Simon wadey
Posts: 13 +0
DDS (Ver_2012-10-19.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by siandmarg at 17:02:53 on 2012-10-24
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3583.2453 [GMT 10:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS1\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Memeo\AutoBackupPro\MemeoBackgroundService.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\WINDOWS1\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\WINDOWS1\system32\SearchIndexer.exe
C:\WINDOWS1\System32\alg.exe
C:\WINDOWS1\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS1\system32\RunDLL32.exe
C:\WINDOWS1\system32\rundll32.exe
C:\Documents and Settings\siandmarg.HOME-2B9F7C8EB0\Bluebirds\BlueBirds.exe
C:\Program Files\HP\HP Photosmart 7510 series\Bin\ScanToPCActivationApp.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\HP Photosmart 7510 series\Bin\HPNetworkCommunicator.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\All Users.WINDOWS1\Application Data\HP Photo Creations\MessageCheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS1\system32\wbem\wmiprvse.exe
C:\WINDOWS1\System32\svchost.exe -k netsvcs
C:\WINDOWS1\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS1\system32\svchost.exe -k NetworkService
C:\WINDOWS1\system32\svchost.exe -k LocalService
C:\WINDOWS1\system32\svchost.exe -k LocalService
C:\WINDOWS1\system32\svchost.exe -k imgsvc
C:\WINDOWS1\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ninemsn.com.au/
mStart Page = hxxp://www.startsearcher.com
uURLSearchHooks: <No Name>: {327f75ed-061b-4339-8cc6-5dd45ad1396d} -
BHO: SnagIt Toolbar Loader: {00C6482D-C502-44C8-8409-FCE54AD9C208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Snagit: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
uRun: [bluebirds] c:\documents and settings\siandmarg.home-2b9f7c8eb0\bluebirds\BlueBirds.exe
uRun: [HP Photosmart 7510 series (NET)] "c:\program files\hp\hp photosmart 7510 series\bin\ScanToPCActivationApp.exe" -deviceID "CN1BF244ZB05T6:NW" -scfn "HP Photosmart 7510 series (NET)" -AutoStart 1
uRun: [Facebook Update] "c:\documents and settings\siandmarg.home-2b9f7c8eb0\local settings\application data\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [ctfmon.exe] c:\windows1\system32\ctfmon.exe
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows1\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
dRun: [CTFMON.EXE] c:\windows1\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: &Search - http://tbedits.marineaquariumfree.c...A4BD-475B-9E32-70DC818D435E&n=2012102105&cv=1
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/Select/asusTek_sys_ctrl3.cab
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://biz.lgservice.com/DjvuViewer/DjVuControl-6.1.4.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1332241673640
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1328103057593
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
TCP: NameServer = 10.1.1.1
TCP: Interfaces\{FF5A8920-ABD5-48D4-BBDF-15AA465828B0} : DHCPNameServer = 10.1.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows1\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows1\system32\drivers\MpFilter.sys [2011-4-18 193552]
R0 NBVol;Nero Backup Volume Filter Driver;c:\windows1\system32\drivers\NBVol.sys [2012-2-7 56496]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows1\system32\drivers\NBVolUp.sys [2012-2-7 12464]
R2 fssfltr;FssFltr;c:\windows1\system32\drivers\fssfltr_tdi.sys [2012-4-5 54760]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-12 399432]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-6 676936]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\memeo\autobackuppro\MemeoBackgroundService.exe [2011-5-13 25824]
R2 NAUpdate;@c:\program files\nero\update\nasvc.exe,-200;c:\program files\nero\update\NASvc.exe [2011-9-23 641832]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-2-22 1258856]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\seagate\seagate dashboard\SeagateDashboardService.exe [2011-6-2 14088]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows1\system32\drivers\dc3d.sys [2012-2-6 45288]
R3 MBAMProtector;MBAMProtector;c:\windows1\system32\drivers\mbam.sys [2012-8-6 22856]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows1\system32\drivers\viahduaa.sys [2008-5-8 2127728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows1\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows1\system32\drivers\ousbehci.sys [2012-2-12 45696]
S3 1394hub;1394 Enabled Hub;c:\windows1\system32\svchost.exe -k netsvcs [2006-2-28 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows1\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-11 250808]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows1\system32\drivers\netaapl.sys [2012-6-17 18432]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows1\system32\drivers\ousb2hub.sys [2012-2-12 56960]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows1\system32\drivers\wg111v2.sys --> c:\windows1\system32\drivers\wg111v2.sys [?]
