.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_26
Run by user at 9:12:21 on 2011-11-03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.364 [GMT 8:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\user\My Documents\My Backups\timmy\Plants vs Zombies\PlantsVsZombies.exe
C:\Documents and Settings\user\My Documents\My Backups\timmy\Plants vs Zombies\popcapgame1.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Globe Broadband\Globe Broadband.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
mWinlogon: Taskman=c:\documents and settings\user\fxmdk.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Microsoft Helper: {c9c42510-9b41-42c1-9dcd-7282a2d07c65} - c:\documents and settings\user\application data\microsoft\BHO32-WGSTI.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Microsoft Firewall 2.9] c:\docume~1\user\locals~1\temp\MSFW.exe
uRun: [Microsoft iexplorer11] c:\docume~1\user\locals~1\temp\iexplore.exe
uRun: [Exception Handler OEM] c:\documents and settings\user\application data\xi-h83df-384922-jo\winmsger.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TMRUBottedTray] "c:\program files\trend micro\rubotted\TMRUBottedTray.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Microsoft Firewall 2.9] c:\docume~1\user\locals~1\temp\MSFW.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Snap] c:\program files\usb 2.0 pc camera\Camera Snap.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart17.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 202.126.40.5 222.127.143.5
TCP: Interfaces\{A5BACF5E-6AB0-478C-A35E-C3AABEDAA924} : DhcpNameServer = 202.126.40.5 222.127.143.5
Notify: igfxcui - igfxdev.dll
IFEO: a2guard.exe - ntsd -d
IFEO: a2service.exe - ntsd -d
IFEO: a2start.exe - ntsd -d
IFEO: Ad-Aware.exe - ntsd -d
IFEO: Ad-AwareAdmin.exe - ntsd -d
.
Note: multiple IFEO entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\30utfx20.default\
FF - prefs.js: browser.startup.homepage -
www.google.com
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: <?xmlversion=1.0?><RDF xmlns=http://www.w3.org/1999/02/22-rdf-syntax-ns# xmlns:em=http://www.mozilla.org/2004/em-rdf#><description about=urn:mozilla:install-manifest><em:id>{a75dc39b-6438-4102-919f-f286bdd5c5e4}: {a75dc39b-6438-4102-919f-f286bdd5c5e4} - c:\program files\mozilla firefox\extensions\{a75dc39b-6438-4102-919f-f286bdd5c5e4}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-1-26 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-1-26 108289]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-1-26 56816]
R2 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2009-11-19 582992]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2010-12-25 114432]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2010-12-25 100736]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-7-2 27632]
R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2009-11-19 206608]
S2 ai7m5fmis4mqn;BCL easyPDF SDK Loader;c:\windows\system32\louhyt.exe --> c:\windows\system32\louhyt.exe [?]
S2 aoypd6oayuyu;BeTwin Terminal Services;c:\documents and settings\localservice\application data\microsoft\duridou.exe --> c:\documents and settings\localservice\application data\microsoft\duridou.exe [?]
S2 lo6moirc7diuot;Network Connectivity Service;c:\windows\system32\nafuwoul.exe --> c:\windows\system32\nafuwoul.exe [?]
S2 SSHNAS;SSHNAS;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 yj5y8iul9f;ASF Agent;c:\documents and settings\localservice\application data\microsoft\vipymmiroo.exe --> c:\documents and settings\localservice\application data\microsoft\vipymmiroo.exe [?]
S3 devlower;Audio Driver Afilter;c:\windows\system32\drivers\devlower.sys [2002-1-1 9216]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2010-7-2 13224]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
S3 ntportio;ntportio;\??\c:\documents and settings\user\my documents\my backups\timmy\programs\phone\ericsson\semctool_v8.4_free\ntportio.sys --> c:\documents and settings\user\my documents\my backups\timmy\programs\phone\ericsson\semctool_v8.4_free\ntportio.sys [?]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2009-11-19 206608]
S3 usbcamcl;Driver for video Device;c:\windows\system32\drivers\usbcamcl.sys [2002-1-1 31104]
S4 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\supportappxl\cdrom_mon.exe [2010-9-22 81920]
S4 pdzui;pdzui; [x]
S4 zxwmxfaxf;zxwmxfaxf; [x]
.
=============== File Associations ===============
.
.scr=AutoCADScriptFile
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2011-10-23 06:34:07 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-03 05:09:56 60416 ----a-w- c:\windows\ALCFDRTM.VER
2011-09-01 02:59:37 60416 ----a-w- c:\windows\ALCFDRTM.EXE
2011-08-31 09:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-19 09:48:09 208896 ----a-w- c:\documents and settings\user\application data\30.exe
2011-08-19 09:47:55 253952 ----a-w- c:\documents and settings\user\application data\2C.exe
2011-08-19 09:47:26 350544 ----a-w- c:\windows\system32\msvcr100.dll
2011-08-19 09:46:17 253952 ----a-w- c:\documents and settings\user\application data\26.exe
2010-04-22 22:17:44 451 ----a-w- c:\program files\0422201015174431.bat
.
============= FINISH: 9:12:43.81 ===============