Hello and thanks for bothering to read this,
My computer was (very) recently flooded with viruses. I managed to delete the one causing the blue screen of death after every five minutes of it running and after that proceeded to do two quick scans with Malwarebytes, on the second scan nothing was found, so I moved on to a full scan. Still nothing found, and I re-installed my free antivirus software (Avira Antivirus).
After that I thought I was out of the woods but I seem to have caught and kept a redirection virus.
Basically every now and then when I click a link after doing a search with google (or bing, or anything else) I get redirected to a relatively random website. After installing the newest versions of Internet Explorer and Firefox I noticed it doesn't go through with redirecting me, instead it stays a blank page and I can find "http://www.goingonearth.com/search.php?q=[Myqueryhere]"
EDIT: I'm replacing both files as I've read a couple other forum posts and realized that I ought to get rid of P2P programs, nothing else should be different though I'm saving the old ones to a .txt just in case.
Oh, and Avira meanwhile caught a...uhm..."TR/DROPPER.Gen Trojan" which is now in quarantine. Don't know if that would help. Anyways, here are the files.
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
Run by [removed] at 20:02:16 on 2011-08-12
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2047.845 [GMT 2:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
Run by [removed] at 11:18:55 on 2011-08-13
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2047.1049 [GMT 2:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\TEMP\vbsqrj\setup.exe
C:\Windows\eHome\EhTray.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
uURLSearchHooks: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\prxtbDVDV.dll
uURLSearchHooks: H - No File
mURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
mURLSearchHooks: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\prxtbDVDV.dll
mURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\users\zoe\appdata\roaming\appconf32.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\prxtbDVDV.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\prxtbDVDV.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
TB: {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - No File
EB: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
uRun: [EADM] "c:\program files\electronic arts\eadm\EADMUI.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [AdobeBridge]
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [DivX Download Manager] "c:\program files\divx\divx plus web player\DDmService.exe" start
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [Adobe_ID0ENQBO] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\users\zoe\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\users\zoe\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: An vorhandene PDF-Datei anfügen - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Free YouTube to iPod Converter - c:\users\zoe\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetoipodconverter.htm
IE: Free YouTube to MP3 Converter - c:\users\zoe\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: In Adobe PDF konvertieren - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\icq7.4\ICQ.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: Interfaces\{F1A27822-154A-4D21-B718-C2E49DC76360} : NameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=gr ... =616163&p=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
FF - component: c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCoreGecko19.dll
FF - component: c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}\components\RadioWMPCoreGecko19.dll
FF - component: c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension3.dll
FF - component: c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
.
============= SERVICES / DRIVERS ===============
.
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-1-5 176128]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2011-1-4 284672]
R2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ati technologies\ati.ace\reservation manager\AMD Reservation Manager.exe [2010-6-17 140224]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-8-12 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-8-12 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-8-12 66616]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-4-17 21992]
R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2010-2-28 821664]
R2 ICQ Service;ICQ Service;c:\program files\icq6toolbar\ICQ Service.exe [2011-2-2 247096]
R2 sftlist;Application Virtualization Client;c:\program files\microsoft application virtualization client\sftlist.exe [2010-4-24 483688]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2011-2-1 37944]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-1-5 6789120]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-1-5 235520]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2010-11-17 101392]
R3 CompFilter;UVCCompositeFilter;c:\windows\system32\drivers\lvbusflt.sys [2010-11-10 20704]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-4-24 550760]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-4-24 195944]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-4-24 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-4-24 19304]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2010-4-24 209768]
