DDS (Ver_09-09-29.01) - NTFSx86 Run by [removed] at 9:40:23.53 on Sat 12/26/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.655 [GMT -6:00] AV: avast! antivirus 4.8.1368 [VPS 091226-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ScanSoft\OmniPage15.0\Opware15.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Webshots\3.1.5.7617\webshots.scr C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe svchost.exe C:\Program Files\AGI\core\4.2\AGCoreService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Safari\Safari.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE D:\Download files\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.conwaycorp.com/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {53707962-6F74-2D53-2644-206D7942484F} - No File BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File uRun: [TClockEx] c:\program files\tclockex\TCLOCKEX.EXE uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [EPSON Stylus Photo R220 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiaia.exe /fu "c:\docume~1\kenspa~1\locals~1\temp\E_S132.tmp" /EF "HKCU" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [Opware15] "c:\program files\scansoft\omnipage15.0\Opware15.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [Logitech Utility] Logi_MwX.Exe StartupFolder: c:\docume~1\kenspa~1\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\3.1.5.7617\Launcher.exe IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: Open with Scansoft PDF Converter 3.0 - c:\program files\scansoft\omnipage15.0\pdfconverter3\IEShellExt.dll /100 IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {2E5E800E-6AC0-411E-940A-369530A35E43} - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\kenspa~1\applic~1\mozilla\firefox\profiles\c01bnm35.default\ FF - prefs.js: browser.search.selectedEngine - Searchalot FF - prefs.js: browser.startup.homepage - hxxp://number1.searchalot.com/ FF - component: c:\documents and settings\ken sparrow\application data\mozilla\firefox\profiles\c01bnm35.default\extensions\{7e7165e2-0767-448c-852f-5fa8714f2c37}\components\PlainOldFavorites.dll FF - component: c:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll ---- FIREFOX POLICIES ---- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-12-19 114768] R2 AGCoreService;AG Core Services;c:\program files\agi\core\4.2\AGCoreService.exe [2009-12-16 20480] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-12-19 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-12-19 138680] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-12-19 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-12-19 352920] S2 mrtRate;mrtRate; [x] =============== Created Last 30 ================ 2009-12-25 15:00 249,856 -------- c:\windows\Setup1.exe 2009-12-25 15:00 73,216 a------- c:\windows\ST6UNST.EXE 2009-12-24 15:08 --d----- c:\program files\Bonjour 2009-12-24 13:36 40,064 a---h--- c:\windows\system32\mlfcache.dat 2009-12-23 08:21 --d----- c:\program files\Microsoft Bootvis 2009-12-23 08:13 0 a------- c:\windows\exctrlst.INI 2009-12-23 08:09 --d----- c:\program files\Resource Kit 2009-12-23 05:39 --d----- c:\windows\$regcmp$ 2009-12-22 19:38 36,363 a------- c:\windows\CSTBox.INI 2009-12-22 07:51 1,531,392 a------- c:\docume~1\kenspa~1\applic~1\tsdnwin.dll 2009-12-22 07:45 --d----- c:\program files\SAMSUNG 2009-12-21 13:49 --d----- c:\docume~1\kenspa~1\applic~1\iWin 2009-12-21 13:47 --d----- c:\docume~1\kenspa~1\applic~1\SpinTop 2009-12-19 20:30 a-dshr-- C:\cmdcons 2009-12-19 20:06 261,632 a------- c:\windows\PEV.exe 2009-12-19 20:06 161,792 a------- c:\windows\SWREG.exe 2009-12-19 20:06 98,816 a------- c:\windows\sed.exe 2009-12-19 20:06 77,312 a------- c:\windows\MBR.exe 2009-12-19 17:14 499,712 a------- c:\windows\system32\MSVCP71.dll 2009-12-19 15:17 411,368 a------- c:\windows\system32\deploytk.dll 2009-12-19 15:17 73,728 a------- c:\windows\system32\javacpl.cpl 2009-12-19 09:03 --d----- C:\MGTools 2009-12-19 08:04 --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-12-19 08:04 --d----- c:\program files\SUPERAntiSpyware 2009-12-19 08:04 --d----- c:\docume~1\kenspa~1\applic~1\SUPERAntiSpyware.com 2009-12-18 20:07 --d----- c:\program files\TrendMicro 2009-12-17 19:51 --d----- C:\Hijack this 2009-12-16 14:20 --d----- C:\$AVG 2009-12-16 14:20 --d----- c:\program files\AVG 2009-12-16 14:20 --d----- c:\docume~1\alluse~1\applic~1\avg9 2009-12-16 10:49 92,160 -c------ c:\windows\system32\dllcache\iecompat.dll 2009-12-16 