DDS
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.2180
Run by Admin at 14:51:20 on 2012-08-27
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1268 [GMT 3:00]
.
AV: AVG Internet Security 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Internet Security 2013 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2013\avgfws.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=112060&tt=201208_mnt_n_3512_1&babsrc=HP_ss&mntrId=1090cd0a0000000000000030672aff98
uInternet Connection Wizard,ShellNext = hxxp://
www.amdsurveys.com/se.ashx?s=5A1E27D24301077E
uURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - c:\program files\utorrentcontrol_v2\prxtbuTo0.dll
BHO: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - c:\program files\utorrentcontrol_v2\prxtbuTo0.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\12.2.0.5\AVG Secure Search_toolbar.dll
BHO: Yontoo: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo\YontooIEClient.dll
TB: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - c:\program files\utorrentcontrol_v2\prxtbuTo0.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\12.2.0.5\AVG Secure Search_toolbar.dll
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [Google Update] "c:\documents and settings\admin\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [ROC_roc_ssl_v12] "c:\program files\avg secure search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\12.2.0\ViProtocol.dll
Notify: AtiExtEvent - Ati2evxx.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-7-27 54112]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-7-27 178656]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-7-27 35168]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-7-27 176096]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-7-27 19808]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-7-27 151520]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-7-27 89440]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-7-27 164704]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2012-8-25 27496]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2012-8-25 13696]
R2 avgfws;AVG Firewall;c:\program files\avg\avg2013\avgfws.exe [2012-8-20 1286392]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-8-20 184304]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-27 655944]
R2 vToolbarUpdater12.2.0;vToolbarUpdater12.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\12.2.0\ToolbarUpdater.exe [2012-8-25 927840]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2012-1-12 30944]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-8-27 22344]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-8-20 5751928]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2012-1-12 30944]
.
=============== Created Last 30 ================
.
2012-08-27 11:21:00--------d-----w-c:\documents and settings\admin\application data\Malwarebytes
2012-08-27 11:20:50--------d-----w-c:\documents and settings\all users\application data\Malwarebytes
2012-08-27 11:20:4922344----a-w-c:\windows\system32\drivers\mbam.sys
2012-08-27 11:20:49--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2012-08-27 10:31:48--------d-----w-c:\documents and settings\admin\application data\KC Softwares
2012-08-27 10:21:43--------d-----w-c:\program files\Yontoo
2012-08-27 10:21:40--------d-----w-c:\documents and settings\all users\application data\Tarma Installer
2012-08-27 10:19:27--------d-----w-c:\program files\KC Softwares
2012-08-27 10:17:40--------d-----w-c:\program files\CCleaner
2012-08-27 09:33:39--------d-----w-c:\documents and settings\all users\application data\Package Cache
2012-08-27 08:15:00102416----a-w-c:\windows\system32\RTNUninst32.dll
2012-08-27 08:03:0733792----a-w-c:\windows\system32\drivers\AmdPPM.sys
2012-08-27 08:02:55--------d-----w-c:\program files\AMD
2012-08-27 04:54:18--------d-----w-c:\documents and settings\admin\local settings\application data\Nero
2012-08-27 04:45:11--------d-----w-c:\program files\MSXML 4.0
2012-08-27 04:30:48--------d-----w-c:\windows\system32\appmgmt
2012-08-27 04:24:37938368----a-w-c:\windows\system32\ativvamv.dll
2012-08-27 04:24:37159744----a-w-c:\windows\system32\atiapfxx.exe
2012-08-27 04:23:59--------d-----w-c:\program files\ATI
2012-08-27 04:22:55--------d-----w-C:\AMD
2012-08-27 04:08:46--------d-----w-c:\documents and settings\admin\local settings\application data\Ahead
2012-08-27 04:05:15--------d-----w-c:\program files\Nero
2012-08-27 04:05:15--------d-----w-c:\documents and settings\all users\application data\Nero
2012-08-27 04:04:49819200----a-w-c:\program files\windows media player\wmsetsdk.exe
2012-08-27 04:04:4947616----a-w-c:\program files\windows media player\msoobci.dll