S2 AMService;AMService;c:\windows\temp\vbsqrj\setup.exe run --> c:\windows\temp\vbsqrj\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-1 135664]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\bitcomet\tools\bitcometservice.exe -service --> c:\program files\bitcomet\tools\BitCometService.exe -service [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-1 135664]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-8-12 22712]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S4 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-8-12 366640]
.
=============== Created Last 30 ================
.
2011-08-13 01:53:37 -------- d-----w- C:\xmldm
2011-08-13 01:53:37 -------- d-----w- C:\kock
2011-08-12 23:06:30 211920 ----a-w- c:\users\zoe\appdata\roaming\AcroIEHelpe.dll
2011-08-12 23:06:14 -------- d-----w- c:\users\zoe\appdata\roaming\5021
2011-08-12 23:06:02 112 ----a-w- c:\users\zoe\appdata\roaming\srvblck2.tmp
2011-08-12 23:05:59 -------- d-----w- c:\users\zoe\appdata\roaming\UAs
2011-08-12 23:05:56 -------- d-----w- c:\users\zoe\appdata\roaming\xmldm
2011-08-12 23:05:56 -------- d-----w- c:\users\zoe\appdata\roaming\kock
2011-08-12 22:00:19 -------- d-----w- c:\users\zoe\appdata\local\{D0FDE71E-F17B-4E93-8D3A-692D862102E0}
2011-08-12 22:00:07 -------- d-----w- c:\users\zoe\appdata\local\{838A7887-7C37-4EC3-973E-C569C9B68A14}
2011-08-12 16:45:46 388096 ----a-r- c:\users\zoe\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-08-12 16:45:46 -------- d-----w- c:\program files\HighjackThis
2011-08-12 16:16:05 -------- d-----w- c:\users\zoe\appdata\roaming\Avira
2011-08-12 16:14:47 -------- d-----w- c:\programdata\Kaspersky Lab
2011-08-12 16:09:24 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-12 16:09:24 -------- d-----w- c:\programdata\Avira
2011-08-12 16:09:24 -------- d-----w- c:\program files\Avira
2011-08-12 16:05:09 -------- d-----w- C:\!KillBox
2011-08-12 16:01:35 -------- d-----w- c:\program files\CCleaner
2011-08-12 14:15:05 -------- d-----w- c:\windows\system32\appmgmt
2011-08-12 09:59:37 -------- d-----w- c:\users\zoe\appdata\local\{F7527933-EA43-4E1D-A1D8-750CFC65D73B}
2011-08-12 09:59:25 -------- d-----w- c:\users\zoe\appdata\local\{A54E48CC-9131-4667-AA2A-6D27B6592C0F}
2011-08-12 09:07:16 -------- d-----w- c:\users\zoe\appdata\roaming\Malwarebytes
2011-08-12 09:07:07 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-12 09:07:07 -------- d-----w- c:\programdata\Malwarebytes
2011-08-12 09:07:03 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-12 09:07:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-12 08:41:18 0 ----a-w- c:\users\zoe\appdata\local\Tzufoxegiri.bin
2011-08-12 08:41:15 -------- d-----w- c:\users\zoe\appdata\local\{CA836C4E-F418-4389-959F-DB48B24638C3}
2011-08-12 08:39:40 65536 --sha-r- c:\windows\system32\unimdmu.dll
2011-08-12 08:39:40 65536 --sha-r- c:\windows\system32\netutilsg.dll
2011-08-12 08:39:39 65536 --sha-r- c:\windows\system32\avifilev.dll
2011-08-11 22:02:51 6881616 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{bca4fb95-a0ea-479a-8590-67cbb6462c0c}\mpengine.dll
2011-08-11 21:58:52 -------- d-----w- c:\users\zoe\appdata\local\{EF3FD35F-E8AA-49CD-9F95-96C9E2131F13}
2011-08-11 21:57:19 -------- d-----w- c:\users\zoe\appdata\local\{BFEF1610-C05A-419E-B3CE-1EA2192BB68D}
2011-08-10 21:18:38 -------- d-----w- c:\users\zoe\appdata\local\{18BFDD37-775A-415D-B518-41905519CF6B}
2011-08-10 21:18:27 -------- d-----w- c:\users\zoe\appdata\local\{2DF35316-4233-4520-AC37-63E980DA2369}
2011-08-10 09:18:01 -------- d-----w- c:\users\zoe\appdata\local\{DE9CE08F-E292-41CA-BB34-62B4909D0D66}
2011-08-10 09:17:49 -------- d-----w- c:\users\zoe\appdata\local\{356568C4-2BC5-4F3F-ABED-B011AB1F4EA8}
2011-08-09 12:15:04 -------- d-----w- c:\users\zoe\appdata\local\{01A4559B-DE5E-4BA3-AAC8-6B724CAA0BF8}
2011-08-09 12:14:52 -------- d-----w- c:\users\zoe\appdata\local\{1979C396-32BF-4B22-ADB6-67A020204D13}
2011-08-09 00:14:21 -------- d-----w- c:\users\zoe\appdata\local\{56834C27-0ABD-4971-9575-81CC47587D39}
2011-08-09 00:12:54 -------- d-----w- c:\users\zoe\appdata\local\{65329A6D-D549-4C35-A6D9-F3E57D5522D2}
2011-08-05 10:16:26 -------- d-----w- c:\users\zoe\appdata\local\{1FB02B90-0164-4554-A73D-6AE05FB209BD}
2011-08-05 10:16:15 -------- d-----w- c:\users\zoe\appdata\local\{FA963413-E2D8-4B66-8846-C7E26BB85FE1}
2011-08-05 08:48:41 -------- d-----w- c:\programdata\Media Center Programs
2011-08-04 22:15:47 -------- d-----w- c:\users\zoe\appdata\local\{5E55A6E5-8880-48C8-8A75-97C050EBB2C5}
2011-08-04 10:15:20 -------- d-----w- c:\users\zoe\appdata\local\{86F1C275-61EF-4447-98F5-AC6738F99585}
2011-08-03 22:14:51 -------- d-----w- c:\users\zoe\appdata\local\{15B469A3-F451-41D2-B57C-B224BB29AF12}
2011-08-03 22:14:39 -------- d-----w- c:\users\zoe\appdata\local\{FCD7B2D2-6102-49E2-87C0-21AFCF0F9B98}
2011-08-03 10:13:52 -------- d-----w- c:\users\zoe\appdata\local\{8E0688BA-D3E7-402E-AF71-F8081F25781D}
2011-08-02 22:12:10 -------- d-----w- c:\users\zoe\appdata\local\{B1AF41D6-4E05-4ADF-8AB0-C6350DFA07D4}
2011-08-01 20:16:32 -------- d-----w- c:\users\zoe\appdata\local\{58523C80-D950-4F51-9F66-7F4F7E712F42}
2011-08-01 16:45:03 -------- d-----w- c:\users\zoe\appdata\roaming\WB Games
2011-08-01 15:43:20 -------- d-----w- c:\program files\WB Games
