hello there, one of my machines has caught a nasty bug, ive managed to get rid of a false program called "system restore" however files and programs are still not showing and getting some re-directs in IE.
any help or advise thankfully recieved.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8053
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
31/10/2011 20:51:24
mbam-log-2011-10-31 (20-51-24).txt
Scan type: Quick scan
Objects scanned: 186013
Time elapsed: 4 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
gmer log blank
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_19
Run by Paulm at 20:36:02 on 2011-10-31
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.44.1033.18.3063.1626 [GMT 0:00]
.
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: {7c5c0f58-e061-457d-9033-77307f5ed00c} - No File
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {7c5c0f58-e061-457d-9033-77307f5ed00c} - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 6\PCSuite.exe" -onlytray
uRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PCSync2.exe" /NoDialog
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [kdx] c:\program files\kontiki\KHost.exe -all
uRun: [Aim6]
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Video Adapter] svahost.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [4oD] "c:\program files\kontiki\KHost.exe" -all
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\users\paulm\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: beatport.com\www
DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{302B52EE-8D07-4D6C-8D72-4AA6A65264F8} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F350D34C-E4DD-4F0D-B640-DAD8A2B04118} : DhcpNameServer = 10.0.150.202
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
mASetup: {B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC} - c:\program files\pixiepack codec pack\InstallerHelper.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\paulm\appdata\roaming\mozilla\firefox\profiles\l018hsfz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2332637&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\users\paulm\appdata\roaming\facebook\npfbplugin_1_0_3.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-10-30 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-10-30 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2011-10-30 110032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-10-30 74640]
R3 agloapod;agloapod;c:\users\paulm\appdata\local\temp\agloapod.sys [2011-10-31 100864]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-12 135664]
S3 CH341SER;CH341SER;c:\windows\system32\drivers\CH341SER.SYS [2008-11-12 37488]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-3-12 135664]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-3-19 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-3-19 8320]
S3 nptdrv2;Moxa NPort RealCOM Driver;c:\windows\system32\drivers\nptdrv2.sys [2009-2-4 77952]
.
=============== Created Last 30 ================
.
2011-10-31 07:19:20 -------- d-sh--w- C:\$RECYCLE.BIN
2011-10-30 22:52:50 -------- d-----w- c:\users\paulm\appdata\local\temp
2011-10-30 22:05:33 -------- d-s---w- C:\ComboFix
2011-10-30 21:47:09 -------- d-----w- c:\users\paulm\appdata\roaming\Avira
2011-10-30 21:41:13 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-10-30 21:41:13 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-10-30 21:41:12 -------- d-----w- c:\programdata\Avira
2011-10-30 21:41:12 -------- d-----w- c:\program files\Avira
2011-10-30 21:03:29 -------- d-----w- c:\users\paulm\appdata\local\Sophos
2011-10-30 14:46:45 98816 ---ha-w- c:\windows\sed.exe
2011-10-30 14:46:45 518144 ---ha-w- c:\windows\SWREG.exe
2011-10-30 14:46:45 256000 ---ha-w- c:\windows\PEV.exe
2011-10-30 14:46:45 208896 ---ha-w- c:\windows\MBR.exe
2011-10-30 14:15:00 717040 ----a-w- c:\windows\system32\PerfStringBackup.TMP
.
==================== Find3M ====================
.
2011-08-31 16:00:50 22216 ---ha-w- c:\windows\system32\drivers\mbam.sys
2011-08-26 09:19:55 404640 ---ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
============= FINISH: 20:42:05.01 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Business
Boot Device: \Device\HarddiskVolume1
Install Date: 29/02/2008 12:28:05
System Uptime: 31/10/2011 19:18:30 (1 hours ago)
.
Motherboard: Hewlett-Packard | | 30A2
Processor: Intel(R) Core(TM)2 CPU T5600 @ 1.83GHz | U10 | 1833/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 75 GiB total, 32.506 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: ROOT\LEGACY_BEEP\XX_NPF_XX
Manufacturer:
Name:
PNP Device ID: ROOT\LEGACY_BEEP\XX_NPF_XX
Service: NPF
.
Class GUID: {4d36e978-e325-11ce-bfc1-08002be10318}
Description: NPort Communication Port 1
Device ID: ROOT\PORTS\0000
Manufacturer: Moxa Technologies Co., Ltd
Name: NPort Communication Port 1 (COM1)
PNP Device ID: ROOT\PORTS\0000
Service: nptdrv2
.
==== System Restore Points ===================
.
