DDS (Ver_09-02-01.01) - NTFSx86
Run by Jim Black at 21:09:59.44 on Sat 02/07/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.99 [GMT -6:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\soundman.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\WINDOWS\system32\FSRremoS.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Qwest\Quickcare\agent\bin\bcont.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Jim Black\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://home.live.com/default.aspx?wa=wsignin1.0
uLocal Page = \blank.htm
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uWindow Title = Windows Internet Explorer provided by Qwest
uDefault_Page_URL = hxxp://qwest.live.com
uSearch Bar =
mDefault_Page_URL = hxxp://qwest.live.com
mStart Page = hxxp://qwest.live.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
mWinlogon: System=c:\windows\system32\svcnost.exe,
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: NoExplorer - No File
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\orbitdownloader\GrabPro.dll
TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [Window Washer] "c:\program files\webroot\washer\wwDisp.exe"
uRun: [PhotoShow Deluxe Media Manager] "c:\progra~1\nero\data\xtras\mssysmgr.exe"
uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe"
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
mRun: [vptray] "c:\progra~1\symant~1\VPTray.exe"
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [SoundMan] "c:\windows\soundman.exe"
mRun: [PCLEPCI] "c:\progra~1\pinnacle\ppe\ppe.exe"
mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NeroFilterCheck] "c:\windows\system32\NeroCheck.exe"
mRun: [Mouse Suite 98 Daemon] "c:\windows\system32\ICO.EXE"
mRun: [DVDTray] "c:\program files\hp dvd\umbrella\DVDTray.exe"
mRun: [DVDBitSet] "c:\program files\hp dvd\umbrella\DVDBitSet.exe" /NOUI
mRun: [Desktop Calendar XP] c:\program files\desktop calendar xp\Calendar.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [AdaptecDirectCD] "c:\program files\adaptec\easy cd creator 5\directcd\DirectCD.exe"
mRun: [QuickCare] "c:\program files\qwest\quickcare\bin\sprtcmd.exe" /P QuickCare
mRun: [Ad-Watch] "c:\program files\lavasoft\ad-aware\AAWTray.exe"
mRun: [SpySweeper] "c:\program files\webroot\spy sweeper\SpySweeperUI.exe" /startintray
StartupFolder: c:\docume~1\jimbla~1\startm~1\programs\startup\mycork~1.lnk - c:\program files\corkboard\CORK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ncprot~1.lnk - c:\program files\sec\natural color pro\NCProTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\orbit.lnk - c:\program files\orbitdownloader\orbitdm.exe
uPolicies-explorer: NoWindowsUpdate = 0 (0x0)
mPolicies-explorer: NoMSAppLogo5ChannelNotify = 1 (0x1)
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} - hxxp://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
DPF: {41564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - hxxp://launch.gamespyarcade.com/software/launch/alaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-6 64160]
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29808]
R1 DCxxMJPG;Pinnacle DC10plus, Motion-JPEG VideoIO Board;c:\windows\system32\drivers\DCxxMJPG.sys [2002-6-26 132604]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 921936]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-9-27 1813232]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2008-8-9 3585384]
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2007-9-9 598856]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-9-5 99376]
R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [2008-11-21 36224]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090207.003\naveng.sys [2009-2-7 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090207.003\navex15.sys [2009-2-7 876112]
R3 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMOUSE.SYS [2006-2-24 16384]
R3 pelusblf;USB Mouse Low Filter Driver;c:\windows\system32\drivers\PELUSBlf.SYS [2006-2-24 10240]
