Ochawe
2010-07-14, 17:17
System is slowing down. Not sure what's up. Would you please take a look at it for me. Thanks
My DDS
DDS (Ver_10-03-17.01) - NTFSx86
Run by Ochawe Bake at 9:36:09.34 on Wed 07/14/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.1022.264 [GMT -4:00]
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Ochawe Bake\Downloads\dds.scr
C:\Windows\system32\conhost.exe
============== Pseudo HJT Report ===============
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
AppInit_DLLs: avgrsstx.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\ochawe~1\appdata\roaming\mozilla\firefox\profiles\8sruxl6e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.eveonline.com/
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\users\ochawe bake\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name",
"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description",
"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [2010-6-11 40560]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-23 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-23 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-23 242896]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-13 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-13 308064]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-3-1 1153368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2010-4-3 44896]
S4 RsFx0150;RsFx0150 Driver;c:\windows\system32\drivers\RsFx0150.sys [2010-4-3 240608]
=============== Created Last 30 ================
2010-07-14 13:33:17 0 d-----w- c:\users\ochawe bake\ERU
2010-07-13 03:09:56 0 d-----w- c:\users\ochawe~1\appdata\roaming\GTS
2010-07-12 20:24:55 0 d-----w- c:\users\ochawe~1\appdata\roaming\Autodesk
2010-07-12 20:19:51 0 d-----w- c:\users\ochawe bake\Adlm
2010-07-12 20:18:36 0 d-----w- c:\programdata\FLEXnet
2010-07-12 20:17:21 81408 ----a-w- c:\temp\xf-maya2010.exe
2010-07-12 20:05:32 0 d-----w- c:\program files\common files\Alias Shared
2010-07-12 20:03:43 0 d-----w- c:\program files\common files\Macrovision Shared
2010-07-12 20:03:22 0 d-----w- c:\program files\common files\en-US
2010-07-12 20:03:20 0 d-----w- c:\program files\common files\ja-JP
2010-07-12 20:02:54 0 d-----w- c:\program files\common files\Autodesk Shared
2010-07-12 20:02:28 0 d-----w- c:\programdata\Autodesk
2010-07-12 19:59:32 0 d-----w- c:\program files\Autodesk
2010-07-12 19:54:13 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-07-12 04:32:51 0 d-----w- c:\users\ochawe~1\appdata\roaming\PureBasic
2010-07-12 04:32:40 0 d-----w- c:\program files\PureBasic
2010-07-11 19:49:47 0 d-----w- c:\windows\system32\custom matrices
2010-07-11 19:49:38 0 d-----w- c:\windows\system32\QuickTime
2010-07-11 19:49:38 0 d-----w- c:\windows\system32\C2MP
2010-07-10 01:35:17 0 d-----w- C:\Empire Earth
2010-07-08 13:25:49 0 d-----w- c:\users\ochawe~1\appdata\roaming\W
2010-07-05 14:57:15 0 d-----w- c:\users\ochawe~1\appdata\roaming\wargaming.net
2010-07-05 14:56:31 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-07-05 14:56:31 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-07-05 14:56:31 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-07-05 14:56:31 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-07-05 14:56:30 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-07-05 14:56:30 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-07-05 14:56:30 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-07-05 14:56:30 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-07-05 14:56:29 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-07-05 14:56:29 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-07-05 14:56:29 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-07-05 14:56:29 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-07-05 14:54:16 0 d--h--w- c:\windows\PIF
2010-07-05 14:47:15 0 d-----w- C:\Games
2010-07-01 09:28:55 0 d-----w- c:\program files\EVE Metrics Uploader
2010-06-29 00:56:00 47456 ----a-w- c:\windows\system32\perf-MSSQL10_50.MSSQLSERVER-sqlagtctr.dll
2010-06-29 00:55:24 73568 ----a-w- c:\windows\system32\perf-MSSQLSERVER-sqlctr10.50.1600.1.dll