RP1093: 20/10/2011 15:13:22 - Scheduled Checkpoint
RP1094: 22/10/2011 11:09:19 - Scheduled Checkpoint
RP1095: 24/10/2011 10:44:43 - Scheduled Checkpoint
RP1096: 26/10/2011 19:21:23 - Scheduled Checkpoint
RP1097: 27/10/2011 10:30:59 - Scheduled Checkpoint
RP1098: 28/10/2011 19:32:51 - Scheduled Checkpoint
RP1099: 29/10/2011 11:08:27 - Scheduled Checkpoint
RP1100: 30/10/2011 21:35:15 - Removed Sophos Anti-Virus
RP1101: 30/10/2011 21:38:34 - Removed Sophos AutoUpdate
RP1102: 30/10/2011 21:39:39 - Removed Sophos Remote Management System
RP1103: 31/10/2011 20:01:24 - Scheduled Checkpoint
.
==== Installed Programs ======================
.
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office system
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Photoshop Lightroom 2.7
Adobe Reader 8.1.4
Adobe Shockwave Player 11.5
Adobe Stock Photos 1.0
Agere Systems HDA Modem
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira Free Antivirus
BeatportDownloader
Bonjour
Canon RAW Codec
CarbonPoker
Debugging Tools for Windows (x86)
DeepBurner v1.8.0.224
DivX Setup
Facebook Plug-In
Facebook Video Calling 1.0.0.8714
Google Chrome
Google Update Helper
HP Photo and Imaging 2.0 - All-in-One
HP Photo and Imaging 2.0 - All-in-One Drivers
HP Photo and Imaging 2.0 - hp psc 2200 series
hp psc 2200 series
Intel(R) Graphics Media Accelerator Driver
iTunes
Java Auto Updater
Java(TM) 6 Update 19
Java(TM) 6 Update 6
Java(TM) 6 Update 7
K-Lite Codec Pack 4.6.2 (Full)
LucisArt 3 ED/SE
Magic FLAC CD Burner 1.06
Malwarebytes' Anti-Malware version 1.51.2.1300
Mask Pro 4.1.8
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft .NET Framework 3.5
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MobileMe Control Panel
Mozilla Firefox 7.0.1 (x86 en-GB)
MSVC80_x86
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
Noiseware Professional Plug-in
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia Software Updater
Norton PC Checkup
PC Connectivity Solution
Photomatix Pro version 3.2
PixiePack Codec Pack
PL-2303 Vista Driver Installer
PodWare
QuickTime
RAW Thumbnail Viewer
Realtek High Definition Audio Driver
Scratch Live 1.9.2 (19222)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB955936)
Security Update for Microsoft Office Excel 2007 (KB955470)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB951808)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office Word 2007 (KB950113)
Security Update for Visio 2007 (KB947590)
SHOUTcast Source DSP 1.9.0 (remove only)
Skype™ 4.0
Sony Sound Forge 8.0d
Spotify
TrackTracker
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Office 2007 (KB946691)
Update for Outlook 2007 Junk Email Filter (kb957258)
VC80CRTRedist - 8.0.50727.4053
VC8MergeModules
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 0.9.9
Wii Video 9 5.04
Winamp
Windows Driver Package - Nokia Modem (05/22/2008 3.8)
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)
Windows Driver Package - Nokia Modem (06/01/2009 4.1)
Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2)
Windows Driver Package - Nokia Modem (10/12/2007 3.6)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Live installer
Windows Live Sign-in Assistant
Windows Media Player Firefox Plugin
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
31/10/2011 07:18:46, Error: EventLog [6008] - The previous system shutdown at 22:57:32 on 30/10/2011 was unexpected.
30/10/2011 20:56:21, Error: EventLog [6008] - The previous system shutdown at 20:50:58 on 30/10/2011 was unexpected.
30/10/2011 20:01:03, Error: EventLog [6008] - The previous system shutdown at 16:24:11 on 30/10/2011 was unexpected.
30/10/2011 16:12:17, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
30/10/2011 16:06:16, Error: EventLog [6008] - The previous system shutdown at 15:08:03 on 30/10/2011 was unexpected.
30/10/2011 14:54:47, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
29/10/2011 22:20:04, Error: Microsoft-Windows-WMPNSS-Service [14344] - A new media server was not initialized because WMCreateDeviceRegistration() encountered error '0xc00d2767'. The Windows Media DRM components on your computer might be corrupted. Verify that protected files play correctly in Windows Media Player, and then restart the WMPNetworkSvc service.
29/10/2011 22:17:33, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume .
29/10/2011 12:23:44, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
24/10/2011 09:00:23, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd
.
==== End Of File ===========================
any help or advise thankfully recieved.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8053
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
31/10/2011 20:51:24
mbam-log-2011-10-31 (20-51-24).txt
Scan type: Quick scan
Objects scanned: 186013
Time elapsed: 4 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
gmer log blank
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_19
Run by Paulm at 20:36:02 on 2011-10-31
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.44.1033.18.3063.1626 [GMT 0:00]
.
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: {7c5c0f58-e061-457d-9033-77307f5ed00c} - No File
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {7c5c0f58-e061-457d-9033-77307f5ed00c} - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 6\PCSuite.exe" -onlytray
uRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PCSync2.exe" /NoDialog
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [kdx] c:\program files\kontiki\KHost.exe -all
uRun: [Aim6]
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Video Adapter] svahost.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [4oD] "c:\program files\kontiki\KHost.exe" -all
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\users\paulm\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: beatport.com\www
DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{302B52EE-8D07-4D6C-8D72-4AA6A65264F8} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{F350D34C-E4DD-4F0D-B640-DAD8A2B04118} : DhcpNameServer = 10.0.150.202
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
mASetup: {B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC} - c:\program files\pixiepack codec pack\InstallerHelper.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\paulm\appdata\roaming\mozilla\firefox\profiles\l018hsfz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2332637&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\users\paulm\appdata\roaming\facebook\npfbplugin_1_0_3.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-10-30 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-10-30 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2011-10-30 110032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-10-30 74640]
R3 agloapod;agloapod;c:\users\paulm\appdata\local\temp\agloapod.sys [2011-10-31 100864]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-12 135664]
S3 CH341SER;CH341SER;c:\windows\system32\drivers\CH341SER.SYS [2008-11-12 37488]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-3-12 135664]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-3-19 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-3-19 8320]
S3 nptdrv2;Moxa NPort RealCOM Driver;c:\windows\system32\drivers\nptdrv2.sys [2009-2-4 77952]
.
=============== Created Last 30 ================
.
2011-10-31 07:19:20 -------- d-sh--w- C:\$RECYCLE.BIN
2011-10-30 22:52:50 -------- d-----w- c:\users\paulm\appdata\local\temp
2011-10-30 22:05:33 -------- d-s---w- C:\ComboFix
2011-10-30 21:47:09 -------- d-----w- c:\users\paulm\appdata\roaming\Avira
2011-10-30 21:41:13 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-10-30 21:41:13 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-10-30 21:41:12 -------- d-----w- c:\programdata\Avira
2011-10-30 21:41:12 -------- d-----w- c:\program files\Avira
2011-10-30 21:03:29 -------- d-----w- c:\users\paulm\appdata\local\Sophos
2011-10-30 14:46:45 98816 ---ha-w- c:\windows\sed.exe
2011-10-30 14:46:45 518144 ---ha-w- c:\windows\SWREG.exe
2011-10-30 14:46:45 256000 ---ha-w- c:\windows\PEV.exe
2011-10-30 14:46:45 208896 ---ha-w- c:\windows\MBR.exe
2011-10-30 14:15:00 717040 ----a-w- c:\windows\system32\PerfStringBackup.TMP
.
==================== Find3M ====================
.
2011-08-31 16:00:50 22216 ---ha-w- c:\windows\system32\drivers\mbam.sys
2011-08-26 09:19:55 404640 ---ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
============= FINISH: 20:42:05.01 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Business
Boot Device: \Device\HarddiskVolume1
Install Date: 29/02/2008 12:28:05
System Uptime: 31/10/2011 19:18:30 (1 hours ago)
.
Motherboard: Hewlett-Packard | | 30A2
Processor: Intel(R) Core(TM)2 CPU T5600 @ 1.83GHz | U10 | 1833/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 75 GiB total, 32.506 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: ROOT\LEGACY_BEEP\XX_NPF_XX
Manufacturer:
Name:
PNP Device ID: ROOT\LEGACY_BEEP\XX_NPF_XX
Service: NPF
.
Class GUID: {4d36e978-e325-11ce-bfc1-08002be10318}
Description: NPort Communication Port 1
Device ID: ROOT\PORTS\0000
Manufacturer: Moxa Technologies Co., Ltd
Name: NPort Communication Port 1 (COM1)
PNP Device ID: ROOT\PORTS\0000
Service: nptdrv2
.
==== System Restore Points ===================
.
