HendrixLove
Posts: 12 +0
I keep getting redirected to other sites when clicking on links through google. I've had this problem for weeks now.
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7475
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
8/15/2011 5:54:54 PM
mbam-log-2011-08-15 (17-54-53).txt
Scan type: Quick scan
Objects scanned: 153975
Time elapsed: 7 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\localservice\application data\02000000ee67bfa11406c.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\02000000ee67bfa11406o.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\02000000ee67bfa11406p.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\02000000ee67bfa11406s.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\02000000ee67bfa11406c.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\02000000ee67bfa11406o.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\02000000ee67bfa11406p.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\02000000ee67bfa11406s.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\atkctrs32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-15 19:43:35
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD800JB-00JJC0 rev.05.01C05
Running: wsxpi9qb.exe; Driver: C:\DOCUME~1\BUDDYR~1\LOCALS~1\Temp\pflcapow.sys
---- System - GMER 1.0.15 ----
SSDT F8C7919C ZwClose
SSDT F8C79156 ZwCreateKey
SSDT F8C791A6 ZwCreateSection
SSDT F8C7914C ZwCreateThread
SSDT F8C7915B ZwDeleteKey
SSDT F8C79165 ZwDeleteValueKey
SSDT F8C79197 ZwDuplicateObject
SSDT F8C7916A ZwLoadKey
SSDT F8C79138 ZwOpenProcess
SSDT F8C7913D ZwOpenThread
SSDT F8C79174 ZwReplaceKey
SSDT F8C7916F ZwRestoreKey
SSDT F8C791AB ZwSetContextThread
SSDT F8C79160 ZwSetValueKey
SSDT F8C79147 ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
? uplwpmqn.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[2656] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00401410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 008D2B4B C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 008D2AD5 C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 008D29FC C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!bind 71AB4480 5 Bytes JMP 008D2986 C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 008D2A5F C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 008D2AFF C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 008D2B99 C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!WSAConnect 71AC0C81 5 Bytes JMP 008D2A94 C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2988] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 104A5451 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2988] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 104A5A99 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_22
Run by Buddy Rich at 19:49:44 on 2011-08-15
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.173 [GMT -7:00]
.
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\kbdtat32.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\atkctrs32.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
mURLSearchHooks: H - No File
BHO: {18C2AE25-2A33-41EC-9A42-48F721A64C8e} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\MSMSGS.EXE" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb03.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBJAEMAQQBNADEANQAtAEEAWgBZADQAOAAtAFQATAA2AFkAOAAtADkAVQBCAFUAUgAtADcAVABHAFYAUwAtADQARgBTAFUANgA"&"inst=NwA2AC0ANwA2ADEAMAA1ADgAOAA2ADcALQBQAEwAKwA5AC0ATgAxAEQAKwAxAA"&"prod=92"&"ver=9.0.894
StartupFolder: c:\docume~1\buddyr~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\amazon~1.lnk - c:\program files\amazon\amazon unbox video\ADVWindowsClientSystemTray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289537335031
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: TPSvc - TPSvc.dll
AppInit_DLLs: c:\windows\system32\netevent32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\buddy rich\application data\mozilla\firefox\profiles\khu7bv1a.default\
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\buddy rich\application data\mozilla\firefox\profiles\khu7bv1a.default\extensions\battlefieldheroespatcher@ea.com\plugins\npBFHUpdater.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-8-15 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-8-15 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-8-15 269480]
R2 aspnet_state32;ASP.NET State Service ;c:\windows\system32\kbdtat32.exe [2011-8-15 715776]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-8-15 66616]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-23 366640]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-7-23 22712]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-3 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-3 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-7-23 41272]
.
=============== Created Last 30 ================
.
