Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4993
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
10/29/2010 5:50:48 PM
mbam-log-2010-10-29 (17-50-48).txt
Scan type: Quick scan
Objects scanned: 138728
Time elapsed: 4 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15477 - http://www.gmer.net
Rootkit scan 2010-10-29 17:44:39
Windows 6.1.7600
Running: 5s08s842.exe; Driver: C:\Users\GARYBU~1\AppData\Local\Temp\awliypoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A89599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AADF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9123A000, 0x2D5378, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[3524] ntdll.dll!LdrLoadDll 7772F625 5 Bytes JMP 002B13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3676] USER32.dll!TrackPopupMenu 75BB4B3B 5 Bytes JMP 6C105CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 91F 7638B9EC 4 Bytes [89, 92, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 927 7638B9F4 4 Bytes [A4, 91, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 943 7638BA10 4 Bytes [89, 92, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 94C 7638BA19 3 Bytes [91, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 95F 7638BA2C 4 Bytes [0E, 67, 49, 6A]
.text ...
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!SHCreateDirectoryExW + E08 763DDFB0 4 Bytes [89, 92, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!SHCreateDirectoryExW + E10 763DDFB8 8 Bytes [A4, 91, 4A, 6A, 2C, 93, 4A, ...]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\secur32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000051 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 862D9AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP3T1L0-4 862D9AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 862D9AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 862D9AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 862D9AEA
Device \Device\Ide\IdeDeviceP3T0L0-3 -> \??\IDE#DiskST3160023A______________________________8.01____#5&2819fc14&0&1.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- EOF - GMER 1.0.15 ----
DDS (Ver_10-10-21.02) - NTFSx86
Run by Gary Buriani at 17:53:54.61 on Fri 10/29/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_15
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3327.2196 [GMT -7:00]
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\CtHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\SearchIndexer.exe
C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe
C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe
C:\Windows\system32\conhost.exe
C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Users\Gary Buriani\Desktop\dds.scr
C:\Windows\system32\conhost.exe
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = <local>
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRunOnce: [wextract_cleanup0] rundll32.exe c:\windows\system32\advpack.dll,delnoderundll32 "c:\users\garybu~1\appdata\local\temp\ixp000.tmp\"
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\garybu~1\appdata\roaming\mozilla\firefox\profiles\zndw0ill.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - HiddenExtension: XULRunner: {E1C89B07-1D7F-4846-9B4F-EFCE33EE95A3} - c:\users\gary buriani\appdata\local\{e1c89b07-1d7f-4846-9b4f-efce33ee95a3}\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-7-9 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-7-9 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-7-9 60936]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
=============== Created Last 30 ================
2010-10-30 00:17:24 6146896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{0ee410d9-e87c-4a67-8088-e5d73119bf9f}\mpengine.dll
2010-10-26 17:28:31 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-26 17:28:31 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-26 17:28:30 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-26 17:28:30 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-26 17:28:00 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-20 14:01:08 469256 ----a-w- c:\program files\common files\windows live\.cache\3d8452181cb705f2d\InstallManager_WLE_WLE.exe
2010-10-20 14:00:53 15712 ----a-w- c:\program files\common files\windows live\.cache\351450c71cb705f22\MeshBetaRemover.exe
2010-10-20 14:00:39 94040 ----a-w- c:\program files\common files\windows live\.cache\2cd9b81f1cb705f1a\DSETUP.dll
2010-10-20 14:00:39 525656 ----a-w- c:\program files\common files\windows live\.cache\2cd9b81f1cb705f1a\DXSETUP.exe
2010-10-20 14:00:39 1691480 ----a-w- c:\program files\common files\windows live\.cache\2cd9b81f1cb705f1a\dsetup32.dll
2010-10-20 14:00:38 94040 ----a-w- c:\program files\common files\windows live\.cache\2c0cc82f1cb705f19\DSETUP.dll
2010-10-20 14:00:38 525656 ----a-w- c:\program files\common files\windows live\.cache\2c0cc82f1cb705f19\DXSETUP.exe
2010-10-20 14:00:38 1691480 ----a-w- c:\program files\common files\windows live\.cache\2c0cc82f1cb705f19\dsetup32.dll
2010-10-20 14:00:17 6260088 ----a-w- c:\program files\common files\windows live\.cache\1f01d0bb1cb705f0e\Silverlight.4.0.exe
2010-10-20 13:59:47 -------- d-----w- c:\users\garybu~1\appdata\local\Windows Live
