DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 16:08:53.31 on Fri 03/13/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.817 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINNT\system32\Ati2evxx.exe C:\WINNT\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINNT\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\WINNT\System32\Ati2evxx.exe C:\WINNT\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\WINNT\System32\NMSSvc.exe C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS C:\WINNT\System32\svchost.exe -k imgsvc C:\DOCSTAR\dsclsv.exe C:\WINNT\system32\rundll32.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINNT\system32\ctfmon.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE C:\Program Files\Microsoft Office\Office10\WINWORD.EXE C:\WINNT\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINNT\system32\msiexec.exe \\D6jn7yf1\desktop\dds.com ============== Pseudo HJT Report =============== uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uStart Page = hxxp://finance.yahoo.com/ uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: NoExplorer - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {24c9a604-1a15-c515-7522-614e4b23dfed} - c:\winnt\Cywquyfx.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll BHO: : {ff238a60-4f1c-4c4b-bd6e-c64a2a892767} - c:\winnt\system32\ibalmcoin_v3619.dll TB: {9D8D4D69-49A5-4456-96B1-5AD7F12AD4A6} - No File TB: {A9DCFD6B-E825-467A-8C35-90DD23D32B44} - No File TB: Band Class: {d848a3ca-0bfb-4de0-ba9e-a57f0cca1c13} - c:\winnt\dealhlpr.dll TB: Search: {db5a0fc6-bb86-1a93-33b9-c2a588d2a8d0} - c:\winnt\Cywquyfx.dll TB: AOL Toolbar: {4982d40a-c53b-4615-b15b-b5b5e98d167c} - c:\program files\aol toolbar\toolbar.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe mRun: [Keyboard Preload Check] c:\oemdrvrs\keyb\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check" mRun: [CANON DR2580C SVC] rundll32.exe DR25SVC.dll,EntryPointUserMessage mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRunOnce: [NSSInstallation] c:\winnt\system32\adobe\shockwave 11\nssstub.exe /RunOnce dRunOnce: [LabelMaker2.0] regsvr32 c:\program files\common files\mysoftware\regdll.dll /s StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\shortc~1.lnk - c:\docstar.bat mPolicies-system: ConsentPromptBehaviorAdmin = 1 (0x1) IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim95\aim.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\winnt\system32\Shdocvw.dll Trusted Zone: fnbchestercounty.com\www Trusted Zone: ingdirect.com\home Trusted Zone: ml.com\www Trusted Zone: prudential.com\www.annuities Trusted Zone: v2020-sai.com\oneview Trusted Zone: v2020-sai.com\www DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab DPF: {00000075-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxacm.CAB DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://support.gateway.com/support/profiler/PCPitStop.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {2D76EB71-F632-75E3-529A-0836E1BCB4D8} - hxxp://public.searchbarcash.com/cab/352/qpmytsxh.cab DPF: {33363249-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/i263_32.cab DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - hxxp://moneycentral.msn.com/cabs/pmupd806.exe DPF: {4E330863-6A11-11D0-BFD8-006097237877} - hxxp://www.installshield.com/client/iftwclix.cab DPF: {511073AD-BE56-4D43-AE68-93390514385E} - hcp://system/TechTools.CAB DPF: {52DCAD2D-D5DD-8EA5-315A-B4FE032A28F9} - hxxp://public.searchbarcash.com/cab/350/anmqsrho.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140380840171 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199376711190 DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} - hcp://system/RunExeActiveX.CAB DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} - hxxp://moneycentral.msn.com/cabs/pmupdate2.exe DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} - hcp://system/StartFirstControl.CAB DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} - hxxp://support.gateway.com/support/serialharvest/gwCID.CAB DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - hxxp://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} - hxxps://reports.reged.com/viewer/activeXViewer/activexviewer.