dds_LOG
DDS (Ver_10-03-17.01) - NTFSx86 NETWORK
Run by admin at 14:21:15.10 on Mon 09/20/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.100 [GMT -7:00]
AV: AVG *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: StopSign Antivirus FREE TRIAL diagnostic version *On-access scanning disabled* (Updated) {3E1D4556-3240-40c8-BBED-64A8690A3FB4}
FW: StopSign Firewall FREE TRIAL version *disabled* {06936B90-CB61-4dcb-AABD-C0E25320F6C3}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\svchost.exe
C:\WINDOWS\setup.exe
C:\WINDOWS\win32.exe
C:\DOCUME~1\admin\LOCALS~1\Temp\drweb.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
C:\DOCUME~1\admin\LOCALS~1\Temp\setup.exe
C:\DOCUME~1\admin\LOCALS~1\Temp\win16.exe
C:\WINDOWS\gdi32.exe
C:\DOCUME~1\admin\LOCALS~1\Temp\winamp.exe
C:\WINDOWS\iexplarer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Documents and Settings\admin\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://hotmail.com/
uInternet Settings,ProxyServer = http=127.0.0.1:6092
uInternet Settings,ProxyOverride = <local>
uWinlogon: Shell=c:\documents and settings\admin\application data\antispy.exe
BHO: c:\windows\system32\g5bks.dll: {b1ba40a1-75f2-51bd-f313-04b03a2c8953} - c:\windows\system32\g5bks.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: LimeWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Bhakupujaxa] rundll32.exe "c:\windows\msvcocm.dll",Startup
uRun: [inetserver.exe] c:\inetserver.exe\inetserver.exe
uRun: [MKfre] c:\windows\wininst.exe
uRun: [MKZe] c:\windows\avp.exe
uRun: [MKeg] c:\windows\smss.exe
uRun: [HNUmZIXnqe] c:\docume~1\admin\locals~1\temp\login.exe
uRun: [MKeta] c:\windows\services.exe
uRun: [HNUmZIXneP] c:\docume~1\admin\locals~1\temp\avp32.exe
uRun: [MKaZ] c:\windows\cmd.exe
uRun: [MKasc] c:\windows\drweb.exe
uRun: [MKerb] c:\windows\taskmgr.exe
uRun: [MKaoc] c:\windows\debug.exe
uRun: [HNUmZIXnvZ] c:\docume~1\admin\locals~1\temp\install.exe
uRun: [HNUmZIXnusc] c:\docume~1\admin\locals~1\temp\winlogon.exe
uRun: [MKayc] c:\windows\csrss.exe
uRun: [MKevc] c:\windows\setup.exe
uRun: [HNUmZIXnZP] c:\docume~1\admin\locals~1\temp\gdi32.exe
uRun: [MKbMc] c:\windows\gdi32.exe
uRun: [HNUmZIXnb] c:\docume~1\admin\locals~1\temp\mdm.exe
uRun: [HNUmZIXnfQ] c:\docume~1\admin\locals~1\temp\win16.exe
uRun: [HNUmZIXnsb] c:\docume~1\admin\locals~1\temp\drweb.exe
uRun: [HNUmZIXn0Z] c:\docume~1\admin\locals~1\temp\system.exe
uRun: [HNUmZIXnwe] c:\docume~1\admin\locals~1\temp\setup.exe
uRun: [HNUmZIXnsf] c:\docume~1\admin\locals~1\temp\lsass.exe
uRun: [HNUmZIXnxc] c:\docume~1\admin\locals~1\temp\smss.exe
uRun: [MKeuf] c:\windows\spoolsv.exe
uRun: [HNUmZIXntg] c:\docume~1\admin\locals~1\temp\wininst.exe
uRun: [MKfpe] c:\windows\winamp.exe
uRun: [HNUmZIXnuf] c:\docume~1\admin\locals~1\temp\csrss.exe
uRun: [MKbtc] c:\windows\hexdump.exe
uRun: [HNUmZIXnz49\admin\LOCALS~1\Temp\4065986940.exe] c:\docume~1\admin\locals~1\temp\4065986940.exe
uRun: [HNUmZIXn11A\admin\LOCALS~1\Temp\3919882296.exe] c:\docume~1\admin\locals~1\temp\3919882296.exe
uRun: [MKexe] c:\windows\system.exe
uRun: [HNUmZIXnth] c:\docume~1\admin\locals~1\temp\svchost.exe
uRun: [HNUmZIXnxb] c:\docume~1\admin\locals~1\temp\sysedit.exe