2010-06-29 00:52:28 0 d-----w- c:\windows\system32\RsFx
2010-06-29 00:41:42 0 d-----w- c:\program files\Microsoft Synchronization Services
2010-06-29 00:41:24 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-06-29 00:41:18 0 d-----w- c:\windows\system32\1033
2010-06-28 13:16:30 0 d-----w- c:\program files\Evemu
2010-06-27 23:51:20 0 d-----w- c:\programdata\MySQL
2010-06-27 23:49:47 0 d-----w- c:\windows\system32\appmgmt
2010-06-27 18:29:47 0 d-----w- c:\program files\DigitalAtmosphere
2010-06-27 16:03:31 0 d-----w- c:\programdata\Stylus Studio
2010-06-27 16:03:13 0 d-----w- c:\users\ochawe~1\appdata\roaming\Stylus Studio
2010-06-27 15:56:41 0 d-----w- c:\program files\Stylus Studio 2009 Release 2 XML Enterprise Suite
2010-06-26 23:22:23 0 d-----w- C:\PicDulip
2010-06-26 23:20:24 0 d-----w- c:\program files\VisiPics
2010-06-25 17:00:28 0 d-----w- c:\users\ochawe~1\appdata\roaming\Uniblue
2010-06-24 06:41:48 0 d-----w- c:\users\ochawe bake\.idlerc
2010-06-24 06:40:33 0 d-----w- c:\program files\Python26
2010-06-23 17:59:23 383562 ----a-w- C:\bootmgr
2010-06-23 17:59:23 0 d-----w- C:\Boot
2010-06-23 17:58:21 0 d-----w- c:\program files\NeoSmart Technologies
2010-06-23 12:58:07 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 12:58:07 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 12:58:07 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 12:58:07 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 12:58:06 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-15 16:17:12 3828736 ----a-w- c:\windows\system32\ffdshow.ax
2010-06-15 16:06:38 153502 ----a-w- c:\windows\system32\libmplayer.dll
2010-06-15 16:05:02 5002416 ----a-w- c:\windows\system32\libavcodec.dll
2010-06-15 15:43:58 1641574 ----a-w- c:\windows\system32\ffmpegmt.dll
==================== Find3M ====================
2010-06-26 23:28:38 7520 --sha-w- c:\programdata\KGyGaAvL.sys
2010-06-02 13:56:19 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-27 07:24:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49:37 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-26 17:00:12 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-24 19:39:50 289065 ----a-w- c:\windows\system32\ff_kernelDeint.dll
2010-05-24 19:38:34 962008 ----a-w- c:\windows\system32\ff_x264.dll
2010-05-24 19:38:22 901509 ----a-w- c:\windows\system32\xvidcore.dll
2010-05-21 14:55:15 88 --sh--r- c:\programdata\984F3A19C7.sys
2010-05-21 05:18:06 977920 ----a-w- c:\windows\system32\wininet.dll
2010-05-18 15:26:22 4254224 ----a-w- c:\windows\system32\qtp-mt334.dll
2010-05-18 15:25:52 40560 ----a-w- c:\windows\system32\drivers\hotcore3.sys
2010-05-18 15:25:52 249872 ----a-w- c:\windows\system32\prgiso.dll
2010-05-14 00:30:09 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2010-05-14 00:30:09 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2010-05-12 15:09:06 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-05-11 21:26:52 324096 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2010-05-11 21:22:22 100864 ----a-w- c:\windows\system32\ff_wmv9.dll
2010-05-10 22:10:04 178688 ----a-w- c:\windows\system32\ff_libmad.dll
2010-05-10 22:09:50 257024 ----a-w- c:\windows\system32\ff_libdts.dll
2010-05-10 22:09:42 142848 ----a-w- c:\windows\system32\ff_liba52.dll
2010-05-10 22:09:30 484864 ----a-w- c:\windows\system32\ff_libfaad2.dll
2010-05-10 22:07:24 1556992 ----a-w- c:\windows\system32\ff_samplerate.dll
2010-05-10 22:05:28 146944 ----a-w- c:\windows\system32\ff_tremor.dll
2010-05-10 22:05:06 113152 ----a-w- c:\windows\system32\ff_unrar.dll
2010-05-10 22:03:56 163328 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2010-05-01 14:49:25 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-04-30 17:51:19 133806 ----a-w- c:\windows\hpwins16.dat
2010-04-23 07:13:36 2048 ----a-w- c:\windows\system32\tzres.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-05-15 01:02:10 3392872 ----a-w- c:\program files\common files\adlmint_libFNP.dll
2009-05-15 01:02:10 3298152 ----a-w- c:\program files\common files\adlmint.dll
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2010-02-25 01:03:50 245760 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c
