DDS (Ver_09-07-30.01) - NTFSx86
Run by Scott at 13:58:38.06 on Sun 09/13/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.791 [GMT -5:00]
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\RAID\vialogsv.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\Scott\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/webhp?rls=ig
uSearch Page =
uSearch Bar =
uInternet Settings,ProxyOverride = <local>
mSearchAssistant = hxxp://searchingforwebsite.info/search.php?q=%s&a=v14-a
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: NitroPDFBHO Class: {cf070cb8-f02f-4af4-a7b7-8d45cad4bb54} - c:\program files\nitro pdf\pdf download\NitroPDF.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: {0C9A45D1-6DF3-4615-9353-07FB5EE9B507} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
TB: {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet explorer\iedvtool.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [360desktop]
uRun: [HijackThis startup scan] c:\program files\trend micro\hijackthis\HijackThis.exe /startupscan
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [ScreenGif] a
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
StartupFolder: c:\docume~1\scott\startm~1\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: HideClock = 0 (0x0)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Save Page As PDF ... - file://c:\program files\nitro pdf\pdf download\nitroweb.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {AD9E6088-E00B-42f9-9F0C-8480525D234E} - {FF5073C0-28A0-4223-9BDF-59FF020FE77C} - c:\program files\nitro pdf\pdf download\NitroPDF.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlcdnet.asus.com/pub/ASUS/misc/dlm-activex-2.2.5.0.cab
DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro2.cce.hp.com/ChatEntry/downloads/sysinfo.cab
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1235932511703
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs: wbsys.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - SABShellExecuteHook Class
============= SERVICES / DRIVERS ===============
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-9-4 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-9-4 74480]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-5-14 731840]
R2 VRAID Log Service;VRAID Log Service;c:\program files\via\raid\vialogsv.exe [2009-8-16 52888]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-8-5 66056]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-8-18 50704]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2009-1-13 340096]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-9-4 7408]
S3 SliceDisk5;SliceDisk5;c:\program files\a-ff find and mount\slicedisk.sys [2009-2-28 10240]
============== File Associations ===============
txtfile=notepad.exe "%1"
=============== Created Last 30 ================
2009-09-13 06:43 <DIR> --d----- c:\program files\Trend Micro
2009-09-12 05:21 <DIR> --d----- c:\windows\system32\amd dragon platform technology dir
2009-09-12 05:16 520,192 a------- c:\windows\system32\amd dragon platform technology.scr
2009-09-11 06:22 186,407 a------- c:\windows\system32\nvapps.nvb
2009-09-08 06:48 <DIR> --d----- c:\program files\Animated ScreenGif
2009-09-08 06:48 <DIR> --d----- C:\GreetSoft
2009-09-08 05:28 737,280 a------- c:\windows\iun6002.exe
2009-09-08 05:28 <DIR> --d----- c:\program files\AndreaMosaic
2009-09-06 19:19 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-09-06 19:19 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-09-06 19:19 <DIR> --d----- c:\docume~1\scott\applic~1\SUPERAntiSpyware.com
2009-08-30 10:12 9,200 -------- c:\windows\system32\drivers\cdralw2k.sys
2009-08-30 10:12 9,072 -------- c:\windows\system32\drivers\cdr4_xp.sys
2009-08-30 10:11 <DIR> --d----- c:\windows\system32\IOSUBSYS
2009-08-30 08:32 <DIR> --d----- c:\program files\FreeCommander
2009-08-30 04:06 <DIR> --d----- c:\program files\CaptureText.com
2009-08-30 03:38 <DIR> --d----- c:\program files\SoftCAT
2009-08-30 03:21 <DIR> --d----- c:\docume~1\scott\applic~1\M8 Software
2009-08-30 03:21 <DIR> --d----- c:\docume~1\alluse~1\applic~1\M8 Software
2009-08-29 13:02 <DIR> --d----- c:\windows\system32\wbem\Repository
2009-08-29 13:01 <DIR> --d----- c:\docume~1\scott\applic~1\ESET
2009-08-29 12:42 335 a------- c:\windows\system32\vsconfig.xml
2009-08-29 12:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
2009-08-29 12:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-08-29 12:27 <DIR> --d----- c:\docume~1\scott\applic~1\Spyware Terminator
2009-08-29 12:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spyware Terminator
2009-08-29 12:27 <DIR> --d----- c:\windows\system32\ZoneLabs
2009-08-29 09:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\RegCure
2009-08-28 18:14 <DIR> --d----- c:\program files\Audacity
2009-08-28 05:57 <DIR> --d----- c:\docume~1\scott\applic~1\Photo! 3D Album
2009-08-28 05:57 3,939,328 a------- c:\windows\Photo! 3D ScreenSaver.scr
2009-08-28 05:57 <DIR> --d----- c:\program files\Photo!
