dusty_bin
2011-08-19, 22:05
Personally I don't get a problem on this machine with Opera, but some other users have been using IE and Firefox and have been getting their google search results hijacked to alternative sites - in the sense that if they click on the link in the list of results they get taken to a different site.
I poked around a bit to look for solutions, and have run tdsskiller and gooredfix that was mentioned somewhere, but these haven't helped as far as I can tell.
Here is the DDS logfile in the hope someone can identify something:
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by happy-fish at 21:58:31 on 2011-08-18
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3581.2582 [GMT 0:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
============== Running Processes ===============
.
E:\PROGRA~1\AVG\AVG10\avgchsvx.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\Program Files\Nero\Tools\InCD\InCDSrv.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
E:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\rundll32.exe
svchost.exe
E:\Program Files\AVG\AVG10\avgwdsvc.exe
E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
E:\WINDOWS\system32\LVCOMSX.EXE
E:\Program Files\Mailtraq\firebird\bin\fbserver.exe
E:\Program Files\Logitech\Video\LogiTray.exe
E:\Program Files\AVG\AVG10\avgtray.exe
E:\Program Files\Nero\Tools\InCD\NBHGui.exe
E:\Program Files\Nero\Tools\InCD\InCD.exe
E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
E:\Program Files\Mailtraq\mailtraq.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
E:\WINDOWS\twain_32\S6U12BX\WATCH.exe
E:\Program Files\ChkMail\CHKMAIL.exe
E:\Program Files\dmt\DMT.exe
E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
E:\Program Files\Logitech\Video\FxSvr2.exe
E:\Program Files\Nero\Tools\InCD\NBHRegInCDSrv.exe
E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
E:\WINDOWS\System32\svchost.exe -k imgsvc
E:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
E:\Program Files\AVG\AVG10\avgnsx.exe
E:\Program Files\Canon\CAL\CALMAIN.exe
E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
E:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
E:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
E:\WINDOWS\System32\svchost.exe -k HTTPFilter
E:\PROGRA~1\AVG\AVG10\avgrsx.exe
E:\Program Files\AVG\AVG10\avgcsrvx.exe
E:\Program Files\Logitech\Video\AlbumDB2.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://happy-fish-06/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - e:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - e:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [LogitechSoftwareUpdate] "e:\program files\logitech\video\ManifestEngine.exe" boot
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "e:\program files\common files\nero\lib\NMBgMonitor.exe"
uRun: [Mailtraq] e:\program files\mailtraq\mailtraq.exe
uRun: [ctfmon.exe] e:\windows\system32\ctfmon.exe
mRun: [EPSON Stylus Photo RX420 Series] e:\windows\system32\spool\drivers\w32x86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
mRun: [LVCOMSX] e:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] e:\program files\logitech\video\ISStart.exe
mRun: [LogitechVideoTray] e:\program files\logitech\video\LogiTray.exe
mRun: [AVG_TRAY] e:\program files\avg\avg10\avgtray.exe
mRun: [NeroFilterCheck] e:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "e:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [NBHGui] e:\program files\nero\tools\incd\NBHGui.exe
mRun: [InCD] e:\program files\nero\tools\incd\InCD.exe
mRun: [Smapp] e:\program files\analog devices\soundmax\SMTray.exe
mRun: [DrvLsnr] e:\program files\analog devices\soundmax\DrvLsnr.exe
mRun: [StartCCC] "e:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "e:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: e:\docume~1\happy-~1\startm~1\programs\startup\chkmail.lnk - e:\program files\chkmail\CHKMAIL.exe
StartupFolder: e:\docume~1\happy-~1\startm~1\programs\startup\dmtv80~1.lnk - e:\program files\dmt\DMT.exe
StartupFolder: e:\docume~1\alluse~1\startm~1\programs\startup\watch.lnk - e:\windows\twain_32\s6u12bx\WATCH.exe
IE: E&xport to Microsoft Excel - e:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\progra~1\spybot~1\SDHelper.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258455809812
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258483486390
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