2011-08-15 23:56:20 -------- d-----w- c:\windows\system32\NtmsData
2011-08-15 23:50:29 -------- d-----w- c:\documents and settings\buddy rich\application data\Avira
2011-08-15 23:48:05 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-15 23:48:01 -------- d-----w- c:\program files\Avira
2011-08-15 23:48:01 -------- d-----w- c:\documents and settings\all users\application data\Avira
2011-08-15 14:06:30 715776 ----a-w- c:\windows\system32\atkctrs32.exe
2011-08-15 14:06:29 157184 ----a-w- c:\windows\system32\netevent32.dll
2011-08-15 14:06:28 715776 ----a-w- c:\windows\system32\kbdtat32.exe
2011-08-11 04:38:20 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-11 04:38:19 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-03 10:16:24 -------- d-----w- c:\documents and settings\buddy rich\local settings\application data\Temp
2011-08-03 10:15:49 -------- d-----w- c:\documents and settings\buddy rich\local settings\application data\Google
2011-08-02 08:18:28 -------- d-----w- c:\program files\Amazon
2011-07-31 06:31:53 -------- d-----w- c:\program files\Project64 1.6
2011-07-24 01:43:33 -------- d-----w- c:\program files\Enigma Software Group
2011-07-23 08:30:05 -------- d-----w- c:\documents and settings\buddy rich\application data\Malwarebytes
2011-07-23 08:29:59 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-23 08:29:58 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-07-23 08:29:55 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-23 08:29:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-23 08:06:54 -------- d-----w- c:\documents and settings\all users\application data\STOPzilla!
2011-07-23 07:01:17 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-07-23 07:01:13 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-07-23 07:00:56 -------- d-----w- c:\windows\Logs
2011-07-22 23:16:13 -------- d-----w- c:\documents and settings\buddy rich\local settings\application data\ApplicationHistory
2011-07-22 22:26:00 0 ---ha-w- c:\documents and settings\buddy rich\xwgmlgcanr.tmp
2011-07-22 06:02:03 138056 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-07-22 06:02:03 138056 ----a-w- c:\documents and settings\buddy rich\application data\PnkBstrK.sys
2011-07-22 06:01:46 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-07-22 06:01:46 189248 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-07-22 06:01:42 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-07-22 04:43:43 -------- d-----w- c:\windows\system32\URTTEMP
2011-07-22 04:43:05 520192 ------w- c:\windows\system32\ati2sgag.exe
2011-07-22 04:42:34 -------- d-----w- c:\program files\ATI Technologies
2011-07-22 04:41:54 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-07-22 04:41:54 225280 ------w- c:\program files\common files\installshield\iscript\iscript.dll
2011-07-22 04:41:54 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-07-22 04:41:53 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-07-22 04:41:53 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2011-07-22 04:41:03 -------- d-----w- C:\6.5_Win2kXP9250AGPAnd9550AGP
2011-07-18 06:13:05 -------- d-----w- c:\program files\New Folder
.
==================== Find3M ====================
.
2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-21 18:45:58 832512 ----a-w- c:\windows\system32\wininet.dll
2011-06-21 18:45:57 78336 ------w- c:\windows\system32\ieencode.dll
2011-06-21 18:45:57 1830912 ------w- c:\windows\system32\inetcpl.cpl
2011-06-21 18:45:57 17408 ------w- c:\windows\system32\corpol.dll
2011-06-21 11:47:20 389120 ------w- c:\windows\system32\html.iec
2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-31 00:30:07 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-31 00:30:07 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
============= FINISH: 19:51:00.60 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 11/11/2010 5:35:20 PM
System Uptime: 8/15/2011 5:56:25 PM (2 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P4B-LA
Processor: Intel(R) Pentium(R) 4 CPU 1.50GHz | PGA 478 | 1494/100mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 75 GiB total, 19.715 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP359: 8/13/2011 11:45:53 PM - System Checkpoint
RP360: 8/15/2011 6:41:04 AM - System Checkpoint
RP361: 8/15/2011 4:40:05 PM - Removed HiJackThis
RP362: 8/15/2011 4:40:43 PM - Removed Project64 1.6
.
==== Installed Programs ======================
.
.
