I've used HJT and MalwareBytes to remove/disable SkyTel.exe and RichVideo.exe
DDS (Ver_2012-11-05.02) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.7.2
Run by msobczak at 7:51:32 on 2012-11-06
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2227 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Notes\SUService.exe
C:\Notes\nsd.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\lxdwcoms.exe
C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe
c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLSERVER2008R2\MSSQL\Binn\sqlservr.exe
C:\PlasticSCM4\server\plasticd.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVCSvc.exe
C:\Program Files\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnsrc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Lexmark 7600 Series\lxdwmon.exe
C:\Program Files\Lexmark 7600 Series\lxdwMsdMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\shup\shup.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\java\jre7\bin\jp2ssv.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [DiscWizardMonitor.exe] "c:\program files\seagate\discwizard\DiscWizardMonitor.exe"
mRun: [Seagate Scheduler2 Service] "c:\program files\common files\seagate\schedule2\schedhlp.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [EM_EXEC] c:\progra~1\logitech\mousew~1\system\EM_EXEC.EXE
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [lxdwmon.exe] "c:\program files\lexmark 7600 series\lxdwmon.exe"
mRun: [lxdwamon] "c:\program files\lexmark 7600 series\lxdwamon.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Carbonite Backup] c:\program files\carbonite\carbonite backup\CarboniteUI.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [Client Access Service] c:\program files\ibm\client access\cwbsvstr.exe
StartupFolder: c:\docume~1\msobczak\startm~1\programs\startup\shup.lnk - c:\program files\shup\shup.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{b0bf7057-6869-4e4b-920c-ea2a58da07f0}\Icon3E5562ED7.ico
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: internet
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxps://secure2.andersonsinc.com/,DanaInfo=andmail1.andent.andersonsinc.com,ST=1+/dwa85W.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://69.153.173.130/CACHE/stc/1/binaries/vpnweb.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1340456778703
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340706629390
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://akamaicdn.webex.com/client/WBXclient-T27L10NSP32EP5-14362/webex/ieatgpc.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://secure2.andersonsinc.com/dana-cached/sc/JuniperSetupClient.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{D2D09479-D355-466E-8CFE-ACA07256E4FF} : DHCPNameServer = 192.168.0.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\msobczak\application data\mozilla\firefox\profiles\a62qguqr.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\msobczak\application data\mozilla\firefox\profiles\a62qguqr.default\extensions\logmeinclient@logmein.com\plugins\npLMI64.dll
FF - plugin: c:\documents and settings\msobczak\application data\mozilla\firefox\profiles\a62qguqr.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2012-10-20 12:48;
; c:\documents and settings\msobczak\application data\mozilla\firefox\profiles\a62qguqr.default\extensions\LogMeInClient@logmein.com
.
============= SERVICES / DRIVERS ===============
.
R0 vididr;Acronis Virtual Disk;c:\windows\system32\drivers\vididr.sys [2012-6-23 125472]
R0 vidsflt53;Acronis Disk Storage Filter (53);c:\windows\system32\drivers\vsflt53.sys [2012-6-23 83392]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-6-24 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-6-24 355632]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2012-6-25 13696]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-10-28 242240]
R1 SWIPsec;SonicWALL IPsec Driver;c:\windows\system32\drivers\SWIPsec.sys [2012-9-15 87064]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-6-24 21256]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-6-24 44808]
R2 LNSUSvc;Lotus Notes Smart Upgrade Service;c:\notes\SUService.exe [2011-9-16 189832]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;c:\notes\nsd.exe -svcinvoke -ini "c:\notes\notes.ini" --> c:\notes\nsd.exe -svcinvoke -ini c:\notes\notes.ini [?]
R2 lxdw_device;lxdw_device;c:\windows\system32\lxdwcoms.exe -service --> c:\windows\system32\lxdwcoms.exe -service [?]