2011-08-01 08:16:07 -------- d-----w- c:\users\zoe\appdata\local\{05EECF92-55D1-4E54-AEFA-46059EAC2585}
2011-07-31 20:15:42 -------- d-----w- c:\users\zoe\appdata\local\{C8448456-5E24-413C-A567-21014ECCD874}
2011-07-30 14:54:32 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-07-30 14:54:32 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-07-30 14:54:32 225280 ------w- c:\program files\common files\installshield\iscript\IScript.dll
2011-07-30 14:54:32 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2011-07-30 14:54:32 176128 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-07-30 08:14:54 -------- d-----w- c:\users\zoe\appdata\local\{D97D916A-53F2-4893-8E8E-612049C0A303}
2011-07-29 20:14:30 -------- d-----w- c:\users\zoe\appdata\local\{CCB7E820-643C-42A4-AE14-EA4A78EBB17B}
2011-07-29 08:12:42 -------- d-----w- c:\users\zoe\appdata\local\{104EF150-E5FF-482D-B241-494165759062}
2011-07-28 11:09:37 7552 ----a-w- c:\windows\system32\drivers\enodpl.sys
2011-07-28 11:09:37 6659 ----a-w- c:\windows\system32\TANDPL.VXD
2011-07-28 11:09:37 6532 ----a-w- c:\windows\system32\ENODPL.VXD
2011-07-28 11:09:37 4736 ----a-w- c:\windows\system32\drivers\tandpl.sys
2011-07-28 11:06:27 692224 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll
2011-07-28 11:06:27 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2011-07-28 11:06:27 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2011-07-28 11:06:27 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2011-07-28 11:06:27 155648 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2011-07-28 11:06:20 163972 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll
2011-07-28 11:06:19 282756 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll
2011-07-27 08:58:36 -------- d-----w- c:\users\zoe\appdata\local\{EC169B0B-B9C9-4833-8AA0-882B24F7D11B}
2011-07-26 11:11:47 -------- d-----w- c:\program files\SQUARE ENIX - Eidos Interactive
2011-07-26 07:56:46 -------- d-----w- c:\users\zoe\appdata\local\{E98E9CD3-ACFD-4686-82D1-EE28D3A52540}
2011-07-25 17:34:24 -------- d-----w- c:\program files\Activision
2011-07-25 17:32:10 -------- d-sh--w- c:\windows\ftpcache
2011-07-25 10:34:20 -------- d-----w- c:\users\zoe\appdata\local\{A0133E41-DA00-46C0-A52C-1E14D8C2F1B7}
2011-07-24 19:30:16 -------- d-----w- c:\users\zoe\appdata\local\{434804DF-6580-45AE-B40B-0702B2EC2257}
2011-07-24 06:22:22 -------- d-----w- c:\users\zoe\appdata\local\{367CB68F-395C-45B2-B9A7-81E34CCA7DE3}
2011-07-23 10:25:22 -------- d-----w- c:\program files\KONAMI
2011-07-23 02:39:35 -------- d-----w- c:\users\zoe\appdata\local\{96ECE04B-9CB0-4D6E-BDED-B00DC3628211}
2011-07-22 14:39:10 -------- d-----w- c:\users\zoe\appdata\local\{DEC66BFD-0A12-4D44-B6E2-1707C2CE8866}
2011-07-21 14:37:07 -------- d-----w- c:\users\zoe\appdata\local\{F0402290-8AAF-4EE3-B1EC-98C97BEB9046}
2011-07-21 14:29:01 -------- d-----w- c:\windows\en
2011-07-21 14:28:36 -------- d-----w- c:\windows\de
2011-07-21 14:27:54 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-07-21 14:25:44 18328 ----a-w- c:\programdata\microsoft\identitycrl\production\ppcrlconfig600.dll
2011-07-21 14:22:51 2983424 ----a-w- c:\windows\system32\UIRibbon.dll
2011-07-21 14:22:51 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-07-21 14:22:04 94040 ----a-w- c:\program files\common files\windows live\.cache\8ffd5d061cc47b105\DSETUP.dll
2011-07-21 14:22:04 525656 ----a-w- c:\program files\common files\windows live\.cache\8ffd5d061cc47b105\DXSETUP.exe
2011-07-21 14:22:04 1691480 ----a-w- c:\program files\common files\windows live\.cache\8ffd5d061cc47b105\dsetup32.dll
2011-07-21 14:21:59 94040 ----a-w- c:\program files\common files\windows live\.cache\8c7959391cc47b104\DSETUP.dll
2011-07-21 14:21:59 525656 ----a-w- c:\program files\common files\windows live\.cache\8c7959391cc47b104\DXSETUP.exe
2011-07-21 14:21:59 1691480 ----a-w- c:\program files\common files\windows live\.cache\8c7959391cc47b104\dsetup32.dll
2011-07-21 14:19:46 -------- d-----w- c:\users\zoe\appdata\local\{E6B97B04-6F2E-4983-BAC1-0D250047934A}
2011-07-20 21:52:09 -------- d-----w- c:\users\zoe\appdata\local\{CA9A386F-B4A9-47B5-A723-07C0622FDB0B}
2011-07-19 15:03:58 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2011-07-19 08:59:12 -------- d-----w- c:\users\zoe\appdata\local\Criterion Games
2011-07-19 08:57:18 11848 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2011-07-19 08:56:58 -------- d-----w- c:\users\zoe\appdata\local\Downloaded Installations
2011-07-19 07:40:03 -------- d-----w- c:\program files\Team17
2011-07-18 09:18:44 -------- d-----w- c:\users\zoe\appdata\local\{8874EA0C-A7B7-4522-8A4A-9AE2EB436410}
2011-07-17 20:31:05 -------- d-----w- c:\users\zoe\appdata\local\{8886B1B2-EF9A-4B2A-916F-0897A2621A5E}
2011-07-16 19:58:59 -------- d-----w- c:\users\zoe\appdata\local\{E5AD17D5-FBF7-4538-A175-CA00DF58FFAF}
2011-07-15 22:57:14 -------- d-----w- c:\users\zoe\appdata\local\{ED3B9CF7-F615-48FF-BF97-27853FCCE16E}
2011-07-15 10:56:49 -------- d-----w- c:\users\zoe\appdata\local\{1ECBA6FF-7862-4629-96EA-559E9EA2E153}
2011-07-14 22:56:25 -------- d-----w- c:\users\zoe\appdata\local\{E3CCAF43-FF36-4161-A23C-180AF6D74E48}
2011-07-14 20:47:46 -------- d-----w- C:\Downloads
2011-07-14 10:54:43 -------- d-----w- c:\users\zoe\appdata\local\{266CEF0F-2C1E-4035-8048-E7CE2A39659C}
.
==================== Find3M ====================
.
