saltherring
2010-10-15, 20:13
Greetings,
I discovered TDSSRt-A & FastClick on my system and removed/quarantined them. However I am wondering if I should do anything else to ensure everything is secure on my PC. I was having system host crashes and browser redirects along with all-around sluggishness. That seems to be
gone but I'm wondering if I should do a system restore at this point.
Any help will be much appreciated. Thanks!
Here's my DDS report:
DDS (Ver_10-10-10.03) - NTFSx86
Run by Joel at 11:59:07.39 on Fri 10/15/2010
Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2036.1184 [GMT -5:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Webroot\Security\current\plugins\antimalware\SSU.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\TRENDnet\802.11n Wireless Client Utility\UMCCfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Joel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.guardian.co.uk
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5081219
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\booyah\SDHelper.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
uRun: [AdobeBridge]
uRun: [EPSON Stylus Photo 1400 Series] "c:\windows\system32\spool\drivers\w32x86\3\e_fatibua.exe" /fu "c:\users\joel\appdata\local\temp\E_S87B5.tmp" /EF "HKCU"
uRun: [Google Update] "c:\users\joel\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [WebrootTrayApp] "c:\program files\webroot\security\current\framework\WRTray.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2011\avp.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\80211n~1.lnk - c:\program files\trendnet\802.11n wireless client utility\UMCCfg.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logoca~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\calibrationloader\CalibrationLoader.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\profil~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\ProfileReminder.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\booyah\SDHelper.dll
DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yuplapp.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\joel\appdata\roaming\mozilla\firefox\profiles\fod8v48d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.guardian.co.uk/world
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - plugin: c:\users\joel\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\users\joel\appdata\roaming\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\users\joel\appdata\roaming\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\users\joel\appdata\roaming\move networks\plugins\npqmp071705000014.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
============= SERVICES / DRIVERS ===============
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2010-4-22 22104]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [2010-3-7 14416]
R2 ssfmonm;ssfmonm;c:\windows\system32\drivers\ssfmonm.sys [2010-9-15 45072]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19984]
R3 netr28u;802.11n USB Wireless Network Adapter Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2010-4-9 599040]
S2 trackcam;TrackerCam Video Capture Driver;c:\windows\system32\drivers\trackcam.sys [2010-1-17 78152]
S3 eyeonedp;eye-one display;c:\windows\system32\drivers\EyeOneDp.sys [2010-3-7 44344]
S3 i1;eye-one;c:\windows\system32\drivers\i1.sys [2010-3-7 26045]
=============== Created Last 30 ================
2010-10-15 07:31:55 6084944 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{a2b1a451-853f-470d-aba4-cdf9d704aa9a}\mpengine.dll
2010-10-14 11:04:05 231936 ----a-w- c:\windows\system32\msshsq.dll
2010-10-14 11:02:57 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-10-14 11:02:57 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-10-14 11:02:55 866816 ----a-w- c:\windows\system32\wmpmde.dll
2010-10-14 11:02:54 157184 ----a-w- c:\windows\system32\t2embed.dll
2010-10-14 11:02:12 303616 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-14 11:02:12 125952 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-14 11:02:12 101888 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-14 11:02:11 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-14 11:02:09 17920 ----a-w- c:\windows\system32\netevent.dll
2010-10-14 11:00:57 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-10-14 11:00:27 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-10-14 11:00:17 531968 ----a-w- c:\windows\system32\comctl32.dll
2010-10-14 02:32:52 150200 ----a-w- c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2010-10-14 02:32:15 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-10-14 02:32:15 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-10-14 02:29:24 -------- d-----w- c:\program files\Kaspersky Lab
2010-10-14 02:29:23 -------- d-----w- c:\progra~2\Kaspersky Lab
2010-10-14 01:30:11 -------- d-----w- c:\progra~2\Kaspersky Lab Setup Files
2010-10-14 00:58:20 -------- d-----w- C:\TDSSKiller_Quarantine
