Rubadubdub
New member
Hi,
I have two things that seems dodgy and i cannot remove,
stdrt.exe (trojan I think)
&
winsppt.exe (not sure don't like it)
I first tried my antivirus avast but that didn't find anything
then I tried spybot but got the same result.
My friend told me to download malwarebytes which I did and it picked up stdrt.exe and I deleted it from quarantine, only when I restarted my computer stdrt.exe started again as well, the same friend told me to run rkill then malwarebytes rkill stopped stdrt.exe and winsppt.exe then malwarebytes did the exact same as stated before with the exact same results.
Please help DDS is posted below,
Thanks
DDS (Ver_10-12-12.02) - NTFSx86
Run by Charles at 13:24:19.81 on Thu 30/12/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.64.1033.18.3071.2249 [GMT 13:00]
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\atieclxx.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\System Control Manager\MSIService.exe
C:\Program Files\Soluto\SolutoService.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Soluto\soluto.exe
C:\windows\Explorer.EXE
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\wsetup\winsppt.exe
C:\Users\Charles\AppData\Local\Temp\mrt415.tmp\stdrt.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Users\Charles\Downloads\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\DllHost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.stuff.co.nz/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.msi.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [Winsppt] c:\wsetup\winsppt.exe
mRun: [MGSysCtrl] c:\program files\system control manager\MGSysCtrl.exe
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: zipfldra.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\charles\appdata\roaming\mozilla\firefox\profiles\bihvf4h3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.stuff.co.nz/
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Flashblock: {3d7eb24f-2740-49df-8937-200b1cc08f8a} - %profile%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF - Ext: FastestFox: smarterwiki@wikiatic.com - %profile%\extensions\smarterwiki@wikiatic.com
FF - Ext: BarTab: bartap@philikon.de - %profile%\extensions\bartap@philikon.de
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: PriceBlink: info@priceblink.com - %profile%\extensions\info@priceblink.com
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: BugMeNot: {987311C6-B504-4aa2-90BF-60CC49808D42} - %profile%\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
FF - Ext: Ghostery: firefox@ghostery.com - %profile%\extensions\firefox@ghostery.com
FF - Ext: SkipScreen: SkipScreen@SkipScreen - %profile%\extensions\SkipScreen@SkipScreen
FF - Ext: Resurrect Pages: {0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3} - %profile%\extensions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 4
FF - user.js: network.http.max-persistent-connections-per-server - 2
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.interval - 750000
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: browser.tabs.closeButtons - 1
============= SERVICES / DRIVERS ===============
R0 PCGenFAM;PCGenFAM;c:\windows\system32\drivers\PCGenFAM.sys [2010-12-26 181704]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-5 165584]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 176128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-5 17744]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-6-5 50768]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384]
R2 Micro Star SCM;Micro Star SCM;c:\program files\system control manager\MSIService.exe [2009-9-19 160768]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-1-20 1153368]
R2 SolutoService;Soluto PCGenome Core Service;c:\program files\soluto\SolutoService.exe [2010-11-1 331296]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-11-26 6650368]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-11-26 231936]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384]
R3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\drivers\netr28.sys [2009-9-11 626688]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\drivers\SiSGB6.sys [2009-6-11 48128]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\drivers\ArcSoftKsUFilter.sys [2009-9-19 17920]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2010-10-24 25832]
S3 MSI_DVD_010507;MSI_DVD_010507;c:\progra~1\msi\msiwdev\DVDSYS32_100507.sys [2010-5-10 22328]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\progra~1\msi\msiwdev\msibios32_100507.sys [2010-5-10 25912]
S3 MSI_VGASYS_010507;MSI_VGASYS_010507;c:\progra~1\msi\msiwdev\VGASYS32_100507.sys [2010-5-10 16696]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-9-19 166912]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-11 139776]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-2 1343400]
=============== Created Last 30 ================
2010-12-29 08:25:20 -------- d-----w- C:\TDSSKiller_Quarantine
2010-12-29 07:23:00 -------- d-----w- c:\users\charles\appdata\roaming\Malwarebytes
2010-12-29 07:22:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-29 07:22:54 -------- d-----w- c:\progra~2\Malwarebytes
