DDS (Ver_09-12-01.01) - NTFSX64
Run by Michael at 16:57:31,15 on 03-01-2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_17
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.45.1030.18.3838.2606 [GMT 1:00]
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\msa.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Users\Michael\AppData\Roaming\setup.exe
c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe
C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Users\Michael\Desktop\virus væk\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page =
hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0406&m=easynote_tj62&r=27361109l1b6l0300z185f4861y255uDefault_Page_URL =
hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0406&m=easynote_tj62&r=27361109l1b6l0300z185f4861y255mDefault_Page_URL =
hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0406&m=easynote_tj62&r=27361109l1b6l0300z185f4861y255mStart Page =
hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0406&m=easynote_tj62&r=27361109l1b6l0300z185f4861y255mLocal Page = c:\windows\syswow64\blank.htm
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Hjælp til tilmelding til Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
uRun: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
uRun: [PlayNC Launcher]
uRun: [SUPERAntiSpyware] c:\program files (x86)\superantispyware\SUPERAntiSpyware.exe
uRun: [B1RQJ7YJ0U] c:\windows\msa.exe
uRun: [PUT2VIDQLG] c:\users\michael\appdata\local\temp\c.exe
mRun: [BackupManagerTray] "c:\program files (x86)\newtech infosystems\packard bell mybackup\BackupManagerTray.exe" -h -k
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [LManager] c:\program files (x86)\launch manager\LManager.exe
mRun: [avast!] "c:\program files\alwil software\avast4\ashDisp.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe"
mRun: [WinsysMon] c:\users\michael\appdata\roaming\setup.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cabNotify: !SASWinLogon - c:\program files (x86)\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files (x86)\superantispyware\SASSEH.DLL
{9030D464-4C02-4ABF-8ECC-5164760863C6}
mRun-x64: [cAudioFilterAgent] c:\program files\conexant\caudiofilteragent\cAudioFilterAgent64.exe
mRun-x64: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun-x64: [Acer ePower Management] c:\program files\packard bell\packard bell power management\ePowerTray.exe
================= FIREFOX ===================
FF - ProfilePath - c:\users\michael\appdata\roaming\mozilla\firefox\profiles\t27ppkn4.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.startup.homepage -
hxxp://login.live.com/login.srf?id=2&vv=450&lc=1030FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;c:\windows\system32\drivers\PxHlpa64.sys [2009-11-22 55024]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-22 89680]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 59904]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-8 169312]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-26 203264]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-22 22096]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-11-22 65616]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-12-2 138680]
R2 ePowerSvc;Acer ePower Service;c:\program files\packard bell\packard bell power management\ePowerSvc.exe [2009-10-26 844320]
R2 Greg_Service;GRegService;c:\program files (x86)\packard bell\registration\GregHSRW.exe [2009-6-4 1150496]
R2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\newtech infosystems\packard bell mybackup\IScheduleSvc.exe [2009-8-21 62720]
R2 Updater Service;Updater Service;c:\program files\packard bell\packard bell updater\UpdaterService.exe [2009-8-18 240160]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-12-2 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-12-2 352920]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60a.sys [2009-6-20 317480]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-10-26 34872]
S1 SASDIFSV;SASDIFSV;c:\program files (x86)\superantispyware\sasdifsv.sys [2009-12-16 9968]
S1 SASKUTIL;SASKUTIL;c:\program files (x86)\superantispyware\SASKUTIL.SYS [2009-12-16 74480]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-10-26 225280]
S3 SASENUM;SASENUM;c:\program files (x86)\superantispyware\SASENUM.SYS [2009-12-16 7408]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
