DeeMal
2012-09-12, 01:34
Windows XP Ver 2002 Serv Pk 3
IBM X30
Pentium III M 1200 MHz
760 MB Ram
40 Meg HD with 34 Meg Used.
Avast Virus Protection
Comodo Firewall
Win Patrol
Superantispyware
Malewarebytes
Added Sanboxie last month and copernic desktop search this week.
I had trouble surfing the Internet this morning. I rebooted and was able to surf. The icon in taskbar showed that it was working fine (dial-up) but it did not allow me to connect to any website. It kept giving me that error page, "Unable to connect.." yada, yada, yada. I also noticed that certain websites didn't work well until I enabled cookies. However, these websites worked fine, without any cookies alerts, while running Opera. Firefox would not work as well. Winauclt sometimes takes up a lot of memory and I am unable to do anything except wait for, sometimes, 20 minutes before I can use my computer again. Seems at times that my system wants to freeze at times but luckily no blue screen of death yet. One other thing, Spybot will not complete without disabling or un-checking one of the boxes for Opera. I also noticed that the folders for Opera are now grey instead of yellow. However, that happened years ago.
I ran Combofix on this machine about a month or two ago and my system shut down and restarted. Nope, I didn't know that I couldn't do that. Well..actually I did and did it anyway. That will not happen again. I have since (actually today) attempted to remove Combofix from the machine. However, I get the following message when I attempt to uninstall it, "Windows cannot fine 'combofix'. Make sure you typed the name correctly, and then try againg. To search for a file, click the start button, and then click Search."
Here are the scans requested by your website along with a Malwarebytes scan.
:):thanks:
========================================================
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.7.2
Run by DLM09260 at 16:39:00 on 2012-09-11
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Disabled*
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyServer = 127.0.0.1:8118
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: 1 (0x1): {02478d38-c3f9-4efb-9b51-7695eca05670} - &Yahoo! Toolbar Helper
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ccleaner] "c:\program files\ccleaner\CCleaner.exe" /AUTO
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe"
uRun: [Copernic Desktop Search - Home] "c:\program files\copernic desktop search - home\DesktopSearchService.exe" /tray
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [TrackPointSrv] c:\program files\lenovo\trackpoint\tp4serv.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [TP4EX] tp4ex.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\dlm09260\startm~1\programs\startup\alarmm~1.lnk - c:\program files\palm\AlarmApp_PSI.exe
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Microsoft XML Parser for Java
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1234369100940
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340656938307
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{1F51527D-CDAA-4E51-ACDD-D02A9CC079CD} : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{EBF653BE-794F-47DF-903D-6947117D14CB} : DhcpNameServer = 192.168.6.1 64.134.255.2 64.134.255.10
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\dlm09260\application data\mozilla\firefox\profiles\vsym55us.default\
FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_265.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-09-09 03:32:38 -------- d-----w- c:\program files\Copernic Desktop Search - Home
2012-09-09 03:32:03 -------- d-----w- c:\documents and settings\dlm09260\local settings\application data\Copernic
2012-09-08 21:40:27 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2012-09-08 21:40:17 73696 ----a-w- c:\program files\mozilla firefox\breakpadinjector.dll
2012-09-06 17:46:04 -------- d-----w- c:\program files\Macrium
2012-09-06 17:30:44 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-06 17:29:46 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-21 09:33:48 12992 ----a-w- c:\windows\system32\drivers\PSVolAcc.sys
2012-08-21 09:33:28 16064 ----a-w- c:\windows\system32\drivers\pssnap.sys
2012-08-21 09:33:20 53952 ----a-w- c:\windows\system32\drivers\psmounter.sys
.
==================== Find3M ====================
.
2012-09-06 17:28:13 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-06 17:28:12 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-22 23:24:41 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-22 23:24:41 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
2012-07-16 01:23:07 1611 ----a-w- c:\windows\system32\drivers\etc\mvps.bat
2012-07-06 13:58:51 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05:18 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 18:46:44 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-03 13:40:15 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49:33 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49:32 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49:32 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05:43 385024 ----a-w- c:\windows\system32\html.iec
2012-06-30 23:56:00 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
.
