I recently downloaded jzip but it changed my web browser home page to search.jzip.com
I have since uninstalled the program but my web browser home page is still being changed.
Here are the requested logs:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 26/04/2008 10:30:54 PM
System Uptime: 13/10/2011 2:13:03 AM (31 hours ago)
.
Motherboard: LENOVO | | LENOVO
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz | CPU 1 | 2403/267mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 39 GiB total, 7.803 GiB free.
D: is FIXED (NTFS) - 409 GiB total, 191.595 GiB free.
E: is Removable
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP603: 13/10/2011 12:13:10 AM - Installed Mobipocket Reader 6.2
RP604: 13/10/2011 12:25:44 AM - Installed Mobipocket Reader 6.2
RP605: 13/10/2011 12:50:18 AM - Installed HiJackThis
RP606: 13/10/2011 1:01:47 AM - Windows Update
RP607: 13/10/2011 1:36:26 AM - Device Driver Package Install: Advanced Micro Devices, Inc. Display adapters
RP608: 14/10/2011 1:35:38 AM - Restore
.
==== Installed Programs ======================
.
.
Acrobat.com
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.6
AMD APP SDK Runtime
AMD Catalyst Install Manager
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Registration
AudioShell 1.3.5
BEHRINGER USB MIDI DRIVER
Bonjour
Cakewalk XL Pack
CamStudio OSS Desktop Recorder
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
ccc-utility
CCC Help English
CommentKahuna
Conduit Engine
Delta
DivX Setup
Driver & Application Installation
File Type Assistant
Free File Viewer 2011
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Intel(R) PRO Network Connections 12.1.12.0
InterVideo DeviceService
iTunes
Jamstix 3.1.0
Java 2 Runtime Environment, SE v1.4.2_19
Java Auto Updater
Java(TM) 6 Update 26
Just Sudoku - Professional Edition 1.1
Just Trains Bristol to Exeter for RailWorks & Railworks 2
K-Lite Codec Pack 4.0.0 (Full)
Lenovo Media Studio
Lenovo PC Type Configuration
LVT
LXH-RAS79 Hotkey driver
Malwarebytes' Anti-Malware version 1.51.2.1300
Market Samurai
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft PowerPoint Viewer
Microsoft Silverlight
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft XML Parser
MiniTool Partition Wizard Home Edition 5.2
Mobipocket Creator 4.2
Mobipocket Reader 6.2
Mozilla Firefox 7.0.1 (x86 en-GB)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
NVIDIA PhysX
OGA Notifier 1.7.0105.35.0
OKAVAgent
PaperPort Image Printer
PC Tune-Up
PIXresizer 2.0.4
PMB
QuickTime
RailWorks
RealNetworks - Microsoft Visual C++ 2005 Runtime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Revo Uninstaller 1.93
ScanSoft PaperPort 11
SecondLifeViewer2 (remove only)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Serif PhotoPlus Starter Edition
SONAR Home Studio 6
Sony USB Driver
Steam
The Lord of the Rings FREE Trial
Traffic Travis 4.0.0
Ulead VideoStudio 11
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
VC 9.0 Runtime
VC80CRTRedist - 8.0.50727.6195
VideoStudio
WinDirStat 1.1.2
Windows Live OneCare safety scanner
Windows Media Player Firefox Plugin
Wings of Prey 1.0.4.1
WinRAR 4.01 (32-bit)
Xvid Video Codec
yuPlay client 0.7.24
ZoneAlarm Antivirus
ZoneAlarm DataLock
ZoneAlarm Extreme Security
ZoneAlarm Firewall
ZoneAlarm Security
.
==== End Of File ===========================
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 9:54:33 on 2011-10-14
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.3326.1109 [GMT 10:00]
.
