DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 17:13:51.34 on Sun 03/01/2009 Internet Explorer: 7.0.6001.18000 Microsoft� Windows Vista� Home Premium 6.0.6001.1.1252.1.1033.18.2039.931 [GMT -5:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agrsmsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\BigFix\bigfix.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Chad\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JNYY8WTV\dds[1].scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com uStart Page = hxxp://www.yahoo.com/ uDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=&Br=EM&Loc=ENG_US&Sys=DTP&M=T5274 uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=&Br=EM&Loc=ENG_US&Sys=DTP&M=T5274 mDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=&Br=EM&Loc=ENG_US&Sys=DTP&M=T5274 mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com mSearchAssistant = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&SubCH=&Br=EM&Loc=ENG_US&Sys=DTP&M=T5274 uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll BHO: NoExplorer - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.6\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\windows\system32\BAE.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.6\CoIEPlg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [osCheck] "c:\program files\norton 360\osCheck.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [NWEReboot] mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\bigfix.lnk - c:\program files\bigfix\bigfix.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\ipsdefs\20080923.001\IDSvix86.sys [2008-9-25 270384] R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-17 149352] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-9-9 99376] R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-2-19 41008] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888] S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184] =============== Created Last 30 ================ 2009-03-01 17:11 --d----- c:\programdata\AV1 2009-03-01 17:11 --d----- c:\progra~2\AV1 2009-02-25 17:46 410,984 a------- c:\windows\system32\deploytk.dll 2009-02-23 20:03 --d----- c:\program files\MagicDVDRipper 2009-02-19 11:31 24,112 a------- c:\windows\system32\drivers\SymIMV.sys 2009-02-19 11:31 9,844 a------- c:\windows\system32\drivers\SymRedir.cat 2009-02-19 11:31 1,611 a------- c:\windows\system32\drivers\SymRedir.inf 2009-02-19 11:31 41,008 a------- c:\windows\system32\drivers\symndisv.sys 2009-02-19 11:31 184,496 a------- c:\windows\system32\drivers\symtdi.sys 2009-02-19 11:31 96,560 a------- c:\windows\system32\drivers\symfw.sys 2009-02-19 11:31 38,576 a------- c:\windows\system32\drivers\symids.sys 2009-02-19 11:31 22,320 a------- c:\windows\system32\drivers\symredrv.sys 2009-02-19 11:31 13,616 a------- c:\windows\system32\drivers\symdns.sys 2009-02-18 19:26 --d----- C:\iSofterOutput 2009-02-18 19:10 45,056 a------- c:\windows\system32\wnaspi32.dll 2009-02-18 19:10 16,512 a------- c:\windows\system32\drivers\aspi32.sys 2009-02-18 19:10 5,600 a------- c:\windows\system\winaspi.dll 2009-02-18 19:10 4,672 a------- c:\windows\system\wowpost.exe 2009-02-18 19:10 --d----- c:\program files\Adaptec ASPI 2009-02-18 19:10 761,856 a------- c:\windows\system32\xvidcore.dll 2009-02-18 19:10 716,800 a------- c:\windows\system32\lameACM.acm 2009-02-18 19:10 180,224 a------- c:\windows\system32\xvidvfw.dll 2009-02-18 19:10 414 a------- c:\windows\system32\lame_acm.xml 2009-02-18 19:10 --d----- c:\program files\iSofter 2009-02-15 15:40 428,544 a------- c:\windows\system32\EncDec.dll 2009-02-15 15:40 217,088 a------- c:\windows\system32\psisrndr.ax 2009-02-15 15:40 293,376 a------- c:\windows\system32\psisdecd.dll 2009-02-15 15:40 177,664 a------- c:\windows\system32\mpg2splt.ax 2009-02-15 15:40 80,896 a------- c:\windows\system32\MSNP.ax 2009-02-15 14:06 a-d----- c:\programdata\TEMP 2009-02-13 18:52 --d----- c:\users\chad\appdata\roaming\AVS4YOU 2009-02-13 18:52 --d----- c:\programdata\AVS4YOU 2009-02-13 18:52 --d----- c:\progra~2\AVS4YOU 2009-02-13 18:51 --d----- c:\program files\common files\AVSMedia 2009-02-13 18:51 1,700,352 a------- c:\windows\system32\GdiPlus.dll 2009-02-13 18:51 974,848 a------- c:\windows\system32\mfc70.dll 2009-02-13 18:51 487,424 a------- c:\windows\system32\msvcp70.dll 2009-02-13 18:51 24,576 a------- c:\windows\system32\msxml3a.dll 2009-02-11 16:45 1,383,424 a------- c:\windows\system32\mshtml.tlb 2009-02-11 16:45 827,392 a------- c:\windows\system32\wininet.dll 2009-02-06 06:46 --d----- c:\program files\Trend Micro ==================== Find3M ==================== 2009-02-27 23:40 86,016 a------- c:\windows\inf\infstor.dat 2009-02-27 23:40 51,200 a------- c:\windows\inf\infpub.dat 2009-02-27 23:40 86,016 a------- c:\windows\inf\infstrng.dat 2009-02-13 18:55 87,608 a------- c:\users\chad\appdata\roaming\inst.exe 2009-02-13 18:55 47,360 a------- c:\users\chad\appdata\roaming\pcouffin.sys 2009-01-08 22:01 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS 2009-01-08 22:01 10,635 a------- c:\windows\system32\drivers\SYMEVENT.CAT 2009-01-08 22:01 806 a------- c:\windows\system32\drivers\SYMEVENT.INF 2008-12-12 12:41 243,840 a------- c:\windows\system32\ZuneWlanCfgSvc.exe 2008-12-10 19:33 200,704 a------- c:\windows\system32\dtu100.dll 2008-12-10 19:33 86,016 a------- c:\windows\system32\dpl100.dll 2008-09-23 18:14 0 a------- c:\users\chad\appdata\roaming\wklnhst.dat 2008-07-28 15:48 665,600 a------- c:\windows\inf\drvindex.dat 2008-01-20 21:43 174 a--sh--- c:\program files\desktop.ini 2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat 2008-11-30 10:38 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat 2008-11-30 10:38 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 2008-11-30 10:38 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat ============= FINISH: 17:14:35.29 ===============