uRun: [HNUmZIXn01+\admin\LOCALS~1\Temp\1872738416.exe] c:\docume~1\admin\locals~1\temp\1872738416.exe
uRun: [HNUmZIXn01O\admin\LOCALS~1\Temp\314958620.exe] c:\docume~1\admin\locals~1\temp\314958620.exe
uRun: [HNUmZIXn02Q\admin\LOCALS~1\Temp\245728976.exe] c:\docume~1\admin\locals~1\temp\245728976.exe
uRun: [HNUmZIXnd] c:\docume~1\admin\locals~1\temp\avp.exe
uRun: [HNUmZIXnrc] c:\docume~1\admin\locals~1\temp\winamp.exe
uRun: [MKfa] c:\windows\win.exe
uRun: [HNUmZIXnqg] c:\docume~1\admin\locals~1\temp\hexdump.exe
uRun: [MKcZ] c:\windows\mdm.exe
uRun: [MKese] c:\windows\svchost.exe
uRun: [MKZSc] c:\windows\avp32.exe
uRun: [HNUmZIXnwpc] c:\docume~1\admin\locals~1\temp\services.exe
uRun: [MKfPc] c:\windows\win32.exe
uRun: [MKdw+] c:\windows\nvsvc32.exe
uRun: [HNUmZIXnsd] c:\docume~1\admin\locals~1\temp\taskmgr.exe
uRun: [MKcuc] c:\windows\lsass.exe
uRun: [MKetc] c:\windows\sysedit.exe
uRun: [MKbta] c:\windows\install.exe
uRun: [HNUmZIXnwg] c:\docume~1\admin\locals~1\temp\spoolsv.exe
uRun: [HNUmZIXnz9] c:\docume~1\admin\locals~1\temp\nvsvc32.exe
uRun: [MKee] c:\windows\user.exe
uRun: [MKbuqc] c:\windows\iexplarer.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [webscan] "c:\program files\acceleration software\anti-virus\stopsignav.exe" -k
mRun: [SoftwareStation] "c:\program files\eacceleration\station\station.exe" /b Startup
mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe
mRun: [OnAccess] "c:\program files\stopsign\onaccess\onaccess.exe" -erk
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0379.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [@OnlineArmor GUI] "c:\program files\online armor\oaui.exe"
mRun: [Sjute] rundll32.exe "c:\windows\ucihehat.dll",Startup
mRun: [MKfre] c:\windows\wininst.exe
mRun: [MKZe] c:\windows\avp.exe
mRun: [MKeg] c:\windows\smss.exe
mRun: [HNUmZIXnqe] c:\docume~1\admin\locals~1\temp\login.exe
mRun: [MKeta] c:\windows\services.exe
mRun: [HNUmZIXneP] c:\docume~1\admin\locals~1\temp\avp32.exe
mRun: [MKaZ] c:\windows\cmd.exe
mRun: [MKasc] c:\windows\drweb.exe
mRun: [MKerb] c:\windows\taskmgr.exe
mRun: [MKaoc] c:\windows\debug.exe
mRun: [HNUmZIXnvZ] c:\docume~1\admin\locals~1\temp\install.exe
mRun: [HNUmZIXnusc] c:\docume~1\admin\locals~1\temp\winlogon.exe
mRun: [MKayc] c:\windows\csrss.exe
mRun: [MKevc] c:\windows\setup.exe
mRun: [HNUmZIXnZP] c:\docume~1\admin\locals~1\temp\gdi32.exe
mRun: [MKbMc] c:\windows\gdi32.exe
mRun: [HNUmZIXnb] c:\docume~1\admin\locals~1\temp\mdm.exe
mRun: [HNUmZIXnfQ] c:\docume~1\admin\locals~1\temp\win16.exe
mRun: [HNUmZIXnsb] c:\docume~1\admin\locals~1\temp\drweb.exe
mRun: [HNUmZIXn0Z] c:\docume~1\admin\locals~1\temp\system.exe
mRun: [HNUmZIXnwe] c:\docume~1\admin\locals~1\temp\setup.exe
mRun: [HNUmZIXnsf] c:\docume~1\admin\locals~1\temp\lsass.exe
mRun: [HNUmZIXnxc] c:\docume~1\admin\locals~1\temp\smss.exe
mRun: [MKeuf] c:\windows\spoolsv.exe
mRun: [HNUmZIXntg] c:\docume~1\admin\locals~1\temp\wininst.exe
mRun: [MKfpe] c:\windows\winamp.exe
mRun: [HNUmZIXnuf] c:\docume~1\admin\locals~1\temp\csrss.exe
mRun: [MKbtc] c:\windows\hexdump.exe
mRun: [HNUmZIXnz49\admin\LOCALS~1\Temp\4065986940.exe] c:\docume~1\admin\locals~1\temp\4065986940.exe