R2 MsDtsServer;SQL Server Integration Services;c:\program files\microsoft sql server\90\dts\binn\MsDtsSrvr.exe [2005-10-14 199384]
R2 MSSQL$SQLSERVER2008R2;SQL Server (SQLSERVER2008R2);c:\program files\microsoft sql server\mssql10_50.sqlserver2008r2\mssql\binn\sqlservr.exe [2012-6-29 43129288]
R2 Plastic Server 4;Plastic Server 4;c:\plasticscm4\server\plasticd.exe [2012-11-3 66880]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\common files\seagate\schedule2\schedul2.exe [2011-6-30 845808]
R2 SWGVCSvc;SonicWALL Global VPN Client Service;c:\program files\sonicwall\sonicwall global vpn client\SWGVCSvc.exe [2009-3-5 227352]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-10-9 493248]
R2 wgsslvpnsrc;WatchGuard SSLVPN Service;c:\program files\watchguard\watchguard mobile vpn with ssl\wgsslvpnsrc.exe [2012-9-5 58368]
R3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 lxdwCATSCustConnectService;lxdwCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdwserv.exe [2012-6-25 98984]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-7 160944]
S3 Aktion_83_2.0.101_Prod_9955;EasyAsk Server Aktion 83 2.0.101 Prod (Port 9955);d:\easyask10\server-aktion83\easyaskserver_aktion_83_2.0.101_prod_9955.exe -zglaxservice aktion_83_2.0.101_prod_9955 -serverproperties easyaskserver_aktion_83_2.0.101_prod_9955.properties --> d:\easyask10\server-aktion83\EasyAskServer_Aktion_83_2.0.101_Prod_9955.exe -zglaxservice Aktion_83_2.0.101_Prod_9955 -serverproperties EasyAskServer_Aktion_83_2.0.101_Prod_9955.properties [?]
S3 Aktion_83_2.0.101_Staging_9956;EasyAsk Server Aktion 83 2.0.101 Staging (Port 9956);d:\easyask10\server-aktion83\easyaskserver_aktion_83_2.0.101_staging_9956.exe -zglaxservice aktion_83_2.0.101_staging_9956 -serverproperties easyaskserver_aktion_83_2.0.101_staging_9956.properties --> d:\easyask10\server-aktion83\EasyAskServer_Aktion_83_2.0.101_Staging_9956.exe -zglaxservice Aktion_83_2.0.101_Staging_9956 -serverproperties EasyAskServer_Aktion_83_2.0.101_Staging_9956.properties [?]
S3 Aktion_D8_1.5.313_Prod_9555;EasyAsk Server Aktion D8 1.5.313 Prod (Port 9555);d:\easyask10\server\easyaskserver_aktion_d8_1.5.313_prod_9555.exe -zglaxservice aktion_d8_1.5.313_prod_9555 -serverproperties easyaskserver_aktion_d8_1.5.313_prod_9555.properties --> d:\easyask10\server\EasyAskServer_Aktion_D8_1.5.313_Prod_9555.exe -zglaxservice Aktion_D8_1.5.313_Prod_9555 -serverproperties EasyAskServer_Aktion_D8_1.5.313_Prod_9555.properties [?]
S3 Aktion_D8_1.5.313_Staging_9556;EasyAsk Server Aktion D8 1.5.313 Staging (Port 9556);d:\easyask10\server\easyaskserver_aktion_d8_1.5.313_staging_9556.exe -zglaxservice aktion_d8_1.5.313_staging_9556 -serverproperties easyaskserver_aktion_d8_1.5.313_staging_9556.properties --> d:\easyask10\server\EasyAskServer_Aktion_D8_1.5.313_Staging_9556.exe -zglaxservice Aktion_D8_1.5.313_Staging_9556 -serverproperties EasyAskServer_Aktion_D8_1.5.313_Staging_9556.properties [?]
S3 msftesql$SQLSERVER2005;SQL Server FullText Search (SQLSERVER2005);c:\program files\microsoft sql server\mssql.1\mssql\binn\msftesql.exe [2005-8-26 92880]
S3 MSSQL$SQLSERVER2005;SQL Server (SQLSERVER2005);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2005-10-14 28768528]
S3 MSSQL$SQLSERVER2008;SQL Server (SQLSERVER2008);c:\program files\microsoft sql server\mssql10.sqlserver2008\mssql\binn\sqlservr.exe [2009-3-30 43010392]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2007-4-23 224896]
S3 SQLAgent$SQLSERVER2005;SQL Server Agent (SQLSERVER2005);c:\program files\microsoft sql server\mssql.1\mssql\binn\SQLAGENT90.EXE [2005-10-14 318680]
S3 SWVNIC;SonicWALL Virtual Miniport;c:\windows\system32\drivers\SWVNIC.sys [2009-3-4 21016]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2010-4-3 44896]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
S4 RsFx0153;RsFx0153 Driver;c:\windows\system32\drivers\RsFx0153.sys [2012-6-29 249288]
S4 SQLAgent$SQLSERVER2008;SQL Server Agent (SQLSERVER2008);c:\program files\microsoft sql server\mssql10.sqlserver2008\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
S4 SQLAgent$SQLSERVER2008R2;SQL Server Agent (SQLSERVER2008R2);c:\program files\microsoft sql server\mssql10_50.sqlserver2008r2\mssql\binn\SQLAGENT.EXE [2012-6-29 379848]
.
