Hi its happening to me i have been browsing the net in order to find the right answer and decipher thew all the info that everyone has posted and still no luck. I nee help i have win7 32bit also using firefox . i did the MBR check.
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: Gigabyte Technology Co., Ltd.
BIOS Manufacturer: Award Software International, Inc.
System Manufacturer: Gigabyte Technology Co., Ltd.
System Product Name: P55A-UD3
Logical Drives Mask: 0x0000001d
Kernel Drivers (total 197):
0x8300D000 \SystemRoot\system32\ntkrnlpa.exe
0x8341D000 \SystemRoot\system32\halmacpi.dll
0x80BC2000 \SystemRoot\system32\kdcom.dll
0x83614000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8368C000 \SystemRoot\system32\PSHED.dll
0x8369D000 \SystemRoot\system32\BOOTVID.dll
0x836A5000 \SystemRoot\system32\CLFS.SYS
0x836E7000 \SystemRoot\system32\CI.dll
0x8C813000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8C884000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8C97C000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x8C985000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x8C9AB000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x8C9F3000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x8C800000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x83792000 \SystemRoot\system32\DRIVERS\pci.sys
0x837BC000 \SystemRoot\System32\drivers\partmgr.sys
0x837CD000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x8CA04000 \SystemRoot\System32\drivers\volmgrx.sys
0x8CA4F000 \SystemRoot\system32\DRIVERS\pciide.sys
0x8CA56000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x8CA64000 \SystemRoot\system32\DRIVERS\mv91cons.sys
0x8CA6D000 \SystemRoot\System32\drivers\mountmgr.sys
0x8CA83000 \SystemRoot\system32\DRIVERS\atapi.sys
0x8CA8C000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x8CAAF000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8CAB8000 \SystemRoot\system32\drivers\fltmgr.sys
0x8CAEC000 \SystemRoot\system32\drivers\fileinfo.sys
0x8CC33000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8CD62000 \SystemRoot\System32\Drivers\msrpc.sys
0x8CD8D000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8CDA0000 \SystemRoot\System32\Drivers\cng.sys
0x8CC00000 \SystemRoot\System32\drivers\pcw.sys
0x8CC0E000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8CAFD000 \SystemRoot\system32\drivers\ndis.sys
0x8CBB4000 \SystemRoot\system32\drivers\NETIO.SYS
0x8CE33000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8CE58000 \SystemRoot\System32\drivers\tcpip.sys
0x8CFA1000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8CFD2000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x8D003000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8D042000 \SystemRoot\System32\Drivers\spldr.sys
0x8D04A000 \SystemRoot\System32\drivers\rdyboost.sys
0x8D077000 \SystemRoot\System32\Drivers\mup.sys
0x8D087000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8D08F000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8D0C1000 \SystemRoot\system32\DRIVERS\disk.sys
0x8D0D2000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8D129000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8D148000 \SystemRoot\System32\Drivers\Null.SYS
0x8D14F000 \SystemRoot\System32\Drivers\Beep.SYS
0x8D156000 \SystemRoot\System32\drivers\vga.sys
0x8D162000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8D183000 \SystemRoot\System32\drivers\watchdog.sys
0x8D190000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8D198000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8D1A0000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8D1A8000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8D1B3000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8D1C1000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8D1D8000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8C892000 \SystemRoot\system32\drivers\afd.sys
0x8CE00000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8D1E3000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8CFDB000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8D1EA000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8CC17000 \SystemRoot\system32\DRIVERS\serial.sys
0x8C8EC000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8C8FF000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8C90F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8CBF2000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8C950000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8C95A000 \??\C:\Program Files\UltraISO\drivers\ISODrive.sys
0x837DD000 \SystemRoot\System32\drivers\discache.sys
0x92627000 \SystemRoot\system32\drivers\csc.sys
0x9268B000 \SystemRoot\System32\Drivers\dfsc.sys
