fyrebyte
2011-01-24, 22:54
My IE connections are being hijacked & forwarded to random sites. I have MalwareBytes AM, CounterSpy & SPybot S&D all installed & mulitple scans, but no hits.
HijackThis shows no BHO or other strange startup items & Symantec AV shows no problems.
Please advise.
Thanks.
DDS (Ver_10-12-12.02) - NTFSx86
Run by tracie at 14:23:47.35 on Mon 01/24/2011
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.141 [GMT -6:00]
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBAMSvc.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBPIMSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBAMTray.exe
C:\WINDOWS\system32\M-AudioTaskBarIcon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\temp\ProcessExplorer\procexp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\temp\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070126
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SBAMTray] "c:\program files\sunbelt software\counterspy\consumer\SBAMTray.exe"
mRun: [M-Audio Taskbar Icon] c:\windows\system32\M-AudioTaskBarIcon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - hxxps://24.248.119.194/CACHE/stc/1/binaries/stcweb.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1295748519296
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://wr1.magnaent.com/dana-cached/setup/JuniperSetupSP1.cab
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
============= SERVICES / DRIVERS ===============
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-12-19 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-12-19 54968]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2011-1-21 21464]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-5-13 98392]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-3-7 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-3-7 169632]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-1-12 363344]
R2 SBAMSvc;CounterSpy Antispyware;c:\program files\sunbelt software\counterspy\consumer\SBAMSvc.exe [2010-8-20 2763080]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2011-1-21 69976]
R2 SBPIMSvc;SB Recovery Service;c:\program files\sunbelt software\counterspy\consumer\SBPIMSvc.exe [2010-8-20 181584]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-3-17 1799408]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-29 102448]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-1-12 20952]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110124.003\naveng.sys [2011-1-24 86008]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110124.003\navex15.sys [2011-1-24 1360760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-22 136176]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\drivers\CSVirtA.sys [2007-7-25 22136]
S3 MAUSBFASTTRACK;Service for M-Audio FastTrack;c:\windows\system32\drivers\MAudioFastTrack.sys [2010-12-7 158344]
S3 PortReporter;Port Reporter;c:\program files\portreporter\PortReporter.exe [2011-1-24 90183]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-3-17 115952]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2003-8-28 189792]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-01-24 19:17:25 1032192 ----a-w- c:\windows\explorer.exe
2011-01-24 17:49:26 -------- d-----w- C:\ComboFix
2011-01-24 16:49:01 -------- d-----w- c:\program files\PortReporter
2011-01-24 16:47:32 152856 ----a-w- c:\temp\PortRptr.exe
2011-01-24 13:21:18 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-01-24 13:21:18 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-24 09:02:55 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-01-24 07:37:43 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2011-01-24 07:37:38 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2011-01-24 07:37:30 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
2011-01-24 07:37:26 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
2011-01-24 07:37:20 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
2011-01-24 07:37:11 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
2011-01-24 07:36:59 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
2011-01-24 07:36:57 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
2011-01-24 07:36:49 19200 ----a-w- c:\windows\system32\dllcache\wstcodec.sys
2011-01-24 07:36:47 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys
2011-01-24 07:36:45 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
2011-01-24 07:36:04 154624 ----a-w- c:\windows\system32\dllcache\wlluc48.sys
2011-01-24 07:34:57 12415 ----a-w- c:\windows\system32\dllcache\wadv01nt.sys
2011-01-24 07:34:51 16925 ----a-w- c:\windows\system32\dllcache\w940nd.sys
2011-01-24 07:34:46 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys
2011-01-24 07:34:41 19528 ----a-w- c:\windows\system32\dllcache\w840nd.sys
2011-01-24 07:34:40 48256 ----a-w- c:\windows\system32\dllcache\w32.dll
2011-01-24 07:34:35 64605 ----a-w- c:\windows\system32\dllcache\vvoice.sys
2011-01-24 07:34:30 397502 ----a-w- c:\windows\system32\dllcache\vpctcom.sys
2011-01-24 07:34:23 604253 ----a-w- c:\windows\system32\dllcache\vmodem.sys
2011-01-24 07:34:18 249402 ----a-w- c:\windows\system32\dllcache\vinwm.sys
2011-01-24 07:34:13 24576 ----a-w- c:\windows\system32\dllcache\viairda.sys
2011-01-24 07:34:06 53760 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2011-01-24 07:32:57 28160 ----a-w- c:\windows\system32\dllcache\umaxu40.dll
2011-01-24 07:32:52 26624 ----a-w- c:\windows\system32\dllcache\umaxu22.dll
2011-01-24 07:32:48 69632 ----a-w- c:\windows\system32\dllcache\umaxu12.dll
2011-01-24 07:32:43 50688 ----a-w- c:\windows\system32\dllcache\umaxscan.dll
2011-01-24 07:32:38 22912 ----a-w- c:\windows\system32\dllcache\umaxpcls.sys
