fangus123
2010-05-23, 21:54
DDS Log:
DDS (Ver_10-03-17.01) - NTFSX64
Run by Angus Wilsown at 19:30:03.79 on 23/05/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.4095.2296 [GMT 1:00]
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files (x86)\NetMeter\NetMeter.exe
C:\Users\Angus Wilsown\Local Settings\Apps\F.lux\flux.exe
C:\Program Files (x86)\Wallpaper Master\Wallpaper.exe
C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
C:\Program Files (x86)\Everything\Everything.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Auzentech\Auzen X-Fi Prelude 7.1\Volume Panel\VolPanlu.exe
C:\Windows\SysWOW64\CTXFIHLP.EXE
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\foobar2000\foobar2000.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
G:\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=userinit.exe
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~2\mif5ba~1\office14\GROOVEEX.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\mif5ba~1\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
uRun: [c:\program files (x86)\netmeter\netmeter.exe] c:\program files (x86)\netmeter\NetMeter.exe
uRun: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
uRun: [F.lux] "c:\users\angus wilsown\local settings\apps\f.lux\flux.exe" /noshow
uRun: [WallpaperChanger] c:\program files (x86)\wallpaper master\Wallpaper.exe
mRun: [DeathAdder] c:\program files (x86)\razer\deathadder\razerhid.exe
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Everything] "c:\program files (x86)\everything\Everything.exe" -startup
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files (x86)\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files (x86)\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~2\mif5ba~1\office14\GROOVEEX.DLL
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun-x64: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun-x64: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun-x64: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun-x64: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\angusw~1\appdata\roaming\mozilla\firefox\profiles\febeprof.angus\
FF - prefs.js: browser.search.selectedEngine - The Pirate Bay
FF - component: c:\users\angus wilsown\appdata\roaming\mozilla\firefox\profiles\febeprof.angus\extensions\{81bf1d23-5f17-408d-ac6b-bd6df7caf670}\components\XpcomOpusConnector.dll
FF - plugin: c:\progra~2\mif5ba~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~2\mif5ba~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files (x86)\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files (x86)\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files (x86)\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files (x86)\opera 10 beta\program\plugins\NPSWF32.dll
FF - plugin: c:\program files (x86)\opera\program\plugins\np_gp.dll
FF - plugin: c:\program files (x86)\opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files (x86)\opera\program\plugins\nprpjplug.dll
FF - plugin: c:\users\angus wilsown\appdata\local\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\users\angus wilsown\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251);c:\windows\system32\drivers\tdrpm251.sys [2009-12-13 1455648]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 173984]
R2 MSSQL$BWDATOOLSET;SQL Server (BWDATOOLSET);c:\program files (x86)\daodb\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2009-12-17 1153368]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2010-3-3 6402560]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-3-3 188928]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l160x64.sys [2009-10-13 61440]
R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2010-2-13 12928]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 22408]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 16008]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-6-18 40832]
S2 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2010-5-8 136176]
S2 MSWU-d6cebc64;MSWU-d6cebc64;c:\windows\system32\d6cebc64.exe --> c:\windows\system32\d6cebc64.exe [?]