AV: ZoneAlarm Antivirus *Enabled/Updated* {DE038A5B-9EDD-18A9-2361-FF7D98D43730}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ZoneAlarm Anti-Spyware *Enabled/Updated* {65626BBF-B8E7-1727-19D1-C40FE3537D8D}
FW: ZoneAlarm Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe
C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Windows\runservice.exe
C:\Program Files\Trend Micro\OKAVAgent\OKAVAgent.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Windows\System32\DeltaIITray.exe
C:\Program Files\Lenovo\file32\hotkey.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
D:\Program Files\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
D:\Program Files\Steam\steam.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\PROGRA~1\CHECKP~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
D:\Program Files\update\realsched.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mDefault_Page_URL = hxxp://www.lenovo.com
mURLSearchHooks: ZoneAlarm Extreme Security Toolbar: {a94e8dc9-07aa-45a7-8af2-a0375473a5cd} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - Conduit Engine
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - d:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: ZoneAlarm Extreme Security: {a94e8dc9-07aa-45a7-8af2-a0375473a5cd} - ZoneAlarm Extreme Security Toolbar
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: ZoneAlarm Extreme Security Toolbar: {a94e8dc9-07aa-45a7-8af2-a0375473a5cd} -
TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} -
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Steam] "d:\program files\steam\steam.exe" -silent
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Xvid] d:\program files\CheckUpdate.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [UVS11 Preload] d:\program files\video studio\uvPL.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\programdata\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [M-Audio Taskbar Icon] c:\windows\system32\DeltaIITray.exe
mRun: [Lenovokey] c:\program files\lenovo\file32\hotkey.exe
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [DeltaIITaskbarApp] c:\windows\system32\DeltaIITray.exe
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [ISW] c:\program files\checkpoint\zaforcefield\ForceField.exe /icon="hidden"
mRun: [ZoneAlarm] c:\program files\checkpoint\zonealarm\zatray.exe
mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [TkBellExe] "d:\program files\update\realsched.exe" -osboot
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "d:\program files\iTunesHelper.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
LSP: c:\progra~1\speedb~1\sblsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{74C65298-7B6A-4716-B1FF-8589C6780BB3} : DhcpNameServer = 192.168.1.1
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\mark\appdata\roaming\mozilla\firefox\profiles\i0zxhjrq.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.jzip.com/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ff ... mid=102&q=
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: d:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: d:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: d:\program files\mozilla plugins\npitunes.dll
FF - plugin: d:\program files\netscape6\nppl3260.dll
FF - plugin: d:\program files\netscape6\nprjplug.dll
FF - plugin: d:\program files\netscape6\nprpjplug.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-10-14 11352]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-9-9 176128]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-6-24 21504]
R2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2011-7-25 27016]
R2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2011-7-25 493184]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2010-10-26 2560]
