDP Discovery Service;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R3 swenum;Software Bus Driver;c:\windows\system32\drivers\swenum.sys [2004-8-4 4352] R3 sysaudio;Microsoft Kernel System Audio Device;c:\windows\system32\drivers\sysaudio.sys [2004-8-4 60800] R3 TapiSrv;Telephony;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 TermService;Terminal Services;c:\windows\system32\svchost -k dcomlaunch –> c:\windows\system32\svchost -k DComLaunch [?] R3 Update;Microcode Update Driver;c:\windows\system32\drivers\update.sys [2004-8-4 364160] R3 upnphost;Universal Plug and Play Device Host;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver;c:\windows\system32\drivers\usbehci.sys [2008-1-24 26624] R3 usbhub;USB2 Enabled Hub;c:\windows\system32\drivers\usbhub.sys [2004-8-4 57600] R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver;c:\windows\system32\drivers\usbuhci.sys [2004-8-4 20480] R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\windows live\messenger\usnsvc.exe [2007-10-18 98328] R3 Wanarp;Remote Access IP ARP Driver;c:\windows\system32\drivers\wanarp.sys [2004-8-4 34560] R3 wdmaud;Microsoft WINMM WDM Audio Compatibility Driver;c:\windows\system32\drivers\wdmaud.sys [2004-8-4 82944] R4 Cdfs;Cdfs;c:\windows\system32\drivers\cdfs.sys [2004-8-4 63744] R4 Ntfs;Ntfs;c:\windows\system32\drivers\ntfs.sys [2008-1-24 574464] S1 Cdaudio;Cdaudio;c:\windows\system32\drivers\cdaudio.sys [2004-8-4 18688] S1 Changer;Changer; [x] S1 i2omgmt;i2omgmt; [x] S1 Imapi;CD-Burning Filter Driver;c:\windows\system32\drivers\imapi.sys [2004-8-4 41856] S1 kbdhid;Keyboard HID Driver;c:\windows\system32\drivers\kbdhid.sys [2008-7-25 14848] S1 lbrtfdc;lbrtfdc; [x] S1 P3;Intel PentiumIII Processor Driver;c:\windows\system32\drivers\p3.sys [2004-8-4 42496] S1 PCIDump;PCIDump; [x] S2 Browser;Computer Browser;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 ac97intc;Intel® 82801 Audio Driver Install Service (WDM);c:\windows\system32\drivers\ac97intc.sys [2001-8-17 96256] S3 aec;Microsoft Kernel Acoustic Echo Canceller;c:\windows\system32\drivers\aec.sys [2004-8-4 142464] S3 aspnet_state;ASP.NET State Service;c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800] S3 AsyncMac;RAS Asynchronous Media Driver;c:\windows\system32\drivers\asyncmac.sys [2004-8-4 14336] S3 Atmarpc;ATM ARP Client Protocol;c:\windows\system32\drivers\atmarpc.sys [2004-8-4 59904] S3 BITS;Background Intelligent Transfer Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 Blfp;Broadcom Advanced Server Program Driver;c:\windows\system32\drivers\baspxp32.sys [2004-2-4 51584] S3 CCDECODE;Closed Caption Decoder;c:\windows\system32\drivers\CCDECODE.sys [2008-12-5 17024] S3 CiSvc;Indexing Service;c:\windows\system32\cisvc.exe [2004-8-4 5632] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86;c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144] S3 COMSysApp;COM+ System Application;c:\windows\system32\dllhost.exe [2004-8-4 5120] S3 dmadmin;Logical Disk Manager Administrative Service;c:\windows\system32\dmadmin.exe [2004-8-4 224768] S3 DMusic;Microsoft Kernel DLS Syntheiszer;c:\windows\system32\drivers\DMusic.sys [2004-8-4 52864] S3 drmkaud;Microsoft Kernel DRM Audio Descrambler;c:\windows\system32\drivers\drmkaud.sys [2004-8-4 2944] S3 E100B;Intel® PRO Adapter Driver;c:\windows\system32\drivers\e100b325.sys [2001-8-17 117760] S3 Flpydisk;Floppy Disk Driver;c:\windows\system32\drivers\flpydisk.sys [2004-8-4 20480] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;c:\windows\microsoft.net\framework\v3.0\wpf\PresentationFontCache.exe [2007-10-9 36864] S3 i81x;i81x;c:\windows\system32\drivers\i81xnt5.sys [2004-8-4 161020] S3 iAimFP0;iAimFP0;c:\windows\system32\drivers\wADV01nt.sys [2004-8-4 12415] S3 iAimFP1;iAimFP1;c:\windows\system32\drivers\wADV02NT.sys [2004-8-4 12127] S3 iAimFP2;iAimFP2;c:\windows\system32\drivers\wADV05NT.sys [2004-8-4 11775] S3 iAimFP3;iAimFP3;c:\windows\system32\drivers\wSiINTxx.sys [2004-8-4 12063] S3 iAimFP4;iAimFP4;c:\windows\system32\drivers\wVchNTxx.sys [2004-8-4 19455] S3 iAimFP5;iAimFP5;c:\windows\system32\drivers\wADV07nt.sys [2004-8-4 11807] S3 iAimFP6;iAimFP6;c:\windows\system32\drivers\wADV08NT.sys [2004-8-4 11295] S3 iAimFP7;iAimFP7;c:\windows\system32\drivers\wADV09NT.sys [2004-8-4 11871] S3 iAimTV0;iAimTV0;c:\windows\system32\drivers\wATV01nt.sys [2004-8-4 29311] S3 iAimTV1;iAimTV1;c:\windows\system32\drivers\wATV02NT.sys [2004-8-4 19551] S3 iAimTV3;iAimTV3;c:\windows\system32\drivers\wATV04nt.sys [2004-8-4 33599] S3 iAimTV4;iAimTV4;c:\windows\system32\drivers\wCh7xxNT.sys [2004-8-4 23615] S3 iAimTV5;iAimTV5;c:\windows\system32\drivers\wATV10nt.sys [2004-8-4 25471] S3 iAimTV6;iAimTV6;c:\windows\system32\drivers\wATV06nt.sys [2004-8-4 22271] S3 ialm;ialm;c:\windows\system32\drivers\ialmnt5.sys [2004-5-6 1302332] S3 IDriverT;InstallDriver Table Manager;c:\program files\common files\installshield\driver\11\intel 32\IDriverT.exe [2005-4-4 69632] S3 idsvc;Windows CardSpace;c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe [2007-10-11 864256] S3 ImapiService;IMAPI CD-Burning COM Service;c:\windows\system32\imapi.exe [2004-8-4 150016] S3 Ip6Fw;IPv6 Windows Firewall Driver;c:\windows\system32\drivers\ip6fw.sys [2004-8-4 29056] S3 IpFilterDriver;IP Traffic Filter Driver;c:\windows\system32\drivers\ipfltdrv.sys [2001-8-17 32896] S3 IpInIp;IP in IP Tunnel Driver;c:\windows\system32\drivers\ipinip.sys [2004-8-4 20992] S3 IRENUM;IR Enumerator Service;c:\windows\system32\drivers\irenum.sys [2004-8-4 11264] S3 mnmsrvc;NetMeeting Remote Desktop Sharing;c:\windows\system32\mnmsrvc.exe [2004-8-4 32768] S3 Modem;Modem;c:\windows\system32\drivers\modem.sys [2004-8-4 30080] S3 MSDTC;Distributed Transaction Coordinator;c:\windows\system32\msdtc.exe [2004-8-4 6144] S3 MSIServer;Windows Installer;c:\windows\system32\msiexec.exe [2004-8-4 78848] S3 MSKSSRV;Microsoft Streaming Service Proxy;c:\windows\system32\drivers\MSKSSRV.sys [2004-8-4 7552] S3 MSPCLOCK;Microsoft Streaming Clock Proxy;c:\windows\system32\drivers\MSPCLOCK.sys [2004-8-4 5376] S3 MSPQM;Microsoft Streaming Quality Manager Proxy;c:\windows\system32\drivers\MSPQM.sys [2004-8-4 4992] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter;c:\windows\system32\drivers\MSTEE.sys [2008-12-5 5504] S3 NABTSFEC;NABTS/FEC VBI Codec;c:\windows\system32\drivers\NABTSFEC.sys [2008-12-5 85376] S3 NdisIP;Microsoft TV/Video Connection;c:\windows\system32\drivers\NdisIP.sys [2008-12-5 10880] S3 Ndisuio;NDIS Usermode