0x926A3000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x926B1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x926D2000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x926E4000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x926EF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x9273A000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x92749000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x92768000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x9279A000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
0x927BC000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x927BE000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x9303D000 \SystemRoot\system32\DRIVERS\atipmdag.sys
0x92A09000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x92AC0000 \SystemRoot\System32\drivers\dxgmms1.sys
0x92AF9000 \SystemRoot\system32\DRIVERS\fdc.sys
0x92B04000 \SystemRoot\system32\DRIVERS\serenum.sys
0x92B0E000 \SystemRoot\system32\DRIVERS\parport.sys
0x92B26000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x92B2C000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x92B39000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x92B4B000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x92B63000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x92B6E000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x92B90000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x92BA8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x92BBF000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x92BD6000 \SystemRoot\System32\Drivers\pcouffin.sys
0x92BE2000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x92BEC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x9357E000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x92BF9000 \SystemRoot\system32\DRIVERS\swenum.sys
0x93000000 \SystemRoot\system32\DRIVERS\ks.sys
0x92BFB000 \SystemRoot\system32\drivers\LGBusEnum.sys
0x9358B000 \SystemRoot\system32\DRIVERS\umbus.sys
0x93599000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x935DD000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
0x935EB000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x927E2000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x82009000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x822AC000 \SystemRoot\system32\drivers\portcls.sys
0x822DB000 \SystemRoot\system32\drivers\drmk.sys
0x822F4000 \SystemRoot\system32\drivers\AtiHdmi.sys
0x82620000 \SystemRoot\System32\win32k.sys
0x82311000 \SystemRoot\System32\drivers\Dxapi.sys
0x8231B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x82880000 \SystemRoot\System32\TSDDD.dll
0x828B0000 \SystemRoot\System32\ATMFD.DLL
0x82900000 \SystemRoot\System32\cdd.dll
0x82326000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8233D000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x82348000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8235B000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x82362000 \SystemRoot\system32\drivers\luafv.sys
0x8237D000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x82389000 \SystemRoot\system32\drivers\WudfPf.sys
0x823A3000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x823AE000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x823CF000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x823DF000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9963B000 \SystemRoot\system32\drivers\HTTP.sys
0x996C0000 \SystemRoot\system32\DRIVERS\bowser.sys
0x996D9000 \SystemRoot\System32\drivers\mpsdrv.sys
0x996EB000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9970E000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x99749000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x99764000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x9B222000 \SystemRoot\system32\drivers\peauth.sys
0x9B2B9000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9B2C3000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9B2E4000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9B35B000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9B3AA000 \SystemRoot\system32\DRIVERS\udfs.sys
0x9976B000 \SystemRoot\System32\DRIVERS\srv.sys
0x9B3EA000 \SystemRoot\System32\Drivers\crashdmp.sys
0x9B200000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x9B20B000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x997BC000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x997CD000 \SystemRoot\System32\drivers\rdpdr.sys
0x9B214000 \SystemRoot\system32\drivers\tdtcp.sys
0x997F2000 \SystemRoot\System32\DRIVERS\tssecsrv.sys
0x99600000 \SystemRoot\System32\Drivers\RDPWD.SYS
0x9B21E000 \SystemRoot\system32\drivers\LGVirHid.sys
0x77960000 \Windows\System32\ntdll.dll
0x47CD0000 \Windows\System32\smss.exe
0x77BA0000 \Windows\System32\apisetschema.dll
0x00DB0000 \Windows\System32\autochk.exe
0x77B80000 \Windows\System32\nsi.dll
0x77B60000 \Windows\System32\sechost.dll
0x77B40000 \Windows\System32\imm32.dll
0x77890000 \Windows\System32\msctf.dll
0x77AC0000 \Windows\System32\comdlg32.dll
0x77690000 \Windows\System32\iertutil.dll