S3 ST50220;Sonix ST50220 USB Video Camera Driver;c:\windows1\system32\drivers\ST50220.sys [2008-5-29 27520]
S3 SWDUMon;SWDUMon;c:\windows1\system32\drivers\SWDUMon.sys [2012-2-11 12984]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows1\system32\svchost.exe -k WINRM [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows1\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-10-24 06:58:52 6918632 ----a-w- c:\documents and settings\all users.windows1\application data\microsoft\microsoft antimalware\definition updates\{d33c9c8f-1977-4ead-bd3c-92b8234b19e5}\mpengine.dll
2012-10-22 08:58:32 6918632 ------w- c:\documents and settings\all users.windows1\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-10-21 09:18:03 -------- d-----w- c:\documents and settings\siandmarg.home-2b9f7c8eb0\application data\Marine Aquarium Lite
2012-10-21 09:12:30 -------- d-----w- c:\program files\MarineAquarium3Free_57
2012-10-11 11:18:00 888168 ----a-w- c:\windows1\system32\nvdispgenco32.dll
2012-10-11 11:18:00 5947392 ----a-w- c:\windows1\system32\nvopencl.dll
2012-09-30 00:23:24 -------- d-----w- C:\AIROPS_MM_REL_V2010_9_1_CLIENT_LA
2012-09-29 10:45:12 -------- d-----w- c:\program files\Tansee iPhone Transfer Photo
.
==================== Find3M ====================
.
2012-10-23 10:39:14 1102256 ----a-w- c:\windows1\system32\nvdrsdb0.bin
2012-10-23 10:39:14 1 ----a-w- c:\windows1\system32\nvdrssel.bin
2012-10-23 10:39:09 1102256 ----a-w- c:\windows1\system32\nvdrsdb1.bin
2012-10-09 10:20:40 73656 ----a-w- c:\windows1\system32\FlashPlayerCPLApp.cpl
2012-10-09 10:20:40 696760 ----a-w- c:\windows1\system32\FlashPlayerApp.exe
2012-10-08 12:59:27 60 ----a-w- c:\windows1\wpd99.drv
2012-09-29 09:54:26 22856 ----a-w- c:\windows1\system32\drivers\mbam.sys
2012-09-24 05:32:24 477168 ----a-w- c:\windows1\system32\npdeployJava1.dll
2012-09-24 05:32:20 473072 ----a-w- c:\windows1\system32\deployJava1.dll
2012-09-24 03:51:47 73728 ----a-w- c:\windows1\system32\javacpl.cpl
2012-09-23 14:28:00 7446528 ----a-w- c:\windows1\system32\nvcuda.dll
2012-09-23 14:28:00 4494208 ----a-w- c:\windows1\system32\nv4_disp.dll
2012-09-23 14:28:00 2578792 ----a-w- c:\windows1\system32\nvcuvid.dll
2012-09-23 14:28:00 2376704 ----a-w- c:\windows1\system32\nvapi.dll
2012-09-23 14:28:00 19103744 ----a-w- c:\windows1\system32\nvoglnt.dll
2012-09-23 14:28:00 1866088 ----a-w- c:\windows1\system32\nvcuvenc.dll
2012-09-23 14:28:00 17551360 ----a-w- c:\windows1\system32\nvcompiler.dll
2012-09-23 14:28:00 12557728 ----a-w- c:\windows1\system32\drivers\nv4_mini.sys
2012-09-23 14:28:00 1009512 ----a-w- c:\windows1\system32\nvdispco32.dll
2012-09-23 13:04:24 54272 ----a-w- c:\windows1\system32\nvwddi.dll
2012-09-23 13:04:12 15512424 ----a-w- c:\windows1\system32\nvcpl.dll
2012-09-23 13:04:11 164200 ----a-w- c:\windows1\system32\nvsvc32.exe
2012-09-23 13:04:11 143720 ----a-w- c:\windows1\system32\nvcolor.exe
2012-09-23 13:04:11 108392 ----a-w- c:\windows1\system32\nvmctray.dll
2012-09-08 08:48:42 12984 ----a-w- c:\windows1\system32\drivers\SWDUMon.sys
2012-08-30 12:03:50 193552 ----a-w- c:\windows1\system32\drivers\MpFilter.sys
2012-08-28 15:14:53 916992 ----a-w- c:\windows1\system32\wininet.dll
2012-08-28 15:14:53 43520 ----a-w- c:\windows1\system32\licmgr10.dll
2012-08-28 15:14:52 1469440 ----a-w- c:\windows1\system32\inetcpl.cpl