=============== Created Last 30 ================
.
2012-11-04 21:27:39 -------- d-----w- c:\documents and settings\msobczak\application data\Malwarebytes
2012-11-04 21:27:29 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-11-04 21:27:28 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-04 21:27:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-11-04 19:11:47 -------- d-----w- c:\documents and settings\msobczak\application data\smkits
2012-11-04 19:06:29 -------- d-----w- C:\HJT
2012-11-03 12:42:00 -------- d-----w- c:\documents and settings\msobczak\local settings\application data\plastic4
2012-11-03 12:23:44 -------- d-----w- C:\PlasticSCM4
2012-10-31 00:05:03 57288 ----a-w- c:\windows\system32\perf-MSSQL10_50.SQLSERVER2008R2-sqlagtctr.dll
2012-10-31 00:04:36 82888 ----a-w- c:\windows\system32\perf-MSSQL$SQLSERVER2008R2-sqlctr10.52.4000.0.dll
2012-10-30 02:19:45 92184 ----a-w- c:\windows\system32\SQSRVRES.DLL
2012-10-30 02:09:31 348256 ----a-w- c:\documents and settings\all users\application data\microsoft\vstahost\ssis_scriptcomponent\9.0\1033\ResourceCache.dll
2012-10-30 02:09:15 348256 ----a-w- c:\documents and settings\all users\application data\microsoft\vstahost\ssis_scripttask\9.0\1033\ResourceCache.dll
2012-10-30 02:07:58 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLSERVER2008-sqlagtctr10.0.1600.22.dll
2012-10-30 02:07:36 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLSERVER2008-sqlctr10.0.1600.22.dll
2012-10-30 02:05:04 416 ----a-w- c:\documents and settings\all users\application data\microsoft\msdn\9.0\1033\ResourceCache.dll
2012-10-30 02:03:01 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-10-30 02:02:23 -------- d-----w- c:\windows\system32\RsFx
2012-10-30 02:01:52 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-10-30 02:01:13 -------- d-----w- c:\program files\MSXML 6.0
2012-10-30 01:38:56 -------- d-----w- c:\documents and settings\msobczak\local settings\application data\Microsoft_Corporation
2012-10-29 22:04:44 -------- d--h--w- c:\program files\Zero G Registry
2012-10-29 22:02:58 -------- d--h--w- c:\documents and settings\msobczak\InstallAnywhere
2012-10-29 21:45:40 -------- d-----w- c:\documents and settings\msobczak\application data\Subversion
2012-10-29 21:24:00 -------- d-----w- C:\PortQryV2
2012-10-29 20:55:30 -------- d-----w- c:\program files\Infor Global Solutions
2012-10-28 20:26:03 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-10-28 20:19:44 -------- d-----w- c:\program files\Microsoft SQL Server
2012-10-28 20:17:32 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-10-28 20:17:25 -------- d-----w- c:\documents and settings\msobczak\application data\DAEMON Tools Lite
2012-10-28 20:17:21 -------- d-----w- c:\program files\DAEMON Tools Lite
2012-10-28 20:16:44 -------- d-----w- c:\documents and settings\all users\application data\DAEMON Tools Lite
2012-10-28 18:00:49 -------- d-----w- C:\PCS
2012-10-27 18:18:17 -------- d-----w- c:\program files\shup
2012-10-25 22:10:11 -------- d-----w- c:\documents and settings\msobczak\local settings\application data\Cisco
2012-10-25 22:09:52 -------- d-----w- c:\program files\Cisco
2012-10-25 22:09:44 -------- d-----w- c:\documents and settings\all users\application data\Cisco
2012-10-13 14:08:20 -------- d-----w- c:\documents and settings\msobczak\.metadata
2012-10-13 14:08:13 -------- d-----w- c:\documents and settings\msobczak\.vec
2012-10-13 14:07:37 -------- d-----w- c:\documents and settings\msobczak\local settings\application data\Help
2012-10-13 14:07:33 -------- d-----w- c:\documents and settings\all users\application data\IBM
2012-10-13 14:07:32 -------- d-----w- c:\documents and settings\msobczak\application data\IBM
.
==================== Find3M ====================
.
2012-10-27 20:34:16 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-27 20:34:15 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-11 13:51:40 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-11 13:51:39 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-11 13:51:39 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-11 13:51:39 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
.
============= FINISH: 7:52:04.34 ===============
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-11-06 07:54:05
-----------------------------
07:54:05.500 OS Version: Windows 5.1.2600 Service Pack 3
07:54:05.500 Number of processors: 2 586 0xF0B
07:54:05.500 ComputerName: HOME-BIOSTAR UserName: msobczak
07:54:07.828 Initialize success
07:54:09.421 AVAST engine defs: 12110600
07:54:20.062 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-18
07:54:20.062 Disk 0 Vendor: WDC_WD5000AAKS-00V1A0 05.01D05 Size: 476940MB BusType: 3
07:54:20.062 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-20
07:54:20.062 Disk 1 Vendor: ST3500320AS SD15 Size: 476940MB BusType: 3
07:54:20.062 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP3T0L0-2b
07:54:20.062 Disk 2 Vendor: ST500DM002-1BD142 KC45 Size: 476940MB BusType: 3
07:54:20.093 Disk 0 MBR read successfully
07:54:20.093 Disk 0 MBR scan
07:54:20.187 Disk 0 Windows XP default MBR code
07:54:20.203 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
07:54:20.203 Disk 0 scanning sectors +976752000
07:54:20.296 Disk 0 scanning C:\WINDOWS\system32\drivers
07:54:28.687 Service scanning
07:54:56.328 Modules scanning
07:55:03.625 Disk 0 trace - called modules:
07:55:03.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys vsflt53.sys hal.dll ACPI.sys atapi.sys pciide.sys
07:55:03.640 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aeaaab8]
07:55:03.640 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> [0x8aeb6c78]
07:55:03.640 5 vsflt53.sys[b7f60c2b] -> nt!IofCallDriver -> \Device\00000082[0x8ae6b9e8]
07:55:03.640 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-18[0x8ae18d98]
07:55:07.984 AVAST engine scan C:\WINDOWS
07:55:16.468 AVAST engine scan C:\WINDOWS\system32
07:59:08.921 AVAST engine scan C:\WINDOWS\system32\drivers
07:59:27.375 AVAST engine scan C:\Documents and Settings\msobczak
08:05:45.734 AVAST engine scan C:\Documents and Settings\All Users
08:07:00.437 Scan finished successfully
08:18:30.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\msobczak\Desktop\MBR.dat"
08:18:30.203 The log file has been saved successfully to "C:\Documents and Settings\msobczak\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-11-06 07:54:05
-----------------------------
07:54:05.500 OS Version: Windows 5.1.2600 Service Pack 3
07:54:05.500 Number of processors: 2 586 0xF0B
07:54:05.500 ComputerName: HOME-BIOSTAR UserName: msobczak
07:54:07.828 Initialize success
07:54:09.421 AVAST engine defs: 12110600
07:54:20.062 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-18
07:54:20.062 Disk 0 Vendor: WDC_WD5000AAKS-00V1A0 05.01D05 Size: 476940MB BusType: 3
07:54:20.062 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-20
07:54:20.062 Disk 1 Vendor: ST3500320AS SD15 Size: 476940MB BusType: 3
07:54:20.062 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP3T0L0-2b
07:54:20.062 Disk 2 Vendor: ST500DM002-1BD142 KC45 Size: 476940MB BusType: 3
07:54:20.093 Disk 0 MBR read successfully
07:54:20.093 Disk 0 MBR scan
07:54:20.187 Disk 0 Windows XP default MBR code
07:54:20.203 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
07:54:20.203 Disk 0 scanning sectors +976752000
07:54:20.296 Disk 0 scanning C:\WINDOWS\system32\drivers
07:54:28.687 Service scanning
07:54:56.328 Modules scanning
07:55:03.625 Disk 0 trace - called modules:
07:55:03.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys vsflt53.sys hal.dll ACPI.sys atapi.sys pciide.sys
07:55:03.640 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aeaaab8]
07:55:03.640 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> [0x8aeb6c78]
07:55:03.640 5 vsflt53.sys[b7f60c2b] -> nt!IofCallDriver -> \Device\00000082[0x8ae6b9e8]
07:55:03.640 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-18[0x8ae18d98]
07:55:07.984 AVAST engine scan C:\WINDOWS
07:55:16.468 AVAST engine scan C:\WINDOWS\system32
07:59:08.921 AVAST engine scan C:\WINDOWS\system32\drivers
07:59:27.375 AVAST engine scan C:\Documents and Settings\msobczak
08:05:45.734 AVAST engine scan C:\Documents and Settings\All Users
08:07:00.437 Scan finished successfully
08:18:30.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\msobczak\Desktop\MBR.dat"
08:18:30.203 The log file has been saved successfully to "C:\Documents and Settings\msobczak\Desktop\aswMBR.txt"
