My browser keeps re-directing me to those sites and I don't know how to fix this.
Sites- toseeka.com, icityfind.com, myclickcheck.su
Thanks!
DDS (Ver_10-03-17.01) - NTFSx86 NETWORK
Run by AJC at 18:27:54.88 on 07/09/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Professional 6.1.7600.0.1252.2.1033.18.3327.2645 [GMT -4:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
H:\Windows\system32\wininit.exe
H:\Windows\system32\lsm.exe
H:\Windows\system32\svchost.exe -k DcomLaunch
H:\Windows\system32\svchost.exe -k RPCSS
H:\Program Files\Microsoft Security Essentials\MsMpEng.exe
H:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
H:\Windows\system32\svchost.exe -k netsvcs
H:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
H:\Windows\system32\svchost.exe -k LocalService
H:\Windows\system32\svchost.exe -k NetworkService
H:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
H:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
H:\Windows\Explorer.EXE
H:\Windows\system32\ctfmon.exe
H:\Program Files\TortoiseSVN\bin\TSVNCache.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Windows\system32\DllHost.exe
H:\Users\AJC\Desktop\dds.scr
H:\Windows\system32\conhost.exe
H:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.ca/
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - h:\program files\askbardis\bar\bin\askBar.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - h:\program files\spybot - search & destroy\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - h:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - h:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - h:\program files\java\jre6\bin\jp2ssv.dll
TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - h:\program files\askbardis\bar\bin\askBar.dll
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
uRun: [Google Update] "h:\users\ajc\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Steam] "x:\program files\steam\steam.exe" -silent
uRun: [AdobeBridge]
mRun: [SaiVolume] h:\program files\saitek\cyborgkeyboard\SaiVolume.exe
mRun: [EvtMgr6] h:\program files\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [StartCCC] "h:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [MSSE] "h:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRunOnce: [MessengerPlusLiveUninstall] "h:\users\ajc\appdata\local\temp\MsgPlusUninstall.exe" /Cleanup
dRun: [XBV6RD5SZF] h:\windows\temp\Yvh.exe
StartupFolder: h:\users\ajc\appdata\roaming\micros~1\windows\startm~1\programs\startup\zcinem~1.lnk - h:\users\ajc\appdata\roaming\microsoft\installer\{3d1a8e16-10a6-43e0-90be-0a0474a637a7}\NewShortcut1_3D1A8E1610A643E090BE0A0474A637A7.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - h:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - h:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - h:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - h:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - h:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: C696E6B6379737 = 64.71.255.198
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - h:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: LBTWlgn - h:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
================= FIREFOX ===================
FF - ProfilePath - h:\users\ajc\appdata\roaming\mozilla\firefox\profiles\dsgmzn05.default\
FF - prefs.js: browser.startup.homepage - Custom Value
FF - plugin: h:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: h:\program files\google\google updater\2.4.1851.5542\npCIDetect14.dll
FF - plugin: h:\program files\google\picasa3\npPicasa3.dll
FF - plugin: h:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: h:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: h:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: h:\program files\opera\program\plugins\nppl3260.dll
FF - plugin: h:\program files\opera\program\plugins\nprpjplug.dll