µTorrent
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.0
Amazon Unbox Video
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Display Driver
Avira AntiVir Personal - Free Antivirus
AVS Update Manager 1.0
AVS Video Converter 8
AVS4YOU Software Navigator 1.4
BitTornado 0.3.17
Bonjour
Cisco Connect
DivX Setup
Google Chrome
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
hp deskjet 845c series (Remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 22
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 5.0 (x86 en-US)
NetAssistant
NetAssistant for Firefox
Octoshape add-in for Adobe Flash Player
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office 2007 System (KB2541012)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2541007)
Security Update for Microsoft Office Groove 2007 (KB2494047)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB2482017)
Security Update for Windows Internet Explorer 7 (KB2497640)
Security Update for Windows Internet Explorer 7 (KB2530548)
Security Update for Windows Internet Explorer 7 (KB2544521)
Security Update for Windows Internet Explorer 7 (KB2559049)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB911564)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB923789)
TouchCopy 09
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office Outlook 2007 (KB2509470)
Update for Outlook 2007 Junk Email Filter (KB2586924)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.1.7
WebFldrs XP
Wiley CPA Exam: How to Master Simulations
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
8/8/2011 3:37:18 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.DebugCRT. Reference error message: The referenced assembly is not installed on your system. .
8/8/2011 3:37:18 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll. Reference error message: The operation completed successfully. .
8/8/2011 3:37:18 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.DebugCRT could not be found and Last Error was The referenced assembly is not installed on your system.
8/15/2011 6:11:27 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
8/15/2011 6:05:53 PM, error: E100B [4] - Adapter Intel(R) PRO/100 VE Network Connection: Adapter Link Down
8/15/2011 5:28:01 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Amazon Unbox Video Service service to connect.
8/15/2011 4:40:08 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
8/13/2011 9:56:12 PM, error: HTTP [15005] - Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number.
8/13/2011 3:07:21 AM, error: Dhcp [1002] - The IP address lease 192.168.1.141 for the Network Card with network address 00E01845525B has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7475
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
8/15/2011 5:54:54 PM
mbam-log-2011-08-15 (17-54-53).txt
Scan type: Quick scan
Objects scanned: 153975
Time elapsed: 7 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\localservice\application data\02000000ee67bfa11406c.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\02000000ee67bfa11406o.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\02000000ee67bfa11406p.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\02000000ee67bfa11406s.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\02000000ee67bfa11406c.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\02000000ee67bfa11406o.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\02000000ee67bfa11406p.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\02000000ee67bfa11406s.manifest (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\atkctrs32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-15 19:43:35
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD800JB-00JJC0 rev.05.01C05
Running: wsxpi9qb.exe; Driver: C:\DOCUME~1\BUDDYR~1\LOCALS~1\Temp\pflcapow.sys
---- System - GMER 1.0.15 ----
SSDT F8C7919C ZwClose
SSDT F8C79156 ZwCreateKey
SSDT F8C791A6 ZwCreateSection
SSDT F8C7914C ZwCreateThread
SSDT F8C7915B ZwDeleteKey
SSDT F8C79165 ZwDeleteValueKey
SSDT F8C79197 ZwDuplicateObject
SSDT F8C7916A ZwLoadKey
SSDT F8C79138 ZwOpenProcess
SSDT F8C7913D ZwOpenThread
SSDT F8C79174 ZwReplaceKey
SSDT F8C7916F ZwRestoreKey
SSDT F8C791AB ZwSetContextThread
SSDT F8C79160 ZwSetValueKey
SSDT F8C79147 ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
? uplwpmqn.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[2656] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00401410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 008D2B4B C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 008D2AD5 C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!WSASocketW 71AB404E 7 Bytes JMP 008D29FC C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!bind 71AB4480 5 Bytes JMP 008D2986 C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 008D2A5F C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 008D2AFF C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 008D2B99 C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2792] WS2_32.dll!WSAConnect 71AC0C81 5 Bytes JMP 008D2A94 C:\WINDOWS\system32\netevent32.dll (BulletStorm/People Can Fly)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2988] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 104A5451 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2988] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 104A5A99 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_22
Run by Buddy Rich at 19:49:44 on 2011-08-15
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.173 [GMT -7:00]
.