I/O Protocol;c:\windows\system32\drivers\ndisuio.sys [2004-8-4 12928] S3 Netlogon;Net Logon;c:\windows\system32\lsass.exe [2004-8-4 13312] S3 NtLmSsp;NT LM Security Support Provider;c:\windows\system32\lsass.exe [2004-8-4 13312] S3 NtmsSvc;Removable Storage;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 NwlnkFlt;IPX Traffic Filter Driver;c:\windows\system32\drivers\nwlnkflt.sys [2001-8-17 12416] S3 NwlnkFwd;IPX Traffic Forwarder Driver;c:\windows\system32\drivers\nwlnkfwd.sys [2001-8-17 32512] S3 PDCOMP;PDCOMP; [x] S3 PDFRAME;PDFRAME; [x] S3 PDRELI;PDRELI; [x] S3 PDRFRAME;PDRFRAME; [x] S3 RDPWD;RDPWD;c:\windows\system32\drivers\rdpwd.sys [2004-8-4 139528] S3 RDSessMgr;Remote Desktop Help Session Manager;c:\windows\system32\sessmgr.exe [2004-8-4 140800] S3 RpcLocator;Remote Procedure Call (RPC) Locator;c:\windows\system32\locator.exe [2004-8-4 75264] S3 RSVP;QoS RSVP;c:\windows\system32\rsvp.exe [2001-8-18 132608] S3 SCardSvr;Smart Card;c:\windows\system32\scardsvr.exe [2004-8-4 95744] S3 Secdrv;Secdrv;c:\windows\system32\drivers\secdrv.sys [2004-7-17 20480] S3 Sfloppy;High-Capacity Floppy Disk Drive;c:\windows\system32\drivers\sfloppy.sys [2004-8-4 11392] S3 SLIP;BDA Slip De-Framer;c:\windows\system32\drivers\SLIP.sys [2008-12-5 11136] S3 splitter;Microsoft Kernel Audio Splitter;c:\windows\system32\drivers\splitter.sys [2004-8-4 6400] S3 stisvc;Windows Image Acquisition (WIA);c:\windows\system32\svchost.exe -k imgsvc [2004-8-4 14336] S3 streamip;BDA IPSink;c:\windows\system32\drivers\StreamIP.sys [2008-12-5 15360] S3 swmidi;Microsoft Kernel GS Wavetable Synthesizer;c:\windows\system32\drivers\swmidi.sys [2001-8-17 54272] S3 SwPrv;MS Software Shadow Copy Provider;c:\windows\system32\dllhost.exe [2004-8-4 5120] S3 SysmonLog;Performance Logs and Alerts;c:\windows\system32\smlogsvc.exe [2004-8-4 89600] S3 TDPIPE;TDPIPE;c:\windows\system32\drivers\tdpipe.sys [2004-8-4 12040] S3 TDTCP;TDTCP;c:\windows\system32\drivers\tdtcp.sys [2004-8-4 21896] S3 UPS;Uninterruptible Power Supply;c:\windows\system32\ups.exe [2004-8-4 18432] S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [2008-8-17 32000] S3 usbccgp;Microsoft USB Generic Parent Driver;c:\windows\system32\drivers\usbccgp.sys [2008-7-25 31616] S3 USBSTOR;USB Mass Storage Driver;c:\windows\system32\drivers\USBSTOR.SYS [2008-1-25 26496] S3 VSS;Volume Shadow Copy;c:\windows\system32\vssvc.exe [2004-8-4 289792] S3 Wdf01000;Wdf01000;c:\windows\system32\drivers\wdf01000.sys [2006-4-20 479200] S3 WDICA;WDICA; [x] S3 WLSetupSvc;Windows Live Setup Service;c:\program files\windows live\installer\WLSetupSvc.exe [2007-10-25 266240] S3 WmdmPmSN;Portable Media Serial Number Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 Wmi;Windows Management Instrumentation Driver Extensions;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 WmiApSrv;WMI Performance Adapter;c:\windows\system32\wbem\wmiapsrv.exe [2004-8-4 126464] S3 WMPNetworkSvc;Windows Media Player Network Sharing Service;c:\program files\windows media player\wmpnetwk.exe [2006-10-18 913408] S3 WSTCODEC;World Standard Teletext Codec;c:\windows\system32\drivers\WSTCODEC.SYS [2008-12-5 19328] S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver;c:\windows\system32\drivers\WudfPf.sys [2006-9-28 77568] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector;c:\windows\system32\drivers\WudfRd.sys [2006-9-28 82944] S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework;c:\windows\system32\svchost.exe -k WudfServiceGroup [2004-8-4 14336] S3 WZCSVC;Wireless Zero Configuration;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 xmlprov;Network Provisioning Service;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21;c:\windows\system32\drivers\xusb21.sys [2008-12-25 61984] S4 Abiosdsk;Abiosdsk; [x] S4 abp480n5;abp480n5; [x] S4 ACPIEC;ACPIEC;c:\windows\system32\drivers\acpiec.sys [2001-8-17 11648] S4 adpu160m;adpu160m;c:\windows\system32\drivers\adpu160m.sys [2001-8-17 101888] S4 adpu320;adpu320;c:\windows\system32\drivers\adpu320.sys [2002-5-9 105472] S4 Aha154x;Aha154x; [x] S4 aic78u2;aic78u2;c:\windows\system32\drivers\aic78u2.sys [2001-8-17 55168] S4 aic78xx;aic78xx;c:\windows\system32\drivers\aic78xx.sys [2001-8-17 56960] S4 Alerter;Alerter;c:\windows\system32\svchost.exe -k LocalService [2004-8-4 14336] S4 AliIde;AliIde; [x] S4 amsint;amsint; [x] S4 asc;asc; [x] S4 asc3350p;asc3350p; [x] S4 asc3550;asc3550; [x] S4 Atdisk;Atdisk; [x] S4 cbidf2k;cbidf2k;c:\windows\system32\drivers\cbidf2k.sys [2001-8-17 13952] S4 cd20xrnt;cd20xrnt; [x] S4 ClipSrv;ClipBook;c:\windows\system32\clipsrv.exe [2004-8-4 33280] S4 CmdIde;CmdIde; [x] S4 Cpqarray;Cpqarray; [x] S4 dac960nt;dac960nt; [x] S4 dmboot;dmboot;c:\windows\system32\drivers\dmboot.sys [2004-8-4 799744] S4 dpti2o;dpti2o;c:\windows\system32\drivers\dpti2o.sys [2001-8-17 20192] S4 Fastfat;Fastfat;c:\windows\system32\drivers\fastfat.sys [2004-8-4 143360] S4 hpn;hpn; [x] S4 i2omp;i2omp; [x] S4 ini910u;ini910u; [x] S4 IntelIde;IntelIde;c:\windows\system32\drivers\intelide.sys [2004-8-4 5504] S4 Messenger;Messenger;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S4 mraid35x;mraid35x; [x] S4 NetDDE;Network DDE;c:\windows\system32\netdde.exe [2004-8-4 111104] S4 NetDDEdsdm;Network DDE DSDM;c:\windows\system32\netdde.exe [2004-8-4 111104] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"c:\windows\microsoft.net\framework\v3.0\windows communication foundation\SMSvcHost.exe" [2007-10-11 122880] S4 ParVdm;ParVdm;c:\windows\system32\drivers\parvdm.sys [2001-8-17 6784] S4 Pcmcia;Pcmcia;c:\windows\system32\drivers\pcmcia.sys [2004-8-4 119936] S4 perc2;perc2; [x] S4 perc2hib;perc2hib; [x] S4 ql1080;ql1080; [x] S4 Ql10wnt;Ql10wnt; [x] S4 ql12160;ql12160; [x] S4 ql1240;ql1240; [x] S4 ql1280;ql1280; [x] S4 RemoteAccess;Routing and Remote Access;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] S4 Simbad;Simbad; [x] S4 Sparrow;Sparrow; [x] S4 sym_hi;sym_hi;c:\windows\system32\drivers\sym_hi.sys [2001-8-17 28384] S4 sym_u3;sym_u3;c:\windows\system32\drivers\sym_u3.sys [2001-8-17 30688] S4 symc810;symc810;c:\windows\system32\drivers\symc810.sys [2001-8-17 16256] S4 symc8xx;symc8xx;c:\windows\system32\drivers\symc8xx.sys [2001-8-17 32640] S4 Symmpi;Symmpi;c:\windows\system32\drivers\symmpi.sys [2004-8-10 28416] S4 TlntSvr;Telnet;c:\windows\system32\tlntsvr.exe [2004-8-4 73216] S4 TosIde;TosIde; [x] S4 Udfs;Udfs;c:\windows\system32\drivers\udfs.sys [2004-8-4 66176] S4 ultra;ultra; [x] S4 