DDS (Ver_09-07-30.01) - NTFSx86
Run by Dennis at 17:15:46.67 on Wed 08/12/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.495.70 [GMT -4:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\TapeWare\TWWINSDR.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee\msc\mcshell.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dennis\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
mWinlogon: userinit=c:\windows\system32\userinit.exe,c:\windows\system32\drivers\smss.exe
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: ICQSys (IE PlugIn): {f54af7de-6038-4026-8433-cc30e3f17212} - c:\windows\system32\dddesot.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll
TB: PCLaw Web Timer: {0e1230f8-ea50-42a9-983c-d22abc2eed4b} - c:\progra~1\acg\pclaw32\plietool.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet
uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe"
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd.exe"
mRun: [DVDTray] c:\program files\hp dvd\umbrella\DVDTray.exe
mRun: [DVDBitSet] c:\program files\hp dvd\umbrella\DVDBitSet.exe /NOUI
mRun: [LGODDFU] "c:\program files\lg_fwupdate\fwupdate.exe" blrun
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [SecurDisc] c:\program files\nero\nero 7\incd\NBHGui.exe
mRun: [InCD] c:\program files\nero\nero 7\incd\InCD.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
IE: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSYYYYYYYYUS
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
IE: {91d9cee5-3906-40f7-b51a-9b013b59c826} - {836ece4e-a83a-404a-9433-6b15a66cb0fc} - c:\progra~1\acg\pclaw32\plietool.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {9d2169e0-0775-4080-9b4e-90fce9945b4a} - {2741ca04-5b65-4b10-afc0-4e8387fe6bde} - c:\progra~1\acg\pclaw32\plietool.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: bankofamerica.com\www
Trusted Zone: turbotax.com
Trusted Zone: westlaw.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab?AuthParam=1210957115_770cc8d1d0adc6f7a6f2cbcf543a6d36&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD40/JSCDL/jre/6u5-b19/jinstall-6u5-windows-i586-jc.cab&File=jinstall-6u5-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38194.4420601852
DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://attewc.webex.com/client/v_mywebex-pso-attewc-test/event/ieatgpc.cab
DPF: {FC01E8B2-B5A6-4660-BD9A-C01B59330DD9} - hxxp://www.vdrv.com/demo/vidrev.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxsrvc.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-13 214024]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-8-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-8-5 74480]
R2 MLPTDR_Q;MLPTDR_Q;c:\windows\system32\MLPTDR_Q.SYS [2003-7-23 18848]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-30 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-30 35272]
R3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-30 34248]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-30 40552]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-8-5 7408]
S2 ihzcvesvoowv;ihzcvesvoowv;\??\c:\windows\system32\drivers\dfdblvtcz.sys --> c:\windows\system32\drivers\dfdblvtcz.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-8-6 38528]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-1-25 42000]
S3 qic157;qic157;c:\windows\system32\drivers\qic157.sys [2004-7-23 6016]
S3 stidexp;stidexp;c:\windows\system32\drivers\stidexp.sys [2004-7-23 5504]
=============== Created Last 30 ================
2009-08-12 16:36 40,960 ac------ c:\windows\system32\dllcache\trialoc.dll
2009-08-12 16:36 20,480 ac------ c:\windows\system32\dllcache\inetwiz.exe
2009-08-12 16:36 16,384 ac------ c:\windows\system32\dllcache\isignup.exe
2009-08-12 16:36 73,728 ac------ c:\windows\system32\dllcache\icwtutor.exe
2009-08-12 16:36 61,440 ac------ c:\windows\system32\dllcache\icwres.dll
2009-08-12 16:36 49,152 ac------ c:\windows\system32\dllcache\icwutil.dll
2009-08-12 16:36 24,576 ac------ c:\windows\system32\dllcache\icwrmind.exe
2009-08-12 16:36 214,528 ac------ c:\windows\system32\dllcache\icwconn1.exe
2009-08-12 16:36 172,032 ac------ c:\windows\system32\dllcache\icwhelp.dll
2009-08-12 16:36 86,016 ac------ c:\windows\system32\dllcache\icwconn2.exe
2009-08-12 16:36 61,440 ac------ c:\windows\system32\dllcache\icwconn.dll
2009-08-12 16:36 32,768 ac------ c:\windows\system32\dllcache\icwdl.dll
2009-08-12 16:35 638,816 ac------ c:\windows\system32\dllcache\iexplore.exe
2009-08-12 16:35 18,432 ac------ c:\windows\system32\dllcache\iedw.exe
2009-08-12 16:35 68,608 ac------ c:\windows\system32\dllcache\hmmapi.dll
2009-08-12 15:54 <DIR> --d----- C:\dat-5707
2009-08-12 15:53 64,190,160 a------- C:\dat-5707.zip
2009-08-12 15:38 91 a------- c:\windows\system32\SKYNETgrplvyxr.dat
2009-08-12 14:40 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat
2009-08-12 14:40 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-08-12 14:40 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
2009-08-12 12:50 26,171,928 a------- C:\sdsetup.exe
2009-08-11 12:47 <DIR> --d----- c:\windows\system32\XPSViewer
2009-08-11 12:44 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-11 12:44 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-11 12:44 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-11 12:44 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-08-11 12:44 117,760 -------- c:\windows\system32\prntvpt.dll
2009-08-11 12:44 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
2009-08-11 12:44 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-08-11 12:44 <DIR> --d----- C:\dea5664b0a05e8816eed8c163ca368
2009-08-11 12:41 <DIR> --d----- c:\windows\SxsCaPendDel
2009-08-11 12:15 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-08-11 12:14 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-08-11 12:14 <DIR> --d----- c:\docume~1\dennis\applic~1\SUPERAntiSpyware.com
2009-08-11 12:13 <DIR> --d----- C:\244c245649f021d56b83eb5f11
2009-08-11 12:10 213,024 a------- c:\windows\system32\drivers\str.sys
2009-08-11 11:47 61,440 a------- c:\windows\system32\drivers\zdufpjba.sys
2009-08-10 14:54 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-08-10 12:56 6,881,824 a------- C:\SUPERAntiSpyware.exe
2009-08-10 12:14 <DIR> --d----- C:\e089a8afa68ae8326f
2009-08-10 12:14 <DIR> --d----- C:\e50356fbf38599ae209f0522b607
2009-08-10 11:28 19,968 a------- c:\windows\system32\SKYNETevxktkai.dll
2009-08-08 21:03 289 a------- C:\Shortcut (2) to 320254-000 ©.lnk
2009-08-08 21:03 289 a------- C:\Shortcut to 320254-000 ©.lnk
2009-08-07 14:38 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-08-07 14:37 <DIR> --d----- c:\documents and settings\dennis\.housecall6.6
2009-08-07 14:20 <DIR> --d----- C:\48b4adb53ef6eb00f4
2009-08-06 17:00 8,550 a------- c:\windows\system32\wispex.html
2009-08-06 17:00 <DIR> a-d----- c:\windows\system32\images
2009-08-06 16:40 <DIR> --d----- c:\docume~1\dennis\applic~1\Malwarebytes
2009-08-06 16:40 38,528 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-06 16:40 17,200 a------- c:\windows\system32\drivers\mbam.sys
2009-08-06 16:40 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-06 16:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-06 16:27 4 a------- c:\windows\system32\bincd32.dat
2009-08-05 05:01 204,800 -c------ c:\windows\system32\dllcache\mswebdvd.dll
2009-07-30 21:29 30 a------- c:\windows\system32\sonhelp.htm
2009-07-30 19:49 1,382 a------- c:\windows\system32\onhelp.htm
2009-07-30 19:36 36 a------- c:\windows\system32\sysnet.dat
2009-07-30 19:36 9 a------- c:\windows\system32\bennuar.old
2009-07-30 19:36 64 a------- c:\windows\ppp4.dat
2009-07-30 19:36 1 a------- c:\windows\ppp3.dat
2009-07-23 11:04 9,021,376 a------- C:\windows-kb890830-v2.12.exe
2009-07-20 13:26 338,239 a------- c:\windows\system32\SKYNETijrucqty.dat
2009-07-17 15:01 58,880 -c------ c:\windows\system32\dllcache\atl.dll
2009-07-16 19:24 552 a------- c:\windows\system32\d3d8caps.dat
2009-07-16 16:51 16,409,960 a------- C:\spybotsd162.exe
2009-07-16 15:49 0 a------- c:\windows\system32\a99k.bin
2009-07-15 16:02 2 a------- c:\windows\01011201014650120.dat
2009-07-15 15:04 <DIR> --dsh--- c:\documents and settings\dennis\PrivacIE
2009-07-15 14:12 <DIR> --d----- c:\windows\system32\lowsec
2009-07-14 18:52 <DIR> --dsh--- c:\documents and settings\dennis\IECompatCache
2009-07-14 18:48 <DIR> --dsh--- c:\documents and settings\dennis\IETldCache
2009-07-14 18:21 <DIR> --d----- c:\windows\ie8updates
2009-07-14 18:16 <DIR> -cd-h--- c:\windows\ie8
2009-07-14 18:13 2 a------- c:\windows\0101120101465752.dat
2009-07-14 18:13 215 a------- c:\windows\system32\MRT.INI
2009-07-14 18:11 102,912 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-07-14 18:11 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-07-14 18:11 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-07-14 15:12 2 a------- c:\windows\0535251103110107106.xvb
2009-07-14 15:12 1 ----h--- c:\windows\jmmark2.dat
2009-07-14 15:12 2 a------- c:\windows\0101120101465749.dat
2009-07-14 15:12 1 ----h--- c:\windows\b4657.dat
2009-07-14 15:12 2 a------- c:\windows\0101120101465349.dat
2009-07-14 15:12 1 ----h--- c:\windows\bf23567.dat
2009-07-14 14:12 1 a------- c:\windows\934fdfg34fgjf23
2009-07-14 14:12 2 a------- c:\windows\0101120101464849.dat
2009-07-14 14:12 2 a------- c:\windows\010112010146118114.dat
==================== Find3M ====================
2009-08-12 16:40 69,120 a------- c:\windows\system32\drivers\SKYNETkuuoflek.sys
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a------- c:\windows\system32\wmpdxm.dll
2009-07-03 13:09 915,456 a------- c:\windows\system32\wininet.dll
2009-06-26 16:39 44,032 -------- c:\windows\system32\SKYNETdapjvona.dll
2009-06-16 10:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-12 08:31 80,896 a------- c:\windows\system32\tlntsess.exe
2009-06-12 08:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-10 10:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 02:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-03 15:09 1,291,264 a------- c:\windows\system32\quartz.dll
2008-05-16 14:05 4,960,221 a------- c:\program files\RivaEncoderSetup.exe
2008-05-16 13:56 1,181,812 a------- c:\program files\free-flv-player.exe
2006-10-09 19:16 284 a------- c:\docume~1\dennis\applic~1\ViewerApp.dat
============= FINISH: 17:19:55.01 ===============