============= FINISH: 16:44:30.62 ===============
========================================================
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-11 16:48:41
-----------------------------
16:48:41.067 OS Version: Windows 5.1.2600 Service Pack 3
16:48:41.067 Number of processors: 1 586 0xB04
16:48:41.067 ComputerName: RCMSMYMADEE UserName: DLM09260
16:48:44.542 Initialize success
16:48:49.159 AVAST engine defs: 12091100
16:48:59.664 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:48:59.674 Disk 0 Vendor: HITACHI_DK23EA-40B 00K3A0B5 Size: 38154MB BusType: 3
16:48:59.684 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-10
16:48:59.684 Disk 1 Vendor: SanDisk_SDCFJ-128 HDX_4.09 Size: 122MB BusType: 3
16:48:59.714 Disk 0 MBR read successfully
16:48:59.724 Disk 0 MBR scan
16:48:59.864 Disk 0 Windows VISTA default MBR code
16:48:59.894 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 34691 MB offset 2048
16:48:59.955 Disk 0 Partition 2 00 13 NTFS 3461 MB offset 71049216
16:48:59.985 Disk 0 scanning sectors +78137344
16:49:00.155 Disk 0 scanning C:\WINDOWS\system32\drivers
16:49:32.431 Service scanning
16:50:23.415 Modules scanning
16:50:39.798 Module: C:\WINDOWS\System32\drivers\dxgthk.sys **SUSPICIOUS**
16:50:43.163 Disk 0 trace - called modules:
16:50:43.203 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
16:50:43.213 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x83b76ab8]
16:50:43.233 3 CLASSPNP.SYS[f75e9fd7] -> nt!IofCallDriver -> \Device\00000095[0x83b65478]
16:50:43.243 5 ACPI.sys[f7540620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x83b62940]
16:50:43.894 AVAST engine scan C:\WINDOWS
16:50:53.388 AVAST engine scan C:\WINDOWS\system32
16:54:50.529 AVAST engine scan C:\WINDOWS\system32\drivers
16:55:16.326 AVAST engine scan C:\Documents and Settings\DLM09260
17:01:01.162 AVAST engine scan C:\Documents and Settings\All Users
17:01:40.939 Scan finished successfully
17:03:49.143 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\DLM09260\Desktop\Spybot Malware Work 091112\MBR.dat"
17:03:49.163 The log file has been saved successfully to "C:\Documents and Settings\DLM09260\Desktop\Spybot Malware Work 091112\aswMBR.txt"
========================================================
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.09.08.08
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
DLM09260 :: RCMSMYMADEE [administrator]
9/11/2012 2:22:16 PM
mbam-log-2012-09-11 (14-22-16).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 270614
Time elapsed: 45 minute(s), 46 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
IBM X30
Pentium III M 1200 MHz
760 MB Ram
40 Meg HD with 34 Meg Used.
Avast Virus Protection
Comodo Firewall
Win Patrol
Superantispyware
Malewarebytes
Added Sanboxie last month and copernic desktop search this week.
I had trouble surfing the Internet this morning. I rebooted and was able to surf. The icon in taskbar showed that it was working fine (dial-up) but it did not allow me to connect to any website. It kept giving me that error page, "Unable to connect.." yada, yada, yada. I also noticed that certain websites didn't work well until I enabled cookies. However, these websites worked fine, without any cookies alerts, while running Opera. Firefox would not work as well. Winauclt sometimes takes up a lot of memory and I am unable to do anything except wait for, sometimes, 20 minutes before I can use my computer again. Seems at times that my system wants to freeze at times but luckily no blue screen of death yet. One other thing, Spybot will not complete without disabling or un-checking one of the boxes for Opera. I also noticed that the folders for Opera are now grey instead of yellow. However, that happened years ago.
I ran Combofix on this machine about a month or two ago and my system shut down and restarted. Nope, I didn't know that I couldn't do that. Well..actually I did and did it anyway. That will not happen again. I have since (actually today) attempted to remove Combofix from the machine. However, I get the following message when I attempt to uninstall it, "Windows cannot fine 'combofix'. Make sure you typed the name correctly, and then try againg. To search for a file, click the start button, and then click Search."
Here are the scans requested by your website along with a Malwarebytes scan.