ViaIde;ViaIde;c:\windows\system32\drivers\viaide.sys [2004-8-4 5376] S4 wuauserv;Automatic Updates;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] ============== File Associations =============== batfile="%1" %* chm.file="c:\windows\hh.exe" %1 cmdfile="%1" %* comfile="%1" %* exefile="%1" %* inffile=%SystemRoot%\System32\NOTEPAD.EXE %1 inifile=%SystemRoot%\System32\NOTEPAD.EXE %1 JSEFile=%SystemRoot%\System32\WScript.exe "%1" %* piffile="%1" %* regedit=regedit.exe %1 regfile=regedit.exe "%1" scrfile="%1" /S txtfile=%SystemRoot%\system32\NOTEPAD.EXE %1 VBEFile=%SystemRoot%\System32\WScript.exe "%1" %* VBSFile=%SystemRoot%\System32\WScript.exe "%1" %* =============== Created Last 30 ================ 2009-02-09 17:36 250 a——- c:\windows\gmer.ini 2009-02-09 17:36 884,736 a——- c:\windows\gmer.dll 2009-02-09 17:36 811,008 a——- c:\windows\gmer.exe 2009-02-09 17:36 85,969 a——- c:\windows\system32\drivers\gmer.sys 2009-02-09 17:36 80 a——- c:\windows\gmer_uninstall.cmd 2009-02-09 14:40 73,728 a——- c:\windows\system32\javacpl.cpl 2009-02-09 14:40 410,984 a——- c:\windows\system32\deploytk.dll 2009-02-09 14:40 148,888 a——- c:\windows\system32\javaws.exe 2009-02-09 14:40 144,792 a——- c:\windows\system32\javaw.exe 2009-02-09 14:40 144,792 a——- c:\windows\system32\java.exe 2009-02-09 14:23 -cd—– C:\_OTMoveIt 2009-02-09 01:44 -cd-hr– c:\documents and settings\administrator\Recent 2009-02-08 21:44 -cd—– c:\docume~1\admini~1\applic~1\Malwarebytes 2009-02-08 21:44 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-02-08 21:44 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-08 21:44 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-02-08 21:44 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-02-08 18:55 –d—– c:\program files\Spybot - Search & Destroy 2009-02-08 18:55 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-02-08 18:29 –d—– c:\program files\Windows Defender 2009-02-08 16:17 –d—– c:\program files\Trojan Remover 2009-02-08 16:00 -cd—– C:\VundoFix Backups 2009-02-07 17:51 -cd-h— C:\$AVG8.VAULT$ 2009-01-26 12:35 –d—– c:\docume~1\alluse~1\applic~1\Electronic Arts 2009-01-20 19:37 –d—– c:\docume~1\alluse~1\applic~1\Fallout3 2009-01-20 19:37 –d—– c:\program files\Bethesda Softworks 2009-01-20 19:35 –d—– c:\windows\system32\xlive 2009-01-20 02:16 -cd—– c:\docume~1\admini~1\applic~1\vlc 2009-01-20 01:30 –d—– c:\program files\Mozilla ActiveX Control v1.7.12 2009-01-20 01:06 -cd—– c:\docume~1\admini~1\applic~1\Graboid Inc 2009-01-16 16:31 268 ac–h— C:\sqmdata01.sqm 2009-01-16 16:31 244 ac–h— C:\sqmnoopt01.sqm 2009-01-14 22:25 –d—– c:\program files\Activision 2009-01-14 22:00 –dsh— c:\windows\ftpcache 2009-01-14 21:44 –d—– c:\program files\PowerISO 2009-01-14 21:42 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Pro 2009-01-14 21:42 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools 2009-01-14 21:41 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite 2009-01-14 21:40 –d—– c:\program files\DAEMON Tools Lite 2009-01-14 21:22 717,296 a——- c:\windows\system32\drivers\sptd.sys 2009-01-14 21:22 -cd—– c:\docume~1\admini~1\applic~1\DAEMON Tools Lite 2009-01-12 18:49 -cd—– c:\docume~1\admini~1\applic~1\DNA 2009-01-12 18:49 –d—– c:\program files\DNA 2009-01-11 15:13 1,456 a——- c:\windows\system32\ealregsnapshot1.reg ==================== Find3M ==================== 2009-02-09 20:30 48,922 a——- c:\windows\prefetch\DDS.SCR-1E2538DD.pf 2009-02-09 20:30 11,460 a——- c:\windows\prefetch\FI.EXE-27F08F22.pf 2009-02-09 20:30 5,114 a——- c:\windows\prefetch\EDS.EXE-1207C288.pf 2009-02-09 20:30 13,384 a——- c:\windows\prefetch\SORT.EXE-194AE83C.pf 2009-02-09 20:30 40,300 a——- c:\windows\prefetch\CSCRIPT.EXE-1C26180C.pf 2009-02-09 20:30 8,698 a——- c:\windows\prefetch\WREGS.EXE-1CD746DD.pf 2009-02-09 20:30 12,180 a——- c:\windows\prefetch\FIND.EXE-0EC32F1E.pf 2009-02-09 20:30 22,734 a——- c:\windows\prefetch\ETPATHS.EXE-15F5AFAC.pf 2009-02-09 20:30 13,528 a——- c:\windows\prefetch\FINDSTR.EXE-0CA6274B.pf 2009-02-09 20:30 49,152 a—h— c:\documents and settings\administrator\ntuser.dat.LOG 2009-02-09 20:30 15,710 a——- c:\windows\prefetch\CMD.EXE-087B4001.pf 2009-02-09 20:30 10,052 a——- c:\windows\prefetch\AVGCMGR.EXE-1D29CBA8.pf 2009-02-09 20:29 16,932 a——- c:\windows\prefetch\NOTEPAD.EXE-336351A9.pf 2009-02-09 20:27 109,482 a——- c:\windows\prefetch\FIREFOX.EXE-28641590.pf 2009-02-09 20:27 8,168 a——- c:\windows\prefetch\JQSNOTIFY.EXE-24AE4A36.pf 2009-02-09 20:05 30,980 a——- c:\windows\prefetch\WMIPRVSE.EXE-28F301A9.pf 2009-02-09 20:05 8,782 a——- c:\windows\prefetch\WREGS.EXE-2373CC13.pf 2009-02-09 20:04 13,182 a——- c:\windows\prefetch\FI.EXE-00203718.pf 2009-02-09 20:04 5,098 a——- c:\windows\prefetch\EDS.EXE-119156EF.pf 2009-02-09 20:04 22,832 a——- c:\windows\prefetch\ETPATHS.EXE-23F6922C.pf 2009-02-09 19:26 89,164 a——- c:\windows\prefetch\ITUNES.EXE-1A268432.pf 2009-02-09 19:03 34,618 a——- c:\windows\prefetch\WLLOGINPROXY.EXE-1781D844.pf 2009-02-09 19:03 64,466 a——- c:\windows\prefetch\IEXPLORE.EXE-27122324.pf 2009-02-09 18:56 224,030 a——- c:\windows\prefetch\layout.ini 2009-02-09 18:41 21,834 a——- c:\windows\prefetch\LOGONUI.EXE-0AF22957.pf 2009-02-09 18:02 81,332 a——- c:\windows\prefetch\MSNMSGR.EXE-030AB647.pf 2009-02-09 17:57 8,782 a——- c:\windows\prefetch\WREGS.EXE-250B8CEF.pf 2009-02-09 17:56 5,110 a——- c:\windows\prefetch\EDS.EXE-111AEB56.pf 2009-02-09 17:56 12,882 a——- c:\windows\prefetch\FI.EXE-24FEA499.pf 2009-02-09 17:56 23,190 a——- c:\windows\prefetch\ETPATHS.EXE-1B382D3F.pf 2009-02-09 17:56 15,906 a——- c:\windows\prefetch\VERCLSID.EXE-3667BD89.pf 2009-02-09 17:56 68,448 a——- c:\windows\prefetch\SCANNINGPROCESS.EXE-0D88C742.pf 2009-02-09 17:55 90,088 a——- c:\windows\prefetch\JAVA.EXE-0C263507.pf 2009-02-09 17:38 62,340 a——- c:\windows\prefetch\GMER.EXE-1300037F.pf 2009-02-09 17:36 40,396 a——- c:\windows\prefetch\WINRAR.EXE-39C6DAD9.pf 2009-02-09 17:35 12,846 a——- c:\windows\prefetch\SYSTEMLOOK.EXE-2EE5A6C3.pf 2009-02-09 17:24 22,824 a——- c:\windows\prefetch\HIJACKTHIS.EXE-235DF147.pf 2009-02-09 14:46 42,044 a——- c:\windows\prefetch\MPCMDRUN.EXE-1F9D1CA1.pf 2009-02-09 14:41 12,036 a——- c:\windows\prefetch\JAVAWS.EXE-021AC9A9.pf 2009-02-09 14:41 21,098 a——- c:\windows\prefetch\JQS.EXE-1D781F77.pf 2009-02-09 14:41 88,640 a——- c:\windows\prefetch\JAVAW.EXE-2DC32ABC.pf 2009-02-09 14:40 55,574 a——- c:\windows\prefetch\UNPACK200.EXE-16F2D239.pf 2009-02-09 14:40 72,366 a——- c:\windows\prefetch\MSIEXEC.EXE-2F8A8CAE.pf 2009-02-09 14:40 49,420 a——- c:\windows\prefetch\ZIPPER.EXE-2C9C69B1.pf 