First off, I would like to say, I had a problem with GMER where it closed early, and no logs were made....I'll run it again later, and then post them. I hope that's okay, and hope that I can at least get some help with just these two.
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7298
Windows 6.1.7600 (Safe Mode)
Internet Explorer 9.0.8080.16413
7/27/2011 5:14:17 PM
mbam-log-2011-07-27 (17-14-17).txt
Scan type: Full scan (C:\|)
Objects scanned: 458713
Time elapsed: 2 hour(s), 58 minute(s), 11 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Josh\AppData\LocalLow\Sun\Java\deployment\cache\6.0\42\53ba4baa-566a60be (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\dwm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\microsoft\conhostu.exe (Trojan.Backdoor.Gen) -> Quarantined and deleted successfully.
c:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\deployment\cache\6.0\57\16998af9-4dbf3fef (Malware.Gen) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\ddee.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\mnj.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\mxd1.txt (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\ppkk.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\uuoo.dat (Malware.Trace) -> Quarantined and deleted successfully.
.
DDS (Ver_2011-06-23.01) - NTFSx86 NETWORK
Internet Explorer: 9.0.8080.16413
Run by Josh at 19:34:19 on 2011-07-27
Microsoft Windows 7 Starter 6.1.7600.0.1252.1.1033.18.1013.384 [GMT -5:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9F56A04A-4886-48F7-B8B2-376F30FC27DF} - No File
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - No File
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2348.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: @c:\program files\msn toolbar\platform\6.3.2348.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2348.0\npwinext.dll
TB: IspAssistant Add-on: {6da1e850-9f71-4b3c-81a4-d9eeef6fcd50} - c:\program files\ispassistant addon\ispassistant.DLL
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {9565115D-C7D6-46D3-BD63-B67B481A4368} - No File
TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet explorer\iedvtool.dll
uRun: [AdobeBridge]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\users\josh\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [BTMeter] c:\program files\battery meter\BTMeter.exe
mRun: [WSED] c:\program files\wsed\WSED.exe
mRun: [<NO NAME>]
mRun: [CapsLKNotify] c:\program files\capslknotify\CapsLKNotify.exe
mRun: [Dell DataSafe Online] "c:\program files\dell datasafe online\DataSafeOnline.exe" /m
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [Bing Bar] "c:\program files\msn toolbar\platform\6.3.2348.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
mRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
dPolicies-explorer: HideSCAHealth = 1 (0x1)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5}
LSP: c:\program files\speedbit video accelerator\SBLSP.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxps://members.hangame.com/common/HanSetup1040.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 68.87.75.198 68.87.64.150
TCP: Interfaces\{8140E8D1-890E-411C-9625-A58EBAB0C460} : DhcpNameServer = 68.87.75.198 68.87.64.150
TCP: Interfaces\{8140E8D1-890E-411C-9625-A58EBAB0C460}\0305652433 : DhcpNameServer = 192.168.1.1 71.242.0.12
TCP: Interfaces\{8140E8D1-890E-411C-9625-A58EBAB0C460}\35B6960737E4564777F627B6 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{8140E8D1-890E-411C-9625-A58EBAB0C460}\6657C6D65627 : DhcpNameServer = 192.168.0.1
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\program files\cozi express\CoziProtocolHandler.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R? 0218071311788613mcinstcleanup;McAfee Application Installer Cleanup (0218071311788613)
R? Akamai;Akamai NetSession Interface
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? CtClsFlt;Creative Camera Class Upper Filter Driver
R? cvhsvc;Client Virtualization Handler
R? DockLoginService;Dock Login Service
R? dump_wmimmc;dump_wmimmc
R? EagleXNt;EagleXNt
R? fssfltr;fssfltr
R? fsssvc;Windows Live Family Safety Service
R? Htsysm;Htsysm
R? JRSKD24;JRSKD24
R? MBAMSwissArmy;MBAMSwissArmy
R? mfeavfk01;McAfee Inc.