2011-07-16 04:37:32 169984 ----a-w- c:\windows\system32\winsrv.dll
2011-07-16 04:34:28 290816 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-16 04:31:12 271360 ----a-w- c:\windows\system32\conhost.exe
2011-07-16 02:21:47 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:21:47 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:21:47 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:21:47 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-09 02:26:10 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-07 12:19:11 21219639 ----a-w- C:\windows.7.codec.pack.v3.1.0.setup.exe
2011-07-07 11:09:20 1582304 ----a-w- C:\rcsetup140_slim.exe
2011-07-07 11:05:32 642712 ----a-w- C:\gfwlivesetup.exe
2011-06-23 04:38:05 3957120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-23 04:38:04 3902336 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-06-21 05:39:53 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-15 09:04:46 86016 ----a-w- c:\windows\system32\odbccu32.dll
2011-06-15 09:04:46 81920 ----a-w- c:\windows\system32\odbccr32.dll
2011-06-15 09:04:46 319488 ----a-w- c:\windows\system32\odbcjt32.dll
2011-06-15 09:04:46 163840 ----a-w- c:\windows\system32\odbctrac.dll
2011-06-15 09:04:46 122880 ----a-w- c:\windows\system32\odbccp32.dll
2011-06-11 02:37:19 2332672 ----a-w- c:\windows\system32\win32k.sys
2011-05-24 17:14:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 10:35:34 294912 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-22 13:28:50 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-05-22 13:28:48 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-04-16 14:26:25 925184 ----a-w- c:\program files\AppWorldInstaller-de.msi
2011-04-08 13:43:48 168166968 ----a-w- c:\program files\OOo_3.3.0_Win_x86_install-wJRE_de.exe
.
============= FINISH: 11:19:44.81 ===============
Attach file:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 1/31/2011 11:09:17 PM
System Uptime: 8/12/2011 8:52:56 PM (15 hours ago)
.
Motherboard: MICRO-STAR INTERNATIONAL CO.,LTD | | MS-7388
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ | CPU 1 | 2600/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 233 GiB total, 55.238 GiB free.
D: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP184: 8/10/2011 2:27:13 PM - Removed XIII
RP185: 8/12/2011 12:02:03 AM - Windows Update
RP186: 8/12/2011 3:00:11 AM - Windows Update
.
==== Installed Programs ======================
.
Acrobat.com
Adobe Acrobat 9 Pro - English, Français, Deutsch
Adobe AIR
Adobe Anchor Service CS4
Adobe Asset Services CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Recommended Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Extra Settings CS4
Adobe Color Video Profiles CS CS4
Adobe Creative Suite 4 Design Standard
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Illustrator CS4
Adobe InDesign CS4
Adobe InDesign CS4 Application Feature Set Files (Roman)
Adobe InDesign CS4 Common Base Files
Adobe InDesign CS4 Icon Handler
Adobe Linguistics CS4
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader X - Deutsch
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe SGM CS4
Adobe SING CS4
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe Version Cue CS4 Server
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
AMD Drag and Drop Transcoding
AMD Fuel
ANNO 1404
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ashampoo Burning Studio Elements 10.0.9
ATI Catalyst Install Manager
ATI Catalyst Registration
ATI Stream SDK v2 Developer
Avira AntiVir Personal - Free Antivirus
Bandisoft MPEG-1 Decoder
BlackBerry Desktop Software 5.0.1
BlackBerry® Media Sync
Bonjour
Burnout(TM) Paradise The Ultimate Box
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
ccc-core-static
ccc-utility
CCC Help English
CCleaner
CDisplayEx 1.8
Conduit Engine
Connect
CPUID CPU-Z 1.57.1
D3DX10
Dead Space™ 2
Die Sims™ 3
Die Sims™ 3 Erstelle einen Sim
DivX-Setup
Dragon Age II
DVDVideoSoftTB Toolbar
EA Download Manager
Fallout 3
Free Audio CD Burner version 1.4.7
Free YouTube to iPod Converter version 3.9.32.324
Free YouTube to MP3 Converter version 3.9.35.324
Google Chrome
Google Update Helper
Harry Potter II
HiJackThis
ICQ Toolbar
ICQ7.4
iTunes
Java Auto Updater
Java(TM) 6 Update 22
Just Cause 2
kuler
LEGO® Harry Potter™: Years 1-4
Malwarebytes' Anti-Malware version 1.51.1.1800
McAfee Security Scan Plus
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office Home and Student 2010 - Deutsch
Microsoft Office Klick-und-Los 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft WSE 3.0 Runtime
Mozilla Firefox 5.0.1 (x86 en-US)
Mozilla Thunderbird (3.1.11)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nexon Game Manager
OpenOffice.org 3.3
Paint.NET v3.5.8
Pando Media Booster
PDF Settings CS4
Photoshop Camera Raw
Prototype(TM)
QuickTime
Roxio Media Manager
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Skype Toolbars
Skype™ 5.3
SPORE™
SPORE™ Galaktische Abenteuer
Suite Shared Configuration CS4
The Lord of the Rings FREE Trial
The Sims™ 3 Ambitions
The Sims™ 3 Fast Lane Stuff
The Sims™ 3 Generations
The Sims™ 3 High-End Loft Stuff
The Sims™ 3 Late Night
The Sims™ 3 Outdoor Living Stuff
The Sims™ 3 World Adventures
Tom Clancy's H.A.W.X
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.1.6
Windows 7 Codec Pack 3.1.0
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalerie
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinRAR
WMV9/VC-1 Video Playback
Worms Reloaded
Yu-Gi-Oh! Power of Chaos JOEY THE PASSION
Yu-Gi-Oh! Power of Chaos KAIBA THE REVENGE
Yu-Gi-Oh! Power of Chaos YUGI THE DESTINY
.