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\kbdtat32.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\atkctrs32.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
mURLSearchHooks: H - No File
BHO: {18C2AE25-2A33-41EC-9A42-48F721A64C8e} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\MSMSGS.EXE" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb03.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBJAEMAQQBNADEANQAtAEEAWgBZADQAOAAtAFQATAA2AFkAOAAtADkAVQBCAFUAUgAtADcAVABHAFYAUwAtADQARgBTAFUANgA"&"inst=NwA2AC0ANwA2ADEAMAA1ADgAOAA2ADcALQBQAEwAKwA5AC0ATgAxAEQAKwAxAA"&"prod=92"&"ver=9.0.894
StartupFolder: c:\docume~1\buddyr~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\amazon~1.lnk - c:\program files\amazon\amazon unbox video\ADVWindowsClientSystemTray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289537335031
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: TPSvc - TPSvc.dll
AppInit_DLLs: c:\windows\system32\netevent32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\buddy rich\application data\mozilla\firefox\profiles\khu7bv1a.default\
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\buddy rich\application data\mozilla\firefox\profiles\khu7bv1a.default\extensions\battlefieldheroespatcher@ea.com\plugins\npBFHUpdater.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-8-15 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-8-15 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-8-15 269480]
R2 aspnet_state32;ASP.NET State Service ;c:\windows\system32\kbdtat32.exe [2011-8-15 715776]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-8-15 66616]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-23 366640]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-7-23 22712]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-3 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-3 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-7-23 41272]
.
=============== Created Last 30 ================
.
2011-08-15 23:56:20 -------- d-----w- c:\windows\system32\NtmsData
2011-08-15 23:50:29 -------- d-----w- c:\documents and settings\buddy rich\application data\Avira
2011-08-15 23:48:05 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-15 23:48:01 -------- d-----w- c:\program files\Avira
2011-08-15 23:48:01 -------- d-----w- c:\documents and settings\all users\application data\Avira
2011-08-15 14:06:30 715776 ----a-w- c:\windows\system32\atkctrs32.exe
2011-08-15 14:06:29 157184 ----a-w- c:\windows\system32\netevent32.dll
2011-08-15 14:06:28 715776 ----a-w- c:\windows\system32\kbdtat32.exe
2011-08-11 04:38:20 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-11 04:38:19 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-03 10:16:24 -------- d-----w- c:\documents and settings\buddy rich\local settings\application data\Temp
2011-08-03 10:15:49 -------- d-----w- c:\documents and settings\buddy rich\local settings\application data\Google
2011-08-02 08:18:28 -------- d-----w- c:\program files\Amazon
2011-07-31 06:31:53 -------- d-----w- c:\program files\Project64 1.6
2011-07-24 01:43:33 -------- d-----w- c:\program files\Enigma Software Group
2011-07-23 08:30:05 -------- d-----w- c:\documents and settings\buddy rich\application data\Malwarebytes
2011-07-23 08:29:59 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-23 08:29:58 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-07-23 08:29:55 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-23 08:29:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-23 08:06:54 -------- d-----w- c:\documents and settings\all users\application data\STOPzilla!
