DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 14:43:39.60 on Wed 03/10/2010 Internet Explorer: 8.0.6001.18882 Microsoft� Windows Vista� Home Premium 6.0.6002.2.1252.1.1033.18.2046.1115 [GMT 0:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\Dwm.exe C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\DllHost.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Windows\System32\rundll32.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Steam\steam.exe C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Steam\SteamService.exe C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe C:\Windows\servicing\TrustedInstaller.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\jon\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://uk.yahoo.com/ mStart Page = hxxp://uk.yahoo.com mDefault_Page_URL = hxxp://uk.yahoo.com mDefault_Search_URL = hxxp://uk.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://uk.search.yahoo.com mSearch Page = hxxp://uk.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://uk.search.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://uk.search.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: PE_IE_Helper Class: {0941c58f-e461-4e03-bd7d-44c27392ade1} - c:\program files\ibm\lotus forms\viewer\3.5\PEhelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.8.0.41\IPSBHO.DLL BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: D: {97d0764d-2eef-38cd-accb-c7e6f78f687c} - c:\windows\system32\is38881.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [EPSON Stylus CX3800 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiaca.exe /fu "c:\windows\temp\E_SFFA2.tmp" /EF "HKCU" uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe" uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.8.0.41\CoIEPlg.dll IFEO: ctfmon.exe - c:\windows\system32\ctfmon_gs.exe ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-1-29 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-1-29 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-1-29 482432] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100305.002\IDSvix86.sys [2010-3-10 343088] R2 N360;Norton 360;c:\program files\norton 360\engine\3.8.0.41\ccSvcHst.exe [2010-1-29 117640] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-9-27 240232] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-11-13 92008] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-16 102448] R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0308000.029\symndisv.sys [2010-1-29 48688] S2 gupdate1ca9217a1d16aa1;Google Update Service (gupdate1ca9217a1d16aa1);c:\program files\google\update\GoogleUpdate.exe [2010-1-10 133104] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-1-18 21504] S3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2007-8-15 552448] S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2009-1-16 13225] =============== Created Last 30 ================ 2010-03-10 14:40:16 0 ----a-w- c:\users\jon\defogger_reenable 2010-03-01 19:14:27 0 d-----w- c:\program files\Trend Micro 2010-02-24 09:48:12 2048 ----a-w- c:\windows\system32\tzres.dll 2010-02-24 09:47:30 471552 ----a-w- c:\windows\system32\secproc_isv.dll 2010-02-24 09:47:30 471552 ----a-w- c:\windows\system32\secproc.dll 2010-02-24 09:47:29 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe 2010-02-24 09:47:29 518144 ----a-w- c:\windows\system32\RMActivate.exe 2010-02-24 09:47:29 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe 2010-02-24 09:47:29 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2010-02-24 09:47:28 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2010-02-24 09:47:27 332288 ----a-w- c:\windows\system32\msdrm.dll 2010-02-24 09:47:27 152064 ----a-w- c:\windows\system32\secproc_ssp.dll 2010-02-24 09:47:23 1696256 ----a-w- c:\windows\system32\gameux.dll 2010-02-24 09:47:20 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-02-24 09:47:20 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2010-02-23 11:19:14 229376 ----a-w- c:\windows\system32\is38881.dll 2010-02-22 12:32:28 0 d-----w- c:\programdata\50059827 2010-02-12 18:23:29 0 d--h--w- c:\windows\msdownld.tmp 2010-02-12 18:23:23 0 d-----w- c:\windows\system32\directx 2010-02-12 17:05:33 0 d-----w- c:\program files\Mass Effect 2 2010-02-10 06:32:24 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys 2010-02-10 06:32:24 302080 ----a-w- c:\windows\system32\drivers\srv.sys 2010-02-10 06:32:17 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-02-10 06:32:17 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-02-10 06:32:06 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys 2010-02-10 06:32:06 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys 2010-02-10 06:32:00 1314816 ----a-w- c:\windows\system32\quartz.dll 2010-02-10 06:31:59 50176 ----a-w- c:\windows\system32\iyuv_32.dll 2010-02-10 06:31:59 31744 ----a-w- c:\windows\system32\msvidc32.dll 2010-02-10 06:31:59 22528 ----a-w- c:\windows\system32\msyuv.dll 2010-02-10 06:31:59 13312 ----a-w- c:\windows\system32\msrle32.dll 2010-02-10 06:31:59 12288 ----a-w- c:\windows\system32\tsbyuv.dll 2010-02-10 06:31:58 91136 ----a-w- c:\windows\system32\avifil32.dll 2010-02-10 06:31:58 82944 ----a-w- c:\windows\system32\mciavi32.dll 2010-02-10 06:31:58 123904 ----a-w- c:\windows\system32\msvfw32.dll 2010-02-10 06:31:49 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-02-10 06:31:49 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys ==================== Find3M ==================== 2010-02-04 10:01:14 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll 2010-02-04 10:01:14 528216 ----a-w- c:\windows\system32\XAudio2_6.dll 2010-02-04 10:01:14 238936 ----a-w- c:\windows\system32\xactengine3_6.dll 2010-02-04 10:01:14 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll 2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll 2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-12-23 01:13:14 24576 ----a-w- c:\windows\system32\AsIO.dll 2009-11-18 00:25:49 86016 ----a-w- c:\windows\inf\infstor.dat 2009-11-18 00:25:49 665600 ----a-w- c:\windows\inf\drvindex.dat 2009-11-18 00:25:49 51200 ----a-w- c:\windows\inf\infpub.dat 2009-11-18 00:25:49 143360 ----a-w- c:\windows\inf\infstrng.dat 2009-01-18 16:58:39 174 --sha-w- c:\program files\desktop.ini 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-12-03 03:00:08 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat 2009-12-03 03:00:08 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat 2009-12-03 03:00:08 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat 2009-10-18 13:09:55 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat 2009-10-18 12:41:21 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat ============= FINISH: 14:44:36.08 ===============