R2 OKAV Agent Service;OKAV Agent Service;c:\program files\trend micro\okavagent\OKAVAgent.exe [2008-2-2 66824]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2011-3-15 428384]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~1\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~1\VideoAcceleratorService.exe -start -scm [?]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-9-9 8606208]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-9-9 248832]
R3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\drivers\deltaII.sys [2009-6-24 302728]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2009-7-14 1443584]
R3 icsak;icsak;c:\program files\checkpoint\zaforcefield\ak\icsak.sys [2011-7-25 36744]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 BCMIDI;BCMIDI;c:\windows\system32\drivers\bcmidi2.sys [2005-10-19 22432]
S3 BEHRINGER_PT_MIDI;Behringer MIDI driver service (pt);c:\windows\system32\drivers\bhrngr_m.sys [2010-3-20 35904]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2009-6-24 21504]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-4-6 16472]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-4-6 11104]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-10-12 16:14:37 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{13fe769e-9e4f-4e6e-8c0a-7d5fc482c78a}\offreg.dll
2011-10-12 15:40:58 -------- dc----w- c:\program files\AMD APP
2011-10-12 15:37:21 -------- dc----w- c:\windows\LastGood.Tmp
2011-10-12 14:50:45 388096 -c--a-r- c:\users\mark\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-10-12 14:26:59 -------- dc----w- c:\users\mark\appdata\roaming\Mobipocket
2011-10-12 14:26:16 -------- dc----w- c:\program files\Mobipocket.com
2011-10-12 13:57:44 -------- dc----w- C:\KindleGen
2011-10-12 13:31:57 -------- dc----w- c:\program files\iPod
2011-10-12 13:23:08 -------- dc----w- c:\program files\Bonjour
2011-10-12 08:14:11 69632 -c--a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-12 08:14:11 57856 -c--a-w- c:\windows\system32\MSDvbNP.ax
2011-10-12 08:14:11 293376 -c--a-w- c:\windows\system32\psisdecd.dll
2011-10-12 08:14:11 217088 -c--a-w- c:\windows\system32\psisrndr.ax
2011-10-12 08:14:09 2043392 -c--a-w- c:\windows\system32\win32k.sys
2011-10-12 08:13:48 2409784 -c--a-w- c:\program files\windows mail\OESpamFilter.dat
2011-10-12 08:13:42 238080 -c--a-w- c:\windows\system32\oleacc.dll
2011-10-12 08:13:41 563712 -c--a-w- c:\windows\system32\oleaut32.dll
2011-10-12 08:13:41 555520 -c--a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-12 08:13:41 4096 -c--a-w- c:\windows\system32\oleaccrc.dll
2011-10-12 08:07:43 7269712 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{13fe769e-9e4f-4e6e-8c0a-7d5fc482c78a}\mpengine.dll
2011-10-11 01:24:52 -------- dc----w- c:\program files\common files\Mobipocket Shared
2011-10-08 13:22:15 -------- dc----w- c:\program files\NCH Software
2011-10-06 05:20:01 -------- dc----w- c:\programdata\boost_interprocess
2011-09-30 04:11:24 -------- dc----w- c:\program files\common files\xing shared
2011-09-29 02:58:46 -------- dc----w- c:\users\mark\appdata\roaming\FreeFileViewer
2011-09-23 11:50:55 -------- dc----w- c:\program files\NVIDIA Corporation
2011-09-23 11:48:12 2106216 -c--a-w- c:\windows\system32\D3DCompiler_43.dll
2011-09-23 11:48:12 1998168 -c--a-w- c:\windows\system32\D3DX9_43.dll
2011-09-14 14:50:42 49664 -c--a-w- c:\windows\system32\CamCodec.dll
2011-09-14 14:24:29 645632 -c--a-w- c:\windows\system32\xvidcore.dll
2011-09-14 14:24:29 240640 -c--a-w- c:\windows\system32\xvidvfw.dll
2011-09-14 14:24:29 153088 -c--a-w- c:\windows\system32\xvid.ax
2011-09-14 01:47:40 53760 -c--a-w- c:\windows\system32\OVDecode.dll
2011-09-14 01:46:58 13625856 -c--a-w- c:\windows\system32\amdocl.dll
2011-09-14 01:38:28 37376 -c--a-w- c:\windows\system32\amdoclcl.dll
.
==================== Find3M ====================
.
