DDS (Ver_09-03-16.01) - NTFSx86
Run by AXIOO at 2:07:32.21 on Wed 04/29/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1028 [GMT 7:00]
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OEM\OSD_1.5.2\OsdService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OEM\OSD_1.5.2\osd.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\AXIOO\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page =
hxxp://www.yahoo.com/uSearch Page =
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL =
hxxp://www.yahoo.com/?fr=fp-yie8mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.htmluInternet Settings,ProxyOverride = *.local
uSearchAssistant =
mSearchAssistant =
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Device Detector] DevDetect.exe -autorun
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [WinampAgent] c:\program files\winamp\winampa.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
StartupFolder: c:\docume~1\axioo\startm~1\programs\startup\frostw~1.lnk - c:\program files\frostwire\FrostWire.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\osd.lnk - c:\windows\installer\{73289228-1853-4623-982a-eb17ff0270ca}\_92336A3DC4E4457994C245.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Backward &Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Si&milar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\axioo\applic~1\mozilla\firefox\profiles\6cl6ev71.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage -
www.yahoo.comFF - prefs.js: keyword.URL -
hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101668&gct=&gc=1&q============== SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir personaledition classic\avgio.sys [2009-4-1 11840]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2009-4-1 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2009-4-1 151297]
R2 OsdService;OSD Service;c:\program files\oem\osd_1.5.2\OsdService.exe [2008-2-22 94208]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-10 602392]
R3 avgntflt;avgntflt;c:\program files\avira\antivir personaledition classic\avgntflt.sys [2009-4-1 52032]
R3 GpdDevDPort;GpdDevDPort;c:\windows\system32\directport.sys [2008-6-17 7168]
R3 GpdKbFilter;GpdKbFilter;c:\windows\system32\kbfiltr.sys [2008-4-22 8192]
R3 ReallusionVirtualAudio;Reallusion Virtual Audio;c:\windows\system32\drivers\RLVrtAuCbl.sys [2008-10-19 31616]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2008-10-19 156160]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2008-10-19 275712]
=============== Created Last 30 ================
2009-04-19 20:39 216,064 a------- c:\windows\system32\CNMLM8R.DLL
2009-04-18 16:28 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
2009-04-18 16:28 25,856 a------- c:\windows\system32\drivers\usbprint.sys
2009-04-18 16:28 15,104 ac------ c:\windows\system32\dllcache\usbscan.sys
2009-04-18 16:28 15,104 a------- c:\windows\system32\drivers\usbscan.sys
2009-04-16 23:01 1,970,176 a------- c:\windows\system32\d3dx9.dll
2009-04-16 23:01 679,936 a------- c:\windows\system32\D3DX81ab.dll
2009-04-16 23:01
--d----- c:\program files\Cheat Engine
2009-04-16 10:48 268,648 a------- c:\windows\system32\mucltui.dll
2009-04-16 10:48 208,744 a------- c:\windows\system32\muweb.dll
2009-04-16 10:48 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-04-15 21:50 --d----- c:\program files\Windows Media Connect 2
2009-04-15 21:48 --d----- c:\windows\system32\LogFiles
2009-04-15 21:37 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-04-15 21:37 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-04-15 21:37 284,160 -c------ c:\windows\system32\dllcache\pdh.dll
2009-04-15 21:37 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 21:37 110,592 -c------ c:\windows\system32\dllcache\services.exe
2009-04-15 21:37 729,088 -c------ c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 21:37 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-04-15 21:37 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-04-15 21:37 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 20:12 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-15 20:12 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-04-15 20:12 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-04-13 12:12 --dsh--- c:\documents and settings\axioo\IECompatCache
2009-04-13 01:39 --d----- c:\docume~1\axioo\applic~1\FrostWire
2009-04-13 01:37 --d----- c:\program files\FrostWire
