as requested
DDS (Ver_09-12-01.01) - NTFSx86
Run by Owner at 16:08:33.73 on Fri 01/15/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.49 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page =
hxxp://google.ca/uDefault_Page_URL =
hxxp://us10.hpwis.com/uSearch Bar =
hxxp://www.google.com/ieuWindow Title = Microsoft Internet Explorer provided by Sympatico
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8mSearch Bar =
hxxp://srch-us10.hpwis.com/uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:\program files\stopzilla!\SZIEBHO.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {871F91FD-3A92-4988-A842-16AB2CFF5AF1} - No File
TB: {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - No File
EB: hp view: {8f4902b6-6c04-4ade-8052-aa58578a21bd} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [WordWeb] "c:\program files\wordweb\wweb32.exe" -startup
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [VTTimer] VTTimer.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\tl-wn3~1.lnk - c:\program files\tp-link\tl-wn321g wireless utility\installer\winxp\TWCU.exe
IE: &MSN Search - c:\program files\msn toolbar suite\tb\02.00.0001.1203\en-us\msntb.dll/search.htm
IE: &Winamp Toolbar Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: Microsoft XML Parser for Java -
file://c:\windows\java\classes\xmldso.cabDPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} -
hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cabDPF: {166B1BCA-3F9C-11CF-8075-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cabDPF: {17492023-C23A-453E-A040-C7C580BBF700} -
hxxp://go.microsoft.com/fwlink/?linkid=39204DPF: {205FF73B-CA67-11D5-99DD-444553540000} -
hxxp://www.wildtangent.com/webdrivers/webinstall/Install.cabDPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} -
hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cabDPF: {5CB1506E-1DEA-4E63-89A7-E40E52AEA1FD} -
hxxp://fulfillment.puretracks.com/onager.cabDPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} -
hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cabDPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
hxxp://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093924185203DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -
hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133732068281DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -
hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cabDPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} -
hxxp://dm.screensavers.com/dm/installers/si/1/sinstaller.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cabDPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38062.4207060185DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cabDPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} -
hxxp://www.photodex.com/pxplay.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabDPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} -
hxxp://3dlifeplayer.dl.3dvia.com/player/install/installer.exeDPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} -
hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabDPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} -
hxxp://costco.pnimedia.com/upload/activex/v3_0_0_2/PhotoCenter_ActiveX_Control.cabHandler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\quicktax 2007\ic2007pp.dll
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - c:\program files\quicktax 2008\ic2008pp.dll
Handler: rlfile - {F541A92B-CDC2-4B7C-BEF1-C7443070F3D8} - c:\program files\blacksmemorables\RocketEngine.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [2009-12-7 61328]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [2009-12-14 163600]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-1-12 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-1-12 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-1-12 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-1-12 56816]
R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [2006-12-14 70016]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys --> c:\windows\system32\drivers\is3srv.sys [?]
S0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [2004-4-12 6097]
S2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe --> c:\progra~1\mcafee\viruss~1\mcshield.exe [?]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys --> c:\windows\system32\drivers\sonyhcs.sys [?]
=============== Created Last 30 ================
2010-01-15 14:37:16 744 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-01-14 22:25:19 0 d-----w- c:\program files\CCleaner
2010-01-14 20:45:54 93696 ----a-w- c:\windows\system32\MyDefragScreenSaver.scr
2010-01-14 20:45:54 935424 ----a-w- c:\windows\system32\MyDefragScreenSaver.exe
2010-01-14 20:45:54 0 d-----w- c:\program files\MyDefrag v4.2.7
2010-01-13 16:19:00 0 d-----w- c:\program files\Combined Community Codec Pack
2010-01-13 14:23:55 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-01-13 14:23:55 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-13 14:22:52 0 d-----w- c:\program files\LimeWire
2010-01-12 23:00:22 1191616 ------w- c:\windows\wweb32.dll
2010-01-12 23:00:21 0 d-----w- c:\program files\WordWeb
2010-01-12 17:19:00 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-12 17:18:48 0 d-----w- c:\program files\Avira
2010-01-12 17:18:48 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-01-12 15:37:14 17152 -c--a-w- c:\windows\system32\dllcache\usbohci.sys
2010-01-12 15:37:14 17152 ----a-w- c:\windows\system32\drivers\usbohci.sys
2010-01-12 15:37:09 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-01-12 15:37:09 60032 ----a-w- c:\windows\system32\drivers\usbaudio.sys
2010-01-12 15:36:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-01-12 15:36:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-01-12 15:36:57 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-01-12 15:36:57 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-01-12 15:36:51 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-01-12 15:36:51 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-01-12 15:36:50 42368 -c--a-w- c:\windows\system32\dllcache\agp440.sys
2010-01-12 15:36:50 42368 ----a-w- c:\windows\system32\drivers\agp440.sys
2010-01-11 21:14:06 0 d-----w- c:\program files\TrendMicro
2010-01-11 20:31:20 0 d-----w- c:\docume~1\owner\applic~1\Malwarebytes
2010-01-11 20:31:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 20:30:58 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-11 20:30:57 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-11 20:30:57 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-11 19:04:29 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 18:20:36 0 d-----w- c:\docume~1\alluse~1\applic~1\SITEguard
2010-01-10 18:18:34 0 d-----w- c:\program files\STOPzilla!
