DDS (Ver_09-03-16.01) - NTFSx86
Run by Julie at 21:51:38.42 on Sat 05/09/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1384 [GMT -4:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Julie\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
\\?\globalroot\systemroot\system32\lmn_setup.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.earthlink.net/partner/more/msie/button/search.html
uSearch Bar = hxxp://start.earthlink.net/AL/Search
uDefault_Page_URL = hxxp://start.earthlink.net
uDefault_Search_URL = hxxp://www.earthlink.net/partner/more/msie/button/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5061115
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: SrchHook Class: {44f9b173-041c-4825-a9b9-d914bd9dcbb3} - c:\program files\earthlink totalaccess\ElnIE.dll
uURLSearchHooks: H - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: {ee15b738-3a57-4236-8c56-d9ce52ed2e6c} - c:\windows\system32\zpwbyet.dll
TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [SetDefaultMIDI] MIDIDef.exe
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [autochk] rundll32.exe c:\docume~1\julie\protect.dll,_IWMPEvents@16
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\Quickset.exe
mRun: [CTSysVol] c:\program files\creative\sbaudigy\surround mixer\CTSysVol.exe /r
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [autochk] rundll32.exe c:\windows\system32\autochk.dll,_IWMPEvents@16
mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRun: [autochk] rundll32.exe c:\windows\system32\config\system~1\protect.dll,_IWMPEvents@16
StartupFolder: c:\docume~1\julie\startm~1\programs\startup\chkdisk.lnk - c:\windows\system32\rundll32.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1225569510671
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1240875870000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFECAFE-0013-0001-0028-ABCDEFABCDEF} - hxxps://esis.ncwise.org/forms/jinitiator/jinit13128.exe
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: sipdipgn - zpwbyet.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli mshgapr.dll c:\windows\system32\wazugige.dll
============= SERVICES / DRIVERS ===============
R0 ilcffezs;ilcffezs;c:\windows\system32\drivers\ilcffezs.sys [2004-8-10 23424]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-3 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-3 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-3 108552]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-2-7 214024]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-4-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-4-28 72944]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-3 298776]
R2 EarthLinkMonitor;EarthLink Monitor Service;c:\program files\earthlink totalaccess\wengine\wmonitor.exe [2005-1-26 65604]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 xgkfvboe;Microsoft System Management BIOS Monitor;c:\windows\system32\svchost.exe -k netsvcs [2004-8-10 14336]
R3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\BW2NDIS5.SYS [2004-11-1 17536]
S3 CM1023264TB;C-Media CM102 Like Sound UDAX Interface;c:\windows\system32\drivers\CM102.sys [2008-10-30 1331712]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-12-5 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-12-5 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-12-5 81288]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-2-7 79240]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-2-7 35240]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-2-7 34216]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-2-7 40488]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-4-28 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-12-5 356920]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-12-5 1079176]
=============== Created Last 30 ================
2009-05-09 21:51 24,064 a--sh--- c:\windows\system32\autochk.dll
2009-05-09 21:51 24,064 a--sh--- c:\documents and settings\julie\protect.dll
2009-05-09 21:43 61,440 a------- c:\windows\system32\drivers\kadirab.sys
2009-05-09 14:21 27,648 a------- c:\windows\system32\lmn_setup.exe
2009-05-07 19:25 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-05-07 19:25 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-05-07 19:25 <DIR> --d----- c:\docume~1\julie\applic~1\SUPERAntiSpyware.com
2009-05-07 19:24 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-05-05 20:14 85,504 a------- c:\windows\system32\click_setup.exe
2009-05-05 20:05 <DIR> --d----- C:\backups
2009-05-05 17:54 <DIR> --d----- c:\docume~1\julie\applic~1\Malwarebytes
2009-05-05 17:54 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-05-05 17:54 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-05 17:54 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-05-05 17:54 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-05-03 19:25 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-03 19:24 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-05-03 19:24 325,896 a------- c:\windows\system32\drivers\avgldx86.sys