2010-12-29 07:22:50 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-29 07:22:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-29 06:02:15 -------- d-----w- c:\users\charles\appdata\roaming\GoldWaveCDDB
2010-12-29 06:02:15 -------- d-----w- c:\progra~2\GoldWaveCDDB
2010-12-29 00:33:49 2380 ----a-w- c:\users\charles\cc_20101229_133328 registry as of 29 12 2010.reg
2010-12-28 21:33:24 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{74cb243f-e510-4da1-8408-078544cf3663}\mpengine.dll
2010-12-28 08:50:10 -------- d-----w- c:\program files\common files\ATI Technologies
2010-12-28 08:50:06 -------- d-----w- c:\program files\ATI Stream
2010-12-27 23:25:59 -------- d-----w- C:\AMD
2010-12-26 03:17:52 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-12-26 03:17:51 -------- d-----w- c:\program files\ffdshow
2010-12-26 03:13:41 -------- d-----w- c:\progra~2\TVersity
2010-12-26 03:05:48 181704 ----a-w- c:\windows\system32\drivers\PCGenFAM.sys
2010-12-26 03:05:44 -------- d-----w- c:\program files\Soluto
2010-12-26 03:02:40 -------- d-----w- c:\progra~2\Soluto
2010-12-25 08:57:41 63948 ----a-w- c:\users\charles\cc_20101225_215720 registry as of 25 12 2010.reg
2010-12-19 23:32:28 -------- d-----w- c:\users\charles\at mount
2010-12-16 04:30:51 -------- d-----w- c:\program files\Freemake
2010-12-15 22:45:19 516096 ----a-w- c:\program files\windows mail\wab.exe
2010-12-15 22:45:14 2048 ----a-w- c:\windows\system32\tzres.dll
2010-12-12 01:43:57 -------- d-----w- c:\users\charles\.zenmap
2010-12-12 01:43:14 -------- d-----w- c:\program files\WinPcap
2010-12-12 01:43:06 -------- d-----w- c:\program files\Nmap
2010-12-11 07:11:55 -------- d-----w- c:\program files\GoldWave
2010-12-08 23:05:42 -------- d-----w- C:\wsetup
==================== Find3M ====================
2010-11-26 03:02:08 16702976 ----a-w- c:\windows\system32\atioglxx.dll
2010-11-26 02:58:22 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-11-26 02:58:12 550400 ----a-w- c:\windows\system32\aticfx32.dll
2010-11-26 02:54:58 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-11-26 02:54:28 393216 ----a-w- c:\windows\system32\atieclxx.exe
2010-11-26 02:54:00 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2010-11-26 02:52:52 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-11-26 02:52:36 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-11-26 02:52:26 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2010-11-26 02:52:18 15872 ----a-w- c:\windows\system32\atimuixx.dll
2010-11-26 02:52:10 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-11-26 02:49:04 4066816 ----a-w- c:\windows\system32\atidxx32.dll
2010-11-26 02:30:20 4122624 ----a-w- c:\windows\system32\atiumdag.dll
2010-11-26 02:30:18 46080 ----a-w- c:\windows\system32\aticalrt.dll
2010-11-26 02:30:08 44032 ----a-w- c:\windows\system32\aticalcl.dll
2010-11-26 02:28:44 5441024 ----a-w- c:\windows\system32\aticaldd.dll
2010-11-26 02:24:36 52736 ----a-w- c:\windows\system32\coinst.dll
2010-11-26 02:22:26 3460096 ----a-w- c:\windows\system32\atiumdva.dll
2010-11-26 02:17:18 249856 ----a-w- c:\windows\system32\atiadlxx.dll
2010-11-26 02:17:04 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-11-26 02:16:54 27136 ----a-w- c:\windows\system32\atigktxx.dll
2010-11-26 02:15:58 30720 ----a-w- c:\windows\system32\atiuxpag.dll
2010-11-26 02:15:42 28672 ----a-w- c:\windows\system32\atiu9pag.dll
2010-11-26 02:09:12 52736 ----a-w- c:\windows\system32\atimpc32.dll
2010-11-26 02:09:12 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2010-11-04 22:02:54 82774 ----a-w- c:\windows\Uninstall Jade Empire.exe
2010-11-04 05:52:17 978944 ----a-w- c:\windows\system32\wininet.dll
2010-11-04 05:48:36 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-04 04:41:26 386048 ----a-w- c:\windows\system32\html.iec
2010-11-04 04:08:54 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-11-02 04:41:12 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-02 04:40:36 496128 ----a-w- c:\windows\system32\taskschd.dll
2010-11-02 04:40:36 305152 ----a-w- c:\windows\system32\taskcomp.dll
2010-11-02 04:39:32 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34:44 192000 ----a-w- c:\windows\system32\taskeng.exe
2010-11-02 04:34:33 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-29 06:59:40 7534 ----a-w- c:\users\charles\cc_20101029_195922 registry 29 10 2010.reg
2010-10-20 04:54:18 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-20 03:00:24 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-10-20 02:58:41 294400 ----a-w- c:\windows\system32\atmfd.dll
2010-10-19 05:23:23 14430 ----a-w- c:\users\charles\cc_20101019_182257 registry as of 19 10 2010.reg
2010-10-18 21:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-16 04:41:02 101760 ----a-w- c:\windows\system32\consent.exe
2010-10-16 04:36:10 314368 ----a-w- c:\windows\system32\webio.dll
============= FINISH: 13:26:49.38 ===============
I have two things that seems dodgy and i cannot remove,
stdrt.exe (trojan I think)
&
winsppt.exe (not sure don't like it)
I first tried my antivirus avast but that didn't find anything
then I tried spybot but got the same result.