2010-01-10 18:18:23 0 d-----w- c:\program files\common files\iS3
2010-01-10 18:18:13 0 d-----w- c:\docume~1\alluse~1\applic~1\STOPzilla!
2010-01-10 16:57:44 0 d-----w- c:\docume~1\owner\applic~1\McAfee
2010-01-10 15:41:18 0 d-----w- c:\program files\common files\McAfee
2010-01-10 15:40:58 0 d-----w- c:\program files\McAfee
2010-01-08 01:55:19 0 d-----w- c:\program files\Western Digital
2010-01-07 17:26:29 0 d-----w- c:\docume~1\alluse~1\applic~1\Seagate
2010-01-07 17:23:30 0 d-----w- c:\program files\Carbonite
2010-01-07 17:21:11 0 d-----w- c:\program files\Seagate
2010-01-06 18:43:11 0 d-----w- C:\extensions
2010-01-06 18:42:55 0 d-----w- c:\program files\YouTube Clip Extractor
2010-01-06 16:28:21 79660 ---ha-w- c:\windows\system32\mlfcache.dat
2010-01-01 02:38:00 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-01 02:38:00 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-01-01 02:35:59 0 d-----w- c:\program files\iPod
2010-01-01 02:35:36 0 d-----w- c:\program files\iTunes
2010-01-01 02:35:36 0 d-----w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-01 02:23:39 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys.bak
2010-01-01 02:23:39 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-12-23 19:13:34 545424 ----a-r- c:\windows\system32\SZComp5.dll
2009-12-23 19:13:32 438928 ----a-r- c:\windows\system32\SZBase5.dll
2009-12-23 19:04:54 17408 ----a-r- c:\windows\system32\SZIO5.dll
==================== Find3M ====================
2010-01-12 17:34:23 81984 ----a-w- c:\windows\system32\bdod.bin
2009-12-14 15:24:24 163600 ----a-r- c:\windows\system32\drivers\SZKGFS.sys
2009-12-10 21:11:40 126976 ----a-r- c:\windows\system32\IS3HTUI5.dll
2009-12-10 21:11:32 393216 ----a-r- c:\windows\system32\IS3DBA5.dll
2009-12-10 21:09:24 385024 ----a-r- c:\windows\system32\IS3UI5.dll
2009-12-10 21:09:08 61440 ----a-r- c:\windows\system32\IS3Hks5.dll
2009-12-10 21:08:48 23040 ----a-r- c:\windows\system32\IS3XDat5.dll
2009-12-10 21:06:52 225280 ----a-r- c:\windows\system32\IS3Win325.dll
2009-12-10 21:06:30 94208 ----a-r- c:\windows\system32\IS3Inet5.dll
2009-12-10 21:05:54 94208 ----a-r- c:\windows\system32\IS3Svc5.dll
2009-12-10 21:02:42 729088 ----a-r- c:\windows\system32\IS3Base5.dll
2009-12-07 21:59:32 61328 ----a-r- c:\windows\system32\drivers\SZKG.sys
2009-12-07 21:59:32 61328 ----a-r- c:\windows\system32\drivers\is3srv.sys.bak
2009-10-29 07:45:38 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-25 00:10:30 20 ---h--w- c:\docume~1\alluse~1\applic~1\PKP_DLdw.DAT
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2005-08-28 00:58:47 774144 ----a-w- c:\program files\RngInterstitial.dll
2008-08-19 18:54:05 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081920080820\index.dat
============= FINISH: 16:09:38.56 ===============