mRun: [HNUmZIXn11A\admin\LOCALS~1\Temp\3919882296.exe] c:\docume~1\admin\locals~1\temp\3919882296.exe
mRun: [MKexe] c:\windows\system.exe
mRun: [HNUmZIXnth] c:\docume~1\admin\locals~1\temp\svchost.exe
mRun: [HNUmZIXnxb] c:\docume~1\admin\locals~1\temp\sysedit.exe
mRun: [HNUmZIXn01+\admin\LOCALS~1\Temp\1872738416.exe] c:\docume~1\admin\locals~1\temp\1872738416.exe
mRun: [HNUmZIXn01O\admin\LOCALS~1\Temp\314958620.exe] c:\docume~1\admin\locals~1\temp\314958620.exe
mRun: [HNUmZIXn02Q\admin\LOCALS~1\Temp\245728976.exe] c:\docume~1\admin\locals~1\temp\245728976.exe
mRun: [HNUmZIXnd] c:\docume~1\admin\locals~1\temp\avp.exe
mRun: [HNUmZIXnrc] c:\docume~1\admin\locals~1\temp\winamp.exe
mRun: [MKfa] c:\windows\win.exe
mRun: [HNUmZIXnqg] c:\docume~1\admin\locals~1\temp\hexdump.exe
mRun: [MKcZ] c:\windows\mdm.exe
mRun: [MKese] c:\windows\svchost.exe
mRun: [HNUmZIXnwpc] c:\docume~1\admin\locals~1\temp\services.exe
mRun: [MKZSc] c:\windows\avp32.exe
mRun: [HNUmZIXnsd] c:\docume~1\admin\locals~1\temp\taskmgr.exe
mRun: [MKfPc] c:\windows\win32.exe
mRun: [MKdw+] c:\windows\nvsvc32.exe
mRun: [MKcuc] c:\windows\lsass.exe
mRun: [MKetc] c:\windows\sysedit.exe
mRun: [MKbta] c:\windows\install.exe
mRun: [HNUmZIXnwg] c:\docume~1\admin\locals~1\temp\spoolsv.exe
mRun: [HNUmZIXnz9] c:\docume~1\admin\locals~1\temp\nvsvc32.exe
mRun: [MKee] c:\windows\user.exe
mRun: [MKbuqc] c:\windows\iexplarer.exe
dRun: [inetserver.exe] c:\inetserver.exe\inetserver.exe
StartupFolder: c:\docume~1\admin\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230586529390
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1230586594593
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} - hxxp://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: {B1BA40A2-75F2-51BD-F413-04B13A2C8953} - No File
STS: c:\windows\system32\g5bks.dll: {b1ba40a1-75f2-51bd-f313-04b03a2c8953} - c:\windows\system32\g5bks.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: ExecuteMonitorShellHook Class: {42dd0873-5fa9-465d-90de-0826020416a5} - c:\program files\stopsign\onaccess\onaccess_hk32.dll
LSA: Notification Packages = msv1_0 scecli
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\25zqgi1k.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://hotmail.com/
FF - prefs.js: keyword.URL - hxxp://search.search-tab.com/?sid=10101058100&s=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 6092
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\microsoft\search enhancement pack\search helper\firefoxextension\searchhelperextension\components\SEPsearchhelperff.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {FCAFF0A7-115F-4837-8BB0-5CD6DC54B36B} - c:\documents and settings\admin\local settings\application data\{FCAFF0A7-115F-4837-8BB0-5CD6DC54B36B}
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
FF - user.js: keyword.URL - hxxp://search.search-tab.com/?sid=10101058100&s=c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 fwcore;Fwcore Filter;c:\windows\system32\drivers\fwcore.sys [2009-4-29 109664]
S1 aesqbii32;aesqbii32;\??\c:\windows\system32\drivers\aesqbii32.sys --> c:\windows\system32\drivers\aesqbii32.sys [?]
