DDS (Ver_10-03-17.01)
Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 1/2/2009 11:48:00 PM
System Uptime: 5/22/2010 8:39:32 PM (0 hours ago)
Motherboard: FIC | | Everex StepNote Series
Processor: Genuine Intel® CPU T2080 @ 1.73GHz | mPGA 479M | 1733/533mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 93 GiB total, 67.19 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Bejeweled Blitz
Blingee Toolbar
CVS Photo Editor Plus
DriverAgent by eSupport.com
Facebook Plug-In
HDAUDIO Soft Data Fax Modem with SmartCP
Highlight Viewer (Windows Live Toolbar)
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Java Auto Updater
Java 6 Update 20
Jewel Quest Solitaire
Junk Mail filter update
Mahjongg Artifacts 2
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.6.3)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
PerfectDisk 2008 Professional
Platform
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB978380)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB978382)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB980470)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Skype web features
Skype™ 4.1
Smart Menus (Windows Live Toolbar)
The Weather Channel Desktop 6
Try Corel Snapfire muvee autoProducer add on
Ultimate Extras sounds from Microsoft® Tinker™
Update for 2007 Microsoft Office System (KB967642)
Update for 2007 Microsoft Office System (KB981715)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb981433)
VIA Chrome9 HC IGP Family Display
VIA Platform Device Manager
VIA Rhine Family Fast Ethernet Adapter
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sync
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Upload Tool
Windows Live Writer
Windows Sound Schemes
WinRAR archiver
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
Zuma Deluxe
==== Event Viewer Messages From Past Week ========
5/22/2010 8:41:00 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Multimedia Class Scheduler service to connect.
5/22/2010 8:41:00 PM, Error: Service Control Manager [7001] - The Windows Audio service depends on the Multimedia Class Scheduler service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
5/22/2010 8:41:00 PM, Error: Service Control Manager [7000] - The Multimedia Class Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
5/22/2010 8:41:00 PM, Error: Service Control Manager [7000] - The aswFsBlk service failed to start due to the following error: The system cannot find the file specified.
5/22/2010 12:13:56 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
5/21/2010 5:07:46 PM, Error: Service Control Manager [7030] - The Eset Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
5/20/2010 8:07:33 PM, Error: EventLog [6008] - The previous system shutdown at 8:05:35 PM on 5/20/2010 was unexpected.
5/20/2010 7:51:35 PM, Error: EventLog [6008] - The previous system shutdown at 7:50:00 PM on 5/20/2010 was unexpected.
5/20/2010 3:15:42 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: aswSP aswTdi easdrv spldr Wanarpv6
5/20/2010 3:15:42 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
5/20/2010 3:15:34 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
5/20/2010 3:15:19 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
5/20/2010 3:15:14 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
5/20/2010 3:15:03 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
5/20/2010 3:14:17 PM, Error: EventLog [6008] - The previous system shutdown at 3:12:03 PM on 5/20/2010 was unexpected.
5/20/2010 3:10:22 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
5/20/2010 3:05:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: easdrv spldr Wanarpv6
5/20/2010 3:04:33 PM, Error: EventLog [6008] - The previous system shutdown at 3:01:49 PM on 5/20/2010 was unexpected.
5/20/2010 11:38:50 PM, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
5/17/2010 4:05:34 PM, Error: EventLog [6008] - The previous system shutdown at 11:36:43 AM on 5/17/2010 was unexpected.
5/15/2010 2:54:29 PM, Error: EventLog [6008] - The previous system shutdown at 11:09:45 AM on 5/15/2010 was unexpected.