2011-10-12 16:15:30 49 -csha-w- c:\windows\system32\mmf.sys
2011-09-30 04:10:34 499712 -c--a-w- c:\windows\system32\msvcp71.dll
2011-09-30 04:10:34 348160 -c--a-w- c:\windows\system32\msvcr71.dll
2011-09-27 04:38:58 404640 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-08 18:26:10 8606208 -c--a-w- c:\windows\system32\drivers\atikmdag.sys
2011-09-08 17:39:44 18534912 -c--a-w- c:\windows\system32\atioglxx.dll
2011-09-08 17:34:20 151552 -c--a-w- c:\windows\system32\atiapfxx.exe
2011-09-08 17:34:10 732672 -c--a-w- c:\windows\system32\aticfx32.dll
2011-09-08 17:30:38 466944 -c--a-w- c:\windows\system32\ATIDEMGX.dll
2011-09-08 17:30:10 401408 -c--a-w- c:\windows\system32\atieclxx.exe
2011-09-08 17:29:46 176128 -c--a-w- c:\windows\system32\atiesrxx.exe
2011-09-08 17:28:46 159744 -c--a-w- c:\windows\system32\atitmmxx.dll
2011-09-08 17:28:32 356352 -c--a-w- c:\windows\system32\atipdlxx.dll
2011-09-08 17:28:22 278528 -c--a-w- c:\windows\system32\Oemdspif.dll
2011-09-08 17:28:16 20992 -c--a-w- c:\windows\system32\atimuixx.dll
2011-09-08 17:28:10 43520 -c--a-w- c:\windows\system32\ati2edxx.dll
2011-09-08 17:24:38 4204032 -c--a-w- c:\windows\system32\atidxx32.dll
2011-09-08 17:18:22 1828864 -c--a-w- c:\windows\system32\atiumdmv.dll
2011-09-08 17:09:40 46080 -c--a-w- c:\windows\system32\aticalrt.dll
2011-09-08 17:09:28 44032 -c--a-w- c:\windows\system32\aticalcl.dll
2011-09-08 17:08:24 4064768 -c--a-w- c:\windows\system32\atiumdva.dll
2011-09-08 17:05:52 7331840 -c--a-w- c:\windows\system32\aticaldd.dll
2011-09-08 17:05:44 4289024 -c--a-w- c:\windows\system32\atiumdag.dll
2011-09-08 16:59:48 52736 -c--a-w- c:\windows\system32\coinst.dll
2011-09-08 16:53:10 270336 -c--a-w- c:\windows\system32\atiadlxx.dll
2011-09-08 16:52:56 13312 -c--a-w- c:\windows\system32\atiglpxx.dll
2011-09-08 16:52:46 32768 -c--a-w- c:\windows\system32\atigktxx.dll
2011-09-08 16:52:20 248832 -c--a-w- c:\windows\system32\drivers\atikmpag.sys
2011-09-08 16:51:54 31744 -c--a-w- c:\windows\system32\atiuxpag.dll
2011-09-08 16:51:44 29184 -c--a-w- c:\windows\system32\atiu9pag.dll
2011-09-08 16:51:22 37376 -c--a-w- c:\windows\system32\atitmpxx.dll
2011-09-08 16:51:12 53248 -c--a-w- c:\windows\system32\drivers\ati2erec.dll
2011-09-08 16:50:54 53760 -c--a-w- c:\windows\system32\atimpc32.dll
2011-09-08 16:50:54 53760 -c--a-w- c:\windows\system32\amdpcom32.dll
2011-09-07 15:45:22 0 -c--a-w- c:\windows\system32\ConduitEngine.tmp
2011-09-01 02:35:59 1798144 -c--a-w- c:\windows\system32\jscript9.dll
2011-09-01 02:28:15 1126912 -c--a-w- c:\windows\system32\wininet.dll
2011-09-01 02:22:54 2382848 -c--a-w- c:\windows\system32\mshtml.tlb
2011-08-31 07:00:50 22216 -c--a-w- c:\windows\system32\drivers\mbam.sys
2011-08-30 13:05:04 83816 -c--a-w- c:\windows\system32\dns-sd.exe
2011-08-30 13:05:04 73064 -c--a-w- c:\windows\system32\dnssd.dll
2011-08-18 14:15:05 45056 -c--a-w- c:\windows\system32\ATIODCLI.exe
2011-08-18 14:14:51 294912 -c--a-w- c:\windows\system32\ATIODE.exe
2011-07-22 20:51:50 94208 -c--a-w- c:\windows\system32\dpl100.dll
.
============= FINISH: 9:56:00.60 ===============
Thank You
I have since uninstalled the program but my web browser home page is still being changed.