2011-07-23 07:01:17 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-07-23 07:01:13 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-07-23 07:00:56 -------- d-----w- c:\windows\Logs
2011-07-22 23:16:13 -------- d-----w- c:\documents and settings\buddy rich\local settings\application data\ApplicationHistory
2011-07-22 22:26:00 0 ---ha-w- c:\documents and settings\buddy rich\xwgmlgcanr.tmp
2011-07-22 06:02:03 138056 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-07-22 06:02:03 138056 ----a-w- c:\documents and settings\buddy rich\application data\PnkBstrK.sys
2011-07-22 06:01:46 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-07-22 06:01:46 189248 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-07-22 06:01:42 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-07-22 04:43:43 -------- d-----w- c:\windows\system32\URTTEMP
2011-07-22 04:43:05 520192 ------w- c:\windows\system32\ati2sgag.exe
2011-07-22 04:42:34 -------- d-----w- c:\program files\ATI Technologies
2011-07-22 04:41:54 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-07-22 04:41:54 225280 ------w- c:\program files\common files\installshield\iscript\iscript.dll
2011-07-22 04:41:54 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-07-22 04:41:53 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-07-22 04:41:53 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2011-07-22 04:41:03 -------- d-----w- C:\6.5_Win2kXP9250AGPAnd9550AGP
2011-07-18 06:13:05 -------- d-----w- c:\program files\New Folder
.
==================== Find3M ====================
.
2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-21 18:45:58 832512 ----a-w- c:\windows\system32\wininet.dll
2011-06-21 18:45:57 78336 ------w- c:\windows\system32\ieencode.dll
2011-06-21 18:45:57 1830912 ------w- c:\windows\system32\inetcpl.cpl
2011-06-21 18:45:57 17408 ------w- c:\windows\system32\corpol.dll
2011-06-21 11:47:20 389120 ------w- c:\windows\system32\html.iec
2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-31 00:30:07 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-31 00:30:07 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
============= FINISH: 19:51:00.60 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 11/11/2010 5:35:20 PM
System Uptime: 8/15/2011 5:56:25 PM (2 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P4B-LA
Processor: Intel(R) Pentium(R) 4 CPU 1.50GHz | PGA 478 | 1494/100mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 75 GiB total, 19.715 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP359: 8/13/2011 11:45:53 PM - System Checkpoint
RP360: 8/15/2011 6:41:04 AM - System Checkpoint
RP361: 8/15/2011 4:40:05 PM - Removed HiJackThis
RP362: 8/15/2011 4:40:43 PM - Removed Project64 1.6
.
==== Installed Programs ======================
.
.
µTorrent
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.0
Amazon Unbox Video
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Display Driver
Avira AntiVir Personal - Free Antivirus
AVS Update Manager 1.0
AVS Video Converter 8
AVS4YOU Software Navigator 1.4
BitTornado 0.3.17
Bonjour
Cisco Connect
DivX Setup
Google Chrome
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
hp deskjet 845c series (Remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 22
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 5.0 (x86 en-US)
NetAssistant
NetAssistant for Firefox
Octoshape add-in for Adobe Flash Player
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office 2007 System (KB2541012)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2541007)
Security Update for Microsoft Office Groove 2007 (KB2494047)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB2482017)
Security Update for Windows Internet Explorer 7 (KB2497640)
Security Update for Windows Internet Explorer 7 (KB2530548)
Security Update for Windows Internet Explorer 7 (KB2544521)
Security Update for Windows Internet Explorer 7 (KB2559049)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB911564)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB923789)
TouchCopy 09
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office Outlook 2007 (KB2509470)
Update for Outlook 2007 Junk Email Filter (KB2586924)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.1.7
WebFldrs XP
Wiley CPA Exam: How to Master Simulations
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
8/8/2011 3:37:18 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.DebugCRT. Reference error message: The referenced assembly is not installed on your system. .
8/8/2011 3:37:18 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll. Reference error message: The operation completed successfully. .
8/8/2011 3:37:18 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.DebugCRT could not be found and Last Error was The referenced assembly is not installed on your system.
8/15/2011 6:11:27 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
8/15/2011 6:05:53 PM, error: E100B [4] - Adapter Intel(R) PRO/100 VE Network Connection: Adapter Link Down
8/15/2011 5:28:01 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Amazon Unbox Video Service service to connect.
8/15/2011 4:40:08 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
8/13/2011 9:56:12 PM, error: HTTP [15005] - Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number.
8/13/2011 3:07:21 AM, error: Dhcp [1002] - The IP address lease 192.168.1.141 for the Network Card with network address 00E01845525B has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================