2009-02-09 14:40 7,470 a——- c:\windows\prefetch\MSI42.TMP-1ED9CA03.pf 2009-02-09 14:40 53,544 a——- c:\windows\prefetch\JRE-6U12-WINDOWS-I586-P.EXE-151E20DB.pf 2009-02-09 14:39 36,958 a——- c:\windows\prefetch\JAVAW.EXE-222468CF.pf 2009-02-09 14:39 25,312 a——- c:\windows\prefetch\JAVAWS.EXE-25F11D4D.pf 2009-02-09 14:38 52,570 a——- c:\windows\prefetch\RUNDLL32.EXE-2CD85FD3.pf 2009-02-09 14:38 12,286 a——- c:\windows\prefetch\IGFXSRVC.EXE-2FB63FE8.pf 2009-02-09 14:37 18,618 a——- c:\windows\prefetch\CHECKER.EXE-1B259BA4.pf 2009-02-09 14:30 55,366 a——- c:\windows\prefetch\CSC.EXE-1113BFA6.pf 2009-02-09 14:30 5,726 a——- c:\windows\prefetch\CVTRES.EXE-13DEB540.pf 2009-02-09 14:30 11,596 a——- c:\windows\prefetch\USNSVC.EXE-2DF2835C.pf 2009-02-09 14:28 14,098 a——- c:\windows\prefetch\IPODSERVICE.EXE-3192DE38.pf 2009-02-09 14:28 6,256 a——- c:\windows\prefetch\NTVDM.EXE-1A10A423.pf 2009-02-09 14:28 18,582 a——- c:\windows\prefetch\RAUI.EXE-0812E922.pf 2009-02-09 14:28 11,290 a——- c:\windows\prefetch\DAEMON.EXE-208767E0.pf 2009-02-09 14:28 13,140 a——- c:\windows\prefetch\BTDNA.EXE-19B6C782.pf 2009-02-09 14:28 11,762 a——- c:\windows\prefetch\CORE.EXE-0535AB52.pf 2009-02-09 14:28 9,344 a——- c:\windows\prefetch\TBPANEL.EXE-003DDFB3.pf 2009-02-09 14:28 7,300 a——- c:\windows\prefetch\COMRADE.EXE-2EA285EF.pf 2009-02-09 14:28 32,772 a——- c:\windows\prefetch\MSASCUI.EXE-08BEC8D8.pf 2009-02-09 14:25 2,048 a–s—- c:\windows\bootstat.dat 2009-02-09 14:25 792,723,456 a–sh— C:\pagefile.sys 2009-02-09 14:24 3,407,872 a—h— c:\documents and settings\administrator\NTUSER.DAT 2009-02-09 14:24 178 -c-sh— c:\documents and settings\administrator\ntuser.ini 2009-02-09 13:58 15,226 a——- c:\windows\prefetch\REGEDIT.EXE-1B606482.pf 2009-02-09 13:50 41,596 a——- c:\windows\prefetch\MBAM.EXE-0BEE0439.pf 2009-02-09 13:41 1,024 a—h— c:\documents and settings\all users\ntuser.dat.LOG 2009-02-04 20:31 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_667.xml 2009-02-04 20:31 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_657.xml 2009-02-03 19:27 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_637.xml 2009-02-03 19:27 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_627.xml 2009-02-02 15:40 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_607.xml 2009-02-02 15:40 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_597.xml 2009-01-31 02:14 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_577.xml 2009-01-31 02:14 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_567.xml 2009-01-29 23:54 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_547.xml 2009-01-29 23:54 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_537.xml 2009-01-27 22:17 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_517.xml 2009-01-27 22:17 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_507.xml 2009-01-25 20:38 3,836 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_493.xml 2009-01-25 20:38 2,150 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_487.xml 2009-01-25 20:38 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_477.xml 2009-01-25 03:11 98,304 a——- c:\windows\system32\CmdLineExt.dll 2009-01-25 02:17 138,464 a——- c:\windows\system32\drivers\PnkBstrK.sys 2009-01-25 02:17 111,928 a——- c:\windows\system32\PnkBstrB.exe 2009-01-24 19:23 5,682 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_465.xml 2009-01-24 19:23 3,734 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_457.xml 2009-01-24 19:22 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_447.xml 2009-01-23 18:23 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_427.xml 2009-01-23 18:23 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_417.xml 2009-01-22 17:02 3,702 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_397.xml 2009-01-22 17:02 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_387.xml 2009-01-21 15:04 3,692 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_373.xml 2009-01-21 15:04 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_367.xml 2009-01-21 15:04 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_357.xml 2009-01-20 04:59 10,414 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_343.xml 2009-01-20 04:59 3,708 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_337.xml 2009-01-20 04:59 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_327.xml 2009-01-18 21:08 1,906 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_307.xml 2009-01-18 21:08 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_297.xml 2009-01-15 19:58 7,248 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_283.xml 2009-01-15 19:58 5,424 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_285.xml 2009-01-15 19:58 1,776 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_279.xml 2009-01-15 19:58 9,874 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_277.xml 2009-01-15 19:58 9,024 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_275.xml 2009-01-15 19:57 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_267.xml 2009-01-14 22:40 22,328 ac—— c:\docume~1\admini~1\applic~1\PnkBstrK.sys 2009-01-14 22:40 682,280 a——- c:\windows\system32\pbsvc.exe 2009-01-14 22:40 66,872 a——- c:\windows\system32\PnkBstrA.exe 2009-01-14 21:37 1,412,752 a——- c:\windows\inf\INFCACHE.1 2009-01-14 20:55 170,976 a——- c:\windows\pchealth\helpctr\config\cache\Professional_32_1033.dat.bak 2009-01-13 23:55 19,748 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_253.xml 2009-01-13 23:55 2,932 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_255.xml 2009-01-13 23:55 2,118 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_247.xml 2009-01-13 23:55 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_237.xml 2009-01-09 10:05 128,516 a——- c:\windows\inf\oem30.PNF 2009-01-09 09:56 192,468 a——- c:\windows\inf\oem29.PNF 2009-01-06 20:04 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_207.xml 2009-01-05 17:58 9,134 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_193.xml 2009-01-05 17:58 2,838 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_195.xml 2009-01-05 17:58 1,776 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_187.xml 2009-01-05 17:58 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_177.xml 2009-01-02 06:07 59,500 a——- c:\windows\inf\oem28.PNF 2009-01-02 03:34 244 ac–h— C:\sqmnoopt00.sqm 2009-01-02 03:34 232 ac–h— C:\sqmdata00.sqm 2008-12-31 23:40 5,318 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_157.xml 2008-12-31 23:40 2,038 