TCP: Interfaces\{9E0179DD-7B5A-49CD-837D-4E982CE753A8} : NameServer = 192.168.1.253
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - e:\program files\avg\avg10\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
Hosts: 127.127.1.0 localclock
Hosts: 192.168.1.1 happy-fish-router
Hosts: 192.168.1.7 happy-fish-06
Hosts: 192.168.1.6 happy-fish-05
Hosts: 192.168.1.5 happy-fish-04
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - e:\documents and settings\happy-fish\application data\mozilla\firefox\profiles\jbs7ix5q.default\
FF - plugin: e:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: e:\program files\canon\zoombrowser ex\program\NPCIG.dll
FF - plugin: e:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: e:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;e:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;e:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 Lbd;Lbd;e:\windows\system32\drivers\Lbd.sys [2011-6-12 64512]
R0 si3112r;Silicon Image SiI 3512 SATARaid Controller;e:\windows\system32\drivers\SI3112r.sys [2007-8-29 116264]
R0 SiWinAcc;SiWinAcc;e:\windows\system32\drivers\SiWinAcc.sys [2007-8-29 19240]
R1 AvgLdx86;AVG AVI Loader Driver;e:\windows\system32\drivers\avgldx86.sys [2010-9-7 248656]
R1 AvgMfx86;AVG Mini-Filter Resident Anti-Virus Shield;e:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896]
R1 Avgtdix;AVG TDI Driver;e:\windows\system32\drivers\avgtdix.sys [2010-9-7 297168]
R2 AVGIDSAgent;AVGIDSAgent;e:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;e:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 FirebirdServerMailtraqInstance;Firebird Server - Mailtraq;e:\program files\mailtraq\firebird\bin\fbserver.exe [2006-10-31 1990656]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;e:\program files\lavasoft\ad-aware\AAWService.exe [2011-5-25 2151640]
R2 NeroRegInCDSrv;Nero Registry InCD Service;e:\program files\nero\tools\incd\NBHRegInCDSrv.exe [2009-10-16 53560]
R2 NTP;Network Time Protocol Daemon;e:\program files\ntp\bin\ntpd.exe -u 3 -m -g -c "e:\program files\ntp\etc\ntp.conf" --> e:\program files\ntp\bin\ntpd.exe -u 3 -m -g -c e:\program files\ntp\etc\ntp.conf [?]
R3 AVGIDSDriver;AVGIDSDriver;e:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134480]
R3 AVGIDSFilter;AVGIDSFilter;e:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24144]
R3 AVGIDSShim;AVGIDSShim;e:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
R3 ham50;Intel HaM Data Fax Voice;e:\windows\system32\drivers\ham50.sys [2009-12-26 365853]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;e:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 BCM42XX;Broadcom iLine10(tm) Network Adapter Driver;e:\windows\system32\drivers\bcm42xx5.sys [2011-2-20 54271]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;e:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-5-25 15232]
S3 N100;Compaq Ethernet or Fast Ethernet NIC Driver;e:\windows\system32\drivers\n100325.sys [2009-11-17 128000]
S3 PCX500;Cisco Wireless LAN Adapters Driver;e:\windows\system32\drivers\pcx500.sys [2011-2-20 169984]
S3 WinRM;Windows Remote Management (WS-Management);e:\windows\system32\svchost.exe -k WINRM [2003-3-31 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;e:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-08-10 03:51:10 139656 -c----w- e:\windows\system32\dllcache\rdpwd.sys
2011-08-10 03:50:13 10496 -c----w- e:\windows\system32\dllcache\ndistapi.sys
.
==================== Find3M ====================
.
2011-07-15 13:29:31 456320 ----a-w- e:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 ----a-w- e:\windows\system32\drivers\ndistapi.sys
2011-07-07 17:42:03 404640 ----a-w- e:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-29 18:46:59 101720 ----a-w- e:\windows\system32\drivers\SBREDrv.sys
2011-06-24 14:10:36 139656 ----a-w- e:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36:30 916480 ----a-w- e:\windows\system32\wininet.dll
2011-06-23 18:36:30 43520 ----a-w- e:\windows\system32\licmgr10.dll
2011-06-23 18:36:30 1469440 ------w- e:\windows\system32\inetcpl.cpl
2011-06-23 12:05:13 385024 ----a-w- e:\windows\system32\html.iec
2011-06-20 17:44:52 293376 ----a-w- e:\windows\system32\winsrv.dll
2011-06-12 18:46:51 16432 ----a-w- e:\windows\system32\lsdelete.exe
2011-06-02 14:02:05 1858944 ----a-w- e:\windows\system32\win32k.sys
2011-05-25 02:00:36 64512 ----a-w- e:\windows\system32\drivers\Lbd.sys
.
