for a few weeks firefox has been going to random links from google instead of where it should. also randomly freezing for 10-15 seconds every few hours.

AVG & malwarebytes have found the odd item but its still not fixed the problem
HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:15:20, on 11/07/2011
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:Program FilesAVGAVG10avgtray.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program FilesAVGAVG10avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~2Office12GR469A~1.DLL
O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe
O4 - HKLM..Run: [GrooveMonitor] 'C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe'
O4 - HKLM..Run: [WinampAgent] 'C:Program FilesWinampwinampa.exe'
O4 - HKLM..Run: [Windows Mobile Device Center] %windir%WindowsMobilewmdc.exe
O4 - HKLM..Run: [PAC7302_Monitor] C:WindowsPixArtPAC7302Monitor.exe
O4 - HKLM..Run: [HP Software Update] C:Program FilesHpHP Software UpdateHPWuSchd2.exe
O4 - HKLM..Run: [HPUsageTracking] 'C:Program FilesHewlett-PackardHP UTbinhppusg.exe' 'C:Program FilesHewlett-PackardHP UT'
O4 - HKLM..Run: [PrnStatusMX] C:Program FilesHewlett-PackardPrnStatusMXPrnStatusMX.exe
O4 - HKLM..Run: [Adobe Reader Speed Launcher] 'C:Program FilesAdobeReader 9.0ReaderReader_sl.exe'
O4 - HKLM..Run: [Adobe ARM] 'C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe'
O4 - HKLM..Run: [SSBkgdUpdate] 'C:Program FilesCommon FilesScansoft SharedSSBkgdUpdateSSBkgdupdate.exe' -Embedding -boot
O4 - HKLM..Run: [PaperPort PTD] C:Program FilesScanSoftPaperPortpptd40nt.exe
O4 - HKLM..Run: [IndexSearch] C:Program FilesScanSoftPaperPortIndexSearch.exe
O4 - HKLM..Run: [BrMfcWnd] C:Program FilesBrotherBrmfcmonBrMfcWnd.exe /AUTORUN
O4 - HKLM..Run: [ControlCenter3] C:Program FilesBrotherControlCenter3brctrcen.exe /autorun
O4 - HKLM..Run: [Malwarebytes Anti-Malware (reboot)] 'C:Program FilesMalwarebytes' Anti-Malwarembam.exe' /runcleanupscript
O4 - HKLM..Run: [AVG_TRAY] C:Program FilesAVGAVG10avgtray.exe
O4 - HKCU..Run: [DriverUpdaterPro] C:Program FilesiXi ToolsDriver Updater ProDriverUpdaterPro.exe -t
O4 - HKCU..Run: [Allway Sync] 'C:Program FilesAllway SyncBinsyncappw.exe' -m
O4 - HKCU..Run: [DAEMON Tools Pro Agent] 'C:Program FilesDAEMON Tools ProDTAgent.exe' -autorun
O4 - HKCU..Run: [PC Suite Tray] 'C:Program FilesNokiaNokia PC Suite 7PCSuite.exe' -onlytray
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUSS-1-5-19..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUSS-1-5-20..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavaj2re1.4.1_07binnpjpi141_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavaj2re1.4.1_07binnpjpi141_07.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll
O9 - Extra button: @C:WindowsWindowsMobileINetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:WindowsWindowsMobileINetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:WindowsWindowsMobileINetRepl.dll
O9 - Extra 'Tools' menuitem: @C:WindowsWindowsMobileINetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:WindowsWindowsMobileINetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:Program FilesSpybot - Search & DestroySDHelper.dll
O9 - Extra button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:Program FilesPlotSoftPDFillDownloadPDF.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:PROGRA~1MICROS~2Office12GRA32A~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program FilesAVGAVG10avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:Program FilesAVGAVG10Identity ProtectionAgentBinAVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:Program FilesAVGAVG10avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:Windowssystem32brsvc01a.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: NBService - Nero AG - C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 - Service: organiser database (organiserservice) - Acresso - C:PROGRA~1VIVIDW~1ORGANI~1.EXE
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:Program FilesCommon FilesRoxio Shared9.0SharedCOMRoxLiveShare9.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:Program FilesSpybot - Search & DestroySDWinSec.exe