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://emoneyadvisor.webex.com/client/T26L/webex/ieatgpc.cab DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100 Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Handler: flowto - {C7101FB0-28FB-11D5-883A-204C4F4F5021} - c:\progra~1\netexc~1.0\FlowHook.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll Notify: LMIinit - LMIinit.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll LSA: Notification Packages = scecli ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\winnt\system32\drivers\avgldx86.sys [2008-7-3 325128] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\winnt\system32\drivers\avgmfx86.sys [2007-3-2 27656] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-2-14 298264] R2 DSClSvc;DocSTAR Client Service;c:\docstar\dsclsv.exe [2006-10-23 102400] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2007-6-4 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\winnt\system32\drivers\LMIRfsDriver.sys [2007-6-4 47640] R2 RioPNP;RioPNP;c:\winnt\system32\drivers\RioPnP.sys [2002-12-12 6736] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S3 PCDRDRV;Pcdr Helper Driver;\??\c:\atf\qctest\pcdoc\pcdrdrv.sys --> c:\atf\qctest\pcdoc\PCDRDRV.sys [?] S4 LMIRfsClientNP;LMIRfsClientNP; [x] =============== Created Last 30 ================ 2009-03-04 12:55 --d----- c:\program files\Trend Micro 2009-03-04 10:47 28,288 a------- c:\winnt\system32\dllcache\xjis.nls 2009-03-04 10:40 83,748 a------- c:\winnt\system32\dllcache\prcp.nls 2009-03-04 10:40 83,748 a------- c:\winnt\system32\dllcache\prc.nls 2009-03-04 10:40 68,608 a------- c:\winnt\system32\dllcache\plugin.ocx 2009-03-04 10:37 47,066 a------- c:\winnt\system32\dllcache\ksc.nls 2009-03-04 10:31 82,172 a------- c:\winnt\system32\dllcache\bopomofo.nls 2009-03-04 10:31 66,728 a------- c:\winnt\system32\dllcache\big5.nls 2009-03-04 09:08 --d----- c:\program files\SDHelper (Spybot - Search & Destroy) 2009-03-03 23:42 --d----- c:\docume~1\owner\applic~1\Malwarebytes 2009-03-03 23:42 15,504 a------- c:\winnt\system32\drivers\mbam.sys 2009-03-03 23:42 38,496 a------- c:\winnt\system32\drivers\mbamswissarmy.sys 2009-03-03 23:42 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-03-03 23:42 --d----- c:\program files\Malwarebytes' Anti-Malware 2009-03-03 23:32 --d----- c:\documents and settings\owner\DoctorWeb 2009-03-03 21:27 116,224 a------- c:\winnt\system32\dllcache\xrxwiadr.dll 2009-03-03 21:26 19,455 a------- c:\winnt\system32\dllcache\wvchntxx.sys 2009-03-03 21:26 12,063 a------- c:\winnt\system32\dllcache\wsiintxx.sys 2009-03-03 21:26 8,192 a------- c:\winnt\system32\dllcache\wshirda.dll 2009-03-03 21:26 8,832 a------- c:\winnt\system32\dllcache\wmiacpi.sys 2009-03-03 21:26 23,615 a------- c:\winnt\system32\dllcache\wch7xxnt.sys 2009-03-03 21:26 31,744 a------- c:\winnt\system32\dllcache\wceusbsh.sys 2009-03-03 21:26 33,599 a------- c:\winnt\system32\dllcache\watv04nt.sys 2009-03-03 21:26 19,551 a------- c:\winnt\system32\dllcache\watv02nt.sys 2009-03-03 21:25 29,311 a------- c:\winnt\system32\dllcache\watv01nt.sys 2009-03-03 21:25 11,775 a------- c:\winnt\system32\dllcache\wadv05nt.sys 2009-03-03 21:25 12,127 a------- c:\winnt\system32\dllcache\wadv02nt.sys 2009-03-03 21:25 12,415 a------- c:\winnt\system32\dllcache\wadv01nt.sys 2009-03-03 21:25 53,760 a------- c:\winnt\system32\dllcache\vfwwdm32.dll 2009-03-03 21:25 25,600 a------- c:\winnt\system32\dllcache\usbser.sys 2009-03-03 21:25 17,024 a------- c:\winnt\system32\dllcache\usbohci.sys 2009-03-03 21:24 82,432 a------- c:\winnt\system32\dllcache\tp4mon.exe 2009-03-03 21:24 149,376 a------- c:\winnt\system32\dllcache\tffsport.sys 2009-03-03 21:23 7,552 a------- c:\winnt\system32\dllcache\sonyait.sys 2009-03-03 21:23 6,912 a------- c:\winnt\system32\dllcache\smbclass.sys 2009-03-03 21:23 16,128 a------- c:\winnt\system32\dllcache\smbbatt.sys 2009-03-03 21:22 32,768 