.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_27
Run by Kiri at 17:35:25 on 2011-12-24
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.3573.2303 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2645238
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - c:\program files\zonealarm_security\prxtbZone.dll
mURLSearchHooks: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - c:\program files\zonealarm_security\prxtbZone.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - c:\program files\zonealarm_security\prxtbZone.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - c:\program files\zonealarm_security\prxtbZone.dll
TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
{555d4d79-4bd2-4094-a395-cfc534424a05}
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVZOVgtTlNWVkwtTzRCWlEtUUlNQ0wtUVREQ0gtNElKTUg"&"inst=NzctNTE4MzA2ODcwLVhPMTArMTItUUlYMSs0LVgyMDEwKzItRjEwTTEwRCsxLUxJQysyLUZMMTArMS1TUDErMS1TUDFUQisxLVNVUCs0LVNQMVMyKzEtRERUKzIwMzE2LUREMTBGKzEtU1QxMEZBUFArMS1GMTBNMTJBVCszLUYxME0xMkErMS1GMTBNMTJBQisxLVUxMCsxLUYxME0xMkFUQk4rMQ"&"prod=90"&"ver=10.0.1416
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\audibl~1.lnk - c:\program files\audible\bin\AudibleDownloadHelper.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{16DD1700-6AB7-4A39-88A3-65B636D309A3} : DhcpNameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{82E70A7F-433D-4D8C-BECF-2044B63C77CA} : DhcpNameServer = 75.75.76.76 75.75.75.75
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\kiri\appdata\roaming\mozilla\firefox\profiles\1m25t38r.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2559647&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.cheapassgamer.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2559647&SearchSource=2&q=
FF - prefs.js: network.proxy.type - 0
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 297168]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-6-18 73728]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2011-2-15 26872]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2011-2-15 488952]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-12-19 366152]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-5-27 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 28624]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-19 111616]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-12-19 22216]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-8-18 7390560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-20 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-20 135664]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-12-24 20:42:01 -------- d-sh--w- C:\$RECYCLE.BIN
2011-12-24 20:27:08 0 ---ha-w- c:\users\kiri\appdata\local\BIT1FC0.tmp
2011-12-24 20:23:27 54784 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-24 19:25:36 -------- d-----w- C:\ComboFix
2011-12-24 18:38:38 98816 ----a-w- c:\windows\sed.exe
2011-12-24 18:38:38 518144 ----a-w- c:\windows\SWREG.exe
2011-12-24 18:38:38 256000 ----a-w- c:\windows\PEV.exe
2011-12-24 18:38:38 208896 ----a-w- c:\windows\MBR.exe
2011-12-24 18:21:09 -------- d-----w- c:\users\kiri\appdata\roaming\AVG10
2011-12-22 05:08:25 29184 ----a-r- c:\users\kiri\appdata\roaming\microsoft\installer\{21ae04e8-ebf6-40db-9aa9-b7a80c5d057d}\Icon21AE04E8.exe
2011-12-22 05:08:18 -------- d-----w- c:\program files\mkv2vob
2011-12-22 05:07:43 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2011-12-21 02:00:21 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-12-20 20:45:51 -------- d-----w- c:\program files\Windows Portable Devices
2011-12-20 08:29:30 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2011-12-20 08:29:28 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2011-12-20 08:29:28 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-12-20 08:28:26 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2011-12-20 08:28:21 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2011-12-20 08:28:20 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2011-12-20 08:28:20 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2011-12-20 08:28:20 252928 ----a-w- c:\windows\system32\dxdiag.exe
2011-12-20 08:28:20 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2011-12-20 08:28:19 519680 ----a-w- c:\windows\system32\d3d11.dll
2011-12-19 17:58:05 -------- d-----w- c:\program files\Conduit
2011-12-19 17:58:02 -------- d-----w- c:\program files\ZoneAlarm_Security
2011-12-19 17:48:36 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-12-19 17:47:57 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-12-19 17:46:40 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-19 17:46:39 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-12-19 17:46:36 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-12-19 17:46:28 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-19 17:46:02 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-12-19 17:46:02 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-12-19 17:46:02 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-12-19 17:46:02 238080 ----a-w- c:\windows\system32\oleacc.dll
2011-12-19 17:45:41 707584 ----a-w- c:\program files\common files\system\wab32.dll
2011-12-19 17:44:48 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-12-19 02:57:20 -------- d-----w- c:\windows\system32\eu-ES
2011-12-19 02:57:20 -------- d-----w- c:\windows\system32\ca-ES
2011-12-19 02:57:20 -------- d-----w- c:\program files\Microsoft Games
2011-12-19 02:57:19 -------- d-----w- c:\windows\system32\vi-VN
2011-12-18 21:39:52 -------- d-----w- c:\windows\system32\EventProviders
2011-12-18 19:57:54 -------- d-----w- c:\users\kiri\appdata\roaming\Twan Wintjes
2011-12-18 19:57:07 -------- d-----w- c:\users\kiri\AVCHDCoder
2011-12-18 19:48:48 -------- d-----w- c:\windows\IswTmp
2011-12-18 19:05:54 -------- d-----w- c:\users\kiri\appdata\local\Welltek_Software
2011-12-15 04:01:26 -------- d-----w- c:\users\kiri\appdata\roaming\mkvtoolnix
2011-12-15 03:47:42 -------- d-----w- c:\users\kiri\temp
2011-11-25 04:22:04 -------- d-----w- c:\users\kiri\appdata\roaming\DVDVideoSoft
2011-11-25 04:21:55 -------- d-----w- c:\users\kiri\appdata\roaming\DVDVideoSoftIEHelpers
.
==================== Find3M ====================
.
2011-11-04 14:54:57 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-27 08:01:53 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-27 08:01:53 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-20 15:55:43 834048 ----a-w- c:\windows\system32\wininet.dll
2011-10-20 14:08:44 389632 ----a-w- c:\windows\system32\html.iec
.
============= FINISH: 17:35:51.99 ===============
ark.txt (119.79K)
Number of downloads: 1
Attached File(s)
-
Attach.txt (12.15K)
Number of downloads: 0
This post has been edited by Hiroshou: 24 December 2011 - 06:29 PM

Help
This topic is locked

Back to top














