hello i recently got the babylod hope page change deal going on where it changes my home page to babylon every time i open my browser. i beleive that babylon got installed when i downloaded one of the drivers that my uncles laptop needed. i need help to get rid of it. heres my scan reports.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by moo at 18:01:59 on 2012-09-09
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.743 [GMT -4:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\BootRacer\BootRacerServ.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\ProgramData\Browser Manager\2.2.630.40\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\Program Files\Core Temp\Core Temp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\ProgramData\Browser Manager\2.2.630.40\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\Program Files\Input Director\IDWinService.exe
C:\Program Files\Input Director\InputDirectorSessionHelper.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe
C:\Program Files\Input Director\InputDirector.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Input Director\IDVistaService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Input Director\InputDirectorClipboardHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\UI0Detect.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=112555&tt=3612_4&babsrc=HP_ss&mntrId=e81f3a99000000000000002637bd3942
mStart Page = hxxp://www.xfinity.com/?cid=xfactiv_eg_self_main
mWindow Title = Windows Internet Explorer provided by Comcast
mURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {2EECD738-5844-4a99-B4B6-146BF802613B} - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: IE AdBlock: {46b37057-5ba8-4014-b28d-6448fd171a3e} - c:\program files\ie adblock\IE AdBlock.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: iBryte BHO: {836da822-8973-4208-9059-e8d94e598824} - mscoree.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: iBryte Toolbar: {2dc54ae0-ed2e-41d8-8f02-8a1723374007} - mscoree.dll
TB: IE AdBlock: {be1b1f92-ac2e-4afb-bc9d-07fe272c1373} - c:\program files\ie adblock\IE AdBlock.dll
TB: {98889811-442D-49dd-99D7-DC866BE87DBC} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [SRS Audio Sandbox] "c:\program files\srs labs\audio sandbox\SRSSSC.exe" /hideme
uRun: [InputDirector] "c:\program files\input director\InputDirector.exe" /hide
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mExplorerRun: [BootRacer] "c:\program files\bootracer\Bootrace.exe" /2
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: SoftwareSASGeneration = 3 (0x3)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/virtualmark/tc/FMSI.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
TCP: DhcpNameServer = 10.0.0.1
TCP: Interfaces\{51528C4F-16C1-4022-82DB-286A6F480975} : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{ABFAFCA2-DF9E-4095-99EC-0CB42009BE88} : DhcpNameServer = 8.8.8.8
TCP: Interfaces\{EDADE56D-B4D4-4531-9CFA-2A74AC368F1B} : DhcpNameServer = 192.168.42.129
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: c:\progra~2\browse~1\22630~1.40\{16cdf~1\browse~1.dll
mASetup: {DEA4A1ED-53B3-E0CF-D5FD-BACECAC3E1AD} - c:\users\moo\appdata\roaming\wauctu32.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\moo\appdata\roaming\mozilla\firefox\profiles\6yyqo9p2.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\moo\appdata\roaming\mozilla\firefox\profiles\6yyqo9p2.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_265.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
FF - plugin: c:\windows\system32\wat\npWatWeb.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=e81f3a99000000000000002637bd3942&q=
FF - user.js: extensions.BabylonToolbar.id - e81f3a99000000000000002637bd3942
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15592
FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.9.12
FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.9.12
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.9.1214:07:50
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=3612_4
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
.
============= SERVICES / DRIVERS ===============
.
R0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys [2011-3-16 13440]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-11-8 36000]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-6-11 242240]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-7-6 214024]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-11-8 83392]
R3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2012-5-7 13440]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2011-4-23 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2011-4-23 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2011-4-23 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2011-4-23 25088]
S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\lgandadb.sys [2011-4-23 25728]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2009-1-29 6016]
S3 FARMNTIO;FARMNTIO;c:\windows\system32\drivers\FarMntIo.sys [2011-7-20 20824]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-8-16 36608]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-6-27 13224]
S3 mamotou;mamotou;c:\windows\system32\drivers\mamotou.sys [2008-9-21 49377]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-7-6 79816]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-7-6 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-7-6 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-7-6 40552]
S3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\drivers\motoandroid.sys [2009-7-10 25856]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2011-4-4 20480]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-1-29 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2009-5-8 42752]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2010-4-1 23424]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2011-2-7 11008]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-2-22 15872]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2008-12-10 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2008-12-10 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2008-12-10 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2008-12-10 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2008-12-10 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2008-12-10 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2008-12-10 115752]
.
=============== Created Last 30 ================
.
