DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.9.2
Run by Anthony Mandich at 13:56:34 on 2013-01-15
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee Security Scan\3.0.285\SSScheduler.exe
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Anthony Mandich.DD11KK81\My Documents\Downloads\avast_free_antivirus_setup.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://
www.google.com/
uProxyServer = hxxp=127.0.0.1:5555
uProxyOverride = <local>;*.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: CescrtHlpr Object: {64182481-4F71-486b-A045-B233BD0DA8FC} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: Google Gears Helper: {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
TB: facemoods Toolbar: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} -
EB: facemoods.com: {929801A8-4AEF-4D12-BE31-D85BF666452B} -
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [BuildBU] c:\dell\bldbubg.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [PrivitizeVPNInstaller] c:\documents and settings\anthony mandich.dd11kk81\local settings\application data\privitizevpninstaller\PrivitizeVPN_1.0.0.2_install_config.exe /S /delayInstall
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:149
mPolicies-Explorer: NoDriveAutoRun = dword:0
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: picclub.com
Trusted Zone: pokerprosnetwork.com
Trusted Zone: ppnpoker.com
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://
www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1358284568734
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{8D65F208-DB9A-46CB-9B92-DCBC1C417BF0} : DHCPNameServer = 209.18.47.61 209.18.47.62
Notify: igfxcui - igfxsrvc.dll
AppInit_DLLs=
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\24.0.1312.52\installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\anthony mandich.dd11kk81\application data\mozilla\firefox\profiles\ir5v5htz.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxps://
www.google.com/
FF - prefs.js: keyword.URL - hxxp://websearch.shopathome.com?user_id={ed30dd2c-e211-409e-af24-d3d6e05c39e6}&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\google\google gears\firefox\lib\ff36\gears.dll
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - component: c:\program files\netratingsnetsight\netsight\meter2\ffaddon\components\nsgkff36_meter2.dll
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_146.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
FF - ExtSQL: 2012-12-07 05:57;
torntv@torntv.com; c:\documents and settings\anthony mandich.dd11kk81\application data\mozilla\firefox\profiles\ir5v5htz.default\extensions\
torntv@torntv.com.xpi
FF - ExtSQL: 2013-01-06 19:36;
toolbar@shopathome.com; c:\documents and settings\anthony mandich.dd11kk81\application data\mozilla\firefox\profiles\ir5v5htz.default\extensions\
toolbar@shopathome.com
FF - ExtSQL: 2013-01-12 03:22; {40D65E82-75AC-47CA-8A73-1CEDC2668EFF}; c:\program files\mozilla firefox\extensions\{40D65E82-75AC-47CA-8A73-1CEDC2668EFF}
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R? androidusb;ADB Interface Driver
R? ATHFMWDL;NETGEAR WG111T Bootloader driver
R? BasicSeek Service;BasicSeek Service
R? bcm;WiMAX Network Adapter
R? bcmbusctr;WiMAX Bus Driver
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? cm_net;C-motech USB Network Adapter Drivers
R? cm_ser;C-motech USB Serial Port2 Driver
R? FsUsbExDisk;FsUsbExDisk
R? hitmanpro35;Hitman Pro 3.5 Support Driver
R? Lbd;Lbd
R? McComponentHostService;McAfee Security Scan Component Host Service
R? NielGfx;Nielsen USB GFX
R? nielprt;Nielsen Patch Service
R? smhwdev;SmartPhone dummy USB PNP Device (Normal)
R? smhwser;USB Device for Legacy Serial Communication (Normal)
R? ssadbus;SAMSUNG Android USB Composite Device driver (WDM)
R? ssadmdfl;SAMSUNG Android USB Modem (Filter)
R? ssadmdm;SAMSUNG Android USB Modem Drivers
R? ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM)
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
S? DNINDIS5;DNINDIS5 NDIS Protocol Driver
S? IntuitUpdateServiceV4;Intuit Update Service v4
S? MBAMProtector;MBAMProtector
S? MBAMScheduler;MBAMScheduler
S? MBAMService;MBAMService
S? MBAMSwissArmy;MBAMSwissArmy
S? NTI BackupNowEZSvr;NTI BackupNowEZSvr
.
=============== Created Last 30 ================
.
2013-01-15 10:16:26 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-01-15 09:59:43 -------- d-----w- c:\documents and settings\anthony mandich.dd11kk81\application data\Malwarebytes
2013-01-15 09:57:26 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-01-15 09:56:46 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-15 09:56:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-15 08:25:16 -------- d-----w- c:\documents and settings\anthony mandich.dd11kk81\application data\FreeFixer
2013-01-15 08:25:15 -------- d-----w- c:\documents and settings\anthony mandich.dd11kk81\local settings\application data\FreeFixer
2013-01-15 08:25:02 -------- d-----w- c:\program files\FreeFixer
2013-01-14 09:57:59 -------- d-----w- c:\program files\common files\Steam
2013-01-14 09:57:52 -------- d-----w- c:\program files\Steam
2013-01-14 07:35:11 -------- d-----w- c:\documents and settings\all users\application data\McAfee Security Scan
2013-01-14 07:34:35 -------- d-----w- c:\program files\McAfee Security Scan
2013-01-13 10:32:29 -------- d-----w- c:\program files\Inkscape
2013-01-12 11:30:51 -------- d-----w- c:\documents and settings\anthony mandich.dd11kk81\local settings\application data\Conduit
2013-01-12 11:19:45 -------- d-----w- c:\program files\BasicSeek
2013-01-12 11:19:45 -------- d-----w- c:\documents and settings\all users\application data\BasicSeek
2012-12-23 05:37:50 -------- d-----w- c:\program files\Golden Euro Casino
2012-12-22 02:54:25 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-12-22 02:54:25 -------- d-----w- c:\windows\system32\wbem\Repository
2012-12-22 02:16:05 194936 ----a-w- c:\documents and settings\anthony mandich.dd11kk81\wgsdgsdgdsgsd(2).exe
2012-12-18 19:08:32 209112 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2012-12-18 19:08:32 209112 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
.
==================== Find3M ====================
.
2013-01-09 08:52:22 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-09 08:52:21 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-21 05:00:00 1768 ----a-w- c:\windows\fonts\PixelNumsT.otf
2012-12-21 05:00:00 1768 ----a-w- c:\windows\fonts\fonts\PixelNumsT.otf
2012-12-16 12:23:59 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-12-09 05:37:30 464024 ----a-r- c:\windows\system32\cpnprt2win32.cid
2012-11-28 18:33:04 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-11-28 18:32:54 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-11-28 18:32:52 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-11-28 18:32:51 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-11-13 01:25:12 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 02:01:39 1371648 ----a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:02:42 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17:54 916992 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17:54 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-01 12:17:54 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-01 00:35:34 385024 ----a-w- c:\windows\system32\html.iec
2012-10-19 23:18:02 440704 ----a-w- c:\windows\CouponPrinter.ocx
.
============= FINISH: 14:14:26.21 ===============