============= FINISH: 21:59:50.11 ===============
I poked around a bit to look for solutions, and have run tdsskiller and gooredfix that was mentioned somewhere, but these haven't helped as far as I can tell.
Here is the DDS logfile in the hope someone can identify something:
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by happy-fish at 21:58:31 on 2011-08-18
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3581.2582 [GMT 0:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
============== Running Processes ===============
.
E:\PROGRA~1\AVG\AVG10\avgchsvx.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\Program Files\Nero\Tools\InCD\InCDSrv.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
E:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\rundll32.exe
svchost.exe
E:\Program Files\AVG\AVG10\avgwdsvc.exe
E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
E:\WINDOWS\system32\LVCOMSX.EXE
E:\Program Files\Mailtraq\firebird\bin\fbserver.exe
E:\Program Files\Logitech\Video\LogiTray.exe
E:\Program Files\AVG\AVG10\avgtray.exe
E:\Program Files\Nero\Tools\InCD\NBHGui.exe
E:\Program Files\Nero\Tools\InCD\InCD.exe
E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
E:\Program Files\Mailtraq\mailtraq.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
E:\WINDOWS\twain_32\S6U12BX\WATCH.exe
E:\Program Files\ChkMail\CHKMAIL.exe
E:\Program Files\dmt\DMT.exe
E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
E:\Program Files\Logitech\Video\FxSvr2.exe
E:\Program Files\Nero\Tools\InCD\NBHRegInCDSrv.exe
E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
E:\WINDOWS\System32\svchost.exe -k imgsvc
E:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
E:\Program Files\AVG\AVG10\avgnsx.exe
E:\Program Files\Canon\CAL\CALMAIN.exe
E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
E:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
E:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
E:\WINDOWS\System32\svchost.exe -k HTTPFilter
E:\PROGRA~1\AVG\AVG10\avgrsx.exe
E:\Program Files\AVG\AVG10\avgcsrvx.exe
E:\Program Files\Logitech\Video\AlbumDB2.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://happy-fish-06/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - e:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - e:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [LogitechSoftwareUpdate] "e:\program files\logitech\video\ManifestEngine.exe" boot
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "e:\program files\common files\nero\lib\NMBgMonitor.exe"
uRun: [Mailtraq] e:\program files\mailtraq\mailtraq.exe
uRun: [ctfmon.exe] e:\windows\system32\ctfmon.exe
mRun: [EPSON Stylus Photo RX420 Series] e:\windows\system32\spool\drivers\w32x86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
mRun: [LVCOMSX] e:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] e:\program files\logitech\video\ISStart.exe
mRun: [LogitechVideoTray] e:\program files\logitech\video\LogiTray.exe
mRun: [AVG_TRAY] e:\program files\avg\avg10\avgtray.exe
mRun: [NeroFilterCheck] e:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "e:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [NBHGui] e:\program files\nero\tools\incd\NBHGui.exe
mRun: [InCD] e:\program files\nero\tools\incd\InCD.exe
mRun: [Smapp] e:\program files\analog devices\soundmax\SMTray.exe
mRun: [DrvLsnr] e:\program files\analog devices\soundmax\DrvLsnr.exe
mRun: [StartCCC] "e:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "e:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: e:\docume~1\happy-~1\startm~1\programs\startup\chkmail.lnk - e:\program files\chkmail\CHKMAIL.exe
StartupFolder: e:\docume~1\happy-~1\startm~1\programs\startup\dmtv80~1.lnk - e:\program files\dmt\DMT.exe
StartupFolder: e:\docume~1\alluse~1\startm~1\programs\startup\watch.lnk - e:\windows\twain_32\s6u12bx\WATCH.exe
IE: E&xport to Microsoft Excel - e:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\progra~1\spybot~1\SDHelper.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258455809812
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258483486390
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
TCP: Interfaces\{9E0179DD-7B5A-49CD-837D-4E982CE753A8} : NameServer = 192.168.1.253
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - e:\program files\avg\avg10\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