=============== Created Last 30 ================
2010-01-03 13:01:06 175616 ----a-w- c:\windows\msa.exe
2010-01-03 13:00:55 115200 --sh--w- c:\users\michael\appdata\roaming\install.config.exe
2010-01-03 13:00:47 242176 ----a-w- c:\windows\syswow64\sshnas.dll
2010-01-03 13:00:42 117248 --sh--w- c:\users\michael\appdata\roaming\install_latest.exe
2010-01-03 10:21:07 0 d-----w- c:\users\michael\appdata\roaming\Malwarebytes
2010-01-03 10:21:01 22104 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 10:21:01 0 d-----w- c:\programdata\Malwarebytes
2010-01-03 10:21:01 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2010-01-02 19:45:31 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-01-02 19:45:15 0 d-----w- c:\users\michael\appdata\roaming\SUPERAntiSpyware.com
2010-01-02 19:45:15 0 d-----w- c:\program files (x86)\SUPERAntiSpyware
2010-01-02 19:44:17 0 d-----w- c:\program files (x86)\common files\Wise Installation Wizard
2010-01-02 19:22:58 0 d-----w- c:\program files\HijackThis
2010-01-01 18:50:40 80996 ----a-w- c:\users\michael\vic-team1.jpg
2009-12-30 16:47:00 178176 ----a-w- c:\windows\syswow64\unrar.dll
2009-12-30 16:46:57 0 d-----w- c:\program files (x86)\K-Lite Codec Pack
2009-12-26 20:02:45 0 d-----w- c:\programdata\Apple Computer
2009-12-26 20:01:54 0 d-----w- c:\programdata\Apple
2009-12-25 15:47:39 0 d-----w- c:\program files (x86)\NCsoft
2009-12-25 15:46:58 28168 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2009-12-24 16:26:26 4196406 ---ha-w- c:\windows\syswow64\toyhide.bmp
2009-12-24 14:30:19 0 d-----w- c:\program files (x86)\Winter Fun Pack 2004 for Windows XP
2009-12-23 18:01:08 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-23 18:00:28 0 d-----w- c:\program files (x86)\DAEMON Tools Lite
2009-12-23 17:59:56 0 d-----w- c:\users\michael\appdata\roaming\DAEMON Tools Lite
2009-12-23 17:59:52 0 d-----w- c:\programdata\DAEMON Tools Lite
2009-12-22 18:41:51 2781550 ----a-w- c:\users\michael\0001De Glade Sømænd - Julefrokosten.mp3
2009-12-10 14:02:00 0 d-----w- c:\program files (x86)\CCleaner
2009-12-09 16:22:47 22 ----a-w- c:\windows\HexEditor_FindList.hed
2009-12-09 15:05:31 679936 ----a-w- c:\windows\syswow64\D3DX81ab.dll
2009-12-09 15:05:31 1970176 ----a-w- c:\windows\syswow64\d3dx9.dll
2009-12-09 15:05:30 0 d-----w- c:\program files (x86)\Cheat Engine
2009-12-09 15:02:56 335 ----a-w- c:\windows\WPE PRO.INI
2009-12-09 10:35:25 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2009-12-09 10:35:25 5958656 ----a-w- c:\windows\syswow64\mshtml.dll
==================== Find3M ====================
2010-01-02 16:17:27 76742 ----a-w- c:\windows\system32\perfc006.dat
2010-01-02 16:17:27 461276 ----a-w- c:\windows\system32\perfh006.dat
2009-12-01 22:48:52 143360 --sh--w- c:\users\michael\appdata\roaming\setup.exe
2009-11-24 23:54:29 1280480 ----a-w- c:\windows\syswow64\aswBoot.exe
2009-11-24 23:49:56 65616 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-02 19:42:06 226688 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:48:16 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-29 07:22:37 2048 ----a-w- c:\windows\syswow64\tzres.dll
2009-10-26 20:39:56 39236 ----a-w- c:\windows\system32\perfd006.dat
2009-10-26 20:39:56 39236 ----a-w- c:\windows\inf\perflib\0406\perfd.dat
2009-10-26 20:39:56 39236 ----a-w- c:\windows\inf\perflib\0406\perfc.dat
2009-10-26 20:39:56 306636 ----a-w- c:\windows\system32\perfi006.dat
2009-10-26 20:39:56 306636 ----a-w- c:\windows\inf\perflib\0406\perfi.dat
2009-10-26 20:39:56 306636 ----a-w- c:\windows\inf\perflib\0406\perfh.dat
2009-10-26 20:25:18 29480 ----a-w- c:\windows\syswow64\msxml3a.dll
2009-10-26 20:25:17 505128 ----a-w- c:\windows\syswow64\msvcp71.dll
2009-10-26 20:25:17 353576 ----a-w- c:\windows\syswow64\msvcr71.dll
2009-10-11 03:17:33 149280 ----a-w- c:\windows\syswow64\javaws.exe
2009-10-11 03:17:32 145184 ----a-w- c:\windows\syswow64\javaw.exe
2009-10-11 03:17:31 145184 ----a-w- c:\windows\syswow64\java.exe
2009-10-11 03:17:27 411368 ----a-w- c:\windows\syswow64\deploytk.dll
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-06-11 15:12:00 776614 ----a-w- c:\program files (x86)\common files\packardbell.ico
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 17:00:05,61 ===============