S3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2009-12-13 250400]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;c:\program files (x86)\common files\creative labs shared\service\AL1Licensing.exe [2010-5-1 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2010-5-1 79360]
S3 CYUSB;Cypress Generic USB Driver;c:\windows\system32\drivers\CYUSB.sys [2010-2-13 47104]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-26 25832]
S3 HTCAND64;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2009-10-26 32768]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam_x64.sys [2008-3-13 27136]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 51445112]
S3 ose64;Office 64 Source Engine;c:\program files\common files\microsoft shared\source engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-5-23 31800]
S3 SaiHF51A;SaiHF51A;c:\windows\system32\drivers\SaiHF51A.sys [2007-5-31 175880]
S3 SaiUF51A;SaiUF51A;c:\windows\system32\drivers\SaiUF51A.sys [2007-5-31 34432]
S4 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\common files\acronis\cdp\afcdpsrv.exe [2009-12-13 2326920]
S4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-3-3 202752]
=============== Created Last 30 ================
2010-05-23 15:00:28 75264 ----a-w- c:\windows\syswow64\d6cebc64.exe
2010-05-23 14:30:56 11 ----a-r- c:\windows\amunres.lsl
2010-05-23 10:37:12 31800 ----a-w- c:\windows\system32\drivers\revoflt.sys
2010-05-23 10:37:11 0 d-----w- c:\program files\VS Revo Group
2010-05-22 08:40:03 0 d-----w- c:\programdata\Logitech
2010-05-22 08:40:02 0 d-----w- c:\program files\Logitech
2010-05-20 21:56:40 8431 ----a-w- c:\users\angus wilsown\.recently-used.xbel
2010-05-17 11:08:30 0 d-----w- c:\program files (x86)\MSXML 4.0
2010-05-16 22:27:01 0 d-----w- c:\users\angusw~1\appdata\roaming\Mael
2010-05-16 22:24:05 0 d-----w- c:\program files (x86)\HxD
2010-05-16 22:12:35 0 d-----w- c:\programdata\HTC
2010-05-16 22:12:33 0 d-----w- c:\programdata\Teleca
2010-05-16 22:12:04 0 d-----w- c:\program files (x86)\Spirent Communications
2010-05-16 21:57:11 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_WinUsb_01007.Wdf
2010-05-16 21:54:39 708168 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2010-05-16 20:54:48 0 d-----w- c:\users\angusw~1\appdata\roaming\FastSum
2010-05-16 20:54:21 0 d-----w- c:\program files (x86)\FastSum
2010-05-16 20:47:07 0 d-----w- C:\ruu_log
2010-05-16 20:42:30 0 d-----w- c:\users\angus wilsown\.android
2010-05-16 20:40:45 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-05-16 18:06:07 0 d-----w- c:\program files (x86)\common files\HP
2010-05-16 18:06:05 0 d-----w- c:\program files (x86)\common files\Hewlett-Packard
2010-05-16 18:05:44 136704 ----a-w- c:\windows\system32\hpf3l70w.dll
2010-05-16 18:05:30 0 d-----w- c:\program files (x86)\HP
2010-05-16 18:04:25 532 ------w- c:\windows\hpomdl46.dat
2010-05-16 18:04:25 173146 ----a-w- c:\windows\hpoins46.dat
2010-05-16 18:04:23 0 d-----w- c:\programdata\HP
2010-05-16 18:04:13 881664 ----a-w- c:\windows\system32\hposwia_d02d.dll
2010-05-16 18:04:13 642360 ----a-w- c:\windows\system32\hpzids40.dll
2010-05-16 18:04:13 551424 ----a-w- c:\windows\system32\hppldcoi.dll
2010-05-16 18:04:12 749056 ----a-w- c:\windows\system32\hpost_d02d.dll
2010-05-16 18:04:12 516096 ----a-w- c:\windows\system32\hposc_d02a.dll
2010-05-16 17:16:08 0 d-----w- c:\users\angusw~1\appdata\roaming\Canneverbe Limited
2010-05-16 17:16:07 0 d-----w- c:\programdata\Canneverbe Limited
2010-05-16 17:15:57 0 d-----w- c:\program files\CDBurnerXP
2010-05-14 20:23:00 0 d-----w- c:\program files\HTC
2010-05-14 20:22:33 0 ----a-w- c:\windows\DbgOut.INI
2010-05-14 19:59:46 0 d-----w- c:\users\angusw~1\appdata\roaming\Teleca
2010-05-14 19:58:38 0 d-----w- c:\program files (x86)\HTC
2010-05-13 20:11:46 0 d-----w- c:\program files (x86)\gish153
2010-05-13 20:11:04 0 d-----w- c:\program files (x86)\Lugaru
2010-05-13 20:09:51 0 d-----w- c:\program files (x86)\Samorost2
2010-05-13 19:26:45 0 d-----w- c:\program files (x86)\Aquaria