==== End Of File ===========================
DDS (Ver_10-03-17.01) - NTFSx86
Run by Olimpia at 20:45:26.02 on Sat 05/22/2010
Internet Explorer: 8.0.6001.18904
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.958.215 [GMT -4:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Windows\system32\taskeng.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PSIService.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\System32\S3Funkey.exe
C:\Windows\System32\s3trayp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
svchost.exe "C:\Windows\system32\apilogeng.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchFilterHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Users\Olimpia\Downloads\dds.scr
============== Pseudo HJT Report ===============
uSearch Page =
uStart Page = hxxp://www.google.com/
uSearch Bar =
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://it.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://it.search.yahoo.com
mSearch Page = hxxp://it.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://it.search.yahoo.com
uURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: {f0626a63-410b-45e2-99a1-3f2475b2d695} - Search Assistant
BHO: BlingeeTb Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\blingee plus\blingeetb.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Blingee Toolbar: {d1121fe0-0145-44c9-aa35-72071ac20a9b} - c:\program files\blingee plus\blingeetb.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DW6]
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [S3Funkey] S3Funkey.exe
mRun: [S3Trayp] S3trayp.exe -chkautorun
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Corel Photo Downloader] c:\program files\cvs\cvs photo editor plus\Corel Photo Downloader.exe
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-system: DisableTaskMgr = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: facebook.com\www
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {7070D8E0-650A-46b3-B03C-9497582E6A74} - %SystemRoot%\system32\soundschemes.exe /AddRegistration
mASetup: {B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24} - %SystemRoot%\system32\soundschemes2.exe /AddRegistration
================= FIREFOX ===================
FF - ProfilePath - c:\users\olimpia\appdata\roaming\mozilla\firefox\profiles\nk6e7upi.default\
FF - component: c:\program files\microsoft\search enhancement pack\search helper\firefoxextension\searchhelperextension\components\SEPsearchhelperff.dll
FF - component: c:\users\olimpia\appdata\roaming\mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\components\FFTextLinks.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\olimpia\appdata\roaming\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\users\olimpia\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2009-1-3 17920]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-5-20 164048]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-5-20 51792]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-20 40384]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2008-1-20 21504]
R2 PD91Agent;PD91Agent;c:\program files\raxco\perfectdisk2008\PD91Agent.exe [2008-9-9 693512]
R3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;c:\windows\system32\drivers\fetnd6v.sys [2008-12-4 43520]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\VTGKModeDX32.sys [2009-1-12 814592]
S2 DnscacheDPS;DNS Client DnscacheDPS;c:\windows\system32\adsldpz.exe srv --> c:\windows\system32\adsldpz.exe srv [?]
S2 gpsvcRpcSs;Group Policy Client gpsvcRpcSs;c:\windows\system32\accessibilitycplq.exe srv --> c:\windows\system32\accessibilitycplq.exe srv [?]
