DDS (Ver_09-10-26.01) - NTFSx86 NETWORK
Run by Owner at 20:11:26.56 on Tue 11/10/2009
Internet Explorer: 7.0.6000.16916
Microsoft
Windows Vista
Home Premium 6.0.6000.0.1252.1.1033.18.3006.2430 [GMT -5:00]
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
SP: McAfee VirusScan *disabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k nȯne
C:\Windows\Explorer.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://my.juno.com/s/search?r=minisearch
uStart Page = hxxp://www.comcast.net/
uWindow Title = Internet Explorer provided by Dell
uSearch Bar = hxxp://www.comcast.net/toolbar2.0/search/
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080306
mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080306
mDefault_Search_URL = hxxp://my.juno.com/s/search?r=minisearch
mSearch Page = hxxp://my.juno.com/s/search?r=minisearch
uSearchURL,(Default) = hxxp://my.juno.com/s/search?r=minisearch
mSearchAssistant = hxxp://www.comcast.net/toolbar2.0/search/
uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - c:\program files\junointernet\SearchEnh1.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
BHO: Pop-up Blocker: {52706ef7-d7a2-49ad-a615-e903858cf284} - c:\program files\junointernet\qsacc\X1IEBHO.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
TB: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] "c:\program files\windows sidebar\Sidebar.exe" /autorun
uRun: [BitComet] c:\program files\bitcomet\BitComet.exe /tray
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [Juno_uoltray] c:\program files\junointernet\exec.exe regrun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DACSMiniApp] c:\program files\fisher-price\dacs\miniapp\DACSMiniApp.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\eventr~1.lnk - c:\pmw\PMREMIND.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\digita~1.lnk - c:\program files\digital line detect\DLG.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
IE: Display All Images with Full Quality - "c:\program files\junointernet\qsacc\appres.dll/228"
IE: Display Image with Full Quality - "c:\program files\junointernet\qsacc\appres.dll/227"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
Trusted Zone: juno.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - hxxp://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: junomsg - {C4D10830-379D-11d4-9B2D-00C04F1579A5} - c:\program files\juno\bin\jmsgpph.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\qn38zjz5.default\
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\qn38zjz5.default\extensions\{6847dfae-037a-400c-a524-27f0a281b692}\components\dtTransparency.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-11-10 23:35:16 8212 ----a-w- c:\windows\mfebcdata
2009-11-09 00:49:39 0 d-----w- c:\users\owner\.SunDownloadManager
2009-11-07 17:05:26 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-11-07 14:41:43 0 d-----w- c:\program files\Trend Micro
2009-11-07 03:25:32 0 d-----w- c:\users\owner\appdata\roaming\Malwarebytes
2009-11-07 03:25:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-07 03:25:27 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-07 03:25:27 0 d-----w- c:\programdata\Malwarebytes
2009-11-07 03:25:27 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-04 19:18:48 0 d-----w- c:\programdata\T1 Games
2009-11-04 07:43:18 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2009-11-03 03:53:11 0 d-----w- c:\program files\Curse of the Pharaoh - The Quest for Nefertiti
2009-11-01 21:09:07 0 d-----w- c:\programdata\1912 Titanic Mystery
2009-11-01 21:08:58 0 d-----w- c:\users\owner\appdata\roaming\TitanicMystery
2009-11-01 13:55:34 0 d-----w- c:\program files\iPod
2009-11-01 13:55:32 0 d-----w- c:\program files\iTunes
2009-10-30 20:03:13 0 d-----w- c:\users\owner\appdata\roaming\HdO Adventure
2009-10-28 07:37:45 311296 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-28 07:37:43 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-10-28 07:37:42 4096 ----a-w- c:\windows\system32\msdxm.ocx
2009-10-28 07:37:42 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-10-28 07:37:41 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-25 18:12:45 0 d-----w- c:\program files\Department 42 - The Mystery of the Nine
2009-10-24 16:10:59 0 d-----w- c:\users\owner\appdata\roaming\GTM_Bodie
2009-10-21 01:47:14 0 d-----w- c:\programdata\GameHouse
2009-10-21 01:46:46 0 d-----w- c:\programdata\Trymedia
2009-10-21 01:42:47 0 d-----w- C:\Games
2009-10-21 01:42:24 0 d-----w- c:\program files\RealArcade
2009-10-19 20:34:21 0 d-----w- c:\programdata\Becky Brogan
2009-10-17 15:23:45 0 d-----w- c:\users\owner\appdata\roaming\Ph03nixNewMedia
2009-10-17 15:20:09 0 d-----w- c:\program files\Curse of the Pharaoh - Tears of Sekhmet
2009-10-14 22:02:12 0 d-----w- c:\program files\Cake Mania Main Street
2009-10-14 11:50:49 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-14 11:50:48 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 11:47:37 428032 ----a-w- c:\windows\system32\EncDec.dll
2009-10-14 11:47:36 292352 ----a-w- c:\windows\system32\psisdecd.dll
2009-10-14 11:47:36 217088 ----a-w- c:\windows\system32\psisrndr.ax
2009-10-14 11:47:35 80896 ----a-w- c:\windows\system32\MSNP.ax
2009-10-14 11:47:33 1244672 ----a-w- c:\windows\system32\mcmde.dll
2009-10-14 11:47:32 68608 ----a-w- c:\windows\system32\Mpeg2Data.ax
2009-10-14 11:47:32 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2009-10-14 11:47:30 177152 ----a-w- c:\windows\system32\mpg2splt.ax
2009-10-14 11:47:01 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-14 11:46:56 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
==================== Find3M ====================
2009-09-19 14:50:11 86016 ----a-w- c:\windows\inf\infstrng.dat
2009-09-19 14:50:11 86016 ----a-w- c:\windows\inf\infstor.dat
2009-09-19 14:50:11 51200 ----a-w- c:\windows\inf\infpub.dat
2009-09-16 14:22:48 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 14:22:48 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 14:22:48 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 14:22:48 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 14:22:14 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-10 17:38:29 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-08 16:19:56 174 --sha-w- c:\program files\desktop.ini
2009-09-08 15:58:54 101376 ----a-w- c:\windows\system32\ifxcardm.dll
2009-09-08 15:58:38 79872 ----a-w- c:\windows\system32\axaltocm.dll
2009-09-08 15:38:27 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-08-29 03:41:42 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-08-29 03:40:31 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 23:31:54 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 14:02:34 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:57:38 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 13:57:36 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 13:56:05 72704 ----a-w- c:\windows\system32\admparse.dll
2009-08-27 11:24:10 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-27 09:51:45 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-08-15 23:58:19 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-15 23:54:25 416768 ----a-w- c:\windows\system32\IKEEXT.DLL
2009-08-15 23:54:01 543232 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2009-08-15 23:53:03 317440 ----a-w- c:\windows\system32\BFE.DLL
2009-08-15 21:30:09 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-08-14 16:40:56 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40:52 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25:18 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25:15 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25:14 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25:10 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25:10 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25:10 10240 ----a-w- c:\windows\system32\finger.exe
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-12-29 17:29:26 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-12-29 17:29:26 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-12-29 17:29:26 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2009-07-08 19:04:07 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-07-08 19:04:07 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-07-08 19:04:07 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-03-06 20:00:42 8192 --sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 20:11:49.56 ===============
OK, here is one. I'll send the next in the following post