O23 - Service: ServiceLayer - Nokia - C:Program FilesPC Connectivity SolutionServiceLayer.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:Program FilesTeamViewerVersion6TeamViewer_Service.exe
End of file - 8045 bytes
DDS - attach
DDS (Ver_2011-06-23.01)
Microsoft Windows 7 Ultimate
Boot Device: DeviceHarddiskVolume1
Install Date: 01/01/2010 11:41:08
System Uptime: 07/08/2011 13:31:50 (7 hours ago)
Motherboard: ASUSTeK Computer INC. | | M2N-MX SE
Processor: AMD Athlon™ 64 X2 Dual Core Processor 5200+ | CPU 1 | 2611/200mhz
Disk Partitions
C: is FIXED (NTFS) - 298 GiB total, 201.24 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
J: is Removable
M: is Removable
Disabled Device Manager Items
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: PocketPC
Manufacturer: HP iPAQ rx3700
Name: Andy's PDA 2
Service: WUDFRd
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB CF Reader
Manufacturer: Generic
Name: G:
Service: WUDFRd
Class GUID:
Device ID: ACPIATK01101010110
PNP Device ID: ACPIATK01101010110
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB MS Reader
Manufacturer: Generic
Name: J:
Service: WUDFRd
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB SD Reader
Manufacturer: Generic
Name: F:

Service: WUDFRd
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB SM Reader
Manufacturer: Generic
Name: H:
Service: WUDFRd
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: DCP-340CW

Keygen Photoshop Cs6

Manufacturer: Brother
Name: M:
Service: WUDFRd
System Restore Points
RP145: 28/06/2011 17:13:52 - Scheduled Checkpoint
RP146: 06/07/2011 11:20:40 - Scheduled Checkpoint
RP147: 14/07/2011 11:45:15 - Scheduled Checkpoint
RP148: 21/07/2011 12:47:27 - Scheduled Checkpoint
RP149: 24/07/2011 18:25:32 - Installed Serif PhotoPlus Starter Edition
RP150: 01/08/2011 20:44:13 - Scheduled Checkpoint
RP151: 07/08/2011 19:22:12 - Installed HiJackThis
RP152: 07/08/2011 20:00:18 - Removed 1st Pricing
RP153: 07/08/2011 20:01:24 - Removed SliQ Invoicing Plus
RP154: 07/08/2011 20:01:41 - Removed MrvlUsgTracking
Installed Programs
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3
Age of Empires III
Allway Sync version 10.3.25
Audacity 1.3.3 (Unicode)
AVG 2011
BitLord 1.1
BlackBerry Desktop Software 6.0
Brother MFL-Pro Suite DCP-340CW
Brother P-touch Editor 5.0
Cable-Mate 3.3
CCleaner (remove only)
Chinese Traditional Fonts Support For Adobe Reader 9
CIF USB Camera
dBpoweramp Music Converter
EPSON Advanced Printer Driver 3
File Scavenger 3.2 (English)
FileZilla Client 3.3.1
Google Earth
Google Update Helper
GPL Ghostscript 8.64
GTA San Andreas
HijackThis 2.0.2
HP Color LaserJet CP1210 Series
HP Color LaserJet CP1210 Series Toolbox
HP LaserJet Toolbox
HP Software Update
Java 2 Runtime Environment, SE v1.4.1_07
Java Web Start
jStock POS
LAME v3.98.2 for Audacity
Magic ISO Maker v5.5 (build 0281)
Malwarebytes' Anti-Malware
Microsoft Age of Empires II
Microsoft AutoRoute 2005
Microsoft Flight Simulator 2004 A Century of Flight
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox 5.0 (x86 en-GB)
Nero 7 Essentials
Nokia Connectivity Cable Driver
Nokia PC Suite
NVIDIA GAME System Software 2.8.1
PC Connectivity Solution
PDFill PDF Editor with FREE Writer and Free Tools
RollerCoaster Tycoon 2
Samsung CLX-216x Series
Samsung ML-1510_700 Series
Serif PhotoPlus Starter Edition
Skype™ 4.2
Spybot - Search & Destroy
TeamViewer 6
TurboCAD Deluxe v12
TurboCAD Symbols
Tysoft PDF (novaPDF 6.3 printer)
Visual C++ 8.0 ATL (x86) WinSXS MSM
Visual C++ 8.0 CRT (x86) WinSXS MSM
Vivid WorkshopData ATI
Winamp Application Detect
Windows Driver Package - Nokia Modem (06/09/2010 4.5)
Windows Driver Package - Nokia Modem (06/09/2010
Windows Driver Package - Nokia pccsmcfd (08/22/2008
Windows Media Player Firefox Plugin
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
WinRAR archiver
Event Viewer Messages From Past Week
07/08/2011 17:23:48, Error: bowser [8003] - The master browser has received a server announcement from the computer ERIC-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{E5681F85-143D-4B98-B4E6-3D602DA015. The master browser is stopping or an election is being forced.
