Another from DDS
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Administrator at 21:08:40.35 on Sat 05/14/2011
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.765.262 [GMT 5:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.internetdownloadmanager.com/welcome.html?v=518b2
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
BHO: LastPass Browser Helper Object: {95d9ecf5-2a4d-4550-be49-70d42f71296e} - c:\program files\lastpass\LPBar.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - c:\program files\lastpass\LPBar.dll
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download FLV videos with IDM from 10 last requested - c:\program files\internet download manager\IEGetVL2.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: LastPass - file://c:\program files\lastpass\context.html?cmd=lastpass
IE: LastPass Fill Forms - file://c:\program files\lastpass\context.html?cmd=fillforms
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - c:\program files\lastpass\LPBar.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
LSP: c:\windows\system32\idmmbc.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
TCP: {A687DCD5-A6BD-43D3-82DC-2CCB643854D3} = 203.99.163.240,202.125.132.12
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\guard32.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\gl03g850.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.pk
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\administrator\application data\idm\idmmzcc3\components\idmmzcc.dll
FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\gl03g850.default\extensions\
[email protected]\platform\winnt_x86-msvc\components\lpxpcom.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\nppl3260.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npqtplugin.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npqtplugin2.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npqtplugin3.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npqtplugin4.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npqtplugin5.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npqtplugin6.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\nprpjplug.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter:
[email protected] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: IDM CC:
[email protected] - c:\documents and settings\administrator\application data\idm\idmmzcc3
FF - Ext: LastPass:
[email protected] - %profile%\extensions\
[email protected].
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-5-13 11608]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-5-2 242472]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-5-2 29400]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-5-13 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-5-13 269480]
R2 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files\advanced system optimizer 3\ASO3DefragSrv.exe [2011-5-13 239928]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-5-13 61960]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2011-5-9 1779792]
R3 crtaud;Conexant Riptide WDM Audio Driver;c:\windows\system32\drivers\crtaud.sys [2011-5-13 42112]
R3 L1c;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2011-5-13 45056]
R3 rpfun;Conexant Riptide Dummy Driver;c:\windows\system32\drivers\rpfun.sys [2011-5-13 3840]
R3 rthwcls;Conexant Riptide Bus / Firmware Downloader;c:\windows\system32\drivers\rthwcls.sys [2011-5-13 30720]
.
=============== Created Last 30 ================
.
2011-05-14 15:20:30 -------- d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes
2011-05-14 15:18:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys9:11 PM 5/14/2011
2011-05-14 15:18:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-05-14 15:18:55 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-14 15:18:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-14 14:31:15 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2011-05-14 14:31:15 -------- d-----w- c:\docume~1\admini~1\applic~1\SUPERAntiSpyware.com
2011-05-14 14:31:06 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-05-14 09:21:24 221184 ----a-w- c:\windows\system32\wmpns.dll
2011-05-14 07:54:51 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2011-05-13 22:11:58 -------- d-----w- c:\windows\system32\NtmsData
2011-05-13 20:43:35 -------- d-----w- c:\docume~1\admini~1\applic~1\TeamViewer
2011-05-13 20:42:54 -------- d-----w- c:\program files\TeamViewer
2011-05-13 18:30:10 -------- d-----w- c:\program files\COMODO
2011-05-13 18:29:39 -------- d-----w- c:\docume~1\alluse~1\applic~1\Comodo
2011-05-13 18:09:39 -------- d-----w- c:\windows\Internet Logs
2011-05-13 16:58:01 106496 ----a-w- c:\windows\system32\TwnLib20.dll
2011-05-13 16:57:59 476320 ------w- c:\windows\system32\ImagXpr7.dll
2011-05-13 16:57:59 471040 ------w- c:\windows\system32\ImagXRA7.dll
2011-05-13 16:57:59 364544 ------w- c:\windows\system32\TwnLib4.dll
2011-05-13 16:57:59 262144 ------w- c:\windows\system32\ImagXR7.dll
2011-05-13 16:57:59 1568768 ------w- c:\windows\system32\ImagX7.dll
2011-05-13 16:57:58 38912 ------w- c:\windows\system32\picn20.dll
2011-05-13 16:57:56 155648 ----a-w- c:\windows\system32\NeroCheck.exe
2011-05-13 16:56:24 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2011-05-13 16:56:24 32592 ----a-w- c:\windows\system32\msonpmon.dll
2011-05-13 16:56:02 -------- d-----w- c:\docume~1\alluse~1\applic~1\Systweak
2011-05-13 16:51:13 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-05-13 16:50:36 -------- d-----w- c:\windows\SHELLNEW
2011-05-13 16:50:08 -------- d-----w- c:\docume~1\admini~1\locals~1\applic~1\Microsoft Help
2011-05-13 16:44:46 -------- d-----w- c:\program files\PowerISO
2011-05-13 16:42:46 -------- d-----w- c:\docume~1\admini~1\applic~1\Systweak
2011-05-13 16:41:59 17136 ----a-w- c:\windows\system32\sasnative32.exe
2011-05-13 16:41:47 -------- d-----w- c:\program files\Advanced System Optimizer 3
2011-05-13 16:07:04 -------- d-----w- c:\docume~1\admini~1\locals~1\applic~1\LastPass
2011-05-13 16:06:20 -------- d-----w- c:\program files\LastPass
.
==================== Find3M ====================
.
2011-05-13 14:48:28 737280 ----a-w- c:\windows\iun6002.exe
2011-05-13 14:25:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-13 14:25:10 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-13 14:23:24 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-02 15:36:04 284744 ----a-w- c:\windows\system32\guard32.dll
2011-04-13 22:40:10 4284416 ----a-w- c:\windows\system32\GPhotos.scr
2011-03-29 08:00:00 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2011-03-24 19:35:18 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2011-03-24 19:28:12 631808 ----a-w- c:\windows\system32\xvidcore.dll
2011-03-19 19:00:38 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-03-05 10:47:16 122368 ----a-w- c:\windows\system32\lagarith.dll
2011-03-03 18:29:52 2712064 ----a-w- c:\windows\system32\x264vfw.dll
2011-03-02 10:43:46 175616 ----a-w- c:\windows\system32\unrar.dll
.
============= FINISH: 21:10:51.04 ===============