any help appreciated
here are files requested:
DDS (Ver_09-02-01.01) - NTFSx86
Run by Mr and Mrs C at 9:14:23.44 on 12/03/2009
Internet Explorer: 7.0.6000.16809
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.1014.117 [GMT 0:00]
AV: Kaspersky Internet Security *On-access scanning enabled* (Updated)
FW: Kaspersky Internet Security *enabled*
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\system32\lxdrcoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Windows\sttray.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Common Files\aol\1191035994\ee\aolsoftware.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Lexmark 4900 Series\lxdrmon.exe
C:\Program Files\Lexmark 4900 Series\ezprint.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Mr and Mrs Cafolla\AppData\Local\uweoe.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\AOL 9.0 VR\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\AOL 9.0 VR\shellmon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Mr and Mrs Cafolla\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.aol.co.uk/
uWindow Title = Internet Explorer provided by Dell
mStart Page = hxxp://uk.yahoo.com
mDefault_Page_URL = hxxp://uk.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: NoExplorer - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: NoExplorer - No File
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - c:\program files\lexmark printable web\bho.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [uweoe] "c:\users\mr and mrs cafolla\appdata\local\uweoe.exe" uweoe
uRun: [Free Download Manager] "c:\program files\free download manager\fdm.exe" -autorun
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe"
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [dscactivate] c:\dell\dsca.exe 3
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [HostManager] c:\program files\common files\aol\1191035994\ee\AOLSoftware.exe
mRun: [Unattend0000000001{5DFC4351-6E03-4198-AF51-DDF31529731C}] c:\dell\cfi\RunGo.lnk
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [lxdrmon.exe] "c:\program files\lexmark 4900 series\lxdrmon.exe"
mRun: [EzPrint] "c:\program files\lexmark 4900 series\ezprint.exe"
StartupFolder: c:\users\mrandm~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\wkcalrem.lnk - c:\program files\common files\microsoft shared\works shared\WkCalRem.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 7.0\ie_banner_deny.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 7.0\SCIEPlgn.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.1.4.cab
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Burger%20Shop/Images/stg_drm.ocx
DPF: {21BB8360-F943-447E-98F3-3C22345375A7} - hxxp://webgames.d.tmsrv.com/c=906621dd4ed9bdac4bcd0d09d79df70d/aff=t_01ku1_wg/p/release/playfirst/wg_chocolatier/chocolatier/ChocolatierWeb.1.0.0.13.cab
DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} - hxxp://o.aolcdn.com/pictures/ap/Resources/v2.13/cab/aolpPlugins.10.6.0.8.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} - hxxp://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-big-island-blends/gamehouseplayer.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} - hxxp://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} - hxxp://aolsvc.aol.com/onlinegames/free-trial-diner-dash-flo-on-the-go/ddfotg.1.0.0.33.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game06.zylom.com/activex/zylomgamesplayer.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Amazing%20Adventures%20The%20Lost%20Tomb/Images/armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v10.cab
DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} - hxxp://aolsvc.aol.com/onlinegames/free-trial-wedding-dash/WeddingDash.1.0.0.47.cab
Notify: igfxcui - igfxdev.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll,c:\progra~1\kasper~1\kasper~1.0\r3hook.dll,c:\progra~1\kasper~1\kasper~1.0\adialhk.dll
============= SERVICES / DRIVERS ===============
R0 AFS;AFS;c:\windows\system32\drivers\AFS.SYS [2008-2-1 77004]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2007-10-16 20496]
S3 Boonty Games;Boonty Games;c:\program files\common files\boonty shared\service\Boonty.exe [2008-5-19 69120]
=============== Created Last 30 ================
2009-03-11 08:06 269,824 a------- c:\windows\system32\schannel.dll
2009-03-11 08:06 2,028,032 a------- c:\windows\system32\win32k.sys
2009-03-10 10:15 <DIR> --d----- C:\Downloads