2010-05-12 08:31:50 976896 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-12 08:31:49 740864 ----a-w- c:\windows\syswow64\inetcomm.dll
2010-05-11 09:51:21 180224 ----a-w- c:\windows\syswow64\QTCF.dll
2010-05-10 16:30:59 0 d-----w- C:\temp
2010-05-10 16:30:54 0 d-----w- c:\users\angusw~1\appdata\roaming\zenses
2010-05-10 16:30:54 0 d-----w- c:\program files (x86)\Zenses2
2010-05-08 16:06:06 0 d-----w- c:\users\angusw~1\appdata\roaming\PeaZip
2010-05-08 16:03:43 0 d-----w- c:\program files\PeaZip
2010-05-03 15:39:51 0 d-----w- c:\users\angusw~1\appdata\roaming\.matplotlib
2010-05-01 21:23:25 0 d-----w- c:\users\angus wilsown\.gimp-2.6
2010-05-01 21:02:31 788 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000002-00001102-00000005-0034415A}.rfx
2010-05-01 21:02:31 60888 ----a-w- c:\windows\system32\BMXStateBkp-{00000004-00000000-00000002-00001102-00000005-0034415A}.rfx
2010-05-01 21:02:31 60888 ----a-w- c:\windows\system32\BMXState-{00000004-00000000-00000002-00001102-00000005-0034415A}.rfx
2010-05-01 21:00:44 90112 ------w- c:\windows\Updreg.EXE
2010-05-01 21:00:23 102400 ----a-w- c:\windows\syswow64\cttele32.dll
2010-05-01 21:00:22 108032 ----a-w- c:\windows\system32\cttele64.dll
2010-05-01 20:59:35 89088 ----a-w- c:\windows\system32\CmdRtr64.DLL
2010-05-01 20:59:35 73728 ----a-w- c:\windows\syswow64\CmdRtr.DLL
2010-05-01 20:59:35 191488 ----a-w- c:\windows\system32\APOMgr64.DLL
2010-05-01 20:59:35 159 ---ha-r- c:\windows\ctfile.rfc
2010-05-01 20:59:35 148480 ----a-w- c:\windows\syswow64\APOMngr.DLL
2010-05-01 20:58:10 0 d-----w- c:\program files (x86)\common files\Creative Labs Shared
2010-05-01 20:57:59 0 d-----w- c:\program files\Creative
2010-04-28 07:21:47 14336 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-04-28 06:40:29 223448 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-04-28 06:39:55 96768 ----a-w- c:\windows\syswow64\sspicli.dll
2010-04-28 06:39:55 22016 ----a-w- c:\windows\syswow64\secur32.dll
2010-04-28 06:39:55 153160 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-04-28 06:39:55 1446912 ----a-w- c:\windows\system32\lsasrv.dll
2010-04-28 06:39:55 12867072 ----a-w- c:\windows\syswow64\shell32.dll
2010-04-25 12:17:09 0 d-----w- c:\program files\7-Zip
==================== Find3M ====================
2010-05-21 18:58:06 1077 ----a-w- c:\program files\cports.cfg
2010-05-06 09:36:38 270208 ------w- c:\windows\system32\MpSigStub.exe
2010-05-01 20:59:48 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2010-05-01 20:59:48 444952 ----a-w- c:\windows\syswow64\wrap_oal.dll
2010-04-20 19:19:27 411368 ----a-w- c:\windows\syswow64\deployJava1.dll
2010-04-20 19:19:27 153376 ----a-w- c:\windows\syswow64\javaws.exe
2010-04-20 19:19:27 145184 ----a-w- c:\windows\syswow64\javaw.exe
2010-04-20 19:19:27 145184 ----a-w- c:\windows\syswow64\java.exe
2010-03-14 18:44:42 51594 ----a-w- c:\users\angusw~1\appdata\roaming\unins000.dat
2010-03-14 18:41:49 867610 ----a-w- c:\users\angusw~1\appdata\roaming\unins000.exe
2010-03-08 21:59:59 612352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 21:33:56 427520 ----a-w- c:\windows\syswow64\vbscript.dll
2010-03-03 04:16:38 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-03-03 04:16:26 446464 ----a-w- c:\windows\syswow64\aticfx32.dll
2010-03-03 04:15:30 497152 ----a-w- c:\windows\system32\aticfx64.dll
2010-03-03 04:13:04 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-03-03 04:12:52 450560 ----a-w- c:\windows\system32\atieclxx.exe
2010-03-03 04:12:12 202752 ----a-w- c:\windows\system32\atiesrxx.exe
2010-03-03 04:10:34 120320 ----a-w- c:\windows\system32\atitmm64.dll
2010-03-03 04:10:12 420864 ----a-w- c:\windows\system32\atipdl64.dll
2010-03-03 04:10:04 356352 ----a-w- c:\windows\syswow64\atipdlxx.dll
2010-03-03 04:09:48 274432 ----a-w- c:\windows\syswow64\Oemdspif.dll
2010-03-03 04:09:40 12288 ----a-w- c:\windows\system32\atimuixx.dll
2010-03-03 04:09:34 59392 ----a-w- c:\windows\system32\atiedu64.dll
2010-03-03 04:09:28 43520 ----a-w- c:\windows\syswow64\ati2edxx.dll
2010-03-03 04:06:18 3131392 ----a-w- c:\windows\syswow64\atidxx32.dll
2010-03-03 04:04:46 18798080 ----a-w- c:\windows\system32\atio6axx.dll