0x77AB0000 \Windows\System32\psapi.dll
0x77590000 \Windows\System32\wininet.dll
0x77530000 \Windows\System32\difxapi.dll
0x77480000 \Windows\System32\rpcrt4.dll
0x77340000 \Windows\System32\urlmon.dll
0x77310000 \Windows\System32\imagehlp.dll
0x77AA0000 \Windows\System32\lpk.dll
0x77230000 \Windows\System32\kernel32.dll
0x77160000 \Windows\System32\user32.dll
0x77110000 \Windows\System32\gdi32.dll
0x77060000 \Windows\System32\msvcrt.dll
0x77020000 \Windows\System32\ws2_32.dll
0x76EC0000 \Windows\System32\ole32.dll
0x76270000 \Windows\System32\shell32.dll
0x760D0000 \Windows\System32\setupapi.dll
0x76030000 \Windows\System32\advapi32.dll
0x75F90000 \Windows\System32\usp10.dll
0x75F30000 \Windows\System32\shlwapi.dll
0x75EE0000 \Windows\System32\Wldap32.dll
0x75ED0000 \Windows\System32\normaliz.dll
0x75E40000 \Windows\System32\clbcatq.dll
0x75DB0000 \Windows\System32\oleaut32.dll
0x75C90000 \Windows\System32\crypt32.dll
0x75C60000 \Windows\System32\cfgmgr32.dll
0x75C30000 \Windows\System32\wintrust.dll
0x75C10000 \Windows\System32\devobj.dll
0x75BC0000 \Windows\System32\KernelBase.dll
0x75B30000 \Windows\System32\comctl32.dll
0x75B20000 \Windows\System32\msasn1.dll
Processes (total 51):
0 System Idle Process
4 System
316 C:\Windows\System32\smss.exe
460 csrss.exe
532 C:\Windows\System32\wininit.exe
540 csrss.exe
584 C:\Windows\System32\services.exe
592 C:\Windows\System32\lsass.exe
600 C:\Windows\System32\lsm.exe
704 C:\Windows\System32\svchost.exe
784 C:\Windows\System32\winlogon.exe
836 C:\Windows\System32\svchost.exe
920 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1024 C:\Windows\System32\svchost.exe
1108 C:\Windows\System32\audiodg.exe
1168 C:\Windows\System32\svchost.exe
1268 WUDFHost.exe
1320 WUDFHost.exe
1396 C:\Windows\System32\svchost.exe
1516 C:\Windows\System32\spoolsv.exe
1544 C:\Windows\System32\svchost.exe
1660 C:\Windows\System32\svchost.exe
1768 C:\Windows\System32\svchost.exe
2116 C:\Windows\System32\dwm.exe
2124 C:\Windows\System32\taskhost.exe
2260 C:\Windows\explorer.exe
2460 C:\Windows\SOUNDMAN.EXE
2488 C:\Windows\System32\svchost.exe
2540 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
2592 C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
2648 C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
2716 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
2744 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
2772 C:\Windows\System32\rundll32.exe
2788 C:\Program Files\Steam\steam.exe
2968 C:\Program Files\Logitech\GamePanel Software\Applets\LCDSirReal.exe
3160 C:\Windows\System32\SearchIndexer.exe
3268 C:\Program Files\Windows Media Player\wmpnetwk.exe
3580 C:\Windows\System32\svchost.exe
4068 C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
2372 C:\Program Files\Windows Media Player\wmplayer.exe
3328 taskhost.exe
3256 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
3892 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
1656 C:\Windows\System32\svchost.exe
3916 C:\Windows\System32\wuauclt.exe
2444 C:\Program Files\Mozilla Firefox\firefox.exe
3572 C:\Users\Darmentle\Desktop\mal\MBRCheck.exe
2080 C:\Windows\System32\conhost.exe
404 C:\Windows\System32\dllhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
PhysicalDrive0 Model Number: WDCWD2000BB-22RDA0, Rev: 20.00K20
Size Device Name MBR Status
--------------------------------------------
186 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
------------------------------------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5363
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
1/7/2011 7:42:33 PM
mbam-log-2011-01-07 (19-42-33).txt
Scan type: Quick scan
Objects scanned: 143932
Time elapsed: 4 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
-----------------------------------------------------------------------------------------------------------------------------------------------------------------
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-07 20:20:59
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 WDC_WD2000BB-22RDA0 rev.20.00K20
Running: 7yeu6h2f.exe; Driver: C:\Users\DARMEN~1\AppData\Local\Temp\pfkiifog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateProcess [0x8CD31F68]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateProcessEx [0x8CD32230]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateUserProcess [0x8CD3252C]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwTerminateProcess [0x8CD319D8]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 83088599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830ACF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 32C 830B483C 8 Bytes [68, 1F, D3, 8C, 30, 22, D3, ...]
.text ntkrnlpa.exe!RtlSidHashLookup + 364 830B4874 4 Bytes [2C, 25, D3, 8C]
.text ntkrnlpa.exe!RtlSidHashLookup + 7B8 830B4CC8 4 Bytes [D8, 19, D3, 8C]
? system32\drivers\PCTCore.sys The system cannot find the path specified. !