2010-10-13 20:57:53 -------- d-----w- c:\users\joel\appdata\roaming\Malwarebytes
2010-10-13 20:57:31 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-13 20:57:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-13 20:57:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-13 20:57:30 -------- d-----w- c:\progra~2\Malwarebytes
2010-10-03 22:51:31 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-10-03 22:51:23 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-03 22:50:45 126464 ----a-w- c:\windows\system32\spoolsv.exe
2010-10-03 22:50:42 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2010-10-03 22:50:11 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-10-03 22:50:07 13312 ----a-w- c:\program files\internet explorer\iecompat.dll
2010-10-03 22:50:05 501760 ----a-w- c:\windows\system32\usp10.dll
2010-10-02 04:54:06 -------- d-----w- c:\program files\Booyah
2010-10-02 03:33:55 -------- d-----w- c:\progra~2\IObit
2010-10-02 03:31:46 -------- d-----w- c:\program files\IObit
2010-10-02 03:11:36 -------- d-----w- c:\program files\Trend Micro
2010-09-22 19:28:50 -------- d-----w- c:\users\joel\appdata\local\Apps
2010-09-22 19:10:50 -------- d-----w- c:\users\joel\appdata\roaming\Quintessential Media Player
2010-09-22 19:10:21 -------- d-----w- c:\program files\Quintessential Media Player
2010-09-22 17:42:37 -------- d-----w- c:\users\joel\appdata\roaming\XemiComputers
2010-09-22 17:20:06 -------- d-----w- c:\program files\Mozilla Sunbird
2010-09-16 04:30:34 45072 ----a-w- c:\windows\system32\drivers\ssfmonm.sys
2010-09-16 04:28:03 -------- dc-h--w- c:\progra~2\{5D7316EC-0EDC-4C87-A589-9244C286BC92}
2010-09-16 04:27:44 -------- d-----w- c:\progra~2\webroot
2010-09-16 04:25:31 -------- d-----w- c:\users\joel\appdata\local\PackageAware
==================== Find3M ====================
2010-09-08 06:01:28 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 05:57:18 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 05:57:05 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-08 05:56:53 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-09-08 05:56:53 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-09-08 05:04:36 385024 ----a-w- c:\windows\system32\html.iec
2010-09-08 04:26:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-09-08 04:25:15 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-08-10 15:02:22 274432 ----a-w- c:\windows\system32\schannel.dll
============= FINISH: 12:01:58.62 ===============
I discovered TDSSRt-A & FastClick on my system and removed/quarantined them. However I am wondering if I should do anything else to ensure everything is secure on my PC. I was having system host crashes and browser redirects along with all-around sluggishness. That seems to be
gone but I'm wondering if I should do a system restore at this point.
Any help will be much appreciated. Thanks!
Here's my DDS report:
DDS (Ver_10-10-10.03) - NTFSx86
Run by Joel at 11:59:07.39 on Fri 10/15/2010
Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2036.1184 [GMT -5:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Webroot\Security\current\plugins\antimalware\SSU.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\TRENDnet\802.11n Wireless Client Utility\UMCCfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Joel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.guardian.co.uk
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5081219
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\booyah\SDHelper.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
uRun: [AdobeBridge]
uRun: [EPSON Stylus Photo 1400 Series] "c:\windows\system32\spool\drivers\w32x86\3\e_fatibua.exe" /fu "c:\users\joel\appdata\local\temp\E_S87B5.tmp" /EF "HKCU"
uRun: [Google Update] "c:\users\joel\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [WebrootTrayApp] "c:\program files\webroot\security\current\framework\WRTray.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2011\avp.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\80211n~1.lnk - c:\program files\trendnet\802.11n wireless client utility\UMCCfg.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logoca~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\calibrationloader\CalibrationLoader.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\profil~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\ProfileReminder.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\booyah\SDHelper.dll
DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yuplapp.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\joel\appdata\roaming\mozilla\firefox\profiles\fod8v48d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.guardian.co.uk/world
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - plugin: c:\users\joel\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\users\joel\appdata\roaming\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\users\joel\appdata\roaming\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\users\joel\appdata\roaming\move networks\plugins\npqmp071705000014.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