Here are the requested logs:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 26/04/2008 10:30:54 PM
System Uptime: 13/10/2011 2:13:03 AM (31 hours ago)
.
Motherboard: LENOVO | | LENOVO
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz | CPU 1 | 2403/267mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 39 GiB total, 7.803 GiB free.
D: is FIXED (NTFS) - 409 GiB total, 191.595 GiB free.
E: is Removable
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP603: 13/10/2011 12:13:10 AM - Installed Mobipocket Reader 6.2
RP604: 13/10/2011 12:25:44 AM - Installed Mobipocket Reader 6.2
RP605: 13/10/2011 12:50:18 AM - Installed HiJackThis
RP606: 13/10/2011 1:01:47 AM - Windows Update
RP607: 13/10/2011 1:36:26 AM - Device Driver Package Install: Advanced Micro Devices, Inc. Display adapters
RP608: 14/10/2011 1:35:38 AM - Restore
.
==== Installed Programs ======================
.
.
Acrobat.com
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.6
AMD APP SDK Runtime
AMD Catalyst Install Manager
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Registration
AudioShell 1.3.5
BEHRINGER USB MIDI DRIVER
Bonjour
Cakewalk XL Pack
CamStudio OSS Desktop Recorder
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
ccc-utility
CCC Help English
CommentKahuna
Conduit Engine
Delta
DivX Setup
Driver & Application Installation
File Type Assistant
Free File Viewer 2011
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Intel(R) PRO Network Connections 12.1.12.0
InterVideo DeviceService
iTunes
Jamstix 3.1.0
Java 2 Runtime Environment, SE v1.4.2_19
Java Auto Updater
Java(TM) 6 Update 26
Just Sudoku - Professional Edition 1.1
Just Trains Bristol to Exeter for RailWorks & Railworks 2
K-Lite Codec Pack 4.0.0 (Full)
Lenovo Media Studio
Lenovo PC Type Configuration
LVT
LXH-RAS79 Hotkey driver
Malwarebytes' Anti-Malware version 1.51.2.1300
Market Samurai
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft PowerPoint Viewer
Microsoft Silverlight
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft XML Parser
MiniTool Partition Wizard Home Edition 5.2
Mobipocket Creator 4.2
Mobipocket Reader 6.2
Mozilla Firefox 7.0.1 (x86 en-GB)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
NVIDIA PhysX
OGA Notifier 1.7.0105.35.0
OKAVAgent
PaperPort Image Printer
PC Tune-Up
PIXresizer 2.0.4
PMB
QuickTime
RailWorks
RealNetworks - Microsoft Visual C++ 2005 Runtime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Revo Uninstaller 1.93
ScanSoft PaperPort 11
SecondLifeViewer2 (remove only)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Serif PhotoPlus Starter Edition
SONAR Home Studio 6
Sony USB Driver
Steam
The Lord of the Rings FREE Trial
Traffic Travis 4.0.0
Ulead VideoStudio 11
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
VC 9.0 Runtime
VC80CRTRedist - 8.0.50727.6195
VideoStudio
WinDirStat 1.1.2
Windows Live OneCare safety scanner
Windows Media Player Firefox Plugin
Wings of Prey 1.0.4.1
WinRAR 4.01 (32-bit)
Xvid Video Codec
yuPlay client 0.7.24
ZoneAlarm Antivirus
ZoneAlarm DataLock
ZoneAlarm Extreme Security
ZoneAlarm Firewall
ZoneAlarm Security
.
==== End Of File ===========================
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 9:54:33 on 2011-10-14
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.3326.1109 [GMT 10:00]
.