2011-01-24 07:32:34 50176 ----a-w- c:\windows\system32\dllcache\umaxp60.dll
2011-01-24 07:32:29 47616 ----a-w- c:\windows\system32\dllcache\umaxcam.dll
2011-01-24 07:32:25 211968 ----a-w- c:\windows\system32\dllcache\um54scan.dll
2011-01-24 07:32:20 216064 ----a-w- c:\windows\system32\dllcache\um34scan.dll
2011-01-24 07:32:14 11520 ----a-w- c:\windows\system32\dllcache\twotrack.sys
2011-01-24 07:32:13 14336 ----a-w- c:\windows\system32\dllcache\tsprof.exe
2011-01-24 07:32:05 166784 ----a-w- c:\windows\system32\dllcache\tridxpm.sys
2011-01-24 07:32:01 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2011-01-24 07:30:56 138528 ----a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2011-01-24 07:30:52 81408 ----a-w- c:\windows\system32\dllcache\tgiul50.dll
2011-01-24 07:30:48 149376 ----a-w- c:\windows\system32\dllcache\tffsport.sys
2011-01-24 07:30:46 19464 ----a-w- c:\windows\system32\dllcache\tdspx.sys
2011-01-24 07:30:41 17129 ----a-w- c:\windows\system32\dllcache\tdkcd31.sys
2011-01-24 07:30:37 37961 ----a-w- c:\windows\system32\dllcache\tdk100b.sys
2011-01-24 07:30:36 21896 ----a-w- c:\windows\system32\dllcache\tdipx.sys
2011-01-24 07:30:35 13192 ----a-w- c:\windows\system32\dllcache\tdasync.sys
2011-01-24 07:30:29 30464 ----a-w- c:\windows\system32\dllcache\tbatm155.sys
2011-01-24 07:30:23 7040 ----a-w- c:\windows\system32\dllcache\tandqic.sys
2011-01-24 07:30:18 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
2011-01-24 07:30:14 172768 ----a-w- c:\windows\system32\dllcache\t2r4disp.dll
2011-01-24 07:30:04 94293 ----a-w- c:\windows\system32\dllcache\sxports.dll
2011-01-24 07:28:53 24660 ----a-w- c:\windows\system32\dllcache\spxupchk.dll
2011-01-24 07:27:57 58368 ----a-w- c:\windows\system32\dllcache\smiminib.sys
2011-01-24 07:26:56 91294 ----a-w- c:\windows\system32\dllcache\skfpwin.sys
2011-01-24 07:26:52 94698 ----a-w- c:\windows\system32\dllcache\sk98xwin.sys
2011-01-24 07:26:47 157696 ----a-w- c:\windows\system32\dllcache\sisv256.dll
2011-01-24 07:26:42 50432 ----a-w- c:\windows\system32\dllcache\sisv.sys
2011-01-24 07:26:40 32768 ----a-w- c:\windows\system32\dllcache\sisnic.sys
2011-01-24 07:26:36 238592 ----a-w- c:\windows\system32\dllcache\sisgrv.dll
2011-01-24 07:26:31 104064 ----a-w- c:\windows\system32\dllcache\sisgrp.sys
2011-01-24 07:26:27 150144 ----a-w- c:\windows\system32\dllcache\sis6306v.dll
2011-01-24 07:26:23 68608 ----a-w- c:\windows\system32\dllcache\sis6306p.sys
2011-01-24 07:26:19 252032 ----a-w- c:\windows\system32\dllcache\sis300iv.dll
2011-01-24 07:26:15 101760 ----a-w- c:\windows\system32\dllcache\sis300ip.sys
2011-01-24 07:26:14 18944 ----a-w- c:\windows\system32\dllcache\simptcp.dll
2011-01-24 07:24:58 16640 ----a-w- c:\windows\system32\dllcache\scmstcs.sys
2011-01-24 07:23:58 166720 ----a-w- c:\windows\system32\dllcache\s3m.sys
2011-01-24 07:22:59 14848 ----a-w- c:\windows\system32\dllcache\register.exe
2011-01-24 07:22:48 19584 ----a-w- c:\windows\system32\dllcache\rasirda.sys
2011-01-24 07:22:41 714762 ----a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2011-01-24 07:22:37 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2011-01-24 07:22:33 41472 ----a-w- c:\windows\system32\dllcache\qvusd.dll
2011-01-24 07:22:29 3328 ----a-w- c:\windows\system32\dllcache\qv2kux.sys
2011-01-24 07:22:28 16384 ----a-w- c:\windows\system32\dllcache\quser.exe
2011-01-24 07:22:27 9728 ----a-w- c:\windows\system32\dllcache\query.exe
2011-01-24 07:22:18 6016 ----a-w- c:\windows\system32\dllcache\qic157.sys
2011-01-24 07:22:11 130942 ----a-w- c:\windows\system32\dllcache\ptserlv.sys
2011-01-24 07:22:07 112574 ----a-w- c:\windows\system32\dllcache\ptserlp.sys
2011-01-24 07:22:03 128286 ----a-w- c:\windows\system32\dllcache\ptserli.sys
2011-01-24 07:22:02 159232 ----a-w- c:\windows\system32\dllcache\ptpusd.dll
2011-01-24 07:20:57 259328 ----a-w- c:\windows\system32\dllcache\perm3dd.dll
2011-01-24 07:19:56 20480 ----a-w- c:\windows\system32\dllcache\ovcomc.dll
2011-01-24 07:19:53 351616 ----a-w- c:\windows\system32\dllcache\ovcodek2.sys
2011-01-24 07:19:49 116736 ----a-w- c:\windows\system32\dllcache\ovcodec2.dll
2011-01-24 07:19:45 31872 ----a-w- c:\windows\system32\dllcache\ovce.sys
2011-01-24 07:19:41 28032 ----a-w- c:\windows\system32\dllcache\ovcd.sys
2011-01-24 07:19:37 48000 ----a-w- c:\windows\system32\dllcache\ovcam2.sys
2011-01-24 07:19:33 25088 ----a-w- c:\windows\system32\dllcache\ovca.sys
2011-01-24 07:19:28 54186 ----a-w- c:\windows\system32\dllcache\otcsercb.sys
2011-01-24 07:19:25 43689 ----a-w- c:\windows\system32\dllcache\otceth5.sys
2011-01-24 07:19:21 27209 ----a-w- c:\windows\system32\dllcache\otc06x5.sys
2011-01-24 07:19:16 54528 ----a-w- c:\windows\system32\dllcache\opl3sax.sys
2011-01-24 07:19:05 198144 ----a-w- c:\windows\system32\dllcache\nv3.sys
2011-01-24 07:19:01 123776 ----a-w- c:\windows\system32\dllcache\nv3.dll
2011-01-24 07:18:48 51552 ----a-w- c:\windows\system32\dllcache\ntgrip.sys
2011-01-24 07:18:47 38912 ----a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2011-01-24 07:18:41 9344 ----a-w- c:\windows\system32\dllcache\ntapm.sys
2011-01-24 07:18:37 7552 ----a-w- c:\windows\system32\dllcache\nsmmc.sys
2011-01-24 07:18:36 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
2011-01-24 07:18:29 87040 ----a-w- c:\windows\system32\dllcache\nm6wdm.sys
2011-01-24 07:18:25 126080 ----a-w- c:\windows\system32\dllcache\nm5a2wdm.sys
2011-01-24 07:18:20 32840 ----a-w- c:\windows\system32\dllcache\ngrpci.sys
2011-01-24 07:18:18 132695 ----a-w- c:\windows\system32\dllcache\netwlan5.sys
2011-01-24 07:18:12 65278 ----a-w- c:\windows\system32\dllcache\netflx3.sys
2011-01-24 07:18:07 39264 ----a-w- c:\windows\system32\dllcache\neo20xx.sys