2010-03-03 03:57:00 3800576 ----a-w- c:\windows\system32\atidxx64.dll
2010-03-03 03:46:42 3703808 ----a-w- c:\windows\syswow64\atiumdag.dll
2010-03-03 03:45:02 14226944 ----a-w- c:\windows\syswow64\atioglxx.dll
2010-03-03 03:39:46 4801536 ----a-w- c:\windows\system32\atiumd64.dll
2010-03-03 03:32:06 2716160 ----a-w- c:\windows\system32\atiumd6a.dll
2010-03-03 03:24:24 2993152 ----a-w- c:\windows\syswow64\atiumdva.dll
2010-03-03 03:23:52 55296 ----a-w- c:\windows\system32\coinst.dll
2010-03-03 03:20:22 43008 ----a-w- c:\windows\system32\aticalrt64.dll
2010-03-03 03:20:20 53248 ----a-w- c:\windows\syswow64\aticalrt.dll
2010-03-03 03:20:10 39936 ----a-w- c:\windows\system32\aticalcl64.dll
2010-03-03 03:20:08 53248 ----a-w- c:\windows\syswow64\aticalcl.dll
2010-03-03 03:19:56 4781568 ----a-w- c:\windows\system32\aticaldd64.dll
2010-03-03 03:18:56 3657728 ----a-w- c:\windows\syswow64\aticaldd.dll
2010-03-03 03:08:50 53248 ----a-w- c:\windows\system32\atimpc64.dll
2010-03-03 03:08:50 53248 ----a-w- c:\windows\system32\amdpcom64.dll
2010-03-03 03:08:44 52224 ----a-w- c:\windows\syswow64\atimpc32.dll
2010-03-03 03:08:44 52224 ----a-w- c:\windows\syswow64\amdpcom32.dll
2010-03-03 03:08:14 330752 ----a-w- c:\windows\system32\atiadlxx.dll
2010-03-03 03:08:06 237568 ----a-w- c:\windows\syswow64\atiadlxy.dll
2010-03-03 03:07:54 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2010-03-03 03:07:48 12800 ----a-w- c:\windows\syswow64\atiglpxx.dll
2010-03-03 03:07:48 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-03-03 03:07:44 16896 ----a-w- c:\windows\system32\atig6txx.dll
2010-03-03 03:07:38 15360 ----a-w- c:\windows\syswow64\atigktxx.dll
2010-03-03 03:06:50 36352 ----a-w- c:\windows\system32\atiuxp64.dll
2010-03-03 03:06:42 27648 ----a-w- c:\windows\syswow64\atiuxpag.dll
2010-03-03 03:06:34 28160 ----a-w- c:\windows\system32\atiu9p64.dll
2010-03-03 03:06:26 20480 ----a-w- c:\windows\syswow64\atiu9pag.dll
2010-02-27 20:35:37 76852 ----a-r- c:\windows\fonts\tesla_regular.ttf
2010-02-27 15:17:00 5509008 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-27 12:07:48 3954568 ----a-w- c:\windows\syswow64\ntkrnlpa.exe
2010-02-27 12:07:48 3899280 ----a-w- c:\windows\syswow64\ntoskrnl.exe
2010-02-25 19:55:46 201875 ----a-w- c:\windows\system32\atiicdxx.dat
2010-02-23 08:22:50 1192960 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 08:16:17 294912 ----a-w- c:\windows\system32\browserchoice.exe
2010-02-23 07:56:00 977920 ----a-w- c:\windows\syswow64\wininet.dll
2010-02-23 07:55:56 1225216 ----a-w- c:\windows\syswow64\urlmon.dll
2010-02-23 07:55:45 606208 ----a-w- c:\windows\syswow64\mstime.dll
2010-02-23 07:55:43 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2010-02-23 07:55:43 5964800 ----a-w- c:\windows\syswow64\mshtml.dll
2010-02-23 07:55:24 10978816 ----a-w- c:\windows\syswow64\ieframe.dll
2010-02-23 07:55:20 381440 ----a-w- c:\windows\syswow64\iedkcs32.dll
2009-11-06 14:03:12 19017 ----a-w- c:\program files\readme.txt
2009-11-06 14:03:12 18364 ----a-w- c:\program files\cports.chm
2009-11-06 14:02:12 49664 ----a-w- c:\program files\cports.exe
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2010-01-23 10:28:18 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 19:32:11.75 ===============
Hi.
Microsoft Security Essentials detected a trojan named 'brj.exe.'. It said my PC needed to be restarted before it could be removed. When my PC was restarted I could no longer connect to the internet, Windows reported my PC as connected to the internet, but nothing was working. Pinging my router worked, but pinging google.com gave me a lookup error. The only thing that works is steam friends for some reason :confused:. I also found 3 suspicious processes; logger.exe, capabilitymanager.exe and generic.exe all running from
C:\Program Files (x86)\Common Files\Teleca Shared, which I have now deleted. Spybot detected some malwate, however it said it needed to be restarted for them to be removed, but on restart they were no longer found. The network is definitely working
Thanks
Angus.