2012-09-09 18:07:55 -------- d-----w- c:\programdata\Browser Manager
2012-09-09 18:07:44 -------- d-----w- c:\users\moo\appdata\roaming\Babylon
2012-09-09 18:07:44 -------- d-----w- c:\programdata\Babylon
2012-09-09 18:07:36 -------- d-----w- c:\users\moo\appdata\roaming\YourFileDownloader
2012-09-03 21:27:12 161880 ----a-w- c:\windows\DP Animation Maker Uninstaller.exe.bak
2012-09-03 20:14:27 -------- d-----w- c:\users\moo\appdata\local\{B47C8C11-674B-4391-BB85-B8E5EAFCDB64}
2012-09-02 19:13:51 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-29 22:30:52 -------- d-----w- c:\users\moo\appdata\local\{A6777C00-054C-4DF3-B4A3-AF3538AEF041}
2012-08-29 02:27:49 -------- d-----w- c:\users\moo\appdata\local\{BD5241BD-F49E-4704-A709-F68A3B426A7A}
2012-08-27 01:36:19 -------- d-----w- c:\users\moo\appdata\local\{745E0656-D910-4CF4-A980-6C14FF8D97B6}
2012-08-26 01:12:04 -------- d-----w- c:\users\moo\appdata\local\{E08EF0EC-8B47-4EC5-9F52-FA0C3DCE11B9}
2012-08-25 09:59:13 -------- d-----w- c:\users\moo\appdata\local\{6759814C-EEAD-44DE-8874-5EB93E643685}
2012-08-23 22:42:30 -------- d-----w- c:\users\moo\appdata\local\{F3DAD6AE-CC60-41D8-A1B0-AA380A72B4ED}
2012-08-20 23:56:18 -------- d-----w- c:\users\moo\appdata\local\{9F1C36F6-678F-40DF-8774-6C2890C92425}
2012-08-19 01:44:17 -------- d-----w- c:\users\moo\appdata\local\{70C54E52-CF3C-4E26-8554-EB6B8CDF4DE1}
2012-08-17 00:58:03 -------- d-----w- c:\users\moo\appdata\local\{C10E8D6F-A6F2-4A2B-8E93-3A5170278799}
2012-08-17 00:57:51 -------- d-----w- c:\users\moo\appdata\local\{D4769204-94F5-4CBF-941A-D38809E231A0}
2012-08-15 21:19:37 -------- d-----w- c:\users\moo\appdata\local\{EF0C808D-2F5A-44D3-8339-2E4F8D446561}
2012-08-15 21:19:23 -------- d-----w- c:\users\moo\appdata\local\{DA40A00A-FE70-4113-8B9F-0D7984751CA3}
2012-08-14 16:14:59 -------- d-----w- c:\windows\system32\drivers\umdf\zh-CN
2012-08-14 16:14:56 -------- d-----w- c:\windows\system32\drivers\umdf\ja-JP
2012-08-14 16:14:54 -------- d-----w- c:\windows\system32\drivers\umdf\pt-BR
2012-08-14 16:14:51 -------- d-----w- c:\windows\system32\drivers\umdf\pt-PT
2012-08-14 16:14:49 -------- d-----w- c:\windows\system32\drivers\umdf\nl-NL
2012-08-14 16:14:46 -------- d-----w- c:\windows\system32\drivers\umdf\it-IT
2012-08-14 16:14:44 -------- d-----w- c:\windows\system32\drivers\umdf\de-DE
2012-08-14 16:14:42 -------- d-----w- c:\windows\system32\drivers\umdf\fr-FR
2012-08-14 16:14:39 -------- d-----w- c:\windows\system32\drivers\umdf\es-ES
2012-08-14 00:09:47 -------- d-----w- c:\users\moo\appdata\local\{0505E015-6817-4621-92C9-85343C6A9696}
2012-08-14 00:09:35 -------- d-----w- c:\users\moo\appdata\local\{4BE37873-7F22-4E8E-BC99-B479B8B02824}
2012-08-12 22:16:20 -------- d-----w- c:\users\moo\appdata\local\{CE29FF04-F20F-4E66-9A73-4CDCCD54C863}
2012-08-12 22:16:08 -------- d-----w- c:\users\moo\appdata\local\{BEDEDD39-AA88-4DEE-BB70-A58CE8EDACB9}
2012-08-12 15:08:31 -------- d-----w- c:\program files\Oracle
2012-08-12 15:07:48 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-11 23:42:02 -------- d-----w- c:\users\moo\appdata\local\{DB940F9E-24B5-4083-9F6F-B9398F541B45}
2012-08-11 23:41:48 -------- d-----w- c:\users\moo\appdata\local\{39E39C38-51AF-46D8-9B2F-567306317E06}
.
==================== Find3M ====================
.