2011-01-24 07:18:03 60480 ----a-w- c:\windows\system32\dllcache\neo20xx.dll
2011-01-24 07:16:43 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys
2011-01-24 07:16:42 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
2011-01-24 07:16:36 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
2011-01-24 07:16:28 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
2011-01-24 07:16:26 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
2011-01-24 07:16:25 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll
2011-01-24 07:16:09 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
2011-01-24 07:16:04 6016 ----a-w- c:\windows\system32\dllcache\msfsio.sys
2011-01-24 07:16:03 51200 ----a-w- c:\windows\system32\dllcache\msdv.sys
2011-01-24 07:15:52 15232 ----a-w- c:\windows\system32\dllcache\mpe.sys
2011-01-24 07:15:44 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2011-01-24 07:15:16 6528 ----a-w- c:\windows\system32\dllcache\miniqic.sys
2011-01-24 07:15:14 34304 ----a-w- c:\windows\system32\dllcache\migisol.exe
2011-01-24 07:15:09 320384 ----a-w- c:\windows\system32\dllcache\mgaum.sys
2011-01-24 07:15:06 235648 ----a-w- c:\windows\system32\dllcache\mgaud.dll
2011-01-24 07:15:05 92416 ----a-w- c:\windows\system32\dllcache\mga.sys
2011-01-24 07:15:04 92032 ----a-w- c:\windows\system32\dllcache\mga.dll
2011-01-24 07:15:03 26112 ----a-w- c:\windows\system32\dllcache\memstpci.sys
2011-01-24 07:15:00 47616 ----a-w- c:\windows\system32\dllcache\memgrp.dll
2011-01-24 07:13:53 70730 ----a-w- c:\windows\system32\dllcache\lne100tx.sys
2011-01-24 07:13:49 20573 ----a-w- c:\windows\system32\dllcache\lne100.sys
2011-01-24 07:13:45 25065 ----a-w- c:\windows\system32\dllcache\lmndis3.sys
2011-01-24 07:13:41 15744 ----a-w- c:\windows\system32\dllcache\lit220p.sys
2011-01-24 07:13:38 34688 ----a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2011-01-24 07:13:34 26442 ----a-w- c:\windows\system32\dllcache\lanepic5.sys
2011-01-24 07:13:30 19016 ----a-w- c:\windows\system32\dllcache\ktc111.sys
2011-01-24 07:13:18 37376 ----a-w- c:\windows\system32\dllcache\kousd.dll
2011-01-24 07:13:17 70656 ----a-w- c:\windows\system32\dllcache\korwbrkr.dll
2011-01-24 07:13:12 253952 ----a-w- c:\windows\system32\dllcache\kdsusd.dll
2011-01-24 07:13:11 48640 ----a-w- c:\windows\system32\dllcache\kdsui.dll
2011-01-24 07:13:08 5632 ----a-w- c:\windows\system32\dllcache\kbdusa.dll
2011-01-24 07:12:58 9216 ----a-w- c:\windows\system32\dllcache\kbdnecat.dll
2011-01-24 07:12:58 7680 ----a-w- c:\windows\system32\dllcache\kbdnecnt.dll
2011-01-24 07:12:57 7168 ----a-w- c:\windows\system32\dllcache\kbdnec95.dll
2011-01-24 07:12:50 8192 ----a-w- c:\windows\system32\dllcache\kbdkor.dll
2011-01-24 07:12:47 8704 ----a-w- c:\windows\system32\dllcache\kbdjpn.dll
2011-01-24 07:12:24 6144 ----a-w- c:\windows\system32\dllcache\kbd106.dll
2011-01-24 07:12:20 5632 ----a-w- c:\windows\system32\dllcache\kbd103.dll
2011-01-24 07:12:17 6144 ----a-w- c:\windows\system32\dllcache\kbd101c.dll
2011-01-24 07:12:14 6144 ----a-w- c:\windows\system32\dllcache\kbd101b.dll
2011-01-24 07:12:12 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2011-01-24 07:12:10 18432 ----a-w- c:\windows\system32\dllcache\jupiw.dll
2011-01-24 07:11:59 26624 ----a-w- c:\windows\system32\dllcache\irstusb.sys
2011-01-24 07:11:56 18688 ----a-w- c:\windows\system32\dllcache\irsir.sys
2011-01-24 07:11:54 28160 ----a-w- c:\windows\system32\dllcache\irmon.dll
2011-01-24 07:11:38 23552 ----a-w- c:\windows\system32\dllcache\irmk7.sys
2011-01-24 07:11:37 151552 ----a-w- c:\windows\system32\dllcache\irftp.exe
2011-01-24 07:11:35 88192 ----a-w- c:\windows\system32\dllcache\irda.sys
2011-01-24 07:11:11 45632 ----a-w- c:\windows\system32\dllcache\ip5515.sys
2011-01-24 07:11:06 90200 ----a-w- c:\windows\system32\dllcache\io8ports.dll
2011-01-24 07:11:03 38784 ----a-w- c:\windows\system32\dllcache\io8.sys
2011-01-24 07:10:46 13056 ----a-w- c:\windows\system32\dllcache\inport.sys
2011-01-24 07:10:32 471102 ----a-w- c:\windows\system32\dllcache\imskdic.dll
2011-01-24 07:10:27 59904 ----a-w- c:\windows\system32\dllcache\imkrinst.exe
2011-01-24 07:10:23 45109 ----a-w- c:\windows\system32\dllcache\imjpuex.exe
2011-01-24 07:10:11 57398 ----a-w- c:\windows\system32\dllcache\imjpdadm.exe
2011-01-24 07:10:01 311359 ----a-w- c:\windows\system32\dllcache\imepadsv.exe
2011-01-24 07:10:00 44032 ----a-w- c:\windows\system32\dllcache\imekrmig.exe
2011-01-24 07:10:00 102463 ----a-w- c:\windows\system32\dllcache\imepadsm.dll
2011-01-24 07:09:20 372824 ----a-w- c:\windows\system32\dllcache\iconf32.dll
2011-01-24 07:09:16 100992 ----a-w- c:\windows\system32\dllcache\icam5usb.sys
2011-01-24 07:09:12 20480 ----a-w- c:\windows\system32\dllcache\icam5ext.dll
2011-01-24 07:09:09 45056 ----a-w- c:\windows\system32\dllcache\icam5com.dll
2011-01-24 07:09:06 154496 ----a-w- c:\windows\system32\dllcache\icam4usb.sys
2011-01-24 07:09:03 61952 ----a-w- c:\windows\system32\dllcache\icam4ext.dll
2011-01-24 07:07:59 488383 ----a-w- c:\windows\system32\dllcache\hsf_v124.sys
2011-01-24 07:06:57 165888 ----a-w- c:\windows\system32\dllcache\hpgt53.dll
2011-01-24 07:05:58 1733120 ----a-w- c:\windows\system32\dllcache\g400d.dll
2011-01-24 03:25:05 16074 ----a-w- c:\windows\system32\dllcache\fa312nd5.sys
2011-01-24 03:23:56 594238 ----a-w- c:\windows\system32\dllcache\es56hpi.sys
2011-01-24 03:23:51 595647 ----a-w- c:\windows\system32\dllcache\es56cvmp.sys
2011-01-24 03:23:46 174464 ----a-w- c:\windows\system32\dllcache\es198x.sys
2011-01-24 03:23:41 72192 ----a-w- c:\windows\system32\dllcache\es1969.sys
2011-01-24 03:23:36 40704 ----a-w- c:\windows\system32\dllcache\es1371mp.sys