My friend told me to download malwarebytes which I did and it picked up stdrt.exe and I deleted it from quarantine, only when I restarted my computer stdrt.exe started again as well, the same friend told me to run rkill then malwarebytes rkill stopped stdrt.exe and winsppt.exe then malwarebytes did the exact same as stated before with the exact same results.
Please help DDS is posted below,
Thanks
DDS (Ver_10-12-12.02) - NTFSx86
Run by Charles at 13:24:19.81 on Thu 30/12/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.64.1033.18.3071.2249 [GMT 13:00]
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\atieclxx.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\System Control Manager\MSIService.exe
C:\Program Files\Soluto\SolutoService.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Soluto\soluto.exe
C:\windows\Explorer.EXE
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\wsetup\winsppt.exe
C:\Users\Charles\AppData\Local\Temp\mrt415.tmp\stdrt.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Users\Charles\Downloads\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\DllHost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.stuff.co.nz/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.msi.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [Winsppt] c:\wsetup\winsppt.exe
mRun: [MGSysCtrl] c:\program files\system control manager\MGSysCtrl.exe
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: zipfldra.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\charles\appdata\roaming\mozilla\firefox\profiles\bihvf4h3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.stuff.co.nz/
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Flashblock: {3d7eb24f-2740-49df-8937-200b1cc08f8a} - %profile%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF - Ext: FastestFox: smarterwiki@wikiatic.com - %profile%\extensions\smarterwiki@wikiatic.com
FF - Ext: BarTab: bartap@philikon.de - %profile%\extensions\bartap@philikon.de
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: PriceBlink: info@priceblink.com - %profile%\extensions\info@priceblink.com
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: BugMeNot: {987311C6-B504-4aa2-90BF-60CC49808D42} - %profile%\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
FF - Ext: Ghostery: firefox@ghostery.com - %profile%\extensions\firefox@ghostery.com
FF - Ext: SkipScreen: SkipScreen@SkipScreen - %profile%\extensions\SkipScreen@SkipScreen
FF - Ext: Resurrect Pages: {0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3} - %profile%\extensions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 4
FF - user.js: network.http.max-persistent-connections-per-server - 2
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.interval - 750000
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: browser.tabs.closeButtons - 1
============= SERVICES / DRIVERS ===============
R0 PCGenFAM;PCGenFAM;c:\windows\system32\drivers\PCGenFAM.sys [2010-12-26 181704]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-5 165584]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 176128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-5 17744]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-6-5 50768]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384]
R2 Micro Star SCM;Micro Star SCM;c:\program files\system control manager\MSIService.exe [2009-9-19 160768]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-1-20 1153368]
R2 SolutoService;Soluto PCGenome Core Service;c:\program files\soluto\SolutoService.exe [2010-11-1 331296]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-11-26 6650368]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-11-26 231936]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-8 40384]
R3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\drivers\netr28.sys [2009-9-11 626688]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\drivers\SiSGB6.sys [2009-6-11 48128]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\drivers\ArcSoftKsUFilter.sys [2009-9-19 17920]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2010-10-24 25832]
S3 MSI_DVD_010507;MSI_DVD_010507;c:\progra~1\msi\msiwdev\DVDSYS32_100507.sys [2010-5-10 22328]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\progra~1\msi\msiwdev\msibios32_100507.sys [2010-5-10 25912]
S3 MSI_VGASYS_010507;MSI_VGASYS_010507;c:\progra~1\msi\msiwdev\VGASYS32_100507.sys [2010-5-10 16696]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-9-19 166912]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-11 139776]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-2 1343400]
=============== Created Last 30 ================
2010-12-29 08:25:20 -------- d-----w- C:\TDSSKiller_Quarantine
2010-12-29 07:23:00 -------- d-----w- c:\users\charles\appdata\roaming\Malwarebytes
2010-12-29 07:22:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-29 07:22:54 -------- d-----w- c:\progra~2\Malwarebytes
