Malwarebytes' Anti-Malware 1.44
Database version: 3717
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/10/2010 11:43:48 AM
mbam-log-2010-02-10 (11-43-47).txt
Scan type: Full Scan (C:\|)
Objects scanned: 321688
Time elapsed: 3 hour(s), 40 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\cleansweep.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/10/2003 10:48:56 AM
System Uptime: 2/7/2010 10:56:50 PM (46 hours ago)
Motherboard: Compaq | | 07E4h
Processor: Intel(R) Pentium(R) 4 CPU 2.66GHz | XU1 PROCESSOR | 2657/533mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 233 GiB total, 118.968 GiB free.
E: is CDROM ()
G: is CDROM ()
H: is FIXED (NTFS) - 932 GiB total, 670.86 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) PRO/100 VM Network Connection
Device ID: PCI\VEN_8086&DEV_103B&SUBSYS_00120E11&REV_81\4&25296D99&0&40F0
Manufacturer: Intel
Name: Intel(R) PRO/100 VM Network Connection
PNP Device ID: PCI\VEN_8086&DEV_103B&SUBSYS_00120E11&REV_81\4&25296D99&0&40F0
Service: E100B
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
7-Zip 4.65
AAC Decoder
ACID Pro 7.0
Acronis Migrate Easy
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 9.2
Adobe Shockwave Player 11.5
Advertising Center
AllToAVI v4 r5394
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft MediaImpression
ArcSoft PhotoImpression 5
ArcSoft VideoImpression 2
Ares 2.1.2
Aspell English Dictionary-0.50-2
AutoUpdate
AVG 9.0
AviSynth 2.5
BitTyrant
Bonjour
Calculator Powertoy for Windows XP
CamStudio
CamStudio Lossless Codec
CCleaner
Combined Community Codec Pack 2009-09-09
DC++ 0.750
Dev-C++ 5 beta 9 release (4.9.9.2)
Digital Camera
DivX Codec
DivX Plus DirectShow Filters
DivX Plus Web Player
DivX Version Checker
DolbyFiles
DVD Flick 1.3.0.7
DVD Shrink 3.2
EA Download Manager
EA Download Manager UI
Fiesta
FreeMind
GIMP 2.6.7
GNU Aspell 0.50-3
GTK+ Runtime 2.14.7 rev a (remove only)
GUI Design Studio 3.6.95.0
Guifications Plugin (remove only)
H.264 Decoder
HandBrake 0.9.3
High-Logic FontCreator 6.0
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
HP Standard Port Monitor
HyperCam 2
Image Resizer Powertoy for Windows XP
Intel(R) Extreme Graphics Driver
Intel(R) PRO Ethernet Adapter and Software
InterVideo DeviceService
iPodRip
iTunes
Java 2 Runtime Environment, SE v1.4.0_01
Java Web Start
Java(TM) 6 Update 3
Kazaa Lite K++ v2.4.3
KeyScrambler
LogMeIn Hamachi
Malwarebytes' Anti-Malware
MapleStory
MediaCoder 0.6.1
MEGA-DSC
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office XP Professional with FrontPage
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft WSE 3.0 Runtime
Miro
MKV Splitter
MKVtoolnix 2.9.8
Mozilla Firefox (3.5.7)
MUSTEK 1200 UB v2.1
Nero ControlCenter
Nero Installer
Nero Suite
NETGEAR WG111v2 wireless USB 2.0 adapter
Notepad++
Orbit
PeerGuardian 2.0
Pidgin
Pokemon PC 2.0
Project64 1.6
PurgeFox - 4.01
QuickTime
RGSS-RTP Standard
RPG Maker 2000 1.05
RPG Maker 2003 v1.08
RPG Maker VX 1.02
RPG Maker VX RTP
RPG Maker XP - Postality Knights Edition ENHANCED
RTP 1.32 Add-On for RM2k
RTP de RPG Maker 2003
RTP for RM2K (Png, Wav, Midi, Fonts)
save2pc Pro 3.51
Scenario RPGMaker 2003
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB972270)
Smart Install Maker 5.02
SoulSeek 157 NS 13e
SoundMAX
SUPER © Version 2009.bld.36 (June 10, 2009)
SUPERAntiSpyware Professional
TES Construction Set
The Sims™ 3
Torrent Searcher 9.0
TreeSize Free V2.3.3
TrueCrypt
Tweak UI
Unlocker 1.8.8
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976749)
VC80CRTRedist - 8.0.50727.4053
Videora iPod classic Converter 5.03
Videora Trial Version 2.15
VirtualDubMOD 1.5.10.3 US
VLC media player 1.0.3
VMware ThinApp
VobSub v2.23 (Remove Only)
Vuze
WebFldrs XP
Window Washer
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Support Tools
Windows XP Service Pack 3
WinFF 1.0.4
WinPcap 4.0
Xvid 1.2.2 final uninstall
XviD4PSP 5.0
Yahoo! Install Manager
Yahoo! Widgets
==== Event Viewer Messages From Past Week ========
2/9/2010 7:39:08 AM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer MOMLUVSDAD that believes that it is the master browser for the domain on transport NetBT_Tcpip_{5874CD5F-02BD-4F2. The master browser is stopping or an election is being forced.
