DDS (Ver_09-03-16.01) - NTFSx86
Run by neil at 19:51:33.21 on 10/04/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.5.0_14
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1371 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wltray.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Documents and Settings\neil\Desktop\HiJack.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\neil\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.co.uk/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\twext.exe,
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
uRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [JMB36X IDE Setup] c:\windows\jm\JMInsIDE.exe
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [wltray.exe] c:\windows\system32\wltray.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [EasyTuneVI] c:\program files\gigabyte\et6\ETcall.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [RCSystem] "c:\program files\creative\shared files\module loader\DLLML.exe" RCSystem * -Startup
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [CTHelper] CTHELPER.EXE
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [CTRegRun] c:\windows\CTRegRun.EXE
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [SMSTray] c:\program files\samsung\samsung media studio 5\SMSTray.exe
mRun: [MAAgent] c:\program files\markany\contentsafer\MAAgent.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: yahoo.co.uk\www
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
DPF: {4A8E7724-D54D-47DA-A906-E4B2BF3BBA93} - hxxp://www.downloadstore.bt.com/install/BTVision_5_0_0_8.cab
DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} - hxxp://www.ea.com/downloads/rtpatch/EARTPX.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - hxxp://www.downloadstore.bt.com/install/Entriq_3_7_0_2.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su2/ocx/15106/CTPID.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: ShellHook Class: {88485281-8b4b-4f8d-9ede-82e29a064277} - c:\progra~1\markany\conten~1\MACSMA~1.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, , digiwet.dll
LSA: Notification Packages = scecli
================= FIREFOX ===================
FF - ProfilePath -
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-23 325128]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-1-4 27656]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-23 107272]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-4-6 353672]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-4 903960]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-4 298264]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2008-5-5 598856]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2008-10-8 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2008-10-8 1324056]
S2 ati64si;ati64si;\??\c:\windows\system32\drivers\ati64si.sys --> c:\windows\system32\drivers\ati64si.sys [?]
S2 fips32cup;fips32cup;\??\c:\windows\system32\drivers\fips32cup.sys --> c:\windows\system32\drivers\fips32cup.sys [?]
S2 FLEXnetRemoteAccess;FLEXnet Licensing Service FLEXnetRemoteAccess;c:\temp\1.tmp srv --> c:\temp\1.tmp srv [?]
S2 i386si;i386si;\??\c:\windows\system32\drivers\i386si.sys --> c:\windows\system32\drivers\i386si.sys [?]
S2 ksi32sk;ksi32sk;\??\c:\windows\system32\drivers\ksi32sk.sys --> c:\windows\system32\drivers\ksi32sk.sys [?]
S2 lanmanserverProtectedStorage;Server lanmanserverProtectedStorage;ð%€|0Ö srv --> ð%€|0Ö srv [?]
S2 netsik;netsik;\??\c:\windows\system32\drivers\netsik.sys --> c:\windows\system32\drivers\netsik.sys [?]
S2 PlugPlayclr_optimization_v2.0.50727_32;Plug and Play PlugPlayclr_optimization_v2.0.50727_32;ð%€|Ë srv --> ð%€|Ë srv [?]
S2 port135sik;port135sik;\??\c:\windows\system32\drivers\port135sik.sys --> c:\windows\system32\drivers\port135sik.sys [?]
S2 SCardSvrdmadmin;Smart Card SCardSvrdmadmin;ð%€|0Ö srv --> ð%€|0Ö srv [?]
S2 ShellHWDetectionPlugPlayclr_optimization_v2.0.50727_32;Shell Hardware Detection ShellHWDetectionPlugPlayclr_optimization_v2.0.50727_32;ð%€|0Ö srv --> ð%€|0Ö srv [?]
S2 ws2_32sik;ws2_32sik;\??\c:\windows\system32\drivers\ws2_32sik.sys --> c:\windows\system32\drivers\ws2_32sik.sys [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2008-12-30 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2008-10-8 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2008-10-8 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2008-10-8 72728]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2008-10-8 72728]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\magix\common\database\bin\fbserver.exe [2009-4-9 1527900]
SUnknown GVTDrv;GVTDrv; [x]
=============== Created Last 30 ================