10:47 -cd-h--- c:\windows\ie8 2009-12-16 08:04 --d----- c:\program files\Webshots 2009-12-16 08:04 --d----- c:\docume~1\kenspa~1\applic~1\AGI 2009-12-16 08:04 --d----- c:\program files\AGI 2009-12-16 08:03 --d----- c:\docume~1\alluse~1\applic~1\agi 2009-12-16 07:43 3,698,584 ac------ c:\windows\system32\dllcache\ieapfltr.dat 2009-12-16 07:43 1,241,088 ac------ c:\windows\system32\dllcache\ieframe.dll.mui 2009-12-16 07:43 445,952 ac------ c:\windows\system32\dllcache\ieapfltr.dll 2009-12-16 07:43 59,904 ac------ c:\windows\system32\dllcache\icardie.dll 2009-12-16 07:43 13,824 -c------ c:\windows\system32\dllcache\ieudinit.exe 2009-12-15 11:18 195,456 -------- c:\windows\system32\MpSigStub.exe 2009-12-15 10:30 203,976 a------- c:\windows\system32\richtx32.ocx 2009-12-15 10:30 140,096 a------- c:\windows\system32\COMDLG32.OCX 2009-12-15 10:30 132,880 a------- c:\windows\system32\MSINET.OCX 2009-12-14 12:32 --dsh--- c:\documents and settings\ken sparrow\IECompatCache 2009-12-14 11:33 --d----- c:\docume~1\alluse~1\applic~1\XoftSpySE 2009-12-12 08:30 132,096 a--shr-- c:\windows\system32\hdwwiz6.dll 2009-12-09 03:04 246,272 ac------ c:\windows\system32\dllcache\ieproxy.dll 2009-12-09 03:04 12,800 ac------ c:\windows\system32\dllcache\xpshims.dll 2009-12-09 03:04 11,069,952 ac------ c:\windows\system32\dllcache\ieframe.dll 2009-12-09 03:04 1,985,536 ac------ c:\windows\system32\dllcache\iertutil.dll 2009-12-09 03:04 594,432 ac------ c:\windows\system32\dllcache\msfeeds.dll 2009-12-09 03:04 55,296 ac------ c:\windows\system32\dllcache\msfeedsbs.dll 2009-12-08 09:06 104,512 a------- c:\windows\system32\drivers\AnyDVD.sys 2009-12-08 06:45 104,960 a------- c:\windows\system32\COMNCTR.DLL 2009-12-08 06:45 97,792 a------- c:\windows\system32\LGUICOM.DLL 2009-12-08 06:45 16,896 a------- c:\windows\system32\LMOUSE32.DLL 2009-12-08 06:45 3,568 a------- c:\windows\system32\LMOUSE16.DLL 2009-12-08 06:45 --d----- c:\program files\common files\Logitech 2009-12-08 06:45 152,064 -------- c:\windows\system32\lmoufrc.dll 2009-12-08 06:45 19,968 -------- c:\windows\LOGI_MWX.EXE 2009-12-08 06:45 70,801 a------- c:\windows\system32\drivers\LMouFlt2.Sys 2009-12-08 06:45 37,887 a------- c:\windows\system32\drivers\LHidUsb.sys 2009-12-08 06:45 25,505 a------- c:\windows\system32\drivers\LHidFlt2.Sys 2009-12-08 06:45 51,729 -------- c:\windows\system32\drivers\L8042PR2.SYS 2009-12-08 06:45 23,375 -------- c:\windows\system32\LCOINST.DLL 2009-12-08 06:45 14,095 -------- c:\windows\system32\drivers\LCCFLTR.SYS 2009-12-07 18:10 5,632 a------- c:\windows\system32\ptpusb.dll 2009-12-07 18:10 159,232 a------- c:\windows\system32\ptpusd.dll 2009-12-04 13:38 --d----- C:\CloneDVDTemp 2009-11-29 19:36 --d----- c:\docume~1\kenspa~1\applic~1\Malwarebytes 2009-11-29 19:36 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-11-29 19:36 19,160 a------- c:\windows\system32\drivers\mbam.sys 2009-11-29 19:36 --d----- c:\program files\Malwarebytes' Anti-Malware 2009-11-29 19:36 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-11-29 11:45 --d----- c:\program files\Registry Clean Expert 2009-11-29 11:42 --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-11-29 11:40 --d----- c:\program files\SpywareBlaster 2009-11-29 11:40 --d----- c:\docume~1\kenspa~1\applic~1\IObit 2009-11-29 11:40 --d----- c:\program files\IObit 2009-11-29 11:34 --d----- c:\docume~1\kenspa~1\applic~1\RegistryDefense 2009-11-29 11:33 --d----- c:\program files\Registry Defense 2009-11-29 11:33 --d----- c:\program files\CCleaner ==================== Find3M ==================== 2009-11-23 14:34 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-11-23 13:18 21,640 a------- c:\windows\system32\emptyregdb.dat 2009-11-21 09:51 471,552 a------- c:\windows\apppatch\aclayers.dll 2009-10-29 01:45 916,480 -------- c:\windows\system32\wininet.dll 2009-10-20 23:38 75,776 a------- c:\windows\system32\strmfilt.dll 2009-10-20 23:38 25,088 a------- c:\windows\system32\httpapi.dll 2009-10-13 04:30 270,336 a------- c:\windows\system32\oakley.dll 2009-10-12 07:38 149,504 a------- c:\windows\system32\rastls.dll 2009-10-12 07:38 79,872 a------- c:\windows\system32\raschap.dll 2009-10-08 14:57 611,328 -------- c:\windows\system32\uiautomationcore.dll 2009-10-08 14:57 220,160 a------- c:\windows\system32\oleacc.dll 2009-10-08 14:56 20,480 a------- c:\windows\system32\oleaccrc.dll 2009-09-28 12:20 89,256 -------- c:\windows\system32\ElbyCDIO.dll ============= FINISH: 9:40:55.26 ===============