2011-01-24 03:23:31 37120 ----a-w- c:\windows\system32\dllcache\es1370mp.sys
2011-01-24 03:23:25 61952 ----a-w- c:\windows\system32\dllcache\eqnloop.exe
2011-01-24 03:23:20 51200 ----a-w- c:\windows\system32\dllcache\eqnlogr.exe
2011-01-24 03:23:15 53248 ----a-w- c:\windows\system32\dllcache\eqndiag.exe
2011-01-24 03:23:10 629952 ----a-w- c:\windows\system32\dllcache\eqn.sys
2011-01-24 03:23:05 114944 ----a-w- c:\windows\system32\dllcache\epstw2k.sys
2011-01-24 03:23:00 18503 ----a-w- c:\windows\system32\dllcache\epro4.sys
2011-01-24 03:21:59 26141 ----a-w- c:\windows\system32\dllcache\el589nd5.sys
2011-01-24 03:20:55 29696 ----a-w- c:\windows\system32\dllcache\dm9pci5.sys
2011-01-24 03:19:56 159828 ----a-w- c:\windows\system32\dllcache\digihlc.dll
2011-01-24 03:18:59 86016 ----a-w- c:\windows\system32\dllcache\dc240usd.dll
2011-01-24 03:17:59 3072 ----a-w- c:\windows\system32\dllcache\cwbmidi.sys
2011-01-24 03:16:57 91264 ----a-w- c:\windows\system32\dllcache\cirrus.dll
2011-01-24 03:15:58 236032 ----a-w- c:\windows\system32\dllcache\camext20.dll
2011-01-24 03:15:54 74240 ----a-w- c:\windows\system32\dllcache\camexo20.dll
2011-01-24 03:15:50 171264 ----a-w- c:\windows\system32\dllcache\camdrv30.sys
2011-01-24 03:15:48 223232 ----a-w- c:\windows\system32\dllcache\camdrv21.sys
2011-01-24 03:15:46 314752 ----a-w- c:\windows\system32\dllcache\camdro21.sys
2011-01-24 03:15:43 10752 ----a-w- c:\windows\system32\dllcache\c_iscii.dll
2011-01-24 03:15:42 6656 ----a-w- c:\windows\system32\dllcache\c_is2022.dll
2011-01-24 03:14:24 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
2011-01-24 03:14:20 31529 ----a-w- c:\windows\system32\dllcache\brzwlan.sys
2011-01-24 03:14:18 10368 ----a-w- c:\windows\system32\dllcache\brusbscn.sys
2011-01-24 03:14:17 11008 ----a-w- c:\windows\system32\dllcache\brusbmdm.sys
2011-01-24 03:14:15 60416 ----a-w- c:\windows\system32\dllcache\brserwdm.sys
2011-01-24 03:14:13 9728 ----a-w- c:\windows\system32\dllcache\brserif.dll
2011-01-24 03:14:11 5120 ----a-w- c:\windows\system32\dllcache\brscnrsm.dll
2011-01-24 03:14:09 39552 ----a-w- c:\windows\system32\dllcache\brparwdm.sys
2011-01-24 03:14:07 3168 ----a-w- c:\windows\system32\dllcache\brparimg.sys
2011-01-24 03:14:03 41472 ----a-w- c:\windows\system32\dllcache\brmfusb.dll
2011-01-24 03:14:02 32256 ----a-w- c:\windows\system32\dllcache\brmfrsmg.exe
2011-01-24 03:14:00 29696 ----a-w- c:\windows\system32\dllcache\brmflpt.dll
2011-01-24 03:12:59 26624 ----a-w- c:\windows\system32\dllcache\ativxbar.sys
2011-01-24 03:11:45 5632 ----a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2011-01-24 03:10:00 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2011-01-24 02:27:06 624128 ----a-w- c:\temp\dds.scr
2011-01-23 18:23:33 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2011-01-23 18:23:32 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-01-23 01:43:53 388608 ----a-w- c:\temp\HijackThis.exe
2011-01-23 01:36:44 4177272 ----a-w- c:\temp\processexplorer\procexp.exe
2011-01-22 15:45:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-22 15:45:37 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-01-22 15:41:27 16409960 ----a-w- c:\temp\spybotsd162.exe
2011-01-22 05:23:59 -------- d-sha-r- C:\cmdcons
2011-01-22 05:11:16 4159861 ----a-r- c:\temp\ComboFix.exe
2011-01-22 04:52:19 69976 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2011-01-22 04:52:18 21464 ----a-w- c:\windows\system32\drivers\sbaphd.sys
2011-01-22 04:33:15 -------- d-----w- c:\program files\Audacity
2011-01-22 04:32:56 2228534 ----a-w- c:\temp\audacity-win-1.2.6.exe
2011-01-22 04:27:14 2899273 ----a-w- c:\temp\agsetup183se.exe
2011-01-22 02:11:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2011-01-22 02:11:45 60032 ----a-w- c:\windows\system32\dllcache\usbaudio.sys
2011-01-22 02:11:22 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-01-22 02:11:22 32128 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
2011-01-22 02:05:29 -------- d-----w- c:\program files\M-Audio
2011-01-22 02:05:29 -------- d-----w- c:\program files\common files\Digidesign
2011-01-22 02:01:33 10652168 ----a-w- c:\temp\Install M-Audio FastTrack 6_0_6.exe
2011-01-13 03:48:06 98816 ----a-w- c:\windows\sed.exe
2011-01-13 03:48:06 89088 ----a-w- c:\windows\MBR.exe
2011-01-13 03:48:06 256512 ----a-w- c:\windows\PEV.exe
2011-01-13 03:48:06 161792 ----a-w- c:\windows\SWREG.exe
2011-01-13 03:34:11 4151804 ----a-r- C:\ComboFix.exe
2011-01-12 12:14:37 -------- d-----w- c:\docume~1\tracie\applic~1\Malwarebytes
2011-01-12 12:13:52 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-12 12:13:51 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-01-12 12:13:47 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-12 12:13:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-12 02:08:11 -------- d-----w- c:\docume~1\tracie\locals~1\applic~1\Ahead
2011-01-12 02:03:25 -------- d-----w- c:\program files\Nero
2011-01-10 23:10:20 -------- d-----w- c:\docume~1\tracie\locals~1\applic~1\Thinstall
2011-01-10 23:10:20 -------- d-----w- c:\docume~1\tracie\applic~1\Thinstall
==================== Find3M ====================
2010-12-07 22:08:32 644104 ----a-w- c:\windows\system32\M-AudioTaskBarIcon.exe
2010-12-07 22:08:24 533000 ----a-w- c:\windows\system32\M-AudioFastTrackControlPanelApplet.cpl
2010-12-07 22:08:22 32776 ----a-w- c:\windows\system32\mausbasio.dll
2010-12-07 22:07:44 2525673 ----a-w- c:\windows\system32\madiousb.dll
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52:35 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-10-28 13:13:22 290048 ----a-w- c:\windows\system32\atmfd.dll
============= FINISH: 14:34:15.43 ===============
I am unable to attach the zipped attach.txt in 1st post...
