I've had problems with pages loading slowly that I wasn't sure if it was the ISP or something else, so I ran a bunch of scanners to find nothing. However, running ComboFix detected a rootkit activity which got me worrying.
I recently reformatted my computer after AVG's shield started giving warnings about Win32/Heur. Various scanners couldn't find anything then, either.
MBM LOG:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6126
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
3/21/2011 10:15:48 PM
mbam-log-2011-03-21 (22-15-48).txt
Scan type: Quick scan
Objects scanned: 135629
Time elapsed: 2 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER LOG:
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-03-21 22:18:56
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3250823NS rev.5.00
Running: ckb0nmko.exe; Driver: C:\DOCUME~1\username\LOCALS~1\Temp\uxtdypog.sys
---- System - GMER 1.0.15 ----
SSDT sptd.sys ZwEnumerateKey [0xF75380EE]
SSDT sptd.sys ZwEnumerateValueKey [0xF753847C]
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 8A16E1E8
Device \Driver\JRAID \Device\Scsi\JRAID1 8A16E1E8
Device \Driver\an8gi89l \Device\Scsi\an8gi89l1Port5Path0Target0Lun0 89FDD1E8
Device \Driver\an8gi89l \Device\Scsi\an8gi89l1 89FDD1E8
Device \FileSystem\Ntfs \Ntfs 8A19C1E8
---- EOF - GMER 1.0.15 ----
DDS LOG:
DDS (Ver_11-03-05.01) - NTFSx86
Run by username at 22:19:51.60 on Mon 03/21/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3007.2612 [GMT -4:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\username\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://start.facemoods.com/?a=ddr
uDefault_Search_URL = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [Gadwin PrintScreen] c:\program files\gadwin systems\printscreen\PrintScreen.exe /nosplash
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
uPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
dPolicies-explorer: NoInstrumentation = 1 (0x1)
dPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
dPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
Trusted Zone: google.ca\www
Trusted Zone: leagueoflegends.com\www
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: schannel.dll, credssp.dll, digest.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\username\applic~1\mozilla\firefox\profiles\tzjge6wq.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\username\application data\mozilla\firefox\profiles\tzjge6wq.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: Linkification: {35106bca-6c78-48c7-ac28-56df30b51d2a} - %profile%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
FF - Ext: Password Exporter: {B17C1C5A-04B1-11DB-9804-B622A1EF5492} - %profile%\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\divx\divx plus web player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\divx\divx plus web player\firefox\wpa
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
.
============= SERVICES / DRIVERS ===============
.
R3 appliandMP;appliandMP;c:\windows\system32\drivers\appliand.sys [2010-6-24 28256]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2011-3-17 35840]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [2010-10-13 101904]
S3 appliand;Applian Network Service;c:\windows\system32\drivers\appliand.sys [2010-6-24 28256]
.
=============== Created Last 30 ================
.
2011-03-22 02:10:34 -------- d-----w- c:\docume~1\username\applic~1\Malwarebytes
2011-03-22 02:10:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-22 02:10:30 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-03-22 02:10:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-22 02:10:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-22 02:06:51 -------- d-----w- c:\windows\system32\xircom
2011-03-22 02:06:51 -------- d-----w- c:\windows\system32\wbem\snmp
2011-03-22 02:06:51 -------- d-----w- c:\windows\srchasst
2011-03-22 01:45:27 -------- d-sha-r- C:\cmdcons
2011-03-22 01:44:43 98816 ----a-w- c:\windows\sed.exe
2011-03-22 01:44:43 89088 ----a-w- c:\windows\MBR.exe
2011-03-22 01:44:43 256512 ----a-w- c:\windows\PEV.exe
2011-03-22 01:44:43 161792 ----a-w- c:\windows\SWREG.exe
2011-03-21 00:59:06 823296 ----a-w- c:\windows\j3dcore-d3d.dll
2011-03-21 00:59:06 49152 ----a-w- c:\windows\j3dcore-ogl-chk.dll
2011-03-21 00:59:06 40960 ----a-w- c:\windows\j3dcore-ogl-cg.dll
2011-03-21 00:59:06 163840 ----a-w- c:\windows\j3dcore-ogl.dll
