DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:30:58.95 on Wed 01/12/2011 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1416 [GMT -6:00] AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB} FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\WINDOWS\system32\IFXTCS.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Sony\SmartWi Connection Utility\SmartWiService.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe c:\program files\verizon wireless\venturi\Client\ventc.exe C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\msfeedssync.exe C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch32.exe C:\Program Files\Apoint\Apoint.exe C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\Apoint\Apntex.exe C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Utilities\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ mStart Page = about:blank uURLSearchHooks: H - No File mURLSearchHooks: H - No File mWinlogon: SHELL=c:\windows\Explorer.exe BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - Adobe PDF Reader Link Helper BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2011\IEToolbar.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File TB: {C70E30C7-140A-4166-A2E8-43557E62B41A} - No File TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Controlled StartUp] c:\program files\startup organizer\Ctrl.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [LXBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBUtime.dll,_RunDLLEntry@16 mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2011\ieshow.exe" uPolicies-explorer: MaxRecentDocs = 4 (0x4) mPolicies-explorer: NoRecentDocsNetHood = 1 (0x1) IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Notify: IfxWlxEN - IfxWlxEN.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [2002-3-11 9216] R1 BdRawPr;BdRawPr;c:\windows\system32\drivers\bdrawpr.sys [2011-1-11 12960] R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [2010-8-25 76768] R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2005-11-29 36768] R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [2010-6-6 6144] R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\microsoft sql server\mssql10.mssqlserver\mssql\binn\fdlauncher.exe [2008-7-10 31256] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2011\TuneUpUtilitiesService32.exe [2010-11-23 1483072] R2 Updatesrv;BitDefender Desktop Update Service;c:\program files\bitdefender\bitdefender 2011\updatesrv.exe [2010-6-29 43424] R3 BDFM;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-4-22 152528] R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf.sys [2010-6-18 111696] R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [2010-10-21 44368] R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-8-29 36352] R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2010-5-21 71961] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2010-5-26 808448] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-7 10064] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 cpuz132;cpuz132;\??\c:\docume~1\user~2.mar\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\user~2.mar\locals~1\temp\cpuz132\cpuz132_x32.sys [?] S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-7-18 23456] S3 icsak;icsak;\??\c:\program files\checkpoint\zaforcefield\ak\icsak.sys --> c:\program files\checkpoint\zaforcefield\ak\icsak.sys [?] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-12-22 20952] S3 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-12-22 363344] S3 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\microsoft sql server\100\dts\binn\MsDtsSrvr.exe [2008-7-10 218136] S3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [2007-7-19 27392] S3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [2007-7-19 41728] S3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [2007-7-19 39808] S3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [2007-7-19 5888] S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\drivers\pwi_bus.sys --> c:\windows\system32\drivers\pwi_bus.sys [?] S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\drivers\pwi_mdfl.sys --> c:\windows\system32\drivers\pwi_mdfl.sys [?] S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\drivers\pwi_mdm.sys --> c:\windows\system32\drivers\pwi_mdm.sys [?] S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\drivers\pwi_oflt.sys --> c:\windows\system32\drivers\pwi_oflt.sys [?] S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\drivers\pwi_serd.sys --> c:\windows\system32\drivers\pwi_serd.sys [?] S3 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\microsoft sql server\msrs10.mssqlserver\reporting services\reportserver\bin\ReportingServicesService.exe [2009-3-30 1113448] S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-8-19 27064] S3 Update Server;BitDefender Update Server v2;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2010-6-29 307544] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2010-5-25 11520] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2003-3-31 14336] S3 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2010-6-28 633424] S4 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2010-6-28 970320] S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128] =============== Created Last 30 ================ 2011-01-12 17:10 0 a--sh--- C:\DkHyperbootSync 2011-01-11 21:29 385 a------- c:\windows\system32\user_gensett.xml 2011-01-11 21:26 --d----- c:\docume~1\user~2.mar\applic~1\BitDefender 2011-01-11 21:25 --d----- c:\program files\BitDefender 2011-01-11 21:18 --d----- c:\program files\common files\BitDefender 2011-01-11 21:18 --d----- c:\docume~1\alluse~1.win\applic~1\BitDefender 2011-01-11 21:17 306,104 a------- c:\windows\system32\drivers\trufos.sys 2011-01-11 21:17 327,368 a------- c:\windows\system32\drivers\bdfsfltr.sys 2011-01-11 21:17 12,960 a------- c:\windows\system32\drivers\bdrawpr.sys 2011-01-04 10:25 --d----- c:\docume~1\alluse~1.win\applic~1\bdch 2011-01-03 19:15 --d----- c:\docume~1\user~2.mar\applic~1\QuickScan 2011-01-02 20:29 --d----- c:\docume~1\user~2.mar\applic~1\IsolatedStorage 2011-01-02 17:14 --d----- c:\windows\system32\wbem\Repository 2011-01-02 17:12 --d----- c:\program files\Doublekiller Pro 2011-01-01 21:17 92 a------- C:\ResumeOmgApDeliveryMgrCntrl_SonicStage_EmdDownloadObj.dmf 2011-01-01 16:39 --d----- c:\docume~1\user~2.mar\applic~1\Vistanita 2011-01-01 16:39 --d----- c:\program files\Vistanita 2011-01-01 12:04 --d----- c:\docume~1\user~2.mar\applic~1\Malwarebytes 2011-01-01 12:04 --d----- c:\docume~1\user~2.mar\applic~1\FileMaker Pro Advanced 2011-01-01 12:04 --d----- c:\docume~1\user~2.mar\applic~1\DMCache 2011-01-01 12:04 --d-h--- c:\windows\PIF 2011-01-01 12:04 --d----- c:\windows\EHome 2011-01-01 12:04 --d----- c:\windows\Downloaded Installations 2010-12-31 15:54 20 a------- c:\windows\system32\SYSTEM 2010-12-30 19:46 --d----- c:\program files\SigmaTel 2010-12-29 11:41 16 a------- c:\windows\system32\asdict.dat 2010-12-29 11:41 4 a------- c:\windows\system32\aspdict-en.dat 2010-12-29 00:14 --d----- c:\program files\MagicISO 2010-12-25 15:22 57 a------- c:\windows\system32\mapisvc.inf 2010-12-25 15:22 132,608 a------- c:\windows\system32\dllcache\fxsclntr.dll 2010-12-25 15:22 31,744 a------- c:\windows\system32\dllcache\fxsroute.dll 2010-12-25 15:22 11,264 a------- c:\windows\system32\dllcache\fxssend.exe 2010-12-25 15:22 --d----- c:\windows\addins 2010-12-25 15:22 