HijackThis shows no BHO or other strange startup items & Symantec AV shows no problems.
Please advise.
Thanks.
DDS (Ver_10-12-12.02) - NTFSx86
Run by tracie at 14:23:47.35 on Mon 01/24/2011
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.141 [GMT -6:00]
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBAMSvc.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBPIMSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SBAMTray.exe
C:\WINDOWS\system32\M-AudioTaskBarIcon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\temp\ProcessExplorer\procexp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\temp\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070126
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SBAMTray] "c:\program files\sunbelt software\counterspy\consumer\SBAMTray.exe"
mRun: [M-Audio Taskbar Icon] c:\windows\system32\M-AudioTaskBarIcon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - hxxps://24.248.119.194/CACHE/stc/1/binaries/stcweb.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1295748519296
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://wr1.magnaent.com/dana-cached/setup/JuniperSetupSP1.cab
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
============= SERVICES / DRIVERS ===============
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-12-19 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-12-19 54968]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2011-1-21 21464]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-5-13 98392]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-3-7 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-3-7 169632]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-1-12 363344]
R2 SBAMSvc;CounterSpy Antispyware;c:\program files\sunbelt software\counterspy\consumer\SBAMSvc.exe [2010-8-20 2763080]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2011-1-21 69976]
R2 SBPIMSvc;SB Recovery Service;c:\program files\sunbelt software\counterspy\consumer\SBPIMSvc.exe [2010-8-20 181584]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-3-17 1799408]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-29 102448]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-1-12 20952]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110124.003\naveng.sys [2011-1-24 86008]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110124.003\navex15.sys [2011-1-24 1360760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-22 136176]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\drivers\CSVirtA.sys [2007-7-25 22136]
S3 MAUSBFASTTRACK;Service for M-Audio FastTrack;c:\windows\system32\drivers\MAudioFastTrack.sys [2010-12-7 158344]
S3 PortReporter;Port Reporter;c:\program files\portreporter\PortReporter.exe [2011-1-24 90183]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-3-17 115952]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2003-8-28 189792]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-01-24 19:17:25 1032192 ----a-w- c:\windows\explorer.exe
2011-01-24 17:49:26 -------- d-----w- C:\ComboFix
2011-01-24 16:49:01 -------- d-----w- c:\program files\PortReporter
2011-01-24 16:47:32 152856 ----a-w- c:\temp\PortRptr.exe
2011-01-24 13:21:18 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-01-24 13:21:18 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-24 09:02:55 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-01-24 07:37:43 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2011-01-24 07:37:38 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2011-01-24 07:37:30 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
2011-01-24 07:37:26 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
2011-01-24 07:37:20 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
2011-01-24 07:37:11 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
2011-01-24 07:36:59 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
2011-01-24 07:36:57 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
2011-01-24 07:36:49 19200 ----a-w- c:\windows\system32\dllcache\wstcodec.sys
2011-01-24 07:36:47 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys
2011-01-24 07:36:45 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
2011-01-24 07:36:04 154624 ----a-w- c:\windows\system32\dllcache\wlluc48.sys
2011-01-24 07:34:57 12415 ----a-w- c:\windows\system32\dllcache\wadv01nt.sys
2011-01-24 07:34:51 16925 ----a-w- c:\windows\system32\dllcache\w940nd.sys
2011-01-24 07:34:46 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys
2011-01-24 07:34:41 19528 ----a-w- c:\windows\system32\dllcache\w840nd.sys
2011-01-24 07:34:40 48256 ----a-w- c:\windows\system32\dllcache\w32.dll
2011-01-24 07:34:35 64605 ----a-w- c:\windows\system32\dllcache\vvoice.sys
2011-01-24 07:34:30 397502 ----a-w- c:\windows\system32\dllcache\vpctcom.sys
2011-01-24 07:34:23 604253 ----a-w- c:\windows\system32\dllcache\vmodem.sys
2011-01-24 07:34:18 249402 ----a-w- c:\windows\system32\dllcache\vinwm.sys
2011-01-24 07:34:13 24576 ----a-w- c:\windows\system32\dllcache\viairda.sys
2011-01-24 07:34:06 53760 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2011-01-24 07:32:57 28160 ----a-w- c:\windows\system32\dllcache\umaxu40.dll
2011-01-24 07:32:52 26624 ----a-w- c:\windows\system32\dllcache\umaxu22.dll
2011-01-24 07:32:48 69632 ----a-w- c:\windows\system32\dllcache\umaxu12.dll
2011-01-24 07:32:43 50688 ----a-w- c:\windows\system32\dllcache\umaxscan.dll
2011-01-24 07:32:38 22912 ----a-w- c:\windows\system32\dllcache\umaxpcls.sys
2011-01-24 07:32:34 50176 ----a-w- c:\windows\system32\dllcache\umaxp60.dll
2011-01-24 07:32:29 47616 ----a-w- c:\windows\system32\dllcache\umaxcam.dll
