DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 20:25:21.15 on Thu 06/03/2010 Internet Explorer: 8.0.6001.18904 Microsoft� Windows Vista� Home Premium 6.0.6002.2.1252.1.1033.18.3581.2107 [GMT -7:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\aestsrv.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Windows\system32\STacSV.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Windows\system32\taskeng.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\OEM02Mon.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\System32\rundll32.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Brenden Wilson\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Brenden Wilson\Downloads\HijackThis.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Brenden Wilson\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\mmc.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Brenden Wilson\Downloads\Defogger.exe C:\Users\Brenden Wilson\Downloads\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [Google Update] "c:\users\brenden wilson\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll AppInit_DLLs: c:\windows\system32\avgrsstx.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-6-3 216200] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-6-3 29584] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-6-3 242896] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-10-9 73728] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-6-3 308064] R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2010-5-5 583360] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-10-9 179712] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-6-3 38224] R3 NWDellModem;Dell Wireless Mobile Broadband Modem Driver;c:\windows\system32\drivers\nwdelmdm.sys [2008-10-9 92288] R3 NWDellPort;Dell Wireless Mobile Broadband Status Port Driver;c:\windows\system32\drivers\nwdelser.sys [2008-10-9 92288] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] S4 NWDellPort2;Dell Wireless Mobile Broadband Status2 Port Driver;c:\windows\system32\drivers\nwdelser2.sys [2008-10-9 92288] =============== Created Last 30 ================ 2010-06-04 03:24:56 20 ----a-w- c:\users\brenden wilson\defogger_reenable 2010-06-04 03:10:27 0 d-----w- c:\users\brende~1\appdata\roaming\SUPERAntiSpyware.com 2010-06-04 03:10:27 0 d-----w- c:\programdata\SUPERAntiSpyware.com 2010-06-04 03:10:24 0 d-----w- c:\program files\SUPERAntiSpyware 2010-06-04 03:02:13 0 d-----w- c:\program files\Windows Portable Devices 2010-06-04 02:58:27 0 d-----w- c:\programdata\TEMP 2010-06-04 02:58:19 1071088 ----a-w- c:\windows\system32\MSCOMCTL.OCX 2010-06-04 02:58:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL 2010-06-04 02:58:17 0 d-----w- c:\program files\SpywareBlaster 2010-06-04 02:51:20 221568 ------w- c:\windows\system32\MpSigStub.exe 2010-06-04 02:49:32 0 d-----w- c:\users\brende~1\appdata\roaming\WinPatrol 2010-06-04 02:49:29 0 d-----w- c:\program files\BillP Studios 2010-06-04 02:47:03 92672 ----a-w- c:\windows\system32\UIAnimation.dll 2010-06-04 02:47:02 3023360 ----a-w- c:\windows\system32\UIRibbon.dll 2010-06-04 02:47:02 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll 2010-06-04 02:45:43 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll 2010-06-04 02:45:43 4096 ----a-w- c:\windows\system32\oleaccrc.dll 2010-06-04 02:45:43 234496 ----a-w- c:\windows\system32\oleacc.dll 2010-06-04 02:45:22 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-06-04 02:45:22 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2010-06-04 02:45:22 1696256 ----a-w- c:\windows\system32\gameux.dll 2010-06-04 02:34:54 0 d-----w- c:\windows\system32\eu-ES 2010-06-04 02:34:54 0 d-----w- c:\windows\system32\ca-ES 2010-06-04 02:34:53 0 d-----w- c:\windows\system32\vi-VN 2010-06-04 01:57:10 0 d-----w- c:\windows\system32\EventProviders 2010-06-04 01:55:59 94720 ----a-w- c:\windows\system32\logagent.exe 2010-06-04 01:47:40 0 d-sh--w- C:\$RECYCLE.BIN 2010-06-04 01:39:29 77312 ----a-w- c:\windows\MBR.exe 2010-06-04 01:39:29 256512 ----a-w- c:\windows\PEV.exe 2010-06-04 00:59:42 377344 ----a-w- c:\windows\system32\winhttp.dll 2010-06-04 00:59:41 420352 ----a-w- c:\windows\system32\vbscript.dll 2010-06-04 00:42:26 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin 2010-06-04 00:42:25 11967524 ----a-w- c:\windows\system32\korwbrkr.lex 2010-06-04 00:39:53 72704 ----a-w- c:\windows\system32\admparse.dll 2010-06-04 00:35:58 499712 ----a-w- c:\windows\system32\kerberos.dll 2010-06-04 00:35:58 270848 ----a-w- c:\windows\system32\schannel.dll 2010-06-03 23:38:00 41984 ----a-w- c:\windows\system32\netfxperf.dll 2010-06-03 23:37:03 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2010-06-03 23:36:01 24064 ----a-w- c:\windows\system32\nshhttp.dll 2010-06-03 23:36:00 411648 ----a-w- c:\windows\system32\drivers\http.sys 2010-06-03 23:36:00 30720 ----a-w- c:\windows\system32\httpapi.dll 2010-06-03 23:34:48 0 d-----r- c:\program files\Skype 2010-06-03 23:34:44 0 d-----w- c:\programdata\Skype 2010-06-03 23:33:54 2048 ----a-w- c:\windows\system32\tzres.dll 2010-06-03 23:30:38 68096 ----a-w- c:\windows\system32\wlanhlp.dll 2010-06-03 23:29:57 471552 ----a-w- c:\windows\system32\secproc_isv.dll 2010-06-03 23:29:57 471552 ----a-w- c:\windows\system32\secproc.dll 2010-06-03 23:29:55 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe 2010-06-03 23:29:54 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2010-06-03 23:29:54 332288 ----a-w- c:\windows\system32\msdrm.dll 2010-06-03 23:29:54 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2010-06-03 23:29:54 152064 ----a-w- c:\windows\system32\secproc_ssp.dll 2010-06-03 23:29:49 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys 2010-06-03 23:29:49 302080 ----a-w- c:\windows\system32\drivers\srv.sys 2010-06-03 23:29:25 160256 ----a-w- c:\windows\system32\wkssvc.dll 2010-06-03 23:29:14 71680 ----a-w- c:\windows\system32\atl.dll 2010-06-03 23:29:12 714240 ----a-w- c:\windows\system32\timedate.cpl 2010-06-03 23:28:31 0 d-----w- c:\program files\DAEMON Tools Lite 2010-06-03 23:28:14 0 d-----w- c:\users\brende~1\appdata\roaming\DAEMON Tools Lite 2010-06-03 23:28:10 0 d-----w- c:\programdata\DAEMON Tools Lite 2010-06-03 23:27:58 313344 ----a-w- c:\windows\system32\wmpdxm.dll 2010-06-03 23:27:56 43520 ----a-w- c:\windows\system32\msdxm.tlb 2010-06-03 23:27:56 18432 ----a-w- c:\windows\system32\amcompat.tlb 2010-06-03 23:27:54 243712 ----a-w- c:\windows\system32\rastls.dll 2010-06-03 23:27:50 623616 ----a-w- c:\windows\system32\localspl.dll 2010-06-03 23:27:24 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL 2010-06-03 23:27:15 60928 ----a-w- c:\windows\system32\msasn1.dll 2010-06-03 23:27:03 144896 ----a-w- c:\windows\system32\drivers\srv2.sys 2010-06-03 23:27:00 1314816 ----a-w- c:\windows\system32\quartz.dll 2010-06-03 23:26:59 91136 ----a-w- c:\windows\system32\avifil32.dll 2010-06-03 23:26:59 82944 ----a-w- c:\windows\system32\mciavi32.dll 2010-06-03 23:26:59 50176 ----a-w- c:\windows\system32\iyuv_32.dll 2010-06-03 23:26:59 31744 ----a-w- c:\windows\system32\msvidc32.dll 2010-06-03 23:26:59 22528 ----a-w- c:\windows\system32\msyuv.dll 2010-06-03 23:26:59 13312 ----a-w- c:\windows\system32\msrle32.dll 2010-06-03 23:26:59 123904 ----a-w- c:\windows\system32\msvfw32.dll 2010-06-03 23:26:59 12288 ----a-w- c:\windows\system32\tsbyuv.dll 2010-06-03 23:26:57 355328 ----a-w- c:\windows\system32\WSDApi.dll 2010-06-03 23:23:34 2036736 ----a-w- c:\windows\system32\win32k.sys 2010-06-03 23:21:36 0 d-----w- c:\program files\SystemRequirementsLab 2010-06-03 23:13:55 172032 ----a-w- c:\windows\system32\wintrust.dll 2010-06-03 23:13:50 98304 ----a-w- c:\windows\system32\cabview.dll 2010-06-03 23:11:20 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2010-06-03 23:11:18 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2010-06-03 23:11:13 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2010-06-03 23:11:11 0 d-----w- c:\windows\system32\drivers\Avg 2010-06-03 23:09:20 2421760 ----a-w- c:\windows\system32\wucltux.dll 2010-06-03 23:09:16 87552 ----a-w- c:\windows\system32\wudriver.dll 2010-06-03 23:09:14 33792 ----a-w- c:\windows\system32\wuapp.exe 2010-06-03 23:09:14 171608 ----a-w- c:\windows\system32\wuwebv.dll 2010-06-03 23:09:12 0 d-----w- c:\program files\AVG 2010-06-03 23:09:00 0 d-----w- c:\programdata\avg9 2010-06-03 23:05:42 0 d-----w- c:\program files\Cisco 2010-06-03 23:05:41 0 d-----w- c:\programdata\Cisco 2010-06-03 23:04:21 0 d-----w- c:\programdata\Sun 2010-06-03 23:04:10 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-06-03 22:39:01 0 d-----w- c:\users\brende~1\appdata\roaming\Malwarebytes 2010-06-03 22:38:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-03 22:38:49 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-06-03 22:38:49 0 d-----w- c:\programdata\Malwarebytes 2010-06-03 22:38:49 0 d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-06-03 22:11:17 146 ----a-w- c:\windows\WININIT.INI 2010-06-03 22:04:49 78622 ----a-w- c:\programdata\nvModes.dat 2010-06-03 19:45:45 0 d-----w- c:\program files\uTorrent 2010-06-03 19:45:18 0 d-----w- c:\users\brende~1\appdata\roaming\uTorrent 2010-06-03 19:44:10 0 d-----w- c:\users\brenden wilson\Bluetooth Software 2010-06-03 19:43:43 0 d-----w- c:\programdata\NVIDIA 2010-06-03 19:41:58 0 d-----w- c:\users\brende~1\appdata\roaming\Dell 2010-06-03 19:40:59 0 d-sh--we c:\programdata\Documents 2010-05-06 02:03:29 8896 ----a-w- c:\windows\system32\vpncategories.dll 2010-05-06 02:03:00 28864 ----a-w- c:\windows\system32\vpnevents.dll 2010-05-06 01:46:36 19680 ----a-w- c:\windows\system32\drivers\vpnva.sys ==================== Find3M ==================== 2010-06-04 03:02:11 86016 ----a-w- c:\windows\inf\infstor.dat 2010-06-04 03:02:11 665600 ----a-w- c:\windows\inf\drvindex.dat 2010-06-04 03:02:11 51200 ----a-w- c:\windows\inf\infpub.dat 2010-06-04 03:02:11 143360 ----a-w- c:\windows\inf\infstrng.dat 2010-06-04 02:00:46 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont 2010-06-03 23:28:33 691696 ----a-w- c:\windows\system32\drivers\sptd.sys 2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat 2008-10-09 19:59:50 74 --sha-r- c:\windows\CT4CET.bin 2008-10-09 22:31:18 8192 --sha-w- c:\windows\users\default\NTUSER.DAT ============= FINISH: 20:28:46.24 ===============