? system32\drivers\pctDS.sys The system cannot find the path specified. !
? system32\drivers\pctEFA.sys The system cannot find the path specified. !
.text C:\Windows\system32\DRIVERS\atipmdag.sys section is writeable [0x93422000, 0x2D1F8A, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipAlloc] [74862494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusStartup] [74845624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusShutdown] [748456E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipFree] [7486250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDeleteGraphics] [74858573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDisposeImage] [74854D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageWidth] [748550CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageHeight] [748551A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [748566D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateFromHDC] [748582CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetCompositingMode] [74858819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetInterpolationMode] [7485907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDrawImageRectI] [7485E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCloneImage] [74854C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[2668] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[2668] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[2668] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[2668] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[4024] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[4024] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[4024] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[4024] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
----------------------------------------------------------------------------------------------------
DDS (Ver_10-12-12.02) - NTFSx86
Run by Darmentle at 20:27:44.84 on Fri 01/07/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3579.2367 [GMT -8:00]
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\rundll32.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Darmentle\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uURLSearchHooks: H - No File
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
uRun: [PlayNC Launcher]
uRun: [fxCommonInit] rundll32.exe "c:\users\darmentle\appdata\local\acroauthenticationsnap\fxCommonInit.dll",CdMouseOffice tapiWISupport
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [NUSB3MON] "c:\program files\nec electronics\usb 3.0 host controller driver\application\nusb3mon.exe"
mRun: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
================= FIREFOX ===================
FF - ProfilePath - c:\users\darmen~1\appdata\roaming\mozilla\firefox\profiles\j0j6bb43.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Aluminium Kai 2: {a45e6b3a-725d-4b20-afde-e7486bfe317c} - %profile%\extensions\{a45e6b3a-725d-4b20-afde-e7486bfe317c}
============= SERVICES / DRIVERS ===============
R0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\drivers\mv91cons.sys [2009-10-9 20008]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2009-12-11 5188096]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2009-12-11 125440]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2009-9-25 56576]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2009-9-25 138240]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-2-12 189440]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-11 172032]
=============== Created Last 30 ================
2011-01-08 03:38:22 -------- d-----w- c:\users\darmen~1\appdata\roaming\Malwarebytes
2011-01-08 03:38:17 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-08 03:38:17 -------- d-----w- c:\progra~2\Malwarebytes
2011-01-08 03:38:14 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-08 03:38:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-08 02:16:34 -------- d-----w- C:\New folder (2)
2011-01-08 02:16:33 -------- d-----w- C:\New folder
2011-01-05 05:28:17 -------- d-----w- c:\program files\PC Tools Security
2011-01-05 05:28:17 -------- d-----w- c:\program files\common files\PC Tools
2011-01-05 03:52:22 -------- d-----w- c:\users\darmen~1\appdata\local\Activision
2010-12-31 21:59:31 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{5150af31-9583-4545-a2de-21c9390a1f2f}\mpengine.dll
2010-12-31 21:55:27 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-12-11 17:03:59 -------- d-----w- c:\users\darmen~1\appdata\local\AcroAuthenticationSnap
==================== Find3M ====================
2010-11-04 05:52:17 978944 ----a-w- c:\windows\system32\wininet.dll
2010-11-04 05:48:36 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-04 04:41:26 386048 ----a-w- c:\windows\system32\html.iec
2010-11-04 04:08:54 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-11-02 04:41:12 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-02 04:40:36 496128 ----a-w- c:\windows\system32\taskschd.dll
2010-11-02 04:40:36 305152 ----a-w- c:\windows\system32\taskcomp.dll
2010-11-02 04:39:32 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34:44 192000 ----a-w- c:\windows\system32\taskeng.exe
2010-11-02 04:34:33 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-27 04:32:36 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-20 04:54:18 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-20 02:58:41 294400 ----a-w- c:\windows\system32\atmfd.dll
2010-10-19 18:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-16 04:41:02 101760 ----a-w- c:\windows\system32\consent.exe
2010-10-16 04:36:10 314368 ----a-w- c:\windows\system32\webio.dll
============= FINISH: 20:27:57.94 ===============
I hope i did this the way it needs to go.
