AFanCorp
2010-10-05, 04:44
Hi,
So my computer acted somewhat strangely recently, so I went through the process of running various malware removal programs such as S&D to attempt to find the problem.
tl;dr
Virtumonde happened, S&D says its gone, pop-ups still occuring.
DDS Report
DDS (Ver_09-09-29.01) - NTFSx86
Run by Alex at 18:01:54.80 on 04/10/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.2.1033.18.4095.2588 [GMT -7:00]
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\Wacom_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WTablet\Wacom_TabletUser.exe
C:\Windows\system32\Wacom_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Users\Alex\Desktop\dds.com
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2535290
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mLocal Page = c:\windows\syswow64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files (x86)\messenger_plus_live_ca-en\tbMess.dll
mURLSearchHooks: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files (x86)\messenger_plus_live_ca-en\tbMess.dll
mWinlogon: Userinit=userinit.exe
BHO: {02d67f2c-49c5-4702-9791-324983d93856} - c:\windows\syswow64\dfshim32.dll
BHO: {03eb18eb-6f44-4093-bdec-d746e3809fc9} - c:\windows\syswow64\dwmcore32.dll
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files (x86)\adobe\/Adobe Contribute CS4/contributeieplugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files (x86)\messenger_plus_live_ca-en\tbMess.dll
BHO: e090261: {8764358c-3e79-6510-7ab3-8d9d02c78c2f} - c:\windows\syswow64\DxpTaskSync32.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files (x86)\adobe\/Adobe Contribute CS4/contributeieplugin.dll
TB: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files (x86)\messenger_plus_live_ca-en\tbMess.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WindowsLivePhone] "c:\program files (x86)\windows live\device manager\msgrdvmn.exe" /AutoRun
uRun: [AdobeBridge]
uRun: [Google Update] "c:\users\alex\appdata\local\google\update\GoogleUpdate.exe" /c
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\NPSWF32_FlashUtil.exe -p
uRunOnce: [SpybotDeletingB3165] command.com /c del "c:\windows\system32\dfshim32.dll"
uRunOnce: [SpybotDeletingD8769] cmd.exe /c del "c:\windows\system32\dfshim32.dll"
uRunOnce: [SpybotDeletingB893] command.com /c del "c:\windows\system32\dfshim32.dll"
uRunOnce: [SpybotDeletingD9958] cmd.exe /c del "c:\windows\system32\dfshim32.dll"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "c:\program files (x86)\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files (x86)\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files (x86)\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe"
mRun: [WindowsLivePhone] c:\program files (x86)\windows live\device manager\msgrdvmn.exe /AutoRun
mRun: [Adobe_ID0ENQBO] c:\progra~2\common~1\adobe\adobev~1\server\bin\VERSIO~3.EXE
mRun: [KKKQ Agent] c:\windows\syswow64\28463\KKKQ.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Corel File Shell Monitor] c:\program files (x86)\corel\corel paintshop photo pro\x3\pspclassic\CorelIOMonitor.exe
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [RTHDBPL] c:\users\alex\appdata\roaming\syswin\lsass.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\system32\DxpTaskSync32.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2535290&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2535290&q=
FF - component: c:\program files (x86)\mozilla firefox\extensions\{01a8ca0a-4c96-465b-a49b-65c46fad54f9}\components\Contribute.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\FFExternalAlert.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCore.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll
FF - plugin: c:\program files (x86)\ahnlab\asp\mykeydefense 2.5\npmkd25aos.dll
