DDS (Ver_09-09-24.01) - NTFSx86
Run by Adam Samaan at 11:55:38.56 on Mon 09/28/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_01
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.735.448 [GMT -7:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Adam Samaan\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page =
hxxp://www.google.comuSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/ieuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uDefault_Search_URL =
hxxp://www.google.com/iemDefault_Search_URL =
hxxp://www.google.com/iemSearch Page =
hxxp://www.google.commStart Page =
hxxp://www.google.comuSearchAssistant =
hxxp://www.google.comuSearchURL,(Default) =
hxxp://www.google.com/search?q=%smSearchAssistant =
hxxp://www.google.comTB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [SoundMan] SOUNDMAN.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} -
hxxp://office.microsoft.com/templates/ieawsdc.cabDPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -
hxxp://www.apple.com/qtactivex/qtplugin.cabDPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} -
hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cabDPF: {26B2A5DA-BFD6-422F-A89A-28A54C74B12B} -
hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_4/PhotoCenter_ActiveX_Control.cabDPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} -
hxxp://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cabDPF: {406B5949-7190-4245-91A9-30A17DE16AD0} -
hxxp://www.costcophotocenter.com/CostcoActivia.cabDPF: {48DD0448-9209-4F81-9F6D-D83562940134} -
hxxp://lads.myspace.com/upload/MySpaceUploader1005.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cabDPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cabDPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} -
hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cabDPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cabDPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
hxxp://download.abacast.com/download/files/abasetup162.cabHandler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
AppInit_DLLs: ,zikubupa.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: {9a315099-39ba-4414-bd64-d91cbe41ac47} - No File
LSA: Notification Packages = scecli vosulome.dll
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-09-28 11:41 49,152 a----r-- c:\windows\system32\ChCfg.exe
2009-09-28 11:40 147,456 a----r-- c:\windows\system32\RtlCPAPI.dll
2009-09-28 11:40 10,528,768 a----r-- c:\windows\system32\RTLCPL.exe
2009-09-28 11:40 141,016 a----r-- c:\windows\system32\alsndmgr.wav
2009-09-28 11:40 18,804,736 a----r-- c:\windows\system32\alsndmgr.cpl
2009-09-28 11:40 577,536 a----r-- c:\windows\soundman.exe
2009-09-28 11:40 4,122,368 a----r-- c:\windows\system32\drivers\alcxwdm.sys
2009-09-28 11:39
--d----- c:\program files\Realtek AC97
2009-09-28 11:39 315,392 a----r-- c:\windows\alcupd.exe
2009-09-28 11:39 217,088 a----r-- c:\windows\Alcrmv.exe
2009-09-27 19:27 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-27 19:27 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-27 19:27 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-20 22:55 32,128 -c------ c:\windows\system32\dllcache\usbccgp.sys
2009-09-20 22:53 25,728 ac------ c:\windows\system32\dllcache\usbser.sys
2009-09-20 22:53 25,728 a------- c:\windows\system32\drivers\usbser.sys
2009-09-02 12:13 --d----- c:\program files\Shared
==================== Find3M ====================
2009-09-24 21:58 38,400 a--sh--- c:\windows\system32\fasapako.dll
2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 11:55 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2008-09-05 20:26 17,035 a------- c:\docume~1\adamsa~1\applic~1\agetamiv.dat
2008-09-05 20:26 14,498 a------- c:\docume~1\adamsa~1\applic~1\sipalumyfa.sys
2008-09-05 20:26 12,959 a------- c:\program files\common files\lagucifot.db
2008-09-05 20:26 12,530 a------- c:\program files\common files\meryxazyg.vbs
2008-09-05 20:26 10,986 a------- c:\docume~1\alluse~1\applic~1\lafafyro.bin
2008-07-10 13:50 26,712 a------- c:\docume~1\adamsa~1\applic~1\GDIPFONTCACHEV1.DAT
============= FINISH: 11:56:21.35 ===============