==== End Of File ===========================
My computer was (very) recently flooded with viruses. I managed to delete the one causing the blue screen of death after every five minutes of it running and after that proceeded to do two quick scans with Malwarebytes, on the second scan nothing was found, so I moved on to a full scan. Still nothing found, and I re-installed my free antivirus software (Avira Antivirus).
After that I thought I was out of the woods but I seem to have caught and kept a redirection virus.
Basically every now and then when I click a link after doing a search with google (or bing, or anything else) I get redirected to a relatively random website. After installing the newest versions of Internet Explorer and Firefox I noticed it doesn't go through with redirecting me, instead it stays a blank page and I can find "http://www.goingonearth.com/search.php?q=[Myqueryhere]"
EDIT: I'm replacing both files as I've read a couple other forum posts and realized that I ought to get rid of P2P programs, nothing else should be different though I'm saving the old ones to a .txt just in case.
Oh, and Avira meanwhile caught a...uhm..."TR/DROPPER.Gen Trojan" which is now in quarantine. Don't know if that would help. Anyways, here are the files.
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
Run by [removed] at 20:02:16 on 2011-08-12
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2047.845 [GMT 2:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22
Run by [removed] at 11:18:55 on 2011-08-13
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2047.1049 [GMT 2:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\TEMP\vbsqrj\setup.exe
C:\Windows\eHome\EhTray.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
uURLSearchHooks: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\prxtbDVDV.dll
uURLSearchHooks: H - No File
mURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
mURLSearchHooks: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\prxtbDVDV.dll
mURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\users\zoe\appdata\roaming\appconf32.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\prxtbDVDV.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\prxtbDVDV.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
TB: {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - No File
EB: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
uRun: [EADM] "c:\program files\electronic arts\eadm\EADMUI.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [AdobeBridge]
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [DivX Download Manager] "c:\program files\divx\divx plus web player\DDmService.exe" start
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [Adobe_ID0ENQBO] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\users\zoe\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\users\zoe\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: An vorhandene PDF-Datei anfügen - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Free YouTube to iPod Converter - c:\users\zoe\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetoipodconverter.htm
IE: Free YouTube to MP3 Converter - c:\users\zoe\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: In Adobe PDF konvertieren - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\icq7.4\ICQ.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: Interfaces\{F1A27822-154A-4D21-B718-C2E49DC76360} : NameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: keyword.URL - hxxp://de.search.yahoo.com/search?fr=gr ... =616163&p=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
FF - component: c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCoreGecko19.dll
FF - component: c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}\components\RadioWMPCoreGecko19.dll
FF - component: c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension3.dll
FF - component: c:\users\zoe\appdata\roaming\mozilla\firefox\profiles\gr2jcjly.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
.
============= SERVICES / DRIVERS ===============
.
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-1-5 176128]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2011-1-4 284672]
R2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ati technologies\ati.ace\reservation manager\AMD Reservation Manager.exe [2010-6-17 140224]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-8-12 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-8-12 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-8-12 66616]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-4-17 21992]
R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2010-2-28 821664]
R2 ICQ Service;ICQ Service;c:\program files\icq6toolbar\ICQ Service.exe [2011-2-2 247096]
R2 sftlist;Application Virtualization Client;c:\program files\microsoft application virtualization client\sftlist.exe [2010-4-24 483688]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2011-2-1 37944]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-1-5 6789120]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-1-5 235520]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2010-11-17 101392]
R3 CompFilter;UVCCompositeFilter;c:\windows\system32\drivers\lvbusflt.sys [2010-11-10 20704]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-4-24 550760]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-4-24 195944]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-4-24 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-4-24 19304]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2010-4-24 209768]