FF - plugin: c:\program files (x86)\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npContribute.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\alex\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\battlefieldheroespatcher@ea.com\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;c:\windows\system32\drivers\pxhlpa64.sys --> c:\windows\system32\drivers\PxHlpa64.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys --> c:\windows\system32\drivers\vwififlt.sys [?]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-13 20992]
R2 MSSQL$BWDATOOLSET;SQL Server (BWDATOOLSET);c:\program files (x86)\daodb\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2009-9-18 1153368]
R2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys --> c:\windows\system32\drivers\SSPORT.sys [?]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\wacom_tablet.exe --> c:\windows\system32\Wacom_Tablet.exe [?]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 2291568]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\common files\macrovision shared\flexnet publisher\FNPLicensingService64.exe [2009-8-18 1436424]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2010-5-22 106040]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\rt64win7.sys --> c:\windows\system32\drivers\Rt64win7.sys [?]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys --> c:\windows\system32\drivers\wacmoumonitor.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 mi-raysat_3dsmax2011_64;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 64-bit 64-bit;c:\program files\autodesk\3ds max 2011\mentalimages\satellite\raysat_3dsmax2011_64server.exe [2010-3-10 86016]
S2 odserv32;Microsoft Office Diagnostics Service ;c:\windows\system32\dxdiagn32.exe [2010-10-4 1108992]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 288112]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\drivers\athurx.sys --> c:\windows\system32\drivers\athurx.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
S3 Mkd3kfNt;Mkd3kfNt;c:\windows\system32\drivers\mkd3kfnt.sys --> c:\windows\system32\drivers\Mkd3kfNt.sys [?]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys --> c:\windows\system32\drivers\teamviewervpn.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\watadminsvc.exe --> c:\windows\system32\wat\WatAdminSvc.exe [?]
=============== Created Last 30 ================
2010-10-04 16:21 <DIR> --d----- c:\program files (x86)\Sophos
2010-10-04 05:20 <DIR> --d----- C:\VundoFix Backups
2010-10-04 05:00 145 a------- c:\windows\wininit.ini
2010-10-04 00:54 <DIR> --dsh--- c:\programdata\SysWoW32
2010-10-04 00:54 <DIR> --dsh--- c:\progra~3\SysWoW32
2010-10-04 00:54 <DIR> --d----- c:\programdata\1279800659
2010-10-04 00:54 <DIR> --d----- c:\progra~3\1279800659
2010-10-04 00:54 203,776 ---sh--- c:\programdata\unrar.exe
2010-10-04 00:54 203,776 ---sh--- c:\progra~3\unrar.exe
2010-10-04 00:51 <DIR> --dsh--- c:\users\alex\appdata\roaming\SysWin
2010-10-04 00:51 4,207 a--sh--- c:\windows\system32\7e7a52341033P.manifest
2010-10-04 00:51 138 a--sh--- c:\windows\system32\7e7a52341033O.manifest
2010-10-04 00:51 51 a--sh--- c:\windows\system32\7e7a52341033C.manifest
2010-10-04 00:51 11 a--sh--- c:\windows\system32\7e7a52341033S.manifest
2010-10-04 00:51 1,108,992 a------- c:\windows\system32\dxdiagn32.exe
2010-10-04 00:51 98 a------- c:\windows\system32\81020227
2010-10-04 00:51 314,880 a------- c:\windows\system32\dwmcore32.dll
2010-10-04 00:48 <DIR> --d----- c:\programdata\Apple Computer
2010-10-04 00:32 <DIR> --d----- c:\program files (x86)\Incomplete
2010-09-30 04:30 <DIR> --d----- c:\windows\WICCodecs
2010-09-30 04:07 108,475 a------- c:\windows\Thumbplug TGA Uninstaller.exe
2010-09-30 04:07 <DIR> --d----- c:\program files (x86)\Thumbplug TGA
2010-09-30 03:46 <DIR> --d----- c:\programdata\Corel
