Thanks in advance for any help.
DDS (Ver_09-05-14.01) - NTFSx86
Run by Zvi Schiff at 18:42:34.62 on 11-Jun-09
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1255.972.1033.18.1023.503 [GMT 3:00]
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
F:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
F:\WINDOWS\System32\svchost.exe -k netsvcs
F:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
F:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
F:\WINDOWS\system32\spoolsv.exe
svchost.exe
F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
F:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
F:\Program Files\Java\jre6\bin\jqs.exe
F:\WINDOWS\system32\svchost.exe -k imgsvc
F:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
F:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
F:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
F:\Program Files\iriver\iriver plus 2\iAgent2.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\Program Files\OpenOffice.org 2.4\program\soffice.exe
F:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
F:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
F:\WINDOWS\explorer.exe
F:\Documents and Settings\Zvi Schiff\Desktop\dds.scr
F:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - f:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - f:\progra~1\spybot~1\SDHelper.dll
BHO: {54B02808-B60E-44CD-A72D-9865117E4E62} - No File
BHO: WsftpBrowserHelper Class: {601ed020-fb6c-11d3-87d8-0050da59922b} - f:\program files\ws_ftp pro\wsbho2k0.dll
BHO: AGFormHelperObj Class: {6620e618-1ab9-4eb2-aca4-cbbe9066dbe6} - f:\program files\agat\agform\AGFormsHelper.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - f:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - f:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AGForms: {ed2e7de7-07db-4941-a06d-f780b93ba730} - f:\program files\agat\agform\AGForms.dll
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [iPlusAgent2] "f:\program files\iriver\iriver plus 2\iAgent2.exe"
uRun: [SpybotSD TeaTimer] f:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Microsoft Update Time] wuam.exe
mRun: [IMONTRAY] f:\program files\intel\intel® active monitor\imontray.exe
mRun: [RegKillElbyCheck] "f:\program files\elaborate bytes\dvd region killer\ElbyCheck.exe" /L RegKill
mRun: [RegKillTray] "f:\program files\elaborate bytes\dvd region killer\RegKillTray.exe"
mRun: [ISUSPM] "f:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [OSSelectorReinstall] f:\program files\common files\acronis\acronis disk director\oss_reinstall.exe
mRun: [AppleSyncNotifier] f:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "f:\program files\quicktime alternative\QTTask.exe" -atboottime
mRun: [iTunesHelper] "f:\program files\itunes\iTunesHelper.exe"
mRun: [ZoneAlarm Client] "f:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [egui] "f:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [MSConfig] f:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
mRun: [Microsoft Update Time] wuam.exe
mRunServices: [Microsoft Update Time] wuam.exe
mRunServices: [Microsoft DirectX] PDSched.exe
StartupFolder: f:\docume~1\zvisch~1\startm~1\programs\startup\openof~1.lnk - f:\program files\openoffice.org 2.4\program\quickstart.exe
IE: Add to AMV Convert Tool... - f:\program files\mp3 player utilities 4.00\amvconverter\grab.html
IE: Add to Media Manager... - f:\program files\mp3 player utilities 4.00\mediamanager\grab.html
IE: {B863453A-26C3-4e1f-A54D-A2CD196348E9} - f:\program files\icqlite\ICQLite.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - f:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - f:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - f:\progra~1\spybot~1\SDHelper.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120170377109
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140612129937
DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} - hxxp://192.168.10.253:50000/bl_camera.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} - hxxp://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5219/mcfscan.cab
TCP: {79F5B094-2307-4D8F-8CBA-6CA6F12997D2} = 192.116.202.222,192.115.106.10
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - f:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - f:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - f:\docume~1\zvisch~1\applic~1\mozilla\firefox\profiles\mlsjzv2i.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: f:\documents and settings\zvi schiff\application data\mozilla\firefox\profiles\mlsjzv2i.default\extensions\{22119944-ed35-4ab1-910b-e619ea06a115}\components\rfproxy_27.dll