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: Gigabyte Technology Co., Ltd.
BIOS Manufacturer: Award Software International, Inc.
System Manufacturer: Gigabyte Technology Co., Ltd.
System Product Name: P55A-UD3
Logical Drives Mask: 0x0000001d
Kernel Drivers (total 197):
0x8300D000 \SystemRoot\system32\ntkrnlpa.exe
0x8341D000 \SystemRoot\system32\halmacpi.dll
0x80BC2000 \SystemRoot\system32\kdcom.dll
0x83614000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8368C000 \SystemRoot\system32\PSHED.dll
0x8369D000 \SystemRoot\system32\BOOTVID.dll
0x836A5000 \SystemRoot\system32\CLFS.SYS
0x836E7000 \SystemRoot\system32\CI.dll
0x8C813000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8C884000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8C97C000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x8C985000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x8C9AB000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x8C9F3000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x8C800000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x83792000 \SystemRoot\system32\DRIVERS\pci.sys
0x837BC000 \SystemRoot\System32\drivers\partmgr.sys
0x837CD000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x8CA04000 \SystemRoot\System32\drivers\volmgrx.sys
0x8CA4F000 \SystemRoot\system32\DRIVERS\pciide.sys
0x8CA56000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x8CA64000 \SystemRoot\system32\DRIVERS\mv91cons.sys
0x8CA6D000 \SystemRoot\System32\drivers\mountmgr.sys
0x8CA83000 \SystemRoot\system32\DRIVERS\atapi.sys
0x8CA8C000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x8CAAF000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8CAB8000 \SystemRoot\system32\drivers\fltmgr.sys
0x8CAEC000 \SystemRoot\system32\drivers\fileinfo.sys
0x8CC33000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8CD62000 \SystemRoot\System32\Drivers\msrpc.sys
0x8CD8D000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8CDA0000 \SystemRoot\System32\Drivers\cng.sys
0x8CC00000 \SystemRoot\System32\drivers\pcw.sys
0x8CC0E000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8CAFD000 \SystemRoot\system32\drivers\ndis.sys
0x8CBB4000 \SystemRoot\system32\drivers\NETIO.SYS
0x8CE33000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8CE58000 \SystemRoot\System32\drivers\tcpip.sys
0x8CFA1000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8CFD2000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x8D003000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8D042000 \SystemRoot\System32\Drivers\spldr.sys
0x8D04A000 \SystemRoot\System32\drivers\rdyboost.sys
0x8D077000 \SystemRoot\System32\Drivers\mup.sys
0x8D087000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8D08F000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8D0C1000 \SystemRoot\system32\DRIVERS\disk.sys
0x8D0D2000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8D129000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8D148000 \SystemRoot\System32\Drivers\Null.SYS
0x8D14F000 \SystemRoot\System32\Drivers\Beep.SYS
0x8D156000 \SystemRoot\System32\drivers\vga.sys
0x8D162000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8D183000 \SystemRoot\System32\drivers\watchdog.sys
0x8D190000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8D198000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8D1A0000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8D1A8000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8D1B3000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8D1C1000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8D1D8000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8C892000 \SystemRoot\system32\drivers\afd.sys
0x8CE00000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8D1E3000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8CFDB000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8D1EA000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8CC17000 \SystemRoot\system32\DRIVERS\serial.sys
0x8C8EC000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8C8FF000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8C90F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8CBF2000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8C950000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8C95A000 \??\C:\Program Files\UltraISO\drivers\ISODrive.sys
0x837DD000 \SystemRoot\System32\drivers\discache.sys
0x92627000 \SystemRoot\system32\drivers\csc.sys
0x9268B000 \SystemRoot\System32\Drivers\dfsc.sys
0x926A3000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x926B1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x926D2000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x926E4000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x926EF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x9273A000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x92749000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x92768000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x9279A000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