2011-01-24 07:32:25 211968 ----a-w- c:\windows\system32\dllcache\um54scan.dll
2011-01-24 07:32:20 216064 ----a-w- c:\windows\system32\dllcache\um34scan.dll
2011-01-24 07:32:14 11520 ----a-w- c:\windows\system32\dllcache\twotrack.sys
2011-01-24 07:32:13 14336 ----a-w- c:\windows\system32\dllcache\tsprof.exe
2011-01-24 07:32:05 166784 ----a-w- c:\windows\system32\dllcache\tridxpm.sys
2011-01-24 07:32:01 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2011-01-24 07:30:56 138528 ----a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2011-01-24 07:30:52 81408 ----a-w- c:\windows\system32\dllcache\tgiul50.dll
2011-01-24 07:30:48 149376 ----a-w- c:\windows\system32\dllcache\tffsport.sys
2011-01-24 07:30:46 19464 ----a-w- c:\windows\system32\dllcache\tdspx.sys
2011-01-24 07:30:41 17129 ----a-w- c:\windows\system32\dllcache\tdkcd31.sys
2011-01-24 07:30:37 37961 ----a-w- c:\windows\system32\dllcache\tdk100b.sys
2011-01-24 07:30:36 21896 ----a-w- c:\windows\system32\dllcache\tdipx.sys
2011-01-24 07:30:35 13192 ----a-w- c:\windows\system32\dllcache\tdasync.sys
2011-01-24 07:30:29 30464 ----a-w- c:\windows\system32\dllcache\tbatm155.sys
2011-01-24 07:30:23 7040 ----a-w- c:\windows\system32\dllcache\tandqic.sys
2011-01-24 07:30:18 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
2011-01-24 07:30:14 172768 ----a-w- c:\windows\system32\dllcache\t2r4disp.dll
2011-01-24 07:30:04 94293 ----a-w- c:\windows\system32\dllcache\sxports.dll
2011-01-24 07:28:53 24660 ----a-w- c:\windows\system32\dllcache\spxupchk.dll
2011-01-24 07:27:57 58368 ----a-w- c:\windows\system32\dllcache\smiminib.sys
2011-01-24 07:26:56 91294 ----a-w- c:\windows\system32\dllcache\skfpwin.sys
2011-01-24 07:26:52 94698 ----a-w- c:\windows\system32\dllcache\sk98xwin.sys
2011-01-24 07:26:47 157696 ----a-w- c:\windows\system32\dllcache\sisv256.dll
2011-01-24 07:26:42 50432 ----a-w- c:\windows\system32\dllcache\sisv.sys
2011-01-24 07:26:40 32768 ----a-w- c:\windows\system32\dllcache\sisnic.sys
2011-01-24 07:26:36 238592 ----a-w- c:\windows\system32\dllcache\sisgrv.dll
2011-01-24 07:26:31 104064 ----a-w- c:\windows\system32\dllcache\sisgrp.sys
2011-01-24 07:26:27 150144 ----a-w- c:\windows\system32\dllcache\sis6306v.dll
2011-01-24 07:26:23 68608 ----a-w- c:\windows\system32\dllcache\sis6306p.sys
2011-01-24 07:26:19 252032 ----a-w- c:\windows\system32\dllcache\sis300iv.dll
2011-01-24 07:26:15 101760 ----a-w- c:\windows\system32\dllcache\sis300ip.sys
2011-01-24 07:26:14 18944 ----a-w- c:\windows\system32\dllcache\simptcp.dll
2011-01-24 07:24:58 16640 ----a-w- c:\windows\system32\dllcache\scmstcs.sys
2011-01-24 07:23:58 166720 ----a-w- c:\windows\system32\dllcache\s3m.sys
2011-01-24 07:22:59 14848 ----a-w- c:\windows\system32\dllcache\register.exe
2011-01-24 07:22:48 19584 ----a-w- c:\windows\system32\dllcache\rasirda.sys
2011-01-24 07:22:41 714762 ----a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2011-01-24 07:22:37 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2011-01-24 07:22:33 41472 ----a-w- c:\windows\system32\dllcache\qvusd.dll
2011-01-24 07:22:29 3328 ----a-w- c:\windows\system32\dllcache\qv2kux.sys
2011-01-24 07:22:28 16384 ----a-w- c:\windows\system32\dllcache\quser.exe
2011-01-24 07:22:27 9728 ----a-w- c:\windows\system32\dllcache\query.exe
2011-01-24 07:22:18 6016 ----a-w- c:\windows\system32\dllcache\qic157.sys
2011-01-24 07:22:11 130942 ----a-w- c:\windows\system32\dllcache\ptserlv.sys
2011-01-24 07:22:07 112574 ----a-w- c:\windows\system32\dllcache\ptserlp.sys
2011-01-24 07:22:03 128286 ----a-w- c:\windows\system32\dllcache\ptserli.sys
2011-01-24 07:22:02 159232 ----a-w- c:\windows\system32\dllcache\ptpusd.dll
2011-01-24 07:20:57 259328 ----a-w- c:\windows\system32\dllcache\perm3dd.dll
2011-01-24 07:19:56 20480 ----a-w- c:\windows\system32\dllcache\ovcomc.dll
2011-01-24 07:19:53 351616 ----a-w- c:\windows\system32\dllcache\ovcodek2.sys
2011-01-24 07:19:49 116736 ----a-w- c:\windows\system32\dllcache\ovcodec2.dll
2011-01-24 07:19:45 31872 ----a-w- c:\windows\system32\dllcache\ovce.sys
2011-01-24 07:19:41 28032 ----a-w- c:\windows\system32\dllcache\ovcd.sys
2011-01-24 07:19:37 48000 ----a-w- c:\windows\system32\dllcache\ovcam2.sys
2011-01-24 07:19:33 25088 ----a-w- c:\windows\system32\dllcache\ovca.sys
2011-01-24 07:19:28 54186 ----a-w- c:\windows\system32\dllcache\otcsercb.sys
2011-01-24 07:19:25 43689 ----a-w- c:\windows\system32\dllcache\otceth5.sys
2011-01-24 07:19:21 27209 ----a-w- c:\windows\system32\dllcache\otc06x5.sys
2011-01-24 07:19:16 54528 ----a-w- c:\windows\system32\dllcache\opl3sax.sys
2011-01-24 07:19:05 198144 ----a-w- c:\windows\system32\dllcache\nv3.sys
2011-01-24 07:19:01 123776 ----a-w- c:\windows\system32\dllcache\nv3.dll
2011-01-24 07:18:48 51552 ----a-w- c:\windows\system32\dllcache\ntgrip.sys
2011-01-24 07:18:47 38912 ----a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2011-01-24 07:18:41 9344 ----a-w- c:\windows\system32\dllcache\ntapm.sys
2011-01-24 07:18:37 7552 ----a-w- c:\windows\system32\dllcache\nsmmc.sys
2011-01-24 07:18:36 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
2011-01-24 07:18:29 87040 ----a-w- c:\windows\system32\dllcache\nm6wdm.sys
2011-01-24 07:18:25 126080 ----a-w- c:\windows\system32\dllcache\nm5a2wdm.sys
2011-01-24 07:18:20 32840 ----a-w- c:\windows\system32\dllcache\ngrpci.sys
2011-01-24 07:18:18 132695 ----a-w- c:\windows\system32\dllcache\netwlan5.sys
2011-01-24 07:18:12 65278 ----a-w- c:\windows\system32\dllcache\netflx3.sys
2011-01-24 07:18:07 39264 ----a-w- c:\windows\system32\dllcache\neo20xx.sys
2011-01-24 07:18:03 60480 ----a-w- c:\windows\system32\dllcache\neo20xx.dll