2012-08-28 12:07:15 385024 ----a-w- c:\windows1\system32\html.iec
2012-08-24 13:53:22 177664 ----a-w- c:\windows1\system32\wintrust.dll
2012-08-21 13:33:26 2148864 ----a-w- c:\windows1\system32\ntoskrnl.exe
2012-08-21 12:58:09 2027520 ----a-w- c:\windows1\system32\ntkrnlpa.exe
2012-08-21 03:01:22 26840 ----a-w- c:\windows1\system32\drivers\GEARAspiWDM.sys
2012-08-21 03:01:22 106928 ----a-w- c:\windows1\system32\GEARAspi.dll
.
============= FINISH: 17:04:21.48 ===============
Internet Explorer: 8.0.6001.18702
Run by siandmarg at 17:02:53 on 2012-10-24
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3583.2453 [GMT 10:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS1\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Memeo\AutoBackupPro\MemeoBackgroundService.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\WINDOWS1\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\WINDOWS1\system32\SearchIndexer.exe
C:\WINDOWS1\System32\alg.exe
C:\WINDOWS1\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS1\system32\RunDLL32.exe
C:\WINDOWS1\system32\rundll32.exe
C:\Documents and Settings\siandmarg.HOME-2B9F7C8EB0\Bluebirds\BlueBirds.exe
C:\Program Files\HP\HP Photosmart 7510 series\Bin\ScanToPCActivationApp.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\HP Photosmart 7510 series\Bin\HPNetworkCommunicator.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\All Users.WINDOWS1\Application Data\HP Photo Creations\MessageCheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS1\system32\wbem\wmiprvse.exe
C:\WINDOWS1\System32\svchost.exe -k netsvcs
C:\WINDOWS1\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS1\system32\svchost.exe -k NetworkService
C:\WINDOWS1\system32\svchost.exe -k LocalService
C:\WINDOWS1\system32\svchost.exe -k LocalService
C:\WINDOWS1\system32\svchost.exe -k imgsvc
C:\WINDOWS1\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ninemsn.com.au/
mStart Page = hxxp://www.startsearcher.com
uURLSearchHooks: <No Name>: {327f75ed-061b-4339-8cc6-5dd45ad1396d} -
BHO: SnagIt Toolbar Loader: {00C6482D-C502-44C8-8409-FCE54AD9C208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Snagit: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
uRun: [bluebirds] c:\documents and settings\siandmarg.home-2b9f7c8eb0\bluebirds\BlueBirds.exe
uRun: [HP Photosmart 7510 series (NET)] "c:\program files\hp\hp photosmart 7510 series\bin\ScanToPCActivationApp.exe" -deviceID "CN1BF244ZB05T6:NW" -scfn "HP Photosmart 7510 series (NET)" -AutoStart 1
uRun: [Facebook Update] "c:\documents and settings\siandmarg.home-2b9f7c8eb0\local settings\application data\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [ctfmon.exe] c:\windows1\system32\ctfmon.exe
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows1\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
dRun: [CTFMON.EXE] c:\windows1\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: &Search - http://tbedits.marineaquariumfree.c...A4BD-475B-9E32-70DC818D435E&n=2012102105&cv=1
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/Select/asusTek_sys_ctrl3.cab
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://biz.lgservice.com/DjvuViewer/DjVuControl-6.1.4.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1332241673640
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1328103057593
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