DDS (Ver_10-03-17.01) - NTFSX64
Run by Angus Wilsown at 19:30:03.79 on 23/05/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.4095.2296 [GMT 1:00]
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files (x86)\NetMeter\NetMeter.exe
C:\Users\Angus Wilsown\Local Settings\Apps\F.lux\flux.exe
C:\Program Files (x86)\Wallpaper Master\Wallpaper.exe
C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
C:\Program Files (x86)\Everything\Everything.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Auzentech\Auzen X-Fi Prelude 7.1\Volume Panel\VolPanlu.exe
C:\Windows\SysWOW64\CTXFIHLP.EXE
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\foobar2000\foobar2000.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
G:\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=userinit.exe
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~2\mif5ba~1\office14\GROOVEEX.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\mif5ba~1\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
uRun: [c:\program files (x86)\netmeter\netmeter.exe] c:\program files (x86)\netmeter\NetMeter.exe
uRun: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
uRun: [F.lux] "c:\users\angus wilsown\local settings\apps\f.lux\flux.exe" /noshow
uRun: [WallpaperChanger] c:\program files (x86)\wallpaper master\Wallpaper.exe
mRun: [DeathAdder] c:\program files (x86)\razer\deathadder\razerhid.exe
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Everything] "c:\program files (x86)\everything\Everything.exe" -startup
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files (x86)\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files (x86)\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~2\mif5ba~1\office14\GROOVEEX.DLL
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun-x64: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun-x64: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun-x64: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun-x64: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\angusw~1\appdata\roaming\mozilla\firefox\profiles\febeprof.angus\
FF - prefs.js: browser.search.selectedEngine - The Pirate Bay
FF - component: c:\users\angus wilsown\appdata\roaming\mozilla\firefox\profiles\febeprof.angus\extensions\{81bf1d23-5f17-408d-ac6b-bd6df7caf670}\components\XpcomOpusConnector.dll
FF - plugin: c:\progra~2\mif5ba~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~2\mif5ba~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files (x86)\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files (x86)\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files (x86)\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files (x86)\opera 10 beta\program\plugins\NPSWF32.dll
FF - plugin: c:\program files (x86)\opera\program\plugins\np_gp.dll
FF - plugin: c:\program files (x86)\opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files (x86)\opera\program\plugins\nprpjplug.dll
FF - plugin: c:\users\angus wilsown\appdata\local\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\users\angus wilsown\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251);c:\windows\system32\drivers\tdrpm251.sys [2009-12-13 1455648]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 173984]
R2 MSSQL$BWDATOOLSET;SQL Server (BWDATOOLSET);c:\program files (x86)\daodb\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2009-12-17 1153368]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atipmdag.sys [2010-3-3 6402560]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-3-3 188928]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l160x64.sys [2009-10-13 61440]
R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2010-2-13 12928]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 22408]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 16008]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-6-18 40832]
S2 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2010-5-8 136176]
S2 MSWU-d6cebc64;MSWU-d6cebc64;c:\windows\system32\d6cebc64.exe --> c:\windows\system32\d6cebc64.exe [?]