2009-04-08 10:44 --d----- c:\program files\Adobe PhotoShop CS3 v10.0 Portable
2009-04-05 23:07 --dsh--- c:\documents and settings\axioo\PrivacIE
2009-04-05 23:06 --dsh--- c:\documents and settings\axioo\IETldCache
2009-04-05 23:04 --d----- c:\windows\ie8updates
2009-04-05 23:02 -cd-h--- c:\windows\ie8
2009-04-05 23:01 --d-h--- c:\windows\msdownld.tmp
2009-04-05 23:00 --dsh--- c:\documents and settings\axioo\UserData
2009-04-05 22:58 105,984 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-04-03 08:50 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-04-03 08:49 914,944 ac------ c:\windows\system32\dllcache\wininet.dll
2009-04-03 08:49 1,206,784 ac------ c:\windows\system32\dllcache\urlmon.dll
2009-04-03 08:49 1,499,136 -c------ c:\windows\system32\dllcache\shdocvw.dll
2009-04-03 08:41 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-03 08:41 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-03 08:41 2,066,048 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-03 08:41 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-03 08:38 5,937,152 ac------ c:\windows\system32\dllcache\mshtml.dll
2009-04-03 08:33 203,136 -c------ c:\windows\system32\dllcache\rmcast.sys
2009-04-03 08:33 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-04-03 08:32 333,952 -c------ c:\windows\system32\dllcache\srv.sys
2009-04-03 08:32 331,776 -c------ c:\windows\system32\dllcache\msadce.dll
2009-04-03 08:31 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2009-04-03 08:26 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2009-04-03 08:26 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll
2009-04-03 02:01 --d----- c:\windows\system32\PreInstall
2009-04-02 17:55 --d----- c:\program files\Yahoo!
2009-04-01 22:31 --d----- c:\docume~1\axioo\applic~1\ACD Systems
2009-04-01 15:26 --d----- c:\program files\Bonjour
2009-04-01 15:23 107,368 a------- c:\windows\system32\GEARAspi.dll
2009-04-01 15:23 15,464 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-04-01 15:23 --d----- c:\program files\iPod
2009-04-01 15:23 --d----- c:\program files\iTunes
2009-04-01 15:23 --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-04-01 13:42 773,120 a------- c:\windows\system32\bubbles.scr
2009-04-01 13:29 --d----- c:\docume~1\axioo\applic~1\Reallusion
2009-04-01 13:27 --d----- c:\program files\XP Codec Pack
2009-04-01 13:23 20,640 -------- c:\windows\system32\drivers\PxHelp20.sys
2009-04-01 13:23 155 a------- c:\windows\winamp.ini
2009-04-01 13:20 --d----- c:\program files\VideoLAN
2009-04-01 13:19 --d----- C:\noob
2009-04-01 13:18 --d----- c:\program files\DivX
2009-04-01 11:09 --d----- c:\program files\Avira
2009-04-01 11:09 --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-04-01 10:58 714 a------- c:\windows\m3jpeg.ini
2009-04-01 10:44 376 a------- c:\windows\ODBC.INI
2009-04-01 10:44 28,040 a------- c:\windows\system32\mdimon.dll
2009-04-01 10:43 --d----- c:\program files\common files\L&H
2009-04-01 10:43 --d----- c:\program files\Microsoft ActiveSync
2009-04-01 10:42 --d----- c:\windows\SHELLNEW
2009-04-01 10:32 --d----- c:\docume~1\alluse~1\applic~1\ACD Systems
2009-04-01 10:32 --d----- c:\program files\common files\ACD Systems
2009-04-01 10:32 --d----- c:\program files\ACD Systems
2009-04-01 10:26 --d----- c:\windows\Downloaded Installations
==================== Find3M ====================
2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 04:31 34,816 a------- c:\windows\system32\imgutil.dll
2009-03-08 04:31 48,128 a------- c:\windows\system32\mshtmler.dll
2009-03-08 04:31 45,568 a------- c:\windows\system32\mshta.exe
2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll
2009-03-06 21:22 284,160 a------- c:\windows\system32\pdh.dll
2009-02-09 19:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 19:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 19:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 19:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 18:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-06 18:11 110,592 a------- c:\windows\system32\services.exe
2009-02-06 18:06 2,145,280 a------- c:\windows\system32\ntoskrnl.exe
2009-02-06 17:39 35,328 a------- c:\windows\system32\sc.exe
2009-02-06 17:32 2,023,936 a------- c:\windows\system32\ntkrnlpa.exe
2009-02-04 02:59 56,832 a------- c:\windows\system32\secur32.dll
============= FINISH: 2:08:00.51 ===============