ESPKH2
2010-05-20, 00:10
My computer seems to be stuck running at full processing power, thus ruining my entire computing experience; Browsing, applications and internet do not run very fluently.
The task manager does not indicate anything requiring much cpu, yet it still utilizes 100% all the time. Any assistance is much appreciated!
DDS (Ver_10-03-17.01) - NTFSx86
Run by Ilan at 17:02:44.01 on Wed 05/19/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.2046.1250 [GMT -7:00]
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Ilan\Downloads\dds(2).scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.bing.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
StartupFolder: c:\users\ilan\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
================= FIREFOX ===================
FF - ProfilePath - c:\users\ilan\appdata\roaming\mozilla\firefox\profiles\r7fbbxcv.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - www.bing.com
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-5-17 64288]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1291544]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-5-18 1153368]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2010\RpcAgentSrv.exe [2010-5-19 93336]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-5-17 1343400]
=============== Created Last 30 ================
2010-05-19 21:29:30 0 d-----w- c:\program files\SiSoftware
2010-05-19 05:28:58 0 d-----w- c:\programdata\Blizzard Entertainment
2010-05-19 05:28:58 0 d-----w- c:\program files\StarCraft II Beta
2010-05-19 05:28:58 0 d-----w- c:\program files\common files\Blizzard Entertainment
2010-05-19 05:28:31 0 d-----w- c:\programdata\Blizzard
2010-05-18 22:26:49 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-05-18 22:26:49 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-05-18 20:07:51 0 d-----w- c:\program files\EA Sports
2010-05-18 20:04:24 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01009.Wdf
2010-05-18 01:16:05 84992 ----a-w- c:\windows\system32\drivers\sdbus.sys
2010-05-18 01:16:05 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-05-18 01:15:53 0 d-----w- c:\windows\system32\Wat
2010-05-17 22:55:11 0 d-----w- c:\windows\pss
2010-05-17 22:11:26 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01009.Wdf
2010-05-17 22:11:18 0 d-----w- c:\program files\Synaptics
2010-05-17 22:10:53 206120 ----a-w- c:\windows\system32\SynCtrl.dll
2010-05-17 22:10:53 169256 ----a-w- c:\windows\system32\SynCOM.dll
2010-05-17 22:10:53 120104 ----a-w- c:\windows\system32\SynTPCo4.dll
2010-05-17 22:10:52 228784 ----a-w- c:\windows\system32\drivers\SynTP.sys
2010-05-17 22:10:52 161064 ----a-w- c:\windows\system32\SynTPAPI.dll
2010-05-17 21:38:54 0 d-----w- c:\programdata\Adobe
2010-05-17 21:38:12 0 d-----w- c:\programdata\NOS
2010-05-17 09:37:30 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-05-17 09:22:58 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-05-17 09:14:48 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-05-17 09:14:48 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-05-17 09:14:47 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-05-17 09:12:13 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-05-17 08:58:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-17 08:58:07 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-17 08:52:53 0 dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-17 08:52:26 0 d-----w- c:\program files\Lavasoft
2010-05-17 08:52:25 0 d-----w- c:\programdata\Lavasoft
2010-05-17 08:21:38 0 d-----r- c:\users\ilan\Podcasts
2010-05-17 08:08:52 0 d-----w- c:\windows\PCHEALTH
2010-05-17 08:08:01 547840 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2010-05-17 06:43:29 797216 ----a-w- c:\windows\system32\nvcplui.exe
2010-05-17 06:43:29 420384 ----a-w- c:\windows\system32\nvcpl.cpl
2010-05-17 06:43:29 1108512 ----a-w- c:\windows\system32\nvcpluir.dll
2010-05-17 06:13:04 0 d-----w- c:\program files\NVIDIA Corporation
2010-05-17 05:26:12 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-05-17 05:19:42 90112 ----a-w- c:\windows\system32\snymsico.dll
2010-05-17 05:19:42 43520 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2010-05-17 05:19:42 32256 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2010-05-17 05:19:41 0 d-----w- C:\dell