2009-08-26 22:05 <DIR> --d----- c:\program files\360desktop
2009-08-26 22:05 <DIR> --d----- c:\docume~1\scott\applic~1\360desktop
2009-08-26 22:05 426 a------- c:\windows\{21D15DED-F125-46C8-8017-CB9F1CEB5B4D}_WiseFW.ini
2009-08-25 05:58 <DIR> --d----- c:\docume~1\scott\applic~1\BID
2009-08-25 05:03 <DIR> --d----- c:\program files\PhotoScape
2009-08-24 23:40 <DIR> --d----- c:\program files\Realtek AC97
2009-08-24 17:43 <DIR> --d----- c:\program files\YCIII
2009-08-18 21:35 281,104 a------- c:\windows\system32\wpcap.dll
2009-08-18 21:35 96,784 a------- c:\windows\system32\Packet.dll
2009-08-18 21:35 53,299 a------- c:\windows\system32\pthreadVC.dll
2009-08-18 21:35 50,704 a------- c:\windows\system32\drivers\npf.sys
2009-08-18 21:35 <DIR> --d----- c:\docume~1\scott\applic~1\Apowersoft
2009-08-18 21:35 <DIR> --d----- c:\program files\Apowersoft
2009-08-16 15:05 27,784 a------- c:\windows\system32\drivers\point32.sys
2009-08-16 15:05 <DIR> --d----- c:\program files\Microsoft IntelliPoint
2009-08-16 14:59 <DIR> --d----- c:\program files\Microsoft IntelliType Pro
2009-08-16 14:34 32,768 a------- c:\windows\system\VRAIDlog.dll
2009-08-16 14:20 940,794 a------- c:\windows\system32\LoopyMusic.wav
2009-08-16 14:20 146,650 a------- c:\windows\system32\BuzzingBee.wav
2009-08-16 14:20 <DIR> --d----- c:\windows\system32\Lang
2009-08-16 14:15 169 a------- c:\windows\RtlRack.ini
2009-08-16 14:00 49,152 a------- c:\windows\system32\ChCfg.exe
2009-08-16 13:57 13,976 a------- c:\windows\system32\drivers\videX32.sys
2009-08-16 10:13 <DIR> --d----- c:\program files\Advanced Business Card Maker
2009-08-16 09:33 <DIR> --d----- c:\docume~1\scott\applic~1\PhotoFiltre Studio X
2009-08-16 09:28 <DIR> --d----- c:\program files\PhotoFiltre Studio X
2009-08-15 14:14 81,920 a------- c:\docume~1\scott\applic~1\ezpinst.exe
2009-08-15 14:14 47,360 a------- c:\windows\system32\drivers\pcouffin.sys
2009-08-15 14:14 47,360 a------- c:\docume~1\scott\applic~1\pcouffin.sys
2009-08-15 14:14 719,872 a------- c:\windows\system32\devil.dll
2009-08-15 14:14 308,224 a------- c:\windows\system32\avisynth.dll
2009-08-15 14:14 <DIR> --d----- c:\program files\McFunSoft Video Capture Convert Burn Solution
==================== Find3M ====================
2009-09-13 13:02 14,336 a------- c:\windows\system32\svchost.exe
2009-09-13 02:28 8,530 a------- c:\windows\pchealth\helpctr\config\cache\Personal_32_1033.dat
2009-08-30 10:47 20,692 a---h--- c:\windows\system32\mlfcache.dat
2009-08-09 04:07 4,212 a---h--- c:\windows\system32\zllictbl.dat
2009-08-05 04:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-03 18:50 2,560 a------- c:\windows\_MSRSTRT.EXE
2009-07-28 23:54 410,984 a------- c:\windows\system32\deploytk.dll
2009-07-17 14:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-03 12:09 915,456 a------- c:\windows\system32\wininet.dll
2009-06-25 03:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 03:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 03:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 03:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 03:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 03:25 54,272 a------- c:\windows\system32\wdigest.dll
2009-06-16 09:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 09:36 81,920 a------- c:\windows\system32\fontsub.dll
2006-02-28 07:00 94,784 ---sh--- c:\windows\twain.dll
2008-04-14 06:42 50,688 ---sh--- c:\windows\twain_32.dll
2008-04-14 06:41 1,028,096 ---sh--- c:\windows\system32\mfc42.dll
2008-04-14 06:42 57,344 ---sh--- c:\windows\system32\msvcirt.dll
2008-04-14 06:42 413,696 ---sh--- c:\windows\system32\msvcp60.dll
2008-04-14 06:42 343,040 ---sh--- c:\windows\system32\msvcrt.dll
2008-04-14 06:42 551,936 ---sh--- c:\windows\system32\oleaut32.dll
2008-04-14 06:42 84,992 ---sh--- c:\windows\system32\olepro32.dll
2008-04-14 06:42 11,776 ---sh--- c:\windows\system32\regsvr32.exe
2009-02-15 12:13 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009021520090216\index.dat
============= FINISH: 13:58:58.12 ===============