DDS (Ver_09-10-13.01) - NTFSx86
Run by Risa at 18:34:17.92 on Sun 10/18/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.116 [GMT -4:00]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\ACS.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k ".Net CLR"
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\svohost.exe
C:\Program Files\Windows Police Pro\Windows Police Pro.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Risa\Local Settings\Temporary Internet Files\Content.IE5\37TUSJGS\dds[1].pif
============== Pseudo HJT Report ===============
uSearch Bar =
hxxp://www.toshiba.com/searchuInternet Settings,ProxyOverride =
BHO: c:\windows\system32\nqpyt99fjs.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\nqpyt99fjs.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [hivew] c:\windows\system32\rundll32.exe c:\docume~1\risa\locals~1\temp\229059371824999.dll,Set1
uRun: [calc] rundll32.exe c:\windows\system32\config\system~1\ntuser.dll,_IWMPEvents@0
uRun: [Login Software 2009] c:\docume~1\risa\locals~1\temp\bvoief4sye.exe
uRun: [Yjafosi8kdf98winmdkmnkmfnwe] c:\docume~1\risa\locals~1\temp\csrss.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [PINGER] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [TPSMain] TPSMain.exe
mRun: [TFncKy] TFncKy.exe
mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe
mRun: [CFSServ.exe] CFSServ.exe -NoClient
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [calc] rundll32.exe c:\windows\system32\calc.dll,_IWMPEvents@0
mRun: [winupdate.exe] c:\windows\system32\winupdate.exe
mRun: [gomayabuk] Rundll32.exe "c:\windows\system32\fomegozu.dll",a
mRun: [98489341] c:\docume~1\alluse~1\applic~1\98489341\98489341.exe
mRun: [Fmawubalikoq] rundll32.exe "c:\windows\iwidoxiy.dll",Startup
StartupFolder: c:\documents and settings\risa\start menu\programs\startup\scandisk.dll
StartupFolder: c:\docume~1\risa\startm~1\programs\startup\scandisk.lnk - c:\windows\system32\rundll32.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: facebook.com\www
Trusted Zone: msn.com\www
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167508361312
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540010} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: gutakila.dll c:\docume~1\risa\locals~1\temp\405318usc.dll c:\docume~1\risa\locals~1\temp\415318333.dll c:\docume~1\risa\locals~1\temp\5340xxx.dll c:\docume~1\risa\locals~1\temp\531842eve.dll c:\windows\system32\fomegozu.dll
SSODL: bepakupiw - {351d05b5-8767-4820-a8e1-7825c8bc0e2f} - c:\windows\system32\fomegozu.dll
STS: c:\windows\system32\nqpyt99fjs.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\nqpyt99fjs.dll
STS: mujuzedij: {351d05b5-8767-4820-a8e1-7825c8bc0e2f} - c:\windows\system32\fomegozu.dll
LSA: Notification Packages = scecli hoheyuli.dll PSWMSCf1.dll
============= SERVICES / DRIVERS ===============
R2 .Net CLR;Microsoft .Net Framework COM+ Support;c:\windows\system32\svchost.exe -k ".Net CLR" [2005-4-20 14336]
R2 Iprip;Network Security;c:\windows\system32\svchost.exe -k netsvcs [2005-4-20 14336]
R2 WDefend;WDefend;c:\windows\svohost.exe [2009-10-18 287232]
S3 isapeep;isapeep;c:\windows\system32\isapeep.sys [2005-4-20 2304]
S3 mndisk;mndisk;c:\windows\system32\mndisk.sys [2005-4-20 2304]
============== File Associations ===============
exefile=c:\windows\system32\pump.exe "%1" %*
=============== Created Last 30 ================
2009-10-18 12:51 540,389 a------- c:\windows\system32\246d60.dll
2009-10-18 12:51 807,140 a------- c:\windows\system32\mne.exe
2009-10-18 12:20 48,966 a------- c:\windows\system32\certstore.dat
2009-10-18 11:59 --d----- c:\windows\system32\schtml
2009-10-18 11:58 94,208 a------- c:\windows\system32\TOCRdll.dll
2009-10-18 11:58 95 a------- c:\windows\TOCR.ini
2009-10-18 11:58 3 a------- c:\windows\system32\bversion.dll
2009-10-18 11:58 --d----- c:\program files\LanqiEngine
2009-10-18 11:57 735,232 a------- c:\windows\system32\AdvOcr.dll
2009-10-18 11:57 94,208 a------- c:\windows\system32\TRSOCR.dll
2009-10-18 11:57 95 a------- c:\windows\system32\TRSOCR.ini
2009-10-18 11:56 120 a------- c:\windows\Rtijodet.dat