DDS (Ver_09-01-19.01) - NTFSx86 NETWORK
Run by dmykrantz at 22:42:46.78 on Sat 01/24/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.697 [GMT -5:00]
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Hewlett-Packard\IAM\bin\asghost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\dmykrantz\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [USB Safely Remove] c:\program files\usb safely remove\USBSafelyRemove.exe /startup
uRun: [DLD.EXE] c:\program files\download direct\DLD.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [PTHOSTTR] c:\program files\hewlett-packard\hp protecttools security manager\PTHOSTTR.EXE /Start
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [CognizanceTS] rundll32.exe c:\progra~1\hewlet~1\iam\bin\ASTSVCC.dll,RegisterModule
mRun: [Recguard] c:\windows\sminst\Recguard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
mRun: [DefragTaskBar] "c:\program files\ashampoo\ashampoo magical defrag 2\bin\defragTaskBar.exe"
mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\update.exe -silent
mRunOnce: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck
mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{ccbaa1f7-e5e1-48b2-9ed9-a79c6a37ce78}\Icon3E5562ED7.ico
uPolicies-explorer: HideClock = 0 (0x0)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-explorer: StartMenuLogoff = 1 (0x1)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot - search & destroy\SDHelper.dll
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: arsvrhpy - arsvrhpy.dll
Notify: igfxcui - igfxdev.dll
Notify: OneCard - c:\program files\hewlett-packard\iam\bin\ASWLNPkg.dll
AppInit_DLLs: APSHook.dll pwjgwa.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = SbHpNp scecli ASWLNPkg
============= SERVICES / DRIVERS ===============
R0 pxark;pxark;c:\windows\system32\drivers\pxark.sys [2009-1-24 26808]
R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\SafeBoot.sys [2007-4-22 100095]
R0 SbAlg;SbAlg;c:\windows\system32\drivers\SbAlg.sys [2006-10-9 44720]
R0 SbFsLock;SbFsLock;c:\windows\system32\drivers\SbFsLock.sys [2007-3-29 13696]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-9-19 36608]
R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
S0 ati5vgxx;ati5vgxx;c:\windows\system32\drivers\ati5vgxx.sys [2009-1-22 32768]
S1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2006-11-30 31944]
S1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [2007-4-22 5808]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\anti trojan elite\atepmon.sys --> c:\program files\anti trojan elite\ATEPMon.sys [?]
S3 ati5tdxx;ati5tdxx;c:\windows\system32\drivers\ati5tdxx.sys [2009-1-22 32768]
S3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2008-10-2 72264]
S3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2008-10-2 34152]
S3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2008-10-2 168776]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
S4 ASBroker;Logon Session Broker;c:\windows\system32\svchost.exe -k Cognizance [2004-8-4 14336]
S4 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-4 14336]
S4 CSIScanner;CSIScanner;c:\program files\prevxcsi\prevxcsi.exe [2009-1-24 927288]
S4 HpFkCryptService;Drive Encryption Service;c:\program files\hewlett-packard\drive encryption\HpFkCrypt.exe [2007-4-22 221184]
S4 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-10-2 104000]
S4 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2006-11-30 144960]
S4 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2006-11-30 54872]
=============== Created Last 30 ================
2009-01-24 20:27 <DIR> --d----- c:\program files\EsetOnlineScanner
2009-01-24 16:15 114,688 a------- c:\windows\system32\chg.exe
2009-01-24 11:26 <DIR> --dsh--- c:\windows\ftpcache
2009-01-24 09:47 <DIR> --d----- c:\program files\a-squared HiJackFree
2009-01-24 08:53 26,808 a------- c:\windows\system32\drivers\pxark.sys
2009-01-24 08:53 <DIR> --d----- c:\program files\PrevxCSI
2009-01-24 08:53 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PrevxCSI
2009-01-22 23:07 <DIR> --d----- c:\windows\Options
2009-01-22 21:57 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-01-22 21:57 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-22 21:57 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-01-22 16:40 32,768 a------- c:\windows\system32\drivers\ati5vgxx.sys
2009-01-22 15:51 32,768 a------- c:\windows\system32\drivers\ati5tdxx.sys
2009-01-22 15:48 2 a------- C:\2120979980
2009-01-19 11:19 299,552 a------- c:\windows\wmsysprx.prx
2009-01-19 11:18 <DIR> --d----- c:\docume~1\dmykra~1\applic~1\Acoustica
2009-01-19 11:17 <DIR> --d----- c:\program files\Acoustica CD Label Maker
2009-01-18 17:12 15,399 a----r-- c:\windows\system32\drivers\netmotcm.sys
2009-01-13 14:23 <DIR> --d----- c:\docume~1\dmykra~1\applic~1\CoSoSys
2009-01-05 20:41 <DIR> --d----- c:\docume~1\dmykra~1\applic~1\Forte
2009-01-05 20:40 <DIR> --d----- c:\program files\Agent
2009-01-02 23:03 <DIR> --d----- c:\windows\Reflexive Arcade Games - Puzzle
2009-01-02 23:03 <DIR> --d----- c:\program files\Reflexive Arcade Games - Puzzle
2009-01-01 22:05 <DIR> --d----- c:\program files\Guitar Pro 5
2009-01-01 21:52 <DIR> --d----- c:\program files\PowerISO
2009-01-01 15:58 <DIR> --d----- c:\program files\Guitar Pro 4
2009-01-01 11:43 <DIR> --d----- c:\program files\Acoustica Shared Effects
2009-01-01 11:43 <DIR> --d----- c:\program files\Acoustica Beatcraft
2008-12-31 18:50 <DIR> --d----- c:\program files\A73 Piano Station
2008-12-30 21:37 0 a------- c:\windows\BlueFoxStudio_Video.INI
2008-12-30 21:33 <DIR> --d----- c:\program files\Bluefox Studio
2008-12-30 19:56 <DIR> --d----- C:\my dvd
2008-12-30 19:54 67 a------- c:\windows\Easy Avi Divx Xvid to DVD Burner.INI
2008-12-30 19:52 <DIR> --d----- c:\program files\Easy Avi Divx Xvid to DVD Burner
2008-12-30 16:07 <DIR> --d----- c:\docume~1\dmykra~1\applic~1\1ClickDVDCopy
==================== Find3M ====================
2009-01-24 16:44 14,336 a------- c:\windows\system32\svchost.exe
2009-01-23 21:56 14,336 a------- c:\windows\system32\dllcache\svchost.exe
2008-12-20 22:01 18,816 a------- c:\windows\system32\drivers\dvd43llh.sys
2008-11-30 21:40 4,096 a------- c:\windows\d3dx.dat
2008-11-11 15:05 249,856 -------- c:\windows\Setup1.exe
2008-11-11 15:05 73,216 a------- c:\windows\ST6UNST.EXE
2008-10-03 15:43 87,608 a------- c:\docume~1\dmykra~1\applic~1\inst.exe
2008-10-03 15:43 47,360 a------- c:\docume~1\dmykra~1\applic~1\pcouffin.sys
============= FINISH: 22:43:09.12 ===============