0x927BC000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x927BE000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x9303D000 \SystemRoot\system32\DRIVERS\atipmdag.sys
0x92A09000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x92AC0000 \SystemRoot\System32\drivers\dxgmms1.sys
0x92AF9000 \SystemRoot\system32\DRIVERS\fdc.sys
0x92B04000 \SystemRoot\system32\DRIVERS\serenum.sys
0x92B0E000 \SystemRoot\system32\DRIVERS\parport.sys
0x92B26000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x92B2C000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x92B39000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x92B4B000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x92B63000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x92B6E000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x92B90000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x92BA8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x92BBF000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x92BD6000 \SystemRoot\System32\Drivers\pcouffin.sys
0x92BE2000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x92BEC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x9357E000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x92BF9000 \SystemRoot\system32\DRIVERS\swenum.sys
0x93000000 \SystemRoot\system32\DRIVERS\ks.sys
0x92BFB000 \SystemRoot\system32\drivers\LGBusEnum.sys
0x9358B000 \SystemRoot\system32\DRIVERS\umbus.sys
0x93599000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x935DD000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
0x935EB000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x927E2000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x82009000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x822AC000 \SystemRoot\system32\drivers\portcls.sys
0x822DB000 \SystemRoot\system32\drivers\drmk.sys
0x822F4000 \SystemRoot\system32\drivers\AtiHdmi.sys
0x82620000 \SystemRoot\System32\win32k.sys
0x82311000 \SystemRoot\System32\drivers\Dxapi.sys
0x8231B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x82880000 \SystemRoot\System32\TSDDD.dll
0x828B0000 \SystemRoot\System32\ATMFD.DLL
0x82900000 \SystemRoot\System32\cdd.dll
0x82326000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8233D000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x82348000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8235B000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x82362000 \SystemRoot\system32\drivers\luafv.sys
0x8237D000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x82389000 \SystemRoot\system32\drivers\WudfPf.sys
0x823A3000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x823AE000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x823CF000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x823DF000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9963B000 \SystemRoot\system32\drivers\HTTP.sys
0x996C0000 \SystemRoot\system32\DRIVERS\bowser.sys
0x996D9000 \SystemRoot\System32\drivers\mpsdrv.sys
0x996EB000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9970E000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x99749000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x99764000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x9B222000 \SystemRoot\system32\drivers\peauth.sys
0x9B2B9000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9B2C3000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9B2E4000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9B35B000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9B3AA000 \SystemRoot\system32\DRIVERS\udfs.sys
0x9976B000 \SystemRoot\System32\DRIVERS\srv.sys
0x9B3EA000 \SystemRoot\System32\Drivers\crashdmp.sys
0x9B200000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x9B20B000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x997BC000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x997CD000 \SystemRoot\System32\drivers\rdpdr.sys
0x9B214000 \SystemRoot\system32\drivers\tdtcp.sys
0x997F2000 \SystemRoot\System32\DRIVERS\tssecsrv.sys
0x99600000 \SystemRoot\System32\Drivers\RDPWD.SYS
0x9B21E000 \SystemRoot\system32\drivers\LGVirHid.sys
0x77960000 \Windows\System32\ntdll.dll
0x47CD0000 \Windows\System32\smss.exe
0x77BA0000 \Windows\System32\apisetschema.dll
0x00DB0000 \Windows\System32\autochk.exe
0x77B80000 \Windows\System32\nsi.dll
0x77B60000 \Windows\System32\sechost.dll
0x77B40000 \Windows\System32\imm32.dll
0x77890000 \Windows\System32\msctf.dll
0x77AC0000 \Windows\System32\comdlg32.dll
0x77690000 \Windows\System32\iertutil.dll
0x77AB0000 \Windows\System32\psapi.dll
0x77590000 \Windows\System32\wininet.dll