2/9/2010 1:42:37 PM, information: Windows File Protection [64004] - The protected system file termsrv.dll could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x800b0100 [No signature was present in the subject. ].
2/7/2010 4:45:01 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
2/7/2010 4:41:57 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 Fips intelppm SASDIFSV SASKUTIL truecrypt
2/7/2010 4:41:41 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/7/2010 10:18:22 PM, error: NetDDE [206] - Listen failed: 15:
2/7/2010 10:18:02 PM, error: NetDDE [206] - Listen failed: 23: The ncb_lana_num member did not specify a valid network number.
2/5/2010 7:02:51 AM, error: PSched [14103] - QoS [Adapter {5874CD5F-02BD-4F2C-8B14-55138A3A0C42}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.
2/5/2010 11:57:12 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
2/5/2010 11:57:12 PM, error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error: After starting, the service hung in a start-pending state.
2/5/2010 11:57:12 PM, error: Service Control Manager [7001] - The Fast User Switching Compatibility service depends on the Terminal Services service which failed to start because of the following error: After starting, the service hung in a start-pending state.
2/5/2010 11:57:12 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/5/2010 11:50:40 PM, error: Service Control Manager [7000] - The npkcrypt service failed to start due to the following error: The system cannot find the path specified.
2/5/2010 1:24:33 PM, error: Service Control Manager [7034] - The Capture Device Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:32 PM, error: Service Control Manager [7034] - The Window Washer Engine service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:30 PM, error: Service Control Manager [7034] - The StarWind iSCSI Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:29 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:27 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:25 PM, error: Service Control Manager [7034] - The SoundMAX Agent Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:20 PM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Network DDE service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Network DDE DSDM service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:16 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Media Player Network Sharing Service service, but this action failed with the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
2/5/2010 1:23:19 PM, error: Service Control Manager [7034] - The LogMeIn Hamachi 2.0 Tunneling Engine service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:19 PM, error: Service Control Manager [7034] - The B's Recorder GOLD Library General Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:18 PM, error: Service Control Manager [7034] - The WMDM PMSP Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:15 PM, error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
2/5/2010 1:23:12 PM, error: Service Control Manager [7034] - The AVG E-mail Scanner service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:11 PM, error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:11 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/4/2010 11:03:49 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
2/4/2010 11:02:52 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2/3/2010 5:49:46 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0023C32129DA. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
2/3/2010 5:49:09 AM, error: Service Control Manager [7000] - The LogMeIn Hamachi 2.0 Tunneling Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/3/2010 5:49:08 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the LogMeIn Hamachi 2.0 Tunneling Engine service to connect.
2/3/2010 1:34:15 PM, error: Srv [2011] - The server's configuration parameter "irpstacksize" is too small for the server to use a local device. Please increase the value of this parameter.