FF - plugin: h:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: h:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: h:\programdata\id software\quakelive\npquakezero.dll
FF - plugin: h:\users\ajc\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: h:\users\ajc\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: h:\users\ajc\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: h:\users\ajc\appdata\roaming\mozilla\plugins\npoctoshape.dll
============= SERVICES / DRIVERS ===============
R1 vwififlt;Virtual WiFi Filter Driver;h:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R3 netr73;RT73 USB Extensible Wireless LAN Card Driver;h:\windows\system32\drivers\netr73.sys [2010-2-24 562464]
R3 RTL8167;Realtek 8167 NT Driver;h:\windows\system32\drivers\Rt86win7.sys [2009-12-19 249888]
R3 SaiK0728;SaiK0728;h:\windows\system32\drivers\SaiK0728.sys [2008-1-21 104960]
S1 MpFilter;Microsoft Malware Protection Driver;h:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
S2 AMD External Events Utility;AMD External Events Utility;h:\windows\system32\atiesrxx.exe [2010-7-6 176128]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;h:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cpuz132;cpuz132;h:\windows\system32\drivers\cpuz132_x32.sys [2010-2-1 12672]
S2 cpuz134;cpuz134;h:\windows\system32\drivers\cpuz134_x32.sys [2010-7-9 20328]
S2 gupdate;Google Update Service (gupdate);h:\program files\google\update\GoogleUpdate.exe [2010-1-16 135664]
S2 SBSDWSCService;SBSD Security Center Service;h:\program files\spybot - search & destroy\SDWinSec.exe [2010-1-2 1153368]
S3 amdkmdag;amdkmdag;h:\windows\system32\drivers\atikmdag.sys [2010-7-6 5882368]
S3 amdkmdap;amdkmdap;h:\windows\system32\drivers\atikmpag.sys [2010-7-6 210944]
S3 ATP;Comodo EasyVPN Miniport Driver;h:\windows\system32\drivers\cmdatp.sys [2010-5-8 17816]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;h:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);h:\windows\system32\drivers\vrtaucbl.sys [2010-3-30 42496]
S3 MpNWMon;Microsoft Malware Protection Network Driver;h:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
S3 StorSvc;Storage Service;h:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 SwitchBoard;Adobe SwitchBoard;h:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);h:\windows\system32\drivers\tap0901t.sys [2010-1-28 27136]
S3 TeamViewer5;TeamViewer 5;h:\program files\teamviewer\version5\TeamViewer_Service.exe [2009-12-17 185640]
S3 WatAdminSvc;Windows Activation Technologies Service;h:\windows\system32\wat\WatAdminSvc.exe [2010-2-23 1343400]
S3 WSDPrintDevice;WSD Print Support via UMB;h:\windows\system32\drivers\WSDPrint.sys [2009-7-13 17920]
S3 ZCinema_TSHD;ZCinema TruSurround HD driver;h:\windows\system32\drivers\ZCinema_SRS_i386.sys [2007-8-22 18448]
S4 CrdphService;COMODO EasyVPN VNC Service;h:\program files\comodo\easyvpn\crdphService.exe [2010-3-29 491768]
S4 EasyVpnAdpt;COMODO EasyVPN Service;h:\program files\comodo\easyvpn\Vpnservice.exe [2010-3-29 45304]
S4 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;h:\program files\logmein hamachi\hamachi-2.exe [2010-3-30 1107336]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;h:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-7-22 47128]
S4 RsFx0103;RsFx0103 Driver;h:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);h:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
S4 TunngleService;TunngleService;h:\program files\tunngle\TnglCtrl.exe [2010-1-28 704760]
=============== Created Last 30 ================
2010-09-07 19:16:16 0 d-----w- h:\windows\system32\appmgmt
2010-09-06 23:16:01 0 d-----w- h:\program files\Rockstar Games
2010-09-05 18:53:34 6656 ----a-w- h:\windows\system32\drivers\obrareqh.sys
2010-09-03 18:18:23 6656 ----a-w- h:\windows\system32\drivers\dulwxisb.sys
2010-09-02 23:53:28 0 d-----w- h:\users\ajc\appdata\roaming\ADBD422F993C28275135701D667A2E2F
