Greetings,
I have a click.giftload infection that returns when I restart my computer.I may also have the remnants of hiloti.gen.d and virtumonde.prx infections, both of which I was able to remove with the use of my computers antivirus/spyware programs.
Because of this infection my computer is now having a lot of problems. Random popups will just open in my browser, the svchost.exe process is using a lot of the cpu’s resources, and half of the time I turn it on the computer will boot up and load to the point where it will show my desktop wallpaper then freeze, preventing the taskbar and my start up programs from appearing.
Similarly, when turning off the computer half of the time a similar thing will happen. When it begins the shutdown process all the programs will close and it will stop at the desktop wallpaper requiring me to hold the power button to shut it down. Finally, my computer will show a blue screen, specifically a stop error, if I turn it on with either the secondary internal hard drive installed or a external usb drive installed. So now it will only operate with the main hard drive installed and in order to use a usb drive it can be connected only after windows has loaded.
Your help in getting my computer back to performing normally would greatly be appreciated.
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by pd30 at 11:54:57.21 on Mon 04/18/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1527 [GMT -4:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Sandboxie\SbieSvc.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Everything\Everything.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\NetWorx\networx.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\Ditto\Ditto.exe
C:\Program Files\3RVX\3RVX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AnVir Task Manager\AnVir.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\NirSoft\Volumouse\volumouse.exe
C:\Program Files\XYplorer\XYplorer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\program files\amp winoff\winoff.exe
C:\Program Files\WinSplit Revolution\WinSplit.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\stickies\stickies.exe
C:\Program Files\FastStone Capture\FSCapture.exe
C:\Program Files\FindAndRunRobot\FindAndRunRobot.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe
C:\Program Files\WinSplit Revolution\WinSplitDrvr32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Documents and Settings\pd30\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uWindow Title = Service Pack 3 Internet Explorer
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe"
uRun: [Ditto] c:\program files\ditto\Ditto.exe
uRun: [3RVX] c:\program files\3rvx\3RVX.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AnVir Task Manager] "c:\program files\anvir task manager\AnVir.exe" Minimized
uRun: [Rainlendar2] c:\program files\rainlendar2\Rainlendar2.exe
uRun: [$Volumouse$] "c:\program files\nirsoft\volumouse\volumouse.exe" /nodlg
uRun: [XYplorer] "c:\program files\xyplorer\XYplorer.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [AMP WinOFF] c:\program files\amp winoff\winoff.exe -quiet
uRun: [Winsplit] c:\program files\winsplit revolution\WinSplit.exe
uRun: [DriverMax]
uRun: [DriverMax_RESTART]
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [Everything] "c:\program files\everything\Everything.exe" -startup
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [NetWorx] "c:\program files\networx\networx.exe" /auto
dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\pd30\startm~1\programs\startup\fastst~1.lnk - c:\program files\faststone capture\FSCapture.exe
StartupFolder: c:\docume~1\pd30\startm~1\programs\startup\findan~1.lnk - c:\program files\findandrunrobot\FindAndRunRobot.exe
StartupFolder: c:\docume~1\pd30\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdockfree\ObjectDock.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\stickies.lnk - c:\program files\stickies\stickies.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
AppInit_DLLs: c:\windows\system32\guard32.dll
STS: ObjectDockShlExt Class: {1984d045-52cf-49cd-db77-08f378fea4db} - c:\program files\stardock\objectdockfree\ODMenu.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\pd30\applic~1\mozilla\firefox\profiles\blegkae2.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US
fficial
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: FEBE: {4BBDD651-70CF-4821-84F8-2B918CF89CA3} - %profile%\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
FF - Ext: Session Manager: {1280606b-2510-4fe0-97ef-9b5a22eafe30} - %profile%\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
FF - Ext: Print Edit: printedit@DW-dev - %profile%\extensions\printedit@DW-dev
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Add Bookmark Here ²: abhere2@moztw.org - %profile%\extensions\abhere2@moztw.org
FF - Ext: AlertCheck: alertcheck@mike.conley - %profile%\extensions\alertcheck@mike.conley