2009-05-03 19:24 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-05-03 19:24 <DIR> --d----- c:\docume~1\julie\applic~1\AVGTOOLBAR
2009-05-03 19:24 <DIR> --d----- c:\program files\AVG
2009-05-03 19:24 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2009-05-03 16:02 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-05-01 19:19 <DIR> --d----- c:\windows\system32\Mozilla Shared
2009-04-28 19:30 268,648 a------- c:\windows\system32\mucltui.dll
2009-04-28 19:30 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-04-27 20:33 <DIR> --d----- c:\windows\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
2009-04-16 06:51 523 a------- c:\windows\ndprst.dll
2009-04-15 23:05 523 a------- c:\windows\ipacle.dll
2009-04-15 11:05 523 a------- c:\windows\oelpasr.dll
2009-04-15 07:50 523 a------- c:\windows\mofomsrD.dll
2009-04-15 06:37 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-04-15 06:37 284,160 -c------ c:\windows\system32\dllcache\pdh.dll
2009-04-15 06:37 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-04-15 06:37 110,592 -c------ c:\windows\system32\dllcache\services.exe
2009-04-15 06:37 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 06:37 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 06:37 729,088 -c------ c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 06:37 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-04-15 06:37 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-04-15 06:36 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-15 06:36 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-04-15 06:36 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-04-14 19:50 523 a------- c:\windows\dherta.dll
2009-04-14 18:32 523 a------- c:\windows\vciasc.dll
2009-04-14 17:43 523 a------- c:\windows\MFMGCry.dll
2009-04-14 16:43 523 a------- c:\windows\sgrfodi.dll
2009-04-14 15:43 523 a------- c:\windows\bmsapni.dll
2009-04-14 14:43 523 a------- c:\windows\tescla.dll
2009-04-14 13:43 523 a------- c:\windows\mp3dmi.dll
2009-04-14 12:43 523 a------- c:\windows\atupmpst.dll
2009-04-14 11:43 523 a------- c:\windows\mhermsvc.dll
2009-04-14 10:43 523 a------- c:\windows\ksenhac.dll
2009-04-14 09:43 523 a------- c:\windows\odpustr.dll
2009-04-14 08:42 523 a------- c:\windows\fgrx32.dll
2009-04-14 07:42 523 a------- c:\windows\ospgtn.dll
2009-04-14 06:42 523 a------- c:\windows\prudiext.dll
2009-04-14 00:59 523 a------- c:\windows\seopasv.dll
2009-04-13 23:59 523 a------- c:\windows\moparas.dll
2009-04-13 22:59 523 a------- c:\windows\wiflip.dll
2009-04-13 21:59 523 a------- c:\windows\dkbdlen.dll
2009-04-13 20:59 523 a------- c:\windows\doudwiak.dll
2009-04-13 19:59 523 a------- c:\windows\klvcrd.dll
2009-04-13 17:55 523 a------- c:\windows\VECtiaml.dll
2009-04-13 15:20 523 a------- c:\windows\fplskbui.dll
2009-04-12 23:50 <DIR> --d----- c:\docume~1\julie\applic~1\hvwbqzio
2009-04-12 19:05 0 a------- c:\windows\Ucawodihoduce.bin
2009-04-10 10:12 523 a------- c:\windows\ebuhoyop.dll
2009-04-10 09:10 523 a------- c:\windows\obadegemidaribiy.dll
2009-04-10 08:08 523 a------- c:\windows\ozeyerez.dll
2009-04-10 07:06 523 a------- c:\windows\upiladolequf.dll
2009-04-10 06:52 523 a------- c:\windows\jtecenui.dll
2009-04-10 06:04 523 a------- c:\windows\uresavadebiberer.dll
2009-04-10 05:02 523 a------- c:\windows\oyavixip.dll
2009-04-10 04:00 523 a------- c:\windows\opukudegem.dll
2009-04-10 02:58 523 a------- c:\windows\aviridas.dll
2009-04-10 01:56 523 a------- c:\windows\uzupijaferoc.dll
2009-04-10 00:54 523 a------- c:\windows\uxaniqivuxegeqe.dll
2009-04-09 23:52 523 a------- c:\windows\ozaluyet.dll
2009-04-09 22:50 523 a------- c:\windows\ivulocupuw.dll
==================== Find3M ====================
2009-03-25 11:06 214,024 a------- c:\windows\system32\drivers\mfehidk.sys
2009-03-25 11:05 34,216 a------- c:\windows\system32\drivers\mferkdk.sys
2009-03-06 10:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-02 20:18 826,368 a------- c:\windows\system32\wininet.dll
2009-02-20 14:09 78,336 a------- c:\windows\system32\ieencode.dll
2009-02-09 08:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 08:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 08:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 08:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 07:13 1,846,784 a------- c:\windows\system32\win32k.sys
2008-03-11 19:20 0 -c------ c:\docume~1\julie\applic~1\wklnhst.dat
2008-06-08 19:37 88 -c-shr-- c:\windows\system32\AD16C10B93.sys
2009-05-09 21:52 24,064 a--sh--- c:\windows\system32\autochk.dll
2008-06-08 19:37 2,828 -c-sh--- c:\windows\system32\KGyGaAvL.sys
============= FINISH: 21:52:28.82 ===============