DDS (Ver_2012-11-05.02) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.7.2
Run by msobczak at 7:51:32 on 2012-11-06
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2227 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Notes\SUService.exe
C:\Notes\nsd.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\lxdwcoms.exe
C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe
c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLSERVER2008R2\MSSQL\Binn\sqlservr.exe
C:\PlasticSCM4\server\plasticd.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVCSvc.exe
C:\Program Files\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnsrc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Lexmark 7600 Series\lxdwmon.exe
C:\Program Files\Lexmark 7600 Series\lxdwMsdMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Program Files\shup\shup.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\java\jre7\bin\jp2ssv.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [DiscWizardMonitor.exe] "c:\program files\seagate\discwizard\DiscWizardMonitor.exe"
mRun: [Seagate Scheduler2 Service] "c:\program files\common files\seagate\schedule2\schedhlp.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [EM_EXEC] c:\progra~1\logitech\mousew~1\system\EM_EXEC.EXE
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [lxdwmon.exe] "c:\program files\lexmark 7600 series\lxdwmon.exe"
mRun: [lxdwamon] "c:\program files\lexmark 7600 series\lxdwamon.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Carbonite Backup] c:\program files\carbonite\carbonite backup\CarboniteUI.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [Client Access Service] c:\program files\ibm\client access\cwbsvstr.exe
StartupFolder: c:\docume~1\msobczak\startm~1\programs\startup\shup.lnk - c:\program files\shup\shup.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{b0bf7057-6869-4e4b-920c-ea2a58da07f0}\Icon3E5562ED7.ico
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: internet
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxps://secure2.andersonsinc.com/,DanaInfo=andmail1.andent.andersonsinc.com,ST=1+/dwa85W.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://69.153.173.130/CACHE/stc/1/binaries/vpnweb.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1340456778703
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1340706629390
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://akamaicdn.webex.com/client/WBXclient-T27L10NSP32EP5-14362/webex/ieatgpc.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://secure2.andersonsinc.com/dana-cached/sc/JuniperSetupClient.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{D2D09479-D355-466E-8CFE-ACA07256E4FF} : DHCPNameServer = 192.168.0.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\msobczak\application data\mozilla\firefox\profiles\a62qguqr.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\msobczak\application data\mozilla\firefox\profiles\a62qguqr.default\extensions\logmeinclient@logmein.com\plugins\npLMI64.dll
FF - plugin: c:\documents and settings\msobczak\application data\mozilla\firefox\profiles\a62qguqr.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2012-10-20 12:48;
.
============= SERVICES / DRIVERS ===============
.
R0 vididr;Acronis Virtual Disk;c:\windows\system32\drivers\vididr.sys [2012-6-23 125472]
R0 vidsflt53;Acronis Disk Storage Filter (53);c:\windows\system32\drivers\vsflt53.sys [2012-6-23 83392]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-6-24 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-6-24 355632]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2012-6-25 13696]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-10-28 242240]
R1 SWIPsec;SonicWALL IPsec Driver;c:\windows\system32\drivers\SWIPsec.sys [2012-9-15 87064]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-6-24 21256]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-6-24 44808]
R2 LNSUSvc;Lotus Notes Smart Upgrade Service;c:\notes\SUService.exe [2011-9-16 189832]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;c:\notes\nsd.exe -svcinvoke -ini "c:\notes\notes.ini" --> c:\notes\nsd.exe -svcinvoke -ini c:\notes\notes.ini [?]
R2 lxdw_device;lxdw_device;c:\windows\system32\lxdwcoms.exe -service --> c:\windows\system32\lxdwcoms.exe -service [?]