S2 AMService;AMService;c:\windows\temp\vbsqrj\setup.exe run --> c:\windows\temp\vbsqrj\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-1 135664]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\program files\bitcomet\tools\bitcometservice.exe -service --> c:\program files\bitcomet\tools\BitCometService.exe -service [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-1 135664]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-8-12 22712]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S4 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-8-12 366640]
.
=============== Created Last 30 ================
.
2011-08-13 01:53:37 -------- d-----w- C:\xmldm
2011-08-13 01:53:37 -------- d-----w- C:\kock
2011-08-12 23:06:30 211920 ----a-w- c:\users\zoe\appdata\roaming\AcroIEHelpe.dll
2011-08-12 23:06:14 -------- d-----w- c:\users\zoe\appdata\roaming\5021
2011-08-12 23:06:02 112 ----a-w- c:\users\zoe\appdata\roaming\srvblck2.tmp
2011-08-12 23:05:59 -------- d-----w- c:\users\zoe\appdata\roaming\UAs
2011-08-12 23:05:56 -------- d-----w- c:\users\zoe\appdata\roaming\xmldm
2011-08-12 23:05:56 -------- d-----w- c:\users\zoe\appdata\roaming\kock
2011-08-12 22:00:19 -------- d-----w- c:\users\zoe\appdata\local\{D0FDE71E-F17B-4E93-8D3A-692D862102E0}
2011-08-12 22:00:07 -------- d-----w- c:\users\zoe\appdata\local\{838A7887-7C37-4EC3-973E-C569C9B68A14}
2011-08-12 16:45:46 388096 ----a-r- c:\users\zoe\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-08-12 16:45:46 -------- d-----w- c:\program files\HighjackThis
2011-08-12 16:16:05 -------- d-----w- c:\users\zoe\appdata\roaming\Avira
2011-08-12 16:14:47 -------- d-----w- c:\programdata\Kaspersky Lab
2011-08-12 16:09:24 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-12 16:09:24 -------- d-----w- c:\programdata\Avira
2011-08-12 16:09:24 -------- d-----w- c:\program files\Avira
2011-08-12 16:05:09 -------- d-----w- C:\!KillBox
2011-08-12 16:01:35 -------- d-----w- c:\program files\CCleaner
2011-08-12 14:15:05 -------- d-----w- c:\windows\system32\appmgmt
2011-08-12 09:59:37 -------- d-----w- c:\users\zoe\appdata\local\{F7527933-EA43-4E1D-A1D8-750CFC65D73B}
2011-08-12 09:59:25 -------- d-----w- c:\users\zoe\appdata\local\{A54E48CC-9131-4667-AA2A-6D27B6592C0F}
2011-08-12 09:07:16 -------- d-----w- c:\users\zoe\appdata\roaming\Malwarebytes
2011-08-12 09:07:07 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-12 09:07:07 -------- d-----w- c:\programdata\Malwarebytes
2011-08-12 09:07:03 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-12 09:07:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-12 08:41:18 0 ----a-w- c:\users\zoe\appdata\local\Tzufoxegiri.bin
2011-08-12 08:41:15 -------- d-----w- c:\users\zoe\appdata\local\{CA836C4E-F418-4389-959F-DB48B24638C3}
2011-08-12 08:39:40 65536 --sha-r- c:\windows\system32\unimdmu.dll
2011-08-12 08:39:40 65536 --sha-r- c:\windows\system32\netutilsg.dll
2011-08-12 08:39:39 65536 --sha-r- c:\windows\system32\avifilev.dll
2011-08-11 22:02:51 6881616 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{bca4fb95-a0ea-479a-8590-67cbb6462c0c}\mpengine.dll
2011-08-11 21:58:52 -------- d-----w- c:\users\zoe\appdata\local\{EF3FD35F-E8AA-49CD-9F95-96C9E2131F13}
2011-08-11 21:57:19 -------- d-----w- c:\users\zoe\appdata\local\{BFEF1610-C05A-419E-B3CE-1EA2192BB68D}
2011-08-10 21:18:38 -------- d-----w- c:\users\zoe\appdata\local\{18BFDD37-775A-415D-B518-41905519CF6B}
2011-08-10 21:18:27 -------- d-----w- c:\users\zoe\appdata\local\{2DF35316-4233-4520-AC37-63E980DA2369}
2011-08-10 09:18:01 -------- d-----w- c:\users\zoe\appdata\local\{DE9CE08F-E292-41CA-BB34-62B4909D0D66}
2011-08-10 09:17:49 -------- d-----w- c:\users\zoe\appdata\local\{356568C4-2BC5-4F3F-ABED-B011AB1F4EA8}
2011-08-09 12:15:04 -------- d-----w- c:\users\zoe\appdata\local\{01A4559B-DE5E-4BA3-AAC8-6B724CAA0BF8}
2011-08-09 12:14:52 -------- d-----w- c:\users\zoe\appdata\local\{1979C396-32BF-4B22-ADB6-67A020204D13}
2011-08-09 00:14:21 -------- d-----w- c:\users\zoe\appdata\local\{56834C27-0ABD-4971-9575-81CC47587D39}
2011-08-09 00:12:54 -------- d-----w- c:\users\zoe\appdata\local\{65329A6D-D549-4C35-A6D9-F3E57D5522D2}
2011-08-05 10:16:26 -------- d-----w- c:\users\zoe\appdata\local\{1FB02B90-0164-4554-A73D-6AE05FB209BD}
2011-08-05 10:16:15 -------- d-----w- c:\users\zoe\appdata\local\{FA963413-E2D8-4B66-8846-C7E26BB85FE1}
2011-08-05 08:48:41 -------- d-----w- c:\programdata\Media Center Programs
2011-08-04 22:15:47 -------- d-----w- c:\users\zoe\appdata\local\{5E55A6E5-8880-48C8-8A75-97C050EBB2C5}
2011-08-04 10:15:20 -------- d-----w- c:\users\zoe\appdata\local\{86F1C275-61EF-4447-98F5-AC6738F99585}
2011-08-03 22:14:51 -------- d-----w- c:\users\zoe\appdata\local\{15B469A3-F451-41D2-B57C-B224BB29AF12}
2011-08-03 22:14:39 -------- d-----w- c:\users\zoe\appdata\local\{FCD7B2D2-6102-49E2-87C0-21AFCF0F9B98}
2011-08-03 10:13:52 -------- d-----w- c:\users\zoe\appdata\local\{8E0688BA-D3E7-402E-AF71-F8081F25781D}
2011-08-02 22:12:10 -------- d-----w- c:\users\zoe\appdata\local\{B1AF41D6-4E05-4ADF-8AB0-C6350DFA07D4}
2011-08-01 20:16:32 -------- d-----w- c:\users\zoe\appdata\local\{58523C80-D950-4F51-9F66-7F4F7E712F42}
2011-08-01 16:45:03 -------- d-----w- c:\users\zoe\appdata\roaming\WB Games