S1 akwhsti;akwhsti;\??\c:\windows\system32\drivers\akwhsti.sys --> c:\windows\system32\drivers\akwhsti.sys [?]
S1 amgqubq;amgqubq;\??\c:\windows\system32\drivers\amgqubq.sys --> c:\windows\system32\drivers\amgqubq.sys [?]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-29 97928]
S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-29 26824]
S1 bwlrfcc;bwlrfcc;\??\c:\windows\system32\drivers\bwlrfcc.sys --> c:\windows\system32\drivers\bwlrfcc.sys [?]
S1 cnpkfxy32;cnpkfxy32;\??\c:\windows\system32\drivers\cnpkfxy32.sys --> c:\windows\system32\drivers\cnpkfxy32.sys [?]
S1 dyluxfm32;dyluxfm32;\??\c:\windows\system32\drivers\dyluxfm32.sys --> c:\windows\system32\drivers\dyluxfm32.sys [?]
S1 evmyqdf32;evmyqdf32;\??\c:\windows\system32\drivers\evmyqdf32.sys --> c:\windows\system32\drivers\evmyqdf32.sys [?]
S1 fblrvfe32;fblrvfe32;\??\c:\windows\system32\drivers\fblrvfe32.sys --> c:\windows\system32\drivers\fblrvfe32.sys [?]
S1 fkbhuob;fkbhuob;\??\c:\windows\system32\drivers\fkbhuob.sys --> c:\windows\system32\drivers\fkbhuob.sys [?]
S1 furnwpo;furnwpo;\??\c:\windows\system32\drivers\furnwpo.sys --> c:\windows\system32\drivers\furnwpo.sys [?]
S1 heavtot32;heavtot32;\??\c:\windows\system32\drivers\heavtot32.sys --> c:\windows\system32\drivers\heavtot32.sys [?]
S1 hskpype;hskpype;\??\c:\windows\system32\drivers\hskpype.sys --> c:\windows\system32\drivers\hskpype.sys [?]
S1 jfkfhhs;jfkfhhs;\??\c:\windows\system32\drivers\jfkfhhs.sys --> c:\windows\system32\drivers\jfkfhhs.sys [?]
S1 jkcopuv;jkcopuv;\??\c:\windows\system32\drivers\jkcopuv.sys --> c:\windows\system32\drivers\jkcopuv.sys [?]
S1 jxmpyen;jxmpyen;\??\c:\windows\system32\drivers\jxmpyen.sys --> c:\windows\system32\drivers\jxmpyen.sys [?]
S1 kbdukgi;kbdukgi;\??\c:\windows\system32\drivers\kbdukgi.sys --> c:\windows\system32\drivers\kbdukgi.sys [?]
S1 kvbacrv32;kvbacrv32;\??\c:\windows\system32\drivers\kvbacrv32.sys --> c:\windows\system32\drivers\kvbacrv32.sys [?]
