DDS (Ver_09-02-01.01) - NTFSx86
Run by ASK at 11:32:29.76 on 20/02/2009
Internet Explorer: 7.0.5730.13
AV: avast! antivirus 4.8.1335 [VPS 090205-1] *On-access scanning disabled* (Outdated)
============== Running Processes ===============
============== Pseudo HJT Report ===============
uStart Page =
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Settings,ProxyOverride = *.local
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: NoExplorer - No File
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: RefresherBand Class: {b24ba06e-fb7b-4757-95c2-dc01125f750e} - c:\progra~1\yrefre~1\YREFRE~1.DLL
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DriverUpdaterPro] c:\program files\xpc tools\driver updater pro\DriverUpdaterPro.exe -t
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\www.msi
DPF: {5d86ddb5-bdf9-441b-9e9e-d4730f4ee499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-02-18 20:36 179,200 a------- c:\windows\SWREG.exe
2009-02-18 20:36 115,712 a------- c:\windows\sed.exe
2009-02-18 18:53 250 a------- c:\windows\gmer.ini
2009-02-17 20:32 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-02-17 20:30 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2009-02-17 20:25 221,184 a------- c:\windows\system32\wmpns.dll
2009-02-17 20:16 <DIR> --d----- c:\windows\pss
2009-02-17 17:26 <DIR> --d----- c:\program files\common files\Softwin
2009-02-16 23:04 <DIR> --d----- c:\windows\system32\3361
2009-02-16 23:04 108,336 a------- c:\windows\system32\MSWINSCK.OCX
2009-02-16 23:03 172 a------- c:\windows\system32\1C1.tmp
2009-02-16 22:16 <DIR> --d----- c:\docume~1\ask\applic~1\Malwarebytes
2009-02-16 22:15 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-16 22:15 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-16 22:15 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-16 22:15 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-16 22:02 <DIR> --d----- c:\program files\Enigma Software Group
2009-02-16 18:50 4 a------- c:\windows\xczuokls
2009-02-16 17:27 6 a------- c:\windows\_id.dat
2009-02-16 17:27 130 a------- c:\windows\adobe.bat
2009-02-16 15:56 676,352 a------- c:\windows\system32\rtl60.bpl
2009-02-16 15:55 67,072 ----h--- c:\windows\system32\secupdat.dat
2009-02-16 15:55 <DIR> --d----- c:\windows\system32\inf
2009-02-16 15:43 1,312 a------- c:\windows\mwgorzqr
2009-02-13 15:30 244 a---h--- C:\sqmnoopt17.sqm
2009-02-13 15:30 232 a---h--- C:\sqmdata17.sqm
2009-01-21 18:32 <DIR> --d----- c:\program files\common files\AnswerWorks 5.0
2009-01-21 18:32 3,523,872 a------- c:\windows\system32\cdintf300.dll
2009-01-21 18:32 1,848,608 a------- c:\windows\system32\acXMLParser.dll
2009-01-21 18:32 <DIR> --d----- c:\docume~1\ask\applic~1\Intuit
2009-01-21 18:32 <DIR> --d----- c:\program files\common files\Intuit
2009-01-21 18:31 <DIR> --d----- c:\program files\Quicken
2009-01-21 18:31 165 a------- c:\windows\QUICKEN.INI
2009-01-21 18:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Intuit
==================== Find3M ====================
2009-02-18 20:39 90,112 a------- c:\windows\DUMP7261.tmp
2009-02-17 21:04 90,112 a------- c:\windows\DUMP82fb.tmp
2009-02-17 20:05 90,112 a------- c:\windows\DUMPe5c7.tmp
2009-02-17 19:58 81,984 a------- c:\windows\system32\bdod.bin
2009-02-16 18:32 65,536 a------- c:\windows\DUMP86f2.tmp
2009-02-16 17:30 182,912 a------- c:\windows\system32\drivers\ndis.sys
2009-02-16 15:45 121,856 a------- c:\windows\system32\userinit.exe
2009-01-15 16:45 132 a------- C:\httpdwl.dat
2008-12-20 18:15 826,368 a------- c:\windows\system32\wininet.dll
2008-06-16 18:15 30,672 a------- c:\docume~1\ask\applic~1\GDIPFONTCACHEV1.DAT
============= FINISH: 11:32:36.89 ===============