06/08/2011 17:11:29, Error: Microsoft-Windows-Application-Experience [205] - The Program Compatibility Assistant service failed to perform the phase two initialization.
End Of File
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.7600.16385
Run by Andy at 20:04:15 on 2011-08-07
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.2047.763 [GMT 1:00]
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Running Processes
C:Windowssystem32svchost.exe -k DcomLaunch
C:Windowssystem32svchost.exe -k RPCSS
C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted
C:Windowssystem32svchost.exe -k netsvcs
C:Windowssystem32svchost.exe -k LocalService
C:Windowssystem32svchost.exe -k NetworkService
C:Windowssystem32svchost.exe -k LocalServiceNoNetwork
C:Program FilesAVGAVG10avgwdsvc.exe
C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation
C:Program FilesVivid WorkshopData ATIjrebinjavaw.exe
C:Windowssystem32svchost.exe -k imgsvc
C:Program FilesTeamViewerVersion6TeamViewer_Service.exe
C:Program FilesAVGAVG10Identity ProtectionAgentBinAVGIDSAgent.exe
C:Program FilesSpybot - Search & DestroySDWinSec.exe
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe
C:Program FilesWinampwinampa.exe
C:Program FilesHPHP Software UpdatehpwuSchd2.exe
C:Program FilesHewlett-PackardHP UTbinhppusg.exe
C:Program FilesHewlett-PackardPrnStatusMXPrnStatusMX.exe
C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe
C:Program FilesAVGAVG10avgnsx.exe
C:Program FilesScanSoftPaperPortpptd40nt.exe
C:Program FilesBrotherBrmfcmonBrMfcWnd.exe
C:Program FilesBrotherBrmfcmonBrMfcmon.exe
C:Program FilesBrotherControlCenter3brccMCtl.exe
C:Program FilesAVGAVG10avgtray.exe
C:Program FilesAllway SyncBinsyncappw.exe
C:Program FilesNokiaNokia PC Suite 7PCSuite.exe
C:Program FilesSpybot - Search & DestroyTeaTimer.exe
C:Windowssystem32svchost.exe -k WindowsMobile
C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted
C:Program FilesWindows Media Playerwmpnetwk.exe
C:Program FilesAVGAVG10Identity Protectionagentbinavgidsmonitor.exe
C:Program FilesPC Connectivity SolutionServiceLayer.exe
C:WindowsSystem32svchost.exe -k LocalServicePeerNet
C:Program FilesPC Connectivity SolutionTransportsNclUSBSrv.exe
C:Program FilesPC Connectivity SolutionTransportsNclRSSrv.exe
C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE
C:Program FilesAVGAVG10avgcsrvx.exe
C:Program FilesDAEMON Tools ProDTShellHlp.exe
C:Program FilesWinampwinamp.exe
C:WindowsSystem32svchost.exe -k swprv
C:Program FilesTrend MicroHijackThisHiJackThis.exe
C:Program FilesMozilla Firefoxfirefox.exe
Pseudo HJT Report
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:program filesavgavg10avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:program filesspybot - search & destroySDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:progra~1micros~2office12GR469A~1.DLL
uRun: [DriverUpdaterPro] c:program filesixi toolsdriver updater proDriverUpdaterPro.exe -t
uRun: [Allway Sync] 'c:program filesallway syncbinsyncappw.exe' -m
uRun: [DAEMON Tools Pro Agent] 'c:program filesdaemon tools proDTAgent.exe' -autorun
uRun: [PC Suite Tray] 'c:program filesnokianokia pc suite 7PCSuite.exe' -onlytray
uRun: [SpybotSD TeaTimer] c:program filesspybot - search & destroyTeaTimer.exe
mRun: [NeroFilterCheck] c:program filescommon filesaheadlibNeroCheck.exe
mRun: [GrooveMonitor] 'c:program filesmicrosoft officeoffice12GrooveMonitor.exe'
mRun: [WinampAgent] 'c:program fileswinampwinampa.exe'
mRun: [Windows Mobile Device Center] %windir%WindowsMobilewmdc.exe
mRun: [PAC7302_Monitor] c:windowspixartpac7302Monitor.exe
mRun: [HP Software Update] c:program fileshphp software updateHPWuSchd2.exe