S1 lbfsvja32;lbfsvja32;\??\c:\windows\system32\drivers\lbfsvja32.sys --> c:\windows\system32\drivers\lbfsvja32.sys [?]
S1 lnywajn;lnywajn;\??\c:\windows\system32\drivers\lnywajn.sys --> c:\windows\system32\drivers\lnywajn.sys [?]
S1 mfftcso;mfftcso;\??\c:\windows\system32\drivers\mfftcso.sys --> c:\windows\system32\drivers\mfftcso.sys [?]
S1 mjovspi;mjovspi;\??\c:\windows\system32\drivers\mjovspi.sys --> c:\windows\system32\drivers\mjovspi.sys [?]
S1 mmxnlcj;mmxnlcj;\??\c:\windows\system32\drivers\mmxnlcj.sys --> c:\windows\system32\drivers\mmxnlcj.sys [?]
S1 mpqslrk;mpqslrk;\??\c:\windows\system32\drivers\mpqslrk.sys --> c:\windows\system32\drivers\mpqslrk.sys [?]
S1 olatolv;olatolv;\??\c:\windows\system32\drivers\olatolv.sys --> c:\windows\system32\drivers\olatolv.sys [?]
S1 pgmncri32;pgmncri32;\??\c:\windows\system32\drivers\pgmncri32.sys --> c:\windows\system32\drivers\pgmncri32.sys [?]
S1 pxojohm32;pxojohm32;\??\c:\windows\system32\drivers\pxojohm32.sys --> c:\windows\system32\drivers\pxojohm32.sys [?]
S1 qjoypws32;qjoypws32;\??\c:\windows\system32\drivers\qjoypws32.sys --> c:\windows\system32\drivers\qjoypws32.sys [?]
S1 qoeqqqq32;qoeqqqq32;\??\c:\windows\system32\drivers\qoeqqqq32.sys --> c:\windows\system32\drivers\qoeqqqq32.sys [?]
S1 qwvjakb32;qwvjakb32;\??\c:\windows\system32\drivers\qwvjakb32.sys --> c:\windows\system32\drivers\qwvjakb32.sys [?]
S1 rllsuqx32;rllsuqx32;\??\c:\windows\system32\drivers\rllsuqx32.sys --> c:\windows\system32\drivers\rllsuqx32.sys [?]
S1 sxmwrjs32;sxmwrjs32;\??\c:\windows\system32\drivers\sxmwrjs32.sys --> c:\windows\system32\drivers\sxmwrjs32.sys [?]
S1 tdmytuv32;tdmytuv32;\??\c:\windows\system32\drivers\tdmytuv32.sys --> c:\windows\system32\drivers\tdmytuv32.sys [?]
S1 tdumvrg;tdumvrg;\??\c:\windows\system32\drivers\tdumvrg.sys --> c:\windows\system32\drivers\tdumvrg.sys [?]
S1 tewcofq32;tewcofq32;\??\c:\windows\system32\drivers\tewcofq32.sys --> c:\windows\system32\drivers\tewcofq32.sys [?]
S1 tojgbat32;tojgbat32;\??\c:\windows\system32\drivers\tojgbat32.sys --> c:\windows\system32\drivers\tojgbat32.sys [?]
S1 tqthqiu;tqthqiu;\??\c:\windows\system32\drivers\tqthqiu.sys --> c:\windows\system32\drivers\tqthqiu.sys [?]
S1 tteiilv;tteiilv;\??\c:\windows\system32\drivers\tteiilv.sys --> c:\windows\system32\drivers\tteiilv.sys [?]
S1 udnjrno32;udnjrno32;\??\c:\windows\system32\drivers\udnjrno32.sys --> c:\windows\system32\drivers\udnjrno32.sys [?]
S1 uqgkeqw32;uqgkeqw32;c:\windows\system32\drivers\uqgkeqw32.sys [2004-8-12 302528]
S1 wcesceq;wcesceq;\??\c:\windows\system32\drivers\wcesceq.sys --> c:\windows\system32\drivers\wcesceq.sys [?]