0x77530000 \Windows\System32\difxapi.dll
0x77480000 \Windows\System32\rpcrt4.dll
0x77340000 \Windows\System32\urlmon.dll
0x77310000 \Windows\System32\imagehlp.dll
0x77AA0000 \Windows\System32\lpk.dll
0x77230000 \Windows\System32\kernel32.dll
0x77160000 \Windows\System32\user32.dll
0x77110000 \Windows\System32\gdi32.dll
0x77060000 \Windows\System32\msvcrt.dll
0x77020000 \Windows\System32\ws2_32.dll
0x76EC0000 \Windows\System32\ole32.dll
0x76270000 \Windows\System32\shell32.dll
0x760D0000 \Windows\System32\setupapi.dll
0x76030000 \Windows\System32\advapi32.dll
0x75F90000 \Windows\System32\usp10.dll
0x75F30000 \Windows\System32\shlwapi.dll
0x75EE0000 \Windows\System32\Wldap32.dll
0x75ED0000 \Windows\System32\normaliz.dll
0x75E40000 \Windows\System32\clbcatq.dll
0x75DB0000 \Windows\System32\oleaut32.dll
0x75C90000 \Windows\System32\crypt32.dll
0x75C60000 \Windows\System32\cfgmgr32.dll
0x75C30000 \Windows\System32\wintrust.dll
0x75C10000 \Windows\System32\devobj.dll
0x75BC0000 \Windows\System32\KernelBase.dll
0x75B30000 \Windows\System32\comctl32.dll
0x75B20000 \Windows\System32\msasn1.dll
Processes (total 51):
0 System Idle Process
4 System
316 C:\Windows\System32\smss.exe
460 csrss.exe
532 C:\Windows\System32\wininit.exe
540 csrss.exe
584 C:\Windows\System32\services.exe
592 C:\Windows\System32\lsass.exe
600 C:\Windows\System32\lsm.exe
704 C:\Windows\System32\svchost.exe
784 C:\Windows\System32\winlogon.exe
836 C:\Windows\System32\svchost.exe
920 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1024 C:\Windows\System32\svchost.exe
1108 C:\Windows\System32\audiodg.exe
1168 C:\Windows\System32\svchost.exe
1268 WUDFHost.exe
1320 WUDFHost.exe
1396 C:\Windows\System32\svchost.exe
1516 C:\Windows\System32\spoolsv.exe
1544 C:\Windows\System32\svchost.exe
1660 C:\Windows\System32\svchost.exe
1768 C:\Windows\System32\svchost.exe
2116 C:\Windows\System32\dwm.exe
2124 C:\Windows\System32\taskhost.exe
2260 C:\Windows\explorer.exe
2460 C:\Windows\SOUNDMAN.EXE
2488 C:\Windows\System32\svchost.exe
2540 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
2592 C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
2648 C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
2716 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
2744 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
2772 C:\Windows\System32\rundll32.exe
2788 C:\Program Files\Steam\steam.exe
2968 C:\Program Files\Logitech\GamePanel Software\Applets\LCDSirReal.exe
3160 C:\Windows\System32\SearchIndexer.exe
3268 C:\Program Files\Windows Media Player\wmpnetwk.exe
3580 C:\Windows\System32\svchost.exe
4068 C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
2372 C:\Program Files\Windows Media Player\wmplayer.exe
3328 taskhost.exe
3256 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
3892 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
1656 C:\Windows\System32\svchost.exe
3916 C:\Windows\System32\wuauclt.exe
2444 C:\Program Files\Mozilla Firefox\firefox.exe
3572 C:\Users\Darmentle\Desktop\mal\MBRCheck.exe
2080 C:\Windows\System32\conhost.exe
404 C:\Windows\System32\dllhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
PhysicalDrive0 Model Number: WDCWD2000BB-22RDA0, Rev: 20.00K20
Size Device Name MBR Status
--------------------------------------------
186 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
Done!
------------------------------------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5363
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
1/7/2011 7:42:33 PM
mbam-log-2011-01-07 (19-42-33).txt
Scan type: Quick scan
Objects scanned: 143932
Time elapsed: 4 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
-----------------------------------------------------------------------------------------------------------------------------------------------------------------
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-07 20:20:59
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 WDC_WD2000BB-22RDA0 rev.20.00K20
Running: 7yeu6h2f.exe; Driver: C:\Users\DARMEN~1\AppData\Local\Temp\pfkiifog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateProcess [0x8CD31F68]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateProcessEx [0x8CD32230]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwCreateUserProcess [0x8CD3252C]
SSDT \SystemRoot\system32\drivers\PCTCore.sys ZwTerminateProcess [0x8CD319D8]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 83088599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830ACF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 32C 830B483C 8 Bytes [68, 1F, D3, 8C, 30, 22, D3, ...]
.text ntkrnlpa.exe!RtlSidHashLookup + 364 830B4874 4 Bytes [2C, 25, D3, 8C]
.text ntkrnlpa.exe!RtlSidHashLookup + 7B8 830B4CC8 4 Bytes [D8, 19, D3, 8C]
? system32\drivers\PCTCore.sys The system cannot find the path specified. !