mRun: [HPUsageTracking] 'c:program fileshewlett-packardhp utbinhppusg.exe' 'c:program fileshewlett-packardHP UT'
mRun: [PrnStatusMX] c:program fileshewlett-packardprnstatusmxPrnStatusMX.exe
mRun: [Adobe Reader Speed Launcher] 'c:program filesadobereader 9.0readerReader_sl.exe'
mRun: [Adobe ARM] 'c:program filescommon filesadobearm1.0AdobeARM.exe'
mRun: [SSBkgdUpdate] 'c:program filescommon filesscansoft sharedssbkgdupdateSSBkgdupdate.exe' -Embedding -boot
mRun: [PaperPort PTD] c:program filesscansoftpaperportpptd40nt.exe
mRun: [IndexSearch] c:program filesscansoftpaperportIndexSearch.exe
mRun: [BrMfcWnd] c:program filesbrotherbrmfcmonBrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:program filesbrothercontrolcenter3brctrcen.exe /autorun
mRun: [Malwarebytes Anti-Malware (reboot)] 'c:program filesmalwarebytes' anti-malwarembam.exe' /runcleanupscript
mRun: [AVG_TRAY] c:program filesavgavg10avgtray.exe
mRun: [ESDUSBMon.exe] c:windowssystem32ESDUSBMon.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:progra~1micros~2office12EXCEL.EXE/3000
IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - c:program filesplotsoftpdfillDownloadPDF.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:progra~1micros~2office12ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:windowswindowsmobileINetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:windowswindowsmobileINetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~2office12REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:program filesspybot - search & destroySDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_07-windows-i586.cab
DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer =
TCP: Interfaces{E5681F85-143D-4B98-B4E6-3D602DA01580} : DhcpNameServer =
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:progra~1micros~2office12GRA32A~1.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:program filesavgavg10avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:progra~1common~1skypeSKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:progra~1micros~2office12GR469A~1.DLL
FF - ProfilePath - c:usersandyappdataroamingmozillafirefoxprofiles2ve92f4l.default
FF - prefs.js: browser.search.selectedEngine - Answers.com
FF - component: c:program filesnokianokia pc suite 7bkmrksynccomponentsBkMrkExt.dll
FF - plugin: c:program filescommon filesresearch in motionbbwebsllauncherNPWebSLLauncher.dll
FF - plugin: c:program filesgooglegoogle earthpluginnpgeplugin.dll
FF - plugin: c:program filesgoogleupdate1.3.21.65npGoogleUpdate3.dll
FF - plugin: c:program filesjavaj2re1.4.1_07binNPJava11.dll
FF - plugin: c:program filesjavaj2re1.4.1_07binNPJava12.dll
FF - plugin: c:program filesjavaj2re1.4.1_07binNPJava13.dll
FF - plugin: c:program filesjavaj2re1.4.1_07binNPJava32.dll
FF - plugin: c:program filesjavaj2re1.4.1_07binNPOJI610.dll
FF - plugin: c:program filesmozilla firefoxpluginsNPJPI141_07.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpwachk.dll
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
R0 AVGIDSEH;AVGIDSEH;c:windowssystem32driversAVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:windowssystem32driversavgrkx86.sys [2011-3-16 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:windowssystem32driversavgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:windowssystem32driversavgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:windowssystem32driversavgtdix.sys [2011-4-5 297168]
R2 AVGIDSAgent;AVGIDSAgent;c:program filesavgavg10identity protectionagentbinAVGIDSAgent.exe [2011-4-18 7398752]
R2 avgwd;AVG WatchDog;c:program filesavgavg10avgwdsvc.exe [2011-2-8 269520]
R2 EPSON ESCPOS Status Service;EPSON ESC/POS Status Service;EpStsSrv.exe --> EpStsSrv.exe [?]