2010-05-17 04:42:00 0 d-----w- c:\windows\Panther
2010-05-17 04:41:42 8192 --sha-r- C:\BOOTSECT.BAK
2010-05-17 04:41:38 383562 --sha-r- C:\bootmgr
2010-05-17 04:41:37 0 d-sh--w- C:\Boot
2010-05-17 04:32:37 0 d-----w- c:\programdata\NVIDIA
2010-05-17 04:30:06 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-17 04:28:21 0 d-sh--w- c:\windows\Installer
2010-05-17 04:15:40 713888 ----a-w- c:\windows\system32\PerfStringBackup.INI
2010-05-17 04:15:00 0 d-----w- c:\windows\system32\wbem\Performance
2010-05-17 04:05:08 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-05-17 04:04:14 132608 ----a-w- c:\windows\system32\cabview.dll
2010-05-17 03:58:49 0 d-sh--w- C:\Recovery
==================== Find3M ====================
2010-03-17 03:46:00 66664 ----a-w- c:\windows\system32\nvshext.dll
2010-03-17 03:45:52 95994 ----a-w- c:\windows\system32\nvcoproc.bin
2010-03-17 03:45:00 82024 ----a-w- c:\windows\system32\nv3dappshextr.dll
2010-03-17 03:45:00 149608 ----a-w- c:\windows\system32\nv3dappshext.dll
2010-03-17 00:01:53 88168 ----a-w- c:\windows\system32\nvinit.dll
2010-03-17 00:01:53 795104 ----a-w- c:\windows\system32\dpinst.exe
2010-03-17 00:01:53 56424 ----a-w- c:\windows\system32\OpenCL.dll
2010-03-17 00:01:53 316008 ----a-w- c:\windows\system32\nvdecodemft.dll
2010-03-17 00:01:53 2908264 ----a-w- c:\windows\system32\nvencodemft.dll
2010-03-17 00:01:53 2647144 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-03-17 00:01:53 223848 ----a-w- c:\windows\system32\nvumdshim.dll
2010-03-17 00:01:53 215656 ----a-w- c:\windows\system32\nvcod1910.dll
2010-03-17 00:01:53 2009704 ----a-w- c:\windows\system32\nvcuvid.dll
2010-03-17 00:01:53 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-03-08 21:33:56 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-03-04 07:33:23 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-02-27 12:07:48 3954568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-27 12:07:48 3899280 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-23 07:56:00 977920 ----a-w- c:\windows\system32\wininet.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 17:04:45.35 ===============
The task manager does not indicate anything requiring much cpu, yet it still utilizes 100% all the time. Any assistance is much appreciated!
DDS (Ver_10-03-17.01) - NTFSx86
Run by Ilan at 17:02:44.01 on Wed 05/19/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.2046.1250 [GMT -7:00]
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Ilan\Downloads\dds(2).scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.bing.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
StartupFolder: c:\users\ilan\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
================= FIREFOX ===================
FF - ProfilePath - c:\users\ilan\appdata\roaming\mozilla\firefox\profiles\r7fbbxcv.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - www.bing.com
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-5-17 64288]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1291544]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-5-18 1153368]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2010\RpcAgentSrv.exe [2010-5-19 93336]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-5-17 1343400]
=============== Created Last 30 ================
2010-05-19 21:29:30 0 d-----w- c:\program files\SiSoftware
2010-05-19 05:28:58 0 d-----w- c:\programdata\Blizzard Entertainment
2010-05-19 05:28:58 0 d-----w- c:\program files\StarCraft II Beta
2010-05-19 05:28:58 0 d-----w- c:\program files\common files\Blizzard Entertainment
2010-05-19 05:28:31 0 d-----w- c:\programdata\Blizzard
2010-05-18 22:26:49 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-05-18 22:26:49 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-05-18 20:07:51 0 d-----w- c:\program files\EA Sports
2010-05-18 20:04:24 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01009.Wdf
2010-05-18 01:16:05 84992 ----a-w- c:\windows\system32\drivers\sdbus.sys
2010-05-18 01:16:05 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-05-18 01:15:53 0 d-----w- c:\windows\system32\Wat
2010-05-17 22:55:11 0 d-----w- c:\windows\pss
