DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 20:04:32.47 on Mon 04/27/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_13 Microsoft� Windows Vista� Home Premium 6.0.6001.1.1252.1.1033.18.2814.1731 [GMT -4:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\SMINST\BLService.exe C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\rundll32.exe C:\Windows\system32\taskeng.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Windows\WindowsMobile\wmdc.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\BJ\Downloads\dds(2).scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb uSearch Bar = hxxp://safesearch.cyberdefender.com/smallsearch.html mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb BHO: ZILLAbar Browser Helper Object: {1827766b-9f49-4854-8034-f6ee26fcb1ec} - c:\program files\stopzilla!\SZSG.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.5.0.135\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.5.0.135\IPSBHO.DLL BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:\program files\stopzilla!\SZIEBHO.dll TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll TB: STOPzilla: {98828ded-a591-462f-83ba-d2f62a68b8b8} - c:\program files\stopzilla!\SZSG.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.5.0.135\coIEPlg.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File TB: {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - No File uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5" mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0" mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0" mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe" mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: c:\program files\common files\is3\anti-spyware\iS3lsp.dll DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-US/wlscctrl2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.5.0.135\CoIEPlg.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\bj\appdata\roaming\mozilla\firefox\profiles\uyafla1s.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1005000.087\SymEFA.sys [2009-4-15 310320] R0 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [2009-3-12 54656] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1005000.087\BHDrvx86.sys [2009-4-15 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1005000.087\cchpx86.sys [2009-4-15 482352] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090420.001\IDSvix86.sys [2009-4-26 292912] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-4-12 101936] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040] R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nis\1005000.087\symndisv.sys [2009-4-15 39984] =============== Created Last 30 ================ 2009-04-18 16:38 81,288 a------- c:\windows\system32\drivers\iksyssec.sys 2009-04-18 16:38 66,952 a------- c:\windows\system32\drivers\iksysflt.sys 2009-04-18 16:38 40,840 a------- c:\windows\system32\drivers\ikfilesec.sys 2009-04-18 16:38 29,576 a------- c:\windows\system32\drivers\kcom.sys 2009-04-18 16:38 --d----- c:\users\bj\appdata\roaming\PC Tools 2009-04-18 16:38 --d----- c:\program files\Spyware Doctor 2009-04-18 16:36 --d----- c:\users\bj\appdata\roaming\GetRightToGo 2009-04-15 19:08 376,832 a------- c:\windows\system32\winhttp.dll 2009-04-15 19:08 562,176 a------- c:\windows\system32\msdtcprx.dll 2009-04-15 19:08 38,912 a------- c:\windows\system32\xolehlp.dll 2009-04-15 19:08 3,600,880 a------- c:\windows\system32\ntkrnlpa.exe 2009-04-15 19:08 3,548,656 a------- c:\windows\system32\ntoskrnl.exe 2009-04-15 19:08 551,424 a------- c:\windows\system32\rpcss.dll 2009-04-15 00:20 --d----- c:\program files\Trend Micro 2009-04-12 20:52 --d----- c:\programdata\SITEguard 2009-04-12 20:52 --d----- c:\progra~2\SITEguard 2009-04-12 20:17 192,952,328 a------- c:\windows\MEMORY.DMP 2009-04-12 17:13 --d--r-- c:\program files\Norton Support 2009-04-12 17:01 25,136 a----r-- c:\windows\system32\drivers\SymIMV.sys 2009-04-12 17:01 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS 2009-04-12 17:01 7,386 a------- c:\windows\system32\drivers\SYMEVENT.CAT 2009-04-12 17:01 805 a------- c:\windows\system32\drivers\SYMEVENT.INF 2009-04-12 17:01 --d----- c:\program files\Symantec 2009-04-12 17:01 --d----- c:\program files\common files\Symantec Shared 2009-04-12 17:00 --d----- c:\windows\system32\drivers\NIS 2009-04-12 17:00 --d----- c:\program files\Norton Internet Security 2009-04-12 16:59 --d----- c:\program files\NortonInstaller 2009-04-12 16:48 61,436,856 a------- C:\NIS09EN.exe 2009-04-12 16:29 --d----- c:\windows\LMIBF49.tmp 2009-04-12 13:14 --d----- c:\program files\STOPzilla! 