Narf the Mouse
New member
It has so far resisted removal by Spybot S&D. I have attempted removal with Avast, but Avast was unable to detect it. The information in the removal page (http://forums.spybot.info/showthread.php?p=378870) was insufficient; no such entry was found in the registry.
I have followed all of the instructions here (http://forums.spybot.info/showthread.php?t=288), save for disabling tea-timer. I did not have it enabled in the first place, because I have no idea what a valid or invalid change would look like, so it was useless for me.
DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by [Name] at 9:07:39.61 on 31/07/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.688 [GMT -7:00]
AV: avast! antivirus 4.8.1368 [VPS 100731-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\ANIWConnService.exe
F:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\CollabNet\Subversion Server\svnserve.exe
F:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
F:\Program Files\Java\jre6\bin\jqs.exe
F:\Program Files\MozyPro\mozyprobackup.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
F:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
F:\Program Files\iZ3D Driver\Win32\S3DCService.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
F:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
F:\Program Files\VMWare\VMWare Player\vmware-authd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\WINDOWS\RTHDCPL.EXE
F:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
F:\Program Files\VMWare\VMWare Player\hqtray.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\soffice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
F:\Program Files\MozyPro\mozyprostat.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Cloanto\Software Director\softdir.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
F:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Documents and Settings\[Name]\Desktop\Portable Apps\FirefoxPortable\FirefoxPortable.exe
C:\Documents and Settings\[Name]\Desktop\Portable Apps\FirefoxPortable\App\firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\SpeedFan\speedfan.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
Y:\MirandaPortable\MirandaPortable.exe
Y:\MirandaPortable\App\miranda\miranda32.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\WINDOWS\system32\taskmgr.exe
F:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\[Name]\Desktop\dds.com
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - f:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - f:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [SODCPreLoad] f:\program files\ibm\lotus\symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\preload.exe c:\docume~1\[Name]\ibm\lotus\symphony\.sodc\
uRun: [Steam] "f:\program files\steam\steam.exe" -silent
uRun: [Control center.exe] f:\program files\iz3d driver\Control center.exe /silent
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [RemoteControl] "c:\program files\cyberlink dvd solution\powerdvd\PDVDServ.exe"
mRun: [InCD] c:\program files\ahead\incd\InCD.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [LGODDFU] "c:\program files\lg_fwupdate\fwupdate.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "f:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [D-Link D-Link Wireless 150 USB Adapter DWA-125] c:\program files\d-link\dwa-125 reva\AirGCFG.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [VMware hqtray] "f:\program files\vmware\vmware player\hqtray.exe"
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\[Name]\startm~1\programs\startup\erunta~1.lnk - f:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\[Name]\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mozypr~1.lnk - f:\program files\mozypro\mozyprostat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\softwa~1.lnk - c:\program files\common files\cloanto\software director\softdir.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - f:\progra~1\spybot~1\SDHelper.dll
LSP: f:\program files\vmware\vmware player\vsocklib.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\system32\guard32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\[Name]\applic~1\mozilla\firefox\profiles\ht5de6vl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - plugin: c:\documents and settings\[Name]\application data\mozilla\firefox\profiles\ht5de6vl.default\extensions\gametap@gametap.com\plugins\npGameTapWebUpdater.dll
FF - plugin: c:\program files\gametap web player\bin\release\npGameTapWebPlayer.dll
FF - plugin: f:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: f:\program files\java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: f:\program files\java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-12 114768]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-5-12 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-5-12 25160]
R1 iZ3DInjectionDriver;Driver inject our D3D and OGL wrappers;f:\program files\iz3d driver\win32\S3DInjectionDriver.sys [2010-7-27 34968]
R1 mozyproFilter;mozyproFilter;c:\windows\system32\drivers\mozypro.sys [2010-2-5 54776]