2010-09-30 03:46 <DIR> --d----- c:\program files (x86)\common files\Protexis
2010-09-30 03:46 <DIR> --d----- c:\progra~3\Corel
2010-09-30 03:44 <DIR> --d----- c:\programdata\Ulead Systems
2010-09-30 03:44 <DIR> --d----- c:\program files (x86)\Corel
2010-09-30 03:44 <DIR> --d----- c:\program files (x86)\common files\Corel
2010-09-30 03:22 <DIR> --d----- c:\program files (x86)\common files\Akamai
2010-09-30 03:07 <DIR> --d----- C:\AirRivals Mods
2010-09-29 04:06 2,048 a------- c:\windows\system32\tzres.dll
2010-09-20 21:59 332 a------- c:\windows\system32\setupinfo.ver
2010-09-20 21:59 140 a------- c:\windows\system32\option.sys
2010-09-20 21:58 492 a------- c:\windows\system32\VersionInfo.ver
2010-09-16 20:57 471,040 a------- c:\windows\system32\SCDialer1.ocx
2010-09-16 20:57 323,584 a------- c:\windows\system32\SCDialer2.ocx
2010-09-16 20:57 118,272 a------- c:\windows\system32\SX5363S.DLL
2010-09-16 20:57 102,400 a------- c:\windows\system32\RV32RTP.dll
2010-09-16 20:57 40 a------- c:\windows\system32\Sx5363.ini
2010-09-16 16:50 151,552 a------- c:\windows\system32\nvRegDev.dll
2010-09-16 15:31 <DIR> --d----- c:\program files (x86)\common files\Autodesk Shared
2010-09-15 14:29 <DIR> --d----- c:\program files (x86)\LexWare
2010-09-15 01:14 262,272 a------- C:\ac4_tex_p.dds
2010-09-14 22:45 <DIR> --d----- c:\program files (x86)\CCP
2010-09-14 17:37 <DIR> --d----- c:\program files (x86)\common files\Alias Shared
2010-09-14 17:32 <DIR> --d----- C:\ja-JP
2010-09-14 17:32 <DIR> --d----- C:\en-US
2010-09-14 03:31 <DIR> --d----- c:\programdata\NVIDIA Corporation
2010-09-14 03:31 <DIR> --d----- c:\progra~3\NVIDIA Corporation
2010-09-14 03:18 <DIR> --d----- c:\windows\PCHEALTH
2010-09-14 02:53 <DIR> --d----- c:\windows\SQLTools9_KB970892_ENU
2010-09-14 02:52 <DIR> --d----- c:\windows\SQL9_KB970892_ENU
2010-09-10 14:45 <DIR> --d----- c:\users\alex\appdata\roaming\Dragon Age Toolset
2010-09-10 14:09 <DIR> --d----- c:\program files (x86)\Microsoft SQL Server
2010-09-10 14:09 <DIR> --d----- c:\program files (x86)\DAODB
2010-09-09 23:32 <DIR> --d----- c:\programdata\BioWare
2010-09-09 23:32 <DIR> --d----- c:\progra~3\BioWare
2010-09-08 11:17 94,208 a------- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 11:17 69,632 a------- c:\windows\system32\QuickTime.qts
==================== Find3M ====================
2010-07-28 23:30 82,944 a------- c:\windows\system32\iccvid.dll
2010-07-22 17:14 65,536 a------- c:\windows\IFinst27.exe
2010-07-10 05:38 14,092,904 a------- c:\windows\system32\nvoglv32.dll
2010-07-10 05:38 10,267,240 a------- c:\windows\system32\nvcompiler.dll
2010-07-10 05:38 9,818,728 a------- c:\windows\system32\nvd3dum.dll
2010-07-10 05:38 5,107,816 a------- c:\windows\system32\nvwgf2um.dll
2010-07-10 05:38 4,553,832 a------- c:\windows\system32\nvcuda.dll
2010-07-10 05:38 2,892,904 a------- c:\windows\system32\nvcuvid.dll
2010-07-10 05:38 2,506,344 a------- c:\windows\system32\nvcuvenc.dll
2010-07-10 05:38 1,625,192 a------- c:\windows\system32\nvapi.dll
2010-07-10 05:38 314,984 a------- c:\windows\system32\nvdecodemft.dll
2010-07-10 05:38 56,936 a------- c:\windows\system32\OpenCL.dll
2010-07-06 22:52 135,168 a------- c:\windows\apppatch\apppatch64\AcXtrnal.dll
2010-07-06 22:52 347,648 a------- c:\windows\apppatch\apppatch64\AcLayers.dll
2010-01-21 12:31 157,694 a------- c:\windows\inf\perflib\0412\perfi.dat
2010-01-21 12:31 157,694 a------- c:\windows\inf\perflib\0412\perfh.dat
2010-01-21 12:31 31,548 a------- c:\windows\inf\perflib\0412\perfd.dat
2010-01-21 12:31 31,548 a------- c:\windows\inf\perflib\0412\perfc.dat
2010-01-21 12:23 141,988 a------- c:\windows\inf\perflib\0411\perfi.dat
2010-01-21 12:23 141,988 a------- c:\windows\inf\perflib\0411\perfh.dat
2010-01-21 12:23 31,548 a------- c:\windows\inf\perflib\0411\perfd.dat
