lmrcpr
2011-09-03, 03:10
Hi,
A few months ago my pc started directing me to add sites when I searched for anything. The AVG scan found problems and cleared them so I though it was ok. The night before last I kept getting AVG warnings about files containing win32/zbot. The pc would not run spybot search and destroy to start with and would not allow me to run in safe mode. It was also comming up with a page not found message for several sites including microsoft this site and avg.
I've since done a AVG rootkits scan that said it had removed 4 problems. Search and destroy is now running but said there was one thing it could not fix.
Here is the dds results. I didn't have the search and destroy results as it would not allow me on this site earlier so I didn't know I needed it. Thank you.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Run by CPR at 0:59:14 on 2011-09-03
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.93 [GMT 1:00]
.
AV: BullGuard Antivirus *Enabled/Updated* {7A9BB333-8EDF-4FDC-A2A5-1A30FA021913}
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: BullGuard Firewall *Disabled*
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\SvcHost.exe -k BullGuard_Main
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe
svchost.exe
C:\WINDOWS\System32\SvcHost.exe -k BullGuard
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uInternet Connection Wizard,ShellNext = iexplore
mURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\documents and settings\cpr\local settings\application data\qsosldmb\yvgfvgvo.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [YvgFvgvo] c:\documents and settings\cpr\local settings\application data\qsosldmb\yvgfvgvo.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Gainward] "c:\program files\xpertvision\TBPanel.exe" /A
mRun: [nwiz] "nwiz.exe" /install
mRun: [SkyTel] SkyTel.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Microsoft Works Update Detection] "c:\program files\common files\microsoft shared\works shared\WkUFind.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRunOnce: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\windows\system32\BGLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{3676FF3D-A78C-4CDA-ACE6-868255941027} : DhcpNameServer = 192.168.0.1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\cpr\application data\mozilla\firefox\profiles\pkhj6d1o.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.sky.com/
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cc68f0b&v=7.007.026.001&i=23&tp=ab&iy=b&ychte=uk&lng=en-US&q=
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff5.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\bullguard ltd\bullguard\antiphishing\ff\antiphishing@bullguard\components\BGFFComponent.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Gamers Unite! Snag Bar: {afe43e80-0abc-4df2-81a0-3fe44b74abe8} - %profile%\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: AVG Security Toolbar em:version=7.007.026.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\avg\avg10\toolbar\firefox\avg@igeared
FF - Ext: XULRunner: {C7587CE6-6C7A-40C5-ACFF-775134790365} - c:\documents and settings\cpr\local settings\application data\{C7587CE6-6C7A-40C5-ACFF-775134790365}
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg10\Firefox4
FF - Ext: BullGuard Safe Browsing: antiphishing@bullguard - c:\program files\bullguard ltd\bullguard\antiphishing\ff\antiphishing@bullguard
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-11-15 64160]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 297168]
R1 BdSpy;BdSpy;c:\windows\system32\drivers\BdSpy.sys [2010-12-16 64608]
R1 NovaShieldFilterDriver;NovaShieldFilterDriver;c:\windows\system32\drivers\NSKernel.sys [2010-12-21 789448]
R1 NovaShieldTDIDriver;NovaShieldTDIDriver;c:\windows\system32\drivers\NSNetmon.sys [2010-12-21 19272]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 BsBhvScan;BullGuard behavioural detection service;c:\program files\bullguard ltd\bullguard\BullGuardBhvScanner.exe [2010-12-17 338264]
R2 BsBrowser;BullGuard antiphishing service;c:\windows\system32\SvcHost.exe -k BullGuard_LowPriv [2009-6-15 14336]
R2 BsFileScan;BullGuard on-access service;c:\windows\system32\SvcHost.exe -k BullGuard [2009-6-15 14336]
R2 BsFire;BullGuard firewall service;c:\windows\system32\SvcHost.exe -k BullGuard [2009-6-15 14336]
R2 BsMailProxy;BullGuard e-mail monitoring service;c:\windows\system32\SvcHost.exe -k BullGuard [2009-6-15 14336]
R2 BsMain;BullGuard main service;c:\windows\system32\SvcHost.exe -k BullGuard_Main [2009-6-15 14336]
R2 BsUpdate;BullGuard update service;c:\program files\bullguard ltd\bullguard\BullGuardUpdate.exe [2010-11-26 320344]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2007-10-9 38144]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [2010-10-12 34280]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2010-10-12 267624]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
R3 BsScanner;BullGuard scanning service;c:\program files\bullguard ltd\bullguard\BullGuardScanner.exe [2010-11-23 288088]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-11-15 38224]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2007-12-28 287232]
S4 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-14 1025352]
S4 BgRaSvc;BgRaSvc;c:\program files\bullguard ltd\bullguard\support\BgRaSvc.exe [2010-11-26 125784]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-9-2 1036104]
S4 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2009-6-15 14336]
.
