. DDS (Ver_11-05-19.01) - NTFSx86 Internet Explorer: 9.0.7930.16406 BrowserJavaVersion: 1.6.0_20 Run by [removed] at 10:53:23 on 2011-05-22 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.1022.329 [GMT -4:00] . AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k apphost C:\Windows\system32\svchost.exe -k ftpsvc C:\Windows\system32\inetsrv\inetinfo.exe C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\sppsvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k iissvcs C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Documents and Settings\Tracey\Downloads\dds.com C:\Windows\system32\WSCRIPT.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uDefault_Page_URL = hxxp://www.msn.com uStart Page = hxxp://www.msn.com uWindow Title = BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:\program files\stopzilla!\SZIEBHO.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File TB: {9565115D-C7D6-46D3-BD63-B67B481A4368} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey StartupFolder: c:\users\tracey\appdata\roaming\microsoft\windows\start menu\programs\startup\PdaNet Desktop.lnk.disabled uPolicies-explorer: HideSCAHealth = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\users\tracey\appdata\roaming\mozilla\firefox\profiles\t8mhl3m6.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - PageRage Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/web?src=ffb&systemid=2&q= FF - component: c:\program files\bearshare applications\mediabar\datamngr\firefoxextension\components\DataMngrHlp.dll FF - component: c:\users\tracey\appdata\roaming\mozilla\firefox\profiles\t8mhl3m6.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll FF - component: c:\users\tracey\appdata\roaming\mozilla\firefox\profiles\t8mhl3m6.default\extensions\[removed]\components\FFHst.dll FF - component: c:\users\tracey\appdata\roaming\mozilla\firefox\profiles\t8mhl3m6.default\extensions\[removed]\components\coolirisstub.dll FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.51204.0\npctrlui.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\picasa2\npPicasa2.dll FF - plugin: c:\program files\picasa2\npPicasa3.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\tracey\appdata\roaming\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\users\tracey\appdata\roaming\mozilla\firefox\profiles\t8mhl3m6.default\extensions\{195a3098-0bd5-4e90-ae22-ba1c540afd1e}\plugins\npGarmin.dll FF - plugin: c:\users\tracey\appdata\roaming\mozilla\firefox\profiles\t8mhl3m6.default\extensions\[removed]\plugins\npcoolirisplugin.dll FF - plugin: c:\users\tracey\appdata\roaming\mozilla\plugins\np-mswmp.dll FF - plugin: c:\windows\system32\wat\npWatWeb.dll . ---- FIREFOX POLICIES ---- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true ============= SERVICES / DRIVERS =============== . R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [2009-12-7 61328] R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [2009-12-14 163600] R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 165264] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128] R2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2010-2-28 821664] R2 ftpsvc;Microsoft FTP Service;c:\windows\system32\svchost.exe -k ftpsvc [2009-7-13 20992] R2 sftlist;Application Virtualization Client;c:\program files\microsoft application virtualization client\sftlist.exe [2010-4-24 483688] R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-4-1 428640] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] R3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2011-5-1 13312] R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-4-24 550760] R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-4-24 195944] R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-4-24 21864] R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-4-24 19304] R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2010-4-24 209768] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504] S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [2009-12-7 61328] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-5-9 1153368] S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2011-5-2 14336] S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2011-5-2 20736] S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2011-5-2 20096] S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2011-5-2 25088] S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\lgandadb.sys [2011-5-2 25728] S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-24 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352] S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\androidusb.sys [2011-5-1 31312] S3 HtcVCom32;HTC Diagnostic Port;c:\windows\system32\drivers\HtcVComV32.sys [2010-11-20 105984] S3 KMWDFILTERx86;HIDServiceDesc;c:\windows\system32\drivers\KMWDFILTER.sys [2009-4-29 25088] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 43392] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144] S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [2011-5-1 9472] S3 smhwdev;SmartPhone dummy USB PNP Device (Normal);c:\windows\system32\drivers\smhwdev.sys [2011-1-11 100864] S3 smhwser;USB Device for Legacy Serial Communication (Normal);c:\windows\system32\drivers\smhwser.sys [2011-1-11 108032] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-9-28 1343400] S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040] S4 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; [x] . =============== Created Last 30 ================ . 2011-05-20 20:50:55 -------- d-----w- c:\program files\Trend Micro 2011-05-20 20:43:01 -------- d-----w- c:\windows\Panther 2011-05-20 20:08:23 -------- d-----w- c:\windows\system32\FxsTmp 2011-05-20 20:08:23 -------- d-----w- c:\windows\addins 2011-05-13 13:42:35 -------- d--h--w- c:\programdata\CanonIJPLM 2011-05-13 13:32:31 69632 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPP97.DLL 2011-05-13 13:32:31 27136 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPD97.DLL 2011-05-13 13:31:58 223744 ----a-w- c:\windows\system32\CNMLM97.DLL 2011-05-13 13:30:56 -------- d--h--w- c:\program files\Canon 2011-05-10 02:00:55 -------- d--h--w- c:\programdata\Spybot - Search & Destroy 2011-05-10 02:00:55 -------- d--h--w- c:\program files\Spybot - Search & Destroy 2011-05-02 17:12:54 -------- d--h--w- c:\users\tracey\appdata\local\MediaGet2 2011-05-02 14:56:34 25088 ----a-w- c:\windows\system32\drivers\lgandmodem.sys 2011-05-02 14:56:34 20736 ----a-w- c:\windows\system32\drivers\lganddiag.sys 2011-05-02 14:56:34 20096 ----a-w- c:\windows\system32\drivers\lgandgps.sys 2011-05-02 14:56:33 25728 ----a-w- c:\windows\system32\drivers\lgandadb.sys 2011-05-02 14:56:33 14336 ----a-w- c:\windows\system32\drivers\lgandbus.sys 2011-05-02 14:56:32 -------- d--h--w- c:\program files\LG Electronics 2011-05-02 14:55:42 -------- d-----w- C:\LGVS740 2011-05-01 16:49:19 9472 ----a-w- c:\windows\system32\drivers\pnetmdm.sys 2011-05-01 16:49:19 31312 ----a-w- c:\windows\system32\drivers\androidusb.sys 2011-05-01 16:49:19 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys 2011-05-01 15:00:27 -------- d--h--w- c:\users\tracey\appdata\roaming\HW group 2011-05-01 14:58:00 -------- d--h--w- c:\program files\HW group 2011-05-01 00:48:26 -------- d--h--w- c:\users\tracey\appdata\roaming\Malwarebytes 2011-05-01 00:48:21 -------- d--h--w- c:\programdata\Malwarebytes 2011-05-01 00:48:18 -------- d--h--w- c:\program files\Malwarebytes' Anti-Malware 2011-04-30 12:11:09 -------- d-----w- C:\symbols 2011-04-29 23:12:28 -------- d-----w- C:\LG 2011-04-29 22:55:24 53248 ----a-w- c:\windows\system32\CommonDL.dll 2011-04-29 22:55:24 44544 ----a-w- c:\windows\system32\msxml4a.dll 2011-04-29 22:55:22 -------- d--h--w- c:\programdata\LGMOBILEAX 2011-04-26 23:30:20 -------- d--h--w- c:\program files\AnyBizSoft 2011-04-25 01:42:27 89048 ---ha-w- c:\program files\mozilla firefox\libEGL.dll 2011-04-25 01:42:27 781272 ---ha-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-04-25 01:42:27 465880 ---ha-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-04-25 01:42:27 1892184 ---ha-w- c:\program files\mozilla firefox\d3dx9_42.dll 2011-04-25 01:42:27 1874904 ---ha-w- c:\program files\mozilla firefox\mozjs.dll 2011-04-25 01:42:27 15832 ---ha-w- c:\program files\mozilla firefox\mozalloc.dll 2011-04-25 01:42:26 1974616 ---ha-w- c:\program files\mozilla firefox\D3DCompiler_42.dll 2011-04-25 01:42:26 142296 ---ha-w- c:\program files\mozilla firefox\components\browsercomps.dll . ==================== Find3M ==================== . 2011-04-19 18:19:30 0 ----a-w- c:\windows\system32\ConduitEngine.tmp 2011-04-01 05:11:10 4333280 ----a-w- c:\windows\system32\drivers\LVUVC.sys 2011-04-01 05:10:46 539232 ----a-w- c:\windows\system32\LVUI2RC.dll 2011-04-01 05:10:24 543328 ----a-w- c:\windows\system32\LVUI2.dll 2011-04-01 05:09:48 291424 ----a-w- c:\windows\system32\drivers\lvrs.sys 2011-04-01 05:08:56 195168 ----a-w- c:\windows\system32\lvci13251014.dll 2011-04-01 05:08:36 301664 ----a-w- c:\windows\system32\LVCodec2.dll 2011-04-01 05:07:02 10877272 ----a-w- c:\windows\system32\LogiDPP.dll 2011-04-01 05:07:02 102744 ----a-w- c:\windows\system32\LogiDPPApp.exe 2011-04-01 05:06:56 331608 ----a-w- c:\windows\system32\DevManagerCore.dll 2011-04-01 04:56:20 39318 ----a-w- c:\windows\system32\Repository.reg 2011-03-25 23:48:06 4284416 ----a-w- c:\windows\system32\GPhotos.scr . ============= FINISH: 10:54:52.22 ===============