2012-09-02 19:13:43 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-24 00:01:48 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-24 00:01:48 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 01:59:03 9826504 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
.
============= FINISH: 18:03:42.14 ===============
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by moo at 18:01:59 on 2012-09-09
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.743 [GMT -4:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\BootRacer\BootRacerServ.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\ProgramData\Browser Manager\2.2.630.40\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\Program Files\Core Temp\Core Temp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\ProgramData\Browser Manager\2.2.630.40\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\Program Files\Input Director\IDWinService.exe
C:\Program Files\Input Director\InputDirectorSessionHelper.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe
C:\Program Files\Input Director\InputDirector.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Input Director\IDVistaService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Input Director\InputDirectorClipboardHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\UI0Detect.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=112555&tt=3612_4&babsrc=HP_ss&mntrId=e81f3a99000000000000002637bd3942
mStart Page = hxxp://www.xfinity.com/?cid=xfactiv_eg_self_main
mWindow Title = Windows Internet Explorer provided by Comcast
mURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {2EECD738-5844-4a99-B4B6-146BF802613B} - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: IE AdBlock: {46b37057-5ba8-4014-b28d-6448fd171a3e} - c:\program files\ie adblock\IE AdBlock.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: iBryte BHO: {836da822-8973-4208-9059-e8d94e598824} - mscoree.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: iBryte Toolbar: {2dc54ae0-ed2e-41d8-8f02-8a1723374007} - mscoree.dll
TB: IE AdBlock: {be1b1f92-ac2e-4afb-bc9d-07fe272c1373} - c:\program files\ie adblock\IE AdBlock.dll
TB: {98889811-442D-49dd-99D7-DC866BE87DBC} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [SRS Audio Sandbox] "c:\program files\srs labs\audio sandbox\SRSSSC.exe" /hideme
uRun: [InputDirector] "c:\program files\input director\InputDirector.exe" /hide
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mExplorerRun: [BootRacer] "c:\program files\bootracer\Bootrace.exe" /2
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: SoftwareSASGeneration = 3 (0x3)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/virtualmark/tc/FMSI.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
TCP: DhcpNameServer = 10.0.0.1
TCP: Interfaces\{51528C4F-16C1-4022-82DB-286A6F480975} : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{ABFAFCA2-DF9E-4095-99EC-0CB42009BE88} : DhcpNameServer = 8.8.8.8
TCP: Interfaces\{EDADE56D-B4D4-4531-9CFA-2A74AC368F1B} : DhcpNameServer = 192.168.42.129
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: c:\progra~2\browse~1\22630~1.40\{16cdf~1\browse~1.dll
mASetup: {DEA4A1ED-53B3-E0CF-D5FD-BACECAC3E1AD} - c:\users\moo\appdata\roaming\wauctu32.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\moo\appdata\roaming\mozilla\firefox\profiles\6yyqo9p2.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\moo\appdata\roaming\mozilla\firefox\profiles\6yyqo9p2.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_265.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
FF - plugin: c:\windows\system32\wat\npWatWeb.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=e81f3a99000000000000002637bd3942&q=
FF - user.js: extensions.BabylonToolbar.id - e81f3a99000000000000002637bd3942
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15592
FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.9.12
FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.9.12
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.9.1214:07:50
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=3612_4
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
.
============= SERVICES / DRIVERS ===============
.
R0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys [2011-3-16 13440]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-11-8 36000]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-6-11 242240]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-7-6 214024]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-11-8 83392]
R3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2012-5-7 13440]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2011-4-23 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2011-4-23 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2011-4-23 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2011-4-23 25088]
S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\lgandadb.sys [2011-4-23 25728]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2009-1-29 6016]
S3 FARMNTIO;FARMNTIO;c:\windows\system32\drivers\FarMntIo.sys [2011-7-20 20824]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-8-16 36608]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-6-27 13224]
S3 mamotou;mamotou;c:\windows\system32\drivers\mamotou.sys [2008-9-21 49377]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-7-6 79816]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-7-6 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-7-6 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-7-6 40552]
S3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\drivers\motoandroid.sys [2009-7-10 25856]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2011-4-4 20480]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-1-29 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2009-5-8 42752]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2010-4-1 23424]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2011-2-7 11008]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-2-22 15872]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2008-12-10 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2008-12-10 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2008-12-10 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2008-12-10 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2008-12-10 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2008-12-10 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2008-12-10 115752]
.
=============== Created Last 30 ================
.