AV: ZoneAlarm Antivirus *Enabled/Updated* {DE038A5B-9EDD-18A9-2361-FF7D98D43730}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ZoneAlarm Anti-Spyware *Enabled/Updated* {65626BBF-B8E7-1727-19D1-C40FE3537D8D}
FW: ZoneAlarm Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe
C:\Program Files\CheckPoint\ZAForceField\ISWMGR.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Windows\runservice.exe
C:\Program Files\Trend Micro\OKAVAgent\OKAVAgent.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Windows\System32\DeltaIITray.exe
C:\Program Files\Lenovo\file32\hotkey.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
D:\Program Files\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
D:\Program Files\Steam\steam.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\PROGRA~1\CHECKP~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
D:\Program Files\update\realsched.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mDefault_Page_URL = hxxp://www.lenovo.com
mURLSearchHooks: ZoneAlarm Extreme Security Toolbar: {a94e8dc9-07aa-45a7-8af2-a0375473a5cd} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - Conduit Engine
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - d:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: ZoneAlarm Extreme Security: {a94e8dc9-07aa-45a7-8af2-a0375473a5cd} - ZoneAlarm Extreme Security Toolbar
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: ZoneAlarm Extreme Security Toolbar: {a94e8dc9-07aa-45a7-8af2-a0375473a5cd} -
TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} -
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Steam] "d:\program files\steam\steam.exe" -silent
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Xvid] d:\program files\CheckUpdate.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [UVS11 Preload] d:\program files\video studio\uvPL.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\programdata\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [M-Audio Taskbar Icon] c:\windows\system32\DeltaIITray.exe
mRun: [Lenovokey] c:\program files\lenovo\file32\hotkey.exe
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [DeltaIITaskbarApp] c:\windows\system32\DeltaIITray.exe
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [ISW] c:\program files\checkpoint\zaforcefield\ForceField.exe /icon="hidden"
mRun: [ZoneAlarm] c:\program files\checkpoint\zonealarm\zatray.exe
mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [TkBellExe] "d:\program files\update\realsched.exe" -osboot
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "d:\program files\iTunesHelper.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
LSP: c:\progra~1\speedb~1\sblsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{74C65298-7B6A-4716-B1FF-8589C6780BB3} : DhcpNameServer = 192.168.1.1
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\mark\appdata\roaming\mozilla\firefox\profiles\i0zxhjrq.default\
FF - prefs.js: browser.startup.homepage - hxxp://search.jzip.com/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ff ... mid=102&q=
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: d:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: d:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: d:\program files\mozilla plugins\npitunes.dll
FF - plugin: d:\program files\netscape6\nppl3260.dll
FF - plugin: d:\program files\netscape6\nprjplug.dll
FF - plugin: d:\program files\netscape6\nprpjplug.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-10-14 11352]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-9-9 176128]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-6-24 21504]
R2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2011-7-25 27016]
R2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2011-7-25 493184]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2010-10-26 2560]