111,104 a------- c:\windows\system32\dllcache\fxscfgwz.dll 2010-12-23 15:46 52 a------- c:\windows\system32\ashttpstats.csv 2010-12-23 01:25 113,933 a------- c:\windows\system32\drivers\klin.dat 2010-12-23 01:25 97,549 a------- c:\windows\system32\drivers\klick.dat 2010-12-22 22:33 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2010-12-22 22:33 20,952 a------- c:\windows\system32\drivers\mbam.sys 2010-12-22 22:33 --d----- c:\program files\Malwarebytes' Anti-Malware 2010-12-22 19:08 0 a------- c:\windows\system32\wsbl.dat 2010-12-22 19:08 0 a------- c:\windows\system32\ph_white.dat 2010-12-22 19:08 0 a------- c:\windows\system32\ph_summ.dat 2010-12-22 19:08 0 a------- c:\windows\system32\ph_spoof.sig 2010-12-22 19:08 0 a------- c:\windows\system32\ph_sign.slf 2010-12-22 19:08 0 a------- c:\windows\system32\ph_fuzzy.sig 2010-12-22 19:08 0 a------- c:\windows\system32\ph_black.dat 2010-12-22 19:08 0 a------- c:\windows\system32\pcwords2.dat 2010-12-22 19:08 0 a------- c:\windows\system32\pcwords.dat 2010-12-22 19:08 0 a------- c:\windows\system32\pc_sign.slf 2010-12-22 19:08 0 a------- c:\windows\system32\ab_sbl.sig 2010-12-22 19:08 0 a------- c:\windows\system32\ab_bl.sig 2010-12-22 18:36 132 a------- c:\windows\system32\rezumatenoi.dat 2010-12-22 15:21 520,994 a------- c:\docume~1\alluse~1.win\applic~1\bdinstall.bin 2010-12-21 21:56 a-dsh--- C:\cmdcons 2010-12-21 21:40 146,432 a------- c:\windows\system32\dllcache\regedit.exe 2010-12-21 21:40 146,432 -------- c:\windows\regedit.exe 2010-12-20 17:40 3,696 a------- c:\windows\system32\RW_{72D15443-6504-11DF-8918-806D6172696F}.dat 2010-12-14 16:53 --d----- c:\program files\Windows Script Control 2010-12-14 16:53 --d----- c:\program files\common files\e.World 2010-12-13 18:00 --d----- c:\docume~1\user~2.mar\applic~1\MetaProducts 2010-12-13 18:00 73,728 a------- c:\windows\system32\SUO.cpl 2010-12-13 17:59 --d----- c:\program files\StartUp Organizer ==================== Find3M ==================== 2011-01-11 23:02 111,696 a------- c:\windows\system32\drivers\bdfndisf.sys 2011-01-11 21:50 152,528 a------- c:\windows\system32\drivers\bdfm.sys 2011-01-06 15:43 62,016 a------- c:\windows\system32\RW_FileType.dat 2011-01-06 15:43 15,956 a------- c:\windows\system32\RW_AppData.dat 2010-11-23 17:16 31,552 a------- c:\windows\system32\TURegOpt.exe 2010-11-23 17:11 29,504 a------- c:\windows\system32\uxtuneup.dll 2010-11-18 12:12 81,920 a------- c:\windows\system32\isign32.dll 2010-11-18 12:12 81,920 a------- c:\windows\system32\dllcache\isign32.dll 2010-11-09 08:52 536,576 a------- c:\windows\system32\dllcache\msado15.dll 2010-11-09 08:52 249,856 a------- c:\windows\system32\odbc32.dll 2010-11-09 08:52 249,856 a------- c:\windows\system32\dllcache\odbc32.dll 2010-11-09 08:52 200,704 a------- c:\windows\system32\dllcache\msadox.dll 2010-11-09 08:52 180,224 a------- c:\windows\system32\dllcache\msadomd.dll 2010-11-09 08:52 143,360 a------- c:\windows\system32\dllcache\msadco.dll 2010-11-09 08:52 102,400 a------- c:\windows\system32\dllcache\msjro.dll 2010-11-03 06:26 173,568 a------- c:\windows\system32\dllcache\ie4uinit.exe 2010-11-02 09:17 40,960 a------- c:\windows\system32\dllcache\ndproxy.sys 2010-10-28 07:13 290,048 a------- c:\windows\system32\dllcache\atmfd.dll 2010-10-28 07:13 290,048 a------- c:\windows\system32\atmfd.dll 2010-10-26 07:25 1,853,312 a------- c:\windows\system32\win32k.sys 2010-10-26 07:25 1,853,312 a------- c:\windows\system32\dllcache\win32k.sys 2010-10-20 16:56 4,212 a---h--- c:\windows\system32\zllictbl.dat 2010-03-29 18:40 100,256 a------- c:\program files\common files\LinkInstaller.exe 2010-07-10 22:21 2 a--shrot c:\windows\winstart.bat ============= FINISH: 17:32:43.00 ===============