FF - component: f:\documents and settings\zvi schiff\application data\mozilla\firefox\profiles\mlsjzv2i.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: f:\documents and settings\zvi schiff\application data\mozilla\firefox\profiles\mlsjzv2i.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
FF - plugin: f:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: f:\program files\mozilla firefox\plugins\NPZoneSB.dll
FF - plugin: f:\program files\picasa2\npPicasa2.dll
---- FIREFOX POLICIES ----
f:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
============= SERVICES / DRIVERS ===============
R0 IFP900;iriver Internet Audio Player IFP-900;f:\windows\system32\drivers\Ifp900.sys [2005-7-19 14531]
R1 epfwtdir;epfwtdir;f:\windows\system32\drivers\epfwtdir.sys [2007-12-21 33800]
R1 KLIF;KLIF;f:\windows\system32\drivers\klif.sys [2009-3-29 148496]
R1 vsdatant;vsdatant;f:\windows\system32\vsdatant.sys [2004-6-17 353672]
R2 ekrn;Eset Service;f:\program files\eset\eset nod32 antivirus\ekrn.exe [2007-12-21 468224]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;f:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 951632]
R2 vsmon;TrueVector Internet Monitor;f:\windows\system32\zonelabs\vsmon.exe -service --> f:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 RegKill;RegKill;f:\windows\system32\drivers\RegKill.sys [2002-3-10 6144]
S2 AtiBt829;ATI WDM Bt829 Video;f:\windows\system32\drivers\atinbtxx.sys [2001-9-26 60464]
S2 BEATUSB;BEATUSB.sys Eratech USB driver;f:\windows\system32\drivers\beatusb.sys [2004-8-25 10988]
S2 TTDec;ATI WDM Teletext Decoder;f:\windows\system32\drivers\atinttxx.sys [2001-9-26 20960]
S3 ati2mpaa;ati2mpaa;f:\windows\system32\drivers\ati2mpaa.sys [2004-6-15 281856]
S3 ATIVXSXX;ATI Audio Crossbar (ATIVXBAR);f:\windows\system32\drivers\ativxbar.sys [2004-6-15 26624]
S3 cirrus;cirrus;f:\windows\system32\drivers\cirrus.sys [2005-9-7 45696]
S3 DCamVQ110;VQ110 Digital Video Camera;f:\windows\system32\drivers\vq110.sys --> f:\windows\system32\drivers\VQ110.sys [?]
S3 ForteUSB;PERSTEL Chic USB Driver Service;f:\windows\system32\drivers\ForteUSB.sys [2004-6-16 10658]
S3 ICDUSB2;Sony IC Recorder (P);f:\windows\system32\drivers\IcdUsb2.sys [2005-2-3 39048]
S3 RipFlash;RipFlash Digital Music Recoder/Player;f:\windows\system32\drivers\RFlashDX.sys [2004-6-16 11100]
S3 Sflodd;Sflodd; [x]
=============== Created Last 30 ================
2009-06-11 15:16 <DIR> --d----- f:\docume~1\zvisch~1\applic~1\Malwarebytes
2009-06-11 15:15 40,160 a------- f:\windows\system32\drivers\mbamswissarmy.sys
2009-06-11 15:15 <DIR> --d----- f:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-11 15:15 19,096 a------- f:\windows\system32\drivers\mbam.sys
2009-06-11 15:15 <DIR> --d----- f:\program files\Malwarebytes' Anti-Malware
2009-06-10 15:29 <DIR> --d----- f:\documents and settings\zvi schiff\DoctorWeb
2009-06-09 19:12 <DIR> a-dshr-- F:\autorun.inf
2009-06-09 14:53 161,792 a------- f:\windows\SWREG.exe
2009-06-09 14:53 155,136 a------- f:\windows\PEV.exe
2009-06-09 14:53 98,816 a------- f:\windows\sed.exe
2009-06-07 13:26 352 a---h--- f:\windows\nod32fixtemdono.reg
2009-06-07 13:25 <DIR> --d----- f:\program files\ESET
==================== Find3M ====================
2009-06-11 18:42 1,595,355,168 a--sh--- f:\windows\system32\drivers\fidbox.dat
2009-06-11 16:13 18,697,232 a--sh--- f:\windows\system32\drivers\fidbox.idx
2009-06-08 15:29 1,744 a------- f:\windows\system32\d3d9caps.dat
2009-04-21 17:09 4,212 a---h--- f:\windows\system32\zllictbl.dat
2009-03-30 16:56 48,728 a---h--- f:\windows\system32\mlfcache.dat
2008-02-12 16:14 32 a------- f:\docume~1\alluse~1\applic~1\ezsid.dat
2006-11-19 19:24 252 a------- f:\documents and settings\zvi schiff\test.dat
2003-05-07 18:13 131,072 a------- f:\windows\inf\DriverInstaller.exe
============= FINISH: 18:43:53.03 ===============
Attached File(s)
-
Attach.txt.zip (4.12K)
Number of downloads: 3

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top
button at the top bar of this topic and Track this Topic. The topics you are tracking can be found
button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
area. Do not include the word "Code".
button.
line here in your next reply.
and wait for the scan to finish.
and save the logfile to your desktop.