R2 OKAV Agent Service;OKAV Agent Service;c:\program files\trend micro\okavagent\OKAVAgent.exe [2008-2-2 66824]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2011-3-15 428384]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~1\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~1\VideoAcceleratorService.exe -start -scm [?]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-9-9 8606208]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-9-9 248832]
R3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\drivers\deltaII.sys [2009-6-24 302728]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2009-7-14 1443584]
R3 icsak;icsak;c:\program files\checkpoint\zaforcefield\ak\icsak.sys [2011-7-25 36744]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 BCMIDI;BCMIDI;c:\windows\system32\drivers\bcmidi2.sys [2005-10-19 22432]
S3 BEHRINGER_PT_MIDI;Behringer MIDI driver service (pt);c:\windows\system32\drivers\bhrngr_m.sys [2010-3-20 35904]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2009-6-24 21504]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-4-6 16472]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-4-6 11104]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-10-12 16:14:37 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{13fe769e-9e4f-4e6e-8c0a-7d5fc482c78a}\offreg.dll
2011-10-12 15:40:58 -------- dc----w- c:\program files\AMD APP
2011-10-12 15:37:21 -------- dc----w- c:\windows\LastGood.Tmp
2011-10-12 14:50:45 388096 -c--a-r- c:\users\mark\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-10-12 14:26:59 -------- dc----w- c:\users\mark\appdata\roaming\Mobipocket
2011-10-12 14:26:16 -------- dc----w- c:\program files\Mobipocket.com
2011-10-12 13:57:44 -------- dc----w- C:\KindleGen
2011-10-12 13:31:57 -------- dc----w- c:\program files\iPod
2011-10-12 13:23:08 -------- dc----w- c:\program files\Bonjour
2011-10-12 08:14:11 69632 -c--a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-12 08:14:11 57856 -c--a-w- c:\windows\system32\MSDvbNP.ax
2011-10-12 08:14:11 293376 -c--a-w- c:\windows\system32\psisdecd.dll
2011-10-12 08:14:11 217088 -c--a-w- c:\windows\system32\psisrndr.ax
2011-10-12 08:14:09 2043392 -c--a-w- c:\windows\system32\win32k.sys
2011-10-12 08:13:48 2409784 -c--a-w- c:\program files\windows mail\OESpamFilter.dat
2011-10-12 08:13:42 238080 -c--a-w- c:\windows\system32\oleacc.dll
2011-10-12 08:13:41 563712 -c--a-w- c:\windows\system32\oleaut32.dll
2011-10-12 08:13:41 555520 -c--a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-12 08:13:41 4096 -c--a-w- c:\windows\system32\oleaccrc.dll
2011-10-12 08:07:43 7269712 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{13fe769e-9e4f-4e6e-8c0a-7d5fc482c78a}\mpengine.dll
2011-10-11 01:24:52 -------- dc----w- c:\program files\common files\Mobipocket Shared
2011-10-08 13:22:15 -------- dc----w- c:\program files\NCH Software
2011-10-06 05:20:01 -------- dc----w- c:\programdata\boost_interprocess
2011-09-30 04:11:24 -------- dc----w- c:\program files\common files\xing shared
2011-09-29 02:58:46 -------- dc----w- c:\users\mark\appdata\roaming\FreeFileViewer
2011-09-23 11:50:55 -------- dc----w- c:\program files\NVIDIA Corporation
2011-09-23 11:48:12 2106216 -c--a-w- c:\windows\system32\D3DCompiler_43.dll
2011-09-23 11:48:12 1998168 -c--a-w- c:\windows\system32\D3DX9_43.dll
2011-09-14 14:50:42 49664 -c--a-w- c:\windows\system32\CamCodec.dll
2011-09-14 14:24:29 645632 -c--a-w- c:\windows\system32\xvidcore.dll
2011-09-14 14:24:29 240640 -c--a-w- c:\windows\system32\xvidvfw.dll
2011-09-14 14:24:29 153088 -c--a-w- c:\windows\system32\xvid.ax
2011-09-14 01:47:40 53760 -c--a-w- c:\windows\system32\OVDecode.dll
2011-09-14 01:46:58 13625856 -c--a-w- c:\windows\system32\amdocl.dll
2011-09-14 01:38:28 37376 -c--a-w- c:\windows\system32\amdoclcl.dll
.
==================== Find3M ====================
.