=============== Created Last 30 ================
.
2011-09-02 22:34:06 4224 ----a-w- c:\windows\system32\drivers\RDPCDD.sys
2011-09-02 11:07:42 -------- d--h--w- C:\$AVG
2011-09-02 09:52:33 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-09-02 09:52:33 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-09-02 00:04:40 -------- d-----w- c:\program files\Trend Micro
2011-09-01 23:58:42 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-09-01 23:57:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2011-09-01 23:57:20 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-09-01 23:57:14 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2011-09-01 23:56:05 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-09-01 23:56:05 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-09-01 23:56:02 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2011-09-01 23:56:01 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2011-09-01 23:56:01 110592 -c----w- c:\windows\system32\dllcache\services.exe
2011-09-01 23:56:00 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2011-09-01 23:56:00 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2011-09-01 23:55:59 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2011-09-01 23:55:58 729088 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2011-09-01 23:55:57 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2011-09-01 23:55:57 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2011-09-01 23:55:54 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-09-01 23:55:53 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-09-01 23:55:50 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-09-01 23:54:38 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2011-09-01 23:52:25 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2011-09-01 23:52:00 2560 ------w- c:\windows\system32\xpsp4res.dll
2011-09-01 22:20:06 -------- d-----w- c:\windows\system32\scripting
2011-09-01 22:20:04 -------- d-----w- c:\windows\l2schemas
2011-09-01 22:20:03 -------- d-----w- c:\windows\system32\en
2011-09-01 22:20:02 -------- d-----w- c:\windows\system32\bits
2011-09-01 22:03:57 -------- d-----w- c:\windows\network diagnostic
2011-09-01 21:55:19 -------- d-----w- c:\windows\EHome
2011-09-01 16:33:11 -------- d-----w- c:\program files\Steam
2011-09-01 11:08:48 166872 ------w- c:\program files\mozilla firefox\softokn3.dll
2011-09-01 11:08:42 105432 ------w- c:\program files\mozilla firefox\nssdbm3.dll
2011-09-01 11:08:38 269272 ------w- c:\program files\mozilla firefox\freebl3.dll
2011-09-01 09:22:51 -------- d-----w- c:\documents and settings\cpr\application data\Software Inspection Library
2011-09-01 07:05:21 304712 ----a-w- c:\windows\system32\drivers\Trufos.sys
2011-09-01 06:50:00 -------- d-----w- c:\documents and settings\cpr\application data\BullGuard
2011-09-01 06:46:28 -------- d-----w- c:\documents and settings\all users\application data\BullGuard
2011-09-01 06:45:46 -------- d-----w- c:\program files\BullGuard Ltd
2011-08-31 20:00:57 -------- d-----w- c:\documents and settings\cpr\local settings\application data\qsosldmb
2011-08-31 19:59:42 0 ----a-w- c:\documents and settings\cpr\0.3191063280485381.exe
2011-08-10 11:31:36 -------- d-----w- c:\documents and settings\cpr\local settings\application data\WMTools Downloaded Files
.
==================== Find3M ====================
.
2011-09-01 06:59:54 100184 ----a-w- c:\windows\system32\BgGamingMonitor.dll
2011-09-01 06:59:15 155992 ----a-w- c:\windows\system32\BGLsp.dll
2011-09-01 06:59:02 789448 ----a-w- c:\windows\system32\drivers\NSKernel.sys
2011-09-01 06:59:02 19272 ----a-w- c:\windows\system32\drivers\NSNetmon.sys
2011-09-01 06:58:41 64608 ----a-w- c:\windows\system32\drivers\BdSpy.sys
.