\WinMail.exe
============= FINISH: 9:36:37.86 ===============
My DDS
DDS (Ver_10-03-17.01) - NTFSx86
Run by Ochawe Bake at 9:36:09.34 on Wed 07/14/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.1022.264 [GMT -4:00]
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Ochawe Bake\Downloads\dds.scr
C:\Windows\system32\conhost.exe
============== Pseudo HJT Report ===============
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
AppInit_DLLs: avgrsstx.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\ochawe~1\appdata\roaming\mozilla\firefox\profiles\8sruxl6e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.eveonline.com/
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\users\ochawe bake\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name",
"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description",
"chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [2010-6-11 40560]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-23 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-23 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-23 242896]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-13 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-13 308064]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-3-1 1153368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2010-4-3 44896]
S4 RsFx0150;RsFx0150 Driver;c:\windows\system32\drivers\RsFx0150.sys [2010-4-3 240608]
=============== Created Last 30 ================
2010-07-14 13:33:17 0 d-----w- c:\users\ochawe bake\ERU
2010-07-13 03:09:56 0 d-----w- c:\users\ochawe~1\appdata\roaming\GTS
2010-07-12 20:24:55 0 d-----w- c:\users\ochawe~1\appdata\roaming\Autodesk
2010-07-12 20:19:51 0 d-----w- c:\users\ochawe bake\Adlm
2010-07-12 20:18:36 0 d-----w- c:\programdata\FLEXnet
2010-07-12 20:17:21 81408 ----a-w- c:\temp\xf-maya2010.exe
2010-07-12 20:05:32 0 d-----w- c:\program files\common files\Alias Shared
2010-07-12 20:03:43 0 d-----w- c:\program files\common files\Macrovision Shared
2010-07-12 20:03:22 0 d-----w- c:\program files\common files\en-US
2010-07-12 20:03:20 0 d-----w- c:\program files\common files\ja-JP
2010-07-12 20:02:54 0 d-----w- c:\program files\common files\Autodesk Shared
2010-07-12 20:02:28 0 d-----w- c:\programdata\Autodesk
2010-07-12 19:59:32 0 d-----w- c:\program files\Autodesk
2010-07-12 19:54:13 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-07-12 04:32:51 0 d-----w- c:\users\ochawe~1\appdata\roaming\PureBasic
2010-07-12 04:32:40 0 d-----w- c:\program files\PureBasic
2010-07-11 19:49:47 0 d-----w- c:\windows\system32\custom matrices
2010-07-11 19:49:38 0 d-----w- c:\windows\system32\QuickTime
2010-07-11 19:49:38 0 d-----w- c:\windows\system32\C2MP
2010-07-10 01:35:17 0 d-----w- C:\Empire Earth
2010-07-08 13:25:49 0 d-----w- c:\users\ochawe~1\appdata\roaming\W
2010-07-05 14:57:15 0 d-----w- c:\users\ochawe~1\appdata\roaming\wargaming.net
2010-07-05 14:56:31 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-07-05 14:56:31 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-07-05 14:56:31 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-07-05 14:56:31 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-07-05 14:56:30 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-07-05 14:56:30 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-07-05 14:56:30 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-07-05 14:56:30 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-07-05 14:56:29 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-07-05 14:56:29 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-07-05 14:56:29 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-07-05 14:56:29 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-07-05 14:54:16 0 d--h--w- c:\windows\PIF
2010-07-05 14:47:15 0 d-----w- C:\Games
2010-07-01 09:28:55 0 d-----w- c:\program files\EVE Metrics Uploader
2010-06-29 00:56:00 47456 ----a-w- c:\windows\system32\perf-MSSQL10_50.MSSQLSERVER-sqlagtctr.dll
2010-06-29 00:55:24 73568 ----a-w- c:\windows\system32\perf-MSSQLSERVER-sqlctr10.50.1600.1.dll
2010-06-29 00:52:28 0 d-----w- c:\windows\system32\RsFx