2012-08-27 04:04:31--------d-----w-c:\windows\RegisteredPackages
2012-08-27 03:53:57--------d-----w-c:\documents and settings\all users\application data\Babylon
2012-08-27 03:53:57--------d-----w-c:\documents and settings\admin\application data\Babylon
2012-08-27 00:37:099600-c--a-w-c:\windows\system32\dllcache\hidusb.sys
2012-08-27 00:37:099600----a-w-c:\windows\system32\drivers\hidusb.sys
2012-08-26 01:04:03--------d--h--w-c:\windows\msdownld.tmp
2012-08-26 00:52:21--------d-----w-c:\documents and settings\admin\local settings\application data\AVG Secure Search
2012-08-25 23:12:18175616----a-w-c:\windows\system32\unrar.dll
2012-08-25 23:12:14--------d-----w-c:\program files\K-Lite Codec Pack
2012-08-25 21:38:57--------d-----w-c:\program files\Ashampoo
2012-08-25 21:22:04--------d-----w-c:\documents and settings\admin\application data\Ashampoo
2012-08-25 21:14:38--------d-----w-c:\program files\VideoLAN
2012-08-25 16:42:34--------d-----w-c:\documents and settings\admin\application data\2K Sports
2012-08-25 16:25:592297552----a-w-c:\windows\system32\d3dx9_26.dll
2012-08-25 16:25:25--------d-----w-c:\windows\Logs
2012-08-25 16:16:0981768----a-w-c:\windows\system32\xinput1_3.dll
2012-08-25 16:13:25--------d-----w-c:\program files\2K Sports
2012-08-25 16:07:00--------d-----w-c:\documents and settings\admin\application data\AVG2013
2012-08-25 16:06:12--------d-----w-c:\documents and settings\admin\application data\TuneUp Software
2012-08-25 16:06:08--------d-----w-c:\documents and settings\all users\application data\AVG Secure Search
2012-08-25 16:05:58--------d-----w-c:\documents and settings\admin\application data\AVG Secure Search
2012-08-25 16:05:5727496----a-w-c:\windows\system32\drivers\avgtpx86.sys
2012-08-25 16:05:55--------d-----w-c:\program files\common files\AVG Secure Search
2012-08-25 16:02:43--------d--h--w-C:\$AVG
2012-08-25 16:02:43--------d-----w-c:\documents and settings\all users\application data\AVG2013
2012-08-25 16:02:19--------d-----w-c:\program files\AVG
2012-08-25 16:00:51--------d--h--w-c:\documents and settings\all users\application data\Common Files
2012-08-25 16:00:51--------d-----w-c:\documents and settings\all users\application data\MFAData
2012-08-25 16:00:51--------d-----w-c:\documents and settings\admin\local settings\application data\MFAData
2012-08-25 16:00:51--------d-----w-c:\documents and settings\admin\local settings\application data\Avg2013
.
==================== Find3M ====================
.
2012-08-27 09:51:3194208----a-w-c:\windows\DUMP9c4f.tmp
2012-08-27 07:54:0594208----a-w-c:\windows\DUMP8e45.tmp
2012-08-25 06:45:500----a-w-c:\windows\ativpsrm.bin
2012-08-13 13:40:54176096----a-w-c:\windows\system32\drivers\avgidsdriverx.sys
2012-08-10 01:52:38164704----a-w-c:\windows\system32\drivers\avgtdix.sys
2012-08-10 01:52:2819808----a-w-c:\windows\system32\drivers\avgidsshimx.sys
2012-08-10 01:52:1835168----a-w-c:\windows\system32\drivers\avgrkx86.sys
2012-08-09 10:56:44178656----a-w-c:\windows\system32\drivers\avglogx.sys
2012-08-09 10:56:3654112----a-w-c:\windows\system32\drivers\avgidshx.sys
2012-08-09 10:56:22151520----a-w-c:\windows\system32\drivers\avgldx86.sys
2012-07-04 06:54:327874560----a-w-c:\windows\system32\drivers\ati2mtag.sys
2012-07-04 04:38:26442368----a-w-c:\windows\system32\ATIDEMGX.dll
2012-07-04 04:37:10306176----a-w-c:\windows\system32\ati2dvag.dll
2012-07-04 04:36:46307200----a-w-c:\windows\system32\atiiiexx.dll
2012-07-04 04:35:0219603456----a-w-c:\windows\system32\atioglxx.dll
2012-07-04 04:32:285335616----a-w-c:\windows\system32\ati3duag.dll
2012-07-04 04:12:46212992----a-w-c:\windows\system32\atipdlxx.dll
2012-07-04 04:12:34163840----a-w-c:\windows\system32\Oemdspif.dll
2012-07-04 04:12:2426112----a-w-c:\windows\system32\Ati2mdxx.exe
2012-07-04 04:12:1643520----a-w-c:\windows\system32\ati2edxx.dll
2012-07-04 04:12:04192512----a-w-c:\windows\system32\ati2evxx.dll
2012-07-04 04:10:40643072----a-w-c:\windows\system32\ati2evxx.exe
2012-07-04 04:09:2053248----a-w-c:\windows\system32\ATIDDC.DLL
2012-07-04 04:08:583586816----a-w-c:\windows\system32\ativvaxx.dll
2012-07-04 04:01:18835584----a-w-c:\windows\system32\atikvmag.dll
2012-07-04 03:56:42634880----a-w-c:\windows\system32\atiok3x2.dll
2012-07-04 03:56:20233472----a-w-c:\windows\system32\atiadlxx.dll
2012-07-04 03:56:0217408----a-w-c:\windows\system32\atitvo32.dll
2012-07-04 03:50:02909312----a-w-c:\windows\system32\ati2cqag.dll
2012-07-04 03:48:3465024----a-w-c:\windows\system32\atimpc32.dll
2012-07-04 03:48:3465024----a-w-c:\windows\system32\amdpcom32.dll
2012-07-04 03:47:5653248----a-w-c:\windows\system32\drivers\ati2erec.dll
.
============= FINISH: 14:51:35.17 ===============