============= FINISH: 1:00:27.75 ===============
A few months ago my pc started directing me to add sites when I searched for anything. The AVG scan found problems and cleared them so I though it was ok. The night before last I kept getting AVG warnings about files containing win32/zbot. The pc would not run spybot search and destroy to start with and would not allow me to run in safe mode. It was also comming up with a page not found message for several sites including microsoft this site and avg.
I've since done a AVG rootkits scan that said it had removed 4 problems. Search and destroy is now running but said there was one thing it could not fix.
Here is the dds results. I didn't have the search and destroy results as it would not allow me on this site earlier so I didn't know I needed it. Thank you.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Run by CPR at 0:59:14 on 2011-09-03
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.93 [GMT 1:00]
.
AV: BullGuard Antivirus *Enabled/Updated* {7A9BB333-8EDF-4FDC-A2A5-1A30FA021913}
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: BullGuard Firewall *Disabled*
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\SvcHost.exe -k BullGuard_Main
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe
svchost.exe
C:\WINDOWS\System32\SvcHost.exe -k BullGuard
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uInternet Connection Wizard,ShellNext = iexplore
mURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\documents and settings\cpr\local settings\application data\qsosldmb\yvgfvgvo.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [YvgFvgvo] c:\documents and settings\cpr\local settings\application data\qsosldmb\yvgfvgvo.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Gainward] "c:\program files\xpertvision\TBPanel.exe" /A
mRun: [nwiz] "nwiz.exe" /install
mRun: [SkyTel] SkyTel.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Microsoft Works Update Detection] "c:\program files\common files\microsoft shared\works shared\WkUFind.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRunOnce: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\windows\system32\BGLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{3676FF3D-A78C-4CDA-ACE6-868255941027} : DhcpNameServer = 192.168.0.1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\cpr\application data\mozilla\firefox\profiles\pkhj6d1o.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.sky.com/
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cc68f0b&v=7.007.026.001&i=23&tp=ab&iy=b&ychte=uk&lng=en-US&q=
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff5.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\bullguard ltd\bullguard\antiphishing\ff\antiphishing@bullguard\components\BGFFComponent.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Gamers Unite! Snag Bar: {afe43e80-0abc-4df2-81a0-3fe44b74abe8} - %profile%\extensions\{afe43e80-0abc-4df2-81a0-3fe44b74abe8}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: AVG Security Toolbar em:version=7.007.026.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\avg\avg10\toolbar\firefox\avg@igeared
FF - Ext: XULRunner: {C7587CE6-6C7A-40C5-ACFF-775134790365} - c:\documents and settings\cpr\local settings\application data\{C7587CE6-6C7A-40C5-ACFF-775134790365}
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg10\Firefox4
FF - Ext: BullGuard Safe Browsing: antiphishing@bullguard - c:\program files\bullguard ltd\bullguard\antiphishing\ff\antiphishing@bullguard
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-11-15 64160]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 297168]
R1 BdSpy;BdSpy;c:\windows\system32\drivers\BdSpy.sys [2010-12-16 64608]
R1 NovaShieldFilterDriver;NovaShieldFilterDriver;c:\windows\system32\drivers\NSKernel.sys [2010-12-21 789448]
R1 NovaShieldTDIDriver;NovaShieldTDIDriver;c:\windows\system32\drivers\NSNetmon.sys [2010-12-21 19272]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 BsBhvScan;BullGuard behavioural detection service;c:\program files\bullguard ltd\bullguard\BullGuardBhvScanner.exe [2010-12-17 338264]
R2 BsBrowser;BullGuard antiphishing service;c:\windows\system32\SvcHost.exe -k BullGuard_LowPriv [2009-6-15 14336]
R2 BsFileScan;BullGuard on-access service;c:\windows\system32\SvcHost.exe -k BullGuard [2009-6-15 14336]
R2 BsFire;BullGuard firewall service;c:\windows\system32\SvcHost.exe -k BullGuard [2009-6-15 14336]
R2 BsMailProxy;BullGuard e-mail monitoring service;c:\windows\system32\SvcHost.exe -k BullGuard [2009-6-15 14336]
R2 BsMain;BullGuard main service;c:\windows\system32\SvcHost.exe -k BullGuard_Main [2009-6-15 14336]
R2 BsUpdate;BullGuard update service;c:\program files\bullguard ltd\bullguard\BullGuardUpdate.exe [2010-11-26 320344]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2007-10-9 38144]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [2010-10-12 34280]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2010-10-12 267624]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
R3 BsScanner;BullGuard scanning service;c:\program files\bullguard ltd\bullguard\BullGuardScanner.exe [2010-11-23 288088]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-11-15 38224]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2007-12-28 287232]
S4 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-14 1025352]
S4 BgRaSvc;BgRaSvc;c:\program files\bullguard ltd\bullguard\support\BgRaSvc.exe [2010-11-26 125784]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-9-2 1036104]
S4 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2009-6-15 14336]
.