2011-03-21 00:58:56 -------- d-----w- c:\docume~1\username\locals~1\applic~1\{3225C812-5FB8-41CE-B15F-997F80151000}
2011-03-21 00:51:52 -------- d-----w- c:\docume~1\username\applic~1\updatetool
2011-03-21 00:50:50 -------- d-----w- C:\glassfish3
2011-03-20 02:05:34 -------- d-----w- c:\program files\SopCast
2011-03-20 02:02:53 -------- d-----w- c:\windows\system32\TVUAx
2011-03-20 02:01:00 -------- d-----w- c:\program files\Veetle
2011-03-19 04:46:15 -------- d-----w- c:\docume~1\username\applic~1\.minecraft
2011-03-17 20:58:03 -------- d-----w- c:\docume~1\username\applic~1\Ubisoft
2011-03-17 20:47:53 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-03-17 20:47:52 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-03-17 20:47:52 -------- d-----w- c:\docume~1\username\applic~1\PunkBuster
2011-03-17 20:25:31 -------- d-----w- c:\docume~1\username\applic~1\LolClient
2011-03-17 20:13:00 -------- d-----w- c:\windows\Logs
2011-03-17 20:07:09 -------- d-----w- c:\docume~1\username\locals~1\applic~1\Temp
2011-03-17 19:49:48 -------- d-----w- c:\docume~1\username\locals~1\applic~1\PMB Files
2011-03-17 19:49:45 -------- d-----w- c:\docume~1\alluse~1\applic~1\PMB Files
2011-03-17 19:49:32 -------- d-----w- c:\program files\Pando Networks
2011-03-17 17:52:54 -------- d-----w- c:\docume~1\username\locals~1\applic~1\Jaksta_Technologies_Pty_L
2011-03-17 17:50:58 -------- d-----w- c:\windows\system32\LogFiles
2011-03-17 17:50:44 -------- d-----w- c:\docume~1\username\applic~1\Replay Media Catcher 4
2011-03-17 17:50:40 -------- d-----w- c:\program files\Applian Technologies
2011-03-17 17:29:54 -------- d-----w- c:\program files\VideoLAN
2011-03-17 17:23:12 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2011-03-17 17:22:22 -------- d-----w- c:\program files\IrfanView
2011-03-17 17:14:13 11776 ----a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
2011-03-17 17:14:07 -------- d-----w- c:\program files\common files\xing shared
2011-03-17 17:14:04 150712 ----a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
2011-03-17 17:14:03 100864 ----a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
2011-03-17 17:03:22 -------- d-----w- c:\program files\Steam
2011-03-17 17:01:23 165376 ----a-w- c:\windows\system32\unrar.dll
2011-03-17 17:01:22 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-03-17 16:58:58 -------- d-----w- c:\docume~1\username\locals~1\applic~1\Apple Computer
2011-03-17 16:42:48 -------- d-----w- c:\program files\JDownloader
2011-03-17 16:39:44 -------- d-----w- c:\program files\GRETECH
2011-03-17 16:39:19 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-03-17 16:33:00 -------- d-----w- c:\program files\Gadwin Systems
2011-03-17 16:27:49 -------- d-----w- c:\program files\common files\DivX Shared
2011-03-17 16:27:37 -------- d-----w- c:\program files\DivX
2011-03-17 16:20:40 -------- d-----w- c:\docume~1\alluse~1\applic~1\DivX
2011-03-17 16:19:54 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-03-17 16:19:39 -------- d-----w- c:\docume~1\username\applic~1\DAEMON Tools Lite
2011-03-17 16:19:39 -------- d-----w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2011-03-17 16:14:37 -------- d-----w- c:\program files\BitComet
2011-03-17 16:14:37 -------- d-----w- c:\docume~1\username\applic~1\BitComet
2011-03-17 16:13:37 -------- d-----w- c:\program files\CDisplay
2011-03-17 15:53:31 -------- d-----w- c:\docume~1\username\locals~1\applic~1\Adobe
2011-03-17 15:52:30 497664 ----a-w- c:\windows\system32\ac3filter.acm
2011-03-17 15:52:29 -------- d-----w- c:\program files\AC3Filter
2011-03-17 15:38:26 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2011-03-17 15:38:26 8192 ----a-w- c:\windows\system32\kbdkor.dll
2011-03-17 15:38:26 6144 ----a-w- c:\windows\system32\kbd106.dll
2011-03-17 15:38:26 6144 ----a-w- c:\windows\system32\kbd101c.dll
2011-03-17 15:38:26 6144 ----a-w- c:\windows\system32\kbd101b.dll
2011-03-17 15:38:26 5632 ----a-w- c:\windows\system32\kbd103.dll
2011-03-17 15:27:26 -------- d-sh--w- c:\documents and settings\username\IECompatCache
2011-03-17 09:23:15 -------- d-----w- c:\program files\ATI
2011-03-17 09:22:55 -------- d-----w- c:\program files\ATI Technologies
2011-03-17 09:21:54 -------- d-----w- c:\program files\common files\Hewlett-Packard