? system32\drivers\pctDS.sys The system cannot find the path specified. !
? system32\drivers\pctEFA.sys The system cannot find the path specified. !
.text C:\Windows\system32\DRIVERS\atipmdag.sys section is writeable [0x93422000, 0x2D1F8A, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipAlloc] [74862494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusStartup] [74845624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusShutdown] [748456E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipFree] [7486250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDeleteGraphics] [74858573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDisposeImage] [74854D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageWidth] [748550CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageHeight] [748551A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [748566D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateFromHDC] [748582CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetCompositingMode] [74858819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetInterpolationMode] [7485907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDrawImageRectI] [7485E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\explorer.exe[1780] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCloneImage] [74854C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[2668] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[2668] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[2668] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[2668] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[4024] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[4024] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[4024] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[4024] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75C45E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
----------------------------------------------------------------------------------------------------
DDS (Ver_10-12-12.02) - NTFSx86
Run by Darmentle at 20:27:44.84 on Fri 01/07/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3579.2367 [GMT -8:00]
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\rundll32.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Darmentle\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uURLSearchHooks: H - No File
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
uRun: [PlayNC Launcher]
uRun: [fxCommonInit] rundll32.exe "c:\users\darmentle\appdata\local\acroauthenticationsnap\fxCommonInit.dll",CdMouseOffice tapiWISupport
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [NUSB3MON] "c:\program files\nec electronics\usb 3.0 host controller driver\application\nusb3mon.exe"
mRun: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
================= FIREFOX ===================
FF - ProfilePath - c:\users\darmen~1\appdata\roaming\mozilla\firefox\profiles\j0j6bb43.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Aluminium Kai 2: {a45e6b3a-725d-4b20-afde-e7486bfe317c} - %profile%\extensions\{a45e6b3a-725d-4b20-afde-e7486bfe317c}
============= SERVICES / DRIVERS ===============
R0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\drivers\mv91cons.sys [2009-10-9 20008]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2009-12-11 5188096]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2009-12-11 125440]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2009-9-25 56576]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2009-9-25 138240]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-2-12 189440]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-11 172032]
=============== Created Last 30 ================
2011-01-08 03:38:22 -------- d-----w- c:\users\darmen~1\appdata\roaming\Malwarebytes
2011-01-08 03:38:17 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-08 03:38:17 -------- d-----w- c:\progra~2\Malwarebytes
2011-01-08 03:38:14 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-08 03:38:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-08 02:16:34 -------- d-----w- C:\New folder (2)
2011-01-08 02:16:33 -------- d-----w- C:\New folder
2011-01-05 05:28:17 -------- d-----w- c:\program files\PC Tools Security
2011-01-05 05:28:17 -------- d-----w- c:\program files\common files\PC Tools
2011-01-05 03:52:22 -------- d-----w- c:\users\darmen~1\appdata\local\Activision
2010-12-31 21:59:31 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{5150af31-9583-4545-a2de-21c9390a1f2f}\mpengine.dll
2010-12-31 21:55:27 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-12-11 17:03:59 -------- d-----w- c:\users\darmen~1\appdata\local\AcroAuthenticationSnap
==================== Find3M ====================
2010-11-04 05:52:17 978944 ----a-w- c:\windows\system32\wininet.dll
2010-11-04 05:48:36 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-04 04:41:26 386048 ----a-w- c:\windows\system32\html.iec
2010-11-04 04:08:54 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-11-02 04:41:12 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-02 04:40:36 496128 ----a-w- c:\windows\system32\taskschd.dll
2010-11-02 04:40:36 305152 ----a-w- c:\windows\system32\taskcomp.dll
2010-11-02 04:39:32 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34:44 192000 ----a-w- c:\windows\system32\taskeng.exe
2010-11-02 04:34:33 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-27 04:32:36 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-20 04:54:18 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-20 02:58:41 294400 ----a-w- c:\windows\system32\atmfd.dll
2010-10-19 18:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-16 04:41:02 101760 ----a-w- c:\windows\system32\consent.exe
2010-10-16 04:36:10 314368 ----a-w- c:\windows\system32\webio.dll
============= FINISH: 20:27:57.94 ===============
I hope i did this the way it needs to go.