2010-09-02 22:57:42 0 d-----w- h:\users\ajc\appdata\roaming\Malwarebytes
2010-09-02 22:57:33 0 d-----w- h:\programdata\Malwarebytes
2010-09-02 22:45:23 0 d-----w- h:\users\ajc\appdata\roaming\D5E2400660A9D7B06C129E93FC8A3E44
2010-09-02 22:27:22 0 d-sh--w- h:\users\ajc\.COMMgr
2010-08-26 18:09:22 0 d-----w- h:\users\ajc\appdata\roaming\fltk.org
2010-08-25 16:38:12 571904 ----a-w- h:\windows\system32\oleaut32.dll
2010-08-24 21:24:04 0 d-----w- h:\program files\Mozilla Firefox 4.0 Beta 4
2010-08-22 19:21:10 0 d-----w- h:\program files\Bethesda Softworks
2010-08-21 21:01:24 21840 ----atw- h:\windows\system32\SIntfNT.dll
2010-08-21 21:01:24 17212 ----atw- h:\windows\system32\SIntf32.dll
2010-08-21 21:01:23 12067 ----atw- h:\windows\system32\SIntf16.dll
2010-08-21 20:59:56 17829 ----a-w- h:\windows\DIIUnin.dat
2010-08-21 20:59:54 94208 ----a-w- h:\windows\DIIUnin.exe
2010-08-21 20:59:54 2829 ----a-w- h:\windows\DIIUnin.pif
2010-08-21 20:49:11 0 d-----w- h:\program files\Diablo II
2010-08-21 00:54:17 506368 ----a-w- h:\windows\system32\sqlite3.dll
2010-08-21 00:43:46 0 d-----w- h:\users\ajc\appdata\roaming\Rainmeter
2010-08-21 00:40:31 0 d-----w- h:\program files\Rainmeter
2010-08-19 22:43:08 65536 --sha-w- h:\users\ajc\ntuser.dat{1073172f-abe3-11df-96d5-002354521ff4}.TM.blf
2010-08-19 22:43:08 524288 --sha-w- h:\users\ajc\ntuser.dat{1073172f-abe3-11df-96d5-002354521ff4}.TMContainer00000000000000000002.regtrans-ms
2010-08-19 22:43:08 524288 --sha-w- h:\users\ajc\ntuser.dat{1073172f-abe3-11df-96d5-002354521ff4}.TMContainer00000000000000000001.regtrans-ms
2010-08-19 22:15:57 0 d-----w- h:\program files\Microsoft Security Essentials
2010-08-19 18:04:55 5 ----a-w- H:\zrpt.xml
2010-08-19 18:04:42 0 d-----w- h:\users\ajc\appdata\roaming\A7F0474077622C0165891DA251AB6CCB
2010-08-16 16:56:07 0 d-----w- h:\program files\HLDJ
2010-08-14 16:57:31 0 d-----w- h:\users\ajc\appdata\roaming\GameTuts
2010-08-14 15:55:55 0 d-----w- h:\program files\VLC
2010-08-11 00:17:57 0 d-----w- h:\program files\RAR Password Recovery Magic
==================== Find3M ====================
2010-08-30 23:19:01 218808 ----a-w- h:\windows\system32\PnkBstrB.exe
2010-08-30 22:25:55 137256 ----a-w- h:\windows\system32\drivers\PnkBstrK.sys
2010-07-31 16:45:59 286720 ----a-w- h:\windows\iun507.exe
2010-07-29 06:30:49 197632 ----a-w- h:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- h:\windows\system32\iccvid.dll
2010-07-07 01:55:08 15461888 ----a-w- h:\windows\system32\atioglxx.dll
2010-07-07 01:54:16 143360 ----a-w- h:\windows\system32\atiapfxx.exe
2010-07-07 01:54:08 513024 ----a-w- h:\windows\system32\aticfx32.dll
2010-07-07 01:51:30 446464 ----a-w- h:\windows\system32\ATIDEMGX.dll
2010-07-07 01:51:10 380928 ----a-w- h:\windows\system32\atieclxx.exe
2010-07-07 01:50:42 176128 ----a-w- h:\windows\system32\atiesrxx.exe
2010-07-07 01:49:42 159744 ----a-w- h:\windows\system32\atitmmxx.dll
2010-07-07 01:49:28 356352 ----a-w- h:\windows\system32\atipdlxx.dll
2010-07-07 01:49:18 278528 ----a-w- h:\windows\system32\Oemdspif.dll
2010-07-07 01:49:12 11776 ----a-w- h:\windows\system32\atimuixx.dll
2010-07-07 01:49:06 43520 ----a-w- h:\windows\system32\ati2edxx.dll
2010-07-07 01:46:26 3826688 ----a-w- h:\windows\system32\atidxx32.dll
2010-07-07 01:29:24 46080 ----a-w- h:\windows\system32\aticalrt.dll
2010-07-07 01:29:14 44032 ----a-w- h:\windows\system32\aticalcl.dll
2010-07-07 01:28:20 3975680 ----a-w- h:\windows\system32\atiumdag.dll
2010-07-07 01:27:58 4323840 ----a-w- h:\windows\system32\aticaldd.dll
2010-07-07 01:24:32 50176 ----a-w- h:\windows\system32\coinst.dll
2010-07-07 01:23:14 3058688 ----a-w- h:\windows\system32\atiumdva.dll
2010-07-07 01:16:00 237568 ----a-w- h:\windows\system32\atiadlxx.dll
2010-07-07 01:15:50 12800 ----a-w- h:\windows\system32\atiglpxx.dll
2010-07-07 01:15:46 16896 ----a-w- h:\windows\system32\atigktxx.dll