FF - Ext: All-in-One Sidebar: {097d3191-e6fa-4728-9826-b533d755359d} - %profile%\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
FF - Ext: Auto Replay for YouTube: {da684c80-6ad7-4a95-80ec-959e8ab082fd} - %profile%\extensions\{da684c80-6ad7-4a95-80ec-959e8ab082fd}
FF - Ext: BarTab: bartap@philikon.de - %profile%\extensions\bartap@philikon.de
FF - Ext: BetterPrivacy: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} - %profile%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF - Ext: CheckFox: {BAEC7B80-9A31-47b2-A68B-DCAC8DF48E87} - %profile%\extensions\{BAEC7B80-9A31-47b2-A68B-DCAC8DF48E87}
FF - Ext: CopyAllUrls: {960BE052-4847-422b-9AD6-8631D3D0A607} - %profile%\extensions\{960BE052-4847-422b-9AD6-8631D3D0A607}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: fireform: fireform@mozilla.org - %profile%\extensions\fireform@mozilla.org
FF - Ext: Firefox Showcase: {89506680-e3f4-484c-a2c0-ed711d481eda} - %profile%\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
FF - Ext: Flashblock: {3d7eb24f-2740-49df-8937-200b1cc08f8a} - %profile%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: Googlepedia: {1ABADB6E-DC4B-11DA-9F70-791A9CD9513E} - %profile%\extensions\{1ABADB6E-DC4B-11DA-9F70-791A9CD9513E}
FF - Ext: Image Zoom: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} - %profile%\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
FF - Ext: CLEO: CLEO@guid.customsoftwareconsult.com - %profile%\extensions\CLEO@guid.customsoftwareconsult.com
FF - Ext: KeepTube Downloader: webmaster@keep-tube.com - %profile%\extensions\webmaster@keep-tube.com
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: Open With: openwith@darktrojan.net - %profile%\extensions\openwith@darktrojan.net
FF - Ext: Panic Button: {24cea704-946d-11da-a72b-0800200c9a66} - %profile%\extensions\{24cea704-946d-11da-a72b-0800200c9a66}
FF - Ext: Modify Headers: {b749fc7c-e949-447f-926c-3f4eed6accfe} - %profile%\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
FF - Ext: Open Tab Count: tabcount@3greeneggs.com - %profile%\extensions\tabcount@3greeneggs.com
FF - Ext: NumExt: numext@alouche.net - %profile%\extensions\numext@alouche.net
FF - Ext: YouTube to MP3: youtube2mp3@mondayx.de - %profile%\extensions\youtube2mp3@mondayx.de
FF - Ext: QuickNote: {C0CB8BA3-6C1B-47e8-A6AB-1FAB889562D9} - %profile%\extensions\{C0CB8BA3-6C1B-47e8-A6AB-1FAB889562D9}
FF - Ext: Read It Later: isreaditlater@ideashower.com - %profile%\extensions\isreaditlater@ideashower.com
FF - Ext: ReminderFox: {ada4b710-8346-4b82-8199-5de2b400a6ae} - %profile%\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Show File Size: {1aE2D8ED-8CDc-5811-8eA1-89F53739A750} - %profile%\extensions\{1aE2D8ED-8CDc-5811-8eA1-89F53739A750}
FF - Ext: Snap Links Plus: snaplinks@snaplinks.mozdev.org - %profile%\extensions\snaplinks@snaplinks.mozdev.org
FF - Ext: Tab Catalog: {049952B3-A745-43bd-8D26-D1349B1ED944} - %profile%\extensions\{049952B3-A745-43bd-8D26-D1349B1ED944}
FF - Ext: Vacuum Places Improved: VacuumPlacesImproved@lultimouomo-gmail.com - %profile%\extensions\VacuumPlacesImproved@lultimouomo-gmail.com
FF - Ext: YouTube Auto Replay: YouTubeAutoReplay@arikv.com - %profile%\extensions\YouTubeAutoReplay@arikv.com
FF - Ext: TidyRead: tidyread@gmail.com - %profile%\extensions\tidyread@gmail.com
FF - Ext: User Agent Switcher: {e968fc70-8f95-4ab9-9e79-304de2a71ee1} - %profile%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
FF - Ext: µTorrent: {dfdd369d-7bf4-432b-8ad6-e2e7b777116a} - %profile%\extensions\{dfdd369d-7bf4-432b-8ad6-e2e7b777116a}
FF - Ext: MacOSX Theme: {00352F14-3F76-4e4d-ACFF-9976D7E4B3B9} - %profile%\extensions\{00352F14-3F76-4e4d-ACFF-9976D7E4B3B9}
FF - Ext: DownThemAll! AntiContainer: anticontainer@downthemall.net - %profile%\extensions\anticontainer@downthemall.net
FF - Ext: SQLite Manager: SQLiteManager@mrinalkant.blogspot.com - %profile%\extensions\SQLiteManager@mrinalkant.blogspot.com
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\divx\divx plus web player\firefox\html5video
FF - Ext: XULRunner: {36EA0E67-1ECB-4ECC-9C04-CC1B5261C221} - c:\documents and settings\pd30\local settings\application data\{36EA0E67-1ECB-4ECC-9C04-CC1B5261C221}
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
.
============= FINISH: 11:59:21.04 ===============
-----------------------------------------------------------------------
--- Search result list ---
Click.GiftLoad: [SBI $89783858] User settings (Registry value, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION\svchost.exe
MediaPlex: Tracking cookie (Internet Explorer: pd30) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
I have a click.giftload infection that returns when I restart my computer.I may also have the remnants of hiloti.gen.d and virtumonde.prx infections, both of which I was able to remove with the use of my computers antivirus/spyware programs.