R2 Esdpdx01;Esdpdx01;c:windowssystem32driversESDPDX01.SYS [2003-12-25 95485]
R2 organiserservice;organiser database;c:progra~1vividw~1organi~1.exe -zglaxservice organiserservice --> c:progra~1vividw~1ORGANI~1.EXE -zglaxservice organiserservice [?]
R2 SBSDWSCService;SBSD Security Center Service;c:program filesspybot - search & destroySDWinSec.exe [2011-6-12 1153368]
R2 SSPORT;SSPORT;c:windowssystem32driversSSPORT.SYS [2010-1-3 5120]
R2 TeamViewer6;TeamViewer 6;c:program filesteamviewerversion6TeamViewer_Service.exe [2011-7-9 2337144]
R3 AVGIDSDriver;AVGIDSDriver;c:windowssystem32driversAVGIDSDriver.sys [2011-4-14 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:windowssystem32driversAVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:windowssystem32driversAVGIDSShim.sys [2011-2-10 21968]
S2 gupdate;Google Update Service (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2010-5-2 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:windowssystem32driversb57nd60x.sys [2009-7-13 229888]
S3 gupdatem;Google Update Service (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2010-5-2 136176]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:windowssystem32driversnmwcdnsu.sys [2010-2-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:windowssystem32driversnmwcdnsuc.sys [2010-2-26 8320]
Created Last 30
2011-08-07 18:22:53 388096 ----a-r- c:usersandyappdataroamingmicrosoftinstaller{45a66726-69bc-466b-a7a4-12fcba4883d7}HiJackThis.exe
2011-08-02 21:06:48 -------- d-----w- c:usersandyappdataroamingKuafh
2011-08-02 21:06:48 -------- d-----w- c:usersandyappdataroamingAkce
2011-08-02 21:04:15 -------- d-----w- c:usersandyappdataroamingOrik
2011-08-02 21:04:15 -------- d-----w- c:usersandyappdataroamingDopada
2011-08-02 18:09:22 -------- d-----w- c:usersandyappdataroamingRanope
2011-08-02 18:09:22 -------- d-----w- c:usersandyappdataroamingFyalyb
2011-07-24 17:27:13 -------- d-----w- c:usersandyappdataroamingSerif
2011-07-24 17:26:28 -------- d-----w- c:program filescommon filesMSSoap
2011-07-24 17:25:58 -------- d-----w- c:program filesSerif
2011-07-21 17:49:43 306688 ----a-w- c:windowsIsUninst.exe
2011-07-20 16:15:06 -------- d-----w- C:EPSON Advanced Printer Driver
2011-07-11 19:10:27 -------- d-----w- c:usersandyappdataroamingMyla
2011-07-11 19:10:27 -------- d-----w- c:usersandyappdataroamingMiuhi
2011-07-11 16:31:45 -------- d-----w- c:usersandyappdataroamingWuex
2011-07-11 16:31:45 -------- d-----w- c:usersandyappdataroamingCohin
2011-07-09 07:24:57 -------- d-----w- c:program filesTeamViewer
2011-08-07 19:00:07 94208 ----a-w- c:usersandyappdataroamingezplay.sys
2011-08-07 19:00:07 87608 ----a-w- c:usersandyappdataroaminginst.exe
2011-08-07 19:00:05 47360 ----a-w- c:usersandyappdataroamingpcouffin.sys
FINISH: 20:04:40.26
GMER - http://www.gmer.net
Rootkit scan 2011-08-07 20:28:20
Windows 6.1.7600 Harddisk0DR0 -> Device0000006a Hitachi_ rev.V54O
Running: bs4orb6x.exe; Driver: C:UsersAndyAppDataLocalTempkxldrpob.sys
---- System - GMER 1.0.15 ----
SSDT SystemRootsystem32DRIVERSAVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0x96B327A0]
SSDT SystemRootsystem32DRIVERSAVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0x96B32848]
SSDT SystemRootsystem32DRIVERSAVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0x96B328E4]
SSDT SystemRootsystem32DRIVERSAVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0x96B32980]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82E4A579 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E6EF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 4E8 82E769E8 4 Bytes [A0, 27, B3, 96]