a------- c:\winnt\system32\dllcache\sisnic.sys 2009-03-03 21:22 43,136 a------- c:\winnt\system32\dllcache\sbp2port.sys 2009-03-03 21:21 20,992 a------- c:\winnt\system32\dllcache\rtl8139.sys 2009-03-03 21:21 79,104 a------- c:\winnt\system32\dllcache\rocket.sys 2009-03-03 21:21 6,016 a------- c:\winnt\system32\dllcache\qic157.sys 2009-03-03 21:21 159,232 a------- c:\winnt\system32\dllcache\ptpusd.dll 2009-03-03 21:21 17,664 a------- c:\winnt\system32\dllcache\ppa3.sys 2009-03-03 21:20 259,328 a------- c:\winnt\system32\dllcache\perm3dd.dll 2009-03-03 21:20 28,032 a------- c:\winnt\system32\dllcache\perm3.sys 2009-03-03 21:20 211,712 a------- c:\winnt\system32\dllcache\perm2dll.dll 2009-03-03 21:20 27,904 a------- c:\winnt\system32\dllcache\perm2.sys 2009-03-03 21:20 29,502 a------- c:\winnt\system32\dllcache\pca200e.sys 2009-03-03 21:20 61,056 a------- c:\winnt\system32\dllcache\ohci1394.sys 2009-03-03 21:19 28,672 a------- c:\winnt\system32\dllcache\nscirda.sys 2009-03-03 21:19 49,024 a------- c:\winnt\system32\dllcache\mstape.sys 2009-03-03 21:18 22,016 a------- c:\winnt\system32\dllcache\msircomm.sys 2009-03-03 21:18 26,112 a------- c:\winnt\system32\dllcache\memstpci.sys 2009-03-03 21:18 7,040 a------- c:\winnt\system32\dllcache\ltotape.sys 2009-03-03 21:17 606,684 a------- c:\winnt\system32\dllcache\ltmdmnt.sys 2009-03-03 21:17 34,688 a------- c:\winnt\system32\dllcache\lbrtfdc.sys 2009-03-03 21:15 27,136 a------- c:\winnt\system32\dllcache\irmon.dll 2009-03-03 21:15 152,576 a------- c:\winnt\system32\dllcache\irftp.exe 2009-03-03 21:15 87,424 a------- c:\winnt\system32\dllcache\irda.sys 2009-03-03 21:14 161,020 a------- c:\winnt\system32\dllcache\i81xnt5.sys 2009-03-03 21:14 702,845 a------- c:\winnt\system32\dllcache\i81xdnt5.dll 2009-03-03 21:14 18,560 a------- c:\winnt\system32\dllcache\i2omp.sys 2009-03-03 21:14 8,192 a------- c:\winnt\system32\dllcache\i2omgmt.sys 2009-03-03 21:13 28,288 a------- c:\winnt\system32\dllcache\grserial.sys 2009-03-03 21:13 59,136 a------- c:\winnt\system32\dllcache\gckernel.sys 2009-03-03 21:13 10,624 a------- c:\winnt\system32\dllcache\gameenum.sys 2009-03-03 21:12 34,173 a------- c:\winnt\system32\dllcache\forehe.sys 2009-03-03 21:11 20,992 a------- c:\winnt\system32\dllcache\dshowext.ax 2009-03-03 21:10 8,320 a------- c:\winnt\system32\dllcache\dlttape.sys 2009-03-03 21:10 48,640 a------- c:\winnt\system32\dllcache\cwrwdm.sys 2009-03-03 21:10 249,856 a------- c:\winnt\system32\dllcache\ctmasetp.dll 2009-03-03 21:09 14,080 a------- c:\winnt\system32\dllcache\cmbatt.sys 2009-03-03 21:09 8,192 a------- c:\winnt\system32\dllcache\changer.sys 2009-03-03 21:05 13,696 a------- c:\winnt\system32\dllcache\avcstrm.sys 2009-03-03 21:05 38,912 a------- c:\winnt\system32\dllcache\avc.sys 2009-03-03 21:03 462,848 a------- c:\winnt\system32\dllcache\a3dapi.dll 2009-03-03 21:03 48,128 a------- c:\winnt\system32\dllcache\61883.sys 2009-03-03 21:03 12,288 a------- c:\winnt\system32\dllcache\4mmdat.sys 2009-03-03 21:03 53,248 a------- c:\winnt\system32\dllcache\1394bus.sys 2009-03-02 20:21 --dsh--- c:\docume~1\alluse~1\applic~1\0392271 2009-02-17 17:53 --d----- c:\winnt\system32\Adobe 2009-02-14 10:17 10,520 a------- c:\winnt\system32\avgrsstx.dll ==================== Find3M ==================== 2009-02-14 10:17 325,128 a------- c:\winnt\system32\drivers\avgldx86.sys 2009-02-02 21:12 101,568 a------- c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT 2009-01-16 22:35 3,594,752 a------- c:\winnt\system32\dllcache\mshtml.dll 2008-12-19 05:10 70,656 a------- c:\winnt\system32\dllcache\ie4uinit.exe 2008-12-19 05:10 13,824 -------- c:\winnt\system32\dllcache\ieudinit.exe 2008-12-19 01:25 634,024 a------- c:\winnt\system32\dllcache\iexplore.exe 2008-12-19 01:23 161,792 a------- c:\winnt\system32\dllcache\ieakui.dll 1998-04-27 00:00 570,128 a------- c:\program files\common files\DAO350.DLL 1991-12-09 14:40 352 a------- c:\documents and settings\owner\SIMPSONS.BAT 1991-12-09 14:39 370 a------- c:\documents and settings\owner\CONFIG.BAT ============= FINISH: 16:09:29.62 ===============