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_147.xml 2008-12-27 20:00 24,572 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_133.xml 2008-12-27 20:00 2,968 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_135.xml 2008-12-27 20:00 8,572 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_127.xml 2008-12-27 20:00 2,040 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_117.xml 2008-12-26 19:20 153,823 a——- c:\windows\inf\oem29.inf 2008-12-26 16:56 102,232 a——- c:\windows\system32\FNTCACHE.DAT 2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf 2008-12-25 10:22 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf 2008-12-25 10:12 5,496 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_105.xml 2008-12-25 10:12 29,702 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_103.xml 2008-12-25 10:12 8,598 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_97.xml 2008-12-25 10:12 2,442 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_77.xml 2008-12-25 10:12 2,040 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_87.xml 2008-12-25 09:54 8,606 a——- c:\windows\inf\oem27.PNF 2008-12-25 09:54 4,776 a——- c:\windows\inf\xinput1_3_x86.PNF 2008-12-25 09:50 4,676 a——- c:\windows\inf\branches.PNF 2008-12-23 21:58 453,152 a——- c:\windows\system32\NVUNINST.EXE 2008-12-19 07:27 2,832 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_75.xml 2008-12-19 07:27 7,118 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_67.xml 2008-12-19 07:27 2,040 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_57.xml 2008-12-12 14:47 586,756 a——- c:\windows\system32\TZLog.log 2008-12-09 23:24 17,593,280 a——- c:\windows\system32\MRT.exe 2008-12-09 19:40 8,990 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_43.xml 2008-12-09 19:40 2,112 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_37.xml 2008-12-09 19:40 2,040 a——- c:\windows\pchealth\helpctr\datacoll\CollectedData_27.xml 2008-12-05 14:27 8,580 a——- c:\windows\inf\oem17.PNF 2008-12-05 14:24 8,584 a——- c:\windows\inf\oem26.PNF 2008-12-05 14:16 1,066,494 a——- c:\windows\setupapi.log.0.old 2008-12-05 14:00 20,236 a——- c:\windows\inf\bda.PNF 2008-12-05 13:58 11,956 a——- c:\windows\inf\streamip.PNF 2008-12-05 13:58 9,096 a——- c:\windows\inf\ndisip.PNF 2008-12-05 13:58 9,200 a——- c:\windows\inf\wstcodec.PNF 2008-12-05 13:58 9,196 a——- c:\windows\inf\slip.PNF 2008-12-05 13:58 9,644 a——- c:\windows\inf\ccdecode.PNF 2008-12-05 13:58 9,636 a——- c:\windows\inf\nabtsfec.PNF 2008-12-05 01:08 52,612 a——- c:\windows\inf\oem25.PNF 2008-12-03 22:02 43,500 a——- c:\windows\inf\kscaptur.PNF 2008-12-03 22:00 7,590 a——- c:\windows\inf\oem22.PNF 2008-12-03 21:59 12,148 a——- c:\windows\inf\oem21.PNF 2008-12-02 15:11 121,260 a——- c:\windows\inf\oem20.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_6_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_5_x86.PNF 2008-12-02 15:09 4,856 a——- c:\windows\inf\d3dx9_32_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_4_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_3_x86.PNF 2008-12-02 15:09 4,856 a——- c:\windows\inf\d3dx9_31_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_2_x86.PNF 2008-12-02 15:09 4,776 a——- c:\windows\inf\xinput1_2_x86.PNF 2008-12-02 15:09 5,192 a——- c:\windows\inf\xact2_1_x86.PNF 2008-12-02 15:09 4,776 a——- c:\windows\inf\xinput1_1_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_30_x86.PNF 2008-12-02 15:08 5,176 a——- c:\windows\inf\xact_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_29_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_28_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_27_x86.PNF 2008-12-02 15:08 4,792 a——- c:\windows\inf\xinput9_1_0_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_26_x86.PNF 2008-12-02 15:08 4,856 a——- c:\windows\inf\d3dx9_25_x86.PNF 2008-12-02 15:08 4,888 a——- c:\windows\inf\d3dx9_24_x86.PNF 2008-11-24 15:13 522,530 a——- c:\windows\system32\PerfStringBackup.INI 2008-11-24 15:13 441,624 a——- c:\windows\system32\perfh009.dat 2008-11-24 15:13 71,308 a——- c:\windows\system32\perfc009.dat 2008-11-21 21:46 1,044,480 a——- c:\windows\system32\libdivx.dll 2008-11-21 21:46 200,704 a——- c:\windows\system32\ssldivx.dll 2008-11-21 21:44 161,096 a——- c:\windows\system32\DivXCodecVersionChecker.exe 2008-11-21 21:44 12,288 a——- c:\windows\system32\DivXWMPExtType.dll 2008-11-12 14:54 33,072 a——- c:\windows\inf\oem28.inf 2008-11-12 14:54 28,683 a——- c:\windows\inf\oem25.inf 2008-11-07 14:23 3,138 a——- c:\windows\inf\oem26.inf 2008-10-16 14:04 54,440 a——- c:\windows\inf\wuau.adm 2008-09-11 09:13 78,749 a—-r– c:\windows\inf\oem20.inf 2008-09-11 09:13 11,706 a—-r– c:\windows\inf\oem21.inf 2008-09-11 09:13 2,491 a—-r– c:\windows\inf\oem22.inf 2008-08-17 14:28 87,608 ac—— c:\docume~1\admini~1\applic~1\inst.exe 2008-08-17 14:28 47,360 ac—— c:\docume~1\admini~1\applic~1\pcouffin.sys 2008-08-17 14:28 7,887 ac—— c:\docume~1\admini~1\applic~1\pcouffin.cat 2008-08-17 14:28 1,144 ac—— c:\docume~1\admini~1\applic~1\pcouffin.inf 2008-08-17 14:28 55 ac—— c:\docume~1\admini~1\applic~1\pcouffin.log 2008-08-17 13:27 5,900 a——- c:\windows\inf\GEARAspiWDM.PNF 2008-08-17 12:47 587 ac—— c:\docume~1\admini~1\applic~1\AutoGK.ini 2008-08-17 10:33 62,236 a——- c:\windows\inf\font.PNF 2008-08-17 07:32 424,000 a——- c:\windows\inf\intl.PNF 2008-08-16 01:27 4,684 a——- c:\windows\inf\Erma.PNF 2008-08-15 16:23 39,228 a——- c:\windows\inf\oem14.PNF 2008-08-15 16:23 35,850 a——- c:\windows\inf\oem13.PNF 2008-08-15 15:20 20,028 a——- c:\windows\inf\oem15.PNF 2008-08-14 18:06 13,824 a——- c:\windows\inf\AegisP.inf 2008-08-14 18:06 9,992 a——- c:\windows\inf\AegisP.PNF 2008-07-25 01:19 12,720 a——- c:\windows\inf\hidserv.PNF 2008-07-25 01:18 44,496 a——- c:\windows\inf\usb.PNF 2008-04-17 13:12 2,761 a——- c:\windows\inf\oem17.inf 2008-01-25 13:50 37,024 a——- c:\windows\inf\usbstor.PNF 2008-01-25 00:23 4,624 a——- c:\windows\inf\msxpsdrv.PNF 2008-01-25 00:15 12,016 a——- c:\windows\inf\wpdmtp.PNF 2008-01-25 00:15 5,256 a——- c:\windows\inf\WPDMTPHW.PNF 2008-01-25 00:15 8,012 a——- c:\windows\inf\wmp11.PNF 2008-01-25 00:15 3,988 a——- c:\windows\inf\wmsetsdk.PNF 2008-01-25 00:15 6,020 a——- c:\windows\inf\skins.PNF 2008-01-25 00:15 4,352 a——- c:\windows\inf\lhtsc.PNF 2008-01-25 00:09 4,424 a——- c:\windows\inf\ieaccess.PNF 2008-01-24 23:33 44,964 a——- c:\windows\inf\printupg.PNF 2008-01-24 23:28 10,922 a——- c:\windows\inf\oem12.PNF 2008-01-24 23:22 78,556 a——- c:\windows\inf\oem11.PNF 2008-01-24 23:21 10,524 a——- c:\windows\inf\WPD10.PNF 