DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 10:43:43.03 on Mon 03/02/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.582 [GMT -5:00] AV: McAfee VirusScan *On-access scanning enabled* (Updated) FW: McAfee Personal Firewall *enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\WINDOWS\system32\java.exe C:\Program Files\McAfee\VirusScan\McShield.exe C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINDOWS\vVX1000.exe C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\I8kfanGUI\I8kfanGUI.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\WlanCU.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Documents and Settings\Amit Cholkar\Desktop\New Folder\dds.scr ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uStart Page = about:blank uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {718dc1e8-1a6a-4870-a9ce-52c5ba124d1e} - c:\windows\system32\fccYrQkH.dll BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [ares] "c:\program files\ares\Ares.exe" -h uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [i8kfangui] c:\program files\i8kfangui\I8kfanGUI.exe /startup uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [ATIModeChange] Ati2mdxx.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [PCTVOICE] pctspk.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AdaptecDirectCD] "c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe" mRun: [VX1000] c:\windows\vVX1000.exe mRun: [AS00_Gear511] c:\program files\netgear\wg511scu\utility\Gear511.exe -hide mRun: [ddoctorv2] "c:\program files\comcast\desktop doctor\bin\sprtcmd.exe" /P ddoctorv2 mRun: [] mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\symant~1.lnk - c:\program files\microsoft office\office\1033\OLFSNT40.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\windows\installer\{bdc88e5a-f47b-4314-ab38-994592e32c95}\NewShortcut1.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178121127344 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} - hxxp://www.ooxtv.com/livetv.ocx DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://mwmus.webex.com/client/v_mywebex-mwm/mywebex/ieatgpc.cab AppInit_DLLs: fmecwm.dll aamuhw.dll pdrxge.dll suvbys.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\amitch~1\applic~1\mozilla\firefox\profiles\06w85h01.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - about:blank FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll ============= SERVICES / DRIVERS =============== R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [2006-12-19 20480] R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-28 201320] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664] R2 LinksysUpdater;Linksys Updater;c:\program files\linksys\linksys updater\bin\LinksysUpdater.exe [2008-1-15 204800] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-1-28 359248] R2 McShield;McAfee Real-time Scanner;c:\program files\mcafee\virusscan\Mcshield.exe [2009-1-28 144704] R3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2008-2-8 16194] R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-1-28 695624] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-1-28 79304] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-1-28 35240] R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-1-28 40488] R3 NETGEAR_WG511_SERVICE;NETGEAR WG511T Wireless Adapter Service;c:\windows\system32\drivers\wg511nd5.sys [2008-2-8 449888] S3 mam4410c;mam4410c;c:\windows\system32\drivers\mam4410c.sys [2008-10-29 24784] S3 mam4410m;mam4410m;c:\windows\system32\drivers\mam4410m.sys [2008-10-29 25044] S3 mam4410u;mam4410u;c:\windows\system32\drivers\mam4410u.sys [2008-10-29 52309] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-1-28 33832] S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys --> c:\windows\system32\drivers\wg111v2.sys [?] S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\SiS163u.sys [2004-12-31 167424] =============== Created Last 30 ================ 2009-03-02 10:17 --d----- C:\GRAPHPAP 2009-02-24 22:04 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat 2009-02-22 16:03 410,984 a------- c:\windows\system32\deploytk.dll 2009-02-09 13:46 --d----- c:\program files\Trend Micro 2009-02-08 14:00 --d----- c:\docume~1\amitch~1\applic~1\Malwarebytes 2009-02-08 14:00 15,504 a------- c:\windows\system32\drivers\mbam.sys 2009-02-08 14:00 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-08 14:00 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-02-08 14:00 --d----- c:\program files\Malwarebytes' Anti-Malware 2009-02-08 12:46 --d----- c:\program files\Spybot - Search & Destroy 2009-02-08 10:39 --d----- c:\windows\system32\XPSViewer 2009-02-08 10:38 117,760 a------- c:\windows\system32\prntvpt.dll 2009-02-08 10:38 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-02-08 10:38 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-02-08 10:38 1,676,288 a------- c:\windows\system32\xpssvcs.dll 2009-02-08 10:38 575,488 a------- c:\windows\system32\xpsshhdr.dll 2009-02-08 10:38 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll 2009-02-08 10:38 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll 2009-02-08 10:38 --d----- C:\d490a21c921a8415de7d5a175f 2009-02-07 10:19 --d----- c:\temp\sTMP3 2009-02-07 10:19 --d----- c:\windows\system32\Z55 2009-02-07 10:19 --d----- c:\windows\system32\x13 2009-02-07 10:19 --d----- C:\Temp ==================== Find3M ==================== 2008-12-20 18:15 826,368 a------- c:\windows\system32\wininet.dll 2008-12-07 11:37 17 a------- c:\program files\stinger10000457.opt 2008-12-07 09:30 2,747,911 a------- c:\program files\stinger10000457.exe 1998-12-08 13:53 186,368 ac------ c:\program files\common files\IRAREG.DLL 1998-12-08 13:53 99,840 ac------ c:\program files\common files\IRAABOUT.DLL 1998-12-08 13:53 70,144 ac------ c:\program files\common files\IRAMDMTR.DLL 1998-12-08 13:53 48,640 ac------ c:\program files\common files\IRALPTTR.DLL 1998-12-08 13:53 31,744 ac------ c:\program files\common files\IRAWEBTR.DLL 1998-12-08 13:53 17,920 ac------ c:\program files\common files\IRASRIAL.DLL 1984-08-08 11:04 500 ac--h--- c:\docume~1\amitch~1\applic~1\MSWWINEDRVM7.DLL 2008-05-15 13:46 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008051520080516\index.dat ============= FINISH: 10:45:06.48 ===============