. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.19190 Run by Jan at 6:45:07 on 2012-04-13 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1739 [GMT -5:00] . AV: Lavasoft Ad-Aware *Enabled/Updated* {BE5DD172-7F42-7948-1A60-E6A720288F81} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Aware *Enabled/Updated* {053C3096-5978-76C6-20D0-DDD55BAFC53C} FW: Lavasoft Ad-Aware *Enabled* {86665057-352D-7810-313F-4F92DEFBC8FA} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe C:\Windows\system32\dldtcoms.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\SMINST\BLService.exe C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Dell V305\dldtmon.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Windows\System32\igfxtray.exe C:\Program Files\Dell V305\dldtMsdMon.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\system32\wbem\wmiprvse.exe C:\PROGRA~1\AD-AWA~1\AdAware.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Windows\ehome\ehmsas.exe C:\Program Files\Ad-Aware Antivirus\Engine\SBAMSvc.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\wuauclt.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.bing.com/ mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5" mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0" mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0" mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [dldtmon.exe] "c:\program files\dell v305\dldtmon.exe" mRun: [dldtamon] "c:\program files\dell v305\dldtamon.exe" mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [Ad-Aware Antivirus] "c:\program files\ad-aware antivirus\AdAwareLauncher" --windows-run mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\users\jan\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab DPF: {DBDC1CDA-B64B-49F7-9535-6317AA416E51} - hxxps://viewtest.coba.unt.edu/downloads/VMware-viewclient.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.2.1 192.168.1.1 192.168.5.1 TCP: Interfaces\{689824B3-1CE9-4657-99A4-665F63D995A3} : DhcpNameServer = 192.168.2.1 192.168.1.1 192.168.5.1 Notify: igfxcui - igfxdev.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-9-7 64512] R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [2012-4-9 221784] R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-9-7 101720] R1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [2012-4-9 78936] R2 Ad-Aware Service;Ad-Aware Service;c:\program files\ad-aware antivirus\AdAwareService.exe [2012-3-29 1161072] R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service --> c:\windows\system32\dldtcoms.exe -service [?] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2008-10-23 365952] R2 SBAMSvc;Ad-Aware;c:\program files\ad-aware antivirus\engine\SBAMSvc.exe [2011-5-17 2804280] R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2011-5-11 74968] R2 wsnm;VMware View Client Service;c:\program files\vmware\vmware view\client\bin\wsnm.exe [2010-2-10 151552] R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-10-23 193840] R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-29 112128] R3 SBFWIMCLMP;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [2012-4-9 69208] R3 sbhips;sbhips;c:\windows\system32\drivers\sbhips.sys [2012-4-9 94040] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldtserv.exe [2008-2-25 99568] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-12 253600] S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2011-10-3 30312] S3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2012-4-9 26224] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-4-9 40776] S3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Service;c:\windows\system32\drivers\SbFwIm.sys [2012-4-9 69208] S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-10-3 96488] S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-10-3 12776] S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-10-3 121576] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-04-13 11:26:33 -------- d-sh--w- C:\$RECYCLE.BIN 2012-04-13 01:55:07 -------- d-----w- c:\program files\ESET 2012-04-13 01:49:50 637848 ----a-w- c:\windows\system32\npdeployJava1.dll 2012-04-13 01:29:18 -------- d-----w- c:\users\jan\appdata\local\Google 2012-04-13 01:29:08 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-04-13 01:29:08 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-04-13 01:12:26 6582328 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{2c3313c7-d44d-4195-b5a6-bad12fd67a6d}\mpengine.dll 2012-04-13 01:06:10 6582328 ------w- c:\programdata\microsoft\windows defender\definition updates\updates\mpengine.dll 2012-04-13 00:35:31 -------- d-----w- c:\users\jan\appdata\local\temp 2012-04-12 23:50:16 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat 2012-04-12 01:03:21 98816 ----a-w- c:\windows\sed.exe 2012-04-12 01:03:21 518144 ----a-w- c:\windows\SWREG.exe 2012-04-12 01:03:21 256000 ----a-w- c:\windows\PEV.exe 2012-04-12 01:03:21 208896 ----a-w- c:\windows\MBR.exe 2012-04-10 03:11:57 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-04-10 02:45:28 94040 ----a-w- c:\windows\system32\drivers\sbhips.sys 2012-04-10 02:45:25 78936 ----a-w- c:\windows\system32\drivers\sbtis.sys 2012-04-10 02:44:25 69208 ----a-w- c:\windows\system32\drivers\SbFwIm.sys 2012-04-10 02:44:24 221784 ----a-w- c:\windows\system32\drivers\SbFw.sys 2012-04-10 01:47:39 -------- d-----w- c:\users\jan\appdata\local\Privatefirewall 2012-04-10 01:40:27 -------- d-----w- c:\programdata\Privacyware 2012-04-09 10:39:39 -------- d-----w- c:\users\jan\appdata\roaming\AVG2012 2012-04-09 10:37:28 -------- d-----w- c:\programdata\AVG2012 2012-04-09 10:35:26 -------- d-----w- c:\program files\AVG 2012-04-09 10:30:35 -------- d-----w- c:\programdata\Common Files 2012-04-09 10:30:18 -------- d-----w- c:\programdata\MFAData 2012-04-09 10:02:15 26224 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2012-04-05 14:40:26 -------- d-----w- c:\users\jan\appdata\roaming\Malwarebytes 2012-04-05 14:39:50 -------- d-----w- c:\programdata\Malwarebytes 2012-04-05 14:39:48 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-04-05 14:39:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-04-04 02:13:21 -------- d-----w- c:\program files\Ad-Aware Antivirus 2012-04-04 02:12:09 -------- d-----w- c:\users\jan\appdata\local\adawarebp 2012-04-04 02:11:57 -------- d-----w- c:\program files\Toolbar Cleaner 2012-04-04 02:11:31 -------- d-----w- c:\program files\adawaretb 2012-04-04 02:04:12 -------- d-----w- c:\users\jan\appdata\roaming\Ad-Aware Antivirus 2012-03-26 15:41:34 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2012-03-17 08:00:55 -------- d-----w- c:\windows\CheckSur 2012-03-16 02:44:10 2044416 ----a-w- c:\windows\system32\win32k.sys 2012-03-16 02:44:06 613376 ----a-w- c:\windows\system32\rdpencom.dll 2012-03-16 02:44:06 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-16 02:43:43 683008 ----a-w- c:\windows\system32\d2d1.dll 2012-03-16 02:43:43 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2012-03-16 02:43:43 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2012-03-16 02:43:43 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2012-03-16 02:43:43 1068544 ----a-w- c:\windows\system32\DWrite.dll . ==================== Find3M ==================== . 2012-04-13 01:48:59 567696 ----a-w- c:\windows\system32\deployJava1.dll 2012-04-09 00:49:08 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys 2012-02-23 15:18:36 237072 ------w- c:\windows\system32\MpSigStub.exe . ============= FINISH: 6:46:31.85 ===============