2010-07-07 01:14:58 30208 ----a-w- h:\windows\system32\atiuxpag.dll
2010-07-07 01:14:44 22528 ----a-w- h:\windows\system32\atiu9pag.dll
2010-07-07 01:11:06 52736 ----a-w- h:\windows\system32\atimpc32.dll
2010-07-07 01:11:06 52736 ----a-w- h:\windows\system32\amdpcom32.dll
2010-06-30 06:25:31 978432 ----a-w- h:\windows\system32\wininet.dll
2010-06-20 16:12:27 87608 ----a-w- h:\users\ajc\appdata\roaming\inst.exe
2010-06-20 16:12:27 47360 ----a-w- h:\users\ajc\appdata\roaming\pcouffin.sys
2010-06-19 06:33:29 3955080 ----a-w- h:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- h:\windows\system32\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- h:\windows\system32\rtutils.dll
2010-06-19 04:07:18 2326016 ----a-w- h:\windows\system32\win32k.sys
2010-06-16 05:48:35 224256 ----a-w- h:\windows\system32\schannel.dll
2010-06-15 22:28:58 2857 ----a-w- h:\windows\system32\atipblag.dat
2010-03-20 01:59:20 40019 ----a-w- h:\program files\LICENSE.txt
2010-03-20 01:56:04 27136 ----a-w- h:\program files\pythonw.exe
2010-03-20 01:53:26 26624 ----a-w- h:\program files\python.exe
2010-03-20 01:52:16 49664 ----a-w- h:\program files\w9xpopen.exe
2010-03-19 20:51:58 56188 ----a-w- h:\program files\README.txt
2010-03-19 20:51:54 165575 ----a-w- h:\program files\NEWS.txt
2009-07-14 04:56:42 31548 ----a-w- h:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- h:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- h:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- h:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- h:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- h:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- h:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- h:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- h:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- h:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- h:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 18:28:32.50 ===============
Sites- toseeka.com, icityfind.com, myclickcheck.su
Thanks!
DDS (Ver_10-03-17.01) - NTFSx86 NETWORK
Run by AJC at 18:27:54.88 on 07/09/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Professional 6.1.7600.0.1252.2.1033.18.3327.2645 [GMT -4:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
H:\Windows\system32\wininit.exe
H:\Windows\system32\lsm.exe
H:\Windows\system32\svchost.exe -k DcomLaunch
H:\Windows\system32\svchost.exe -k RPCSS
H:\Program Files\Microsoft Security Essentials\MsMpEng.exe
H:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
H:\Windows\system32\svchost.exe -k netsvcs
H:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
H:\Windows\system32\svchost.exe -k LocalService
H:\Windows\system32\svchost.exe -k NetworkService
H:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
H:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
H:\Windows\Explorer.EXE
H:\Windows\system32\ctfmon.exe
H:\Program Files\TortoiseSVN\bin\TSVNCache.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Users\AJC\AppData\Local\Google\Chrome\Application\chrome.exe
H:\Windows\system32\DllHost.exe
H:\Users\AJC\Desktop\dds.scr
H:\Windows\system32\conhost.exe
H:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.ca/
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - h:\program files\askbardis\bar\bin\askBar.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - h:\program files\spybot - search & destroy\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - h:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - h:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - h:\program files\java\jre6\bin\jp2ssv.dll
TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - h:\program files\askbardis\bar\bin\askBar.dll
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
uRun: [Google Update] "h:\users\ajc\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Steam] "x:\program files\steam\steam.exe" -silent
