DDS.TXT
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Ron Drever at 19:11:32 on 2012-08-19
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.2046.1243 [GMT 10:00]
.
AV: Total Defense Anti-Virus Plus *Enabled/Updated* {6B98D35F-BB76-41C0-876B-A50645ED099A}
AV: CA Anti-Virus *Enabled/Updated* {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: AVG Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\Anti-Virus Plus\caamsvc.exe
C:\Program Files\CA\CA Internet Security Suite\Anti-Virus Plus\isafe.exe
C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\lxdicoms.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INGAUSTRALIA\Binn\sqlservr.exe
C:\MSDE\Binn\MSSQL$IWBDB\Binn\sqlservr.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\WINDOWS\LOGI_MWX.EXE
C:\WINDOWS\Twain_32\Fjscan32\SOP\FtLnSOP.exe
C:\Program Files\iSync\Client\iSchedule.exe
C:\WINDOWS\Twain_32\Fjscan32\FTPWREVT\FTPWREVT.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Citrix\ICA Client\redirector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Share Wealth Systems\DataUpdater1\bin\PDU.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\explorer.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com.au/
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10615&gct=&gc=1&q=%s
uURLSearchHooks: WiseConvert Toolbar: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - c:\program files\wiseconvert\prxtbWise.dll
mWinlogon: Userinit=userinit.exe,
BHO: PE_IE_Helper Class: {0941c58f-e461-4e03-bd7d-44c27392ade1} - c:\program files\ibm\workplace forms\viewer\2.7\PEhelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile: {d5233fcd-d258-4903-89b8-fb1568e7413d} - mscoree.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: WiseConvert Toolbar: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - c:\program files\wiseconvert\prxtbWise.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: WiseConvert Toolbar: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - c:\program files\wiseconvert\prxtbWise.dll
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [PDU] c:\program files\share wealth systems\dataupdater1\bin\PDU.exe ONWINDOWSSTART
uRun: [Bomgar_Cleanup_ZD1731207819967] cmd.exe /C rd /S /Q "c:\documents and settings\all users.windows\application data\iyogi-scc-4fcd82f9" & reg delete hkcu\software\microsoft\windows\currentversion\Run /v Bomgar_Cleanup_ZD1731207819967 /f
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Bomgar_Cleanup_ZD71299217532] cmd.exe /C rd /S /Q "c:\documents and settings\all users.windows\application data\iyogi-scc-500df585" & reg delete hkcu\software\microsoft\windows\currentversion\Run /v Bomgar_Cleanup_ZD71299217532 /f
mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Logitech Utility] LOGI_MWX.EXE
mRun: [FtLnSOP_setup] c:\windows\twain_32\fjscan32\sop\FtLnSOP.exe
mRun: [iSchedule] c:\program files\isync\client\iSchedule.exe /minimise
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [FTPWRENV] c:\windows\twain_32\fjscan32\ftpwrevt\FTPWREVT.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\redirector.exe" /startup
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\rondre~1.ron\startm~1\programs\startup\seagat~1.lnk - c:\documents and settings\ron drever.ronsnewdesktop\application data\leadertech\powerregister\Seagate Product Registration.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: Search the Web
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: amp.com.au\powerterm
Trusted Zone: clublinks.com.au\www
Trusted Zone: gio.com.au\www.cisme
Trusted Zone: microsoft.com\www.update
Trusted Zone: youtube.com\www
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {070DC617-E3B7-468B-A29C-D4E84FAE938C} - hxxp://utilities.pcpitstop.com/pctuneup2/controls/pctuneup.cab
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1342481658500
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228174782593
DPF: {7EC816D4-6FC3-4C58-A7DA-A770EE461602} - hxxps://powerterm.amp.com.au/WebConnect/windows/ptdownloader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.2
TCP: Interfaces\{C7E224D4-7D91-471F-9C11-366EF54E2048} : DhcpNameServer = 192.168.0.2
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
AppInit_DLLs: c:\progra~1\citrix\icacli~1\RSHook.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 relog_ap nwprovau
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 12404636;12404636;c:\windows\system32\drivers\12404636.sys [2012-7-24 133208]
R0 28447009;28447009;c:\windows\system32\drivers\28447009.sys [2012-7-26 133208]
R0 51584566;51584566;c:\windows\system32\drivers\51584566.sys [2012-7-24 133208]
R0 94034860;94034860;c:\windows\system32\drivers\94034860.sys [2012-8-2 133208]
R0 KmxAMRT;KmxAMRT;c:\windows\system32\drivers\KmxAMRT.sys [2011-10-27 170064]
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2011-9-6 123984]
R1 0554340drv;0554340drv;c:\windows\system32\drivers\0554340drv.sys [2012-7-24 475736]
R1 1069827drv;1069827drv;c:\windows\system32\drivers\1069827drv.sys [2012-7-24 475736]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2012-5-17 67960]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2011-10-26 83536]
R2 CAAMSvc;CAAMSvc;c:\program files\ca\ca internet security suite\anti-virus plus\caamsvc.exe [2012-6-5 210248]
R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\anti-virus plus\isafe.exe [2012-6-5 224304]
R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\ca\ca internet security suite\ccschedulersvc.exe [2012-6-5 207920]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2011-4-28 10448]
R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service --> c:\windows\system32\lxdicoms.exe -service [?]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\microsoft sql server\mssql.2\mssql\binn\sqlservr.exe [2010-12-10 29293408]
R2 MSSQL$INGAUSTRALIA;MSSQL$INGAUSTRALIA;c:\program files\microsoft sql server\mssql$ingaustralia\binn\sqlservr.exe -singaustralia --> c:\program files\microsoft sql server\mssql$ingaustralia\binn\sqlservr.exe -sINGAUSTRALIA [?]
