DDS (Ver_09-02-01.01) - NTFSx86
Run by Fatima at 12:30:29.04 on Thu 02/26/2009
Internet Explorer: 7.0.6001.18000
Microsoft
Windows Vista
Home Premium 6.0.6001.1.1252.1.1033.18.3061.1540 [GMT -5:00]
AV: Norton Internet Security *On-access scanning enabled* (Outdated)
FW: Norton Internet Security *disabled*
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\aestsrv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Fatima\AppData\Local\Temp\a.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Fatima\AppData\Local\Temp\~tmpa.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Fatima\Desktop\dds.scr
============== Pseudo HJT Report ===============
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1080802
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.0\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.0\CoIEPlg.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [MSFox] c:\users\fatima\appdata\local\temp\a.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [isCfgWiz] "c:\program files\common files\symantec shared\opc\{c86ea115-facd-4aa8-bfa2-398c677d0936}\SYMCUW.exe" -G:{77CCBE0B-A541-49a9-883E-14F8337EC861} -T:Config -REBOOT
mRun: [815608714] "c:\programdata\1824161404\815608714.exe"
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mRunOnce: [Cleanup] C:\cleanup.exe
StartupFolder: c:\users\fatima\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: sonicwall.com\sslvpn
DPF: {44C1E3A2-B594-401C-B27A-D1B4476E4797} - hxxps://remote.rex-corp.net/XTSAC.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-2-26 130424]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-8-1 73728]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-1-9 149864]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-2-26 348752]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-8-1 111616]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-2-26 38496]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2008-8-1 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2008-8-1 7424]
S3 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\ipsdefs\20070823.002\IDSvix86.sys [2008-8-1 180272]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-8-21 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-8-21 8320]
=============== Created Last 30 ================
2009-02-26 11:51
--d----- c:\users\fatima\appdata\roaming\Malwarebytes
2009-02-26 11:51 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-26 11:51 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-26 11:51 --d----- c:\programdata\Malwarebytes
2009-02-26 11:51 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-26 11:51 --d----- c:\progra~2\Malwarebytes
2009-02-26 11:05 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
2009-02-26 11:05 130,424 a------- c:\windows\system32\drivers\PCTCore.sys
2009-02-26 11:05 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys
2009-02-26 11:05 a-d----- c:\programdata\TEMP
2009-02-26 11:05 --d----- c:\program files\common files\PC Tools
2009-02-26 11:05 64,392 a------- c:\windows\system32\drivers\pctplsg.sys
2009-02-26 11:05 --d----- c:\users\fatima\appdata\roaming\PC Tools
2009-02-26 11:05 --d----- c:\programdata\PC Tools
2009-02-26 11:05 --d----- c:\program files\Spyware Doctor
2009-02-26 11:05 --d----- c:\progra~2\PC Tools
2009-02-26 10:48 105,016 a------- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-02-26 10:48 97,800 a------- c:\windows\system32\infocardapi.dll
2009-02-26 10:48 622,080 a------- c:\windows\system32\icardagt.exe
2009-02-26 10:48 43,544 a------- c:\windows\system32\PresentationHostProxy.dll
2009-02-26 10:48 37,384 a------- c:\windows\system32\infocardcpl.cpl
2009-02-26 10:48 11,264 a------- c:\windows\system32\icardres.dll
2009-02-26 10:48 781,344 a------- c:\windows\system32\PresentationNative_v0300.dll
2009-02-26 10:48 326,160 a------- c:\windows\system32\PresentationHost.exe
2009-02-26 10:44 96,760 a------- c:\windows\system32\dfshim.dll
2009-02-26 10:44 282,112 a------- c:\windows\system32\mscoree.dll
2009-02-26 10:44 41,984 a------- c:\windows\system32\netfxperf.dll
2009-02-26 10:43 158,720 a------- c:\windows\system32\mscorier.dll
2009-02-26 10:43 83,968 a------- c:\windows\system32\mscories.dll
2009-02-26 10:17 --d----- c:\programdata\1824161404
2009-02-26 10:17 --d----- c:\progra~2\1824161404
2009-02-26 08:49 --d----- c:\program files\Trend Micro
2009-02-26 07:49 --d----- c:\users\fatima\appdata\roaming\Logs
2009-02-14 19:37 428,544 a------- c:\windows\system32\EncDec.dll
2009-02-14 19:37 217,088 a------- c:\windows\system32\psisrndr.ax
2009-02-14 19:37 293,376 a------- c:\windows\system32\psisdecd.dll
2009-02-14 19:37 177,664 a------- c:\windows\system32\mpg2splt.ax
2009-02-14 19:37 80,896 a------- c:\windows\system32\MSNP.ax
2009-02-13 22:01 --d----- c:\program files\BitPim
2009-02-13 21:00 --d----- c:\programdata\AVS4YOU
2009-02-13 21:00 --d----- c:\progra~2\AVS4YOU
2009-02-13 21:00 --d----- c:\program files\common files\AVSMedia
2009-02-13 21:00 24,576 a------- c:\windows\system32\msxml3a.dll
2009-02-13 21:00 --d----- c:\program files\AVS4YOU
2009-02-13 17:43 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-02-13 17:42 --d----- c:\program files\common files\Real
2009-02-13 17:41 22,912 a------- c:\windows\system32\drivers\lgusbmodem.sys
2009-02-13 17:41 21,248 a------- c:\windows\system32\drivers\lgusbdiag.sys
2009-02-13 17:41 12,672 a------- c:\windows\system32\drivers\lgusbbus.sys
2009-02-13 17:41 --d----- c:\program files\LG Electronics
2009-02-13 17:39 --d----- c:\program files\V CAST Music with Rhapsody
2009-02-11 04:15 --d----- c:\program files\Amazon
2009-02-10 20:26 827,392 a------- c:\windows\system32\wininet.dll
2009-02-10 20:26 1,383,424 a------- c:\windows\system32\mshtml.tlb
2009-02-10 19:29 --d----- c:\users\fatima\appdata\roaming\uTorrent
2009-02-07 04:34 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2009-02-07 04:34 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2009-02-04 19:05 --d----- c:\users\fatima\appdata\roaming\LimeWire
2009-02-04 19:05 --d----- c:\program files\LimeWire
==================== Find3M ====================
2009-02-13 17:42 143,360 a------- c:\windows\inf\infstrng.dat
2009-02-13 17:42 51,200 a------- c:\windows\inf\infpub.dat
2009-02-13 17:42 86,016 a------- c:\windows\inf\infstor.dat
2009-01-24 19:28 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_xusb21_01005.Wdf
2008-09-22 18:43 0 a------- c:\users\fatima\appdata\roaming\wklnhst.dat
2008-09-11 22:48 665,600 a------- c:\windows\inf\drvindex.dat
2008-01-20 21:43 174 a--sh--- c:\program files\desktop.ini
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 12:31:05.03 ===============