TCP: NameServer = 10.1.1.1
TCP: Interfaces\{FF5A8920-ABD5-48D4-BBDF-15AA465828B0} : DHCPNameServer = 10.1.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows1\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows1\system32\drivers\MpFilter.sys [2011-4-18 193552]
R0 NBVol;Nero Backup Volume Filter Driver;c:\windows1\system32\drivers\NBVol.sys [2012-2-7 56496]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows1\system32\drivers\NBVolUp.sys [2012-2-7 12464]
R2 fssfltr;FssFltr;c:\windows1\system32\drivers\fssfltr_tdi.sys [2012-4-5 54760]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-12 399432]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-6 676936]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\memeo\autobackuppro\MemeoBackgroundService.exe [2011-5-13 25824]
R2 NAUpdate;@c:\program files\nero\update\nasvc.exe,-200;c:\program files\nero\update\NASvc.exe [2011-9-23 641832]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-2-22 1258856]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\seagate\seagate dashboard\SeagateDashboardService.exe [2011-6-2 14088]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows1\system32\drivers\dc3d.sys [2012-2-6 45288]
R3 MBAMProtector;MBAMProtector;c:\windows1\system32\drivers\mbam.sys [2012-8-6 22856]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows1\system32\drivers\viahduaa.sys [2008-5-8 2127728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows1\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows1\system32\drivers\ousbehci.sys [2012-2-12 45696]
S3 1394hub;1394 Enabled Hub;c:\windows1\system32\svchost.exe -k netsvcs [2006-2-28 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows1\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-11 250808]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows1\system32\drivers\netaapl.sys [2012-6-17 18432]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows1\system32\drivers\ousb2hub.sys [2012-2-12 56960]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows1\system32\drivers\wg111v2.sys --> c:\windows1\system32\drivers\wg111v2.sys [?]
S3 ST50220;Sonix ST50220 USB Video Camera Driver;c:\windows1\system32\drivers\ST50220.sys [2008-5-29 27520]
S3 SWDUMon;SWDUMon;c:\windows1\system32\drivers\SWDUMon.sys [2012-2-11 12984]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows1\system32\svchost.exe -k WINRM [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows1\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-10-24 06:58:52 6918632 ----a-w- c:\documents and settings\all users.windows1\application data\microsoft\microsoft antimalware\definition updates\{d33c9c8f-1977-4ead-bd3c-92b8234b19e5}\mpengine.dll
2012-10-22 08:58:32 6918632 ------w- c:\documents and settings\all users.windows1\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-10-21 09:18:03 -------- d-----w- c:\documents and settings\siandmarg.home-2b9f7c8eb0\application data\Marine Aquarium Lite
2012-10-21 09:12:30 -------- d-----w- c:\program files\MarineAquarium3Free_57
2012-10-11 11:18:00 888168 ----a-w- c:\windows1\system32\nvdispgenco32.dll
2012-10-11 11:18:00 5947392 ----a-w- c:\windows1\system32\nvopencl.dll
2012-09-30 00:23:24 -------- d-----w- C:\AIROPS_MM_REL_V2010_9_1_CLIENT_LA
2012-09-29 10:45:12 -------- d-----w- c:\program files\Tansee iPhone Transfer Photo
.