2011-10-12 16:15:30 49 -csha-w- c:\windows\system32\mmf.sys
2011-09-30 04:10:34 499712 -c--a-w- c:\windows\system32\msvcp71.dll
2011-09-30 04:10:34 348160 -c--a-w- c:\windows\system32\msvcr71.dll
2011-09-27 04:38:58 404640 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-08 18:26:10 8606208 -c--a-w- c:\windows\system32\drivers\atikmdag.sys
2011-09-08 17:39:44 18534912 -c--a-w- c:\windows\system32\atioglxx.dll
2011-09-08 17:34:20 151552 -c--a-w- c:\windows\system32\atiapfxx.exe
2011-09-08 17:34:10 732672 -c--a-w- c:\windows\system32\aticfx32.dll
2011-09-08 17:30:38 466944 -c--a-w- c:\windows\system32\ATIDEMGX.dll
2011-09-08 17:30:10 401408 -c--a-w- c:\windows\system32\atieclxx.exe
2011-09-08 17:29:46 176128 -c--a-w- c:\windows\system32\atiesrxx.exe
2011-09-08 17:28:46 159744 -c--a-w- c:\windows\system32\atitmmxx.dll
2011-09-08 17:28:32 356352 -c--a-w- c:\windows\system32\atipdlxx.dll
2011-09-08 17:28:22 278528 -c--a-w- c:\windows\system32\Oemdspif.dll
2011-09-08 17:28:16 20992 -c--a-w- c:\windows\system32\atimuixx.dll
2011-09-08 17:28:10 43520 -c--a-w- c:\windows\system32\ati2edxx.dll
2011-09-08 17:24:38 4204032 -c--a-w- c:\windows\system32\atidxx32.dll
2011-09-08 17:18:22 1828864 -c--a-w- c:\windows\system32\atiumdmv.dll
2011-09-08 17:09:40 46080 -c--a-w- c:\windows\system32\aticalrt.dll
2011-09-08 17:09:28 44032 -c--a-w- c:\windows\system32\aticalcl.dll
2011-09-08 17:08:24 4064768 -c--a-w- c:\windows\system32\atiumdva.dll
2011-09-08 17:05:52 7331840 -c--a-w- c:\windows\system32\aticaldd.dll
2011-09-08 17:05:44 4289024 -c--a-w- c:\windows\system32\atiumdag.dll
2011-09-08 16:59:48 52736 -c--a-w- c:\windows\system32\coinst.dll
2011-09-08 16:53:10 270336 -c--a-w- c:\windows\system32\atiadlxx.dll
2011-09-08 16:52:56 13312 -c--a-w- c:\windows\system32\atiglpxx.dll
2011-09-08 16:52:46 32768 -c--a-w- c:\windows\system32\atigktxx.dll
2011-09-08 16:52:20 248832 -c--a-w- c:\windows\system32\drivers\atikmpag.sys
2011-09-08 16:51:54 31744 -c--a-w- c:\windows\system32\atiuxpag.dll
2011-09-08 16:51:44 29184 -c--a-w- c:\windows\system32\atiu9pag.dll
2011-09-08 16:51:22 37376 -c--a-w- c:\windows\system32\atitmpxx.dll
2011-09-08 16:51:12 53248 -c--a-w- c:\windows\system32\drivers\ati2erec.dll
2011-09-08 16:50:54 53760 -c--a-w- c:\windows\system32\atimpc32.dll
2011-09-08 16:50:54 53760 -c--a-w- c:\windows\system32\amdpcom32.dll
2011-09-07 15:45:22 0 -c--a-w- c:\windows\system32\ConduitEngine.tmp
2011-09-01 02:35:59 1798144 -c--a-w- c:\windows\system32\jscript9.dll
2011-09-01 02:28:15 1126912 -c--a-w- c:\windows\system32\wininet.dll
2011-09-01 02:22:54 2382848 -c--a-w- c:\windows\system32\mshtml.tlb
2011-08-31 07:00:50 22216 -c--a-w- c:\windows\system32\drivers\mbam.sys
2011-08-30 13:05:04 83816 -c--a-w- c:\windows\system32\dns-sd.exe
2011-08-30 13:05:04 73064 -c--a-w- c:\windows\system32\dnssd.dll
2011-08-18 14:15:05 45056 -c--a-w- c:\windows\system32\ATIODCLI.exe
2011-08-18 14:14:51 294912 -c--a-w- c:\windows\system32\ATIODE.exe
2011-07-22 20:51:50 94208 -c--a-w- c:\windows\system32\dpl100.dll
.
============= FINISH: 9:56:00.60 ===============
Thank You
textbox. Do not include the word Code
.