.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Greg at 16:55:29 on 2011-10-07
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2217 [GMT -4:00]
.
AV: AVG Anti-Virus *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\3238208952:1205533758.exe
svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Linksys\WUSB54GSC\WLService.exe
C:\Program Files\Linksys\WUSB54GSC\WUSB54GSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\internet explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uURLSearchHooks: H - No File
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: adfabonppr Object: {26d02f99-ae5b-4533-ad67-e23b4b20d60d} - c:\windows\$blstun$\qgnnv.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: brumabonpgrm Object: {795f4311-02c9-4b7b-a9bb-78d4fe68a98d} - c:\windows\$blstun$\lmatn.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [dlcxmon.exe] "c:\program files\dell photo aio printer 926\dlcxmon.exe"
mRun: [MemoryCardManager] c:\program files\dell photo aio printer 926\memcard.exe
mRun: [FaxCenterServer] "c:\program files\dell pc fax\fm3032.exe" /s
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [Corel Photo Downloader] c:\program files\corel\corel photo album 6\MediaDetect.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [DLCXCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCXtime.dll,_RunDLLEntry@16
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QNyxA1uvDoFpHs8234A] c:\windows\system32\FsWKfRL9gXjCkBz.exe
mRun: [volmgr] %APPDATA%\volmgr.exe
mRun: [DibD3pnG5Q6W8R8234A] c:\windows\system32\S4pmH5sQJdLgZhC.exe
dRun: [tgtYlbINMYG.exe] c:\documents and settings\all users\application data\tgtYlbINMYG.exe
StartupFolder: c:\docume~1\greg\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-system: DisableTaskMgr = 1 (0x1)
dPolicies-explorer: NoDesktop = 1 (0x1)
dPolicies-system: DisableTaskMgr = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{477A5AC8-5CBC-4C60-BA9C-A2AF7719E1D3} : DhcpNameServer = 192.168.0.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: avgrsstarter - avgrsstx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\greg\application data\mozilla\firefox\profiles\8zvej24t.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage -
WWW.GOOGLE.COM
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4ae25787&v=7.007.026.001&i=26&tp=ab&iy=&ychte=us&lng=en-US&q=
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Search
FF - user.js: browser.search.order.1 - Search
FF - user.js: keyword.URL - hxxp://search.internet-search-results.com/?sid=10101182100&s=
============= SERVICES / DRIVERS ===============
.
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-4-3 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-4-3 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-4-3 29712]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-4-3 243152]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-6-25 308136]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 WUSB54GSC;WUSB54GSC;c:\program files\linksys\wusb54gsc\WLService.exe [2008-11-26 53307]
S2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-6-25 921952]
S2 gupdate1c99b7fb460f64;Google Update Service (gupdate1c99b7fb460f64);c:\program files\google\update\GoogleUpdate.exe [2009-3-2 133104]
S3 atidgllk;atidgllk;c:\dell\drivers\r169419\atidgllk.sys [2008-4-2 12048]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-10-26 1025352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-3-2 133104]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-9-30 27064]
.
=============== Created Last 30 ================
.
2011-10-07 20:50:36 -------- d-----w- c:\documents and settings\greg\application data\VK8gRZqhYwUrOtP
2011-10-07 20:50:10 -------- d-----w- c:\documents and settings\greg\application data\wvD2obF4pHsJd
2011-10-07 20:50:10 -------- d-----w- c:\documents and settings\greg\application data\H3pnG5aQHdK
2011-10-07 20:43:27 -------- d-----w- c:\windows\system32\NnG4aQH6dKfLhX
2011-10-07 20:43:27 -------- d-----w- C:\EwkUVrlOBx0c1b3
2011-10-07 20:43:16 3001856 ----a-w- c:\windows\system32\S4pmH5sQJdLgZhC.exe
2011-10-07 20:43:15 -------- d-----w- C:\urzPNyxA1v2b
2011-10-07 20:31:55 -------- d-----w- c:\documents and settings\greg\application data\XycA1ivD3n4m6W7
2011-10-07 20:31:54 -------- d-----w- c:\documents and settings\greg\application data\XIVrlONtx0c2b3n
2011-10-06 21:11:23 -------- d-----w- c:\documents and settings\greg\application data\hJ7dEK8gRqYwUrO
2011-10-06 21:11:22 -------- d-----w- c:\documents and settings\greg\application data\gonG4amH6W7E9Tq