2010-12-29 07:22:50 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-29 07:22:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-29 06:02:15 -------- d-----w- c:\users\charles\appdata\roaming\GoldWaveCDDB
2010-12-29 06:02:15 -------- d-----w- c:\progra~2\GoldWaveCDDB
2010-12-29 00:33:49 2380 ----a-w- c:\users\charles\cc_20101229_133328 registry as of 29 12 2010.reg
2010-12-28 21:33:24 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{74cb243f-e510-4da1-8408-078544cf3663}\mpengine.dll
2010-12-28 08:50:10 -------- d-----w- c:\program files\common files\ATI Technologies
2010-12-28 08:50:06 -------- d-----w- c:\program files\ATI Stream
2010-12-27 23:25:59 -------- d-----w- C:\AMD
2010-12-26 03:17:52 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-12-26 03:17:51 -------- d-----w- c:\program files\ffdshow
2010-12-26 03:13:41 -------- d-----w- c:\progra~2\TVersity
2010-12-26 03:05:48 181704 ----a-w- c:\windows\system32\drivers\PCGenFAM.sys
2010-12-26 03:05:44 -------- d-----w- c:\program files\Soluto
2010-12-26 03:02:40 -------- d-----w- c:\progra~2\Soluto
2010-12-25 08:57:41 63948 ----a-w- c:\users\charles\cc_20101225_215720 registry as of 25 12 2010.reg
2010-12-19 23:32:28 -------- d-----w- c:\users\charles\at mount
2010-12-16 04:30:51 -------- d-----w- c:\program files\Freemake
2010-12-15 22:45:19 516096 ----a-w- c:\program files\windows mail\wab.exe
2010-12-15 22:45:14 2048 ----a-w- c:\windows\system32\tzres.dll
2010-12-12 01:43:57 -------- d-----w- c:\users\charles\.zenmap
2010-12-12 01:43:14 -------- d-----w- c:\program files\WinPcap
2010-12-12 01:43:06 -------- d-----w- c:\program files\Nmap
2010-12-11 07:11:55 -------- d-----w- c:\program files\GoldWave
2010-12-08 23:05:42 -------- d-----w- C:\wsetup
==================== Find3M ====================
2010-11-26 03:02:08 16702976 ----a-w- c:\windows\system32\atioglxx.dll
2010-11-26 02:58:22 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-11-26 02:58:12 550400 ----a-w- c:\windows\system32\aticfx32.dll
2010-11-26 02:54:58 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-11-26 02:54:28 393216 ----a-w- c:\windows\system32\atieclxx.exe
2010-11-26 02:54:00 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2010-11-26 02:52:52 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-11-26 02:52:36 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-11-26 02:52:26 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2010-11-26 02:52:18 15872 ----a-w- c:\windows\system32\atimuixx.dll
2010-11-26 02:52:10 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-11-26 02:49:04 4066816 ----a-w- c:\windows\system32\atidxx32.dll
2010-11-26 02:30:20 4122624 ----a-w- c:\windows\system32\atiumdag.dll
2010-11-26 02:30:18 46080 ----a-w- c:\windows\system32\aticalrt.dll
2010-11-26 02:30:08 44032 ----a-w- c:\windows\system32\aticalcl.dll
2010-11-26 02:28:44 5441024 ----a-w- c:\windows\system32\aticaldd.dll
2010-11-26 02:24:36 52736 ----a-w- c:\windows\system32\coinst.dll
2010-11-26 02:22:26 3460096 ----a-w- c:\windows\system32\atiumdva.dll
2010-11-26 02:17:18 249856 ----a-w- c:\windows\system32\atiadlxx.dll
2010-11-26 02:17:04 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-11-26 02:16:54 27136 ----a-w- c:\windows\system32\atigktxx.dll
2010-11-26 02:15:58 30720 ----a-w- c:\windows\system32\atiuxpag.dll
2010-11-26 02:15:42 28672 ----a-w- c:\windows\system32\atiu9pag.dll
2010-11-26 02:09:12 52736 ----a-w- c:\windows\system32\atimpc32.dll
2010-11-26 02:09:12 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2010-11-04 22:02:54 82774 ----a-w- c:\windows\Uninstall Jade Empire.exe
2010-11-04 05:52:17 978944 ----a-w- c:\windows\system32\wininet.dll
2010-11-04 05:48:36 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-04 04:41:26 386048 ----a-w- c:\windows\system32\html.iec
2010-11-04 04:08:54 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-11-02 04:41:12 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-02 04:40:36 496128 ----a-w- c:\windows\system32\taskschd.dll
2010-11-02 04:40:36 305152 ----a-w- c:\windows\system32\taskcomp.dll
2010-11-02 04:39:32 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34:44 192000 ----a-w- c:\windows\system32\taskeng.exe
2010-11-02 04:34:33 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-29 06:59:40 7534 ----a-w- c:\users\charles\cc_20101029_195922 registry 29 10 2010.reg
2010-10-20 04:54:18 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-20 03:00:24 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-10-20 02:58:41 294400 ----a-w- c:\windows\system32\atmfd.dll
2010-10-19 05:23:23 14430 ----a-w- c:\users\charles\cc_20101019_182257 registry as of 19 10 2010.reg
2010-10-18 21:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-16 04:41:02 101760 ----a-w- c:\windows\system32\consent.exe
2010-10-16 04:36:10 314368 ----a-w- c:\windows\system32\webio.dll
============= FINISH: 13:26:49.38 ===============