==== End Of File ===========================
DDS (Ver_09-12-01.01) - NTFSx86
Run by Alex at 20:24:37.98 on Tue 02/09/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.66 [GMT -5:00]
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Alex\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = file:///H:/dls/backup/lulz/Anon%20Party%20Hard/anon_partyhard30.swf
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uInternet Settings,ProxyServer = 83.133.119.38:8080
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: CKeyScramblerBHO Object: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
TB: {338B4DFE-2E2C-4338-9E41-E176D497299E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Window Washer] c:\program files\webroot\washer\wwDisp.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [cleansweep.exe] c:\cleansweep.exe\cleansweep.exe
mRun: [DrvLsnr] "c:\program files\analog devices\soundmax\DrvLsnr.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\orbit.lnk - c:\program files\orbitdownloader\orbitdm.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Download All with FlashGet - c:\documents and settings\Alex\my documents\random junk\programs\flashget\jc_all.htm
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Download with FlashGet - c:\documents and settings\Alex\my documents\random junk\programs\flashget\jc_link.htm
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: Download FLV video content with IDM - c:\documents and settings\Alex\my documents\random junk\programs\internet download manager\IEGetVL.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} - hxxp://office.microsoft.com/productupdates/content/opuc.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37868.274537037
DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_0_01-win.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\Alex\applic~1\mozilla\firefox\profiles\um5wf9ps.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\{81bf1d23-5f17-408d-ac6b-bd6df7caf670}\components\XpcomOpusConnector.dll
FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\
[email protected]\components\KeyScramblerIE.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2009-12-30 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-12-30 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-30 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-12-30 28424]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-30 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 74480]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-12-30 906520]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-12-30 285392]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2009-12-30 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2009-12-30 5832712]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-12-3 236368]
R2 StarWindService;StarWind iSCSI Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindService.exe [2005-4-1 217600]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-12-30 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2009-12-30 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2009-12-30 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2009-12-30 25736]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2007-8-9 113896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-12-3 19160]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2009-12-12 272128]
R3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [2007-8-8 223128]
S0 gxal;gxal;c:\windows\system32\drivers\naaajasa.sys --> c:\windows\system32\drivers\naaajasa.sys [?]
S2 PowerManager;Power Manager;c:\windows\svchost.exe --> c:\windows\svchost.exe [?]
S3 aic32p;aic32p;\??\c:\windows\system32\drivers\ipfmpo.sys --> c:\windows\system32\drivers\ipfmpo.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-12-30 30104]
S3 dsreader;MaxDrive Driver (dsreader.sys);c:\windows\system32\drivers\dsreader.sys [2001-1-2 19677]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-1-25 42000]
S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [2007-12-8 15104]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [2009-11-29 627072]
S3 XDva281;XDva281;\??\c:\windows\system32\xdva281.sys --> c:\windows\system32\XDva281.sys [?]
=============== Created Last 30 ================
2010-02-09 19:20:17 0 d-----w- c:\program files\Trend Micro
2010-02-05 18:21:23 0 d-----w- c:\docume~1\Alex\applic~1\Subversion
2010-02-05 18:19:32 0 d-----w- c:\program files\GUI Design Studio
2010-02-03 10:47:38 0 d-----w- c:\program files\LogMeIn Hamachi
2010-01-29 21:12:58 0 d-----w- C:\ProgramData
2010-01-29 21:12:58 0 d-----w- c:\docume~1\alluse~1\applic~1\Electronic Arts
2010-01-29 21:08:44 447752 ----a-r- c:\windows\system32\vp6vfw.dll
2010-01-29 21:08:40 0 d-----w- c:\program files\Microsoft WSE
2010-01-28 04:50:22 22297 ----a-w- c:\documents and settings\Alex\.recently-used.xbel
2010-01-27 01:03:39 0 d-----w- c:\docume~1\alluse~1\applic~1\Kazaa
2010-01-27 00:27:38 0 d-----w- c:\docume~1\Alex\applic~1\Kazaa Lite
2010-01-27 00:27:33 0 d-----w- c:\program files\Kazaa Lite K++
2010-01-26 23:56:47 0 d-----w- C:\My Shared Folder
2010-01-26 23:56:46 0 d-----w- c:\program files\Torrent Searcher 9.0
2010-01-26 07:27:29 766 ----a-w- c:\windows\DSC.ico
2010-01-26 07:27:29 7431 ----a-w- c:\windows\Tw504b.src
2010-01-26 07:27:29 65536 ----a-w- c:\windows\PCCam.exe
2010-01-26 07:27:29 515803 ----a-w- c:\windows\system32\drivers\CA504bv.sys
2010-01-26 07:27:29 19456 ----a-w- c:\windows\system32\Dext504b.ax
2010-01-26 07:27:29 14381 ----a-w- c:\windows\Tw504b.ini
2010-01-26 07:27:29 131072 ----a-w- c:\windows\system32\SP5X_32.DLL
2010-01-26 07:27:29 10986 ----a-w- c:\windows\system32\drivers\Bulk504b.sys
2010-01-26 07:27:29 0 d-----w- c:\windows\MEGA-DSC
2010-01-25 10:58:18 479056 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-24 17:23:47 0 d-----w- c:\program files\Pidgin
2010-01-24 17:23:03 0 d-----w- c:\program files\common files\GTK
2010-01-24 07:39:24 0 d-----w- c:\docume~1\Alex\applic~1\NetMedia Providers
2010-01-24 06:51:35 0 d-----w- c:\program files\Vstplugins
2010-01-24 06:51:04 0 d-----w- c:\program files\Sony
2010-01-24 06:44:50 0 d-----w- c:\program files\Sony Setup
2010-01-14 06:34:29 0 d-----w- c:\program files\Yahoo!
