I apologize for jumping the gun earlier and posting the HJT log instead of the DDS log. Here is my post from yesterday.
Hello,
I have a problem that I think is an infection but it may just be Google, I am not sure. When I search something in Google, and click a link to the result, I get sent to some non related page. When I click back then reclick the link, it takes me to the right page. This only happens rarely but I don't think it should happen at all. I just tried it and it happened once but I have tried various searches and clicked 20+ links and can't replicate it. I wanted to replicate it to get a screen shot as the address bar says something like google ads. I'm sure later when I am searching it will repeat the same thing as this is what it normally does. The first 1-3 links will be redirected then everything will be fine for the next day or two.
The following searches have come up clean, Spybot SD, Malwarebytes, Avast and boot scan with Avast.
Just google or infection?
Thanks for the help.
Edit: I searched again today and it took me to some weird site instead of the right one.
www"dot"infomash"dot"org /"some other stuff here"
In sticky says to post both logs, but the attach logs says not to post it unless requested. So here is just the DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Daniel at 19:46:43.77 on Mon 08/16/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1068 [GMT -4:00]
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Games\Spy\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\explorer.exe
C:\Games\Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SYSTEM32\mspaint.exe
C:\Documents and Settings\Daniel\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
BHO: {4314F235-1E09-4193-AAAE-042D73E41824} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\games\spy\spybot~1\SDHelper.dll
BHO: {A78FAF59-B270-4B28-A275-68A94333847F} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {F9C48591-50FA-4A03-BB63-5F3B832C8D88} - No File
uRun: [SpybotSD TeaTimer] c:\games\spy\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [kdx] c:\windows\kdx\KHost.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\games\quick\qttask.exe" -atboottime
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: E&xport to Microsoft Excel
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\games\spy\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136503940425
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} - hxxp://www.gamespot.com/KDX/zd/kdx.cab
Filter: text/html - {33d38737-6480-4192-b77e-139d94a90223} -
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\games\spy\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, mcenspc.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\daniel\applic~1\mozilla\firefox\profiles\tmsh95n6.default\
FF - plugin: c:\documents and settings\daniel\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\daniel\application data\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\documents and settings\daniel\application data\real\rhapsodyplayerengine\nprhapengine.dll
FF - plugin: c:\games\codec\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\games\codec\divx\divx web player\npdivx32.dll
FF - plugin: c:\games\firefox\plugins\npbittorrent.dll
FF - plugin: c:\games\firefox\plugins\npdeployJava1.dll
FF - plugin: c:\games\quick\plugins\npqtplugin.dll
FF - plugin: c:\games\quick\plugins\npqtplugin2.dll
FF - plugin: c:\games\quick\plugins\npqtplugin3.dll
FF - plugin: c:\games\quick\plugins\npqtplugin4.dll
FF - plugin: c:\games\quick\plugins\npqtplugin5.dll
FF - plugin: c:\games\quick\plugins\npqtplugin6.dll
FF - plugin: c:\games\quick\plugins\npqtplugin7.dll
FF - plugin: c:\games\real\netscape6\nppl3260.dll
FF - plugin: c:\games\real\netscape6\nprjplug.dll
FF - plugin: c:\games\real\netscape6\nprpjplug.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: XULRunner: {048EA5A5-9571-46C1-998D-F27D44AB2B9B} - c:\documents and settings\daniel\local settings\application data\{048EA5A5-9571-46C1-998D-F27D44AB2B9B}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-1-6 165456]
R1 SASDIFSV;SASDIFSV;c:\games\spy\superantispyware\sasdifsv.sys [2008-12-4 8944]
R1 SASKUTIL;SASKUTIL;c:\games\spy\superantispyware\SASKUTIL.SYS [2008-12-4 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-6 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-25 40384]
R2 gpib420;GPIB Analyzer;c:\windows\system32\drivers\gpib420.sys [2006-2-13 31334]
R2 GpibPrtK;Gpib Port;c:\windows\system32\drivers\GpibPrtK.sys [2006-2-13 199783]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-7-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2006-7-4 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2006-7-4 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2006-7-4 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-7-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2006-7-4 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-7-20 200704]
R2 nidwgk;nidwgk;c:\windows\system32\drivers\nidwgk.dll [2006-7-10 979456]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-7-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-7-16 81920]
R2 nigplk;nigplk;c:\windows\system32\drivers\nigplk.dll [2006-2-15 101376]
R2 nihsdrk;nihsdrk;c:\windows\system32\drivers\nihsdrk.dll [2006-7-10 815616]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2006-7-4 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-7-16 20480]
R2 nipsdk;nipsdk;c:\windows\system32\drivers\nipsdk.dll [2006-7-10 246784]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-7-18 71680]
R2 nisldk;nisldk;c:\windows\system32\drivers\nisldk.dll [2006-7-10 395776]
R2 nisrcdk;nisrcdk;c:\windows\system32\drivers\nisrcdk.dll [2006-7-10 965632]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2006-7-4 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-7-16 496640]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-7-20 1746432]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-7-16 19968]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-25 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-25 40384]