.text ntkrnlpa.exe!RtlSidHashLookup + 7B8 82E76CB8 4 Bytes [48, 28, B3, 96]
.text ntkrnlpa.exe!RtlSidHashLookup + 7BD 82E76CBD 3 Bytes [28, B3, 96]
.text ntkrnlpa.exe!RtlSidHashLookup + 82C 82E76D2C 4 Bytes [80, 29, B3, 96] {SUB BYTE [ECX], 0xb3; XCHG ESI, EAX}
? System32Driversspzy.sys The system cannot find the path specified. !
.text USBPORT.SYS!DllUnload 8E1AACA0 5 Bytes JMP 862EC450
? C:UsersAndyAppDataLocalTempmbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:Program FilesMozilla Firefoxfirefox.exe[404] ntdll.dll!LdrLoadDll 777CF585 5 Bytes JMP 01251410 C:Program FilesMozilla Firefoxfirefox.exe (Firefox/Mozilla Corporation)
.text C:Program FilesMozilla Firefoxplugin-container.exe[4668] USER32.dll!SetWindowLongA 7650B1E3 5 Bytes JMP 5E11EDA6 C:Program FilesMozilla Firefoxxul.dll (Mozilla Foundation)
.text C:Program FilesMozilla Firefoxplugin-container.exe[4668] USER32.dll!SetWindowLongW 76516614 5 Bytes JMP 5E11ED38 C:Program FilesMozilla Firefoxxul.dll (Mozilla Foundation)
.text C:Program FilesMozilla Firefoxplugin-container.exe[4668] USER32.dll!GetWindowInfo 76516A82 5 Bytes JMP 5DF35451 C:Program FilesMozilla Firefoxxul.dll (Mozilla Foundation)
.text C:Program FilesMozilla Firefoxplugin-container.exe[4668] USER32.dll!TrackPopupMenu 76534B3B 5 Bytes JMP 5DF35A99 C:Program FilesMozilla Firefoxxul.dll (Mozilla Foundation)
.text C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE[6056] kernel32.dll!SetUnhandledExceptionFilter 760A3142 5 Bytes JMP 636B5629 C:Program FilesCommon FilesMicrosoft Sharedoffice12mso.dll (2007 Microsoft Office component/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device FileSystemNtfs Ntfs 84E781F8
Device FileSystemfastfat FatCdrom 86EB51F8
Device DriverACPI_HAL Device00000050 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device Driverusbohci DeviceUSBPDO-0 86307470
Device Driverusbehci DeviceUSBPDO-1 85E20470
AttachedDevice Drivertdx DeviceTcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device Drivervolmgr DeviceHarddiskVolume1 84E721F8
AttachedDevice Drivervolmgr DeviceHarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device DriverNetBT DeviceNetBT_Tcpip_{E5681F85-143D-4B98-B4E6-3D602DA01580} 861601F8
Device DriverPCI_PNP9168 Device00000058 spzy.sys
Device Drivervolmgr DeviceHarddiskVolume2 84E721F8
AttachedDevice Drivervolmgr DeviceHarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device Drivercdrom DeviceCdRom0 861201F8
Device Driveratapi DeviceIdeIdePort0 84E751F8
Device Driveratapi DeviceIdeIdePort1 84E751F8
Device Drivervolmgr DeviceHarddiskVolume3 84E721F8
AttachedDevice Drivervolmgr DeviceHarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device Drivercdrom DeviceCdRom1 861201F8
Device Drivervolmgr DeviceHarddiskVolume4 84E721F8
AttachedDevice Drivervolmgr DeviceHarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device DriverUSBSTOR Device00000081 862CC470
Device Drivervolmgr DeviceHarddiskVolume5 84E721F8
AttachedDevice Drivervolmgr DeviceHarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device Drivervolmgr DeviceHarddiskVolume6 84E721F8
AttachedDevice Drivervolmgr DeviceHarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device DriverUSBSTOR Device00000082 862CC470
Device Driversptd Device4232267168 spzy.sys
Device DriverUSBSTOR Device00000083 862CC470