R2 MsDtsServer;SQL Server Integration Services;c:\program files\microsoft sql server\90\dts\binn\MsDtsSrvr.exe [2005-10-14 199384]
R2 MSSQL$SQLSERVER2008R2;SQL Server (SQLSERVER2008R2);c:\program files\microsoft sql server\mssql10_50.sqlserver2008r2\mssql\binn\sqlservr.exe [2012-6-29 43129288]
R2 Plastic Server 4;Plastic Server 4;c:\plasticscm4\server\plasticd.exe [2012-11-3 66880]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\common files\seagate\schedule2\schedul2.exe [2011-6-30 845808]
R2 SWGVCSvc;SonicWALL Global VPN Client Service;c:\program files\sonicwall\sonicwall global vpn client\SWGVCSvc.exe [2009-3-5 227352]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-10-9 493248]
R2 wgsslvpnsrc;WatchGuard SSLVPN Service;c:\program files\watchguard\watchguard mobile vpn with ssl\wgsslvpnsrc.exe [2012-9-5 58368]
R3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 lxdwCATSCustConnectService;lxdwCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdwserv.exe [2012-6-25 98984]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-7 160944]
S3 Aktion_83_2.0.101_Prod_9955;EasyAsk Server Aktion 83 2.0.101 Prod (Port 9955);d:\easyask10\server-aktion83\easyaskserver_aktion_83_2.0.101_prod_9955.exe -zglaxservice aktion_83_2.0.101_prod_9955 -serverproperties easyaskserver_aktion_83_2.0.101_prod_9955.properties --> d:\easyask10\server-aktion83\EasyAskServer_Aktion_83_2.0.101_Prod_9955.exe -zglaxservice Aktion_83_2.0.101_Prod_9955 -serverproperties EasyAskServer_Aktion_83_2.0.101_Prod_9955.properties [?]
S3 Aktion_83_2.0.101_Staging_9956;EasyAsk Server Aktion 83 2.0.101 Staging (Port 9956);d:\easyask10\server-aktion83\easyaskserver_aktion_83_2.0.101_staging_9956.exe -zglaxservice aktion_83_2.0.101_staging_9956 -serverproperties easyaskserver_aktion_83_2.0.101_staging_9956.properties --> d:\easyask10\server-aktion83\EasyAskServer_Aktion_83_2.0.101_Staging_9956.exe -zglaxservice Aktion_83_2.0.101_Staging_9956 -serverproperties EasyAskServer_Aktion_83_2.0.101_Staging_9956.properties [?]
S3 Aktion_D8_1.5.313_Prod_9555;EasyAsk Server Aktion D8 1.5.313 Prod (Port 9555);d:\easyask10\server\easyaskserver_aktion_d8_1.5.313_prod_9555.exe -zglaxservice aktion_d8_1.5.313_prod_9555 -serverproperties easyaskserver_aktion_d8_1.5.313_prod_9555.properties --> d:\easyask10\server\EasyAskServer_Aktion_D8_1.5.313_Prod_9555.exe -zglaxservice Aktion_D8_1.5.313_Prod_9555 -serverproperties EasyAskServer_Aktion_D8_1.5.313_Prod_9555.properties [?]
S3 Aktion_D8_1.5.313_Staging_9556;EasyAsk Server Aktion D8 1.5.313 Staging (Port 9556);d:\easyask10\server\easyaskserver_aktion_d8_1.5.313_staging_9556.exe -zglaxservice aktion_d8_1.5.313_staging_9556 -serverproperties easyaskserver_aktion_d8_1.5.313_staging_9556.properties --> d:\easyask10\server\EasyAskServer_Aktion_D8_1.5.313_Staging_9556.exe -zglaxservice Aktion_D8_1.5.313_Staging_9556 -serverproperties EasyAskServer_Aktion_D8_1.5.313_Staging_9556.properties [?]
S3 msftesql$SQLSERVER2005;SQL Server FullText Search (SQLSERVER2005);c:\program files\microsoft sql server\mssql.1\mssql\binn\msftesql.exe [2005-8-26 92880]
S3 MSSQL$SQLSERVER2005;SQL Server (SQLSERVER2005);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2005-10-14 28768528]
S3 MSSQL$SQLSERVER2008;SQL Server (SQLSERVER2008);c:\program files\microsoft sql server\mssql10.sqlserver2008\mssql\binn\sqlservr.exe [2009-3-30 43010392]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2007-4-23 224896]
S3 SQLAgent$SQLSERVER2005;SQL Server Agent (SQLSERVER2005);c:\program files\microsoft sql server\mssql.1\mssql\binn\SQLAGENT90.EXE [2005-10-14 318680]
S3 SWVNIC;SonicWALL Virtual Miniport;c:\windows\system32\drivers\SWVNIC.sys [2009-3-4 21016]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2010-4-3 44896]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
S4 RsFx0153;RsFx0153 Driver;c:\windows\system32\drivers\RsFx0153.sys [2012-6-29 249288]
S4 SQLAgent$SQLSERVER2008;SQL Server Agent (SQLSERVER2008);c:\program files\microsoft sql server\mssql10.sqlserver2008\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
S4 SQLAgent$SQLSERVER2008R2;SQL Server Agent (SQLSERVER2008R2);c:\program files\microsoft sql server\mssql10_50.sqlserver2008r2\mssql\binn\SQLAGENT.EXE [2012-6-29 379848]
.