S1 wkmeuhr32;wkmeuhr32;\??\c:\windows\system32\drivers\wkmeuhr32.sys --> c:\windows\system32\drivers\wkmeuhr32.sys [?]
S2 AMPingService;AMPingService;c:\docume~1\admin\locals~1\temp\amping.exe --> c:\docume~1\admin\locals~1\temp\AMPing.exe [?]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-12-29 875288]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-12-29 231704]
S2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-12-29 76040]
S2 eac_notifysvc;eAcceleration Notification Service;c:\progra~1\eaccel~1\framew~1\eac_svc.exe [2009-4-29 111672]
S2 eac_productsvc;eAcceleration Product Manager Service;c:\progra~1\eaccel~1\framew~1\eac_productsvc.exe [2009-4-29 263504]
S2 FWService;FWService;c:\program files\stopsign\firewall\fwservice.exe -service --> c:\program files\stopsign\firewall\FWService.exe -Service [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-5 135664]
S2 ldr7x;ldr7x;c:\windows\system32\drivers\ldr7x.sys [2010-9-1 26496]
S2 ssfwmonsvc;StopSign Firewall Security Center Provider;c:\progra~1\eaccel~1\framew~1\eac_svc.exe [2009-4-29 111672]
S2 sstsmonsvc;StopSign Antivirus Security Center Provider;c:\progra~1\eaccel~1\framew~1\eac_svc.exe [2009-4-29 111672]
S2 tcpip7x;tcpip7x;c:\windows\system32\drivers\tcpip7x.sys [2010-9-1 256256]
S3 cpuz132;cpuz132;\??\c:\docume~1\admin\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\admin\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 zgchsdiag;ZTE CDMA Handset Diagnostic Port;c:\windows\system32\drivers\zgchsdiag.sys [2009-2-24 105216]
S3 zgchsmdm;ZTE CDMA Handset USB Modem Proprietary;c:\windows\system32\drivers\zgchsmdm.sys [2009-2-24 105216]
=============== Created Last 30 ================
2010-09-20 21:17:48 0 ----a-w- c:\documents and settings\admin\defogger_reenable
2010-09-20 21:03:36 21636 ---h--w- c:\windows\iexplarer.exe
2010-09-20 18:53:02 21636 ---h--w- c:\windows\user.exe
2010-09-20 18:52:35 21636 ---h--w- c:\windows\install.exe
2010-09-20 18:51:50 21636 ---h--w- c:\windows\sysedit.exe
2010-09-20 18:47:40 21636 ---h--w- c:\windows\win.exe
2010-09-20 18:47:40 21636 ---h--w- c:\windows\lsass.exe
2010-09-20 18:47:29 21636 ---h--w- c:\windows\win32.exe
2010-09-20 18:47:27 21636 ---h--w- c:\windows\mdm.exe
2010-09-20 18:47:09 21636 ---h--w- c:\windows\nvsvc32.exe
2010-09-20 18:47:08 21636 ---h--w- c:\windows\avp32.exe
2010-09-20 18:47:07 21636 ---h--w- c:\windows\svchost.exe
2010-09-20 13:21:22 21636 ---h--w- c:\windows\system.exe
2010-09-20 11:31:16 21636 ---h--w- c:\windows\hexdump.exe
2010-09-20 09:45:37 21636 ---h--w- c:\windows\winamp.exe
2010-09-20 08:00:59 21636 ---h--w- c:\windows\win16.exe
2010-09-20 08:00:59 21636 ---h--w- c:\windows\spoolsv.exe
2010-09-20 02:50:40 21636 ---h--w- c:\windows\gdi32.exe
2010-09-20 01:06:25 21636 ---h--w- c:\windows\setup.exe
2010-09-20 01:00:33 21636 ---h--w- c:\windows\csrss.exe
2010-09-19 23:13:58 21636 ---h--w- c:\windows\taskmgr.exe
2010-09-19 23:13:57 21636 ---h--w- c:\windows\debug.exe
2010-09-19 23:13:57 21636 ---h--w- c:\windows\cmd.exe
2010-09-19 23:13:56 21636 ---h--w- c:\windows\drweb.exe
2010-09-19 21:40:21 21636 ---h--w- c:\windows\services.exe
2010-09-19 21:30:21 21636 ---h--w- c:\windows\smss.exe