S3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2009-12-13 250400]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;c:\program files (x86)\common files\creative labs shared\service\AL1Licensing.exe [2010-5-1 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2010-5-1 79360]
S3 CYUSB;Cypress Generic USB Driver;c:\windows\system32\drivers\CYUSB.sys [2010-2-13 47104]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-26 25832]
S3 HTCAND64;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2009-10-26 32768]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam_x64.sys [2008-3-13 27136]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 51445112]
S3 ose64;Office 64 Source Engine;c:\program files\common files\microsoft shared\source engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-5-23 31800]
S3 SaiHF51A;SaiHF51A;c:\windows\system32\drivers\SaiHF51A.sys [2007-5-31 175880]
S3 SaiUF51A;SaiUF51A;c:\windows\system32\drivers\SaiUF51A.sys [2007-5-31 34432]
S4 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\common files\acronis\cdp\afcdpsrv.exe [2009-12-13 2326920]
S4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-3-3 202752]
=============== Created Last 30 ================
2010-05-23 15:00:28 75264 ----a-w- c:\windows\syswow64\d6cebc64.exe
2010-05-23 14:30:56 11 ----a-r- c:\windows\amunres.lsl
2010-05-23 10:37:12 31800 ----a-w- c:\windows\system32\drivers\revoflt.sys
2010-05-23 10:37:11 0 d-----w- c:\program files\VS Revo Group
2010-05-22 08:40:03 0 d-----w- c:\programdata\Logitech
2010-05-22 08:40:02 0 d-----w- c:\program files\Logitech
2010-05-20 21:56:40 8431 ----a-w- c:\users\angus wilsown\.recently-used.xbel
2010-05-17 11:08:30 0 d-----w- c:\program files (x86)\MSXML 4.0
2010-05-16 22:27:01 0 d-----w- c:\users\angusw~1\appdata\roaming\Mael
2010-05-16 22:24:05 0 d-----w- c:\program files (x86)\HxD
2010-05-16 22:12:35 0 d-----w- c:\programdata\HTC
2010-05-16 22:12:33 0 d-----w- c:\programdata\Teleca
2010-05-16 22:12:04 0 d-----w- c:\program files (x86)\Spirent Communications
2010-05-16 21:57:11 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_WinUsb_01007.Wdf
2010-05-16 21:54:39 708168 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2010-05-16 20:54:48 0 d-----w- c:\users\angusw~1\appdata\roaming\FastSum
2010-05-16 20:54:21 0 d-----w- c:\program files (x86)\FastSum
2010-05-16 20:47:07 0 d-----w- C:\ruu_log
2010-05-16 20:42:30 0 d-----w- c:\users\angus wilsown\.android
2010-05-16 20:40:45 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-05-16 18:06:07 0 d-----w- c:\program files (x86)\common files\HP
2010-05-16 18:06:05 0 d-----w- c:\program files (x86)\common files\Hewlett-Packard
2010-05-16 18:05:44 136704 ----a-w- c:\windows\system32\hpf3l70w.dll
2010-05-16 18:05:30 0 d-----w- c:\program files (x86)\HP
2010-05-16 18:04:25 532 ------w- c:\windows\hpomdl46.dat
2010-05-16 18:04:25 173146 ----a-w- c:\windows\hpoins46.dat
2010-05-16 18:04:23 0 d-----w- c:\programdata\HP
2010-05-16 18:04:13 881664 ----a-w- c:\windows\system32\hposwia_d02d.dll
2010-05-16 18:04:13 642360 ----a-w- c:\windows\system32\hpzids40.dll
2010-05-16 18:04:13 551424 ----a-w- c:\windows\system32\hppldcoi.dll
2010-05-16 18:04:12 749056 ----a-w- c:\windows\system32\hpost_d02d.dll
2010-05-16 18:04:12 516096 ----a-w- c:\windows\system32\hposc_d02a.dll
2010-05-16 17:16:08 0 d-----w- c:\users\angusw~1\appdata\roaming\Canneverbe Limited
2010-05-16 17:16:07 0 d-----w- c:\programdata\Canneverbe Limited
2010-05-16 17:15:57 0 d-----w- c:\program files\CDBurnerXP
2010-05-14 20:23:00 0 d-----w- c:\program files\HTC
2010-05-14 20:22:33 0 ----a-w- c:\windows\DbgOut.INI
2010-05-14 19:59:46 0 d-----w- c:\users\angusw~1\appdata\roaming\Teleca
2010-05-14 19:58:38 0 d-----w- c:\program files (x86)\HTC
2010-05-13 20:11:46 0 d-----w- c:\program files (x86)\gish153
2010-05-13 20:11:04 0 d-----w- c:\program files (x86)\Lugaru
2010-05-13 20:09:51 0 d-----w- c:\program files (x86)\Samorost2
2010-05-13 19:26:45 0 d-----w- c:\program files (x86)\Aquaria
2010-05-12 08:31:50 976896 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-12 08:31:49 740864 ----a-w- c:\windows\syswow64\inetcomm.dll