2010-01-21 12:23 31,548 a------- c:\windows\inf\perflib\0411\perfc.dat
2009-07-13 22:37 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
2009-07-13 22:37 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
2009-07-13 22:37 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
2009-07-13 22:37 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
2009-07-13 21:54 174 a--sh--- c:\program files (x86)\desktop.ini
2009-07-13 18:00 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 18:00 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 18:00 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 18:00 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 13:44 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
2009-12-01 18:44 16,384 a--sh--- c:\windows\temp\cookies\index.dat
2009-12-01 18:44 16,384 a--sh--- c:\windows\temp\history\history.ie5\index.dat
2009-12-01 18:44 16,384 a--sh--- c:\windows\temp\temporary internet files\content.ie5\index.dat
2009-07-13 18:39 398,848 a--sh--- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-13 18:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 18:03:17.34 ===============
Attached is the S&D report.
So my computer acted somewhat strangely recently, so I went through the process of running various malware removal programs such as S&D to attempt to find the problem.
tl;dr
Virtumonde happened, S&D says its gone, pop-ups still occuring.
DDS Report
DDS (Ver_09-09-29.01) - NTFSx86
Run by Alex at 18:01:54.80 on 04/10/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.2.1033.18.4095.2588 [GMT -7:00]
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\Wacom_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WTablet\Wacom_TabletUser.exe
C:\Windows\system32\Wacom_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alex\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Users\Alex\Desktop\dds.com
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2535290
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mLocal Page = c:\windows\syswow64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files (x86)\messenger_plus_live_ca-en\tbMess.dll
mURLSearchHooks: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files (x86)\messenger_plus_live_ca-en\tbMess.dll
mWinlogon: Userinit=userinit.exe
BHO: {02d67f2c-49c5-4702-9791-324983d93856} - c:\windows\syswow64\dfshim32.dll
BHO: {03eb18eb-6f44-4093-bdec-d746e3809fc9} - c:\windows\syswow64\dwmcore32.dll
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files (x86)\adobe\/Adobe Contribute CS4/contributeieplugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files (x86)\messenger_plus_live_ca-en\tbMess.dll
BHO: e090261: {8764358c-3e79-6510-7ab3-8d9d02c78c2f} - c:\windows\syswow64\DxpTaskSync32.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files (x86)\adobe\/Adobe Contribute CS4/contributeieplugin.dll
TB: Messenger Plus Live CA-EN Toolbar: {437c4386-9237-441f-a940-009430030ee0} - c:\program files (x86)\messenger_plus_live_ca-en\tbMess.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WindowsLivePhone] "c:\program files (x86)\windows live\device manager\msgrdvmn.exe" /AutoRun
uRun: [AdobeBridge]
uRun: [Google Update] "c:\users\alex\appdata\local\google\update\GoogleUpdate.exe" /c
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\NPSWF32_FlashUtil.exe -p
uRunOnce: [SpybotDeletingB3165] command.com /c del "c:\windows\system32\dfshim32.dll"
uRunOnce: [SpybotDeletingD8769] cmd.exe /c del "c:\windows\system32\dfshim32.dll"
uRunOnce: [SpybotDeletingB893] command.com /c del "c:\windows\system32\dfshim32.dll"
uRunOnce: [SpybotDeletingD9958] cmd.exe /c del "c:\windows\system32\dfshim32.dll"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "c:\program files (x86)\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files (x86)\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files (x86)\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe"