2010-05-17 22:11:26 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01009.Wdf
2010-05-17 22:11:18 0 d-----w- c:\program files\Synaptics
2010-05-17 22:10:53 206120 ----a-w- c:\windows\system32\SynCtrl.dll
2010-05-17 22:10:53 169256 ----a-w- c:\windows\system32\SynCOM.dll
2010-05-17 22:10:53 120104 ----a-w- c:\windows\system32\SynTPCo4.dll
2010-05-17 22:10:52 228784 ----a-w- c:\windows\system32\drivers\SynTP.sys
2010-05-17 22:10:52 161064 ----a-w- c:\windows\system32\SynTPAPI.dll
2010-05-17 21:38:54 0 d-----w- c:\programdata\Adobe
2010-05-17 21:38:12 0 d-----w- c:\programdata\NOS
2010-05-17 09:37:30 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-05-17 09:22:58 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-05-17 09:14:48 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-05-17 09:14:48 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-05-17 09:14:47 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-05-17 09:12:13 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-05-17 08:58:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-17 08:58:07 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-17 08:52:53 0 dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-17 08:52:26 0 d-----w- c:\program files\Lavasoft
2010-05-17 08:52:25 0 d-----w- c:\programdata\Lavasoft
2010-05-17 08:21:38 0 d-----r- c:\users\ilan\Podcasts
2010-05-17 08:08:52 0 d-----w- c:\windows\PCHEALTH
2010-05-17 08:08:01 547840 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2010-05-17 06:43:29 797216 ----a-w- c:\windows\system32\nvcplui.exe
2010-05-17 06:43:29 420384 ----a-w- c:\windows\system32\nvcpl.cpl
2010-05-17 06:43:29 1108512 ----a-w- c:\windows\system32\nvcpluir.dll
2010-05-17 06:13:04 0 d-----w- c:\program files\NVIDIA Corporation
2010-05-17 05:26:12 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-05-17 05:19:42 90112 ----a-w- c:\windows\system32\snymsico.dll
2010-05-17 05:19:42 43520 ----a-w- c:\windows\system32\drivers\rimsptsk.sys
2010-05-17 05:19:42 32256 ----a-w- c:\windows\system32\drivers\rimmptsk.sys
2010-05-17 05:19:41 0 d-----w- C:\dell
2010-05-17 04:42:00 0 d-----w- c:\windows\Panther
2010-05-17 04:41:42 8192 --sha-r- C:\BOOTSECT.BAK
2010-05-17 04:41:38 383562 --sha-r- C:\bootmgr
2010-05-17 04:41:37 0 d-sh--w- C:\Boot
2010-05-17 04:32:37 0 d-----w- c:\programdata\NVIDIA
2010-05-17 04:30:06 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-17 04:28:21 0 d-sh--w- c:\windows\Installer
2010-05-17 04:15:40 713888 ----a-w- c:\windows\system32\PerfStringBackup.INI
2010-05-17 04:15:00 0 d-----w- c:\windows\system32\wbem\Performance
2010-05-17 04:05:08 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-05-17 04:04:14 132608 ----a-w- c:\windows\system32\cabview.dll
2010-05-17 03:58:49 0 d-sh--w- C:\Recovery
==================== Find3M ====================
2010-03-17 03:46:00 66664 ----a-w- c:\windows\system32\nvshext.dll
2010-03-17 03:45:52 95994 ----a-w- c:\windows\system32\nvcoproc.bin
2010-03-17 03:45:00 82024 ----a-w- c:\windows\system32\nv3dappshextr.dll
2010-03-17 03:45:00 149608 ----a-w- c:\windows\system32\nv3dappshext.dll
2010-03-17 00:01:53 88168 ----a-w- c:\windows\system32\nvinit.dll
2010-03-17 00:01:53 795104 ----a-w- c:\windows\system32\dpinst.exe
2010-03-17 00:01:53 56424 ----a-w- c:\windows\system32\OpenCL.dll
2010-03-17 00:01:53 316008 ----a-w- c:\windows\system32\nvdecodemft.dll
2010-03-17 00:01:53 2908264 ----a-w- c:\windows\system32\nvencodemft.dll
2010-03-17 00:01:53 2647144 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-03-17 00:01:53 223848 ----a-w- c:\windows\system32\nvumdshim.dll
2010-03-17 00:01:53 215656 ----a-w- c:\windows\system32\nvcod1910.dll
2010-03-17 00:01:53 2009704 ----a-w- c:\windows\system32\nvcuvid.dll
2010-03-17 00:01:53 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-03-08 21:33:56 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-03-04 07:33:23 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-02-27 12:07:48 3954568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-27 12:07:48 3899280 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-23 07:56:00 977920 ----a-w- c:\windows\system32\wininet.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 17:04:45.35 ===============