2010-06-29 00:41:42 0 d-----w- c:\program files\Microsoft Synchronization Services
2010-06-29 00:41:24 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-06-29 00:41:18 0 d-----w- c:\windows\system32\1033
2010-06-28 13:16:30 0 d-----w- c:\program files\Evemu
2010-06-27 23:51:20 0 d-----w- c:\programdata\MySQL
2010-06-27 23:49:47 0 d-----w- c:\windows\system32\appmgmt
2010-06-27 18:29:47 0 d-----w- c:\program files\DigitalAtmosphere
2010-06-27 16:03:31 0 d-----w- c:\programdata\Stylus Studio
2010-06-27 16:03:13 0 d-----w- c:\users\ochawe~1\appdata\roaming\Stylus Studio
2010-06-27 15:56:41 0 d-----w- c:\program files\Stylus Studio 2009 Release 2 XML Enterprise Suite
2010-06-26 23:22:23 0 d-----w- C:\PicDulip
2010-06-26 23:20:24 0 d-----w- c:\program files\VisiPics
2010-06-25 17:00:28 0 d-----w- c:\users\ochawe~1\appdata\roaming\Uniblue
2010-06-24 06:41:48 0 d-----w- c:\users\ochawe bake\.idlerc
2010-06-24 06:40:33 0 d-----w- c:\program files\Python26
2010-06-23 17:59:23 383562 ----a-w- C:\bootmgr
2010-06-23 17:59:23 0 d-----w- C:\Boot
2010-06-23 17:58:21 0 d-----w- c:\program files\NeoSmart Technologies
2010-06-23 12:58:07 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 12:58:07 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 12:58:07 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 12:58:07 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 12:58:06 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-15 16:17:12 3828736 ----a-w- c:\windows\system32\ffdshow.ax
2010-06-15 16:06:38 153502 ----a-w- c:\windows\system32\libmplayer.dll
2010-06-15 16:05:02 5002416 ----a-w- c:\windows\system32\libavcodec.dll
2010-06-15 15:43:58 1641574 ----a-w- c:\windows\system32\ffmpegmt.dll
==================== Find3M ====================
2010-06-26 23:28:38 7520 --sha-w- c:\programdata\KGyGaAvL.sys
2010-06-02 13:56:19 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-27 07:24:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49:37 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-26 17:00:12 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-24 19:39:50 289065 ----a-w- c:\windows\system32\ff_kernelDeint.dll
2010-05-24 19:38:34 962008 ----a-w- c:\windows\system32\ff_x264.dll
2010-05-24 19:38:22 901509 ----a-w- c:\windows\system32\xvidcore.dll
2010-05-21 14:55:15 88 --sh--r- c:\programdata\984F3A19C7.sys
2010-05-21 05:18:06 977920 ----a-w- c:\windows\system32\wininet.dll
2010-05-18 15:26:22 4254224 ----a-w- c:\windows\system32\qtp-mt334.dll
2010-05-18 15:25:52 40560 ----a-w- c:\windows\system32\drivers\hotcore3.sys
2010-05-18 15:25:52 249872 ----a-w- c:\windows\system32\prgiso.dll
2010-05-14 00:30:09 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2010-05-14 00:30:09 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2010-05-12 15:09:06 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-05-11 21:26:52 324096 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2010-05-11 21:22:22 100864 ----a-w- c:\windows\system32\ff_wmv9.dll
2010-05-10 22:10:04 178688 ----a-w- c:\windows\system32\ff_libmad.dll
2010-05-10 22:09:50 257024 ----a-w- c:\windows\system32\ff_libdts.dll
2010-05-10 22:09:42 142848 ----a-w- c:\windows\system32\ff_liba52.dll
2010-05-10 22:09:30 484864 ----a-w- c:\windows\system32\ff_libfaad2.dll
2010-05-10 22:07:24 1556992 ----a-w- c:\windows\system32\ff_samplerate.dll
2010-05-10 22:05:28 146944 ----a-w- c:\windows\system32\ff_tremor.dll
2010-05-10 22:05:06 113152 ----a-w- c:\windows\system32\ff_unrar.dll
2010-05-10 22:03:56 163328 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2010-05-01 14:49:25 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-04-30 17:51:19 133806 ----a-w- c:\windows\hpwins16.dat
2010-04-23 07:13:36 2048 ----a-w- c:\windows\system32\tzres.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-05-15 01:02:10 3392872 ----a-w- c:\program files\common files\adlmint_libFNP.dll
2009-05-15 01:02:10 3298152 ----a-w- c:\program files\common files\adlmint.dll
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2010-02-25 01:03:50 245760 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c
\WinMail.exe
============= FINISH: 9:36:37.86 ===============