. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.6001.18000 Run by [removed] at 20:15:27 on 2011-08-25 Microsoft� Windows Vista� Home Premium 6.0.6001.1.1252.1.1033.18.2938.901 [GMT -7:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Sandboxie\SbieSvc.exe C:\Windows\RtkAudioService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Sony\VAIO Care\collsvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\DllHost.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\taskeng.exe C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\igfxext.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Sony\VAIO Care\listener.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Windows\system32\taskeng.exe C:\Program Files\Sony\VAIO Care\VCsystray.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\Program Files\Steam\Steam.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Program Files\Sony\VAIO Power Management\SPMService.exe C:\Program Files\Common Files\Steam\SteamService.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Sandboxie\SandboxieRpcSs.exe C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe C:\Program Files\Mozilla Firefox\firefox.exe c:\program files\steam\steamapps\doommonk\team fortress 2\hl2.exe C:\Program Files\Steam\GameOverlayUI.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYR&bmod=SNYR uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SNYR&bmod=SNYR mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYR&bmod=SNYR mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SNYR&bmod=SNYR BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe" uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [VAIOMyMemCenter] "c:\program files\sony\vaio my memory center\VAIO MyMemCenter.exe" 1 mRun: [VAIORegistration] "c:\program files\sony\first experience\WelcomeLauncher.exe" mRun: [VAIOSurvey] "c:\program files\sony\vaio survey\VAIO Sat Survey.exe" mRun: [VWLASU] "c:\program files\sony\vaio wireless wizard\AutoLaunchWLASU.exe" mRun: [ISBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe" mRun: [Unattend0000000001{D7274DFA-7899-48B3-8660-F7C8B10FE4E9}] %PROGRAMFILES%\Sony\First Experience\VAIOWelcome.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{D10402C1-9CDE-4582-A6B7-6C0D33B0E7BC} : DhcpNameServer = 192.168.1.1 Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\maria\appdata\roaming\mozilla\firefox\profiles\12ig9t47.default\ FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R1 MpKslfba6275a;MpKslfba6275a;c:\programdata\microsoft\microsoft antimalware\definition updates\{8fa45220-af18-4c85-b2fc-8399934c61f8}\MpKslfba6275a.sys [2011-8-25 28752] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-8-25 366640] R2 RtkAudioService;Realtek Audio Service;c:\windows\RTKAUDIOSERVICE.EXE [2008-10-29 104992] R2 SampleCollector;Intel(R) Sample Collector;c:\program files\sony\vaio care\collsvc.exe [2011-8-24 122880] R2 VAIO Power Management;VAIO Power Management;c:\program files\sony\vaio power management\SPMService.exe [2008-10-29 415584] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-8-25 22712] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944] R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2011-6-17 128272] R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2008-10-29 9344] S2 VCFw;VAIO Content Folder Watcher;c:\program files\common files\sony shared\vaio content folder watcher\VCFw.exe [2008-9-3 446464] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392] S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2011-8-24 337184] S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2011-8-24 83232] . =============== Created Last 30 ================ . 2011-08-26 02:50:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2011-08-26 02:50:17 -------- d-----w- c:\program files\Spybot - Search & Destroy 2011-08-26 02:24:36 -------- d-----r- C:\Sandbox 2011-08-26 01:46:52 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8fa45220-af18-4c85-b2fc-8399934c61f8}\MpKslfba6275a.sys 2011-08-25 19:07:29 -------- d-----w- c:\program files\common files\Steam 2011-08-25 19:07:18 -------- d-----w- c:\program files\Steam 2011-08-25 19:07:00 -------- d-----w- c:\program files\Sandboxie 2011-08-25 19:03:19 -------- d-----w- c:\users\maria\appdata\local\Mozilla 2011-08-25 18:17:42 -------- d-----w- c:\windows\Intuit 2011-08-25 18:14:45 439632 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{281e0119-8464-4adf-8a25-d3d03accd4e8}\gapaengine.dll 2011-08-25 18:14:34 7152464 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{8fa45220-af18-4c85-b2fc-8399934c61f8}\mpengine.dll 2011-08-25 18:14:09 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-08-25 18:11:20 -------- d-----w- c:\program files\Microsoft Security Client 2011-08-25 18:11:01 -------- d-----w- c:\users\maria\appdata\local\Adobe 2011-08-25 18:10:07 98184 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2011-08-25 18:10:07 902024 ----a-w- c:\windows\system32\drivers\tcpip.sys 2011-08-25 18:10:07 595456 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2011-08-25 18:10:07 438272 ----a-w- c:\windows\system32\IKEEXT.DLL 2011-08-25 18:10:07 328704 ----a-w- c:\windows\system32\BFE.DLL 2011-08-25 18:10:07 220040 ----a-w- c:\windows\system32\drivers\netio.sys 2011-08-25 18:09:49 -------- d-----w- c:\users\maria\appdata\roaming\Malwarebytes 2011-08-25 18:09:44 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-25 18:09:44 -------- d-----w- c:\programdata\Malwarebytes 2011-08-25 18:09:37 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-08-25 18:09:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-08-25 17:26:17 472808 ------w- c:\windows\system32\deployJava1.dll 2011-08-25 17:22:41 2421760 ----a-w- c:\windows\system32\wucltux.dll 2011-08-25 17:22:27 87552 ----a-w- c:\windows\system32\wudriver.dll 2011-08-25 17:22:15 33792 ----a-w- c:\windows\system32\wuapp.exe 2011-08-25 17:22:15 171608 ----a-w- c:\windows\system32\wuwebv.dll 2011-08-25 07:01:26 98304 ------w- c:\windows\system32\VESWinlogon.dll 2011-08-25 06:58:46 -------- d-----w- c:\programdata\Uninstall 2011-08-25 06:57:44 129520 ------w- c:\windows\system32\pxafs.dll 2011-08-25 06:54:28 245408 ------w- c:\windows\system32\unicows.dll 2011-08-25 06:54:28 212480 ------w- c:\windows\system32\PCDLIB32.DLL 2011-08-25 06:54:26 55808 ------w- c:\windows\system32\ArcSoftKsUFilter.dll 2011-08-25 06:54:25 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll 2011-08-25 06:54:24 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll 2011-08-25 06:54:24 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe 2011-08-25 06:54:24 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll 2011-08-25 06:54:24 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll 2011-08-25 06:50:38 114688 ----a-w- c:\program files\windows sidebar\gadgets\ebaygadget.gadget\bin\eBayGadget.dll 2011-08-25 06:43:44 749568 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iKernel.dll 2011-08-25 06:43:44 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\ctor.dll 2011-08-25 06:43:44 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\DotNetInstaller.exe 2011-08-25 06:43:44 323716 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\setup.dll 2011-08-25 06:43:44 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iscript.dll 2011-08-25 06:43:44 192644 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iGdi.dll 2011-08-25 06:43:44 180224 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iuser.dll 2011-08-25 06:43:03 -------- d-----w- c:\program files\OCA Marker 2011-08-25 06:42:28 -------- d-----w- c:\program files\common files\PX Storage Engine 2011-08-25 06:42:28 -------- d-----w- c:\program files\common files\Napster Shared 2011-08-25 06:42:17 -------- d-----w- c:\programdata\Napster 2011-08-25 06:42:16 -------- d-----w- c:\program files\Napster 2011-08-25 06:40:53 33104 ------w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll 2011-08-25 06:40:53 32592 ------w- c:\windows\system32\msonpmon.dll 2011-08-25 06:40:04 -------- d-----w- c:\windows\PCHEALTH 2011-08-25 06:38:00 -------- d-----w- c:\program files\common files\supportsoft 2011-08-25 06:37:54 3518464 ------w- c:\windows\system32\cdintf300.dll 2011-08-25 06:37:54 1843200 ------w- c:\windows\system32\acXMLParser.dll 2011-08-25 06:36:41 -------- d-----w- c:\programdata\Intuit 2011-08-25 06:36:41 -------- d-----w- c:\program files\Intuit 2011-08-25 06:36:41 -------- d-----w- c:\program files\common files\Intuit 2011-08-25 06:36:23 -------- d-----w- c:\programdata\SQL Anywhere 10 2011-08-25 06:36:23 -------- d-----w- c:\programdata\COMMON FILES 2011-08-25 06:36:17 -------- d-----w- c:\program files\MSXML 4.0 2011-08-25 06:31:12 -------- d-----w- c:\windows\Sonysys . ==================== Find3M ==================== . . ============= FINISH: 20:18:47.37 ===============