mRun: [WindowsLivePhone] c:\program files (x86)\windows live\device manager\msgrdvmn.exe /AutoRun
mRun: [Adobe_ID0ENQBO] c:\progra~2\common~1\adobe\adobev~1\server\bin\VERSIO~3.EXE
mRun: [KKKQ Agent] c:\windows\syswow64\28463\KKKQ.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Corel File Shell Monitor] c:\program files (x86)\corel\corel paintshop photo pro\x3\pspclassic\CorelIOMonitor.exe
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [RTHDBPL] c:\users\alex\appdata\roaming\syswin\lsass.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\system32\DxpTaskSync32.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2535290&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2535290&q=
FF - component: c:\program files (x86)\mozilla firefox\extensions\{01a8ca0a-4c96-465b-a49b-65c46fad54f9}\components\Contribute.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\FFExternalAlert.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{437c4386-9237-441f-a940-009430030ee0}\components\RadioWMPCore.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
FF - component: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll
FF - plugin: c:\program files (x86)\ahnlab\asp\mykeydefense 2.5\npmkd25aos.dll
FF - plugin: c:\program files (x86)\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npContribute.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\alex\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\alex\appdata\roaming\mozilla\firefox\profiles\7vlukm3x.default\extensions\battlefieldheroespatcher@ea.com\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;c:\windows\system32\drivers\pxhlpa64.sys --> c:\windows\system32\drivers\PxHlpa64.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys --> c:\windows\system32\drivers\vwififlt.sys [?]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-13 20992]
R2 MSSQL$BWDATOOLSET;SQL Server (BWDATOOLSET);c:\program files (x86)\daodb\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2009-9-18 1153368]
R2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys --> c:\windows\system32\drivers\SSPORT.sys [?]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\wacom_tablet.exe --> c:\windows\system32\Wacom_Tablet.exe [?]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 2291568]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\common files\macrovision shared\flexnet publisher\FNPLicensingService64.exe [2009-8-18 1436424]
R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2010-5-22 106040]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\rt64win7.sys --> c:\windows\system32\drivers\Rt64win7.sys [?]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys --> c:\windows\system32\drivers\wacmoumonitor.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 mi-raysat_3dsmax2011_64;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 64-bit 64-bit;c:\program files\autodesk\3ds max 2011\mentalimages\satellite\raysat_3dsmax2011_64server.exe [2010-3-10 86016]
S2 odserv32;Microsoft Office Diagnostics Service ;c:\windows\system32\dxdiagn32.exe [2010-10-4 1108992]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 288112]
S3 athur;Wireless Network Adapter Service;c:\windows\system32\drivers\athurx.sys --> c:\windows\system32\drivers\athurx.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]
S3 Mkd3kfNt;Mkd3kfNt;c:\windows\system32\drivers\mkd3kfnt.sys --> c:\windows\system32\drivers\Mkd3kfNt.sys [?]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys --> c:\windows\system32\drivers\teamviewervpn.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\watadminsvc.exe --> c:\windows\system32\wat\WatAdminSvc.exe [?]