2008-01-24 23:21 22,146 a——- c:\windows\inf\WMDM10.PNF 2008-01-24 23:21 10,744 a——- c:\windows\inf\WMFSDK10.PNF 2008-01-24 23:21 13,082 a——- c:\windows\inf\codecs10.PNF 2008-01-24 23:21 6,770 a——- c:\windows\inf\DRM10.PNF 2008-01-24 23:21 6,178 a——- c:\windows\inf\MPPRE10.PNF 2008-01-24 15:40 3,764 a——- c:\windows\inf\minioc.PNF 2008-01-24 15:36 4,524 a——- c:\windows\inf\ProfSec.Inf 2008-01-24 15:32 7,290 a——- c:\windows\inf\oem8.PNF 2008-01-24 15:32 6,082 a——- c:\windows\inf\oem7.PNF 2008-01-24 15:25 112,360 a——- c:\windows\inf\monitor8.PNF 2008-01-24 08:11 48,316 a——- c:\windows\inf\accessor.PNF 2008-01-24 08:08 63,112 a——- c:\windows\inf\msmouse.PNF 2008-01-24 08:08 100,612 a——- c:\windows\inf\syssetup.PNF 2008-01-24 08:07 100,124 a——- c:\windows\inf\input.PNF 2008-01-24 07:44 21,352 a——- c:\windows\inf\wab50.PNF 2008-01-24 07:44 87,456 a——- c:\windows\inf\msmsgs.PNF 2008-01-24 07:44 56,940 a——- c:\windows\inf\wmp.PNF 2008-01-24 07:44 83,728 a——- c:\windows\inf\ie.PNF 2008-01-24 07:44 1,051,064 a——- c:\windows\inf\layout.PNF 2008-01-24 07:44 60,940 a——- c:\windows\inf\msnetmtg.PNF 2008-01-24 07:44 108,188 a——- c:\windows\inf\monitor.PNF 2008-01-24 07:44 35,964 a——- c:\windows\inf\msoe50.PNF 2008-01-24 07:44 8,136 a——- c:\windows\inf\ProfSec.PNF 2008-01-24 07:42 262,144 a——- c:\documents and settings\all users\ntuser.dat 2008-01-24 07:40 55,068 a——- c:\windows\inf\oem9.PNF 2008-01-24 07:40 222,180 a——- c:\windows\inf\drvindex.PNF 2008-01-24 07:40 54,620 a——- c:\windows\inf\oem3.PNF 2008-01-24 07:40 7,800 a——- c:\windows\inf\certclas.PNF 2007-02-20 11:50 35,940 a——- c:\windows\inf\oem15.inf 2007-02-17 01:41 6,838 a——- c:\windows\inf\oem27.inf 2006-11-02 12:41 2,037 a——- c:\windows\inf\skins.inf 2006-10-03 02:43 2,402,550 a——- c:\windows\inf\inetres.adm 2006-09-28 12:53 20,044 a——- c:\windows\inf\windowsdefender.adm 2006-09-11 17:00 8,019 a——- c:\windows\inf\wpdmtp.inf 2006-09-01 08:55 37,836 ——– c:\windows\inf\iem\0409\inetset.iem 2006-09-01 08:55 13,696 ——– c:\windows\inf\iem\0409\inetcorp.iem 2006-08-31 01:01 2,204 a——- c:\windows\inf\msxpsdrv.inf 2006-08-25 17:09 2,428 ——– c:\windows\inf\wmp11.inf 2006-08-24 08:35 5,412 a——- c:\windows\inf\oem12.inf 2006-06-08 09:53 37,776 a——- c:\windows\inf\oem13.inf 2006-04-25 10:10 69,612 a——- c:\windows\inf\wmplayer.adm 2006-04-25 10:09 1,816 ——– c:\windows\inf\WPDMTPHW.INF 2005-12-05 14:19 56,644 a——- c:\windows\inf\oem11.inf 2005-10-17 18:43 41,297 a——- c:\windows\inf\oem14.inf 2005-01-28 13:44 16,724 a——- c:\windows\inf\WMDM10.inf 2005-01-28 13:44 4,668 a——- c:\windows\inf\WMFSDK10.inf 2005-01-28 13:44 4,395 a——- c:\windows\inf\codecs10.inf 2005-01-28 13:44 3,954 a——- c:\windows\inf\wpd10.inf 2005-01-28 13:44 1,911 a——- c:\windows\inf\DRM10.inf 2004-09-14 04:09 33,672 a——- c:\windows\inf\AER_1025.ADM 2004-08-09 06:21 62 a–sh— c:\docume~1\alluse~1\applic~1\desktop.ini 2004-08-09 06:21 62 a–sh— c:\docume~1\admini~1\applic~1\desktop.ini 2004-08-04 15:00 81,775 a——- c:\windows\inf\comnt5.inf 2004-08-04 15:00 6,398 a——- c:\windows\inf\msmqocm.inf 2004-08-04 15:00 3,284 a——- c:\windows\inf\dtcnt5.inf 2004-08-04 12:00 1,498,946 a——- c:\windows\inf\ntprint.inf 2004-08-04 12:00 849,768 a——- c:\windows\inf\intl.inf 2004-08-04 12:00 408,529 a——- c:\windows\inf\layout.inf 2004-08-04 12:00 67,816 a——- c:\windows\inf\drvindex.inf 2004-08-04 12:00 48,044 a——- c:\windows\inf\biosinfo.inf 2004-08-04 12:00 6,464 a——- c:\windows\inf\mstask.inf 2004-08-04 08:07 114,810 a——- c:\windows\inf\tsoc.inf 2004-08-04 08:07 25,815 a——- c:\windows\inf\accessor.inf 2004-08-04 08:07 8,047 a——- c:\windows\inf\wordpad.inf 2004-08-04 08:07 5,748 a——- c:\windows\inf\multimed.inf 2004-08-04 08:07 3,928 a——- c:\windows\inf\msnmsn.inf 2004-08-04 08:07 836,490 a——- c:\windows\inf\iis.inf 2004-08-04 08:07 50,680 a——- c:\windows\inf\fxsocm.inf 2004-08-04 08:04 48,885 a——- c:\windows\inf\ims.inf 2004-08-04 05:51 28,806 a——- c:\windows\inf\wmp.inf 2004-08-04 05:51 18,286 a——- c:\windows\inf\mplayer2.inf 2004-08-04 05:51 17,272 a——- c:\windows\inf\wmdm.inf 2004-08-04 05:51 3,637 a——- c:\windows\inf\mymusic.inf 2004-08-04 05:41 85,069 a——- c:\windows\inf\mdmhamrw.inf 2004-08-04 05:41 60,733 a——- c:\windows\inf\mdmlt3.inf 2004-08-04 05:41 28,128 a——- c:\windows\inf\mdmntstm.inf 2004-08-04 05:41 299,444 a——- c:\windows\inf\mdmrpci.inf 2004-08-04 05:39 2,938 a——- c:\windows\inf\netrndis.inf 2004-08-04 05:34 8,847 a——- c:\windows\inf\netnm.inf 2004-08-04 05:31 17,503 a——- c:\windows\inf\netwlan.inf 2004-08-04 05:31 9,030 a——- c:\windows\inf\netwlan2.inf 2004-08-04 05:31 9,022 a——- c:\windows\inf\netrtsnt.inf 2004-08-04 05:31 10,068 a——- c:\windows\inf\netwv48.inf 2004-08-04 05:31 8,810 a——- c:\windows\inf\netklsi.inf 2004-08-04 05:23 7,379 a——- c:\windows\inf\moviemk.inf 2004-08-04 05:23 51,427 a——- c:\windows\inf\msmsgs.inf 2004-08-04 05:11 3,612 a——- c:\windows\inf\wstcodec.inf 2004-08-04 05:11 6,091 a——- c:\windows\inf\au.inf 2004-08-04 05:11 11,985 a——- c:\windows\inf\usbvideo.inf 2004-08-04 05:11 23,708 a——- c:\windows\inf\usbport.inf 2004-08-04 05:09 53,259 a——- c:\windows\inf\pnpscsi.inf 2004-08-04 05:09 5,089 a——- c:\windows\inf\pchealth.inf 2004-08-04 05:09 6,592 a——- c:\windows\inf\p2p.inf 2004-08-04 05:09 6,344 a——- c:\windows\inf\oobe.inf 2004-08-04 05:09 3,998 a——- c:\windows\inf\netwzc.inf 2004-08-04 05:09 3,243 a——- c:\windows\inf\netupnph.inf 2004-08-04 05:09 24,187 a——- c:\windows\inf\nettcpip.inf 2004-08-04 05:09 39,025 a——- c:\windows\inf\netrass.inf 2004-08-04 05:09 9,074 a——- c:\windows\inf\netoc.inf 2004-08-04 05:09 11,747 a——- c:\windows\inf\netmscli.inf 2004-08-04 05:09 6,151 a——- c:\windows\inf\netip6.inf 2004-08-04 05:07 4,433 a——- c:\windows\inf\hidserv.inf 2004-08-04 05:07 3,751 a——- c:\windows\inf\HidDigi.inf 2004-08-04 05:06 315,309 a——- c:\windows\inf\dwup.inf 2004-08-04 05:06 39,513 a——- c:\windows\inf\devxprop.inf 2004-08-04 05:06 5,327 a——- c:\windows\inf\disk.inf 2004-08-04 05:06 295,169 a——- c:\windows\inf\defltwk.inf 2004-08-04 05:06 8,134 a——- c:\windows\inf\cpu.inf 2004-08-04 05:06 35,450 a——- c:\windows\inf\cdrom.inf 2004-08-04 05:06 3,776 a——- c:\windows\inf\ccdecode.inf 2004-08-04 05:05 9,921 a——- c:\windows\inf\bda.inf 2004-08-04 05:05 5,442 a——- c:\windows\inf\battery.inf 2004-08-04 05:05 3,976 a——- c:\windows\inf\agp.inf 2004-08-04 05:05 4,727 a——- c:\windows\inf\acpi.inf 2004-08-04 05:02 49,661 a——- c:\windows\inf\mdmusrk1.inf 2004-08-04 05:02 15,527 a——- c:\windows\inf\mdmvv.inf 2004-08-04 05:02 27,971 