R? npggsvc;nProtect GameGuard Service
R? osppsvc;Office Software Protection Platform
R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
R? RTL8167;Realtek 8167 NT Driver
R? SASDIFSV;SASDIFSV
R? SASKUTIL;SASKUTIL
R? sdAuxService;PC Tools Auxiliary Service
R? sdCoreService;PC Tools Security Service
R? Sftfs;Sftfs
R? sftlist;Application Virtualization Client
R? Sftplay;Sftplay
R? Sftredir;Sftredir
R? SftService;SoftThinks Agent Service
R? Sftvol;Sftvol
R? sftvsa;Application Virtualization Service Agent
R? SwitchBoard;Adobe SwitchBoard
R? TabletServicePen;TabletServicePen
R? TouchServicePen;Wacom Consumer Touch Service
R? VideoAcceleratorService;VideoAcceleratorService
R? vwifimp;Microsoft Virtual WiFi Miniport Service
R? wacmoumonitor;Wacom Mode Helper
R? wlcrasvc;Windows Live Mesh remote connections service
R? XDva370;XDva370
R? XDva380;XDva380
R? XDva383;XDva383
R? XDva385;XDva385
R? XDva387;XDva387
S? EMSC;COMPAL Embedded System Control
S? PCTCore;PCTools KDS
S? pctDS;PC Tools Data Store
S? vwififlt;Virtual WiFi Filter Driver
.
=============== Created Last 30 ================
.
2011-07-25 18:10:06 -------- d-----w- c:\programdata\VirtualizedApplications
2011-07-25 15:15:34 -------- d-----w- c:\users\josh\appdata\local\SoftGrid Client
2011-07-25 15:15:16 -------- d-----w- c:\users\josh\appdata\roaming\SoftGrid Client
2011-07-25 14:58:11 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
2011-07-25 14:57:30 -------- d-----w- c:\users\josh\appdata\roaming\TP
2011-07-20 13:45:06 -------- d-----w- c:\programdata\UAB
2011-07-20 13:44:42 -------- d-----w- c:\users\josh\appdata\local\PC_Drivers_Headquarters
2011-07-20 13:44:01 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2011-07-20 13:41:50 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2011-07-15 12:15:11 -------- d-----w- c:\users\josh\appdata\roaming\WTablet
2011-07-15 06:13:05 290816 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-15 06:13:02 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-15 04:34:37 284160 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-07-15 04:34:36 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-07-15 04:34:33 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-07-15 04:34:32 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-07-15 04:34:25 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-07-15 04:34:24 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-07-15 04:34:23 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-07-15 04:32:49 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-07-15 04:32:47 1210240 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-07-15 04:32:46 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-07-15 04:32:44 1686016 ----a-w- c:\windows\system32\esent.dll
2011-07-15 04:32:43 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-07-15 04:32:42 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2011-07-15 04:32:41 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-07-15 04:32:41 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-07-15 04:32:39 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-07-13 23:23:00 -------- d-----w- c:\program files\tasofro
2011-07-13 09:28:40 2332672 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 09:19:44 169984 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 09:17:44 271872 ----a-w- c:\windows\system32\conhost.exe
2011-07-08 15:12:21 153 ----a-w- c:\users\josh\appdata\roaming\microsoft\gb_237495.bat
2011-07-08 15:06:08 135 ----a-w- c:\users\josh\appdata\roaming\microsoft\gb_536081.bat
2011-07-07 15:40:46 135 ----a-w- c:\users\josh\appdata\roaming\microsoft\gb_225327.bat
2011-07-05 08:33:56 155 ----a-w- c:\users\josh\appdata\roaming\microsoft\gb_125067233.bat
2011-06-29 16:27:36 118784 --sha-r- c:\windows\system32\normnfde.dll
2011-06-29 07:27:55 294912 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 03:34:56 1553920 ----a-w- c:\windows\system32\tquery.dll
2011-06-29 03:34:56 1401856 ----a-w- c:\windows\system32\mssrch.dll
2011-06-29 03:34:53 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-06-29 03:34:53 428032 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 03:34:53 337408 ----a-w- c:\windows\system32\mssph.dll
2011-06-29 03:34:51 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-29 03:34:51 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-06-29 03:34:51 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 03:34:50 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-06-28 18:18:10 -------- d-----w- c:\program files\IspAssistant Addon
.
==================== Find3M ====================
.
2011-07-07 00:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-07 00:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-02 03:45:49 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-06-02 03:45:49 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-02 03:45:49 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-06-02 03:45:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-05-28 00:50:30 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-23 22:20:48 23315824 ----a-w- c:\windows\system32\PenTablet_5.2.4-6.exe
2011-05-22 19:41:27 512992 ----a-w- c:\windows\system32\sdasetup_revwire207.exe
2011-05-21 07:42:21 1980928 ----a-w- c:\windows\system32\GrandChase_pando_downloader.exe
2011-05-21 05:40:40 2034176 ----a-w- c:\windows\system32\Pangya_downloader.exe
2011-05-21 03:31:03 437248 ----a-w- c:\windows\system32\paint.exe
2011-05-04 02:43:59 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-05-04 02:43:48 96256 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-05-04 02:43:41 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-05-03 04:50:29 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:57:34 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:57:21 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:57:13 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
.