2010-10-20 13:59:22 3181568 ----a-w- c:\windows\system32\mf.dll
2010-10-20 13:59:22 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-10-20 13:59:21 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2010-10-20 01:17:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-10-20 01:06:31 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-20 01:06:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-18 21:28:30 388096 ----a-r- c:\users\garybu~1\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2010-10-14 04:56:59 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-14 04:56:59 308736 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-14 04:56:59 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-10-14 04:56:59 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-14 04:56:59 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-14 04:56:58 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-10-14 04:56:57 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2010-10-07 14:24:37 674280 ----a-w- c:\windows\system32\thescarecrow_3264060.scr
2010-10-07 14:22:17 674280 ----a-w- c:\windows\system32\thethanksgivingfeast_3264061.scr
2010-09-30 21:25:16 30376 ----a-w- c:\windows\system32\drivers\ElbyCDIO.sys
2010-09-30 11:18:24 89256 ----a-w- c:\windows\system32\ElbyCDIO.dll
2010-09-30 04:21:51 190976 ----a-w- c:\windows\system32\drivers\ks.sys
==================== Find3M ====================
2010-10-19 18:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-09-21 21:03:14 208768 ----a-w- c:\windows\system32\LIVESSP.DLL
2010-09-08 04:30:04 978432 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22:31 386048 ----a-w- c:\windows\system32\html.iec
2010-09-08 02:48:16 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-05 02:29:16 87608 ----a-w- c:\users\garybu~1\appdata\roaming\inst.exe
2010-09-05 02:29:16 47360 ----a-w- c:\users\garybu~1\appdata\roaming\pcouffin.sys
2010-09-01 04:23:49 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-08-31 04:32:30 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-08-26 21:22:44 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-08-26 04:39:58 109056 ----a-w- c:\windows\system32\t2embed.dll
2010-08-21 05:36:24 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-21 05:33:24 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-08-21 05:32:37 316928 ----a-w- c:\windows\system32\spoolsv.exe
============= FINISH: 17:54:32.45 ===============
www.malwarebytes.org
Database version: 4993
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
10/29/2010 5:50:48 PM
mbam-log-2010-10-29 (17-50-48).txt
Scan type: Quick scan
Objects scanned: 138728
Time elapsed: 4 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15477 - http://www.gmer.net
Rootkit scan 2010-10-29 17:44:39
Windows 6.1.7600
Running: 5s08s842.exe; Driver: C:\Users\GARYBU~1\AppData\Local\Temp\awliypoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A89599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AADF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9123A000, 0x2D5378, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[3524] ntdll.dll!LdrLoadDll 7772F625 5 Bytes JMP 002B13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3676] USER32.dll!TrackPopupMenu 75BB4B3B 5 Bytes JMP 6C105CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 91F 7638B9EC 4 Bytes [89, 92, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 927 7638B9F4 4 Bytes [A4, 91, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 943 7638BA10 4 Bytes [89, 92, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 94C 7638BA19 3 Bytes [91, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!PathIsExe + 95F 7638BA2C 4 Bytes [0E, 67, 49, 6A]
.text ...
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!SHCreateDirectoryExW + E08 763DDFB0 4 Bytes [89, 92, 4A, 6A]
.text C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] SHELL32.dll!SHCreateDirectoryExW + E10 763DDFB8 8 Bytes [A4, 91, 4A, 6A, 2C, 93, 4A, ...]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe[1860] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe[2556] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe[3952] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe[3972] @ C:\Windows\system32\secur32.dll [KERNEL32.dll!GetProcAddress] [75675E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000051 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 862D9AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP3T1L0-4 862D9AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 862D9AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 862D9AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 862D9AEA
Device \Device\Ide\IdeDeviceP3T0L0-3 -> \??\IDE#DiskST3160023A______________________________8.01____#5&2819fc14&0&1.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- EOF - GMER 1.0.15 ----
DDS (Ver_10-10-21.02) - NTFSx86
Run by Gary Buriani at 17:53:54.61 on Fri 10/29/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_15
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3327.2196 [GMT -7:00]
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\CtHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\SearchIndexer.exe
C:\Users\Gary Buriani\Documents\ShowMyPC3010.exe