a——- c:\windows\inf\mdmsuprv.inf 2004-08-04 05:02 49,296 a——- c:\windows\inf\mdmgen.inf 2004-08-04 05:02 41,011 a——- c:\windows\inf\mdmetech.inf 2004-08-04 05:02 26,756 a——- c:\windows\inf\mdmbtmdm.inf 2004-08-04 05:02 4,473 a——- c:\windows\inf\tdibth.inf 2004-08-04 05:02 11,681 a——- c:\windows\inf\bth.inf 2004-08-04 05:01 79,843 a——- c:\windows\inf\mdmirmdm.inf 2004-08-04 05:00 2,563 a——- c:\windows\inf\bthpan.inf 2004-08-04 05:00 46,281 a——- c:\windows\inf\msnetmtg.inf 2004-08-04 05:00 24,371 a——- c:\windows\inf\wdma_int.inf 2004-08-04 05:00 18,736 a——- c:\windows\inf\wdma_via.inf 2004-08-04 05:00 63,294 a——- c:\windows\inf\wdma_ali.inf 2004-08-04 04:59 111,115 a——- c:\windows\inf\netfxocm.inf 2004-07-18 05:55 50,067 a——- c:\windows\inf\mdmcxsf2.inf 2004-07-18 05:54 1,744,202 a——- c:\windows\inf\system.adm 2004-07-18 05:54 10,865 a——- c:\windows\inf\nvts.inf 2004-07-17 18:45 6,769 a——- c:\windows\inf\wmfsdk.inf 2004-07-17 18:42 40,282 a——- c:\windows\inf\conf.adm 2004-07-17 18:41 18,516 a——- c:\windows\inf\inetset.adm 2004-07-17 18:40 6,140 a——- c:\windows\inf\qmgr.inf 2004-07-17 18:40 7,946 a——- c:\windows\inf\fp40ext.inf 2004-07-17 18:37 43,229 a——- c:\windows\inf\setupqry.inf 2004-07-06 09:28 44,229 a——- c:\windows\inf\oem9.inf 2004-06-16 11:45 28,037 a——- c:\windows\inf\oem6.inf 2004-05-07 10:43 44,236 a——- c:\windows\inf\oem3.inf 2004-05-04 17:31 36,680 a——- c:\windows\inf\oem0.inf 2004-04-05 16:19 4,824 a——- c:\windows\inf\oem1.inf 2004-03-11 10:21 3,891 a——- c:\windows\inf\oem5.inf 2004-03-11 10:21 3,548 a——- c:\windows\inf\oem4.inf 2004-03-11 10:21 3,627 a——- c:\windows\inf\oem2.inf 2004-02-04 19:26 2,963 a——- c:\windows\inf\oem7.inf 2004-02-04 19:26 3,845 a——- c:\windows\inf\oem8.inf 2003-07-18 14:42 39,132 a——- c:\windows\inf\AER_1040.ADM 2003-07-18 14:37 38,066 a——- c:\windows\inf\AER_3082.ADM 2003-07-12 02:55 23,748 a——- c:\windows\inf\AER_2052.ADM 2003-07-12 02:52 26,616 a——- c:\windows\inf\AER_1042.ADM 2003-07-12 02:48 23,282 a——- c:\windows\inf\AER_1028.ADM 2003-07-12 02:43 26,292 a——- c:\windows\inf\AER_1041.ADM 2003-07-12 02:40 39,516 a——- c:\windows\inf\AER_1031.ADM 2003-01-13 16:11 39,366 a——- c:\windows\inf\AER_1036.ADM 2002-10-10 08:44 34,066 a——- c:\windows\inf\AER_1033.ADM 2001-08-17 21:26 8,860 a——- c:\windows\inf\games.inf 2001-08-17 21:26 8,842 a——- c:\windows\inf\communic.inf 2001-08-17 21:26 7,316 a——- c:\windows\inf\optional.inf 2001-08-17 21:26 6,324 a——- c:\windows\inf\igames.inf 2001-08-17 21:26 5,839 a——- c:\windows\inf\wbemoc.inf 2001-08-17 21:26 3,551 a——- c:\windows\inf\pinball.inf 2001-08-17 20:28 48,940 a——- c:\windows\inf\mdmxircc.inf 2001-08-17 20:28 46,837 a——- c:\windows\inf\mdmxirmp.inf 2001-08-17 20:28 57,364 a——- c:\windows\inf\mdmusrgl.inf 2001-08-17 20:28 38,179 a——- c:\windows\inf\mdmpctel.inf 2001-08-17 20:28 29,028 a——- c:\windows\inf\mdmosice.inf 2001-08-17 20:28 49,556 a——- c:\windows\inf\mdmltsft.inf 2001-08-17 20:28 48,980 a——- c:\windows\inf\mdmltleo.inf 2001-08-17 20:28 13,982 a——- c:\windows\inf\mdmsgsmu.inf 2001-08-17 20:28 1,544,841 a——- c:\windows\inf\mdmrpciw.inf 2001-08-17 20:28 43,975 a——- c:\windows\inf\mdmess.inf 2001-08-17 20:28 620,730 a——- c:\windows\inf\mdmcxsft.inf 2001-08-17 20:28 48,170 a——- c:\windows\inf\mdmbcmsm.inf 2001-08-17 20:27 55,764 a——- c:\windows\inf\mdm3mini.inf 2001-08-17 20:27 30,934 a——- c:\windows\inf\mdm656n5.inf 2001-08-17 19:56 2,447 a——- c:\windows\inf\ndisuio.inf 2001-08-17 19:18 7,611 a——- c:\windows\inf\mpsstln.inf 2001-08-17 19:18 2,565 a——- c:\windows\inf\stalport.inf 2001-08-17 19:17 9,856 a——- c:\windows\inf\spxports.inf 2001-08-17 19:17 14,782 a——- c:\windows\inf\spx.inf 2001-08-17 19:17 7,450 a——- c:\windows\inf\asynceqn.inf 2001-08-17 19:17 3,207 a——- c:\windows\inf\eqnport.inf 2001-08-17 19:17 4,671 a——- c:\windows\inf\digirp.inf 2001-08-17 19:17 3,999 a——- c:\windows\inf\digirprt.inf 2001-08-17 19:17 19,125 a——- c:\windows\inf\mdmdigi.inf 2001-08-17 19:17 14,981 a——- c:\windows\inf\dgasync.inf 2001-08-17 19:17 14,952 a——- c:\windows\inf\dgaport.inf 2001-08-17 19:16 7,159 a——- c:\windows\inf\ctmaport.inf 2001-08-17 19:16 5,095 a——- c:\windows\inf\netctmrk.inf 2001-08-17 19:14 6,520 a——- c:\windows\inf\nettiger.inf 2001-08-17 19:12 4,637 a——- c:\windows\inf\nettb155.inf 2001-08-17 19:11 8,339 a——- c:\windows\inf\netibm2.inf 2001-08-17 19:10 7,072 a——- c:\windows\inf\netel90a.inf 2001-08-17 19:08 2,597 a——- c:\windows\inf\netepvcm.inf 2001-08-17 19:08 2,134 a——- c:\windows\inf\netepvcp.inf 2001-08-17 19:08 2,300 a——- c:\windows\inf\net1394.inf 2001-08-17 19:03 4,673 a——- c:\windows\inf\mfsocket.inf 2001-08-17 19:02 16,592 a——- c:\windows\inf\dvd.inf 2001-08-17 19:02 3,816 a——- c:\windows\inf\dshowext.inf 2001-08-17 19:02 2,243 a——- c:\windows\inf\dot4prt.inf 2001-08-17 19:02 42,416 a——- c:\windows\inf\dot4.inf 2001-08-17 19:02 33,702 a——- c:\windows\inf\display.inf 2001-08-17 19:02 11,373 a——- c:\windows\inf\dimaps.inf 2001-08-17 19:02 2,139 a——- c:\windows\inf\dfrg.inf 2001-08-17 19:02 7,813 a——- c:\windows\inf\cyzport.inf 2001-08-17 19:02 4,627 a——- c:\windows\inf\cyyport.inf 2001-08-17 19:02 2,589 a——- c:\windows\inf\cyclom-y.inf 2001-08-17 19:02 2,418 a——- c:\windows\inf\cyclad-z.inf 2001-08-17 19:02 2,186 a——- c:\windows\inf\certclas.inf 2001-08-17 18:58 3,651 a——- c:\windows\inf\fsvga.inf 2001-08-17 18:58 24,491 a——- c:\windows\inf\netnf3.inf 2001-08-17 18:57 4,898 a——- c:\windows\inf\viafir2k.inf 2001-08-17 18:57 4,701 a——- c:\windows\inf\irmk7w2k.inf 2001-08-17 18:57 4,228 a——- c:\windows\inf\irdaalif.inf 2001-08-17 18:57 3,711 a——- c:\windows\inf\irstusb.inf 2001-08-17 18:55 86,985 a——- c:\windows\inf\wdma_aur.inf 2001-08-17 18:55 16,408 a——- c:\windows\inf\wdma_azt.inf 2001-08-17 18:55 267,903 a——- c:\windows\inf\wdma10k1.inf 2001-08-17 18:55 23,685 a——- c:\windows\inf\wdmaudio.inf 2001-08-17 18:55 3,581 a——- c:\windows\inf\wave.inf 2001-08-02 00:21 4,177 a——- c:\windows\inf\nv3.inf 2001-07-30 23:47 25,633 a——- c:\windows\inf\atim128.inf 2001-07-26 23:19 14,340 a——- c:\windows\inf\tshoot.inf 2001-07-22 01:58 4,422 a——- c:\windows\inf\perm3.inf 2001-07-22 01:58 6,131 a——- c:\windows\inf\perm2.inf 2001-07-22 01:58 60,593 a——- c:\windows\inf\monitor5.inf 2001-07-22 01:58 52,670 a——- c:\windows\inf\monitor8.inf 2001-07-22 01:58 45,673 a——- c:\windows\inf\monitor6.inf 2001-07-22 01:58 41,883 a——- c:\windows\inf\monitor3.inf 2001-07-22 01:58 40,439 a——- c:\windows\inf\monitor7.inf 2001-07-22 01:58 40,054 a——- c:\windows\inf\monitor4.inf 2001-07-22 01:58 52,117 