2011-01-24 07:16:43 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys
2011-01-24 07:16:42 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
2011-01-24 07:16:36 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
2011-01-24 07:16:28 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
2011-01-24 07:16:26 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
2011-01-24 07:16:25 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll
2011-01-24 07:16:09 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
2011-01-24 07:16:04 6016 ----a-w- c:\windows\system32\dllcache\msfsio.sys
2011-01-24 07:16:03 51200 ----a-w- c:\windows\system32\dllcache\msdv.sys
2011-01-24 07:15:52 15232 ----a-w- c:\windows\system32\dllcache\mpe.sys
2011-01-24 07:15:44 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2011-01-24 07:15:16 6528 ----a-w- c:\windows\system32\dllcache\miniqic.sys
2011-01-24 07:15:14 34304 ----a-w- c:\windows\system32\dllcache\migisol.exe
2011-01-24 07:15:09 320384 ----a-w- c:\windows\system32\dllcache\mgaum.sys
2011-01-24 07:15:06 235648 ----a-w- c:\windows\system32\dllcache\mgaud.dll
2011-01-24 07:15:05 92416 ----a-w- c:\windows\system32\dllcache\mga.sys
2011-01-24 07:15:04 92032 ----a-w- c:\windows\system32\dllcache\mga.dll
2011-01-24 07:15:03 26112 ----a-w- c:\windows\system32\dllcache\memstpci.sys
2011-01-24 07:15:00 47616 ----a-w- c:\windows\system32\dllcache\memgrp.dll
2011-01-24 07:13:53 70730 ----a-w- c:\windows\system32\dllcache\lne100tx.sys
2011-01-24 07:13:49 20573 ----a-w- c:\windows\system32\dllcache\lne100.sys
2011-01-24 07:13:45 25065 ----a-w- c:\windows\system32\dllcache\lmndis3.sys
2011-01-24 07:13:41 15744 ----a-w- c:\windows\system32\dllcache\lit220p.sys
2011-01-24 07:13:38 34688 ----a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2011-01-24 07:13:34 26442 ----a-w- c:\windows\system32\dllcache\lanepic5.sys
2011-01-24 07:13:30 19016 ----a-w- c:\windows\system32\dllcache\ktc111.sys
2011-01-24 07:13:18 37376 ----a-w- c:\windows\system32\dllcache\kousd.dll
2011-01-24 07:13:17 70656 ----a-w- c:\windows\system32\dllcache\korwbrkr.dll
2011-01-24 07:13:12 253952 ----a-w- c:\windows\system32\dllcache\kdsusd.dll
2011-01-24 07:13:11 48640 ----a-w- c:\windows\system32\dllcache\kdsui.dll
2011-01-24 07:13:08 5632 ----a-w- c:\windows\system32\dllcache\kbdusa.dll
2011-01-24 07:12:58 9216 ----a-w- c:\windows\system32\dllcache\kbdnecat.dll
2011-01-24 07:12:58 7680 ----a-w- c:\windows\system32\dllcache\kbdnecnt.dll
2011-01-24 07:12:57 7168 ----a-w- c:\windows\system32\dllcache\kbdnec95.dll
2011-01-24 07:12:50 8192 ----a-w- c:\windows\system32\dllcache\kbdkor.dll
2011-01-24 07:12:47 8704 ----a-w- c:\windows\system32\dllcache\kbdjpn.dll
2011-01-24 07:12:24 6144 ----a-w- c:\windows\system32\dllcache\kbd106.dll
2011-01-24 07:12:20 5632 ----a-w- c:\windows\system32\dllcache\kbd103.dll
2011-01-24 07:12:17 6144 ----a-w- c:\windows\system32\dllcache\kbd101c.dll
2011-01-24 07:12:14 6144 ----a-w- c:\windows\system32\dllcache\kbd101b.dll
2011-01-24 07:12:12 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2011-01-24 07:12:10 18432 ----a-w- c:\windows\system32\dllcache\jupiw.dll
2011-01-24 07:11:59 26624 ----a-w- c:\windows\system32\dllcache\irstusb.sys
2011-01-24 07:11:56 18688 ----a-w- c:\windows\system32\dllcache\irsir.sys
2011-01-24 07:11:54 28160 ----a-w- c:\windows\system32\dllcache\irmon.dll
2011-01-24 07:11:38 23552 ----a-w- c:\windows\system32\dllcache\irmk7.sys
2011-01-24 07:11:37 151552 ----a-w- c:\windows\system32\dllcache\irftp.exe
2011-01-24 07:11:35 88192 ----a-w- c:\windows\system32\dllcache\irda.sys
2011-01-24 07:11:11 45632 ----a-w- c:\windows\system32\dllcache\ip5515.sys
2011-01-24 07:11:06 90200 ----a-w- c:\windows\system32\dllcache\io8ports.dll
2011-01-24 07:11:03 38784 ----a-w- c:\windows\system32\dllcache\io8.sys
2011-01-24 07:10:46 13056 ----a-w- c:\windows\system32\dllcache\inport.sys
2011-01-24 07:10:32 471102 ----a-w- c:\windows\system32\dllcache\imskdic.dll
2011-01-24 07:10:27 59904 ----a-w- c:\windows\system32\dllcache\imkrinst.exe
2011-01-24 07:10:23 45109 ----a-w- c:\windows\system32\dllcache\imjpuex.exe
2011-01-24 07:10:11 57398 ----a-w- c:\windows\system32\dllcache\imjpdadm.exe
2011-01-24 07:10:01 311359 ----a-w- c:\windows\system32\dllcache\imepadsv.exe
2011-01-24 07:10:00 44032 ----a-w- c:\windows\system32\dllcache\imekrmig.exe
2011-01-24 07:10:00 102463 ----a-w- c:\windows\system32\dllcache\imepadsm.dll
2011-01-24 07:09:20 372824 ----a-w- c:\windows\system32\dllcache\iconf32.dll
2011-01-24 07:09:16 100992 ----a-w- c:\windows\system32\dllcache\icam5usb.sys
2011-01-24 07:09:12 20480 ----a-w- c:\windows\system32\dllcache\icam5ext.dll
2011-01-24 07:09:09 45056 ----a-w- c:\windows\system32\dllcache\icam5com.dll
2011-01-24 07:09:06 154496 ----a-w- c:\windows\system32\dllcache\icam4usb.sys
2011-01-24 07:09:03 61952 ----a-w- c:\windows\system32\dllcache\icam4ext.dll
2011-01-24 07:07:59 488383 ----a-w- c:\windows\system32\dllcache\hsf_v124.sys
2011-01-24 07:06:57 165888 ----a-w- c:\windows\system32\dllcache\hpgt53.dll
2011-01-24 07:05:58 1733120 ----a-w- c:\windows\system32\dllcache\g400d.dll
2011-01-24 03:25:05 16074 ----a-w- c:\windows\system32\dllcache\fa312nd5.sys
2011-01-24 03:23:56 594238 ----a-w- c:\windows\system32\dllcache\es56hpi.sys
2011-01-24 03:23:51 595647 ----a-w- c:\windows\system32\dllcache\es56cvmp.sys
2011-01-24 03:23:46 174464 ----a-w- c:\windows\system32\dllcache\es198x.sys
2011-01-24 03:23:41 72192 ----a-w- c:\windows\system32\dllcache\es1969.sys
2011-01-24 03:23:36 40704 ----a-w- c:\windows\system32\dllcache\es1371mp.sys
2011-01-24 03:23:31 37120 ----a-w- c:\windows\system32\dllcache\es1370mp.sys