2011-10-06 01:07:37 -------- d-----w- c:\documents and settings\greg\application data\tVrlOBtxPuSiD
2011-10-06 01:07:37 -------- d-----w- c:\documents and settings\greg\application data\hpnG4aQH6
2011-10-05 23:02:49 -------- d-----w- c:\documents and settings\greg\application data\XF4amH6sW7
2011-10-05 23:02:49 -------- d-----w- c:\documents and settings\greg\application data\HdWK8fRZ9TwUeIt
2011-10-05 20:02:10 -------- d-----w- c:\documents and settings\greg\application data\ZVrlONtxPuSiDpG
2011-10-05 20:02:09 -------- d-----w- c:\documents and settings\greg\application data\bmH5sQJ7dLgZhCk
2011-10-05 19:49:06 120832 ---ha-w- c:\windows\system32\beep.sys
2011-10-05 19:48:50 468480 ----a-w- c:\documents and settings\all users\application data\tgtYlbINMYG.exe
2011-10-05 19:48:35 -------- d--h--w- c:\windows\$BLSTUN$
2011-10-05 19:48:27 -------- d-----w- c:\documents and settings\all users\application data\WSTB
2011-10-05 19:23:34 -------- d-----w- c:\documents and settings\greg\application data\hmH5sQJ7dLgZhCk
2011-10-05 19:23:33 -------- d-----w- c:\documents and settings\greg\application data\VjUCekIBrPyAuDo
2011-10-04 21:46:55 -------- d-----w- c:\documents and settings\greg\application data\sEL8gTZqhCk
2011-10-04 21:46:55 -------- d-----w- c:\documents and settings\greg\application data\nNycA1uvDoFp
2011-10-03 23:37:31 -------- d-----w- c:\documents and settings\greg\application data\k7fRL9gTXjCkBzN
2011-10-03 23:37:31 -------- d-----w- c:\documents and settings\greg\application data\BonG4aQH6W
2011-10-03 23:30:18 -------- d-----w- c:\documents and settings\greg\application data\dD3onF4am6W7E9T
2011-10-03 23:30:17 -------- d-----w- c:\documents and settings\greg\application data\DcS2ibF3pGaJdKf
2011-10-03 19:04:23 2398208 ---ha-w- c:\windows\system32\FsWKfRL9gXjCkBz.exe
2011-10-01 14:45:53 -------- d--h--w- C:\ComboFix
2011-10-01 00:04:30 -------- d-sh--w- c:\documents and settings\greg\PrivacIE
2011-10-01 00:03:28 -------- d-sh--w- c:\documents and settings\greg\IETldCache
2011-10-01 00:00:28 -------- d--h--w- c:\windows\ie8updates
2011-09-30 23:58:20 -------- dc-h--w- c:\windows\ie8
2011-09-30 23:56:28 7680 ---h--w- c:\windows\system32\dllcache\iecompat.dll
2011-09-30 23:56:26 602112 ---h--w- c:\windows\system32\dllcache\msfeeds.dll
2011-09-30 23:56:26 55296 ---h--w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-09-30 23:56:25 743424 ---h--w- c:\windows\system32\dllcache\iedvtool.dll
2011-09-30 23:56:25 247808 ---h--w- c:\windows\system32\dllcache\ieproxy.dll
2011-09-30 23:56:25 12800 ---h--w- c:\windows\system32\dllcache\xpshims.dll
2011-09-30 23:56:24 1991680 ---h--w- c:\windows\system32\dllcache\iertutil.dll
2011-09-30 23:56:23 11081728 ---h--w- c:\windows\system32\dllcache\ieframe.dll
2011-09-30 23:31:32 -------- d-----w- c:\documents and settings\greg\local settings\application data\VS Revo Group
2011-09-30 23:31:23 27064 ---ha-w- c:\windows\system32\drivers\revoflt.sys
2011-09-30 23:31:22 -------- d--h--w- c:\program files\VS Revo Group
2011-09-24 02:52:51 -------- d--h--w- C:\_OTL
2011-09-21 18:22:41 -------- d-----w- c:\documents and settings\greg\local settings\application data\ApplicationHistory
2011-09-21 17:38:27 -------- d--h--w- C:\COMBO-FIX4520C
2011-09-21 17:35:22 -------- d--h--w- C:\COMBO-FIX17960C
2011-09-14 23:27:11 -------- d-----w- c:\documents and settings\greg\application data\SUPERAntiSpyware.com
2011-09-14 23:26:42 -------- d--h--w- c:\program files\SUPERAntiSpyware
2011-09-14 23:26:42 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2011-09-13 20:39:51 -------- d--h--w- c:\program files\iPod
2011-09-13 20:39:42 -------- d--h--w- c:\program files\iTunes
2011-09-12 23:46:31 -------- d--h--w- c:\program files\ESET
2011-09-10 01:07:09 -------- d--h--w- c:\windows\PIF
.
==================== Find3M ====================
.
2011-10-05 19:51:57 120832 ---ha-w- c:\windows\system32\drivers\beep.sys
2011-09-09 09:12:13 599040 ---ha-w- c:\windows\system32\crypt32.dll
2011-09-06 17:21:58 5852 --sha-w- c:\windows\system32\KGyGaAvL.sys
2011-09-06 17:21:57 104 --sh--r- c:\windows\system32\5018098FE8.sys
2011-08-30 18:17:11 404640 ---ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29:31 456320 ---ha-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-12 15:20:54 83816 ---ha-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20:54 73064 ---ha-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20:54 178536 ---ha-w- c:\windows\system32\dnssdX.dll
.
============= FINISH: 17:02:24.75 ===============