S3 lne100v5;lne100v5;c:\windows\system32\drivers\lne100v5.sys [2008-11-21 36224]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-9-27 116464]
=============== Created Last 30 ================
2009-02-07 19:11 268 a---h--- C:\sqmdata05.sqm
2009-02-07 19:11 244 a---h--- C:\sqmnoopt05.sqm
2009-02-07 12:51 <DIR> --d----- c:\program files\Trend Micro
2009-02-06 16:47 1,538,928 a------- c:\windows\WRSetup.dll
2009-02-06 08:28 15,688 a------- c:\windows\system32\lsdelete.exe
2009-02-06 05:03 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-02-06 05:02 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-06 05:01 <DIR> --d----- c:\program files\Lavasoft
2009-02-05 20:47 <DIR> --d----- c:\program files\NoAdware
2009-02-05 19:57 17,797 a------- c:\windows\system32\682page.9o
2009-02-05 19:53 7,680 a------- c:\windows\system32\rasha.exe
2009-02-05 18:18 416 ---shr-- C:\autorun.inf
2009-01-28 20:11 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-01-28 19:59 <DIR> --d----- c:\windows\system32\LogFiles
2009-01-18 01:33 <DIR> --d----- c:\docume~1\jimbla~1\applic~1\uTorrent
2009-01-15 22:59 <DIR> --d----- c:\program files\Orbitdownloader
2009-01-15 22:56 <DIR> --d----- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-01-15 22:56 <DIR> --d----- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-01-15 22:33 268 a---h--- C:\sqmdata04.sqm
2009-01-15 22:33 244 a---h--- C:\sqmnoopt04.sqm
2009-01-15 22:10 <DIR> --d----- c:\docume~1\jimbla~1\applic~1\Malwarebytes
2009-01-15 22:10 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-01-15 22:09 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-15 22:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-01-15 22:09 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-01-15 21:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SITEguard
2009-01-15 21:30 <DIR> --d----- c:\program files\common files\iS3
2009-01-15 21:30 <DIR> --d----- c:\docume~1\alluse~1\applic~1\STOPzilla!
2009-01-15 21:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\1291391199
2009-01-12 18:22 <DIR> --d----- c:\docume~1\jimbla~1\applic~1\Search Settings
2009-01-12 17:38 <DIR> --d----- c:\program files\Search Settings
2009-01-12 17:34 274,432 a------- c:\windows\system32\TubeFinder.exe
2009-01-12 17:34 208,500 a------- c:\windows\system32\ReyXpBasics.tlb
2009-01-12 17:34 119,568 a------- c:\windows\system32\VB6FR.DLL
2009-01-12 17:34 364,544 a------- c:\windows\system32\PropertyGrid.ocx
2009-01-12 17:34 84,512 a------- c:\windows\system32\PICCLP32.OCX
2009-01-12 17:34 9,728 a------- c:\windows\system32\PCCLPFR.DLL
2009-01-12 17:34 141,312 a------- c:\windows\system32\MSCMCFR.DLL
2009-01-12 17:34 24,576 a------- c:\windows\system32\ControlSubX.ocx
2009-01-12 17:34 32,768 a------- c:\windows\system32\CMDLGFR.DLL
2009-01-12 17:34 <DIR> --d----- c:\program files\Free FLV Converter
2009-01-12 17:18 <DIR> --d----- c:\docume~1\jimbla~1\applic~1\GrabPro
2009-01-12 16:01 <DIR> --d----- C:\TubeTilla Free
2009-01-12 15:57 <DIR> --d----- c:\windows\system32\XPSViewer
2009-01-12 15:54 14,048 -------- c:\windows\system32\spmsg2.dll
2009-01-12 08:28 <DIR> --d----- c:\program files\KeepV Converter
2009-01-12 02:03 <DIR> --d----- c:\program files\Flash Favorite
2009-01-11 18:59 <DIR> --d----- c:\docume~1\jimbla~1\applic~1\Moyea
==================== Find3M ====================
2009-02-07 19:14 196 a------- c:\windows\system32\drivers\ALCICH.DAT
2009-02-05 19:57 18,288 a------- c:\windows\system32\wtl_dt545.zip
2008-12-11 04:57 333,952 a------- c:\windows\system32\drivers\srv.sys
2008-04-15 17:53 47,360 ac------ c:\docume~1\jimbla~1\applic~1\pcouffin.sys
2008-04-15 17:53 87,608 a------- c:\docume~1\jimbla~1\applic~1\inst.exe
2008-02-02 16:30 451 a------- c:\documents and settings\jim black\reset.cmd
2003-10-01 20:30 0 ac------ c:\program files\update.ini
2008-07-22 06:25 32,768 ac-sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008072220080723\index.dat
============= FINISH: 21:19:37.45 ===============