============= FINISH: 19:42:44.97 ===============
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7298
Windows 6.1.7600 (Safe Mode)
Internet Explorer 9.0.8080.16413
7/27/2011 5:14:17 PM
mbam-log-2011-07-27 (17-14-17).txt
Scan type: Full scan (C:\|)
Objects scanned: 458713
Time elapsed: 2 hour(s), 58 minute(s), 11 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Josh\AppData\LocalLow\Sun\Java\deployment\cache\6.0\42\53ba4baa-566a60be (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\dwm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\microsoft\conhostu.exe (Trojan.Backdoor.Gen) -> Quarantined and deleted successfully.
c:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\deployment\cache\6.0\57\16998af9-4dbf3fef (Malware.Gen) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\ddee.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\mnj.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\mxd1.txt (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\ppkk.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\Users\Josh\AppData\Roaming\Sun\uuoo.dat (Malware.Trace) -> Quarantined and deleted successfully.
.
DDS (Ver_2011-06-23.01) - NTFSx86 NETWORK
Internet Explorer: 9.0.8080.16413
Run by Josh at 19:34:19 on 2011-07-27
Microsoft Windows 7 Starter 6.1.7600.0.1252.1.1033.18.1013.384 [GMT -5:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9F56A04A-4886-48F7-B8B2-376F30FC27DF} - No File
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - No File
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2348.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: @c:\program files\msn toolbar\platform\6.3.2348.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2348.0\npwinext.dll
TB: IspAssistant Add-on: {6da1e850-9f71-4b3c-81a4-d9eeef6fcd50} - c:\program files\ispassistant addon\ispassistant.DLL
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {9565115D-C7D6-46D3-BD63-B67B481A4368} - No File
TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet explorer\iedvtool.dll
uRun: [AdobeBridge]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\users\josh\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [BTMeter] c:\program files\battery meter\BTMeter.exe
mRun: [WSED] c:\program files\wsed\WSED.exe
mRun: [<NO NAME>]
mRun: [CapsLKNotify] c:\program files\capslknotify\CapsLKNotify.exe
mRun: [Dell DataSafe Online] "c:\program files\dell datasafe online\DataSafeOnline.exe" /m
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [Bing Bar] "c:\program files\msn toolbar\platform\6.3.2348.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
mRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
dPolicies-explorer: HideSCAHealth = 1 (0x1)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5}
LSP: c:\program files\speedbit video accelerator\SBLSP.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxps://members.hangame.com/common/HanSetup1040.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 68.87.75.198 68.87.64.150
TCP: Interfaces\{8140E8D1-890E-411C-9625-A58EBAB0C460} : DhcpNameServer = 68.87.75.198 68.87.64.150
TCP: Interfaces\{8140E8D1-890E-411C-9625-A58EBAB0C460}\0305652433 : DhcpNameServer = 192.168.1.1 71.242.0.12
TCP: Interfaces\{8140E8D1-890E-411C-9625-A58EBAB0C460}\35B6960737E4564777F627B6 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{8140E8D1-890E-411C-9625-A58EBAB0C460}\6657C6D65627 : DhcpNameServer = 192.168.0.1
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\program files\cozi express\CoziProtocolHandler.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R? 0218071311788613mcinstcleanup;McAfee Application Installer Cleanup (0218071311788613)
R? Akamai;Akamai NetSession Interface
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? CtClsFlt;Creative Camera Class Upper Filter Driver
R? cvhsvc;Client Virtualization Handler
R? DockLoginService;Dock Login Service
R? dump_wmimmc;dump_wmimmc
R? EagleXNt;EagleXNt
R? fssfltr;fssfltr
R? fsssvc;Windows Live Family Safety Service
R? Htsysm;Htsysm
R? JRSKD24;JRSKD24
R? MBAMSwissArmy;MBAMSwissArmy
R? mfeavfk01;McAfee Inc.
R? npggsvc;nProtect GameGuard Service
R? osppsvc;Office Software Protection Platform
R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
R? RTL8167;Realtek 8167 NT Driver
R? SASDIFSV;SASDIFSV
R? SASKUTIL;SASKUTIL
R? sdAuxService;PC Tools Auxiliary Service
R? sdCoreService;PC Tools Security Service
R? Sftfs;Sftfs
R? sftlist;Application Virtualization Client
R? Sftplay;Sftplay
R? Sftredir;Sftredir
R? SftService;SoftThinks Agent Service
R? Sftvol;Sftvol
R? sftvsa;Application Virtualization Service Agent
R? SwitchBoard;Adobe SwitchBoard
R? TabletServicePen;TabletServicePen
R? TouchServicePen;Wacom Consumer Touch Service
R? VideoAcceleratorService;VideoAcceleratorService
R? vwifimp;Microsoft Virtual WiFi Miniport Service
R? wacmoumonitor;Wacom Mode Helper
R? wlcrasvc;Windows Live Mesh remote connections service
R? XDva370;XDva370
R? XDva380;XDva380
R? XDva383;XDva383
R? XDva385;XDva385
R? XDva387;XDva387
S? EMSC;COMPAL Embedded System Control
S? PCTCore;PCTools KDS
S? pctDS;PC Tools Data Store
S? vwififlt;Virtual WiFi Filter Driver
.