2011-08-01 15:43:20 -------- d-----w- c:\program files\WB Games
2011-08-01 08:16:07 -------- d-----w- c:\users\zoe\appdata\local\{05EECF92-55D1-4E54-AEFA-46059EAC2585}
2011-07-31 20:15:42 -------- d-----w- c:\users\zoe\appdata\local\{C8448456-5E24-413C-A567-21014ECCD874}
2011-07-30 14:54:32 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-07-30 14:54:32 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-07-30 14:54:32 225280 ------w- c:\program files\common files\installshield\iscript\IScript.dll
2011-07-30 14:54:32 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2011-07-30 14:54:32 176128 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-07-30 08:14:54 -------- d-----w- c:\users\zoe\appdata\local\{D97D916A-53F2-4893-8E8E-612049C0A303}
2011-07-29 20:14:30 -------- d-----w- c:\users\zoe\appdata\local\{CCB7E820-643C-42A4-AE14-EA4A78EBB17B}
2011-07-29 08:12:42 -------- d-----w- c:\users\zoe\appdata\local\{104EF150-E5FF-482D-B241-494165759062}
2011-07-28 11:09:37 7552 ----a-w- c:\windows\system32\drivers\enodpl.sys
2011-07-28 11:09:37 6659 ----a-w- c:\windows\system32\TANDPL.VXD
2011-07-28 11:09:37 6532 ----a-w- c:\windows\system32\ENODPL.VXD
2011-07-28 11:09:37 4736 ----a-w- c:\windows\system32\drivers\tandpl.sys
2011-07-28 11:06:27 692224 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll
2011-07-28 11:06:27 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2011-07-28 11:06:27 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2011-07-28 11:06:27 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2011-07-28 11:06:27 155648 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2011-07-28 11:06:20 163972 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll
2011-07-28 11:06:19 282756 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll
2011-07-27 08:58:36 -------- d-----w- c:\users\zoe\appdata\local\{EC169B0B-B9C9-4833-8AA0-882B24F7D11B}
2011-07-26 11:11:47 -------- d-----w- c:\program files\SQUARE ENIX - Eidos Interactive
2011-07-26 07:56:46 -------- d-----w- c:\users\zoe\appdata\local\{E98E9CD3-ACFD-4686-82D1-EE28D3A52540}
2011-07-25 17:34:24 -------- d-----w- c:\program files\Activision
2011-07-25 17:32:10 -------- d-sh--w- c:\windows\ftpcache
2011-07-25 10:34:20 -------- d-----w- c:\users\zoe\appdata\local\{A0133E41-DA00-46C0-A52C-1E14D8C2F1B7}
2011-07-24 19:30:16 -------- d-----w- c:\users\zoe\appdata\local\{434804DF-6580-45AE-B40B-0702B2EC2257}
2011-07-24 06:22:22 -------- d-----w- c:\users\zoe\appdata\local\{367CB68F-395C-45B2-B9A7-81E34CCA7DE3}
2011-07-23 10:25:22 -------- d-----w- c:\program files\KONAMI
2011-07-23 02:39:35 -------- d-----w- c:\users\zoe\appdata\local\{96ECE04B-9CB0-4D6E-BDED-B00DC3628211}
2011-07-22 14:39:10 -------- d-----w- c:\users\zoe\appdata\local\{DEC66BFD-0A12-4D44-B6E2-1707C2CE8866}
2011-07-21 14:37:07 -------- d-----w- c:\users\zoe\appdata\local\{F0402290-8AAF-4EE3-B1EC-98C97BEB9046}
2011-07-21 14:29:01 -------- d-----w- c:\windows\en
2011-07-21 14:28:36 -------- d-----w- c:\windows\de
2011-07-21 14:27:54 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-07-21 14:25:44 18328 ----a-w- c:\programdata\microsoft\identitycrl\production\ppcrlconfig600.dll
2011-07-21 14:22:51 2983424 ----a-w- c:\windows\system32\UIRibbon.dll
2011-07-21 14:22:51 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-07-21 14:22:04 94040 ----a-w- c:\program files\common files\windows live\.cache\8ffd5d061cc47b105\DSETUP.dll
2011-07-21 14:22:04 525656 ----a-w- c:\program files\common files\windows live\.cache\8ffd5d061cc47b105\DXSETUP.exe
2011-07-21 14:22:04 1691480 ----a-w- c:\program files\common files\windows live\.cache\8ffd5d061cc47b105\dsetup32.dll
2011-07-21 14:21:59 94040 ----a-w- c:\program files\common files\windows live\.cache\8c7959391cc47b104\DSETUP.dll
2011-07-21 14:21:59 525656 ----a-w- c:\program files\common files\windows live\.cache\8c7959391cc47b104\DXSETUP.exe
2011-07-21 14:21:59 1691480 ----a-w- c:\program files\common files\windows live\.cache\8c7959391cc47b104\dsetup32.dll
2011-07-21 14:19:46 -------- d-----w- c:\users\zoe\appdata\local\{E6B97B04-6F2E-4983-BAC1-0D250047934A}
2011-07-20 21:52:09 -------- d-----w- c:\users\zoe\appdata\local\{CA9A386F-B4A9-47B5-A723-07C0622FDB0B}
2011-07-19 15:03:58 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2011-07-19 08:59:12 -------- d-----w- c:\users\zoe\appdata\local\Criterion Games
2011-07-19 08:57:18 11848 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2011-07-19 08:56:58 -------- d-----w- c:\users\zoe\appdata\local\Downloaded Installations
2011-07-19 07:40:03 -------- d-----w- c:\program files\Team17
2011-07-18 09:18:44 -------- d-----w- c:\users\zoe\appdata\local\{8874EA0C-A7B7-4522-8A4A-9AE2EB436410}
2011-07-17 20:31:05 -------- d-----w- c:\users\zoe\appdata\local\{8886B1B2-EF9A-4B2A-916F-0897A2621A5E}
2011-07-16 19:58:59 -------- d-----w- c:\users\zoe\appdata\local\{E5AD17D5-FBF7-4538-A175-CA00DF58FFAF}
2011-07-15 22:57:14 -------- d-----w- c:\users\zoe\appdata\local\{ED3B9CF7-F615-48FF-BF97-27853FCCE16E}
2011-07-15 10:56:49 -------- d-----w- c:\users\zoe\appdata\local\{1ECBA6FF-7862-4629-96EA-559E9EA2E153}
2011-07-14 22:56:25 -------- d-----w- c:\users\zoe\appdata\local\{E3CCAF43-FF36-4161-A23C-180AF6D74E48}
2011-07-14 20:47:46 -------- d-----w- C:\Downloads
2011-07-14 10:54:43 -------- d-----w- c:\users\zoe\appdata\local\{266CEF0F-2C1E-4035-8048-E7CE2A39659C}
.
==================== Find3M ====================
.