2009-04-10 17:56 <DIR> --d----- c:\program files\Trend Micro
2009-04-10 15:28 102,400 a------- c:\windows\system32\TG_VIEW0607.DLL
2009-04-10 15:28 90,112 a------- c:\windows\system32\TG_SYNC.DLL
2009-04-10 15:28 <DIR> --d----- C:\$temp
2009-04-10 14:18 <DIR> --d----- C:\ConverterOutput
2009-04-10 14:17 92,326 a------- c:\windows\system32\HKCU_GNU.reg
2009-04-10 14:17 6,700 a------- c:\windows\system32\HKLM_GNU.reg
2009-04-10 14:17 60,273 a------- c:\windows\system32\pthreadGC2.dll
2009-04-10 14:17 6,144 a------- c:\windows\system32\ff_acm.acm
2009-04-10 14:17 547 a------- c:\windows\system32\ff_vfw.dll.manifest
2009-04-10 14:17 14,909 a------- c:\windows\system32\A_reg.reg
2009-04-10 14:17 516,096 a------- c:\windows\system32\CLVSDS.ax
2009-04-10 14:17 364,544 a------- c:\windows\system32\cdg.dll
2009-04-10 14:17 348,160 a------- c:\windows\system32\cdga.dll
2009-04-10 14:17 114,688 a------- c:\windows\system32\PropListCtrl.ocx
2009-04-10 14:17 <DIR> --d----- c:\program files\Cucusoft
2009-04-09 20:36 88 a------- c:\windows\MovieEdit.INI
2009-04-09 19:59 46 a------- c:\windows\mxcdr.INI
2009-04-09 16:25 101,376 a------- c:\windows\system32\drivers\ACEDRV07.sys
2009-04-09 16:23 <DIR> --d----- c:\docume~1\alluse~1.win\applic~1\MAGIX
2009-04-09 16:19 245,760 a------- c:\windows\system32\mp4sds32.ax
2009-04-09 16:19 420,240 a------- c:\windows\system32\mpg4c32.dll
2009-04-09 16:19 309,616 a------- c:\windows\system32\wmv8dmod.dll
2009-04-09 16:17 <DIR> --d----- c:\program files\common files\MAGIX Shared
2009-04-09 16:12 1,089,536 a------- c:\windows\system32\ROBOEX32.DLL
2009-04-09 16:12 49,152 a------- c:\windows\system32\INETWH32.dll
2009-04-09 16:12 <DIR> --d----- C:\MAGIX
2009-04-09 16:12 85,504 a------- c:\windows\system32\HtmlWH.dll
2009-04-09 16:12 638,976 a------- c:\windows\system32\mgxoschk.dll
2009-04-09 16:12 5,729 a------- c:\windows\mgxoschk.ini
2009-04-09 16:12 <DIR> --d----- c:\windows\system32\MAGIX
2009-04-09 14:58 <DIR> --d----- C:\FAMILY_GUY_BLUE_HARVEST1
2009-04-08 19:46 <DIR> --d----- c:\program files\DVD Decrypter
2009-04-08 19:44 <DIR> --d----- C:\FAMILY_GUY_BLUE_HARVEST
2009-04-08 19:22 <DIR> --d----- c:\program files\DVD Shrink
2009-04-08 09:12 <DIR> --d----- c:\docume~1\alluse~1.win\applic~1\GRETECH
2009-04-08 09:11 <DIR> --d----- c:\program files\GRETECH
2009-04-06 11:12 4,212 a---h--- c:\windows\system32\zllictbl.dat
2009-04-06 11:12 1,221,512 a------- c:\windows\system32\zpeng25.dll
2009-04-06 11:12 <DIR> --d----- c:\windows\system32\ZoneLabs
2009-04-06 11:12 <DIR> --d----- c:\program files\Zone Labs
2009-04-06 11:12 350,192 a------- c:\windows\system32\vsconfig.xml
2009-04-06 11:11 <DIR> --d----- c:\windows\Internet Logs
2009-04-05 22:35 <DIR> --d----- c:\windows\system32\scripting
2009-04-05 22:35 <DIR> --d----- c:\windows\system32\en
2009-04-05 22:35 <DIR> --d----- c:\windows\system32\bits
2009-04-05 22:35 <DIR> --d----- c:\windows\l2schemas
2009-04-05 22:31 <DIR> --d----- c:\windows\network diagnostic
2009-04-05 22:27 723,456 a------- c:\windows\system32\dllcache\userenv.dll
2009-04-05 01:08 16,384 a------t c:\temp\Perflib_Perfdata_264.dat
2009-04-05 01:08 16,384 a------t c:\temp\Perflib_Perfdata_208.dat
2009-04-05 01:06 16,384 a------t c:\temp\Perflib_Perfdata_254.dat
2009-04-05 01:06 16,384 a------t c:\temp\Perflib_Perfdata_1ac.dat
2009-04-03 21:06 16,384 a------t c:\temp\Perflib_Perfdata_edc.dat
2009-03-24 11:39 16,384 a------t c:\temp\Perflib_Perfdata_5a4.dat
2009-03-22 18:21 20,488 a--s---- c:\temp\2798493143.exe
2009-03-15 21:51 4,268,864 a------- c:\temp\mpengine.dll
2009-03-15 21:51 <DIR> --d----- C:\4d0ddd2e7d929057268cd378c97b
2009-03-14 22:08 <DIR> --d----- c:\docume~1\alluse~1.win\applic~1\2DBoy
2009-03-14 22:07 <DIR> --d----- c:\program files\WorldOfGooDemo
2009-03-12 20:13 221,184 a------- c:\windows\system32\wmpns.dll
==================== Find3M ====================
2009-04-10 19:32 24,944 a------- c:\windows\system32\drivers\GVTDrv.sys
2009-04-10 19:32 16,608 a------- c:\windows\gdrv.sys
2009-04-09 20:38 139,112 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-09 20:38 202,144 a------- c:\windows\system32\PnkBstrB.exe
2009-04-07 20:29 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-03-30 19:47 65,024 a------- c:\windows\IFinst26.exe
2009-03-09 17:21 56,320 ---shr-- c:\windows\system32\acelpdect.exe
2009-02-13 20:41 114,688 a------- c:\windows\system32\clockx.dll
2009-02-09 11:19 1,846,272 a------- c:\windows\system32\win32k.sys
2009-02-09 11:19 1,846,272 a------- c:\windows\system32\dllcache\win32k.sys
2009-02-04 21:29 10,520 a------- c:\windows\system32\avgrsstx.dll
2008-11-07 23:40 22,328 a------- c:\docume~1\neil\applic~1\PnkBstrK.sys
============= FINISH: 19:51:59.62 ===============