RP1093: 20/10/2011 15:13:22 - Scheduled Checkpoint
RP1094: 22/10/2011 11:09:19 - Scheduled Checkpoint
RP1095: 24/10/2011 10:44:43 - Scheduled Checkpoint
RP1096: 26/10/2011 19:21:23 - Scheduled Checkpoint
RP1097: 27/10/2011 10:30:59 - Scheduled Checkpoint
RP1098: 28/10/2011 19:32:51 - Scheduled Checkpoint
RP1099: 29/10/2011 11:08:27 - Scheduled Checkpoint
RP1100: 30/10/2011 21:35:15 - Removed Sophos Anti-Virus
RP1101: 30/10/2011 21:38:34 - Removed Sophos AutoUpdate
RP1102: 30/10/2011 21:39:39 - Removed Sophos Remote Management System
RP1103: 31/10/2011 20:01:24 - Scheduled Checkpoint
.
==== Installed Programs ======================
.
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office system
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Photoshop Lightroom 2.7
Adobe Reader 8.1.4
Adobe Shockwave Player 11.5
Adobe Stock Photos 1.0
Agere Systems HDA Modem
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira Free Antivirus
BeatportDownloader
Bonjour
Canon RAW Codec
CarbonPoker
Debugging Tools for Windows (x86)
DeepBurner v1.8.0.224
DivX Setup
Facebook Plug-In
Facebook Video Calling 1.0.0.8714
Google Chrome
Google Update Helper
HP Photo and Imaging 2.0 - All-in-One
HP Photo and Imaging 2.0 - All-in-One Drivers
HP Photo and Imaging 2.0 - hp psc 2200 series
hp psc 2200 series
Intel(R) Graphics Media Accelerator Driver
iTunes
Java Auto Updater
Java(TM) 6 Update 19
Java(TM) 6 Update 6
Java(TM) 6 Update 7
K-Lite Codec Pack 4.6.2 (Full)
LucisArt 3 ED/SE
Magic FLAC CD Burner 1.06
Malwarebytes' Anti-Malware version 1.51.2.1300
Mask Pro 4.1.8
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft .NET Framework 3.5
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MobileMe Control Panel
Mozilla Firefox 7.0.1 (x86 en-GB)
MSVC80_x86
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
Noiseware Professional Plug-in
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia Software Updater
Norton PC Checkup
PC Connectivity Solution
Photomatix Pro version 3.2
PixiePack Codec Pack
PL-2303 Vista Driver Installer
PodWare
QuickTime
RAW Thumbnail Viewer
Realtek High Definition Audio Driver
Scratch Live 1.9.2 (19222)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB955936)
Security Update for Microsoft Office Excel 2007 (KB955470)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB951808)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office Word 2007 (KB950113)
Security Update for Visio 2007 (KB947590)
SHOUTcast Source DSP 1.9.0 (remove only)
Skype™ 4.0
Sony Sound Forge 8.0d
Spotify
TrackTracker
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Office 2007 (KB946691)
Update for Outlook 2007 Junk Email Filter (kb957258)
VC80CRTRedist - 8.0.50727.4053
VC8MergeModules
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 0.9.9
Wii Video 9 5.04
Winamp
Windows Driver Package - Nokia Modem (05/22/2008 3.8)
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)
Windows Driver Package - Nokia Modem (06/01/2009 4.1)
Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2)
Windows Driver Package - Nokia Modem (10/12/2007 3.6)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Live installer
Windows Live Sign-in Assistant
Windows Media Player Firefox Plugin
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
31/10/2011 07:18:46, Error: EventLog [6008] - The previous system shutdown at 22:57:32 on 30/10/2011 was unexpected.
30/10/2011 20:56:21, Error: EventLog [6008] - The previous system shutdown at 20:50:58 on 30/10/2011 was unexpected.
30/10/2011 20:01:03, Error: EventLog [6008] - The previous system shutdown at 16:24:11 on 30/10/2011 was unexpected.
30/10/2011 16:12:17, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
30/10/2011 16:06:16, Error: EventLog [6008] - The previous system shutdown at 15:08:03 on 30/10/2011 was unexpected.
30/10/2011 14:54:47, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
29/10/2011 22:20:04, Error: Microsoft-Windows-WMPNSS-Service [14344] - A new media server was not initialized because WMCreateDeviceRegistration() encountered error '0xc00d2767'. The Windows Media DRM components on your computer might be corrupted. Verify that protected files play correctly in Windows Media Player, and then restart the WMPNetworkSvc service.
29/10/2011 22:17:33, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume .
29/10/2011 12:23:44, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
24/10/2011 09:00:23, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd
.
==== End Of File ===========================