2010-05-11 09:51:21 180224 ----a-w- c:\windows\syswow64\QTCF.dll
2010-05-10 16:30:59 0 d-----w- C:\temp
2010-05-10 16:30:54 0 d-----w- c:\users\angusw~1\appdata\roaming\zenses
2010-05-10 16:30:54 0 d-----w- c:\program files (x86)\Zenses2
2010-05-08 16:06:06 0 d-----w- c:\users\angusw~1\appdata\roaming\PeaZip
2010-05-08 16:03:43 0 d-----w- c:\program files\PeaZip
2010-05-03 15:39:51 0 d-----w- c:\users\angusw~1\appdata\roaming\.matplotlib
2010-05-01 21:23:25 0 d-----w- c:\users\angus wilsown\.gimp-2.6
2010-05-01 21:02:31 788 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000002-00001102-00000005-0034415A}.rfx
2010-05-01 21:02:31 60888 ----a-w- c:\windows\system32\BMXStateBkp-{00000004-00000000-00000002-00001102-00000005-0034415A}.rfx
2010-05-01 21:02:31 60888 ----a-w- c:\windows\system32\BMXState-{00000004-00000000-00000002-00001102-00000005-0034415A}.rfx
2010-05-01 21:00:44 90112 ------w- c:\windows\Updreg.EXE
2010-05-01 21:00:23 102400 ----a-w- c:\windows\syswow64\cttele32.dll
2010-05-01 21:00:22 108032 ----a-w- c:\windows\system32\cttele64.dll
2010-05-01 20:59:35 89088 ----a-w- c:\windows\system32\CmdRtr64.DLL
2010-05-01 20:59:35 73728 ----a-w- c:\windows\syswow64\CmdRtr.DLL
2010-05-01 20:59:35 191488 ----a-w- c:\windows\system32\APOMgr64.DLL
2010-05-01 20:59:35 159 ---ha-r- c:\windows\ctfile.rfc
2010-05-01 20:59:35 148480 ----a-w- c:\windows\syswow64\APOMngr.DLL
2010-05-01 20:58:10 0 d-----w- c:\program files (x86)\common files\Creative Labs Shared
2010-05-01 20:57:59 0 d-----w- c:\program files\Creative
2010-04-28 07:21:47 14336 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-04-28 06:40:29 223448 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-04-28 06:39:55 96768 ----a-w- c:\windows\syswow64\sspicli.dll
2010-04-28 06:39:55 22016 ----a-w- c:\windows\syswow64\secur32.dll
2010-04-28 06:39:55 153160 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-04-28 06:39:55 1446912 ----a-w- c:\windows\system32\lsasrv.dll
2010-04-28 06:39:55 12867072 ----a-w- c:\windows\syswow64\shell32.dll
2010-04-25 12:17:09 0 d-----w- c:\program files\7-Zip
==================== Find3M ====================
2010-05-21 18:58:06 1077 ----a-w- c:\program files\cports.cfg
2010-05-06 09:36:38 270208 ------w- c:\windows\system32\MpSigStub.exe
2010-05-01 20:59:48 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2010-05-01 20:59:48 444952 ----a-w- c:\windows\syswow64\wrap_oal.dll
2010-04-20 19:19:27 411368 ----a-w- c:\windows\syswow64\deployJava1.dll
2010-04-20 19:19:27 153376 ----a-w- c:\windows\syswow64\javaws.exe
2010-04-20 19:19:27 145184 ----a-w- c:\windows\syswow64\javaw.exe
2010-04-20 19:19:27 145184 ----a-w- c:\windows\syswow64\java.exe
2010-03-14 18:44:42 51594 ----a-w- c:\users\angusw~1\appdata\roaming\unins000.dat
2010-03-14 18:41:49 867610 ----a-w- c:\users\angusw~1\appdata\roaming\unins000.exe
2010-03-08 21:59:59 612352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 21:33:56 427520 ----a-w- c:\windows\syswow64\vbscript.dll
2010-03-03 04:16:38 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-03-03 04:16:26 446464 ----a-w- c:\windows\syswow64\aticfx32.dll
2010-03-03 04:15:30 497152 ----a-w- c:\windows\system32\aticfx64.dll
2010-03-03 04:13:04 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-03-03 04:12:52 450560 ----a-w- c:\windows\system32\atieclxx.exe
2010-03-03 04:12:12 202752 ----a-w- c:\windows\system32\atiesrxx.exe
2010-03-03 04:10:34 120320 ----a-w- c:\windows\system32\atitmm64.dll
2010-03-03 04:10:12 420864 ----a-w- c:\windows\system32\atipdl64.dll
2010-03-03 04:10:04 356352 ----a-w- c:\windows\syswow64\atipdlxx.dll
2010-03-03 04:09:48 274432 ----a-w- c:\windows\syswow64\Oemdspif.dll
2010-03-03 04:09:40 12288 ----a-w- c:\windows\system32\atimuixx.dll
2010-03-03 04:09:34 59392 ----a-w- c:\windows\system32\atiedu64.dll
2010-03-03 04:09:28 43520 ----a-w- c:\windows\syswow64\ati2edxx.dll
2010-03-03 04:06:18 3131392 ----a-w- c:\windows\syswow64\atidxx32.dll
2010-03-03 04:04:46 18798080 ----a-w- c:\windows\system32\atio6axx.dll