2011-03-17 09:21:24 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-17 09:21:18 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-03-17 09:19:41 1953792 ----a-w- c:\windows\system32\xRaidSetup.exe
2011-03-17 09:19:41 143360 ----a-w- c:\windows\system32\xRaidAPI.dll
2011-03-17 09:19:39 -------- d-----w- c:\windows\RaidTool
2011-03-17 09:18:25 6912 ----a-w- c:\windows\system32\drivers\JGOGO.sys
2011-03-17 09:18:25 46208 ----a-w- c:\windows\system32\drivers\jraid.sys
2011-03-17 09:18:07 -------- d-----w- c:\windows\system32\Attansic
2011-03-17 09:18:05 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\ctor.dll
2011-03-17 09:18:05 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\DotNetInstaller.exe
2011-03-17 09:18:05 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iscript.dll
2011-03-17 09:18:05 151552 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iuser.dll
2011-03-17 09:18:05 -------- d-----w- c:\program files\Attansic
2011-03-17 09:18:04 634880 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iKernel.dll
2011-03-17 09:18:04 270468 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\Setup.dll
2011-03-17 09:18:04 159876 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\IGdi.dll
2011-03-17 09:15:27 -------- d-----w- c:\windows\system32\ReinstallBackups
2011-03-17 09:15:25 53248 ----a-w- c:\windows\system32\CSVer.dll
.
==================== Find3M ====================
.
2011-03-17 17:14:01 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-03-17 01:34:57 0 ----a-w- c:\windows\ativpsrm.bin
2011-02-03 01:40:23 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 23:19:39 73728 ----a-w- c:\windows\system32\javacpl.cpl
.
============= FINISH: 22:20:07.14 ===============
I recently reformatted my computer after AVG's shield started giving warnings about Win32/Heur. Various scanners couldn't find anything then, either.
MBM LOG:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6126
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
3/21/2011 10:15:48 PM
mbam-log-2011-03-21 (22-15-48).txt
Scan type: Quick scan
Objects scanned: 135629
Time elapsed: 2 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER LOG:
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-03-21 22:18:56
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3250823NS rev.5.00
Running: ckb0nmko.exe; Driver: C:\DOCUME~1\username\LOCALS~1\Temp\uxtdypog.sys
---- System - GMER 1.0.15 ----
SSDT sptd.sys ZwEnumerateKey [0xF75380EE]
SSDT sptd.sys ZwEnumerateValueKey [0xF753847C]
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 8A16E1E8
Device \Driver\JRAID \Device\Scsi\JRAID1 8A16E1E8
Device \Driver\an8gi89l \Device\Scsi\an8gi89l1Port5Path0Target0Lun0 89FDD1E8
Device \Driver\an8gi89l \Device\Scsi\an8gi89l1 89FDD1E8
Device \FileSystem\Ntfs \Ntfs 8A19C1E8
---- EOF - GMER 1.0.15 ----
DDS LOG:
DDS (Ver_11-03-05.01) - NTFSx86
Run by username at 22:19:51.60 on Mon 03/21/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3007.2612 [GMT -4:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\username\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://start.facemoods.com/?a=ddr
uDefault_Search_URL = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [Gadwin PrintScreen] c:\program files\gadwin systems\printscreen\PrintScreen.exe /nosplash
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
uPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
dPolicies-explorer: NoInstrumentation = 1 (0x1)
dPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
dPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
Trusted Zone: google.ca\www
Trusted Zone: leagueoflegends.com\www
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: schannel.dll, credssp.dll, digest.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\username\applic~1\mozilla\firefox\profiles\tzjge6wq.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\username\application data\mozilla\firefox\profiles\tzjge6wq.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: Linkification: {35106bca-6c78-48c7-ac28-56df30b51d2a} - %profile%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
FF - Ext: Password Exporter: {B17C1C5A-04B1-11DB-9804-B622A1EF5492} - %profile%\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}
FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\divx\divx plus web player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\divx\divx plus web player\firefox\wpa
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
.
