Logs
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5676
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
2/5/2011 12:26:46 AM
mbam-log-2011-02-05 (00-26-46).txt
Scan type: Quick scan
Objects scanned: 151647
Time elapsed: 3 minute(s), 2 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 9
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\program files\qvodplayer\QvodBand.dll (Spyware.OnlineGames) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9F44453E-1E46-4D5C-B57C-112FF2EDAE82} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\VXEG3ZNNE5 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\CE8SIIFGSU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files\qvodplayer\QvodBand.dll (Spyware.OnlineGames) -> Delete on reboot.
c:\WINDOWS\Tasks\{35dc3473-a719-4d14-b7c1-fd326ca84a0c}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
===========================================================
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2011-02-05 16:25:37
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-7 Hitachi_HDS721616PLA380 rev.P22OA50U
Running: lbz2mme6.exe; Driver: C:\DOCUME~1\user\LOCALS~1\Temp\afeyiaoc.sys
---- System - GMER 1.0.15 ----
SSDT B86DDBDE ZwCreateKey
SSDT B86DDBD4 ZwCreateThread
SSDT B86DDBE3 ZwDeleteKey
SSDT B86DDBED ZwDeleteValueKey
SSDT spxj.sys ZwEnumerateKey [0xB7ECDDA4]
SSDT spxj.sys ZwEnumerateValueKey [0xB7ECE132]
SSDT B86DDBF2 ZwLoadKey
SSDT spxj.sys ZwOpenKey [0xB7EB50C0]
SSDT B86DDBC0 ZwOpenProcess
SSDT B86DDBC5 ZwOpenThread
SSDT spxj.sys ZwQueryKey [0xB7ECE20A]
SSDT spxj.sys ZwQueryValueKey [0xB7ECE08A]
SSDT B86DDBFC ZwReplaceKey
SSDT B86DDBF7 ZwRestoreKey
SSDT B86DDBE8 ZwSetValueKey
INT 0x62 ? 8A5F0BF8
INT 0x73 ? 8A5F0BF8
INT 0x83 ? 8A5F0BF8
INT 0xB4 ? 8A367BF8
INT 0xB4 ? 8A367BF8
INT 0xB4 ? 8A367BF8
INT 0xB4 ? 8A367BF8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2F10 80503B10 4 Bytes CALL 0508A8F0
? spxj.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6F6C380, 0x3DF295, 0xE8000020]
.text USBPORT.SYS!DllUnload B6F4D62C 5 Bytes JMP 8A3671D8
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!ReadFile 7C80180E 7 Bytes JMP 011E87F9 c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 011E872D c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!CloseHandle 7C809B77 5 Bytes JMP 011E8AB6 c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!CreateFileW 7C810976 5 Bytes JMP 011E8793 c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!GetFileSizeEx 7C810C21 5 Bytes JMP 011E8B3E c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!GetFileSize 7C810C8F 5 Bytes JMP 011E8AF7 c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!SetFilePointer 7C810DA6 5 Bytes JMP 011E89AB c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!WriteFile 7C810F9F 7 Bytes JMP 011E88AB c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!SetFilePointerEx 7C81F475 5 Bytes JMP 011E8A05 c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!GetOverlappedResult 7C81FCF4 5 Bytes JMP 011E8B85 c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!OpenFile 7C826B99 5 Bytes JMP 011E895D c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!ReadFileEx 7C8384C5 5 Bytes JMP 011E8852 c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
.text C:\Program Files\PPStream\ppsap.exe[1904] kernel32.dll!WriteFileEx 7C85C4E1 5 Bytes JMP 011E8904 c:\Program Files\PPStream\1.1.0.2802\vodres.dll (PPS ???接?/PPStream Inc.)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EB6042] spxj.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EB613E] spxj.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EB60C0] spxj.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EB6800] spxj.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EB66D6] spxj.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B7EC5B90] spxj.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A5EF1F8
Device \Driver\usbohci \Device\USBPDO-0 8A3631F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A6391F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A6391F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A6391F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A6391F8
Device \Driver\usbohci \Device\USBPDO-1 8A3631F8
Device \Driver\usbehci \Device\USBPDO-2 8A3431F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A5F11F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A5F11F8
Device \Driver\Cdrom \Device\CdRom0 8A2F51F8
Device \Driver\atapi \Device\Ide\IdePort0 8A5F01F8
Device \Driver\atapi \Device\Ide\IdePort1 8A5F01F8
Device \Driver\atapi \Device\Ide\IdePort2 8A5F01F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-7 8A5F01F8
Device \Driver\atapi \Device\Ide\IdePort3 8A5F01F8
Device \Driver\atapi \Device\Ide\IdePort4 8A5F01F8
Device \Driver\atapi \Device\Ide\IdePort5 8A5F01F8
Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 8A5F01F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A26E500
Device \Driver\NetBT \Device\NetbiosSmb 8A26E500
Device \Driver\usbohci \Device\USBFDO-0 8A3631F8
Device \Driver\usbohci \Device\USBFDO-1 8A3631F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A444500
Device \Driver\usbehci \Device\USBFDO-2 8A3431F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A444500
Device \Driver\Ftdisk \Device\FtControl 8A5F11F8
Device \FileSystem\Cdfs \Cdfs 8A28D500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001986002950
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001986002950@0023f12af4b4 0xAB 0x17 0x59 0xC9 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001f81000250
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEC 0xDB 0x47 0xA1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001986002950 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001986002950@0023f12af4b4 0xAB 0x17 0x59 0xC9 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001f81000250 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xEC 0xDB 0x47 0xA1 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPS
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPS@InstallLocation C:\Program Files\PPSGame