==================== Find3M ====================
.
2012-10-23 10:39:14 1102256 ----a-w- c:\windows1\system32\nvdrsdb0.bin
2012-10-23 10:39:14 1 ----a-w- c:\windows1\system32\nvdrssel.bin
2012-10-23 10:39:09 1102256 ----a-w- c:\windows1\system32\nvdrsdb1.bin
2012-10-09 10:20:40 73656 ----a-w- c:\windows1\system32\FlashPlayerCPLApp.cpl
2012-10-09 10:20:40 696760 ----a-w- c:\windows1\system32\FlashPlayerApp.exe
2012-10-08 12:59:27 60 ----a-w- c:\windows1\wpd99.drv
2012-09-29 09:54:26 22856 ----a-w- c:\windows1\system32\drivers\mbam.sys
2012-09-24 05:32:24 477168 ----a-w- c:\windows1\system32\npdeployJava1.dll
2012-09-24 05:32:20 473072 ----a-w- c:\windows1\system32\deployJava1.dll
2012-09-24 03:51:47 73728 ----a-w- c:\windows1\system32\javacpl.cpl
2012-09-23 14:28:00 7446528 ----a-w- c:\windows1\system32\nvcuda.dll
2012-09-23 14:28:00 4494208 ----a-w- c:\windows1\system32\nv4_disp.dll
2012-09-23 14:28:00 2578792 ----a-w- c:\windows1\system32\nvcuvid.dll
2012-09-23 14:28:00 2376704 ----a-w- c:\windows1\system32\nvapi.dll
2012-09-23 14:28:00 19103744 ----a-w- c:\windows1\system32\nvoglnt.dll
2012-09-23 14:28:00 1866088 ----a-w- c:\windows1\system32\nvcuvenc.dll
2012-09-23 14:28:00 17551360 ----a-w- c:\windows1\system32\nvcompiler.dll
2012-09-23 14:28:00 12557728 ----a-w- c:\windows1\system32\drivers\nv4_mini.sys
2012-09-23 14:28:00 1009512 ----a-w- c:\windows1\system32\nvdispco32.dll
2012-09-23 13:04:24 54272 ----a-w- c:\windows1\system32\nvwddi.dll
2012-09-23 13:04:12 15512424 ----a-w- c:\windows1\system32\nvcpl.dll
2012-09-23 13:04:11 164200 ----a-w- c:\windows1\system32\nvsvc32.exe
2012-09-23 13:04:11 143720 ----a-w- c:\windows1\system32\nvcolor.exe
2012-09-23 13:04:11 108392 ----a-w- c:\windows1\system32\nvmctray.dll
2012-09-08 08:48:42 12984 ----a-w- c:\windows1\system32\drivers\SWDUMon.sys
2012-08-30 12:03:50 193552 ----a-w- c:\windows1\system32\drivers\MpFilter.sys
2012-08-28 15:14:53 916992 ----a-w- c:\windows1\system32\wininet.dll
2012-08-28 15:14:53 43520 ----a-w- c:\windows1\system32\licmgr10.dll
2012-08-28 15:14:52 1469440 ----a-w- c:\windows1\system32\inetcpl.cpl
2012-08-28 12:07:15 385024 ----a-w- c:\windows1\system32\html.iec
2012-08-24 13:53:22 177664 ----a-w- c:\windows1\system32\wintrust.dll
2012-08-21 13:33:26 2148864 ----a-w- c:\windows1\system32\ntoskrnl.exe
2012-08-21 12:58:09 2027520 ----a-w- c:\windows1\system32\ntkrnlpa.exe
2012-08-21 03:01:22 26840 ----a-w- c:\windows1\system32\drivers\GEARAspiWDM.sys
2012-08-21 03:01:22 106928 ----a-w- c:\windows1\system32\GEARAspi.dll
.
============= FINISH: 17:04:21.48 ===============