=============== Created Last 30 ================
2010-10-04 16:21 <DIR> --d----- c:\program files (x86)\Sophos
2010-10-04 05:20 <DIR> --d----- C:\VundoFix Backups
2010-10-04 05:00 145 a------- c:\windows\wininit.ini
2010-10-04 00:54 <DIR> --dsh--- c:\programdata\SysWoW32
2010-10-04 00:54 <DIR> --dsh--- c:\progra~3\SysWoW32
2010-10-04 00:54 <DIR> --d----- c:\programdata\1279800659
2010-10-04 00:54 <DIR> --d----- c:\progra~3\1279800659
2010-10-04 00:54 203,776 ---sh--- c:\programdata\unrar.exe
2010-10-04 00:54 203,776 ---sh--- c:\progra~3\unrar.exe
2010-10-04 00:51 <DIR> --dsh--- c:\users\alex\appdata\roaming\SysWin
2010-10-04 00:51 4,207 a--sh--- c:\windows\system32\7e7a52341033P.manifest
2010-10-04 00:51 138 a--sh--- c:\windows\system32\7e7a52341033O.manifest
2010-10-04 00:51 51 a--sh--- c:\windows\system32\7e7a52341033C.manifest
2010-10-04 00:51 11 a--sh--- c:\windows\system32\7e7a52341033S.manifest
2010-10-04 00:51 1,108,992 a------- c:\windows\system32\dxdiagn32.exe
2010-10-04 00:51 98 a------- c:\windows\system32\81020227
2010-10-04 00:51 314,880 a------- c:\windows\system32\dwmcore32.dll
2010-10-04 00:48 <DIR> --d----- c:\programdata\Apple Computer
2010-10-04 00:32 <DIR> --d----- c:\program files (x86)\Incomplete
2010-09-30 04:30 <DIR> --d----- c:\windows\WICCodecs
2010-09-30 04:07 108,475 a------- c:\windows\Thumbplug TGA Uninstaller.exe
2010-09-30 04:07 <DIR> --d----- c:\program files (x86)\Thumbplug TGA
2010-09-30 03:46 <DIR> --d----- c:\programdata\Corel
2010-09-30 03:46 <DIR> --d----- c:\program files (x86)\common files\Protexis
2010-09-30 03:46 <DIR> --d----- c:\progra~3\Corel
2010-09-30 03:44 <DIR> --d----- c:\programdata\Ulead Systems
2010-09-30 03:44 <DIR> --d----- c:\program files (x86)\Corel
2010-09-30 03:44 <DIR> --d----- c:\program files (x86)\common files\Corel
2010-09-30 03:22 <DIR> --d----- c:\program files (x86)\common files\Akamai
2010-09-30 03:07 <DIR> --d----- C:\AirRivals Mods
2010-09-29 04:06 2,048 a------- c:\windows\system32\tzres.dll
2010-09-20 21:59 332 a------- c:\windows\system32\setupinfo.ver
2010-09-20 21:59 140 a------- c:\windows\system32\option.sys
2010-09-20 21:58 492 a------- c:\windows\system32\VersionInfo.ver
2010-09-16 20:57 471,040 a------- c:\windows\system32\SCDialer1.ocx
2010-09-16 20:57 323,584 a------- c:\windows\system32\SCDialer2.ocx
2010-09-16 20:57 118,272 a------- c:\windows\system32\SX5363S.DLL
2010-09-16 20:57 102,400 a------- c:\windows\system32\RV32RTP.dll
2010-09-16 20:57 40 a------- c:\windows\system32\Sx5363.ini
2010-09-16 16:50 151,552 a------- c:\windows\system32\nvRegDev.dll
2010-09-16 15:31 <DIR> --d----- c:\program files (x86)\common files\Autodesk Shared
2010-09-15 14:29 <DIR> --d----- c:\program files (x86)\LexWare
2010-09-15 01:14 262,272 a------- C:\ac4_tex_p.dds
2010-09-14 22:45 <DIR> --d----- c:\program files (x86)\CCP
2010-09-14 17:37 <DIR> --d----- c:\program files (x86)\common files\Alias Shared
2010-09-14 17:32 <DIR> --d----- C:\ja-JP
2010-09-14 17:32 <DIR> --d----- C:\en-US
2010-09-14 03:31 <DIR> --d----- c:\programdata\NVIDIA Corporation
2010-09-14 03:31 <DIR> --d----- c:\progra~3\NVIDIA Corporation
2010-09-14 03:18 <DIR> --d----- c:\windows\PCHEALTH
2010-09-14 02:53 <DIR> --d----- c:\windows\SQLTools9_KB970892_ENU
