DDS (Ver_09-03-16.01) - NTFSx86
Run by Michael at 22:10:14.04 on Sat 03/28/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.140 [GMT -5:00]
AV: AVG Anti-Virus plus Firewall *On-access scanning enabled* (Updated)
FW: AVG Firewall *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\QBOOKSW\Components\QBAgent\qbdagent2002.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Michael\Desktop\New Briefcase\dds.scr
============== Pseudo HJT Report ===============
uLocal Page = \blank.htm
uStart Page =
www.scullypages.com/BHO: Adobe PDF Reader Link Helper: {
removed for security} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {
removed for security} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Trellian BHO Impl: {
removed for security} - c:\program files\trellian\toolbar\toolbar.dll
BHO: AVG Safe Search: {
removed for security} - c:\program files\avg\avg8\avgssie.dll
BHO: {
removed for security} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Java(tm) Plug-In SSV Helper: {
removed for security} - c:\program files\java\jre6\bin\ssv.dll
BHO: AVGTOOLBAR: {
removed for security} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {
removed for security} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {
removed for security} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: OToolbarHelper Class: {
removed for security} - c:\program files\paypal\paypal plug-in\PayPalHelper.dll
TB: AVGTOOLBAR: {
removed for security} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: &RoboForm: {
removed for security} - c:\program files\siber systems\ai roboform\roboform.dll
TB: Trellian &Toolbar: {
removed for security} - c:\program files\trellian\toolbar\toolbar.dll
TB: PayPal Plug-In: {
removed for security} - c:\program files\paypal\paypal plug-in\OToolbar.dll
EB: {
removed for security} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Lexmark X73 Button Monitor] c:\progra~1\lexmar~1\ACMonitor_X73.exe
mRun: [Lexmark X73 Button Manager] c:\progra~1\lexmar~1\AcBtnMgr_X73.exe
mRun: [PrinTray] c:\windows\system32\spool\drivers\w32x86\3\printray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\qbooksw\components\qbagent\qbdagent2002.exe
IE: Customize Menu -
file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Fill Forms -
file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar -
file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms -
file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {
removed for security} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {
removed for security} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {
removed for security} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {
removed for security} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {
removed for security} - c:\program files\messenger\msmsgs.exe
IE: {
removed for security} - {
removed for security} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {
removed for security} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java -
file://c:\windows\java\classes\xmldso.cabDPF: {
removed for security} -
hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1205163384551DPF: {
removed for security} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cabDPF: {
removed for security} -
hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cabDPF: {
removed for security} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabHandler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - f:\program files\coreftp\pftpns.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {
removed for security} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\michael\applic~1\mozilla\firefox\profiles\m7pbmj4m.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT447260&SearchSource=3&q============== SERVICES / DRIVERS ===============
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-3-10 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-3-10 325640]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-3-10 27656]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-3-10 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-15 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-15 298264]
R2 avgfws8;AVG8 Firewall;c:\progra~1\avg\avg8\avgfws8.exe [2009-1-15 1356616]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2008-3-10 29208]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2008-3-10 29208]
S3 OKI OPHC DCS Loader;OKI OPHC DCS Loader;c:\windows\system32\spool\drivers\w32x86\3\OPHCLDCS.EXE [2005-5-10 24576]
=============== Created Last 30 ================
2009-03-28 20:55 1,409 a------- c:\windows\QTFont.for
2009-03-28 20:55 54,156 a---h--- c:\windows\QTFont.qfn
2009-03-28 03:18
--d----- c:\docume~1\michael\applic~1\Uniblue
2009-03-28 03:17 -cd-h--- c:\docume~1\alluse~1\applic~1\~0
2009-03-25 22:53 --d----- c:\docume~1\alluse~1\applic~1\SecTaskMan
2009-03-25 22:53 --d----- c:\program files\Security Task Manager
2009-03-24 03:26 --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-03-23 23:16 2,790 a------- c:\windows\system32\tmp.reg
2009-03-23 23:15 --d----- c:\documents and settings\michael\SmitfraudFix
2009-03-23 15:22 --d----- c:\program files\Enigma Software Group
2009-03-23 10:07 --d----- c:\docume~1\michael\applic~1\Malwarebytes
2009-03-23 10:07 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-03-18 05:15 --d----- c:\program files\AshongSoft
2009-03-17 23:05 8 a------- c:\windows\sess_583d2815c194179b0cb7179a4cf9dd98
2009-02-28 14:05 410,984 a------- c:\windows\system32\deploytk.dll
==================== Find3M ====================
2009-03-25 11:07 10,520 a------- c:\windows\system32\avgrsstx.dll
2009-03-25 11:07 325,640 a------- c:\windows\system32\drivers\avgldx86.sys
2009-03-25 11:07 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-03-24 01:38 253,952 a------- c:\windows\system32\skinboxer43.dll
2009-03-23 07:57 25,088 a------- c:\windows\system32\userinit.exe
2009-02-09 06:13 1,846,784 a------- c:\windows\system32\win32k.sys
2008-07-18 21:38 60,744 a------- c:\documents and settings\michael\g2mdlhlpx.exe
2001-07-26 19:58 47 a------- c:\program files\ACMonitor_X73.ini
2001-07-05 15:46 8,116 a------- c:\program files\OSLO3071b2.USB
2001-05-11 14:39 53,248 a------- c:\program files\ACMonitor_X73.exe
2001-05-08 19:36 114,688 a------- c:\program files\lxarscan.dll
2001-04-23 17:22 1,437 a------- c:\program files\gtx73.ini
2001-02-22 12:54 768 a------- c:\program files\x73_lut.dat
2008-10-26 10:38 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008102620081027\index.dat
============= FINISH: 22:11:19.37 ===============