uRun: [AdobeBridge]
mRun: [SaiVolume] h:\program files\saitek\cyborgkeyboard\SaiVolume.exe
mRun: [EvtMgr6] h:\program files\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [StartCCC] "h:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [MSSE] "h:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRunOnce: [MessengerPlusLiveUninstall] "h:\users\ajc\appdata\local\temp\MsgPlusUninstall.exe" /Cleanup
dRun: [XBV6RD5SZF] h:\windows\temp\Yvh.exe
StartupFolder: h:\users\ajc\appdata\roaming\micros~1\windows\startm~1\programs\startup\zcinem~1.lnk - h:\users\ajc\appdata\roaming\microsoft\installer\{3d1a8e16-10a6-43e0-90be-0a0474a637a7}\NewShortcut1_3D1A8E1610A643E090BE0A0474A637A7.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - h:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - h:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - h:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - h:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - h:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: C696E6B6379737 = 64.71.255.198
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - h:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: LBTWlgn - h:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
================= FIREFOX ===================
FF - ProfilePath - h:\users\ajc\appdata\roaming\mozilla\firefox\profiles\dsgmzn05.default\
FF - prefs.js: browser.startup.homepage - Custom Value
FF - plugin: h:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: h:\program files\google\google updater\2.4.1851.5542\npCIDetect14.dll
FF - plugin: h:\program files\google\picasa3\npPicasa3.dll
FF - plugin: h:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: h:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: h:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: h:\program files\opera\program\plugins\nppl3260.dll
FF - plugin: h:\program files\opera\program\plugins\nprpjplug.dll
FF - plugin: h:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: h:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: h:\programdata\id software\quakelive\npquakezero.dll
FF - plugin: h:\users\ajc\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: h:\users\ajc\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: h:\users\ajc\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: h:\users\ajc\appdata\roaming\mozilla\plugins\npoctoshape.dll
============= SERVICES / DRIVERS ===============
R1 vwififlt;Virtual WiFi Filter Driver;h:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R3 netr73;RT73 USB Extensible Wireless LAN Card Driver;h:\windows\system32\drivers\netr73.sys [2010-2-24 562464]
R3 RTL8167;Realtek 8167 NT Driver;h:\windows\system32\drivers\Rt86win7.sys [2009-12-19 249888]
R3 SaiK0728;SaiK0728;h:\windows\system32\drivers\SaiK0728.sys [2008-1-21 104960]
S1 MpFilter;Microsoft Malware Protection Driver;h:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
S2 AMD External Events Utility;AMD External Events Utility;h:\windows\system32\atiesrxx.exe [2010-7-6 176128]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;h:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cpuz132;cpuz132;h:\windows\system32\drivers\cpuz132_x32.sys [2010-2-1 12672]
S2 cpuz134;cpuz134;h:\windows\system32\drivers\cpuz134_x32.sys [2010-7-9 20328]
S2 gupdate;Google Update Service (gupdate);h:\program files\google\update\GoogleUpdate.exe [2010-1-16 135664]
S2 SBSDWSCService;SBSD Security Center Service;h:\program files\spybot - search & destroy\SDWinSec.exe [2010-1-2 1153368]
S3 amdkmdag;amdkmdag;h:\windows\system32\drivers\atikmdag.sys [2010-7-6 5882368]
S3 amdkmdap;amdkmdap;h:\windows\system32\drivers\atikmpag.sys [2010-7-6 210944]
S3 ATP;Comodo EasyVPN Miniport Driver;h:\windows\system32\drivers\cmdatp.sys [2010-5-8 17816]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;h:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);h:\windows\system32\drivers\vrtaucbl.sys [2010-3-30 42496]