2011-01-24 03:23:25 61952 ----a-w- c:\windows\system32\dllcache\eqnloop.exe
2011-01-24 03:23:20 51200 ----a-w- c:\windows\system32\dllcache\eqnlogr.exe
2011-01-24 03:23:15 53248 ----a-w- c:\windows\system32\dllcache\eqndiag.exe
2011-01-24 03:23:10 629952 ----a-w- c:\windows\system32\dllcache\eqn.sys
2011-01-24 03:23:05 114944 ----a-w- c:\windows\system32\dllcache\epstw2k.sys
2011-01-24 03:23:00 18503 ----a-w- c:\windows\system32\dllcache\epro4.sys
2011-01-24 03:21:59 26141 ----a-w- c:\windows\system32\dllcache\el589nd5.sys
2011-01-24 03:20:55 29696 ----a-w- c:\windows\system32\dllcache\dm9pci5.sys
2011-01-24 03:19:56 159828 ----a-w- c:\windows\system32\dllcache\digihlc.dll
2011-01-24 03:18:59 86016 ----a-w- c:\windows\system32\dllcache\dc240usd.dll
2011-01-24 03:17:59 3072 ----a-w- c:\windows\system32\dllcache\cwbmidi.sys
2011-01-24 03:16:57 91264 ----a-w- c:\windows\system32\dllcache\cirrus.dll
2011-01-24 03:15:58 236032 ----a-w- c:\windows\system32\dllcache\camext20.dll
2011-01-24 03:15:54 74240 ----a-w- c:\windows\system32\dllcache\camexo20.dll
2011-01-24 03:15:50 171264 ----a-w- c:\windows\system32\dllcache\camdrv30.sys
2011-01-24 03:15:48 223232 ----a-w- c:\windows\system32\dllcache\camdrv21.sys
2011-01-24 03:15:46 314752 ----a-w- c:\windows\system32\dllcache\camdro21.sys
2011-01-24 03:15:43 10752 ----a-w- c:\windows\system32\dllcache\c_iscii.dll
2011-01-24 03:15:42 6656 ----a-w- c:\windows\system32\dllcache\c_is2022.dll
2011-01-24 03:14:24 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
2011-01-24 03:14:20 31529 ----a-w- c:\windows\system32\dllcache\brzwlan.sys
2011-01-24 03:14:18 10368 ----a-w- c:\windows\system32\dllcache\brusbscn.sys
2011-01-24 03:14:17 11008 ----a-w- c:\windows\system32\dllcache\brusbmdm.sys
2011-01-24 03:14:15 60416 ----a-w- c:\windows\system32\dllcache\brserwdm.sys
2011-01-24 03:14:13 9728 ----a-w- c:\windows\system32\dllcache\brserif.dll
2011-01-24 03:14:11 5120 ----a-w- c:\windows\system32\dllcache\brscnrsm.dll
2011-01-24 03:14:09 39552 ----a-w- c:\windows\system32\dllcache\brparwdm.sys
2011-01-24 03:14:07 3168 ----a-w- c:\windows\system32\dllcache\brparimg.sys
2011-01-24 03:14:03 41472 ----a-w- c:\windows\system32\dllcache\brmfusb.dll
2011-01-24 03:14:02 32256 ----a-w- c:\windows\system32\dllcache\brmfrsmg.exe
2011-01-24 03:14:00 29696 ----a-w- c:\windows\system32\dllcache\brmflpt.dll
2011-01-24 03:12:59 26624 ----a-w- c:\windows\system32\dllcache\ativxbar.sys
2011-01-24 03:11:45 5632 ----a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2011-01-24 03:10:00 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2011-01-24 02:27:06 624128 ----a-w- c:\temp\dds.scr
2011-01-23 18:23:33 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2011-01-23 18:23:32 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-01-23 01:43:53 388608 ----a-w- c:\temp\HijackThis.exe
2011-01-23 01:36:44 4177272 ----a-w- c:\temp\processexplorer\procexp.exe
2011-01-22 15:45:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-22 15:45:37 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-01-22 15:41:27 16409960 ----a-w- c:\temp\spybotsd162.exe
2011-01-22 05:23:59 -------- d-sha-r- C:\cmdcons
2011-01-22 05:11:16 4159861 ----a-r- c:\temp\ComboFix.exe
2011-01-22 04:52:19 69976 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2011-01-22 04:52:18 21464 ----a-w- c:\windows\system32\drivers\sbaphd.sys
2011-01-22 04:33:15 -------- d-----w- c:\program files\Audacity
2011-01-22 04:32:56 2228534 ----a-w- c:\temp\audacity-win-1.2.6.exe
2011-01-22 04:27:14 2899273 ----a-w- c:\temp\agsetup183se.exe
2011-01-22 02:11:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2011-01-22 02:11:45 60032 ----a-w- c:\windows\system32\dllcache\usbaudio.sys
2011-01-22 02:11:22 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-01-22 02:11:22 32128 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
2011-01-22 02:05:29 -------- d-----w- c:\program files\M-Audio
2011-01-22 02:05:29 -------- d-----w- c:\program files\common files\Digidesign
2011-01-22 02:01:33 10652168 ----a-w- c:\temp\Install M-Audio FastTrack 6_0_6.exe
2011-01-13 03:48:06 98816 ----a-w- c:\windows\sed.exe
2011-01-13 03:48:06 89088 ----a-w- c:\windows\MBR.exe
2011-01-13 03:48:06 256512 ----a-w- c:\windows\PEV.exe
2011-01-13 03:48:06 161792 ----a-w- c:\windows\SWREG.exe
2011-01-13 03:34:11 4151804 ----a-r- C:\ComboFix.exe
2011-01-12 12:14:37 -------- d-----w- c:\docume~1\tracie\applic~1\Malwarebytes
2011-01-12 12:13:52 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-12 12:13:51 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-01-12 12:13:47 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-12 12:13:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-12 02:08:11 -------- d-----w- c:\docume~1\tracie\locals~1\applic~1\Ahead
2011-01-12 02:03:25 -------- d-----w- c:\program files\Nero
2011-01-10 23:10:20 -------- d-----w- c:\docume~1\tracie\locals~1\applic~1\Thinstall
2011-01-10 23:10:20 -------- d-----w- c:\docume~1\tracie\applic~1\Thinstall
==================== Find3M ====================
2010-12-07 22:08:32 644104 ----a-w- c:\windows\system32\M-AudioTaskBarIcon.exe
2010-12-07 22:08:24 533000 ----a-w- c:\windows\system32\M-AudioFastTrackControlPanelApplet.cpl
2010-12-07 22:08:22 32776 ----a-w- c:\windows\system32\mausbasio.dll
2010-12-07 22:07:44 2525673 ----a-w- c:\windows\system32\madiousb.dll
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52:35 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-10-28 13:13:22 290048 ----a-w- c:\windows\system32\atmfd.dll
============= FINISH: 14:34:15.43 ===============
I am unable to attach the zipped attach.txt in 1st post...