============= SERVICES / DRIVERS ===============
.
R3 appliandMP;appliandMP;c:\windows\system32\drivers\appliand.sys [2010-6-24 28256]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2011-3-17 35840]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [2010-10-13 101904]
S3 appliand;Applian Network Service;c:\windows\system32\drivers\appliand.sys [2010-6-24 28256]
.
=============== Created Last 30 ================
.
2011-03-22 02:10:34 -------- d-----w- c:\docume~1\username\applic~1\Malwarebytes
2011-03-22 02:10:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-22 02:10:30 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-03-22 02:10:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-22 02:10:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-22 02:06:51 -------- d-----w- c:\windows\system32\xircom
2011-03-22 02:06:51 -------- d-----w- c:\windows\system32\wbem\snmp
2011-03-22 02:06:51 -------- d-----w- c:\windows\srchasst
2011-03-22 01:45:27 -------- d-sha-r- C:\cmdcons
2011-03-22 01:44:43 98816 ----a-w- c:\windows\sed.exe
2011-03-22 01:44:43 89088 ----a-w- c:\windows\MBR.exe
2011-03-22 01:44:43 256512 ----a-w- c:\windows\PEV.exe
2011-03-22 01:44:43 161792 ----a-w- c:\windows\SWREG.exe
2011-03-21 00:59:06 823296 ----a-w- c:\windows\j3dcore-d3d.dll
2011-03-21 00:59:06 49152 ----a-w- c:\windows\j3dcore-ogl-chk.dll
2011-03-21 00:59:06 40960 ----a-w- c:\windows\j3dcore-ogl-cg.dll
2011-03-21 00:59:06 163840 ----a-w- c:\windows\j3dcore-ogl.dll
2011-03-21 00:58:56 -------- d-----w- c:\docume~1\username\locals~1\applic~1\{3225C812-5FB8-41CE-B15F-997F80151000}
2011-03-21 00:51:52 -------- d-----w- c:\docume~1\username\applic~1\updatetool
2011-03-21 00:50:50 -------- d-----w- C:\glassfish3
2011-03-20 02:05:34 -------- d-----w- c:\program files\SopCast
2011-03-20 02:02:53 -------- d-----w- c:\windows\system32\TVUAx
2011-03-20 02:01:00 -------- d-----w- c:\program files\Veetle
2011-03-19 04:46:15 -------- d-----w- c:\docume~1\username\applic~1\.minecraft
2011-03-17 20:58:03 -------- d-----w- c:\docume~1\username\applic~1\Ubisoft
2011-03-17 20:47:53 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-03-17 20:47:52 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-03-17 20:47:52 -------- d-----w- c:\docume~1\username\applic~1\PunkBuster
2011-03-17 20:25:31 -------- d-----w- c:\docume~1\username\applic~1\LolClient
2011-03-17 20:13:00 -------- d-----w- c:\windows\Logs
2011-03-17 20:07:09 -------- d-----w- c:\docume~1\username\locals~1\applic~1\Temp
2011-03-17 19:49:48 -------- d-----w- c:\docume~1\username\locals~1\applic~1\PMB Files
2011-03-17 19:49:45 -------- d-----w- c:\docume~1\alluse~1\applic~1\PMB Files
2011-03-17 19:49:32 -------- d-----w- c:\program files\Pando Networks
2011-03-17 17:52:54 -------- d-----w- c:\docume~1\username\locals~1\applic~1\Jaksta_Technologies_Pty_L
2011-03-17 17:50:58 -------- d-----w- c:\windows\system32\LogFiles
2011-03-17 17:50:44 -------- d-----w- c:\docume~1\username\applic~1\Replay Media Catcher 4
2011-03-17 17:50:40 -------- d-----w- c:\program files\Applian Technologies
2011-03-17 17:29:54 -------- d-----w- c:\program files\VideoLAN
2011-03-17 17:23:12 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2011-03-17 17:22:22 -------- d-----w- c:\program files\IrfanView
2011-03-17 17:14:13 11776 ----a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
2011-03-17 17:14:07 -------- d-----w- c:\program files\common files\xing shared
2011-03-17 17:14:04 150712 ----a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
2011-03-17 17:14:03 100864 ----a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
2011-03-17 17:03:22 -------- d-----w- c:\program files\Steam
2011-03-17 17:01:23 165376 ----a-w- c:\windows\system32\unrar.dll