R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2003-2-14 59328]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-7-16 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-7-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-7-16 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-7-16 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-7-16 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-7-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-7-16 790528]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-7-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-7-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-6-5 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-6-5 151683]
S3 nipalusb;NI-PAL USB Driver;c:\windows\system32\drivers\nipalusb.sys [2006-7-13 105472]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-7-16 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-7-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-7-16 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-7-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-6-6 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-7-16 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWK.sys [2006-7-14 8704]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciK.sys [2006-7-14 48128]
S3 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiK.sys [2006-7-14 10752]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-7-20 434688]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2005-8-2 42512]
S3 SASENUM;SASENUM;c:\games\spy\superantispyware\SASENUM.SYS [2008-12-4 7408]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]
============== File Associations ===============
.scr=AutoCADScriptFile
=============== Created Last 30 ================
2010-08-01 23:42:09 38848 ----a-w- c:\windows\avastSS.scr
2010-07-24 20:45:22 10559 ----a-w- c:\documents and settings\daniel\.recently-used.xbel
==================== Find3M ====================
2010-08-15 04:00:21 26048 ----a-w- c:\windows\system32\nvModes.dat
2010-07-27 06:30:35 8462336 ------w- c:\windows\system32\dllcache\shell32.dll
2010-07-17 09:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-30 12:31:35 149504 ------w- c:\windows\system32\dllcache\schannel.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-23 13:44:04 1851904 ------w- c:\windows\system32\dllcache\win32k.sys
2010-06-23 12:06:51 70656 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2010-06-23 12:06:51 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2010-06-21 15:27:11 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-21 15:27:11 354304 ------w- c:\windows\system32\dllcache\srv.sys
2010-06-18 13:36:12 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-06-17 15:12:57 634656 ------w- c:\windows\system32\dllcache\iexplore.exe
2010-06-17 15:11:25 161792 ------w- c:\windows\system32\dllcache\ieakui.dll
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31:20 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-14 07:41:45 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2006-07-19 21:17:00 88761 ----a-w- c:\windows\inf\pxiclean.exe
============= FINISH: 19:47:15.71 ===============
Hello,
I have a problem that I think is an infection but it may just be Google, I am not sure. When I search something in Google, and click a link to the result, I get sent to some non related page. When I click back then reclick the link, it takes me to the right page. This only happens rarely but I don't think it should happen at all. I just tried it and it happened once but I have tried various searches and clicked 20+ links and can't replicate it. I wanted to replicate it to get a screen shot as the address bar says something like google ads. I'm sure later when I am searching it will repeat the same thing as this is what it normally does. The first 1-3 links will be redirected then everything will be fine for the next day or two.
The following searches have come up clean, Spybot SD, Malwarebytes, Avast and boot scan with Avast.
Just google or infection?
Thanks for the help.
Edit: I searched again today and it took me to some weird site instead of the right one.
www"dot"infomash"dot"org /"some other stuff here"
In sticky says to post both logs, but the attach logs says not to post it unless requested. So here is just the DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Daniel at 19:46:43.77 on Mon 08/16/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1068 [GMT -4:00]
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Games\Spy\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\explorer.exe
C:\Games\Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SYSTEM32\mspaint.exe
C:\Documents and Settings\Daniel\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
BHO: {4314F235-1E09-4193-AAAE-042D73E41824} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\games\spy\spybot~1\SDHelper.dll
BHO: {A78FAF59-B270-4B28-A275-68A94333847F} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {F9C48591-50FA-4A03-BB63-5F3B832C8D88} - No File
uRun: [SpybotSD TeaTimer] c:\games\spy\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [kdx] c:\windows\kdx\KHost.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\games\quick\qttask.exe" -atboottime
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: E&xport to Microsoft Excel
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\games\spy\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136503940425
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} - hxxp://www.gamespot.com/KDX/zd/kdx.cab
Filter: text/html - {33d38737-6480-4192-b77e-139d94a90223} -
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\games\spy\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, mcenspc.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\daniel\applic~1\mozilla\firefox\profiles\tmsh95n6.default\
FF - plugin: c:\documents and settings\daniel\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\daniel\application data\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\documents and settings\daniel\application data\real\rhapsodyplayerengine\nprhapengine.dll