2010-03-03 03:57:00 3800576 ----a-w- c:\windows\system32\atidxx64.dll
2010-03-03 03:46:42 3703808 ----a-w- c:\windows\syswow64\atiumdag.dll
2010-03-03 03:45:02 14226944 ----a-w- c:\windows\syswow64\atioglxx.dll
2010-03-03 03:39:46 4801536 ----a-w- c:\windows\system32\atiumd64.dll
2010-03-03 03:32:06 2716160 ----a-w- c:\windows\system32\atiumd6a.dll
2010-03-03 03:24:24 2993152 ----a-w- c:\windows\syswow64\atiumdva.dll
2010-03-03 03:23:52 55296 ----a-w- c:\windows\system32\coinst.dll
2010-03-03 03:20:22 43008 ----a-w- c:\windows\system32\aticalrt64.dll
2010-03-03 03:20:20 53248 ----a-w- c:\windows\syswow64\aticalrt.dll
2010-03-03 03:20:10 39936 ----a-w- c:\windows\system32\aticalcl64.dll
2010-03-03 03:20:08 53248 ----a-w- c:\windows\syswow64\aticalcl.dll
2010-03-03 03:19:56 4781568 ----a-w- c:\windows\system32\aticaldd64.dll
2010-03-03 03:18:56 3657728 ----a-w- c:\windows\syswow64\aticaldd.dll
2010-03-03 03:08:50 53248 ----a-w- c:\windows\system32\atimpc64.dll
2010-03-03 03:08:50 53248 ----a-w- c:\windows\system32\amdpcom64.dll
2010-03-03 03:08:44 52224 ----a-w- c:\windows\syswow64\atimpc32.dll
2010-03-03 03:08:44 52224 ----a-w- c:\windows\syswow64\amdpcom32.dll
2010-03-03 03:08:14 330752 ----a-w- c:\windows\system32\atiadlxx.dll
2010-03-03 03:08:06 237568 ----a-w- c:\windows\syswow64\atiadlxy.dll
2010-03-03 03:07:54 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2010-03-03 03:07:48 12800 ----a-w- c:\windows\syswow64\atiglpxx.dll
2010-03-03 03:07:48 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-03-03 03:07:44 16896 ----a-w- c:\windows\system32\atig6txx.dll
2010-03-03 03:07:38 15360 ----a-w- c:\windows\syswow64\atigktxx.dll
2010-03-03 03:06:50 36352 ----a-w- c:\windows\system32\atiuxp64.dll
2010-03-03 03:06:42 27648 ----a-w- c:\windows\syswow64\atiuxpag.dll
2010-03-03 03:06:34 28160 ----a-w- c:\windows\system32\atiu9p64.dll
2010-03-03 03:06:26 20480 ----a-w- c:\windows\syswow64\atiu9pag.dll
2010-02-27 20:35:37 76852 ----a-r- c:\windows\fonts\tesla_regular.ttf
2010-02-27 15:17:00 5509008 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-27 12:07:48 3954568 ----a-w- c:\windows\syswow64\ntkrnlpa.exe
2010-02-27 12:07:48 3899280 ----a-w- c:\windows\syswow64\ntoskrnl.exe
2010-02-25 19:55:46 201875 ----a-w- c:\windows\system32\atiicdxx.dat
2010-02-23 08:22:50 1192960 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 08:16:17 294912 ----a-w- c:\windows\system32\browserchoice.exe
2010-02-23 07:56:00 977920 ----a-w- c:\windows\syswow64\wininet.dll
2010-02-23 07:55:56 1225216 ----a-w- c:\windows\syswow64\urlmon.dll
2010-02-23 07:55:45 606208 ----a-w- c:\windows\syswow64\mstime.dll
2010-02-23 07:55:43 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2010-02-23 07:55:43 5964800 ----a-w- c:\windows\syswow64\mshtml.dll
2010-02-23 07:55:24 10978816 ----a-w- c:\windows\syswow64\ieframe.dll
2010-02-23 07:55:20 381440 ----a-w- c:\windows\syswow64\iedkcs32.dll
2009-11-06 14:03:12 19017 ----a-w- c:\program files\readme.txt
2009-11-06 14:03:12 18364 ----a-w- c:\program files\cports.chm
2009-11-06 14:02:12 49664 ----a-w- c:\program files\cports.exe
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2010-01-23 10:28:18 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 19:32:11.75 ===============
Hi.
Microsoft Security Essentials detected a trojan named 'brj.exe.'. It said my PC needed to be restarted before it could be removed. When my PC was restarted I could no longer connect to the internet, Windows reported my PC as connected to the internet, but nothing was working. Pinging my router worked, but pinging google.com gave me a lookup error. The only thing that works is steam friends for some reason :confused:. I also found 3 suspicious processes; logger.exe, capabilitymanager.exe and generic.exe all running from
C:\Program Files (x86)\Common Files\Teleca Shared, which I have now deleted. Spybot detected some malwate, however it said it needed to be restarted for them to be removed, but on restart they were no longer found. The network is definitely working
Thanks
Angus.