S2 hidservSLUINotify;Human Interface Device Access hidservSLUINotify;c:\windows\system32\appendo.exe srv --> c:\windows\system32\appendo.exe srv [?]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-20 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-20 40384]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-11-6 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 PD91Engine;PD91Engine;c:\program files\raxco\perfectdisk2008\PD91Engine.exe [2008-9-9 906504]
=============== Created Last 30 ================
2010-05-23 00:43:17 0 ----a-w- c:\users\olimpia\defogger_reenable
2010-05-21 20:38:25 0 d-----w- c:\program files\Trend Micro
2010-05-21 20:25:57 232 ----a-w- c:\windows\reimage.ini
2010-05-21 03:42:16 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-21 03:37:36 0 d-----w- c:\programdata\Lavasoft
2010-05-21 00:35:59 0 d-----w- c:\windows\system32\eu-ES
2010-05-21 00:35:59 0 d-----w- c:\windows\system32\ca-ES
2010-05-21 00:35:54 0 d-----w- c:\windows\system32\vi-VN
2010-05-20 23:51:35 155154022 ----a-w- c:\windows\MEMORY.DMP
2010-05-20 21:56:59 0 d-----w- c:\users\olimpia\appdata\roaming\Malwarebytes
2010-05-20 19:11:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-20 19:11:37 0 d-----w- c:\programdata\Malwarebytes
2010-05-20 19:11:36 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-20 19:11:36 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-20 19:10:25 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-05-20 19:10:12 0 d-----w- c:\programdata\Alwil Software
2010-05-20 19:04:39 1048576 --sha-w- c:\users\olimpia\NTUSER.DAT{0f69446c-6a70-11db-8eb3-985e31beb686}.TxR.2.regtrans-ms
2010-05-20 19:04:39 1048576 --sha-w- c:\users\olimpia\NTUSER.DAT{0f69446c-6a70-11db-8eb3-985e31beb686}.TxR.1.regtrans-ms
2010-05-20 19:04:39 1048576 --sha-w- c:\users\olimpia\NTUSER.DAT{0f69446c-6a70-11db-8eb3-985e31beb686}.TxR.0.regtrans-ms
2010-05-20 19:04:38 65536 --sha-w- c:\users\olimpia\NTUSER.DAT{0f69446c-6a70-11db-8eb3-985e31beb686}.TxR.blf
2010-05-20 00:10:37 74752 ------w- c:\windows\system32\aedc.sys
2010-05-19 11:52:02 0 ----a-w- c:\windows\system32\4597.exe
2010-05-19 11:32:01 0 ----a-w- c:\windows\system32\15116.exe
2010-05-19 11:12:01 0 ----a-w- c:\windows\system32\30294.exe
2010-05-19 10:52:00 0 ----a-w- c:\windows\system32\20687.exe
2010-05-19 10:32:00 0 ----a-w- c:\windows\system32\23025.exe
2010-05-19 10:12:00 0 ----a-w- c:\windows\system32\11798.exe
2010-05-19 09:51:59 0 ----a-w- c:\windows\system32\13499.exe
2010-05-19 09:31:59 0 ----a-w- c:\windows\system32\12419.exe
2010-05-19 09:11:58 0 ----a-w- c:\windows\system32\17596.exe
2010-05-19 08:51:58 0 ----a-w- c:\windows\system32\21819.exe
2010-05-19 08:31:57 0 ----a-w- c:\windows\system32\9235.exe
2010-05-19 08:11:57 0 ----a-w- c:\windows\system32\9903.exe
2010-05-19 07:51:56 0 ----a-w- c:\windows\system32\2957.exe
2010-05-18 22:29:51 0 ----a-w- c:\windows\system32\23727.exe
2010-05-18 22:09:51 0 ----a-w- c:\windows\system32\31288.exe
2010-05-18 21:49:50 0 ----a-w- c:\windows\system32\11741.exe
2010-05-18 21:29:50 0 ----a-w- c:\windows\system32\10082.exe
2010-05-18 21:09:50 0 ----a-w- c:\windows\system32\5234.exe
2010-05-18 20:49:49 0 ----a-w- c:\windows\system32\11966.exe
2010-05-18 20:29:48 0 ----a-w- c:\windows\system32\9945.exe
2010-05-18 20:09:48 0 ----a-w- c:\windows\system32\2013.exe
2010-05-18 09:05:39 25088 ----a-w- c:\windows\system32\0042.DLL
2010-05-17 07:26:08 0 d-----w- c:\programdata\Sun
2010-05-17 07:25:31 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-17 01:58:13 0 ----a-w- c:\windows\system32\5436.exe
2010-05-17 01:38:13 0 ----a-w- c:\windows\system32\4827.exe
2010-05-17 01:18:12 0 ----a-w- c:\windows\system32\11942.exe
2010-05-17 00:58:12 0 ----a-w- c:\windows\system32\2995.exe
2010-05-17 00:38:11 0 ----a-w- c:\windows\system32\491.exe
2010-05-17 00:18:11 0 ----a-w- c:\windows\system32\9961.exe
2010-05-16 23:58:11 0 ----a-w- c:\windows\system32\16827.exe
2010-05-16 23:38:10 0 ----a-w- c:\windows\system32\23281.exe