2010-09-19 21:30:19 21636 ---h--w- c:\windows\avp.exe
2010-09-19 21:30:18 21636 ---h--w- c:\windows\wininst.exe
2010-09-18 18:07:31 30000 ----a-w- c:\windows\system32\c55ninda.dll
2010-09-18 03:55:10 30000 ----a-w- c:\windows\system32\g5bks.dll
2010-09-18 00:56:44 30000 ----a-w- c:\windows\system32\fmbk2p0ph.dll
2010-09-17 23:45:15 384879 ----a-w- c:\windows\system32\msjvkmul.dll
2010-09-17 23:45:12 30000 ----a-w- c:\windows\system32\l8yu9.dll
2010-09-17 01:27:28 0 ----a-w- c:\windows\system32\drivers\vmvlcg.sys
2010-09-17 01:26:38 0 d-----w- c:\docume~1\admin\applic~1\C7E7E282F0A2D9226FFD2296CB708F5D
2010-09-17 01:03:42 0 d-----w- c:\docume~1\alluse~1\applic~1\OnlineArmor
2010-09-17 01:03:42 0 d-----w- c:\docume~1\admin\applic~1\OnlineArmor
2010-09-17 01:03:25 38856 ----a-w- c:\windows\system32\drivers\oahlp32.sys
2010-09-17 01:03:25 29272 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-09-17 01:03:25 25000 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-09-17 01:03:25 201168 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-09-17 01:03:21 0 d-----w- c:\program files\Online Armor
2010-09-16 23:59:04 8832 ----a-w- c:\windows\system32\drivers\rasacd.sys
2010-09-16 20:23:22 0 d-----w- c:\program files\Trend Micro
2010-09-16 20:10:09 0 d-----w- C:\_OTM
2010-09-14 01:51:32 0 d-----w- c:\docume~1\alluse~1\applic~1\Update
2010-09-14 01:00:22 0 d-----w- c:\docume~1\admin\applic~1\Malwarebytes
2010-09-14 01:00:04 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-14 01:00:03 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-14 01:00:03 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-14 01:00:03 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-09-13 20:57:56 212480 ----a-w- c:\windows\Djefid.exe
2010-09-10 15:30:29 777728 ----a-w- c:\windows\system32\drivers\bxpcsxh.sys
2010-09-10 15:29:13 2838 ----a-w- C:\zrpt.xml
2010-09-10 15:20:25 186368 ----a-w- c:\windows\Djefic.exe
2010-09-03 14:59:51 75776 --sha-r- c:\windows\system32\syskey9.dll
2010-09-02 02:19:00 0 ----a-w- c:\windows\Yteyuji.bin
2010-09-02 02:18:58 120 ----a-w- c:\windows\Gdupi.dat
2010-09-02 02:15:27 256256 ----a-w- c:\windows\system32\drivers\tcpip7x.sys
2010-09-02 02:14:58 26496 ----a-w- c:\windows\system32\drivers\ldr7x.sys
2010-08-28 16:11:43 0 d-----w- c:\windows\system32\wbem\Repository
2010-08-28 16:09:56 0 d-----w- c:\windows\system32\drivers\Avg
2010-08-28 16:09:15 0 d-----w- c:\program files\common files\eAcceleration
2010-08-28 16:09:14 0 d-----w- c:\program files\Acceleration Software
2010-08-28 15:44:57 0 d-----w- c:\program files\Acceleration Software(2)
2010-08-23 00:52:53 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-23 00:52:53 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-08-22 16:44:10 0 d-----w- C:\$AVG8.VAULT$
2010-08-22 07:36:52 0 d-----w- c:\docume~1\admin\applic~1\Odip
==================== Find3M ====================
2008-12-30 02:18:57 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008122220081229\index.dat
2008-12-30 02:18:57 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008122920081230\index.dat
============= FINISH: 14:21:48.96 ===============