============= SERVICES / DRIVERS ===============
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2010-4-22 22104]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [2010-3-7 14416]
R2 ssfmonm;ssfmonm;c:\windows\system32\drivers\ssfmonm.sys [2010-9-15 45072]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19984]
R3 netr28u;802.11n USB Wireless Network Adapter Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2010-4-9 599040]
S2 trackcam;TrackerCam Video Capture Driver;c:\windows\system32\drivers\trackcam.sys [2010-1-17 78152]
S3 eyeonedp;eye-one display;c:\windows\system32\drivers\EyeOneDp.sys [2010-3-7 44344]
S3 i1;eye-one;c:\windows\system32\drivers\i1.sys [2010-3-7 26045]
=============== Created Last 30 ================
2010-10-15 07:31:55 6084944 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{a2b1a451-853f-470d-aba4-cdf9d704aa9a}\mpengine.dll
2010-10-14 11:04:05 231936 ----a-w- c:\windows\system32\msshsq.dll
2010-10-14 11:02:57 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-10-14 11:02:57 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-10-14 11:02:55 866816 ----a-w- c:\windows\system32\wmpmde.dll
2010-10-14 11:02:54 157184 ----a-w- c:\windows\system32\t2embed.dll
2010-10-14 11:02:12 303616 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-14 11:02:12 125952 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-14 11:02:12 101888 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-14 11:02:11 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-14 11:02:09 17920 ----a-w- c:\windows\system32\netevent.dll
2010-10-14 11:00:57 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-10-14 11:00:27 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-10-14 11:00:17 531968 ----a-w- c:\windows\system32\comctl32.dll
2010-10-14 02:32:52 150200 ----a-w- c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2010-10-14 02:32:15 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-10-14 02:32:15 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-10-14 02:29:24 -------- d-----w- c:\program files\Kaspersky Lab
2010-10-14 02:29:23 -------- d-----w- c:\progra~2\Kaspersky Lab
2010-10-14 01:30:11 -------- d-----w- c:\progra~2\Kaspersky Lab Setup Files
2010-10-14 00:58:20 -------- d-----w- C:\TDSSKiller_Quarantine
2010-10-13 20:57:53 -------- d-----w- c:\users\joel\appdata\roaming\Malwarebytes
2010-10-13 20:57:31 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-13 20:57:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-13 20:57:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-13 20:57:30 -------- d-----w- c:\progra~2\Malwarebytes
2010-10-03 22:51:31 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-10-03 22:51:23 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-03 22:50:45 126464 ----a-w- c:\windows\system32\spoolsv.exe
2010-10-03 22:50:42 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2010-10-03 22:50:11 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-10-03 22:50:07 13312 ----a-w- c:\program files\internet explorer\iecompat.dll
2010-10-03 22:50:05 501760 ----a-w- c:\windows\system32\usp10.dll
2010-10-02 04:54:06 -------- d-----w- c:\program files\Booyah
2010-10-02 03:33:55 -------- d-----w- c:\progra~2\IObit
2010-10-02 03:31:46 -------- d-----w- c:\program files\IObit
2010-10-02 03:11:36 -------- d-----w- c:\program files\Trend Micro
2010-09-22 19:28:50 -------- d-----w- c:\users\joel\appdata\local\Apps
2010-09-22 19:10:50 -------- d-----w- c:\users\joel\appdata\roaming\Quintessential Media Player
2010-09-22 19:10:21 -------- d-----w- c:\program files\Quintessential Media Player
2010-09-22 17:42:37 -------- d-----w- c:\users\joel\appdata\roaming\XemiComputers
2010-09-22 17:20:06 -------- d-----w- c:\program files\Mozilla Sunbird
2010-09-16 04:30:34 45072 ----a-w- c:\windows\system32\drivers\ssfmonm.sys
2010-09-16 04:28:03 -------- dc-h--w- c:\progra~2\{5D7316EC-0EDC-4C87-A589-9244C286BC92}
2010-09-16 04:27:44 -------- d-----w- c:\progra~2\webroot
2010-09-16 04:25:31 -------- d-----w- c:\users\joel\appdata\local\PackageAware
==================== Find3M ====================
2010-09-08 06:01:28 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 05:57:18 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 05:57:05 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-08 05:56:53 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-09-08 05:56:53 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-09-08 05:04:36 385024 ----a-w- c:\windows\system32\html.iec
2010-09-08 04:26:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-09-08 04:25:15 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-08-10 15:02:22 274432 ----a-w- c:\windows\system32\schannel.dll
============= FINISH: 12:01:58.62 ===============