2010-05-16 23:18:10 0 ----a-w- c:\windows\system32\28145.exe
2010-05-16 22:58:10 0 ----a-w- c:\windows\system32\5705.exe
2010-05-16 22:38:09 0 ----a-w- c:\windows\system32\24464.exe
2010-05-16 19:37:31 778 ----a-w- C:\Security essentials 2010.lnk
2010-05-13 00:06:05 0 d-----w- C:\Poker Application
2010-05-12 23:51:29 0 d-----w- c:\program files\PokerStars.NET
2010-05-11 14:02:08 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-04-30 15:23:33 10 ----a-w- c:\windows\popcinfo.dat
2010-04-30 15:06:17 0 d-----w- c:\programdata\Oberon Media
2010-04-27 10:57:52 166400 ----a-w- c:\windows\system32\o.dat
2010-04-26 14:23:23 0 ----a-w- c:\windows\system32\ACWb.sys
==================== Find3M ====================
2010-05-21 21:08:51 86016 ----a-w- c:\windows\inf\infstrng.dat
2010-05-21 21:08:51 86016 ----a-w- c:\windows\inf\infstor.dat
2010-05-21 21:08:51 51200 ----a-w- c:\windows\inf\infpub.dat
2010-05-21 00:35:42 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-05-21 00:24:20 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2010-05-16 02:00:26 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-04-17 11:48:33 86897 --sha-w- c:\windows\system32\apphelpe.sys
2010-03-05 14:01:02 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-24 14:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33:45 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33:45 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55:36 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2008-01-21 02:41:56 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:40:37 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:40:37 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-12-04 22:40:01 8 --sh--r- c:\windows\system32\7BF5025C67.sys
============= FINISH: 20:48:30.87 ===============
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-05-22 21:41:01
Windows 6.0.6002 Service Pack 2
Running: rpc8plec.exe; Driver: C:\Users\Olimpia\AppData\Local\Temp\uxldyfoc.sys
---- Kernel code sections - GMER 1.0.15 ----
? C:\Windows\system32\aedc.sys The process cannot access the file because it is being used by another process.
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\wuauclt.exe[696] ntdll.dll!NtProtectVirtualMemory 777E4D34 5 Bytes JMP 0030000A
.text C:\Windows\system32\wuauclt.exe[696] ntdll.dll!NtWriteVirtualMemory 777E5674 5 Bytes JMP 0031000A
.text C:\Windows\system32\wuauclt.exe[696] ntdll.dll!KiUserExceptionDispatcher 777E5DC8 5 Bytes JMP 001A000A
.text C:\Windows\system32\svchost.exe[1056] ntdll.dll!NtProtectVirtualMemory 777E4D34 5 Bytes JMP 0082000A
.text C:\Windows\system32\svchost.exe[1056] ntdll.dll!NtWriteVirtualMemory 777E5674 5 Bytes JMP 0083000A
.text C:\Windows\system32\svchost.exe[1056] ntdll.dll!KiUserExceptionDispatcher 777E5DC8 5 Bytes JMP 0081000A
.text C:\Windows\system32\svchost.exe[1056] ole32.dll!CoCreateInstance 766C9EA6 5 Bytes JMP 008A000A
.text C:\Windows\Explorer.EXE[1748] ntdll.dll!NtProtectVirtualMemory 777E4D34 5 Bytes JMP 007E000A
.text C:\Windows\Explorer.EXE[1748] ntdll.dll!NtWriteVirtualMemory 777E5674 3 Bytes JMP 007F000A
.text C:\Windows\Explorer.EXE[1748] ntdll.dll!NtWriteVirtualMemory + 4 777E5678 1 Byte [89]
.text C:\Windows\Explorer.EXE[1748] ntdll.dll!KiUserExceptionDispatcher 777E5DC8 5 Bytes JMP 007D000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1848] ntdll.dll!NtProtectVirtualMemory 777E4D34 5 Bytes JMP 01B9000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1848] ntdll.dll!NtWriteVirtualMemory 777E5674 5 Bytes JMP 01BA000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1848] ntdll.dll!KiUserExceptionDispatcher 777E5DC8 5 Bytes JMP 009F000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp aedc.sys
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----