. DDS (Ver_11-03-05.01) - NTFSx86 NETWORK Run by Administrator at 11:32:24.37 on Fri 03/18/2011 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1689 [GMT 1:00] . AV: AVG Internet Security Network Edition *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Administrator\Desktop\dds.com . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [HPPQVideo] "c:\program files\hp\scheduledlaunch\hp laserjet p2050 series\bin\hppschlnch.exe" -r software\hewlett-packard\scheduledlaunch\LJ_P2050_Series -f PQOptimizerVideo.xml -o RemindLater mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 dRunOnce: [IE7-11] rundll32 advpack.dll,LaunchINFSection NR_IE7en.inf,AfterUserStart IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html IE: Iz&vezi u Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL . ============= SERVICES / DRIVERS =============== . R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-1-5 25168] R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-1-5 52872] R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [2009-11-14 24064] R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-5 243024] R3 k57w2k;Broadcom NetLink (TM) Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [2009-11-14 176640] S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-5 216400] S1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-5 29584] S2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-6-25 921952] S2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-6-25 308136] S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-6-25 5897808] S3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-1-5 122448] S3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-1-5 30288] S3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-1-5 26192] S4 gupdate;Google Update Service (gupdate);"c:\program files\google\update\googleupdate.exe" /svc --> c:\program files\google\update\GoogleUpdate.exe [?] . =============== Created Last 30 ================ . 2011-03-16 12:12:51 -------- d-----w- c:\program files\common files\Wise Installation Wizard 2011-03-16 09:12:00 135168 -c----w- c:\windows\system32\dllcache\shsvcs.dll 2011-03-16 08:58:47 -------- d--h--w- c:\windows\system32\GroupPolicy 2011-03-15 10:33:06 -------- d--h--w- c:\docume~1\alluse~1\applic~1\Common Files 2011-03-09 05:54:27 270848 -c----w- c:\windows\system32\dllcache\sbe.dll 2011-03-09 05:54:27 186880 -c----w- c:\windows\system32\dllcache\encdec.dll 2011-03-09 05:54:21 677888 -c----w- c:\windows\system32\dllcache\lhmstsc.exe 2011-03-09 05:54:21 2067456 -c----w- c:\windows\system32\dllcache\lhmstscx.dll 2011-03-04 09:52:21 90112 --sh--r- c:\windows\AnarchyIRCLib.dll 2011-03-04 09:52:21 125952 --sha-r- c:\windows\ctxfix.exe 2011-03-04 09:52:21 0 ----a-w- c:\windows\lsasc.exe 2011-02-28 10:42:41 -------- d-----w- c:\docume~1\admini~1\applic~1\Monotype Imaging 2011-02-28 10:33:42 28672 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\TSKppr.dll 2011-02-28 10:33:41 61440 ----a-w- c:\windows\system32\TSKMON.DLL 2011-02-17 10:18:05 -------- d-----w- c:\program files\InCode Solutions 2011-02-17 09:28:16 99840 -c----w- c:\windows\system32\dllcache\srvsvc.dll 2011-02-17 09:27:45 90112 -c----w- c:\windows\system32\dllcache\wshext.dll 2011-02-17 09:27:44 180224 -c----w- c:\windows\system32\dllcache\scrobj.dll 2011-02-17 09:27:44 172032 -c----w- c:\windows\system32\dllcache\scrrun.dll 2011-02-17 09:27:44 155648 -c----w- c:\windows\system32\dllcache\wscript.exe 2011-02-17 09:27:44 135168 -c----w- c:\windows\system32\dllcache\cscript.exe 2011-02-17 09:27:33 81920 -c----w- c:\windows\system32\dllcache\isign32.dll 2011-02-17 09:27:08 58880 -c----w- c:\windows\system32\dllcache\spoolsv.exe 2011-02-17 09:27:02 439296 -c----w- c:\windows\system32\dllcache\shimgvw.dll 2011-02-17 09:26:17 1288192 -c----w- c:\windows\system32\dllcache\ole32.dll 2011-02-17 09:26:03 293376 -c----w- c:\windows\system32\dllcache\winsrv.dll 2011-02-17 09:25:49 406016 -c----w- c:\windows\system32\dllcache\usp10.dll 2011-02-17 09:25:37 249856 -c----w- c:\windows\system32\dllcache\odbc32.dll 2011-02-17 09:25:36 536576 -c----w- c:\windows\system32\dllcache\msado15.dll 2011-02-17 09:25:36 200704 -c----w- c:\windows\system32\dllcache\msadox.dll 2011-02-17 09:25:36 180224 -c----w- c:\windows\system32\dllcache\msadomd.dll 2011-02-17 09:25:36 143360 -c----w- c:\windows\system32\dllcache\msadco.dll 2011-02-17 09:25:36 102400 -c----w- c:\windows\system32\dllcache\msjro.dll 2011-02-17 09:25:04 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll 2011-02-17 09:25:04 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll 2011-02-17 09:24:26 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll 2011-02-17 09:22:02 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys 2011-02-17 09:18:37 45568 -c----w- c:\windows\system32\dllcache\wab.exe 2011-02-16 14:22:44 -------- d-----w- c:\program files\UPHClean 2011-02-16 13:58:36 56623 ------w- c:\windows\system32\drivers\ati1btxx.sys 2011-02-16 13:57:56 19569 ----a-w- c:\windows\003108_.tmp 2011-02-16 13:02:54 -------- d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes 2011-02-16 13:02:49 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-02-16 13:02:48 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2011-02-16 13:02:45 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-02-16 13:02:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-02-16 13:01:24 -------- d-----w- c:\windows\pss 2011-02-16 13:00:28 -------- d-sh--w- c:\documents and settings\administrator\IECompatCache 2011-02-16 10:50:17 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0 . ==================== Find3M ==================== . 2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll 2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll 2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll 2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll 2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll 2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys 2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll 2010-12-20 23:59:20 916480 ----a-w- c:\windows\system32\wininet.dll 2010-12-20 23:59:19 43520 ----a-w- c:\windows\system32\licmgr10.dll 2010-12-20 23:59:19 1469440 ------w- c:\windows\system32\inetcpl.cpl 2010-12-20 17:26:00 730112 ----a-w- c:\windows\system32\lsasrv.dll 2010-12-20 12:55:26 385024 ----a-w- c:\windows\system32\html.iec 2010-03-13 11:49:04 125952 --sha-r- c:\windows\ctxfix.exe 2008-04-14 04:42:16 64000 --sha-r- c:\windows\system32\cleanmgr.exe 2008-04-14 04:42:20 180224 --sha-r- c:\windows\system32\dwwin.exe 2008-04-14 04:42:32 1200640 --sha-r- c:\windows\system32\ntbackup.exe 2008-04-14 04:42:34 380416 --sha-r- c:\windows\system32\restore\rstrui.exe . ============= FINISH: 11:32:52.29 ===============