Because of this infection my computer is now having a lot of problems. Random popups will just open in my browser, the svchost.exe process is using a lot of the cpu’s resources, and half of the time I turn it on the computer will boot up and load to the point where it will show my desktop wallpaper then freeze, preventing the taskbar and my start up programs from appearing.
Similarly, when turning off the computer half of the time a similar thing will happen. When it begins the shutdown process all the programs will close and it will stop at the desktop wallpaper requiring me to hold the power button to shut it down. Finally, my computer will show a blue screen, specifically a stop error, if I turn it on with either the secondary internal hard drive installed or a external usb drive installed. So now it will only operate with the main hard drive installed and in order to use a usb drive it can be connected only after windows has loaded.
Your help in getting my computer back to performing normally would greatly be appreciated.
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by pd30 at 11:54:57.21 on Mon 04/18/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1527 [GMT -4:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Sandboxie\SbieSvc.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Everything\Everything.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\NetWorx\networx.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\Ditto\Ditto.exe
C:\Program Files\3RVX\3RVX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AnVir Task Manager\AnVir.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\NirSoft\Volumouse\volumouse.exe
C:\Program Files\XYplorer\XYplorer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\program files\amp winoff\winoff.exe
C:\Program Files\WinSplit Revolution\WinSplit.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\stickies\stickies.exe
C:\Program Files\FastStone Capture\FSCapture.exe
C:\Program Files\FindAndRunRobot\FindAndRunRobot.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe
C:\Program Files\WinSplit Revolution\WinSplitDrvr32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Documents and Settings\pd30\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uWindow Title = Service Pack 3 Internet Explorer
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe"
uRun: [Ditto] c:\program files\ditto\Ditto.exe
uRun: [3RVX] c:\program files\3rvx\3RVX.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AnVir Task Manager] "c:\program files\anvir task manager\AnVir.exe" Minimized
uRun: [Rainlendar2] c:\program files\rainlendar2\Rainlendar2.exe
uRun: [$Volumouse$] "c:\program files\nirsoft\volumouse\volumouse.exe" /nodlg
uRun: [XYplorer] "c:\program files\xyplorer\XYplorer.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [AMP WinOFF] c:\program files\amp winoff\winoff.exe -quiet
uRun: [Winsplit] c:\program files\winsplit revolution\WinSplit.exe
uRun: [DriverMax]
uRun: [DriverMax_RESTART]
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [Everything] "c:\program files\everything\Everything.exe" -startup
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [NetWorx] "c:\program files\networx\networx.exe" /auto
dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\pd30\startm~1\programs\startup\fastst~1.lnk - c:\program files\faststone capture\FSCapture.exe
StartupFolder: c:\docume~1\pd30\startm~1\programs\startup\findan~1.lnk - c:\program files\findandrunrobot\FindAndRunRobot.exe
StartupFolder: c:\docume~1\pd30\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdockfree\ObjectDock.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\stickies.lnk - c:\program files\stickies\stickies.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
AppInit_DLLs: c:\windows\system32\guard32.dll
STS: ObjectDockShlExt Class: {1984d045-52cf-49cd-db77-08f378fea4db} - c:\program files\stardock\objectdockfree\ODMenu.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\pd30\applic~1\mozilla\firefox\profiles\blegkae2.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: FEBE: {4BBDD651-70CF-4821-84F8-2B918CF89CA3} - %profile%\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
FF - Ext: Session Manager: {1280606b-2510-4fe0-97ef-9b5a22eafe30} - %profile%\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
FF - Ext: Print Edit: printedit@DW-dev - %profile%\extensions\printedit@DW-dev
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Add Bookmark Here ²: abhere2@moztw.org - %profile%\extensions\abhere2@moztw.org
FF - Ext: AlertCheck: alertcheck@mike.conley - %profile%\extensions\alertcheck@mike.conley