=============== Created Last 30 ================
.
2012-11-04 21:27:39 -------- d-----w- c:\documents and settings\msobczak\application data\Malwarebytes
2012-11-04 21:27:29 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-11-04 21:27:28 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-04 21:27:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-11-04 19:11:47 -------- d-----w- c:\documents and settings\msobczak\application data\smkits
2012-11-04 19:06:29 -------- d-----w- C:\HJT
2012-11-03 12:42:00 -------- d-----w- c:\documents and settings\msobczak\local settings\application data\plastic4
2012-11-03 12:23:44 -------- d-----w- C:\PlasticSCM4
2012-10-31 00:05:03 57288 ----a-w- c:\windows\system32\perf-MSSQL10_50.SQLSERVER2008R2-sqlagtctr.dll
2012-10-31 00:04:36 82888 ----a-w- c:\windows\system32\perf-MSSQL$SQLSERVER2008R2-sqlctr10.52.4000.0.dll
2012-10-30 02:19:45 92184 ----a-w- c:\windows\system32\SQSRVRES.DLL
2012-10-30 02:09:31 348256 ----a-w- c:\documents and settings\all users\application data\microsoft\vstahost\ssis_scriptcomponent\9.0\1033\ResourceCache.dll
2012-10-30 02:09:15 348256 ----a-w- c:\documents and settings\all users\application data\microsoft\vstahost\ssis_scripttask\9.0\1033\ResourceCache.dll
2012-10-30 02:07:58 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLSERVER2008-sqlagtctr10.0.1600.22.dll
2012-10-30 02:07:36 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLSERVER2008-sqlctr10.0.1600.22.dll
2012-10-30 02:05:04 416 ----a-w- c:\documents and settings\all users\application data\microsoft\msdn\9.0\1033\ResourceCache.dll
2012-10-30 02:03:01 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-10-30 02:02:23 -------- d-----w- c:\windows\system32\RsFx
2012-10-30 02:01:52 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-10-30 02:01:13 -------- d-----w- c:\program files\MSXML 6.0
2012-10-30 01:38:56 -------- d-----w- c:\documents and settings\msobczak\local settings\application data\Microsoft_Corporation
2012-10-29 22:04:44 -------- d--h--w- c:\program files\Zero G Registry
2012-10-29 22:02:58 -------- d--h--w- c:\documents and settings\msobczak\InstallAnywhere
2012-10-29 21:45:40 -------- d-----w- c:\documents and settings\msobczak\application data\Subversion
2012-10-29 21:24:00 -------- d-----w- C:\PortQryV2
2012-10-29 20:55:30 -------- d-----w- c:\program files\Infor Global Solutions
2012-10-28 20:26:03 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-10-28 20:19:44 -------- d-----w- c:\program files\Microsoft SQL Server
2012-10-28 20:17:32 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-10-28 20:17:25 -------- d-----w- c:\documents and settings\msobczak\application data\DAEMON Tools Lite
2012-10-28 20:17:21 -------- d-----w- c:\program files\DAEMON Tools Lite
2012-10-28 20:16:44 -------- d-----w- c:\documents and settings\all users\application data\DAEMON Tools Lite
2012-10-28 18:00:49 -------- d-----w- C:\PCS
2012-10-27 18:18:17 -------- d-----w- c:\program files\shup
2012-10-25 22:10:11 -------- d-----w- c:\documents and settings\msobczak\local settings\application data\Cisco
2012-10-25 22:09:52 -------- d-----w- c:\program files\Cisco
2012-10-25 22:09:44 -------- d-----w- c:\documents and settings\all users\application data\Cisco
2012-10-13 14:08:20 -------- d-----w- c:\documents and settings\msobczak\.metadata
2012-10-13 14:08:13 -------- d-----w- c:\documents and settings\msobczak\.vec
2012-10-13 14:07:37 -------- d-----w- c:\documents and settings\msobczak\local settings\application data\Help
2012-10-13 14:07:33 -------- d-----w- c:\documents and settings\all users\application data\IBM
2012-10-13 14:07:32 -------- d-----w- c:\documents and settings\msobczak\application data\IBM
.
==================== Find3M ====================
.
2012-10-27 20:34:16 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-27 20:34:15 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-11 13:51:40 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-11 13:51:39 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-11 13:51:39 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-11 13:51:39 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
.