2009-03-10 10:10 <DIR> --d----- c:\users\mrandm~1\appdata\roaming\Free Download Manager
2009-03-10 10:10 <DIR> --d----- c:\program files\Free Download Manager
2009-03-10 09:35 <DIR> --d----- c:\program files\uTorrent
2009-03-10 09:34 <DIR> --d----- c:\users\mrandm~1\appdata\roaming\uTorrent
2009-03-09 23:26 <DIR> --d----- c:\programdata\wmp
2009-03-09 23:26 <DIR> --d----- c:\progra~2\wmp
2009-03-09 23:26 <DIR> --d----- c:\program files\WebMediaPlayer
2009-02-27 07:15 <DIR> --d----- c:\programdata\Ezprint
2009-02-27 07:15 <DIR> --d----- c:\progra~2\Ezprint
2009-02-26 19:30 <DIR> --d----- c:\programdata\Lx_cats
2009-02-26 19:30 <DIR> --d----- c:\progra~2\Lx_cats
2009-02-26 19:28 <DIR> --d----- C:\logs
2009-02-26 19:17 61,218 a------- c:\windows\system32\lxdrprpr.chm
2009-02-26 19:17 360,448 a------- c:\windows\system32\lxdrcoin.dll
2009-02-26 19:14 40,960 a------- c:\windows\system32\lxdrvs.dll
2009-02-26 19:08 1,036,288 a------- c:\windows\system32\lxdrdrs.dll
2009-02-26 19:08 81,920 a------- c:\windows\system32\lxdrcaps.dll
2009-02-26 19:08 69,632 a------- c:\windows\system32\lxdrcnv4.dll
2009-02-26 19:06 <DIR> --d----- c:\program files\Lexmark Toolbar
2009-02-26 19:06 <DIR> --d----- c:\program files\Lexmark Printable Web
2009-02-26 19:06 44 a------- c:\windows\system32\lxdrrwrd.ini
2009-02-26 19:05 17,064 a------- c:\windows\system32\LXDRwupd.exe
2009-02-26 19:05 352,256 a------- c:\windows\system32\LXDRwupd.dll
2009-02-26 19:02 376,832 a------- c:\windows\system32\lxdrcomm.dll
2009-02-26 19:02 765,952 a------- c:\windows\system32\lxdrcomc.dll
2009-02-26 19:02 369,320 a------- c:\windows\system32\lxdrcfg.exe
2009-02-26 19:02 77,906 a------- c:\windows\system32\LXDRcfg.dll
2009-02-26 19:02 2,043 a------- c:\windows\system32\lxdr.loc
2009-02-26 19:02 <DIR> --d----- c:\program files\Lexmark 4900 Series
2009-02-19 16:28 28,672 a----r-- C:\setupSNK.exe
2009-02-19 16:16 <DIR> --d----- C:\Setup
2009-02-15 20:44 1,409 a------- c:\windows\system32\tmpEC428.FOT
2009-02-15 20:44 1,409 a------- c:\windows\system32\tmpB5528.FOT
2009-02-15 20:44 1,409 a------- c:\windows\system32\tmp93328.FOT
2009-02-15 20:44 1,409 a------- c:\windows\system32\tmp7E528.FOT
2009-02-15 20:44 1,409 a------- c:\windows\system32\tmp46628.FOT
2009-02-15 20:44 1,409 a------- c:\windows\system32\tmp31428.FOT
2009-02-15 20:44 1,409 a------- c:\windows\system32\tmp8F028.FOT
2009-02-14 09:34 1,409 a------- c:\windows\system32\tmp527C4.FOT
2009-02-14 09:34 1,409 a------- c:\windows\system32\tmpB51C4.FOT
2009-02-14 09:34 1,409 a------- c:\windows\system32\tmp235C4.FOT
2009-02-14 09:34 1,409 a------- c:\windows\system32\tmp240C4.FOT
2009-02-14 09:33 1,409 a------- c:\windows\system32\tmpE22B4.FOT
2009-02-14 09:33 1,409 a------- c:\windows\system32\tmp1CB94.FOT
2009-02-14 09:33 1,409 a------- c:\windows\system32\tmp87394.FOT
==================== Find3M ====================
2009-03-12 08:31 3,082,232,864 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-03-12 08:07 41,279,960 a--sh--- c:\windows\system32\drivers\fidbox.idx
2009-03-03 16:08 5,340 a------- c:\users\mrandm~1\appdata\roaming\wklnhst.dat
2009-02-26 19:27 86,016 a------- c:\windows\inf\infstrng.dat
2009-02-26 19:27 51,200 a------- c:\windows\inf\infpub.dat
2009-02-26 19:25 86,016 a------- c:\windows\inf\infstor.dat
2009-02-04 10:30 101,287 a------- c:\windows\system32\drivers\klin.dat
2009-02-04 10:30 89,601 a------- c:\windows\system32\drivers\klick.dat
2009-01-15 04:16 826,368 a------- c:\windows\system32\wininet.dll
2009-01-15 04:16 56,320 a------- c:\windows\system32\iesetup.dll
2009-01-15 04:16 52,736 a------- c:\windows\apppatch\iebrshim.dll
2009-01-15 04:15 26,624 a------- c:\windows\system32\ieUnatt.exe
2008-12-14 12:56 174 a--sh--- c:\program files\desktop.ini
2008-06-12 07:02 665,600 a------- c:\windows\inf\drvindex.dat
2008-03-04 22:29 0 a---h--- c:\users\mr and mrs cafolla\hpothb07.dat
2006-11-02 12:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 12:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 09:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2008-05-26 13:48 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-05-26 13:48 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-05-26 13:48 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2007-09-29 10:39 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT
============= FINISH: 9:18:03.16 ===============
Attached File(s)
-
Attach.txt (3.15K)
Number of downloads: 1

Help
This topic is locked

Back to top