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2007-4-23 81688]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2009-11-18 116560]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2009-11-18 41424]
R2 ANIWConnService;ANIWConn Service;c:\windows\system32\ANIWConnService.exe [2010-4-27 147456]
R2 Apache2.2;Apache2.2;f:\program files\apache software foundation\apache2.2\bin\httpd.exe [2010-3-4 24645]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-12 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-12 138680]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2009-5-12 723632]
R2 CSVNsvnserve;CollabNet Subversion svnserve;f:\program files\collabnet\subversion server\svnserve.exe [2009-10-22 114780]
R2 mozyprobackup;MozyPro Backup Service;f:\program files\mozypro\mozyprobackup.exe [2010-1-4 78136]
R2 S3D Service (Win32);S3D Service (Win32);f:\program files\iz3d driver\win32\S3DCService.exe [2010-7-27 360960]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2010-5-21 70704]
R2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\common files\vmware\usb\vmware-usbarbitrator.exe [2010-5-20 539184]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-12 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-12 352920]
R3 e2eVAWdm;e2eSoft VAudio;c:\windows\system32\drivers\VAud_WDM.sys [2010-5-27 48096]
R3 fdrawcmd;Low-level Floppy Driver;c:\windows\system32\drivers\fdrawcmd.sys [2008-11-3 27544]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [2009-9-15 38248]
R3 rt2870;D-Link 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2010-4-27 715520]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-11-18 95568]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2009-11-10 104016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [2010-3-5 386784]
S3 catdrive;Catweasel Drive Driver;c:\windows\system32\drivers\catdri2k.sys [2010-5-19 6877]
S3 catjoyst;Catweasel joystick Driver;c:\windows\system32\drivers\catjoy2k.sys [2010-5-19 5520]
S3 catkeybd;Catweasel keyboard Driver;c:\windows\system32\drivers\catkey2k.sys [2010-5-19 9968]
S3 catweasl;Catweasel Driver;c:\windows\system32\drivers\Catwea2k.sys [2010-5-19 89839]
S3 MTK;Media Technology Kernel Driver;c:\windows\system32\drivers\mtk.sys --> c:\windows\system32\drivers\mtk.sys [?]
S3 ProfileSharpServer;ProfileSharpServer;f:\program files\softprodigy\profilesharp enterprise edition v1.3\ProfileSharpServer.exe [2006-11-1 73728]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688]
=============== Created Last 30 ================
2010-07-31 00:59:52 104 ----a-w- c:\windows\CORION2.INI
2010-07-28 14:59:12 0 d-----w- c:\docume~1\alluse~1\applic~1\tBGmcqRI
2010-07-28 13:58:33 0 d-----w- c:\docume~1\[Name]\applic~1\NVIDIA
2010-07-27 22:47:18 185344 ----a-w- c:\windows\system32\PCGW32.DLL
2010-07-27 21:05:37 232968 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-07-27 21:05:34 232968 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-07-27 21:05:34 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-07-27 21:05:34 0 ----a-w- c:\windows\system32\nvdrswr.lk
2010-07-27 20:40:32 0 d-----w- c:\windows\system32\NVIDIA Corporation
2010-07-27 20:31:01 0 d-----w- c:\docume~1\[Name]\applic~1\iZ3D Driver
2010-07-27 20:30:59 0 d-----w- c:\docume~1\alluse~1\applic~1\iZ3D Driver
2010-07-20 21:15:09 882 ----a-w- c:\documents and settings\[Name]\.recently-used.xbel
2010-07-13 21:53:27 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-09 23:24:26 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-07-09 23:24:18 277608 ----a-w- c:\windows\system32\nvmccs.dll
2010-07-09 23:24:18 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-09 23:24:16 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2010-07-09 23:24:16 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-07-09 23:24:16 13923432 ----a-w- c:\windows\system32\nvcpl.dll
==================== Find3M ====================
2010-07-28 03:03:31 230736 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2010-07-07 20:46:46 604776 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-06-13 00:29:01 51874 ----a-w- c:\windows\FdUninstall.exe
2010-05-27 02:01:14 20216 ---ha-w- c:\windows\system32\mlfcache.dat
2010-05-21 07:39:48 334384 ----a-w- c:\windows\system32\vmnetdhcp.exe
2010-05-21 07:39:38 399920 ----a-w- c:\windows\system32\vmnat.exe
2010-05-21 07:38:50 760368 ----a-w- c:\windows\system32\vnetlib.dll
2010-05-21 07:37:30 51248 ----a-w- c:\windows\system32\vmnetbridge.dll
2010-05-21 06:13:38 252464 ----a-w- c:\windows\system32\vmnc.dll
2010-05-21 04:19:20 59952 ----a-w- c:\windows\system32\vnetinst.dll
2010-05-04 17:20:39 832512 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20:34 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20:32 17408 ----a-w- c:\windows\system32\corpol.dll
2005-04-01 05:17:42 40960 ----a-w- c:\program files\Uninstall_CDS.exe
============= FINISH: 9:08:50.20 ===============
I turned on TeaTimer because it occurred to me that knowing the program name that's trying to change a setting would at least tell me something.