Hosts: 127.127.1.0 localclock
Hosts: 192.168.1.1 happy-fish-router
Hosts: 192.168.1.7 happy-fish-06
Hosts: 192.168.1.6 happy-fish-05
Hosts: 192.168.1.5 happy-fish-04
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - e:\documents and settings\happy-fish\application data\mozilla\firefox\profiles\jbs7ix5q.default\
FF - plugin: e:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: e:\program files\canon\zoombrowser ex\program\NPCIG.dll
FF - plugin: e:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: e:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;e:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;e:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 Lbd;Lbd;e:\windows\system32\drivers\Lbd.sys [2011-6-12 64512]
R0 si3112r;Silicon Image SiI 3512 SATARaid Controller;e:\windows\system32\drivers\SI3112r.sys [2007-8-29 116264]
R0 SiWinAcc;SiWinAcc;e:\windows\system32\drivers\SiWinAcc.sys [2007-8-29 19240]
R1 AvgLdx86;AVG AVI Loader Driver;e:\windows\system32\drivers\avgldx86.sys [2010-9-7 248656]
R1 AvgMfx86;AVG Mini-Filter Resident Anti-Virus Shield;e:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896]
R1 Avgtdix;AVG TDI Driver;e:\windows\system32\drivers\avgtdix.sys [2010-9-7 297168]
R2 AVGIDSAgent;AVGIDSAgent;e:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;e:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 FirebirdServerMailtraqInstance;Firebird Server - Mailtraq;e:\program files\mailtraq\firebird\bin\fbserver.exe [2006-10-31 1990656]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;e:\program files\lavasoft\ad-aware\AAWService.exe [2011-5-25 2151640]
R2 NeroRegInCDSrv;Nero Registry InCD Service;e:\program files\nero\tools\incd\NBHRegInCDSrv.exe [2009-10-16 53560]
R2 NTP;Network Time Protocol Daemon;e:\program files\ntp\bin\ntpd.exe -u 3 -m -g -c "e:\program files\ntp\etc\ntp.conf" --> e:\program files\ntp\bin\ntpd.exe -u 3 -m -g -c e:\program files\ntp\etc\ntp.conf [?]
R3 AVGIDSDriver;AVGIDSDriver;e:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134480]
R3 AVGIDSFilter;AVGIDSFilter;e:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24144]
R3 AVGIDSShim;AVGIDSShim;e:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
R3 ham50;Intel HaM Data Fax Voice;e:\windows\system32\drivers\ham50.sys [2009-12-26 365853]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;e:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 BCM42XX;Broadcom iLine10(tm) Network Adapter Driver;e:\windows\system32\drivers\bcm42xx5.sys [2011-2-20 54271]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;e:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-5-25 15232]
S3 N100;Compaq Ethernet or Fast Ethernet NIC Driver;e:\windows\system32\drivers\n100325.sys [2009-11-17 128000]
S3 PCX500;Cisco Wireless LAN Adapters Driver;e:\windows\system32\drivers\pcx500.sys [2011-2-20 169984]
S3 WinRM;Windows Remote Management (WS-Management);e:\windows\system32\svchost.exe -k WINRM [2003-3-31 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;e:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-08-10 03:51:10 139656 -c----w- e:\windows\system32\dllcache\rdpwd.sys
2011-08-10 03:50:13 10496 -c----w- e:\windows\system32\dllcache\ndistapi.sys
.
==================== Find3M ====================
.
2011-07-15 13:29:31 456320 ----a-w- e:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 ----a-w- e:\windows\system32\drivers\ndistapi.sys
2011-07-07 17:42:03 404640 ----a-w- e:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-29 18:46:59 101720 ----a-w- e:\windows\system32\drivers\SBREDrv.sys
2011-06-24 14:10:36 139656 ----a-w- e:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36:30 916480 ----a-w- e:\windows\system32\wininet.dll
2011-06-23 18:36:30 43520 ----a-w- e:\windows\system32\licmgr10.dll
2011-06-23 18:36:30 1469440 ------w- e:\windows\system32\inetcpl.cpl
2011-06-23 12:05:13 385024 ----a-w- e:\windows\system32\html.iec
2011-06-20 17:44:52 293376 ----a-w- e:\windows\system32\winsrv.dll
2011-06-12 18:46:51 16432 ----a-w- e:\windows\system32\lsdelete.exe
2011-06-02 14:02:05 1858944 ----a-w- e:\windows\system32\win32k.sys
2011-05-25 02:00:36 64512 ----a-w- e:\windows\system32\drivers\Lbd.sys
.
============= FINISH: 21:59:50.11 ===============