2011-07-16 04:37:32 169984 ----a-w- c:\windows\system32\winsrv.dll
2011-07-16 04:34:28 290816 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-16 04:31:12 271360 ----a-w- c:\windows\system32\conhost.exe
2011-07-16 02:21:47 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:21:47 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:21:47 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:21:47 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-09 02:26:10 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-07 12:19:11 21219639 ----a-w- C:\windows.7.codec.pack.v3.1.0.setup.exe
2011-07-07 11:09:20 1582304 ----a-w- C:\rcsetup140_slim.exe
2011-07-07 11:05:32 642712 ----a-w- C:\gfwlivesetup.exe
2011-06-23 04:38:05 3957120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-23 04:38:04 3902336 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-06-21 05:39:53 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-15 09:04:46 86016 ----a-w- c:\windows\system32\odbccu32.dll
2011-06-15 09:04:46 81920 ----a-w- c:\windows\system32\odbccr32.dll
2011-06-15 09:04:46 319488 ----a-w- c:\windows\system32\odbcjt32.dll
2011-06-15 09:04:46 163840 ----a-w- c:\windows\system32\odbctrac.dll
2011-06-15 09:04:46 122880 ----a-w- c:\windows\system32\odbccp32.dll
2011-06-11 02:37:19 2332672 ----a-w- c:\windows\system32\win32k.sys
2011-05-24 17:14:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 10:35:34 294912 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-22 13:28:50 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-05-22 13:28:48 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-04-16 14:26:25 925184 ----a-w- c:\program files\AppWorldInstaller-de.msi
2011-04-08 13:43:48 168166968 ----a-w- c:\program files\OOo_3.3.0_Win_x86_install-wJRE_de.exe
.
============= FINISH: 11:19:44.81 ===============
Attach file:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 1/31/2011 11:09:17 PM
System Uptime: 8/12/2011 8:52:56 PM (15 hours ago)
.
Motherboard: MICRO-STAR INTERNATIONAL CO.,LTD | | MS-7388
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ | CPU 1 | 2600/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 233 GiB total, 55.238 GiB free.
D: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP184: 8/10/2011 2:27:13 PM - Removed XIII
RP185: 8/12/2011 12:02:03 AM - Windows Update
RP186: 8/12/2011 3:00:11 AM - Windows Update
.
==== Installed Programs ======================
.
Acrobat.com
Adobe Acrobat 9 Pro - English, Français, Deutsch
Adobe AIR
Adobe Anchor Service CS4
Adobe Asset Services CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Recommended Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Extra Settings CS4
Adobe Color Video Profiles CS CS4
Adobe Creative Suite 4 Design Standard
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Illustrator CS4
Adobe InDesign CS4
Adobe InDesign CS4 Application Feature Set Files (Roman)
Adobe InDesign CS4 Common Base Files
Adobe InDesign CS4 Icon Handler
Adobe Linguistics CS4
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader X - Deutsch
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe SGM CS4
Adobe SING CS4
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe Version Cue CS4 Server
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
AMD Drag and Drop Transcoding
AMD Fuel
ANNO 1404
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ashampoo Burning Studio Elements 10.0.9
ATI Catalyst Install Manager
ATI Catalyst Registration
ATI Stream SDK v2 Developer
Avira AntiVir Personal - Free Antivirus
Bandisoft MPEG-1 Decoder
BlackBerry Desktop Software 5.0.1
BlackBerry® Media Sync
Bonjour
Burnout(TM) Paradise The Ultimate Box
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
ccc-core-static
ccc-utility
CCC Help English
CCleaner
CDisplayEx 1.8
Conduit Engine
Connect
CPUID CPU-Z 1.57.1
D3DX10
Dead Space™ 2
Die Sims™ 3
Die Sims™ 3 Erstelle einen Sim
DivX-Setup
Dragon Age II
DVDVideoSoftTB Toolbar
EA Download Manager
Fallout 3
Free Audio CD Burner version 1.4.7
Free YouTube to iPod Converter version 3.9.32.324
Free YouTube to MP3 Converter version 3.9.35.324
Google Chrome
Google Update Helper
Harry Potter II
HiJackThis
ICQ Toolbar
ICQ7.4
iTunes
Java Auto Updater
Java(TM) 6 Update 22
Just Cause 2
kuler
LEGO® Harry Potter™: Years 1-4
Malwarebytes' Anti-Malware version 1.51.1.1800
McAfee Security Scan Plus
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office Home and Student 2010 - Deutsch
Microsoft Office Klick-und-Los 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft WSE 3.0 Runtime
Mozilla Firefox 5.0.1 (x86 en-US)
Mozilla Thunderbird (3.1.11)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nexon Game Manager
OpenOffice.org 3.3
Paint.NET v3.5.8
Pando Media Booster
PDF Settings CS4
Photoshop Camera Raw
Prototype(TM)
QuickTime
Roxio Media Manager
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Skype Toolbars
Skype™ 5.3
SPORE™
SPORE™ Galaktische Abenteuer
Suite Shared Configuration CS4
The Lord of the Rings FREE Trial
The Sims™ 3 Ambitions
The Sims™ 3 Fast Lane Stuff
The Sims™ 3 Generations
The Sims™ 3 High-End Loft Stuff
The Sims™ 3 Late Night
The Sims™ 3 Outdoor Living Stuff
The Sims™ 3 World Adventures
Tom Clancy's H.A.W.X
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.1.6
Windows 7 Codec Pack 3.1.0
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalerie
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinRAR
WMV9/VC-1 Video Playback
Worms Reloaded
Yu-Gi-Oh! Power of Chaos JOEY THE PASSION
Yu-Gi-Oh! Power of Chaos KAIBA THE REVENGE
Yu-Gi-Oh! Power of Chaos YUGI THE DESTINY
.
==== End Of File ===========================