:):thanks:
========================================================
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.7.2
Run by DLM09260 at 16:39:00 on 2012-09-11
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Disabled*
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyServer = 127.0.0.1:8118
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: 1 (0x1): {02478d38-c3f9-4efb-9b51-7695eca05670} - &Yahoo! Toolbar Helper
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ccleaner] "c:\program files\ccleaner\CCleaner.exe" /AUTO
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe"
uRun: [Copernic Desktop Search - Home] "c:\program files\copernic desktop search - home\DesktopSearchService.exe" /tray
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [TrackPointSrv] c:\program files\lenovo\trackpoint\tp4serv.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [TP4EX] tp4ex.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\dlm09260\startm~1\programs\startup\alarmm~1.lnk - c:\program files\palm\AlarmApp_PSI.exe
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Microsoft XML Parser for Java
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1234369100940
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340656938307
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{1F51527D-CDAA-4E51-ACDD-D02A9CC079CD} : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{EBF653BE-794F-47DF-903D-6947117D14CB} : DhcpNameServer = 192.168.6.1 64.134.255.2 64.134.255.10
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\dlm09260\application data\mozilla\firefox\profiles\vsym55us.default\
FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_265.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-09-09 03:32:38 -------- d-----w- c:\program files\Copernic Desktop Search - Home
2012-09-09 03:32:03 -------- d-----w- c:\documents and settings\dlm09260\local settings\application data\Copernic
2012-09-08 21:40:27 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2012-09-08 21:40:17 73696 ----a-w- c:\program files\mozilla firefox\breakpadinjector.dll
2012-09-06 17:46:04 -------- d-----w- c:\program files\Macrium
2012-09-06 17:30:44 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-06 17:29:46 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-21 09:33:48 12992 ----a-w- c:\windows\system32\drivers\PSVolAcc.sys
2012-08-21 09:33:28 16064 ----a-w- c:\windows\system32\drivers\pssnap.sys
2012-08-21 09:33:20 53952 ----a-w- c:\windows\system32\drivers\psmounter.sys
.
==================== Find3M ====================
.
2012-09-06 17:28:13 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-06 17:28:12 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-22 23:24:41 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-22 23:24:41 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
2012-07-16 01:23:07 1611 ----a-w- c:\windows\system32\drivers\etc\mvps.bat
2012-07-06 13:58:51 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05:18 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 18:46:44 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-03 13:40:15 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49:33 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49:32 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49:32 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05:43 385024 ----a-w- c:\windows\system32\html.iec
2012-06-30 23:56:00 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
.
============= FINISH: 16:44:30.62 ===============
========================================================
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-11 16:48:41
-----------------------------
16:48:41.067 OS Version: Windows 5.1.2600 Service Pack 3
16:48:41.067 Number of processors: 1 586 0xB04
16:48:41.067 ComputerName: RCMSMYMADEE UserName: DLM09260
16:48:44.542 Initialize success
16:48:49.159 AVAST engine defs: 12091100
16:48:59.664 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:48:59.674 Disk 0 Vendor: HITACHI_DK23EA-40B 00K3A0B5 Size: 38154MB BusType: 3
16:48:59.684 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-10
16:48:59.684 Disk 1 Vendor: SanDisk_SDCFJ-128 HDX_4.09 Size: 122MB BusType: 3
16:48:59.714 Disk 0 MBR read successfully
16:48:59.724 Disk 0 MBR scan
16:48:59.864 Disk 0 Windows VISTA default MBR code
16:48:59.894 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 34691 MB offset 2048
16:48:59.955 Disk 0 Partition 2 00 13 NTFS 3461 MB offset 71049216
16:48:59.985 Disk 0 scanning sectors +78137344
16:49:00.155 Disk 0 scanning C:\WINDOWS\system32\drivers
16:49:32.431 Service scanning
16:50:23.415 Modules scanning
16:50:39.798 Module: C:\WINDOWS\System32\drivers\dxgthk.sys **SUSPICIOUS**
16:50:43.163 Disk 0 trace - called modules:
16:50:43.203 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
16:50:43.213 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x83b76ab8]
16:50:43.233 3 CLASSPNP.SYS[f75e9fd7] -> nt!IofCallDriver -> \Device\00000095[0x83b65478]
16:50:43.243 5 ACPI.sys[f7540620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x83b62940]
16:50:43.894 AVAST engine scan C:\WINDOWS
16:50:53.388 AVAST engine scan C:\WINDOWS\system32
16:54:50.529 AVAST engine scan C:\WINDOWS\system32\drivers
16:55:16.326 AVAST engine scan C:\Documents and Settings\DLM09260
17:01:01.162 AVAST engine scan C:\Documents and Settings\All Users
17:01:40.939 Scan finished successfully
17:03:49.143 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\DLM09260\Desktop\Spybot Malware Work 091112\MBR.dat"
17:03:49.163 The log file has been saved successfully to "C:\Documents and Settings\DLM09260\Desktop\Spybot Malware Work 091112\aswMBR.txt"
========================================================
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.09.08.08
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
DLM09260 :: RCMSMYMADEE [administrator]
9/11/2012 2:22:16 PM
mbam-log-2012-09-11 (14-22-16).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 270614
Time elapsed: 45 minute(s), 46 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)