a——- c:\windows\inf\monitor.inf 2001-07-22 01:58 47,730 a——- c:\windows\inf\monitor2.inf 2001-07-22 01:41 11,209 a——- c:\windows\inf\neo20xx.inf 2001-07-22 01:41 3,322 a——- c:\windows\inf\mgau.inf 2001-07-22 01:41 3,085 a——- c:\windows\inf\mtxvideo.inf 2001-07-22 01:41 3,874 a——- c:\windows\inf\g200.inf 2001-07-22 01:41 2,773 a——- c:\windows\inf\i740nt5.inf 2001-07-22 01:40 29,798 a——- c:\windows\inf\atividin.inf 2001-07-22 01:40 3,046 a——- c:\windows\inf\atirage3.inf 2001-07-22 01:40 32,342 a——- c:\windows\inf\atimpab.inf 2001-07-22 01:39 17,675 a——- c:\windows\inf\3dfxvs2k.inf 2001-07-22 01:39 3,149 a——- c:\windows\inf\banshee.inf 2001-07-22 01:32 7,072 a——- c:\windows\inf\netel980.inf 2001-07-21 21:32 6,823 a——- c:\windows\inf\inetcorp.adm 2001-07-21 21:32 2,762 a——- c:\windows\inf\iereset.inf 2001-07-21 21:15 8,463 a——- c:\windows\inf\corelist.inf 2004-08-04 08:00 48,680 ac-sh— c:\windows\winnt.bmp 2004-08-04 08:00 48,680 ac-sh— c:\windows\winnt256.bmp 2008-01-24 15:29 227 a–shr– c:\windows\assembly\Desktop.ini 2004-08-09 13:32 67 ac-sh— c:\windows\fonts\desktop.ini 2004-08-04 08:00 2,737,914 ac-shr– c:\windows\pchealth\helpctr\packagestore\instance_Professional_32_1033.cab 2004-08-09 13:32 727 ac-shr– c:\windows\pchealth\helpctr\packagestore\package_1.cab 2004-08-09 13:32 19,854 ac-shr– c:\windows\pchealth\helpctr\packagestore\package_2.cab 2004-08-09 13:32 244,933 ac-shr– c:\windows\pchealth\helpctr\packagestore\package_3.cab 2004-08-04 08:00 7,068 ac-shr– c:\windows\pchealth\helpctr\packagestore\package_4.cab 2008-01-24 15:33 68,327 a–shr– c:\windows\pchealth\helpctr\packagestore\package_5.cab 2008-01-24 15:33 305,145 a–shr– c:\windows\pchealth\helpctr\packagestore\package_6.cab 2008-01-24 15:34 7,079 a–shr– c:\windows\pchealth\helpctr\packagestore\package_7.cab 2008-01-24 15:34 59,928 a–shr– c:\windows\pchealth\helpctr\packagestore\package_8.cab 2004-08-09 06:21 62 a–sh— c:\windows\system32\config\systemprofile\application data\desktop.ini 2004-08-09 13:41 2,570 a–sh— c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\Desktop.htt 2004-08-09 13:42 119 a–sh— c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\quick launch\desktop.ini 2004-08-09 13:42 122 a–sh— c:\windows\system32\config\systemprofile\favorites\Desktop.ini 2008-01-24 15:27 62 a–sh— c:\windows\system32\config\systemprofile\local settings\desktop.ini 2008-01-24 15:38 113 —sh— c:\windows\system32\config\systemprofile\local settings\history\desktop.ini 2008-01-24 15:38 113 —sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\desktop.ini 2008-01-24 15:38 67 —sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\desktop.ini 2008-01-24 15:38 67 —sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\desktop.ini 2008-01-24 15:38 67 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\d4zbshqv\desktop.ini 2008-01-24 15:38 67 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\dtcd8uvn\desktop.ini 2008-01-24 15:38 67 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\qk37zt06\desktop.ini 2008-01-24 15:38 67 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\xsn0aq3m\desktop.ini 2004-08-09 13:42 84 a–sh— c:\windows\system32\config\systemprofile\my documents\desktop.ini 2004-08-09 13:42 189 a–sh— c:\windows\system32\config\systemprofile\my documents\my music\Desktop.ini 2004-08-09 13:42 191 a–sh— c:\windows\system32\config\systemprofile\my documents\my pictures\Desktop.ini 2004-08-09 13:42 150 a–sh— c:\windows\system32\config\systemprofile\recent\Desktop.ini 2004-08-09 13:31 181 a–sh— c:\windows\system32\config\systemprofile\sendto\desktop.ini 2004-08-09 06:21 62 a–sh— c:\windows\system32\config\systemprofile\start menu\desktop.ini 2004-08-09 13:42 234 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\desktop.ini 2004-08-09 13:41 542 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\accessories\desktop.ini 2004-08-09 13:34 348 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\accessories\accessibility\desktop.ini 2004-08-09 13:34 84 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\accessories\entertainment\desktop.ini 2004-08-09 13:34 84 a–sh— c:\windows\system32\config\systemprofile\start menu\programs\startup\desktop.ini 2008-01-24 15:35 1,663 a–shr– c:\windows\system32\drivers\103C_HP_BPC_HP Compaq dc7100 SFF(PL216E)_YB_0CBD_QCZC509_EU_46_I097Ch_SHP_V_B786C1 v01.05_T040616_WXP2_L409_M504_J40_7Intel_8Pentium 4_92.8_#080124_N14E41677_(PL216E)_X_CD4_Z_2_G80862582_OSAMSUNG CD-ROM SC-148A.MRK 2004-08-04 08:00 19,528 —shr– c:\windows\system32\restore\filelist.xml ============= FINISH: 20:31:05.87 =============== System Look: SystemLook v1.0bb by jpshortstuff Log created at 20:31 on 09/02/2009 by Administrator ========== reg ========== [HKEY_LOCAL_MACHINE\Software\Mozilla] (No values found) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox] (No values found) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox] "CurrentVersion"="3.0.6 (en-GB)" @="1.9.0.6" [HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\3.0.6 (en-GB)] @="3.0.6 (en-GB)" [HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\3.0.6 (en-GB)\Main] "Install Directory"="C:\Program Files\Mozilla Firefox" "PathToExe"="C:\Program Files\Mozilla Firefox\firefox.exe" "Program Folder Path"="C:\Documents and Settings\All Users\Start Menu\Programs\" "Start Menu Folder"="Mozilla Firefox" [HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox\3.0.6 (en-GB)\Uninstall] "Create Start Menu Shortcut"= 0x00000001 (1) "Description"="Mozilla Firefox (3.0.6)" "Uninstall Log Folder"="C:\Program Files\Mozilla Firefox\uninstall" [HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 3.0.6] "GeckoVer"="1.9.0.6" [HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 3.0.6\bin] "PathToExe"="C:\Program Files\Mozilla Firefox\firefox.exe" [HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox 3.0.6\extensions] "Components"="C:\Program Files\Mozilla Firefox\components" "Plugins"="C:\Program Files\Mozilla Firefox\plugins" ========== dir ========== c:\docume~1\admini~1\applic~1\mozilla\firefox\pro - Unable to find folder. -=End Of File=-
Hi,

XUL Cache
Did you install this extension yourself? If not, remove it. If so, disable it, restart Firefox and see if that stops the redirects.

Thanks.
Can you see an extension called Default on your list? If so, try disabling/removing that.

Since Safe Mode works fine, it must be a problem with an Add-On or extension.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI