. DDS (Ver_2011-06-12.02) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 19:28:53 on 2011-06-20 Microsoft� Windows Vista� Home Premium 6.0.6002.2.1252.44.1033.18.3069.1375 [GMT 1:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\taskeng.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\rundll32.exe C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe C:\Windows\system32\nvvsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Program Files\McAfee\Common Framework\naPrdMgr.exe C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe C:\Windows\System32\mobsync.exe C:\Windows\System32\ico.exe C:\Windows\System32\Pmxmiced.exe C:\Windows\System32\nvraidservice.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\sttray.exe C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Users\Colin\AppData\Local\Google\Update\GoogleUpdate.exe C:\Program Files\Steam\steam.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\uTorrent\uTorrent.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Safari\Safari.exe C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe C:\Users\Colin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Colin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Colin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Colin\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\Dsygya.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uStart Page = hxxp://www.google.co.uk/ig uWindow Title = Internet Explorer provided by Dell uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080204 uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [Google Update] "c:\users\colin\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [Steam] "c:\program files\steam\steam.exe" -silent uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode mRun: [PMX Daemon] ICO.EXE mRun: [NVRaidService] c:\windows\system32\nvraidservice.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [] mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [SigmatelSysTrayApp] sttray.exe mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105 IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{9CEE6A1D-34DD-49E9-8A16-0E84E4FD9724} : DhcpNameServer = 192.168.1.254 Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - c:\program files\tiscali\tiscali internet\dlls\tiscalifilter.dll Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL Hosts: 127.0.0.1 www.spywareinfo.com . ============= SERVICES / DRIVERS =============== . R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2007-10-16 31784] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2010-12-21 21504] R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2010-12-21 103744] R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2007-10-16 144704] R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2007-10-16 54608] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-10-16 369256] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-2-4 179712] R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2010-12-21 72680] R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2010-12-21 33960] R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2010-12-21 171272] R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-2-4 18432] R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-2-4 19008] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-6-19 1153368] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-4 30192] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-06-19 22:04:57 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2011-06-19 22:04:57 -------- d-----w- c:\program files\Spybot - Search & Destroy 2011-06-19 21:01:37 388096 ----a-r- c:\users\colin\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-06-19 21:01:36 -------- d-----w- c:\program files\Trend Micro 2011-06-19 19:59:36 221568 ----a-w- c:\windows\system32\drivers\netio.sys 2011-06-19 19:32:42 235008 ----a-w- c:\windows\Dsygya.exe 2011-06-19 19:32:39 144896 --sha-r- c:\windows\system32\localsecv.dll 2011-06-19 19:10:53 -------- d---a-w- c:\users\colin\Electronic Arts 2011-06-17 17:02:12 6962000 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{fab83a85-46ba-47c0-bdd7-962b0c23f740}\mpengine.dll 2011-06-16 08:00:37 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2011-06-16 08:00:36 141104 ----a-w- c:\program files\internet explorer\sqmapi.dll 2011-06-16 08:00:35 1797632 ----a-w- c:\windows\system32\jscript9.dll 2011-06-15 16:24:41 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys 2011-06-15 16:24:32 273408 ----a-w- c:\windows\system32\drivers\afd.sys 2011-06-15 16:24:30 146432 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-06-15 16:24:30 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-15 16:24:29 563712 ----a-w- c:\windows\system32\oleaut32.dll 2011-06-15 16:24:20 739328 ----a-w- c:\windows\system32\inetcomm.dll 2011-06-15 16:24:18 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-15 16:24:17 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-15 16:24:17 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-15 16:24:16 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat 2011-06-10 18:21:37 -------- d-----w- c:\users\colin\appdata\local\Aspyr 2011-06-10 15:56:35 452440 ----a-w- c:\windows\system32\d3dx10_40.dll 2011-06-10 15:56:35 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll 2011-06-10 15:56:33 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll 2011-06-10 15:07:48 -------- d-----w- c:\program files\Aspyr 2011-06-06 20:05:21 -------- d-----w- c:\users\colin\appdata\roaming\Rovio 2011-06-06 20:03:05 -------- d-----w- c:\program files\Rovio 2011-06-06 18:32:09 -------- d-----w- C:\LOGS 2011-06-04 13:13:13 -------- d-----w- c:\program files\MSECache 2011-06-04 10:08:07 -------- d-----w- c:\programdata\Solidshield 2011-06-04 09:59:17 -------- d-----w- c:\users\colin\appdata\local\Origin 2011-06-04 09:58:57 -------- d-----w- c:\program files\Origin Games 2011-06-04 09:58:47 -------- d-----w- c:\program files\Origin 2011-06-04 09:56:25 -------- d-----w- c:\users\colin\appdata\local\Electronic Arts 2011-06-04 09:56:13 -------- d-----w- c:\programdata\Origin . ==================== Find3M ==================== . 2011-04-09 17:55:44 15453336 ----a-w- c:\windows\system32\xlive.dll 2011-04-09 17:55:42 13642904 ----a-w- c:\windows\system32\xlivefnt.dll 2011-04-06 15:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll 2011-04-06 15:20:16 75040 ----a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 15:20:16 197920 ----a-w- c:\windows\system32\dnssdX.dll 2011-04-06 15:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe 2011-03-25 23:48:06 4284416 ----a-w- c:\windows\system32\GPhotos.scr . ============= FINISH: 19:30:04.66 ===============