FF - Ext: All-in-One Sidebar: {097d3191-e6fa-4728-9826-b533d755359d} - %profile%\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
FF - Ext: Auto Replay for YouTube: {da684c80-6ad7-4a95-80ec-959e8ab082fd} - %profile%\extensions\{da684c80-6ad7-4a95-80ec-959e8ab082fd}
FF - Ext: BarTab: bartap@philikon.de - %profile%\extensions\bartap@philikon.de
FF - Ext: BetterPrivacy: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} - %profile%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
FF - Ext: CheckFox: {BAEC7B80-9A31-47b2-A68B-DCAC8DF48E87} - %profile%\extensions\{BAEC7B80-9A31-47b2-A68B-DCAC8DF48E87}
FF - Ext: CopyAllUrls: {960BE052-4847-422b-9AD6-8631D3D0A607} - %profile%\extensions\{960BE052-4847-422b-9AD6-8631D3D0A607}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: fireform: fireform@mozilla.org - %profile%\extensions\fireform@mozilla.org
FF - Ext: Firefox Showcase: {89506680-e3f4-484c-a2c0-ed711d481eda} - %profile%\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
FF - Ext: Flashblock: {3d7eb24f-2740-49df-8937-200b1cc08f8a} - %profile%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: Googlepedia: {1ABADB6E-DC4B-11DA-9F70-791A9CD9513E} - %profile%\extensions\{1ABADB6E-DC4B-11DA-9F70-791A9CD9513E}
FF - Ext: Image Zoom: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} - %profile%\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
FF - Ext: CLEO: CLEO@guid.customsoftwareconsult.com - %profile%\extensions\CLEO@guid.customsoftwareconsult.com
FF - Ext: KeepTube Downloader: webmaster@keep-tube.com - %profile%\extensions\webmaster@keep-tube.com
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: Open With: openwith@darktrojan.net - %profile%\extensions\openwith@darktrojan.net
FF - Ext: Panic Button: {24cea704-946d-11da-a72b-0800200c9a66} - %profile%\extensions\{24cea704-946d-11da-a72b-0800200c9a66}
FF - Ext: Modify Headers: {b749fc7c-e949-447f-926c-3f4eed6accfe} - %profile%\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
FF - Ext: Open Tab Count: tabcount@3greeneggs.com - %profile%\extensions\tabcount@3greeneggs.com
FF - Ext: NumExt: numext@alouche.net - %profile%\extensions\numext@alouche.net
FF - Ext: YouTube to MP3: youtube2mp3@mondayx.de - %profile%\extensions\youtube2mp3@mondayx.de
FF - Ext: QuickNote: {C0CB8BA3-6C1B-47e8-A6AB-1FAB889562D9} - %profile%\extensions\{C0CB8BA3-6C1B-47e8-A6AB-1FAB889562D9}
FF - Ext: Read It Later: isreaditlater@ideashower.com - %profile%\extensions\isreaditlater@ideashower.com
FF - Ext: ReminderFox: {ada4b710-8346-4b82-8199-5de2b400a6ae} - %profile%\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Show File Size: {1aE2D8ED-8CDc-5811-8eA1-89F53739A750} - %profile%\extensions\{1aE2D8ED-8CDc-5811-8eA1-89F53739A750}
FF - Ext: Snap Links Plus: snaplinks@snaplinks.mozdev.org - %profile%\extensions\snaplinks@snaplinks.mozdev.org
FF - Ext: Tab Catalog: {049952B3-A745-43bd-8D26-D1349B1ED944} - %profile%\extensions\{049952B3-A745-43bd-8D26-D1349B1ED944}
FF - Ext: Vacuum Places Improved: VacuumPlacesImproved@lultimouomo-gmail.com - %profile%\extensions\VacuumPlacesImproved@lultimouomo-gmail.com
FF - Ext: YouTube Auto Replay: YouTubeAutoReplay@arikv.com - %profile%\extensions\YouTubeAutoReplay@arikv.com
FF - Ext: TidyRead: tidyread@gmail.com - %profile%\extensions\tidyread@gmail.com
FF - Ext: User Agent Switcher: {e968fc70-8f95-4ab9-9e79-304de2a71ee1} - %profile%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
FF - Ext: µTorrent: {dfdd369d-7bf4-432b-8ad6-e2e7b777116a} - %profile%\extensions\{dfdd369d-7bf4-432b-8ad6-e2e7b777116a}
FF - Ext: MacOSX Theme: {00352F14-3F76-4e4d-ACFF-9976D7E4B3B9} - %profile%\extensions\{00352F14-3F76-4e4d-ACFF-9976D7E4B3B9}
FF - Ext: DownThemAll! AntiContainer: anticontainer@downthemall.net - %profile%\extensions\anticontainer@downthemall.net
FF - Ext: SQLite Manager: SQLiteManager@mrinalkant.blogspot.com - %profile%\extensions\SQLiteManager@mrinalkant.blogspot.com
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\divx\divx plus web player\firefox\html5video
FF - Ext: XULRunner: {36EA0E67-1ECB-4ECC-9C04-CC1B5261C221} - c:\documents and settings\pd30\local settings\application data\{36EA0E67-1ECB-4ECC-9C04-CC1B5261C221}
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
.
============= FINISH: 11:59:21.04 ===============
-----------------------------------------------------------------------
--- Search result list ---
Click.GiftLoad: [SBI $89783858] User settings (Registry value, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION\svchost.exe
MediaPlex: Tracking cookie (Internet Explorer: pd30) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---