DDS (Ver_09-12-01.01) - NTFSx86
Run by xp at 21:01:23.57 on Wed 12/09/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.874.66.1033.18.1534.878 [GMT -8:00]
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
D:\My Documents\CPE17AntiAutorun1400.exe
D:\games\DAEMON Tools\daemon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\xp\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page =
hxxp://search.live.commSearchAssistant =
hxxp://search.live.com/sphome.aspxmWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [EPSON Stylus Photo R230 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiaip.exe /fu "c:\windows\temp\E_S3E7.tmp" /EF "HKCU"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [UnlockerAssistant] c:\program files\unlocker\UnlockerAssistant.exe -H
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [protect_autorun] d:\my documents\CPE17AntiAutorun1400.exe /start
mRun: [DAEMON Tools] "d:\games\daemon tools\daemon.exe" -lang 1033
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
dRunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabTCP: {AC056B3B-1292-48CB-9979-AD25906723A2} = 202.96.144.47,202.96.128.143
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\xp\applic~1\mozilla\firefox\profiles\bqtwtzzb.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.bing.com/search?FORM=IEFM1&q=FF - prefs.js: browser.startup.homepage -
hxxp://go.microsoft.com/fwlink/?LinkId=69157FF - prefs.js: keyword.URL -
hxxp://www.bing.com/search?FORM=IEFM1&q=FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
============= SERVICES / DRIVERS ===============
R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2006-11-30 31944]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\cyberlink\powerdvd8\000.fcl [2008-2-1 41456]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-11-30 54752]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2006-2-20 104000]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2007-2-22 144960]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2007-2-22 54872]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-12-5 38224]
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2006-2-20 72264]
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2006-2-20 34152]
R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2006-2-20 170408]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
=============== Created Last 30 ================
2009-12-06 17:37:39 0 d-----w- c:\windows\system32\CatRoot_bak
2009-12-06 16:47:23 989184 ------w- c:\windows\system32\dllcache\kernel32.dll
2009-12-06 16:43:24 74240 ----a-w- c:\windows\system32\SET302.tmp
2009-12-06 16:43:24 74240 ------w- c:\windows\system32\dllcache\mscms.dll
2009-12-06 16:43:13 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2009-12-06 16:43:13 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2009-12-06 16:42:59 253952 ----a-w- c:\windows\system32\SET2D2.tmp
2009-12-06 16:42:59 253952 ------w- c:\windows\system32\dllcache\es.dll
2009-12-06 16:42:43 132096 ------w- c:\windows\system32\dllcache\wkssvc.dll
2009-12-06 16:42:29 84992 ------w- c:\windows\system32\dllcache\avifil32.dll
2009-12-06 16:42:15 344064 ------w- c:\windows\system32\dllcache\localspl.dll
2009-12-06 16:42:01 1290752 ------w- c:\windows\system32\SET28B.tmp
2009-12-06 16:42:01 1290752 ------w- c:\windows\system32\dllcache\quartz.dll
2009-12-06 16:41:22 91648 ------w- c:\windows\system32\dllcache\mtxoci.dll
2009-12-06 16:41:22 66560 ----a-w- c:\windows\system32\SET26E.tmp
2009-12-06 16:41:22 66560 ------w- c:\windows\system32\dllcache\mtxclu.dll
2009-12-06 16:41:22 58880 ------w- c:\windows\system32\dllcache\msdtclog.dll
2009-12-06 16:41:22 161792 ------w- c:\windows\system32\dllcache\msdtcuiu.dll
2009-12-06 16:41:21 956928 ------w- c:\windows\system32\dllcache\msdtctm.dll
2009-12-06 16:41:21 428032 ------w- c:\windows\system32\dllcache\msdtcprx.dll
2009-12-06 14:26:18 0 d-----w- c:\program files\MSXML 4.0
2009-12-06 14:21:01 47104 ------w- c:\windows\system32\dllcache\mqdscli.dll
2009-12-06 14:21:01 4608 ------w- c:\windows\system32\dllcache\mqsvc.exe
2009-12-06 14:21:01 16896 ------w- c:\windows\system32\dllcache\mqise.dll
2009-12-06 14:21:00 95744 ------w- c:\windows\system32\dllcache\mqsec.dll
2009-12-06 14:21:00 91776 ------w- c:\windows\system32\dllcache\mqac.sys
2009-12-06 14:21:00 48640 ------w- c:\windows\system32\dllcache\mqupgrd.dll
2009-12-06 14:21:00 471552 ------w- c:\windows\system32\dllcache\mqutil.dll
2009-12-06 14:21:00 225280 ------w- c:\windows\system32\dllcache\mqoa.dll
2009-12-06 14:21:00 138240 ------w- c:\windows\system32\dllcache\mqad.dll
2009-12-06 14:20:59 661504 ------w- c:\windows\system32\dllcache\mqqm.dll
2009-12-06 14:20:59 517120 ------w- c:\windows\system32\dllcache\mqsnap.dll
2009-12-06 14:20:59 19968 ------w- c:\windows\system32\dllcache\mqbkup.exe