I have followed all of the instructions here (http://forums.spybot.info/showthread.php?t=288), save for disabling tea-timer. I did not have it enabled in the first place, because I have no idea what a valid or invalid change would look like, so it was useless for me.
DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by [Name] at 9:07:39.61 on 31/07/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.688 [GMT -7:00]
AV: avast! antivirus 4.8.1368 [VPS 100731-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\ANIWConnService.exe
F:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\CollabNet\Subversion Server\svnserve.exe
F:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
F:\Program Files\Java\jre6\bin\jqs.exe
F:\Program Files\MozyPro\mozyprobackup.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
F:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
F:\Program Files\iZ3D Driver\Win32\S3DCService.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
F:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
F:\Program Files\VMWare\VMWare Player\vmware-authd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\WINDOWS\RTHDCPL.EXE
F:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
F:\Program Files\VMWare\VMWare Player\hqtray.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\soffice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
F:\Program Files\MozyPro\mozyprostat.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Cloanto\Software Director\softdir.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
F:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Documents and Settings\[Name]\Desktop\Portable Apps\FirefoxPortable\FirefoxPortable.exe
C:\Documents and Settings\[Name]\Desktop\Portable Apps\FirefoxPortable\App\firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\SpeedFan\speedfan.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
Y:\MirandaPortable\MirandaPortable.exe
Y:\MirandaPortable\App\miranda\miranda32.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\WINDOWS\system32\taskmgr.exe
F:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\[Name]\Desktop\dds.com
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - f:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - f:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [SODCPreLoad] f:\program files\ibm\lotus\symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090908-0900\preload.exe c:\docume~1\[Name]\ibm\lotus\symphony\.sodc\
uRun: [Steam] "f:\program files\steam\steam.exe" -silent
uRun: [Control center.exe] f:\program files\iz3d driver\Control center.exe /silent
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [RemoteControl] "c:\program files\cyberlink dvd solution\powerdvd\PDVDServ.exe"
mRun: [InCD] c:\program files\ahead\incd\InCD.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [LGODDFU] "c:\program files\lg_fwupdate\fwupdate.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "f:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [D-Link D-Link Wireless 150 USB Adapter DWA-125] c:\program files\d-link\dwa-125 reva\AirGCFG.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [VMware hqtray] "f:\program files\vmware\vmware player\hqtray.exe"
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\[Name]\startm~1\programs\startup\erunta~1.lnk - f:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\[Name]\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mozypr~1.lnk - f:\program files\mozypro\mozyprostat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\softwa~1.lnk - c:\program files\common files\cloanto\software director\softdir.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - f:\progra~1\spybot~1\SDHelper.dll
LSP: f:\program files\vmware\vmware player\vsocklib.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\system32\guard32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\[Name]\applic~1\mozilla\firefox\profiles\ht5de6vl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - plugin: c:\documents and settings\[Name]\application data\mozilla\firefox\profiles\ht5de6vl.default\extensions\gametap@gametap.com\plugins\npGameTapWebUpdater.dll
FF - plugin: c:\program files\gametap web player\bin\release\npGameTapWebPlayer.dll
FF - plugin: f:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: f:\program files\java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: f:\program files\java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-12 114768]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-5-12 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-5-12 25160]
R1 iZ3DInjectionDriver;Driver inject our D3D and OGL wrappers;f:\program files\iz3d driver\win32\S3DInjectionDriver.sys [2010-7-27 34968]
R1 mozyproFilter;mozyproFilter;c:\windows\system32\drivers\mozypro.sys [2010-2-5 54776]
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2007-4-23 81688]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2009-11-18 116560]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2009-11-18 41424]