R2 MSSQL$IWBDB;MSSQL$IWBDB;c:\msde\binn\mssql$iwbdb\binn\sqlservr.exe -siwbdb --> c:\msde\binn\mssql$iwbdb\binn\sqlservr.exe -sIWBDB [?]
R2 MSSQL$VISIPLAN;SQL Server (VISIPLAN);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2010-12-10 29293408]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-26 35088]
R2 UmxEngine;TM Engine;c:\program files\ca\sharedcomponents\tmengine\UmxEngine.exe [2011-4-4 662096]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2011-9-6 331344]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S3 16614;16614;c:\windows\system32\drivers\16614 [2012-3-2 9072]
S3 20222;20222;c:\windows\system32\drivers\20222 [2011-7-22 9072]
S3 8536;8536;c:\windows\system32\drivers\8536 [2012-6-13 9072]
S3 ACT! Scheduler;ACT! Scheduler;c:\program files\act\act for windows\Act.Scheduler.exe [2010-1-20 81920]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-7-16 250056]
S3 AIPS;Arp Intelligent Protection Service;c:\program files\netcutdefender\services\aips.exe [2012-7-23 262144]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-1-28 1691480]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2012-5-19 30312]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2012-4-30 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2012-4-30 8456]
S3 FJTWMKSV;FJTWMKSV;c:\windows\twain_32\fjscan32\FJTWMKSV.exe [2009-2-25 36864]
S3 GEST Service;GEST Service for program management.;c:\program files\gigabyte\energysaver\GSvr.exe [2008-9-19 80392]
S3 GPSUpdaterService;GPSUpdaterService;c:\windows\system32\GPSUpdaterService.exe [2012-4-5 157184]
S3 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-19 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-12-19 135664]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys --> c:\windows\system32\drivers\massfilter.sys [?]
S3 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\total defense\PCPitstopScheduleService.exe [2012-6-27 91816]
S3 PenCommService;Livescribe Pulse Smartpen Service;c:\program files\common files\livescribe\pencomm\PenCommService.exe [2011-10-28 470528]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
S3 PulseUsb;Livescribe Smartpen USB Driver;c:\windows\system32\drivers\PulseUsb.sys [2012-8-1 20480]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2012-7-17 332928]
S3 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2012-7-25 1326176]
S3 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2012-7-25 681056]
S3 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 SQLAgent$INGAUSTRALIA;SQLAgent$INGAUSTRALIA;c:\program files\microsoft sql server\mssql$ingaustralia\binn\sqlagent.exe -i ingaustralia --> c:\program files\microsoft sql server\mssql$ingaustralia\binn\sqlagent.EXE -i INGAUSTRALIA [?]
S3 SQLAgent$IWBDB;SQLAgent$IWBDB;c:\msde\binn\mssql$iwbdb\binn\sqlagent.exe -i iwbdb --> c:\msde\binn\mssql$iwbdb\binn\sqlagent.EXE -i IWBDB [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2012-5-19 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2012-5-19 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2012-5-19 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2012-5-19 114280]
S3 TNET1130;D-Link AirPlus G+ Wireless Adapter;c:\windows\system32\drivers\GPlus.sys [2008-10-10 283392]
S3 wzcahe.sys;wzcahe.sys;\??\c:\windows\system32\drivers\wzcahe.sys --> c:\windows\system32\drivers\wzcahe.sys [?]
S3 xcpip;TCP/IP Protocol Driver;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]
S3 xpsec;IPSEC driver;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\zteusbnet.sys --> c:\windows\system32\drivers\ZTEusbnet.sys [?]
.
=============== Created Last 30 ================
.
2012-08-19 06:50:20 86016 ----a-w- c:\windows\unvise32.exe
2012-08-19 06:50:14 -------- d-----w- c:\program files\Restore My Files Data Recovery v6.01
2012-08-19 02:09:42 102400 ----a-w- c:\windows\RegBootClean.exe
2012-08-13 08:21:39 -------- d-----w- c:\documents and settings\ron drever.ronsnewdesktop\application data\Nico Mak Computing
2012-08-13 08:19:41 -------- d-----w- c:\program files\Vuze
2012-08-10 09:44:23 -------- d-----w- c:\documents and settings\ron drever.ronsnewdesktop\.zenmap
2012-08-10 09:42:25 -------- d-----w- c:\program files\Nmap
2012-08-09 00:07:04 476936 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-08-09 00:03:40 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2012-08-09 00:03:40 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2012-08-09 00:03:40 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2012-08-09 00:03:40 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2012-08-09 00:03:40 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2012-08-09 00:03:40 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2012-08-09 00:03:40 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2012-08-08 06:33:47 -------- d-----w- c:\documents and settings\ron drever.ronsnewdesktop\local settings\application data\Secunia PSI
2012-08-08 06:33:19 -------- d-----w- c:\program files\Secunia
2012-08-02 10:45:27 133208 ----a-w- c:\windows\system32\drivers\94034860.sys
2012-08-01 12:07:42 -------- d-----w- C:\TDSSKiller_Quarantine
2012-08-01 09:33:14 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-01 09:33:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-01 05:40:26 -------- d-----w- c:\documents and settings\ron drever.ronsnewdesktop\local settings\application data\Livescribe
2012-08-01 05:40:25 -------- d-----w- c:\documents and settings\all users.windows\application data\Livescribe
2012-08-01 05:28:47 -------- d-----w- c:\documents and settings\ron drever.ronsnewdesktop\application data\com.livescribe.LivescribeConnect
2012-08-01 05:28:36 20480 ----a-w- c:\windows\system32\drivers\PulseUsb.sys
2012-08-01 05:28:36 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2012-08-01 05:28:26 -------- d-----w- c:\program files\common files\Livescribe
2012-08-01 05:28:10 -------- d-----w- c:\program files\Livescribe
2012-07-26 12:02:51 133208 ----a-w- c:\windows\system32\drivers\28447009.sys
2012-07-25 23:36:36 -------- d-----w- c:\documents and settings\ron drever.ronsnewdesktop\application data\ElevatedDiagnostics
2012-07-25 11:36:27 -------- d-----w- c:\documents and settings\all users.windows\application data\SecTaskMan
2012-07-25 11:36:14 -------- d-----w- c:\program files\Security Task Manager
2012-07-25 06:51:14 -------- d-----w- c:\documents and settings\ron drever.ronsnewdesktop\application data\Wireshark
2012-07-24 07:44:58 -------- d-----w- c:\program files\Wireshark
2012-07-24 03:57:36 475736 ----a-w- c:\windows\system32\drivers\1069827drv.sys
2012-07-24 03:57:36 133208 ----a-w- c:\windows\system32\drivers\12404636.sys
2012-07-24 02:37:30 475736 ----a-w- c:\windows\system32\drivers\0554340drv.sys
2012-07-24 02:37:30 133208 ----a-w- c:\windows\system32\drivers\51584566.sys
2012-07-24 00:20:03 8 --sh--r- c:\documents and settings\all users.windows\application data\6390A2B50D.sys
2012-07-23 13:16:20 -------- d-----w- c:\program files\NetCutDefender
2012-07-23 12:50:17 -------- d-----w- c:\program files\WinPcap
2012-07-23 12:49:56 389120 ----a-w- c:\windows\system32\actskn43.ocx
2012-07-23 12:49:55 -------- d-----w- c:\program files\netcut
.
==================== Find3M ====================
.
2012-08-19 02:58:06 1682 --sha-w- c:\documents and settings\all users.windows\application data\KGyGaAvL.sys
2012-08-14 23:54:23 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-14 23:54:23 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-09 00:06:46 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-09 00:06:46 472840 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-26 23:24:12 16608 ----a-w- c:\windows\gdrv.sys
2012-06-13 05:15:05 9072 ----a-w- c:\windows\system32\drivers\8536
2012-06-08 04:51:15 52362164 ----a-w- C:\eb_install3.exe
2012-06-05 05:50:55 1445888 ----a-w- c:\documents and settings\ron drever.ronsnewdesktop\DesktopWinsockxpFix.exe
2012-06-05 05:50:47 186368 ----a-w- c:\documents and settings\ron drever.ronsnewdesktop\DesktopLSPFix.exe
2012-06-05 05:50:43 36864 ----a-w- c:\documents and settings\ron drever.ronsnewdesktop\DesktopSafeMSI.exe
2012-06-02 05:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 05:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 05:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 05:19:34 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 05:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 05:18:58 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 05:18:58 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 05:18:58 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22:09 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-28 14:38:50 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-05-23 08:50:06 4659712 ----a-w- c:\windows\system32\Redemption.dll
2012-05-23 08:49:34 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2012-05-23 08:49:34 30568 ----a-w- c:\windows\MusiccityDownload.exe
2012-05-23 08:49:32 45320 ----a-w- c:\windows\system32\MAMACExtract.dll
2012-05-23 08:49:32 14336 ----a-w- c:\windows\system32\avrt.dll
2012-05-23 08:49:30 821824 ----a-w- c:\windows\system32\dgderapi.dll
2012-05-23 08:49:30 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
2012-05-23 08:49:30 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
.
============= FINISH: 19:12:31.82 ===============
I am scanning the GMER as we speak so that will be uploaded shortly.
I have another computer with similar problems do i just upload my log files?


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top