C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\SMPCSetup.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\sps.exe
C:\Windows\system32\conhost.exe
C:\Users\GARYBU~1\AppData\Local\Temp\IXP000.TMP\smwinvnc.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Users\Gary Buriani\Desktop\dds.scr
C:\Windows\system32\conhost.exe
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = <local>
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRunOnce: [wextract_cleanup0] rundll32.exe c:\windows\system32\advpack.dll,delnoderundll32 "c:\users\garybu~1\appdata\local\temp\ixp000.tmp\"
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\garybu~1\appdata\roaming\mozilla\firefox\profiles\zndw0ill.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - HiddenExtension: XULRunner: {E1C89B07-1D7F-4846-9B4F-EFCE33EE95A3} - c:\users\gary buriani\appdata\local\{e1c89b07-1d7f-4846-9b4f-efce33ee95a3}\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-7-9 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-7-9 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-7-9 60936]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
=============== Created Last 30 ================
2010-10-30 00:17:24 6146896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{0ee410d9-e87c-4a67-8088-e5d73119bf9f}\mpengine.dll
2010-10-26 17:28:31 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-26 17:28:31 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-26 17:28:30 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-26 17:28:30 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-26 17:28:00 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-20 14:01:08 469256 ----a-w- c:\program files\common files\windows live\.cache\3d8452181cb705f2d\InstallManager_WLE_WLE.exe
2010-10-20 14:00:53 15712 ----a-w- c:\program files\common files\windows live\.cache\351450c71cb705f22\MeshBetaRemover.exe
2010-10-20 14:00:39 94040 ----a-w- c:\program files\common files\windows live\.cache\2cd9b81f1cb705f1a\DSETUP.dll
2010-10-20 14:00:39 525656 ----a-w- c:\program files\common files\windows live\.cache\2cd9b81f1cb705f1a\DXSETUP.exe
2010-10-20 14:00:39 1691480 ----a-w- c:\program files\common files\windows live\.cache\2cd9b81f1cb705f1a\dsetup32.dll
2010-10-20 14:00:38 94040 ----a-w- c:\program files\common files\windows live\.cache\2c0cc82f1cb705f19\DSETUP.dll
2010-10-20 14:00:38 525656 ----a-w- c:\program files\common files\windows live\.cache\2c0cc82f1cb705f19\DXSETUP.exe
2010-10-20 14:00:38 1691480 ----a-w- c:\program files\common files\windows live\.cache\2c0cc82f1cb705f19\dsetup32.dll
2010-10-20 14:00:17 6260088 ----a-w- c:\program files\common files\windows live\.cache\1f01d0bb1cb705f0e\Silverlight.4.0.exe
2010-10-20 13:59:47 -------- d-----w- c:\users\garybu~1\appdata\local\Windows Live
2010-10-20 13:59:22 3181568 ----a-w- c:\windows\system32\mf.dll
2010-10-20 13:59:22 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-10-20 13:59:21 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2010-10-20 01:17:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-10-20 01:06:31 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-20 01:06:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-18 21:28:30 388096 ----a-r- c:\users\garybu~1\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2010-10-14 04:56:59 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-14 04:56:59 308736 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-14 04:56:59 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-10-14 04:56:59 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-14 04:56:59 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-14 04:56:58 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-10-14 04:56:57 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2010-10-07 14:24:37 674280 ----a-w- c:\windows\system32\thescarecrow_3264060.scr
2010-10-07 14:22:17 674280 ----a-w- c:\windows\system32\thethanksgivingfeast_3264061.scr
2010-09-30 21:25:16 30376 ----a-w- c:\windows\system32\drivers\ElbyCDIO.sys
2010-09-30 11:18:24 89256 ----a-w- c:\windows\system32\ElbyCDIO.dll
2010-09-30 04:21:51 190976 ----a-w- c:\windows\system32\drivers\ks.sys
==================== Find3M ====================
2010-10-19 18:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-09-21 21:03:14 208768 ----a-w- c:\windows\system32\LIVESSP.DLL
2010-09-08 04:30:04 978432 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22:31 386048 ----a-w- c:\windows\system32\html.iec
2010-09-08 02:48:16 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-05 02:29:16 87608 ----a-w- c:\users\garybu~1\appdata\roaming\inst.exe
2010-09-05 02:29:16 47360 ----a-w- c:\users\garybu~1\appdata\roaming\pcouffin.sys
2010-09-01 04:23:49 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-08-31 04:32:30 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-08-26 21:22:44 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-08-26 04:39:58 109056 ----a-w- c:\windows\system32\t2embed.dll
2010-08-21 05:36:24 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-21 05:33:24 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-08-21 05:32:37 316928 ----a-w- c:\windows\system32\spoolsv.exe
============= FINISH: 17:54:32.45 ===============