. DDS (Ver_11-05-19.01) - NTFSx86 NETWORK Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Run by [removed] at 22:57:26 on 2011-05-31 Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18.2047.1700 [GMT 2:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Programfiler\Internet Explorer\IEXPLORE.EXE C:\Programfiler\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Administrator\Skrivebord\dds.scr C:\WINDOWS\system32\WSCRIPT.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programfiler\fellesfiler\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\programfiler\avg\avg10\avgssie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\programfiler\microsoft office\office12\GrooveShellExtensions.dll BHO: P�loggingshjelp for Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programfiler\fellesfiler\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programfiler\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programfiler\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [SUPERAntiSpyware] c:\programfiler\superantispyware\SUPERAntiSpyware.exe uRunOnce: [AVG search provider] "c:\programfiler\avg\avg10\SearchProvider.exe" /AFTERINST mRun: [NWEReboot] mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [RTHDCPL] RTHDCPL.EXE mRun: [DelReg] c:\programfiler\msi\overclockingcenter\DelReg.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [GrooveMonitor] "c:\programfiler\microsoft office\office12\GrooveMonitor.exe" mRun: [iTunesHelper] "c:\programfiler\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\programfiler\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\programfiler\fellesfiler\adobe\arm\1.0\AdobeARM.exe" mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\programfiler\malwarebytes' anti-malware\Myscan.exe" /runcleanupscript mRun: [AVG_TRAY] c:\programfiler\avg\avg10\avgtray.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programfiler\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/uno1/GAME_UNO1.cab DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx TCP: {E8D77B98-F623-42DA-B22D-D2C1BF8043A4} = 192.168.10.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\programfiler\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programfiler\avg\avg10\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\felles~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\programfiler\superantispyware\SASWINLO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\programfiler\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\programfiler\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\administrator\programdata\mozilla\firefox\profiles\kma3qi9v.default\ FF - plugin: c:\programfiler\microsoft silverlight\4.0.60310.0\npctrlui.dll FF - plugin: c:\programfiler\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\programfiler\pando networks\media booster\npPandoWebPlugin.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 297168] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656] S1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896] S1 SASDIFSV;SASDIFSV;c:\programfiler\superantispyware\sasdifsv.sys [2010-2-17 12872] S1 SASKUTIL;SASKUTIL;c:\programfiler\superantispyware\SASKUTIL.SYS [2010-5-10 67656] S2 AVGIDSAgent;AVGIDSAgent;c:\programfiler\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752] S2 avgwd;AVG WatchDog;c:\programfiler\avg\avg10\avgwdsvc.exe [2011-2-8 269520] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-5-28 1684736] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134480] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144] S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216] S3 DualCoreCenter;DualCoreCenter;c:\programfiler\msi\overclockingcenter\NTGLM7X.sys [2010-6-20 28672] S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [2006-8-28 10664] S3 RushTopDevice_J;RushTopDevice_J;c:\programfiler\msi\overclockingcenter\RushJ.sys [2010-6-20 18944] S3 RushTopDevice2;RushTopDevice2;c:\programfiler\msi\overclockingcenter\RushTop.sys [2010-6-20 54272] S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [2007-12-9 61536] S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [2008-12-22 41984] . =============== Created Last 30 ================ . 2011-05-31 19:11:45 -------- d-sh--w- c:\documents and settings\administrator\PrivacIE 2011-05-31 11:48:01 -------- d--h--w- c:\documents and settings\all users\programdata\Common Files 2011-05-31 11:47:35 -------- d-----w- c:\documents and settings\administrator\programdata\AVG10 2011-05-31 11:28:55 -------- d-----w- c:\windows\system32\drivers\AVG 2011-05-31 11:28:55 -------- d-----w- c:\documents and settings\all users\programdata\AVG10 2011-05-31 11:28:01 -------- d-----w- c:\programfiler\AVG 2011-05-31 11:23:23 -------- d-----w- c:\documents and settings\all users\programdata\MFAData 2011-05-31 00:26:22 -------- d-----w- c:\documents and settings\administrator\programdata\SUPERAntiSpyware.com 2011-05-31 00:26:09 -------- d-----w- c:\programfiler\SUPERAntiSpyware 2011-05-31 00:23:33 -------- d-----w- c:\documents and settings\administrator\programdata\Malwarebytes 2011-05-31 00:23:28 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-31 00:23:28 -------- d-----w- c:\documents and settings\all users\programdata\Malwarebytes 2011-05-31 00:23:25 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-05-31 00:23:25 -------- d-----w- c:\programfiler\Malwarebytes' Anti-Malware 2011-05-31 00:21:27 -------- d-----w- c:\documents and settings\administrator\lokale innstillinger\programdata\Mozilla 2011-05-15 18:19:34 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-11 12:04:13 -------- d-----w- c:\documents and settings\all users\programdata\PMB Files 2011-05-11 12:04:04 -------- d-----w- c:\programfiler\Pando Networks 2011-05-09 13:27:12 89048 ----a-w- c:\programfiler\mozilla firefox\libEGL.dll 2011-05-09 13:27:12 781272 ----a-w- c:\programfiler\mozilla firefox\mozsqlite3.dll 2011-05-09 13:27:12 465880 ----a-w- c:\programfiler\mozilla firefox\libGLESv2.dll 2011-05-09 13:27:12 1874904 ----a-w- c:\programfiler\mozilla firefox\mozjs.dll 2011-05-09 13:27:12 15832 ----a-w- c:\programfiler\mozilla firefox\mozalloc.dll 2011-05-09 13:27:11 1974616 ----a-w- c:\programfiler\mozilla firefox\D3DCompiler_42.dll 2011-05-09 13:27:11 1892184 ----a-w- c:\programfiler\mozilla firefox\d3dx9_42.dll 2011-05-09 13:27:11 142296 ----a-w- c:\programfiler\mozilla firefox\components\browsercomps.dll . ==================== Find3M ==================== . 2011-04-14 19:28:42 134480 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys 2011-04-06 14:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll 2011-04-06 14:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe 2011-04-04 22:59:56 297168 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2011-03-16 14:03:20 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys 2011-03-07 05:33:44 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:36:58 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:53:37 1857920 ----a-w- c:\windows\system32\win32k.sys . ============= FINISH: 22:57:34,53 ===============