S3 MpNWMon;Microsoft Malware Protection Network Driver;h:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
S3 StorSvc;Storage Service;h:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 SwitchBoard;Adobe SwitchBoard;h:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);h:\windows\system32\drivers\tap0901t.sys [2010-1-28 27136]
S3 TeamViewer5;TeamViewer 5;h:\program files\teamviewer\version5\TeamViewer_Service.exe [2009-12-17 185640]
S3 WatAdminSvc;Windows Activation Technologies Service;h:\windows\system32\wat\WatAdminSvc.exe [2010-2-23 1343400]
S3 WSDPrintDevice;WSD Print Support via UMB;h:\windows\system32\drivers\WSDPrint.sys [2009-7-13 17920]
S3 ZCinema_TSHD;ZCinema TruSurround HD driver;h:\windows\system32\drivers\ZCinema_SRS_i386.sys [2007-8-22 18448]
S4 CrdphService;COMODO EasyVPN VNC Service;h:\program files\comodo\easyvpn\crdphService.exe [2010-3-29 491768]
S4 EasyVpnAdpt;COMODO EasyVPN Service;h:\program files\comodo\easyvpn\Vpnservice.exe [2010-3-29 45304]
S4 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;h:\program files\logmein hamachi\hamachi-2.exe [2010-3-30 1107336]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;h:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-7-22 47128]
S4 RsFx0103;RsFx0103 Driver;h:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);h:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
S4 TunngleService;TunngleService;h:\program files\tunngle\TnglCtrl.exe [2010-1-28 704760]
=============== Created Last 30 ================
2010-09-07 19:16:16 0 d-----w- h:\windows\system32\appmgmt
2010-09-06 23:16:01 0 d-----w- h:\program files\Rockstar Games
2010-09-05 18:53:34 6656 ----a-w- h:\windows\system32\drivers\obrareqh.sys
2010-09-03 18:18:23 6656 ----a-w- h:\windows\system32\drivers\dulwxisb.sys
2010-09-02 23:53:28 0 d-----w- h:\users\ajc\appdata\roaming\ADBD422F993C28275135701D667A2E2F
2010-09-02 22:57:42 0 d-----w- h:\users\ajc\appdata\roaming\Malwarebytes
2010-09-02 22:57:33 0 d-----w- h:\programdata\Malwarebytes
2010-09-02 22:45:23 0 d-----w- h:\users\ajc\appdata\roaming\D5E2400660A9D7B06C129E93FC8A3E44
2010-09-02 22:27:22 0 d-sh--w- h:\users\ajc\.COMMgr
2010-08-26 18:09:22 0 d-----w- h:\users\ajc\appdata\roaming\fltk.org
2010-08-25 16:38:12 571904 ----a-w- h:\windows\system32\oleaut32.dll
2010-08-24 21:24:04 0 d-----w- h:\program files\Mozilla Firefox 4.0 Beta 4
2010-08-22 19:21:10 0 d-----w- h:\program files\Bethesda Softworks
2010-08-21 21:01:24 21840 ----atw- h:\windows\system32\SIntfNT.dll
2010-08-21 21:01:24 17212 ----atw- h:\windows\system32\SIntf32.dll
2010-08-21 21:01:23 12067 ----atw- h:\windows\system32\SIntf16.dll
2010-08-21 20:59:56 17829 ----a-w- h:\windows\DIIUnin.dat
2010-08-21 20:59:54 94208 ----a-w- h:\windows\DIIUnin.exe
2010-08-21 20:59:54 2829 ----a-w- h:\windows\DIIUnin.pif
2010-08-21 20:49:11 0 d-----w- h:\program files\Diablo II
2010-08-21 00:54:17 506368 ----a-w- h:\windows\system32\sqlite3.dll
2010-08-21 00:43:46 0 d-----w- h:\users\ajc\appdata\roaming\Rainmeter
2010-08-21 00:40:31 0 d-----w- h:\program files\Rainmeter
2010-08-19 22:43:08 65536 --sha-w- h:\users\ajc\ntuser.dat{1073172f-abe3-11df-96d5-002354521ff4}.TM.blf
2010-08-19 22:43:08 524288 --sha-w- h:\users\ajc\ntuser.dat{1073172f-abe3-11df-96d5-002354521ff4}.TMContainer00000000000000000002.regtrans-ms
2010-08-19 22:43:08 524288 --sha-w- h:\users\ajc\ntuser.dat{1073172f-abe3-11df-96d5-002354521ff4}.TMContainer00000000000000000001.regtrans-ms
2010-08-19 22:15:57 0 d-----w- h:\program files\Microsoft Security Essentials
2010-08-19 18:04:55 5 ----a-w- H:\zrpt.xml
2010-08-19 18:04:42 0 d-----w- h:\users\ajc\appdata\roaming\A7F0474077622C0165891DA251AB6CCB
2010-08-16 16:56:07 0 d-----w- h:\program files\HLDJ
2010-08-14 16:57:31 0 d-----w- h:\users\ajc\appdata\roaming\GameTuts
2010-08-14 15:55:55 0 d-----w- h:\program files\VLC