R2 ANIWConnService;ANIWConn Service;c:\windows\system32\ANIWConnService.exe [2010-4-27 147456]
R2 Apache2.2;Apache2.2;f:\program files\apache software foundation\apache2.2\bin\httpd.exe [2010-3-4 24645]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-12 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-12 138680]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2009-5-12 723632]
R2 CSVNsvnserve;CollabNet Subversion svnserve;f:\program files\collabnet\subversion server\svnserve.exe [2009-10-22 114780]
R2 mozyprobackup;MozyPro Backup Service;f:\program files\mozypro\mozyprobackup.exe [2010-1-4 78136]
R2 S3D Service (Win32);S3D Service (Win32);f:\program files\iz3d driver\win32\S3DCService.exe [2010-7-27 360960]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2010-5-21 70704]
R2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\common files\vmware\usb\vmware-usbarbitrator.exe [2010-5-20 539184]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-12 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-12 352920]
R3 e2eVAWdm;e2eSoft VAudio;c:\windows\system32\drivers\VAud_WDM.sys [2010-5-27 48096]
R3 fdrawcmd;Low-level Floppy Driver;c:\windows\system32\drivers\fdrawcmd.sys [2008-11-3 27544]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [2009-9-15 38248]
R3 rt2870;D-Link 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2010-4-27 715520]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-11-18 95568]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2009-11-10 104016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [2010-3-5 386784]
S3 catdrive;Catweasel Drive Driver;c:\windows\system32\drivers\catdri2k.sys [2010-5-19 6877]
S3 catjoyst;Catweasel joystick Driver;c:\windows\system32\drivers\catjoy2k.sys [2010-5-19 5520]
S3 catkeybd;Catweasel keyboard Driver;c:\windows\system32\drivers\catkey2k.sys [2010-5-19 9968]
S3 catweasl;Catweasel Driver;c:\windows\system32\drivers\Catwea2k.sys [2010-5-19 89839]
S3 MTK;Media Technology Kernel Driver;c:\windows\system32\drivers\mtk.sys --> c:\windows\system32\drivers\mtk.sys [?]
S3 ProfileSharpServer;ProfileSharpServer;f:\program files\softprodigy\profilesharp enterprise edition v1.3\ProfileSharpServer.exe [2006-11-1 73728]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688]
=============== Created Last 30 ================
2010-07-31 00:59:52 104 ----a-w- c:\windows\CORION2.INI
2010-07-28 14:59:12 0 d-----w- c:\docume~1\alluse~1\applic~1\tBGmcqRI
2010-07-28 13:58:33 0 d-----w- c:\docume~1\[Name]\applic~1\NVIDIA
2010-07-27 22:47:18 185344 ----a-w- c:\windows\system32\PCGW32.DLL
2010-07-27 21:05:37 232968 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-07-27 21:05:34 232968 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-07-27 21:05:34 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-07-27 21:05:34 0 ----a-w- c:\windows\system32\nvdrswr.lk
2010-07-27 20:40:32 0 d-----w- c:\windows\system32\NVIDIA Corporation
2010-07-27 20:31:01 0 d-----w- c:\docume~1\[Name]\applic~1\iZ3D Driver
2010-07-27 20:30:59 0 d-----w- c:\docume~1\alluse~1\applic~1\iZ3D Driver
2010-07-20 21:15:09 882 ----a-w- c:\documents and settings\[Name]\.recently-used.xbel
2010-07-13 21:53:27 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-09 23:24:26 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-07-09 23:24:18 277608 ----a-w- c:\windows\system32\nvmccs.dll
2010-07-09 23:24:18 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-09 23:24:16 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2010-07-09 23:24:16 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-07-09 23:24:16 13923432 ----a-w- c:\windows\system32\nvcpl.dll
==================== Find3M ====================
2010-07-28 03:03:31 230736 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2010-07-07 20:46:46 604776 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-06-13 00:29:01 51874 ----a-w- c:\windows\FdUninstall.exe
2010-05-27 02:01:14 20216 ---ha-w- c:\windows\system32\mlfcache.dat
2010-05-21 07:39:48 334384 ----a-w- c:\windows\system32\vmnetdhcp.exe
2010-05-21 07:39:38 399920 ----a-w- c:\windows\system32\vmnat.exe
2010-05-21 07:38:50 760368 ----a-w- c:\windows\system32\vnetlib.dll
2010-05-21 07:37:30 51248 ----a-w- c:\windows\system32\vmnetbridge.dll
2010-05-21 06:13:38 252464 ----a-w- c:\windows\system32\vmnc.dll
2010-05-21 04:19:20 59952 ----a-w- c:\windows\system32\vnetinst.dll
2010-05-04 17:20:39 832512 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20:34 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20:32 17408 ----a-w- c:\windows\system32\corpol.dll
2005-04-01 05:17:42 40960 ----a-w- c:\program files\Uninstall_CDS.exe
============= FINISH: 9:08:50.20 ===============
I turned on TeaTimer because it occurred to me that knowing the program name that's trying to change a setting would at least tell me something.
Last edited by a moderator: