DDS (Ver_09-10-26.01) - NTFSx86
Run by Owner at 18:38:37.96 on Sat 11/07/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.305 [GMT -6:00]
AV: Norton Internet Security 2006 *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
AV: Trend Micro AntiVirus *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: Norton Internet Security 2006 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
svchost.exe "C:\WINDOWS\system32\$winnt$k.exe"
C:\Nexon\MapleStory\npkcmsvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
svchost
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\dwaxmz.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
BHO: {08b6dc9f-434b-4539-981e-cbb9749aa809} - sovapeha.dll
BHO: c:\windows\system32\wzwtxnmi.dll: {a45a4b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\wzwtxnmi.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 3.0\aoltb.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe"
uRun: [Aim6]
uRun: [A00F27B806A.exe] "c:\docume~1\owner\locals~1\temp\_A00F27B806A.exe"
uRun: [BackUp Windows 2009] c:\docume~1\owner\locals~1\temp\dwaxmz.exe
uRun: [djcfwqpj] "c:\documents and settings\owner\local settings\application data\dblnqt\sflksysguard.exe"
uRun: [p2pxmld8] "rundll32.exe" "c:\documents and settings\owner\local settings\application data\p2pxmld8\p2pxmld8.dll", DllInit
uRun: [Yjafosi8kdf98winmdkmnkmfnwe] c:\docume~1\owner\locals~1\temp\winlogon.exe
mRun: [VAIO Recovery] "c:\windows\sonysys\vaio recovery\PartSeal.exe"
mRun: [Switcher.exe] "c:\program files\sony\wireless switch setting utility\Switcher.exe"
mRun: [UserFaultCheck] "c:\windows\system32\dumprep.exe" 0 -u
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe"
mRun: [djcfwqpj] "c:\documents and settings\owner\local settings\application data\dblnqt\sflksysguard.exe"
mRun: [yusasehab] Rundll32.exe "c:\windows\system32\mofebese.dll",a
dRun: [userinit] c:\windows\system32\twex.exe
dRun: [huyalolupo] Rundll32.exe "difizavu.dll",s
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\trendm~1.lnk - c:\program files\trend micro\tmas\Tmas.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: EnableProfileQuota = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 3.0\aoltb.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C021A4D6-173F-4BF4-B38C-B12CAA20E518} - hxxp://www.mgoon.com/launcher.cab
DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {e2883e8f-472f-4fb0-9522-ac9bf37916a7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {738C508A-8A1B-40C4-933B-AB10D2676EC7} = 77.74.48.113
TCP: {D55872FF-6096-4139-90DC-F248503529CE} = 77.74.48.113
Notify: igfxcui - igfxdev.dll
Notify: VESWinlogon - VESWinlogon.dll
Notify: __c00729c - c:\windows\system32\__c00729C.dat
Notify: __c00c7944 - c:\windows\system32\__c00C7944.dat
Notify: __c00e8b8a - c:\windows\system32\__c00E8B8A.dat
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: kedumoroh - {9b083d54-1833-4831-a8f6-5879332e016b} - c:\windows\system32\nazesuna.dll
SSODL: maniyiter - {0c3d1003-3d13-44a6-ad47-0bc191e91821} - c:\windows\system32\mofebese.dll
STS: c:\windows\system32\wzwtxnmi.dll: {a45a4b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\wzwtxnmi.dll
STS: mujuzedij: {9b083d54-1833-4831-a8f6-5879332e016b} - c:\windows\system32\nazesuna.dll
STS: tokatiluy: {0c3d1003-3d13-44a6-ad47-0bc191e91821} - c:\windows\system32\mofebese.dll
SEH: Trend Micro Anti-Spyware Shell Extension: {03a80b1d-5c6a-42c2-9dfb-81b6005d8023} - c:\program files\trend micro\tmas\sshook.dll
LSA: Notification Packages = scecli difizavu.dll takujiza.dll
============= SERVICES / DRIVERS ===============
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29808]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -svaio_vedb --> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -sVAIO_VEDB [?]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2009-6-11 50192]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2009-6-11 36368]
R2 TmProxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2009-6-11 677128]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-7-19 24652]
R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\spy sweeper\WRConsumerService.exe [2009-1-29 1201640]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-9-1 226304]
S2 mhnntmssvc;MHN MHNNtmsSvc;c:\windows\system32\$winnt$k.exe srv --> c:\windows\system32\$winnt$k.exe srv [?]
S2 wpsvxepi;USB Scanner Helper;c:\windows\system32\svchost.exe -k netsvcs [2006-9-1 14336]
S3 MzBot;MzBot;\??\c:\mzbot.sys --> c:\MzBot.sys [?]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.exe -i vaio_vedb --> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.EXE -i VAIO_VEDB [?]
S3 XDva007;XDva007;\??\c:\windows\system32\xdva007.sys --> c:\windows\system32\XDva007.sys [?]
=============== Created Last 30 ================
2009-11-08 00:24:10 12032 ----a-w- c:\windows\system32\iehelper.dll
2009-11-08 00:23:41 27648 ----a-w- c:\windows\system32\__c00E8B8A.dat
2009-11-08 00:01:31 0 d-s---w- C:\Combo-Fix27522C
2009-11-07 23:50:57 0 d-s---w- C:\Combo-Fix
2009-11-07 17:36:18 0 d-sha-r- C:\cmdcons
2009-11-07 16:14:50 98816 ----a-w- c:\windows\sed.exe
2009-11-07 16:14:50 77312 ----a-w- c:\windows\MBR.exe
2009-11-07 16:14:50 267264 ----a-w- c:\windows\PEV.exe
2009-11-07 16:14:50 161792 ----a-w- c:\windows\SWREG.exe
2009-11-07 15:29:33 3249 ----a-w- c:\windows\system32\wbem\Outlook_01ca5fbf1b6a6186.mof
2009-11-07 15:15:25 76780 ----a-w- c:\windows\system32\__c00913B1.exe
2009-11-07 15:14:19 0 d-----w- C:\SafetyCenter
2009-11-07 15:13:54 32768 ----a-w- c:\windows\system32\__c00EAAA4.exe
2009-11-07 13:39:45 54156 ---ha-w- c:\windows\QTFont.qfn
2009-11-07 13:39:45 1409 ----a-w- c:\windows\QTFont.for
2009-11-07 00:30:07 2713 --sh--w- c:\windows\system32\tumibule.exe
2009-11-07 00:30:06 2713 --sh--w- c:\windows\system32\nigokeyo.exe
2009-11-07 00:26:01 832 ----a-w- c:\windows\system32\wininit.dll
2009-11-07 00:25:49 32 --s-a-w- c:\windows\system32\3752377456.dat
2009-11-07 00:24:13 15000 ----a-w- c:\windows\system32\wzwtxnmi.dll
2009-11-07 00:24:07 52224 ----a-w- C:\luobk.exe
2009-11-07 00:24:07 37376 ----a-w- C:\oqbkddrr.exe
2009-11-07 00:24:07 32768 ----a-w- C:\ilywlxxf.exe
2009-11-07 00:24:05 0 --sha-w- C:\1155048582
2009-10-28 20:30:52 0 d-----w- c:\program files\oakxsp
2009-10-28 20:30:01 288768 ----a-w- c:\windows\system32\~.exe
==================== Find3M ====================
2009-11-08 00:39:08 44288 ----a-w- c:\windows\system32\drivers\396463a.sys
2009-11-06 12:35:10 10752 ----a-w- c:\windows\DCEBoot.exe
2009-10-18 00:45:53 356352 ----a-w- c:\documents and settings\owner\cwshredder.dll
2009-10-08 03:05:57 944 ----a-w- c:\docume~1\owner\applic~1\wklnhst.dat
2009-09-18 19:08:30 1563008 ----a-w- c:\windows\WRSetup.dll
2009-09-18 18:42:18 176752 ----a-w- c:\windows\system32\drivers\ssidrv.sys
2009-09-18 18:42:16 29808 ----a-w- c:\windows\system32\drivers\ssfs0bbc.sys
2009-09-18 18:42:16 23152 ----a-w- c:\windows\system32\drivers\sshrmd.sys
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
2008-04-14 00:12:36 61440 --sh--r- c:\windows\system32\$winnt$k.exe
2007-06-23 19:06:56 88 --sh--r- c:\windows\system32\9AAE4F43F0.sys
2009-08-07 00:24:20 52224 --sha-w- c:\windows\system32\difizavu.dll
2009-08-07 15:32:56 60416 --sha-w- c:\windows\system32\dunuwopo.dll
2007-06-23 22:04:33 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-07 15:32:56 92672 --sha-w- c:\windows\system32\mofebese.dll
2009-08-07 15:32:58 53760 --sha-w- c:\windows\system32\nefaneji.dll
2009-08-07 00:24:20 52224 --sha-w- c:\windows\system32\sovapeha.dll
2009-08-07 00:24:20 52224 --sha-w- c:\windows\system32\takujiza.dll
2009-08-07 15:32:58 45056 --sha-w- c:\windows\system32\voladeti.dll
2009-08-07 15:32:59 39424 --sha-w- c:\windows\system32\wakatuha.dll
2009-08-07 00:30:03 39424 --sha-w- c:\windows\system32\weyuneve.dll
2009-08-07 00:30:03 45056 --sha-w- c:\windows\system32\zeyebome.dll
2008-09-14 17:19:54 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091420080915\index.dat
============= FINISH: 18:42:26.23 ===============