2009-04-12 13:14 --d----- c:\programdata\STOPzilla! 2009-04-12 13:14 --d----- c:\program files\common files\iS3 2009-04-12 13:14 --d----- c:\progra~2\STOPzilla! 2009-04-03 13:50 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf 2009-04-03 13:30 --d----- c:\program files\HTC Touch Pro User Guide 2009-04-03 13:27 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf 2009-03-31 14:57 17,408 a----r-- c:\windows\system32\SZIO5.dll 2009-03-31 14:56 294,912 a----r-- c:\windows\system32\SZBase5.dll 2009-03-31 14:55 540,672 a----r-- c:\windows\system32\SZComp5.dll ==================== Find3M ==================== 2009-04-16 23:23 86,016 a------- c:\windows\inf\infstrng.dat 2009-04-16 23:23 86,016 a------- c:\windows\inf\infstor.dat 2009-04-16 23:23 51,200 a------- c:\windows\inf\infpub.dat 2009-04-12 20:13 66,946 a------- c:\programdata\nvModes.dat 2009-04-12 20:13 66,946 a------- c:\progra~2\nvModes.dat 2009-03-27 10:56 126,976 a----r-- c:\windows\system32\IS3HTUI5.dll 2009-03-27 10:55 393,216 a----r-- c:\windows\system32\IS3DBA5.dll 2009-03-27 10:55 372,736 a----r-- c:\windows\system32\IS3UI5.dll 2009-03-27 10:55 61,440 a----r-- c:\windows\system32\IS3Hks5.dll 2009-03-27 10:54 23,040 a----r-- c:\windows\system32\IS3XDat5.dll 2009-03-27 10:54 221,184 a----r-- c:\windows\system32\IS3Win325.dll 2009-03-27 10:54 94,208 a----r-- c:\windows\system32\IS3Inet5.dll 2009-03-27 10:53 90,112 a----r-- c:\windows\system32\IS3Svc5.dll 2009-03-27 10:50 716,800 a----r-- c:\windows\system32\IS3Base5.dll 2009-03-16 23:38 40,960 a------- c:\windows\apppatch\apihex86.dll 2009-03-16 23:38 13,824 a------- c:\windows\system32\apilogen.dll 2009-03-16 23:38 24,064 a------- c:\windows\system32\amxread.dll 2009-03-12 12:18 54,656 a----r-- c:\windows\system32\drivers\SZKG.sys 2009-03-09 05:19 410,984 a------- c:\windows\system32\deploytk.dll 2009-03-06 17:12 21,256 a------- c:\windows\help\oem\scripts\HPScript.exe 2009-03-05 20:23 0 a--shr-- c:\windows\system32\drivers\103C_HP_cNB_G60 Notebook PC_Y5335KV_0U_Q2CE905826L_E508165-001_4A_I303C_SWistron_V08.48_F.34_T081223_WV3-1_L409_M2814_J250_7AMD_8F31_92.10_#090204_N168C001C;10DE0760_(ZY538UA#ABA)_XMOBILE_CN10_Z_2F.34_G10DE0845.MRK 2009-03-05 12:29 16,648 a------- c:\windows\help\oem\scripts\HC_ProtectSmartPatch.exe 2009-03-03 00:40 827,392 a------- c:\windows\system32\wininet.dll 2009-03-03 00:39 183,296 a------- c:\windows\system32\sdohlp.dll 2009-03-03 00:39 26,112 a------- c:\windows\system32\printfilterpipelineprxy.dll 2009-03-03 00:37 78,336 a------- c:\windows\system32\ieencode.dll 2009-03-03 00:37 98,304 a------- c:\windows\system32\iasrecst.dll 2009-03-03 00:37 54,784 a------- c:\windows\system32\iasads.dll 2009-03-03 00:37 44,032 a------- c:\windows\system32\iasdatastore.dll 2009-03-02 23:04 666,624 a------- c:\windows\system32\printfilterpipelinesvc.exe 2009-03-02 22:38 17,408 a------- c:\windows\system32\iashost.exe 2009-03-02 22:28 26,624 a------- c:\windows\system32\ieUnatt.exe 2009-02-13 04:49 72,704 a------- c:\windows\system32\secur32.dll 2009-02-13 04:49 1,255,936 a------- c:\windows\system32\lsasrv.dll 2009-02-08 23:10 2,033,152 a------- c:\windows\system32\win32k.sys 2009-02-05 00:11 1,053,232 a------- c:\windows\system32\MFC71u.dll 2009-02-05 00:11 505,392 a------- c:\windows\system32\msvcp71.dll 2009-02-05 00:11 353,840 a------- c:\windows\system32\msvcr71.dll 2009-02-05 00:11 1,066,544 a------- c:\windows\system32\MFC71.dll 2009-02-04 05:45 453,152 a------- c:\windows\system32\NVUNINST.EXE 2009-01-30 18:24 14,600 a------- c:\windows\help\oem\scripts\HC_InstallHPHC.exe 2008-10-25 19:12 665,600 a------- c:\windows\inf\drvindex.dat 2008-01-20 22:43 174 a--sh--- c:\program files\desktop.ini 2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 20:06:47.44 ===============