DDS (Version 1.0) - NTFSx86 Run by [removed] at 2:20:11.59 on Sat 12/06/2008 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.763 [GMT -8:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\AlienGUIse\wbload.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Logitech\G-series Software\LGDCore.exe C:\Program Files\Logitech\G-series Software\LCDMon.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Winferno\Secure IE\SIEPulse.exe C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe C:\program files\steam\steam.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe c:\program files\common files\mcafee\mna\mcnasvc.exe C:\WINDOWS\DvzCommon\DvzMsgr.exe C:\Program Files\Palm\Hotsync.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\IC Media Corp\ICM532\Launchpad.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\system32\Pen_Tablet.exe C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe C:\WINDOWS\system32\Pen_Tablet.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\Winferno\Secure IE\SecureIE.exe C:\Program Files\Windows Defender\MpCmdRun.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Authorized User\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = about:blank uWindow Title = Windows Internet Explorer provided by Comcast mStart Page = hxxp://www.comcast.net/ mWindow Title = Windows Internet Explorer provided by Comcast uInternet Settings,ProxyOverride = *.local uURLSearchHooks: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll mWinlogon: SFCDisable=-99 (0xffffff9d) BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll BHO: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll TB: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll uRun: [Steam] "c:\program files\steam\steam.exe" -silent uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe" -NoStart uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [nah_Shell] c:\documents and settings\authorized user\nah_qehg.exe uRun: [HPseti] "c:\documents and settings\authorized user\application data\google\runhh6110411.exe" uRun: [Intelinet] c:\program files\intelinet\Intelinet.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [] mRun: [Launch LGDCore] "c:\program files\logitech\g-series software\LGDCore.exe" /SHOWHIDE mRun: [Launch LCDMon] "c:\program files\logitech\g-series software\LCDMon.exe" mRun: [Lexmark X1100 Series] "c:\program files\lexmark x1100 series\lxbkbmgr.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe mRun: [tgcmd] c:\program files\support.com\bin\tgcmd.exe /server /startmonitor /deaf mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r mRun: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SIE2004] mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [SIE2007] "c:\program files\winferno\secure ie\SIEPulse.exe" mRun: [Corel Photo Downloader] "c:\program files\common files\corel\corel photodownloader\Corel Photo Downloader.exe" -startup StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\datavi~1.lnk - c:\windows\dvzcommon\DvzMsgr.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\interv~1.lnk - c:\program files\intervideo\common\bin\WinCinemaMgr.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\launch~1.lnk - c:\program files\ic media corp.\icm532\Launchpad.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: *.microsoft.com Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: WB - c:\program files\alienguise\fastload.dll AppInit_DLLs: wbsys.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\progra~1\wifd1f~1\MpShHook.dll ============= SERVICES / DRIVERS =============== R0 VOBID;VOBID;c:\windows\system32\drivers\vobid.sys [2003-8-1 29239] R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2006-11-10 207656] R1 vobiw;vobiw;c:\windows\system32\drivers\vobiw.sys [2004-2-20 187392] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\mcafee\siteadvisor\McSACore.exe" [2008-9-5 203280] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-3-13 358736] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2006-11-10 144704] R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-6-1 1373480] R2 WinDefend;Windows Defender;"c:\program files\windows defender\MsMpEng.exe" [2006-11-3 13592] R3 cdrdrv;Cdrdrv;c:\windows\system32\drivers\Cdrdrv.sys [2004-2-3 62976] R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2006-11-10 605512] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-11-10 79240] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-11-10 35240] R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-11-10 40488] R3 wacommousefilter;Wacom Mouse Filter Driver;c:\windows\system32\drivers\wacommousefilter.sys [2008-6-1 11312] R3 wacomvhid;Wacom Virtual Hid Driver;c:\windows\system32\drivers\wacomvhid.sys [2008-6-1 12848] R3 WacomVKHid;Virtual Keyboard Driver;c:\windows\system32\drivers\WacomVKHid.sys [2008-6-1 11440] S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [2007-8-12 95744] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-11-10 34152] =============== Created Last 30 ================ 2008-12-03 18:44 325 a------- c:\documents and settings\authorized user\nah_log.dat 2008-11-29 08:40 --d----- c:\program files\Trend Micro 2008-11-29 08:31 --d----- c:\docume~1\author~1\applic~1\Malwarebytes 2008-11-29 08:31 15,504 a------- c:\windows\system32\drivers\mbam.sys 2008-11-29 08:31 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2008-11-29 08:31 --d----- c:\program files\Malwarebytes' Anti-Malware 2008-11-29 08:31 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2008-11-28 23:13 --d----- c:\program files\Spybot - Search & Destroy 2008-11-28 23:13 --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2008-11-28 22:43 0 a------- C:\proc.id 2008-11-28 22:43 0 a------- C:\asdasd.asdasd 2008-11-28 22:42 --d----- c:\program files\Intelinet 2008-11-28 18:34 --d----- c:\docume~1\author~1\applic~1\Winferno 2008-11-28 18:32 835,584 a------- c:\windows\system32\WINCTL4.ocx 2008-11-28 18:32 495,616 a------- c:\windows\system32\WINUTIL5.dll 2008-11-28 18:32 393,216 a------- c:\windows\system32\WINLCTL5.dll 2008-11-28 18:32 212,240 a------- c:\windows\system32\RICHTX32.OCX 2008-11-28 18:32 148,480 a------- c:\windows\system32\TLBINF32.DLL 2008-11-28 16:13 --d----- c:\program files\common files\Symantec Shared 2008-11-28 13:13 --d----- c:\windows\system32\Adobe 2008-11-28 12:23 --d----- c:\docume~1\author~1\applic~1\HorizonWimba 2008-11-21 20:09 --d----- c:\program files\iPod 2008-11-21 20:09 --d----- c:\program files\iTunes 2008-11-21 20:09 --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-11-14 23:07 --d----- c:\docume~1\alluse~1\applic~1\ZoomBrowser 2008-11-14 23:06 --d----- c:\program files\Canon 2008-11-14 23:04 --d----- c:\program files\common files\Canon 2008-11-14 12:53 23,896 a---h--- c:\windows\system32\mlfcache.dat 2008-11-12 05:42 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys 2008-11-12 05:42 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll ==================== Find3M ==================== 2008-11-28 17:46 295,424 a------- c:\windows\system32\termsrv.dll 2008-11-28 17:46 507,904 a------- c:\windows\system32\winlogon.exe 2008-10-24 03:21 455,296 a------- c:\windows\system32\drivers\mrxsmb.sys 2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll 2008-09-27 19:22 86,327 ac------ c:\windows\pchealth\helpctr\offlinecache\index.dat 2008-09-15 04:12 1,846,400 a------- c:\windows\system32\win32k.sys 2008-09-09 17:14 1,307,648 a------- c:\windows\system32\msxml6.dll 2008-02-25 16:16 22,328 ac------ c:\docume~1\author~1\applic~1\PnkBstrK.sys 2008-02-01 18:01 5,689 ac------ c:\program files\install.log ============= FINISH: 2:21:02.06 ===============