2010-01-12 22:40:56 0 d-----w- c:\docume~1\Alex\applic~1\AVG9
2010-01-11 02:34:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Azureus
2010-01-11 02:33:44 0 d-----w- c:\docume~1\Alex\applic~1\Azureus
2010-01-11 02:28:53 0 d-----w- c:\program files\Vuze
==================== Find3M ====================
2010-01-07 21:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-30 20:51:34 25608 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2009-12-30 20:51:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-30 20:51:33 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-30 20:51:33 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-12-30 20:51:24 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-30 20:49:18 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2009-12-30 20:49:18 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-12-30 09:22:29 223440 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2009-12-21 19:14:05 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-20 06:06:39 79416 ----a-w- c:\windows\fonts\Becker-Bold.ttf
2009-12-20 06:06:39 55432 ----a-w- c:\windows\fonts\Becker_Bold.ttf
2009-12-13 17:02:59 92594 ----a-w- c:\windows\fonts\CCWiccanSansInt-Regular.PFB
2009-12-13 17:01:58 48972 ----a-w- c:\windows\fonts\CCAltogetherOoky-Capitals.ttf
2009-12-13 17:00:58 60835 ----a-w- c:\windows\fonts\CCExterminate-AllOfThem.PFB
2009-12-13 16:59:58 45876 ----a-w- c:\windows\fonts\CCCutthroatInt-Regular.ttf
2009-12-12 22:46:12 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-12-09 18:57:52 306688 ----a-w- c:\windows\IsUninst.exe
2009-12-08 23:33:17 2554 ----a-w- c:\windows\system32\tmp.reg
2009-12-08 20:48:01 380928 ----a-w- c:\windows\SynCor.exe
2009-12-08 20:48:01 299520 ----a-w- c:\windows\uninst.exe
2009-12-05 17:02:33 45816 ----a-w- c:\windows\fonts\euronymous-fo+st.ttf
2009-12-03 01:37:40 46504 ----a-w- c:\windows\fonts\Formal_436_BT.ttf
2009-12-02 11:18:36 55324 ----a-w- c:\windows\fonts\Cooper_Md_BT_Medium.ttf
2009-12-02 11:13:11 76000 ----a-w- c:\windows\fonts\ANNA____.ttf
2009-11-30 01:08:17 507392 ----a-w- c:\windows\system32\AutoPartNt.exe
2009-11-30 00:42:48 37888 ----a-w- c:\windows\system32\setupnt.dll
2009-11-30 00:42:47 126976 ----a-w- c:\windows\system32\snapapi.dll
2009-11-14 00:47:32 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47:28 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47:28 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47:28 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47:28 696320 ----a-w- c:\windows\system32\DivX.dll
2006-05-03 09:06:54 163328 --sha-r- c:\windows\system32\flvDX.dll
2009-08-23 00:35:38 952 --sha-w- c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47:16 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30:52 216064 --sha-r- c:\windows\system32\nbDX.dll
============= FINISH: 20:27:47.01 ===============