DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 17:05:08.27 on Wed 01/06/2010 Internet Explorer: 7.0.6000.16945 Microsoft� Windows Vista� Home Premium 6.0.6000.0.1252.1.1033.18.2037.985 [GMT -5:00] AV: Symantec AntiVirus *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C} AV: PC-cillin Internet Security - Virus Protection *On-access scanning enabled* (Outdated) {7D2296BC-32CC-4519-917E-52E652474AF5} SP: PC-cillin Internet Security - Spyware Protection *enabled* (Outdated) {003DD9A8-02A6-43CF-81BA-5D403CAD001E} SP: Symantec AntiVirus *enabled* (Outdated) {6C85A515-B91D-4D2B-AF18-40984A4A8493} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} FW: PC-cillin Internet Security - Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\aestsrv.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\STacSV.exe C:\Windows\system32\svchost.exe -k imgsvc C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wuauclt.exe C:\Program Files\AOL 9.0a\waol.exe C:\Program Files\Common Files\AOL\1206589056\ee\aolsoftware.exe C:\Program Files\AOL 9.0a\shellmon.exe C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Windows\System32\rpcnet.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\sam\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\88BWRB84\dds[1].scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://windiwsfsearch.com/search?q={searchTerms} uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5080225 mSearchMigratedDefaultURL = hxxp://windiwsfsearch.com/search?q={searchTerms} uRun: [AOL Fast Start] "c:\program files\aol 9.0a\AOL.EXE" -b mRun: [] mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime TCP: {75FC6395-CE2A-454A-88A5-62EE56CA0FC0} = 205.188.146.145 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: igfxcui - igfxdev.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-5-28 8944] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-5-28 55024] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-10-24 99376] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-5-28 7408] =============== Created Last 30 ================ 2010-01-06 21:38:06 0 d-----w- c:\users\sam\appdata\roaming\Absolute 2010-01-06 21:34:48 51200 ----a-w- c:\windows\system32\rpcnet.dll 2010-01-06 21:34:30 51200 ----a-w- c:\windows\system32\rpcnet.exe 2010-01-06 21:30:00 0 d-----w- c:\windows\LoJackInstaller 2010-01-01 03:06:14 0 d-----w- c:\programdata\Apple Computer 2010-01-01 03:04:59 0 d-----w- c:\programdata\Apple 2009-12-16 19:46:48 24064 ----a-w- c:\windows\system32\nshhttp.dll 2009-12-16 19:46:45 396800 ----a-w- c:\windows\system32\drivers\http.sys 2009-12-16 19:46:45 31232 ----a-w- c:\windows\system32\httpapi.dll 2009-12-13 16:32:00 832512 ----a-w- c:\windows\system32\wininet.dll 2009-12-11 00:46:30 378368 ----a-w- c:\windows\system32\winhttp.dll 2009-12-11 00:34:22 274432 ----a-w- c:\windows\system32\raschap.dll 2009-12-11 00:34:22 232960 ----a-w- c:\windows\system32\rastls.dll ==================== Find3M ==================== 2009-11-03 01:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe 2009-10-29 07:59:17 2048 ----a-w- c:\windows\system32\tzres.dll 2009-10-27 15:01:43 56320 ----a-w- c:\windows\system32\iesetup.dll 2009-10-27 15:01:39 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-10-27 14:59:14 72704 ----a-w- c:\windows\system32\admparse.dll 2009-10-27 12:27:14 26624 ----a-w- c:\windows\system32\ieUnatt.exe 2009-10-27 10:56:00 48128 ----a-w- c:\windows\system32\mshtmler.dll 2009-10-21 16:45:04 33792 ----a-w- c:\windows\system32\identprv.dll 2009-01-07 06:03:53 86016 ----a-w- c:\windows\inf\infstrng.dat 2009-01-07 06:03:53 51200 ----a-w- c:\windows\inf\infpub.dat 2009-01-07 06:03:52 86016 ----a-w- c:\windows\inf\infstor.dat 2008-12-17 23:04:30 174 --sha-w- c:\program files\desktop.ini 2008-07-23 00:27:12 665600 ----a-w- c:\windows\inf\drvindex.dat 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat 2008-02-25 05:46:38 8192 --sha-w- c:\windows\users\default\NTUSER.DAT ============= FINISH: 17:07:37.55 ===============