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@FriendlyName Indeo? video 5.10 Compression Filter
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@CLSID {1F73E9B1-8C3A-11D0-A3BE-00A0C9244436}
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@FilterData 0x02 0x00 0x00 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@EncoderType 1
---- EOF - GMER 1.0.15 ----
==========================================================
DDS (Ver_10-12-12.02) - NTFSx86
Run by user at 17:08:30.73 on 02/05/2011 Sat
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.2.950.886.1033.18.2046.1472 [GMT 8:00]
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\PPStream\ppsap.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Documents and Settings\user\Desktop\dds.scr
C:\WINDOWS\system32\conime.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.facebook.com/?ref=hp
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [PPS Accelerator] c:\program files\ppstream\ppsap.exe
uRun: [Flock Update] "c:\documents and settings\user\local settings\application data\flock\update\FlockUpdate.exe" /c
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /install
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\user\startm~1\programs\startup\viikii~1.lnk - c:\program files\viikiidesktopplugin\ViiKiiDesktopPlugin.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1296789077718
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\1ix7ps8c.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.my/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - component: c:\documents and settings\user\application data\mozilla\firefox\profiles\1ix7ps8c.default\extensions\{6ac85730-7d0f-4de0-b3fa-21142dd85326}\platform\winnt\components\ColorZilla.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\user\application data\mozilla\firefox\profiles\1ix7ps8c.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
FF - plugin: c:\program files\ahnlab\asp\components\aosmgr\conflict_221\npaosmgr.dll
FF - plugin: c:\program files\ahnlab\asp\mykeydefense 2.5\npmkd25aos.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Xmarks:
foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com
FF - Ext: Noia 2.0 eXtreme OPT:
noia2_option@kk.noia - %profile%\extensions\noia2_option@kk.noia
FF - Ext: Noia 2.0 (eXtreme): {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} - %profile%\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
FF - Ext: Black Stratini: {b41cb5f0-2e52-11de-8c30-0800200c9a66} - %profile%\extensions\{b41cb5f0-2e52-11de-8c30-0800200c9a66}
FF - Ext: ColorfulTabs: {0545b830-f0aa-4d7e-8820-50a4629a56fe} - %profile%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF - Ext: Silvermel and Charamel XT:
silvermelxt@pardal.de - %profile%\extensions\silvermelxt@pardal.de
FF - Ext: Silvermel:
silvermel@pardal.de - %profile%\extensions\silvermel@pardal.de
FF - Ext: gTranslate: {aff87fa2-a58e-4edd-b852-0a20203c1e17} - %profile%\extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}
FF - Ext: ColorZilla: {6AC85730-7D0F-4de0-B3FA-21142DD85326} - %profile%\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-3-20 11608]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-4 14336]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-3-20 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-3-20 267944]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-3-20 61960]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-9-11 27632]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2010-9-11 13224]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-02-05 04:41:00 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-02-05 04:37:58 266360 ----a-w- c:\windows\system32\TweakUI.exe
2011-02-04 16:14:33 -------- d-----w- c:\docume~1\user\applic~1\Malwarebytes
2011-02-04 16:14:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-04 16:14:29 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-02-04 16:14:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-04 16:14:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-04 03:22:45 -------- d-----w- c:\windows\system32\PreInstall
2011-02-04 03:12:27 -------- d-----w- c:\windows\system32\SoftwareDistribution
2011-02-04 03:12:25 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2011-02-04 03:12:22 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2011-02-04 03:12:21 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2011-02-04 03:12:20 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2011-01-25 07:58:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2011-01-25 06:47:09 -------- d-----w- c:\docume~1\user\applic~1\Local
2011-01-21 01:47:20 268800 ----a-w- c:\program files\windows media player\plugins\wmp_lyricsplugin.dll
2011-01-17 11:06:05 -------- d-----w- c:\docume~1\user\locals~1\applic~1\Apple
2011-01-17 11:05:45 -------- d-----w- c:\docume~1\user\locals~1\applic~1\Apple Computer
2011-01-10 13:06:08 -------- d-----w- c:\docume~1\alluse~1\applic~1\PopCap Games
==================== Find3M ====================
2010-11-29 09:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 09:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-27 14:34:26 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-11-27 14:34:26 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-11-12 10:53:06 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 08:34:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-12 00:44:54 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-11-08 22:57:04 353592 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
============= FINISH: 17:08:58.67 ===============
========================================================
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/31/2007 6:59:59 AM
System Uptime: 2/5/2011 3:01:41 PM (2 hours ago)
Motherboard: Intel Corporation | | D102GGC2
Processor: Intel(R) Pentium(R) D CPU 2.80GHz | | 2800/200mhz
Processor: Intel(R) Pentium(R) D CPU 2.80GHz | | 2800/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 92 GiB total, 58.11 GiB free.