2010-09-14 02:52 <DIR> --d----- c:\windows\SQL9_KB970892_ENU
2010-09-10 14:45 <DIR> --d----- c:\users\alex\appdata\roaming\Dragon Age Toolset
2010-09-10 14:09 <DIR> --d----- c:\program files (x86)\Microsoft SQL Server
2010-09-10 14:09 <DIR> --d----- c:\program files (x86)\DAODB
2010-09-09 23:32 <DIR> --d----- c:\programdata\BioWare
2010-09-09 23:32 <DIR> --d----- c:\progra~3\BioWare
2010-09-08 11:17 94,208 a------- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 11:17 69,632 a------- c:\windows\system32\QuickTime.qts
==================== Find3M ====================
2010-07-28 23:30 82,944 a------- c:\windows\system32\iccvid.dll
2010-07-22 17:14 65,536 a------- c:\windows\IFinst27.exe
2010-07-10 05:38 14,092,904 a------- c:\windows\system32\nvoglv32.dll
2010-07-10 05:38 10,267,240 a------- c:\windows\system32\nvcompiler.dll
2010-07-10 05:38 9,818,728 a------- c:\windows\system32\nvd3dum.dll
2010-07-10 05:38 5,107,816 a------- c:\windows\system32\nvwgf2um.dll
2010-07-10 05:38 4,553,832 a------- c:\windows\system32\nvcuda.dll
2010-07-10 05:38 2,892,904 a------- c:\windows\system32\nvcuvid.dll
2010-07-10 05:38 2,506,344 a------- c:\windows\system32\nvcuvenc.dll
2010-07-10 05:38 1,625,192 a------- c:\windows\system32\nvapi.dll
2010-07-10 05:38 314,984 a------- c:\windows\system32\nvdecodemft.dll
2010-07-10 05:38 56,936 a------- c:\windows\system32\OpenCL.dll
2010-07-06 22:52 135,168 a------- c:\windows\apppatch\apppatch64\AcXtrnal.dll
2010-07-06 22:52 347,648 a------- c:\windows\apppatch\apppatch64\AcLayers.dll
2010-01-21 12:31 157,694 a------- c:\windows\inf\perflib\0412\perfi.dat
2010-01-21 12:31 157,694 a------- c:\windows\inf\perflib\0412\perfh.dat
2010-01-21 12:31 31,548 a------- c:\windows\inf\perflib\0412\perfd.dat
2010-01-21 12:31 31,548 a------- c:\windows\inf\perflib\0412\perfc.dat
2010-01-21 12:23 141,988 a------- c:\windows\inf\perflib\0411\perfi.dat
2010-01-21 12:23 141,988 a------- c:\windows\inf\perflib\0411\perfh.dat
2010-01-21 12:23 31,548 a------- c:\windows\inf\perflib\0411\perfd.dat
2010-01-21 12:23 31,548 a------- c:\windows\inf\perflib\0411\perfc.dat
2009-07-13 22:37 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
2009-07-13 22:37 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
2009-07-13 22:37 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
2009-07-13 22:37 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
2009-07-13 21:54 174 a--sh--- c:\program files (x86)\desktop.ini
2009-07-13 18:00 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 18:00 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 18:00 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 18:00 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 13:44 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
2009-12-01 18:44 16,384 a--sh--- c:\windows\temp\cookies\index.dat
2009-12-01 18:44 16,384 a--sh--- c:\windows\temp\history\history.ie5\index.dat
2009-12-01 18:44 16,384 a--sh--- c:\windows\temp\temporary internet files\content.ie5\index.dat
2009-07-13 18:39 398,848 a--sh--- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-13 18:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 18:03:17.34 ===============
Attached is the S&D report.