2010-08-11 00:17:57 0 d-----w- h:\program files\RAR Password Recovery Magic
==================== Find3M ====================
2010-08-30 23:19:01 218808 ----a-w- h:\windows\system32\PnkBstrB.exe
2010-08-30 22:25:55 137256 ----a-w- h:\windows\system32\drivers\PnkBstrK.sys
2010-07-31 16:45:59 286720 ----a-w- h:\windows\iun507.exe
2010-07-29 06:30:49 197632 ----a-w- h:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- h:\windows\system32\iccvid.dll
2010-07-07 01:55:08 15461888 ----a-w- h:\windows\system32\atioglxx.dll
2010-07-07 01:54:16 143360 ----a-w- h:\windows\system32\atiapfxx.exe
2010-07-07 01:54:08 513024 ----a-w- h:\windows\system32\aticfx32.dll
2010-07-07 01:51:30 446464 ----a-w- h:\windows\system32\ATIDEMGX.dll
2010-07-07 01:51:10 380928 ----a-w- h:\windows\system32\atieclxx.exe
2010-07-07 01:50:42 176128 ----a-w- h:\windows\system32\atiesrxx.exe
2010-07-07 01:49:42 159744 ----a-w- h:\windows\system32\atitmmxx.dll
2010-07-07 01:49:28 356352 ----a-w- h:\windows\system32\atipdlxx.dll
2010-07-07 01:49:18 278528 ----a-w- h:\windows\system32\Oemdspif.dll
2010-07-07 01:49:12 11776 ----a-w- h:\windows\system32\atimuixx.dll
2010-07-07 01:49:06 43520 ----a-w- h:\windows\system32\ati2edxx.dll
2010-07-07 01:46:26 3826688 ----a-w- h:\windows\system32\atidxx32.dll
2010-07-07 01:29:24 46080 ----a-w- h:\windows\system32\aticalrt.dll
2010-07-07 01:29:14 44032 ----a-w- h:\windows\system32\aticalcl.dll
2010-07-07 01:28:20 3975680 ----a-w- h:\windows\system32\atiumdag.dll
2010-07-07 01:27:58 4323840 ----a-w- h:\windows\system32\aticaldd.dll
2010-07-07 01:24:32 50176 ----a-w- h:\windows\system32\coinst.dll
2010-07-07 01:23:14 3058688 ----a-w- h:\windows\system32\atiumdva.dll
2010-07-07 01:16:00 237568 ----a-w- h:\windows\system32\atiadlxx.dll
2010-07-07 01:15:50 12800 ----a-w- h:\windows\system32\atiglpxx.dll
2010-07-07 01:15:46 16896 ----a-w- h:\windows\system32\atigktxx.dll
2010-07-07 01:14:58 30208 ----a-w- h:\windows\system32\atiuxpag.dll
2010-07-07 01:14:44 22528 ----a-w- h:\windows\system32\atiu9pag.dll
2010-07-07 01:11:06 52736 ----a-w- h:\windows\system32\atimpc32.dll
2010-07-07 01:11:06 52736 ----a-w- h:\windows\system32\amdpcom32.dll
2010-06-30 06:25:31 978432 ----a-w- h:\windows\system32\wininet.dll
2010-06-20 16:12:27 87608 ----a-w- h:\users\ajc\appdata\roaming\inst.exe
2010-06-20 16:12:27 47360 ----a-w- h:\users\ajc\appdata\roaming\pcouffin.sys
2010-06-19 06:33:29 3955080 ----a-w- h:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 ----a-w- h:\windows\system32\ntoskrnl.exe
2010-06-19 06:23:50 37376 ----a-w- h:\windows\system32\rtutils.dll
2010-06-19 04:07:18 2326016 ----a-w- h:\windows\system32\win32k.sys
2010-06-16 05:48:35 224256 ----a-w- h:\windows\system32\schannel.dll
2010-06-15 22:28:58 2857 ----a-w- h:\windows\system32\atipblag.dat
2010-03-20 01:59:20 40019 ----a-w- h:\program files\LICENSE.txt
2010-03-20 01:56:04 27136 ----a-w- h:\program files\pythonw.exe
2010-03-20 01:53:26 26624 ----a-w- h:\program files\python.exe
2010-03-20 01:52:16 49664 ----a-w- h:\program files\w9xpopen.exe
2010-03-19 20:51:58 56188 ----a-w- h:\program files\README.txt
2010-03-19 20:51:54 165575 ----a-w- h:\program files\NEWS.txt
2009-07-14 04:56:42 31548 ----a-w- h:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- h:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- h:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- h:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- h:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- h:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- h:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- h:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- h:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- h:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- h:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 18:28:32.50 ===============