============= FINISH: 7:52:04.34 ===============
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-11-06 07:54:05
-----------------------------
07:54:05.500 OS Version: Windows 5.1.2600 Service Pack 3
07:54:05.500 Number of processors: 2 586 0xF0B
07:54:05.500 ComputerName: HOME-BIOSTAR UserName: msobczak
07:54:07.828 Initialize success
07:54:09.421 AVAST engine defs: 12110600
07:54:20.062 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-18
07:54:20.062 Disk 0 Vendor: WDC_WD5000AAKS-00V1A0 05.01D05 Size: 476940MB BusType: 3
07:54:20.062 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-20
07:54:20.062 Disk 1 Vendor: ST3500320AS SD15 Size: 476940MB BusType: 3
07:54:20.062 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP3T0L0-2b
07:54:20.062 Disk 2 Vendor: ST500DM002-1BD142 KC45 Size: 476940MB BusType: 3
07:54:20.093 Disk 0 MBR read successfully
07:54:20.093 Disk 0 MBR scan
07:54:20.187 Disk 0 Windows XP default MBR code
07:54:20.203 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
07:54:20.203 Disk 0 scanning sectors +976752000
07:54:20.296 Disk 0 scanning C:\WINDOWS\system32\drivers
07:54:28.687 Service scanning
07:54:56.328 Modules scanning
07:55:03.625 Disk 0 trace - called modules:
07:55:03.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys vsflt53.sys hal.dll ACPI.sys atapi.sys pciide.sys
07:55:03.640 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aeaaab8]
07:55:03.640 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> [0x8aeb6c78]
07:55:03.640 5 vsflt53.sys[b7f60c2b] -> nt!IofCallDriver -> \Device\00000082[0x8ae6b9e8]
07:55:03.640 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-18[0x8ae18d98]
07:55:07.984 AVAST engine scan C:\WINDOWS
07:55:16.468 AVAST engine scan C:\WINDOWS\system32
07:59:08.921 AVAST engine scan C:\WINDOWS\system32\drivers
07:59:27.375 AVAST engine scan C:\Documents and Settings\msobczak
08:05:45.734 AVAST engine scan C:\Documents and Settings\All Users
08:07:00.437 Scan finished successfully
08:18:30.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\msobczak\Desktop\MBR.dat"
08:18:30.203 The log file has been saved successfully to "C:\Documents and Settings\msobczak\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-11-06 07:54:05
-----------------------------
07:54:05.500 OS Version: Windows 5.1.2600 Service Pack 3
07:54:05.500 Number of processors: 2 586 0xF0B
07:54:05.500 ComputerName: HOME-BIOSTAR UserName: msobczak
07:54:07.828 Initialize success
07:54:09.421 AVAST engine defs: 12110600
07:54:20.062 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-18
07:54:20.062 Disk 0 Vendor: WDC_WD5000AAKS-00V1A0 05.01D05 Size: 476940MB BusType: 3
07:54:20.062 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-20
07:54:20.062 Disk 1 Vendor: ST3500320AS SD15 Size: 476940MB BusType: 3
07:54:20.062 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP3T0L0-2b
07:54:20.062 Disk 2 Vendor: ST500DM002-1BD142 KC45 Size: 476940MB BusType: 3
07:54:20.093 Disk 0 MBR read successfully
07:54:20.093 Disk 0 MBR scan
07:54:20.187 Disk 0 Windows XP default MBR code
07:54:20.203 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476929 MB offset 63
07:54:20.203 Disk 0 scanning sectors +976752000
07:54:20.296 Disk 0 scanning C:\WINDOWS\system32\drivers
07:54:28.687 Service scanning
07:54:56.328 Modules scanning
07:55:03.625 Disk 0 trace - called modules:
07:55:03.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys vsflt53.sys hal.dll ACPI.sys atapi.sys pciide.sys
07:55:03.640 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aeaaab8]
07:55:03.640 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> [0x8aeb6c78]
07:55:03.640 5 vsflt53.sys[b7f60c2b] -> nt!IofCallDriver -> \Device\00000082[0x8ae6b9e8]
07:55:03.640 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-18[0x8ae18d98]
07:55:07.984 AVAST engine scan C:\WINDOWS
07:55:16.468 AVAST engine scan C:\WINDOWS\system32
07:59:08.921 AVAST engine scan C:\WINDOWS\system32\drivers
07:59:27.375 AVAST engine scan C:\Documents and Settings\msobczak
08:05:45.734 AVAST engine scan C:\Documents and Settings\All Users
08:07:00.437 Scan finished successfully
08:18:30.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\msobczak\Desktop\MBR.dat"
08:18:30.203 The log file has been saved successfully to "C:\Documents and Settings\msobczak\Desktop\aswMBR.txt"
Last edited by a moderator: