. DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17 Run by [removed] at 9:58:00 on 2011-11-06 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1680 [GMT -5:00] . AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\Explorer.EXE . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.dell4me.com/myway uDefault_Page_URL = hxxp://www.dell4me.com/myway uSearch Bar = hxxp://bfc.myway.com/search/de_srchlft.html BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - No File BHO: {A7327C09-B521-4EDB-8509-7D2660C9EC98} - No File BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [nwiz] nwiz.exe /installquiet mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ViewMgr] c:\program files\viewpoint\viewpoint manager\ViewMgr.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [iiovsVgraP.exe] c:\documents and settings\all users\application data\iiovsVgraP.exe mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409 DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} - hxxp://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120692167375 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129856913093 DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} - hxxp://us-download.mcafee.com/products/protected/mvt/mvt.cab DPF: {7B19E477-0FF8-11d4-9914-005004D3B3DB} - hxxp://java.sun.com/products/plugin/1.2/jinstall-122_017-win.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] [removed] TCP: Interfaces\{EC25D4BD-EAE4-44CE-A9AB-369A5798FCD2} : DhcpNameServer = [removed] [removed] [removed] Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - . ============= SERVICES / DRIVERS =============== . S1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-11-11 11608] S1 mferkdk;VSCore mferkdk;\??\c:\program files\mcafee\virusscan enterprise\mferkdk.sys --> c:\program files\mcafee\virusscan enterprise\mferkdk.sys [?] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-11-11 108289] S2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-11-11 185089] S2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-11-11 56816] S2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [2008-11-2 72672] S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-11-5 366152] S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-10-24 24652] S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [2005-11-25 69692] S3 iMSPCLOj;iMSPCLOj;\??\c:\docume~1\samuel~1\locals~1\temp\imspcloj.sys --> c:\docume~1\samuel~1\locals~1\temp\iMSPCLOj.sys [?] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-11-5 22216] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?] S3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [2009-4-4 611584] S3 RCopySys;RCopySys;c:\documents and settings\samuel polio\application data\officeguardian\RCopySys.sys [2008-10-18 6656] S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344] S4 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-3-14 103744] . =============== Created Last 30 ================ . 2011-11-06 02:32:35 -------- d-----w- c:\program files\Free Window Registry Repair 2011-11-05 23:04:50 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes 2011-11-05 23:04:35 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes 2011-11-05 23:04:31 22216 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-11-05 23:04:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-11-05 22:52:11 -------- d-----w- c:\documents and settings\administrator\PrivacIE 2011-11-05 22:51:48 -------- d-sh--w- c:\documents and settings\administrator\IETldCache 2011-11-05 22:42:25 -------- d-----w- C:\7dd5a465ee099c16381b20788ddd 2011-11-05 22:41:02 -------- d-----w- C:\f54bddf08dc70aaa2bb8d9968a7b 2011-10-31 19:12:40 330624 ---ha-w- c:\documents and settings\all users\application data\6DSS92c31Apgjk.exe 2011-10-31 19:10:09 407424 ---ha-w- c:\documents and settings\all users\application data\iiovsVgraP.exe 2011-10-13 01:16:43 -------- d-----w- c:\program files\Bonjour 2011-10-09 18:28:08 -------- d--h--w- c:\documents and settings\all users\application data\WEBREG 2011-10-09 18:16:58 6784 ----a-w- c:\windows\system32\drivers\serscan.sys 2011-10-09 18:16:58 6784 ----a-w- c:\windows\system32\dllcache\serscan.sys 2011-10-09 18:10:20 -------- d-----w- c:\program files\common files\HP 2011-10-09 18:10:18 -------- d-----w- c:\program files\common files\Hewlett-Packard 2011-10-09 18:09:51 -------- d-----w- c:\windows\hpoj4500g510n-z 2011-10-09 18:06:55 -------- d-----w- c:\program files\HP 2011-10-09 18:02:34 316928 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\hpfpp092.dll 2011-10-09 18:02:33 122880 ----a-w- c:\windows\system32\hpf3l092.dll 2011-10-09 18:01:21 315392 ----a-r- c:\windows\system32\hpwvst01.dll 2011-10-09 18:01:19 593920 ----a-r- c:\windows\system32\hpwtscl5.dll 2011-10-09 18:01:18 716288 ----a-r- c:\windows\system32\hpwwiax9.dll 2011-10-08 18:49:57 62976 ------w- c:\windows\system32\dllcache\cdrom.sys 2011-10-08 18:49:57 465920 ------w- c:\windows\system32\imapi2fs.dll 2011-10-08 18:49:57 465920 ------w- c:\windows\system32\dllcache\imapi2fs.dll 2011-10-08 18:49:57 317952 ------w- c:\windows\system32\imapi2.dll 2011-10-08 18:49:57 317952 ------w- c:\windows\system32\dllcache\imapi2.dll . ==================== Find3M ==================== . 2011-09-26 15:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll 2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll 2011-09-09 09:12:13 599040 ----a-w- c:\windows\system32\crypt32.dll 2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys 2011-08-31 03:05:04 83816 ----a-w- c:\windows\system32\dns-sd.exe 2011-08-31 03:05:04 73064 ----a-w- c:\windows\system32\dnssd.dll 2011-08-31 03:05:04 178536 ----a-w- c:\windows\system32\dnssdX.dll 2011-08-22 23:48:55 916480 ----a-w- c:\windows\system32\wininet.dll 2011-08-22 23:48:54 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-08-22 23:48:54 1469440 ----a-w- c:\windows\system32\inetcpl.cpl 2011-08-22 11:56:39 385024 ----a-w- c:\windows\system32\html.iec 2011-08-17 13:49:54 138496 ----a-w- c:\windows\system32\drivers\afd.sys 2005-11-27 20:45:03 76 -c--a-w- c:\program files\image.bat 2005-11-27 20:45:03 76 -c--a-w- c:\program files\buttons.bat 2003-04-29 12:33:00 588120576 -c--a-w- c:\program files\en_vs.net_2003_pro_full.exe 2004-08-04 10:00:00 94784 -csh--w- c:\windows\twain.dll 2008-04-14 00:12:07 50688 --sh--w- c:\windows\twain_32.dll 2011-02-08 13:33:55 978944 --sha-w- c:\windows\system32\mfc42.dll 2008-04-14 00:12:01 57344 --sha-w- c:\windows\system32\msvcirt.dll 2008-04-14 00:12:01 413696 --sha-w- c:\windows\system32\msvcp60.dll 2008-04-14 00:12:01 343040 --sha-w- c:\windows\system32\msvcrt.dll 2010-12-20 17:32:15 551936 --sh--w- c:\windows\system32\oleaut32.dll 2008-04-14 00:12:02 84992 --sha-w- c:\windows\system32\olepro32.dll 2008-04-14 00:12:32 11776 --sh--w- c:\windows\system32\regsvr32.exe . ============= FINISH: 9:59:26.17 ===============