D: is FIXED (NTFS) - 61 GiB total, 61.163 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&29C049B9&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&29C049B9&0
Service: i8042prt
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
32 Bit HP CIO Components Installer
Acrobat.com
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Photoshop CS5
Adobe Reader X
Adobe Shockwave Player 11.5
AhnLab Online Security
AIO_Scan
Akamai NetSession Interface
Apple Application Support
Apple Software Update
Avira AntiVir Personal - Free Antivirus
BitTorrent
BufferChm
Combined Community Codec Pack 2009-09-09
Copy
CustomerResearchQFolder
Destinations
DeviceManagementQFolder
DivX Setup
DJ_AIO_ProductContext
DJ_AIO_Software
DJ_AIO_Software_min
eSupportQFolder
F4100
F4100_Help
High Definition Audio Driver Package - KB888111
Hotfix for Windows XP (KB915865)
HP Customer Participation Program 8.0
HP Deskjet All-In-One Software 8.0
HP Deskjet All-In-One Software 9.0
HP Imaging Device Functions 8.0
HP Photosmart Essential
HP Product Assistant
HP Solution Center 8.0
HP Update
HPProductAssistant
HPSSupply
Intel(R) PRO Network Connections
Java Auto Updater
Java(TM) 6 Update 23
Lyrics Plugin for Windows Media Player
Malwarebytes' Anti-Malware
MarketResearch
Messenger Plus! Live
Microsoft .NET Framework 2.0
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft WSE 3.0 Runtime
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox (3.6.13)
MSVCRT
MSXML 4.0 SP2 Parser and SDK
Nero 7 Ultra Edition
neroxml
NVIDIA Drivers
NVIDIA nView Desktop Manager
NVIDIA PhysX
PCSX2 - Playstation 2 Emulator
PDF Settings CS5
PowerDVD
PPStream V2.7.0.1208 Final
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Scan
Segoe UI
SolutionCenter
Status
Toolbox
TrayApp
Tweak UI
UnloadSupport
Update for Windows XP (KB898461)
Update for Windows XP (KB932823-v3)
Update Service
VC80CRTRedist - 8.0.50727.4053
WebFldrs XP
WebReg
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format Runtime
Windows Media Player 10
WinRAR archiver
WinZip 14.5
谷歌拼音?入法 2.3
==== Event Viewer Messages From Past Week ========
2/5/2011 2:54:11 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2/5/2011 2:53:57 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/5/2011 2:53:37 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss sptd ssmdrv Tcpip
2/5/2011 2:53:37 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
2/5/2011 2:53:37 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/5/2011 2:53:37 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/5/2011 2:53:37 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/5/2011 2:52:15 PM, error: sptd [4] - Driver detected an internal error in its data structures for .
2/5/2011 12:58:28 AM, error: atapi [9] - The device, \Device\Ide\IdePort2, did not respond within the timeout period.
2/5/2011 12:48:55 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.DebugCRT. Reference error message: The referenced assembly is not installed on your system. .
2/5/2011 12:48:55 PM, error: SideBySide [59] - Generate Activation Context failed for c:\program files\real\realplayer\plugins\rmxrend.dll. Reference error message: The operation completed successfully. .
2/5/2011 12:48:55 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.DebugCRT could not be found and Last Error was The referenced assembly is not installed on your system.
2/5/2011 12:06:09 AM, error: Service Control Manager [7034] - The NMIndexingService service terminated unexpectedly. It has done this 1 time(s).
2/5/2011 12:06:08 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2011 12:06:08 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
2/5/2011 11:55:32 AM, error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort2.
2/4/2011 2:25:01 PM, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found.
==== End Of File ===========================