2011-03-17 17:01:22 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-03-17 16:58:58 -------- d-----w- c:\docume~1\username\locals~1\applic~1\Apple Computer
2011-03-17 16:42:48 -------- d-----w- c:\program files\JDownloader
2011-03-17 16:39:44 -------- d-----w- c:\program files\GRETECH
2011-03-17 16:39:19 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-03-17 16:33:00 -------- d-----w- c:\program files\Gadwin Systems
2011-03-17 16:27:49 -------- d-----w- c:\program files\common files\DivX Shared
2011-03-17 16:27:37 -------- d-----w- c:\program files\DivX
2011-03-17 16:20:40 -------- d-----w- c:\docume~1\alluse~1\applic~1\DivX
2011-03-17 16:19:54 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-03-17 16:19:39 -------- d-----w- c:\docume~1\username\applic~1\DAEMON Tools Lite
2011-03-17 16:19:39 -------- d-----w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2011-03-17 16:14:37 -------- d-----w- c:\program files\BitComet
2011-03-17 16:14:37 -------- d-----w- c:\docume~1\username\applic~1\BitComet
2011-03-17 16:13:37 -------- d-----w- c:\program files\CDisplay
2011-03-17 15:53:31 -------- d-----w- c:\docume~1\username\locals~1\applic~1\Adobe
2011-03-17 15:52:30 497664 ----a-w- c:\windows\system32\ac3filter.acm
2011-03-17 15:52:29 -------- d-----w- c:\program files\AC3Filter
2011-03-17 15:38:26 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2011-03-17 15:38:26 8192 ----a-w- c:\windows\system32\kbdkor.dll
2011-03-17 15:38:26 6144 ----a-w- c:\windows\system32\kbd106.dll
2011-03-17 15:38:26 6144 ----a-w- c:\windows\system32\kbd101c.dll
2011-03-17 15:38:26 6144 ----a-w- c:\windows\system32\kbd101b.dll
2011-03-17 15:38:26 5632 ----a-w- c:\windows\system32\kbd103.dll
2011-03-17 15:27:26 -------- d-sh--w- c:\documents and settings\username\IECompatCache
2011-03-17 09:23:15 -------- d-----w- c:\program files\ATI
2011-03-17 09:22:55 -------- d-----w- c:\program files\ATI Technologies
2011-03-17 09:21:54 -------- d-----w- c:\program files\common files\Hewlett-Packard
2011-03-17 09:21:24 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-17 09:21:18 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-03-17 09:19:41 1953792 ----a-w- c:\windows\system32\xRaidSetup.exe
2011-03-17 09:19:41 143360 ----a-w- c:\windows\system32\xRaidAPI.dll
2011-03-17 09:19:39 -------- d-----w- c:\windows\RaidTool
2011-03-17 09:18:25 6912 ----a-w- c:\windows\system32\drivers\JGOGO.sys
2011-03-17 09:18:25 46208 ----a-w- c:\windows\system32\drivers\jraid.sys
2011-03-17 09:18:07 -------- d-----w- c:\windows\system32\Attansic
2011-03-17 09:18:05 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\ctor.dll
2011-03-17 09:18:05 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\DotNetInstaller.exe
2011-03-17 09:18:05 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iscript.dll
2011-03-17 09:18:05 151552 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iuser.dll
2011-03-17 09:18:05 -------- d-----w- c:\program files\Attansic
2011-03-17 09:18:04 634880 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\iKernel.dll
2011-03-17 09:18:04 270468 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\Setup.dll
2011-03-17 09:18:04 159876 ----a-w- c:\program files\common files\installshield\professional\runtime\0700\intel32\IGdi.dll
2011-03-17 09:15:27 -------- d-----w- c:\windows\system32\ReinstallBackups
2011-03-17 09:15:25 53248 ----a-w- c:\windows\system32\CSVer.dll
.
==================== Find3M ====================
.
2011-03-17 17:14:01 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-03-17 01:34:57 0 ----a-w- c:\windows\ativpsrm.bin
2011-02-03 01:40:23 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 23:19:39 73728 ----a-w- c:\windows\system32\javacpl.cpl
.
============= FINISH: 22:20:07.14 ===============