FF - plugin: c:\games\codec\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\games\codec\divx\divx web player\npdivx32.dll
FF - plugin: c:\games\firefox\plugins\npbittorrent.dll
FF - plugin: c:\games\firefox\plugins\npdeployJava1.dll
FF - plugin: c:\games\quick\plugins\npqtplugin.dll
FF - plugin: c:\games\quick\plugins\npqtplugin2.dll
FF - plugin: c:\games\quick\plugins\npqtplugin3.dll
FF - plugin: c:\games\quick\plugins\npqtplugin4.dll
FF - plugin: c:\games\quick\plugins\npqtplugin5.dll
FF - plugin: c:\games\quick\plugins\npqtplugin6.dll
FF - plugin: c:\games\quick\plugins\npqtplugin7.dll
FF - plugin: c:\games\real\netscape6\nppl3260.dll
FF - plugin: c:\games\real\netscape6\nprjplug.dll
FF - plugin: c:\games\real\netscape6\nprpjplug.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: XULRunner: {048EA5A5-9571-46C1-998D-F27D44AB2B9B} - c:\documents and settings\daniel\local settings\application data\{048EA5A5-9571-46C1-998D-F27D44AB2B9B}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-1-6 165456]
R1 SASDIFSV;SASDIFSV;c:\games\spy\superantispyware\sasdifsv.sys [2008-12-4 8944]
R1 SASKUTIL;SASKUTIL;c:\games\spy\superantispyware\SASKUTIL.SYS [2008-12-4 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-6 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-25 40384]
R2 gpib420;GPIB Analyzer;c:\windows\system32\drivers\gpib420.sys [2006-2-13 31334]
R2 GpibPrtK;Gpib Port;c:\windows\system32\drivers\GpibPrtK.sys [2006-2-13 199783]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-7-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2006-7-4 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2006-7-4 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2006-7-4 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-7-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2006-7-4 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-7-20 200704]
R2 nidwgk;nidwgk;c:\windows\system32\drivers\nidwgk.dll [2006-7-10 979456]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-7-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-7-16 81920]
R2 nigplk;nigplk;c:\windows\system32\drivers\nigplk.dll [2006-2-15 101376]
R2 nihsdrk;nihsdrk;c:\windows\system32\drivers\nihsdrk.dll [2006-7-10 815616]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2006-7-4 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-7-16 20480]
R2 nipsdk;nipsdk;c:\windows\system32\drivers\nipsdk.dll [2006-7-10 246784]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-7-18 71680]
R2 nisldk;nisldk;c:\windows\system32\drivers\nisldk.dll [2006-7-10 395776]
R2 nisrcdk;nisrcdk;c:\windows\system32\drivers\nisrcdk.dll [2006-7-10 965632]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2006-7-4 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-7-16 496640]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-7-20 1746432]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-7-16 19968]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-25 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-25 40384]
R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2003-2-14 59328]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-7-16 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-7-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-7-16 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-7-16 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-7-16 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-7-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-7-16 790528]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-7-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-7-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-6-5 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-6-5 151683]
S3 nipalusb;NI-PAL USB Driver;c:\windows\system32\drivers\nipalusb.sys [2006-7-13 105472]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-7-16 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-7-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-7-16 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-7-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-6-6 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-7-16 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWK.sys [2006-7-14 8704]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciK.sys [2006-7-14 48128]
S3 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiK.sys [2006-7-14 10752]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-7-20 434688]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2005-8-2 42512]
S3 SASENUM;SASENUM;c:\games\spy\superantispyware\SASENUM.SYS [2008-12-4 7408]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]
============== File Associations ===============
.scr=AutoCADScriptFile
=============== Created Last 30 ================
2010-08-01 23:42:09 38848 ----a-w- c:\windows\avastSS.scr
2010-07-24 20:45:22 10559 ----a-w- c:\documents and settings\daniel\.recently-used.xbel
==================== Find3M ====================
2010-08-15 04:00:21 26048 ----a-w- c:\windows\system32\nvModes.dat
2010-07-27 06:30:35 8462336 ------w- c:\windows\system32\dllcache\shell32.dll
2010-07-17 09:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-30 12:31:35 149504 ------w- c:\windows\system32\dllcache\schannel.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-23 13:44:04 1851904 ------w- c:\windows\system32\dllcache\win32k.sys
2010-06-23 12:06:51 70656 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2010-06-23 12:06:51 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2010-06-21 15:27:11 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-21 15:27:11 354304 ------w- c:\windows\system32\dllcache\srv.sys
2010-06-18 13:36:12 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-06-17 15:12:57 634656 ------w- c:\windows\system32\dllcache\iexplore.exe
2010-06-17 15:11:25 161792 ------w- c:\windows\system32\dllcache\ieakui.dll
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31:20 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-14 07:41:45 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2006-07-19 21:17:00 88761 ----a-w- c:\windows\inf\pxiclean.exe
============= FINISH: 19:47:15.71 ===============