2009-12-06 14:20:59 186880 ------w- c:\windows\system32\dllcache\mqtrig.dll
2009-12-06 14:20:59 169472 ------w- c:\windows\system32\dllcache\msmqocm.dll
2009-12-06 14:20:59 123392 ------w- c:\windows\system32\dllcache\mqrtdep.dll
2009-12-06 14:20:59 117248 ------w- c:\windows\system32\dllcache\mqtgsvc.exe
2009-12-06 14:20:58 177152 ------w- c:\windows\system32\dllcache\mqrt.dll
2009-12-06 14:20:46 332800 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-12-06 14:19:59 283648 ------w- c:\windows\system32\dllcache\gdi32.dll
2009-12-06 14:17:56 0 d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-12-06 14:17:35 417792 ------w- c:\windows\system32\dllcache\vbscript.dll
2009-12-06 14:17:15 0 d-----w- c:\program files\MSXML 6.0
2009-12-06 14:13:24 80896 ------w- c:\windows\system32\dllcache\tlntsess.exe
2009-12-06 14:13:24 76288 ------w- c:\windows\system32\dllcache\telnet.exe
2009-12-06 14:13:00 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-12-06 14:13:00 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-12-06 14:12:46 0 d--h--w- c:\windows\$hf_mig$
2009-12-06 08:52:07 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-12-06 06:10:11 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2009-12-06 06:05:19 58880 ------w- c:\windows\system32\dllcache\atl.dll
2009-12-06 06:04:44 8454656 ------w- c:\windows\system32\dllcache\shell32.dll
2009-12-06 06:00:03 138368 ------w- c:\windows\system32\dllcache\afd.sys
2009-12-06 06:00:02 360320 ------w- c:\windows\system32\dllcache\tcpip.sys
2009-12-06 06:00:02 245248 ------w- c:\windows\system32\dllcache\mswsock.dll
2009-12-06 06:00:02 100352 ------w- c:\windows\system32\dllcache\6to4svc.dll
2009-12-06 05:58:41 584192 ------w- c:\windows\system32\dllcache\rpcrt4.dll
2009-12-06 05:50:23 351232 ------w- c:\windows\system32\dllcache\winhttp.dll
2009-12-06 05:49:38 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
2009-12-06 05:46:53 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2009-12-06 05:41:28 1850112 ------w- c:\windows\system32\dllcache\win32k.sys
2009-12-06 05:36:56 1435648 ------w- c:\windows\system32\dllcache\query.dll
2009-12-06 05:35:32 177152 ------w- c:\windows\system32\dllcache\msctfime.ime
2009-12-06 04:27:21 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-12-06 04:23:21 128512 ------w- c:\windows\system32\dllcache\dhtmled.ocx
2009-12-06 04:19:10 202752 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-12-06 04:18:45 453632 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-12-06 04:18:15 333184 ------w- c:\windows\system32\dllcache\srv.sys
2009-12-06 04:18:02 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2009-12-06 04:17:40 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-12-06 04:14:31 683520 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-12-06 04:11:15 450560 ------w- c:\windows\system32\dllcache\jscript.dll
2009-12-06 00:53:34 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-12-06 00:53:34 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2009-12-06 00:52:57 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2009-12-06 00:52:57 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2009-12-06 00:52:57 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2009-12-06 00:52:57 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2009-12-06 00:52:56 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-12-06 00:25:16 0 d-----w- c:\docume~1\xp\applic~1\Malwarebytes
2009-12-06 00:25:12 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-06 00:25:10 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-06 00:25:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-06 00:25:09 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-01 05:57:23 0 d-----w- c:\documents and settings\xp\Tracing
2009-12-01 05:31:01 0 d-----w- c:\program files\Microsoft Office Outlook Connector
2009-12-01 05:30:50 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-12-01 05:29:36 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-12-01 05:29:22 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-01 05:28:54 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-12-01 05:27:43 0 d-----w- c:\program files\Microsoft
2009-12-01 05:27:28 0 d-----w- c:\program files\Windows Live SkyDrive
2009-12-01 05:09:40 0 d-----w- c:\program files\common files\Windows Live
2009-11-16 04:13:10 0 d-----w- c:\docume~1\xp\applic~1\Merscom
2009-11-16 04:13:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Merscom
2009-11-16 01:23:59 0 d-----w- c:\program files\Hostile Makeover
==================== Find3M ====================
2009-09-18 09:56:10 18432 ------w- c:\windows\system32\dllcache\iedw.exe
2009-09-11 14:33:52 133632 ------w- c:\windows\system32\msv1_0.dll
2009-09-11 14:03:37 136192 ----a-w- c:\windows\system32\SET2FD.tmp
2009-09-11 14:03:37 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
============= FINISH: 21:01:55.32 ===============