. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 17:55:00.02 on Tue 04/19/2011 Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_05 Microsoft� Windows Vista� Home Basic 6.0.6002.2.1252.1.1033.18.1406.660 [GMT -4:00] . AV: Trend Micro Titanium *Enabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902} AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Trend Micro Titanium *Enabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe C:\Windows\System32\rundll32.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiSeAgnt.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Trend Micro\Browser Guard\BGUI.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Comodo\SecureEmail\ComodoSE.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Trend Micro\Browser Guard\tmiegsrv.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\wbem\wmiprvse.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Windows\system32\msiexec.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\owner\Family Folder\Documents\Downloads\dds.scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyServer = 168.94.74.68:8080 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: TmIEPlugInBHO Class: {1ca1377b-dc1d-4a52-9585-6e06050fac53} - c:\program files\trend micro\amsp\module\20004\1.5.1464\6.6.1079\TmIEPlg.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: {9F3209E2-334B-41E9-B09C-703F398742E7} - No File BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL BHO: TmBpIeBHO Class: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} - c:\program files\trend micro\amsp\module\20002\6.5.1234\6.5.1234\TmBpIe32.dll BHO: TMIEGBHO Class: {f1ad4a42-ba52-47bc-89df-3f68f24c017f} - c:\program files\trend micro\browser guard\TMAMS.dll TB: TMBGBAR TOOLBAR: {c8137a8d-415d-450c-a1b1-d0c519d45296} - c:\program files\trend micro\browser guard\tmieg.dll uRun: [Sidebar] "c:\program files\windows sidebar\Sidebar.exe" /autorun uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe" uRun: [RegistryBooster] "c:\program files\uniblue\registrybooster\launcher.exe" delay 20000 uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [RtHDVCpl] "c:\windows\RtHDVCpl.exe" mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [PWRISOVM.EXE] "c:\program files\poweriso\PWRISOVM.EXE" mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [Trend Micro Titanium] "c:\program files\trend micro\titanium\uiframework\uiWinMgr.exe" -set Silent "1" SplashURL "" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [Trend Micro RUBotted V2.0 Beta] c:\program files\trend micro\rubotted\RUBottedGUI.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Trend Micro Client Framework] "c:\program files\trend micro\uniclient\uifrmwrk\UIWatchDog.exe" mRun: [Trend Micro Browser Guard] "c:\program files\trend micro\browser guard\BGUI.EXE" StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\ymetray.lnk - c:\program files\yahoo!\yahoo! music jukebox\ymetray.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll LSP: c:\windows\system32\CEmLSP.dll Trusted Zone: jhancock.com Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - c:\program files\trend micro\amsp\module\20002\6.5.1234\6.5.1234\TmBpIe32.dll Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - c:\program files\trend micro\amsp\module\20004\1.5.1464\6.6.1079\TmIEPlg.dll AppInit_DLLs: oepl.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\x634e9zy.default\ FF - prefs.js: network.proxy.ftp - 168.94.74.68 FF - prefs.js: network.proxy.ftp_port - 8080 FF - prefs.js: network.proxy.gopher - 168.94.74.68 FF - prefs.js: network.proxy.gopher_port - 8080 FF - prefs.js: network.proxy.http - 168.94.74.68 FF - prefs.js: network.proxy.http_port - 8080 FF - prefs.js: network.proxy.socks - 168.94.74.68 FF - prefs.js: network.proxy.socks_port - 8080 FF - prefs.js: network.proxy.ssl - 168.94.74.68 FF - prefs.js: network.proxy.ssl_port - 8080 FF - prefs.js: network.proxy.type - 0 FF - component: c:\program files\trend micro\amsp\module\20004\1.5.1464\6.6.1079\firefoxextension\components\TmFFExt.dll FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL FF - plugin: c:\program files\final codecs\mozillaplugins\nppl3260.dll FF - plugin: c:\program files\final codecs\mozillaplugins\nprjplug.dll FF - plugin: c:\program files\final codecs\mozillaplugins\nprpjplug.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: Trend Micro NSC Firefox Extension: {22C7F6C6-8D67-4534-92B5-529A0EC09405} - c:\program files\trend micro\amsp\module\20004\1.5.1464\6.6.1079\firefoxextension FF - Ext: Fire.fm: {6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3} - %profile%\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3} FF - Ext: Answers: {C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51} - %profile%\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51} FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF - Ext: BetterPrivacy: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} - %profile%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 165264] R1 MpKsl91c1a2ec;MpKsl91c1a2ec;c:\programdata\microsoft\microsoft antimalware\definition updates\{f84a5fd0-7c7c-485d-bc59-91d797cb066a}\MpKsl91c1a2ec.sys [2011-4-19 28752] R2 Amsp;Trend Micro Solution Platform;c:\program files\trend micro\amsp\coreServiceShell.exe [2010-12-2 188272] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-24 21504] R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704] R2 RUBotSrv;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\RUBotSrv.exe [2011-2-9 439632] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-9-21 1153368] R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2010-12-2 64080] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 43392] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-6 135664] S3 AppBoosterService;AppBooster Service;c:\program files\common files\2tox common\BoostService.exe [2010-9-21 1550336] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-04-19 18:25:44 28752 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{f84a5fd0-7c7c-485d-bc59-91d797cb066a}\MpKsl91c1a2ec.sys 2011-04-19 05:48:56 388096 ----a-r- c:\users\owner\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-04-19 05:43:26 -------- d-----w- c:\users\owner\appdata\local\Browser Guard 2011-04-18 14:53:51 6792528 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{f84a5fd0-7c7c-485d-bc59-91d797cb066a}\mpengine.dll 2011-04-14 23:35:47 -------- d-----w- c:\users\owner\appdata\roaming\Comodo 2011-04-13 21:35:57 1162240 ----a-w- c:\windows\system32\mfc42u.dll 2011-04-13 21:35:56 1136640 ----a-w- c:\windows\system32\mfc42.dll 2011-04-13 21:35:53 305152 ----a-w- c:\windows\system32\drivers\srv.sys 2011-04-13 21:35:52 146432 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-04-13 21:35:52 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-04-13 21:35:46 86528 ----a-w- c:\windows\system32\dnsrslvr.dll 2011-04-13 21:35:46 25088 ----a-w- c:\windows\system32\dnscacheugc.exe 2011-04-13 21:35:41 2041856 ----a-w- c:\windows\system32\win32k.sys 2011-04-13 21:35:36 739328 ----a-w- c:\windows\system32\inetcomm.dll 2011-04-13 21:35:32 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-04-13 21:35:27 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat 2011-04-12 08:07:13 -------- d-----w- C:\temp 2011-04-05 16:14:26 439632 ------w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{b55bca34-71b8-449f-994a-584b661a1990}\gapaengine.dll 2011-03-25 15:49:15 439632 ------w- c:\progra~2\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll 2011-03-22 22:50:15 1068544 ----a-w- c:\windows\system32\DWrite.dll 2011-03-22 22:50:14 797696 ----a-w- c:\windows\system32\FntCache.dll 2011-03-22 22:50:14 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2011-03-21 17:38:50 691880 ----a-w- c:\windows\system32\CEmLSP.dll 2011-03-21 17:38:48 331432 ----a-w- c:\windows\system32\oepl.dll 2011-03-21 17:38:47 -------- d-----w- c:\program files\Comodo 2011-03-21 14:47:58 -------- d-----w- c:\users\owner\appdata\local\Rootkit . ==================== Find3M ==================== . 2011-02-22 06:21:28 916480 ----a-w- c:\windows\system32\wininet.dll 2011-02-22 06:17:08 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-02-22 06:16:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl 2011-02-22 06:16:40 71680 ----a-w- c:\windows\system32\iesetup.dll 2011-02-22 06:16:40 109056 ----a-w- c:\windows\system32\iesysprep.dll 2011-02-22 05:20:39 385024 ----a-w- c:\windows\system32\html.iec 2011-02-22 04:43:54 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2011-02-22 04:42:38 1638912 ----a-w- c:\windows\system32\mshtml.tlb 2011-02-18 21:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll 2011-02-16 16:16:37 34304 ----a-w- c:\windows\system32\atmlib.dll 2011-02-16 14:02:23 292864 ----a-w- c:\windows\system32\atmfd.dll 2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll 2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll 2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll 2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll 2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv 2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll 2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll 2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll 2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll 2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll 2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll 2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll 2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll 2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll 2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll 2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll 2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll 2011-01-20 14:12:46 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll 2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll 2008-02-24 23:36:18 774144 ----a-w- c:\program files\RngInterstitial.dll . ============= FINISH: 17:56:35.41 ===============