=============== Created Last 30 ================
.
2011-07-25 18:10:06 -------- d-----w- c:\programdata\VirtualizedApplications
2011-07-25 15:15:34 -------- d-----w- c:\users\josh\appdata\local\SoftGrid Client
2011-07-25 15:15:16 -------- d-----w- c:\users\josh\appdata\roaming\SoftGrid Client
2011-07-25 14:58:11 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
2011-07-25 14:57:30 -------- d-----w- c:\users\josh\appdata\roaming\TP
2011-07-20 13:45:06 -------- d-----w- c:\programdata\UAB
2011-07-20 13:44:42 -------- d-----w- c:\users\josh\appdata\local\PC_Drivers_Headquarters
2011-07-20 13:44:01 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2011-07-20 13:41:50 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2011-07-15 12:15:11 -------- d-----w- c:\users\josh\appdata\roaming\WTablet
2011-07-15 06:13:05 290816 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-15 06:13:02 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-15 04:34:37 284160 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-07-15 04:34:36 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-07-15 04:34:33 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-07-15 04:34:32 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-07-15 04:34:25 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-07-15 04:34:24 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-07-15 04:34:23 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-07-15 04:32:49 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-07-15 04:32:47 1210240 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-07-15 04:32:46 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-07-15 04:32:44 1686016 ----a-w- c:\windows\system32\esent.dll
2011-07-15 04:32:43 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-07-15 04:32:42 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2011-07-15 04:32:41 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-07-15 04:32:41 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-07-15 04:32:39 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-07-13 23:23:00 -------- d-----w- c:\program files\tasofro
2011-07-13 09:28:40 2332672 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 09:19:44 169984 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 09:17:44 271872 ----a-w- c:\windows\system32\conhost.exe
2011-07-08 15:12:21 153 ----a-w- c:\users\josh\appdata\roaming\microsoft\gb_237495.bat
2011-07-08 15:06:08 135 ----a-w- c:\users\josh\appdata\roaming\microsoft\gb_536081.bat
2011-07-07 15:40:46 135 ----a-w- c:\users\josh\appdata\roaming\microsoft\gb_225327.bat
2011-07-05 08:33:56 155 ----a-w- c:\users\josh\appdata\roaming\microsoft\gb_125067233.bat
2011-06-29 16:27:36 118784 --sha-r- c:\windows\system32\normnfde.dll
2011-06-29 07:27:55 294912 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 03:34:56 1553920 ----a-w- c:\windows\system32\tquery.dll
2011-06-29 03:34:56 1401856 ----a-w- c:\windows\system32\mssrch.dll
2011-06-29 03:34:53 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-06-29 03:34:53 428032 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 03:34:53 337408 ----a-w- c:\windows\system32\mssph.dll
2011-06-29 03:34:51 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-29 03:34:51 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-06-29 03:34:51 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 03:34:50 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-06-28 18:18:10 -------- d-----w- c:\program files\IspAssistant Addon
.
==================== Find3M ====================
.
2011-07-07 00:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-07 00:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-02 03:45:49 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-06-02 03:45:49 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-02 03:45:49 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-06-02 03:45:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-05-28 00:50:30 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-23 22:20:48 23315824 ----a-w- c:\windows\system32\PenTablet_5.2.4-6.exe
2011-05-22 19:41:27 512992 ----a-w- c:\windows\system32\sdasetup_revwire207.exe
2011-05-21 07:42:21 1980928 ----a-w- c:\windows\system32\GrandChase_pando_downloader.exe
2011-05-21 05:40:40 2034176 ----a-w- c:\windows\system32\Pangya_downloader.exe
2011-05-21 03:31:03 437248 ----a-w- c:\windows\system32\paint.exe
2011-05-04 02:43:59 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-05-04 02:43:48 96256 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-05-04 02:43:41 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-05-03 04:50:29 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:57:34 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:57:21 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:57:13 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
.
============= FINISH: 19:42:44.97 ===============