=============== Created Last 30 ================
.
2011-09-02 22:34:06 4224 ----a-w- c:\windows\system32\drivers\RDPCDD.sys
2011-09-02 11:07:42 -------- d--h--w- C:\$AVG
2011-09-02 09:52:33 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-09-02 09:52:33 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-09-02 00:04:40 -------- d-----w- c:\program files\Trend Micro
2011-09-01 23:58:42 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-09-01 23:57:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2011-09-01 23:57:20 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-09-01 23:57:14 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2011-09-01 23:56:05 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-09-01 23:56:05 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-09-01 23:56:02 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2011-09-01 23:56:01 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2011-09-01 23:56:01 110592 -c----w- c:\windows\system32\dllcache\services.exe
2011-09-01 23:56:00 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2011-09-01 23:56:00 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2011-09-01 23:55:59 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2011-09-01 23:55:58 729088 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2011-09-01 23:55:57 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2011-09-01 23:55:57 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2011-09-01 23:55:54 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-09-01 23:55:53 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-09-01 23:55:50 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-09-01 23:54:38 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2011-09-01 23:52:25 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2011-09-01 23:52:00 2560 ------w- c:\windows\system32\xpsp4res.dll
2011-09-01 22:20:06 -------- d-----w- c:\windows\system32\scripting
2011-09-01 22:20:04 -------- d-----w- c:\windows\l2schemas
2011-09-01 22:20:03 -------- d-----w- c:\windows\system32\en
2011-09-01 22:20:02 -------- d-----w- c:\windows\system32\bits
2011-09-01 22:03:57 -------- d-----w- c:\windows\network diagnostic
2011-09-01 21:55:19 -------- d-----w- c:\windows\EHome
2011-09-01 16:33:11 -------- d-----w- c:\program files\Steam
2011-09-01 11:08:48 166872 ------w- c:\program files\mozilla firefox\softokn3.dll
2011-09-01 11:08:42 105432 ------w- c:\program files\mozilla firefox\nssdbm3.dll
2011-09-01 11:08:38 269272 ------w- c:\program files\mozilla firefox\freebl3.dll
2011-09-01 09:22:51 -------- d-----w- c:\documents and settings\cpr\application data\Software Inspection Library
2011-09-01 07:05:21 304712 ----a-w- c:\windows\system32\drivers\Trufos.sys
2011-09-01 06:50:00 -------- d-----w- c:\documents and settings\cpr\application data\BullGuard
2011-09-01 06:46:28 -------- d-----w- c:\documents and settings\all users\application data\BullGuard
2011-09-01 06:45:46 -------- d-----w- c:\program files\BullGuard Ltd
2011-08-31 20:00:57 -------- d-----w- c:\documents and settings\cpr\local settings\application data\qsosldmb
2011-08-31 19:59:42 0 ----a-w- c:\documents and settings\cpr\0.3191063280485381.exe
2011-08-10 11:31:36 -------- d-----w- c:\documents and settings\cpr\local settings\application data\WMTools Downloaded Files
.
==================== Find3M ====================
.
2011-09-01 06:59:54 100184 ----a-w- c:\windows\system32\BgGamingMonitor.dll
2011-09-01 06:59:15 155992 ----a-w- c:\windows\system32\BGLsp.dll
2011-09-01 06:59:02 789448 ----a-w- c:\windows\system32\drivers\NSKernel.sys
2011-09-01 06:59:02 19272 ----a-w- c:\windows\system32\drivers\NSNetmon.sys
2011-09-01 06:58:41 64608 ----a-w- c:\windows\system32\drivers\BdSpy.sys
.
============= FINISH: 1:00:27.75 ===============