2012-09-09 18:07:55 -------- d-----w- c:\programdata\Browser Manager
2012-09-09 18:07:44 -------- d-----w- c:\users\moo\appdata\roaming\Babylon
2012-09-09 18:07:44 -------- d-----w- c:\programdata\Babylon
2012-09-09 18:07:36 -------- d-----w- c:\users\moo\appdata\roaming\YourFileDownloader
2012-09-03 21:27:12 161880 ----a-w- c:\windows\DP Animation Maker Uninstaller.exe.bak
2012-09-03 20:14:27 -------- d-----w- c:\users\moo\appdata\local\{B47C8C11-674B-4391-BB85-B8E5EAFCDB64}
2012-09-02 19:13:51 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-29 22:30:52 -------- d-----w- c:\users\moo\appdata\local\{A6777C00-054C-4DF3-B4A3-AF3538AEF041}
2012-08-29 02:27:49 -------- d-----w- c:\users\moo\appdata\local\{BD5241BD-F49E-4704-A709-F68A3B426A7A}
2012-08-27 01:36:19 -------- d-----w- c:\users\moo\appdata\local\{745E0656-D910-4CF4-A980-6C14FF8D97B6}
2012-08-26 01:12:04 -------- d-----w- c:\users\moo\appdata\local\{E08EF0EC-8B47-4EC5-9F52-FA0C3DCE11B9}
2012-08-25 09:59:13 -------- d-----w- c:\users\moo\appdata\local\{6759814C-EEAD-44DE-8874-5EB93E643685}
2012-08-23 22:42:30 -------- d-----w- c:\users\moo\appdata\local\{F3DAD6AE-CC60-41D8-A1B0-AA380A72B4ED}
2012-08-20 23:56:18 -------- d-----w- c:\users\moo\appdata\local\{9F1C36F6-678F-40DF-8774-6C2890C92425}
2012-08-19 01:44:17 -------- d-----w- c:\users\moo\appdata\local\{70C54E52-CF3C-4E26-8554-EB6B8CDF4DE1}
2012-08-17 00:58:03 -------- d-----w- c:\users\moo\appdata\local\{C10E8D6F-A6F2-4A2B-8E93-3A5170278799}
2012-08-17 00:57:51 -------- d-----w- c:\users\moo\appdata\local\{D4769204-94F5-4CBF-941A-D38809E231A0}
2012-08-15 21:19:37 -------- d-----w- c:\users\moo\appdata\local\{EF0C808D-2F5A-44D3-8339-2E4F8D446561}
2012-08-15 21:19:23 -------- d-----w- c:\users\moo\appdata\local\{DA40A00A-FE70-4113-8B9F-0D7984751CA3}
2012-08-14 16:14:59 -------- d-----w- c:\windows\system32\drivers\umdf\zh-CN
2012-08-14 16:14:56 -------- d-----w- c:\windows\system32\drivers\umdf\ja-JP
2012-08-14 16:14:54 -------- d-----w- c:\windows\system32\drivers\umdf\pt-BR
2012-08-14 16:14:51 -------- d-----w- c:\windows\system32\drivers\umdf\pt-PT
2012-08-14 16:14:49 -------- d-----w- c:\windows\system32\drivers\umdf\nl-NL
2012-08-14 16:14:46 -------- d-----w- c:\windows\system32\drivers\umdf\it-IT
2012-08-14 16:14:44 -------- d-----w- c:\windows\system32\drivers\umdf\de-DE
2012-08-14 16:14:42 -------- d-----w- c:\windows\system32\drivers\umdf\fr-FR
2012-08-14 16:14:39 -------- d-----w- c:\windows\system32\drivers\umdf\es-ES
2012-08-14 00:09:47 -------- d-----w- c:\users\moo\appdata\local\{0505E015-6817-4621-92C9-85343C6A9696}
2012-08-14 00:09:35 -------- d-----w- c:\users\moo\appdata\local\{4BE37873-7F22-4E8E-BC99-B479B8B02824}
2012-08-12 22:16:20 -------- d-----w- c:\users\moo\appdata\local\{CE29FF04-F20F-4E66-9A73-4CDCCD54C863}
2012-08-12 22:16:08 -------- d-----w- c:\users\moo\appdata\local\{BEDEDD39-AA88-4DEE-BB70-A58CE8EDACB9}
2012-08-12 15:08:31 -------- d-----w- c:\program files\Oracle
2012-08-12 15:07:48 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-11 23:42:02 -------- d-----w- c:\users\moo\appdata\local\{DB940F9E-24B5-4083-9F6F-B9398F541B45}
2012-08-11 23:41:48 -------- d-----w- c:\users\moo\appdata\local\{39E39C38-51AF-46D8-9B2F-567306317E06}
.
==================== Find3M ====================
.
2012-09-02 19:13:43 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-24 00:01:48 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-24 00:01:48 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 01:59:03 9826504 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
.
============= FINISH: 18:03:42.14 ===============