Device DriverUSBSTOR Device00000077 862CC470
Device DriverNetBT DeviceNetBt_Wins_Export 861601F8
Device Drivernvstor DeviceRaidPort0 84E761F8
AttachedDevice Drivertdx DeviceUdp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device Drivernvstor Device0000006a 84E761F8
AttachedDevice Drivertdx DeviceRawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device Drivernvstor Device0000006b 84E761F8
Device Driverusbohci DeviceUSBFDO-0 86307470
Device Driverusbehci DeviceUSBFDO-1 85E20470
Device DriverUSBSTOR Device0000007b 862CC470
Device DriverUSBSTOR Device0000007c 862CC470
Device DriverUSBSTOR Device0000007d 862CC470
Device DriverUSBSTOR Device0000007e 862CC470
Device DriverUSBSTOR Device0000007f 862CC470
Device Driverakd6fm27 DeviceScsiakd6fm271Port3Path0Target0Lun0 862ED470
Device Driverakd6fm27 DeviceScsiakd6fm271 862ED470
Device FileSystemfastfat Fat 86EB51F8
AttachedDevice FileSystemfastfat Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice FileSystemfastfat Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Processes - GMER 1.0.15 ----
Library C:Windowssystem32hppatusg01.dll (*** hidden *** ) @ C:Program FilesHewlett-PackardHP UTbinhppusg.exe [2696] 0x03DF0000
---- Registry - GMER 1.0.15 ----
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg@s1 771343423
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg@s2 285507792
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg@h0 1
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC@p0 C:Program FilesDAEMON Tools Pro
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC@u0 0x8E 0x45 0x00 0x00 ...
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC@h0 0
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC@hdf12 0x39 0x98 0x12 0x0D ...
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001@hdf12 0xEC 0x7B 0xB5 0x70 ...
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001gdq0Tysoft
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001gdq0@hdf12 0x07 0xDC 0x3D 0x6D ...
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001gdq1
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001gdq1@hdf12 0xB2 0xA5 0xF7 0x9C ...
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001gdq2
Reg HKLMSYSTEMCurrentControlSetservicessptdCfg14919EA49A8F3B4AA3CF1058D9A 64CEC00000001gdq2@hdf12 0x5E 0x40 0xBC 0x1A ...
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C (not active ControlSet)
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C@p0 C:Program FilesDAEMON Tools Pro
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C@u0 0x8E 0x45 0x00 0x00 ...
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C@h0 0
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C@hdf12 0x39 0x98 0x12 0x0D ...
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001 (not active ControlSet)
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001@hdf12 0xEC 0x7B 0xB5 0x70 ...
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001gdq0 (not active ControlSet)
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001gdq0@hdf12 0x07 0xDC 0x3D 0x6D ...
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001gdq1 (not active ControlSet)
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001gdq1@hdf12 0xB2 0xA5 0xF7 0x9C ...
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001gdq2 (not active ControlSet)
Reg HKLMSYSTEMControlSet002servicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CE C00000001gdq2@hdf12 0x5E 0x40 0xBC 0x1A ...

---- EOF - GMER 1.0.15 ----
