DDS:
DDS (Ver_09-05-14.01) - NTFSx86
Run by Chris Wiswell at 21:35:21.81 on Tue 06/02/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.624 [GMT -7:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IDT\WDM\STacSV.exe
svchost.exe
svchost.exe "C:\WINDOWS\system32\apphelpc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\sttray.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Chris Wiswell\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://mail.google.com/mail/?shva=1#inbox
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IDTSysTrayApp] sttray.exe
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_06\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HP Mobile Broadband] c:\swsetup\hpqwwan\HPMobileBroadband.exe /TrayMode
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
StartupFolder: c:\docume~1\chrisw~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
============= SERVICES / DRIVERS ===============
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2008-12-19 112128]
S2 amd64si;amd64si;\??\c:\windows\system32\drivers\amd64si.sys --> c:\windows\system32\drivers\amd64si.sys [?]
S2 MSDTCdmserver;Distributed Transaction Coordinator MSDTCdmserver;c:\windows\system32\apphelpc.exe srv --> c:\windows\system32\apphelpc.exe srv [?]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
=============== Created Last 30 ================
2009-06-02 21:15 <DIR> a-dshr-- C:\cmdcons
2009-06-02 21:12 161,792 a------- c:\windows\SWREG.exe
2009-06-02 21:12 154,624 a------- c:\windows\PEV.exe
2009-06-02 21:12 98,816 a------- c:\windows\sed.exe
2009-06-02 20:44 <DIR> --d----- c:\program files\Compaq
2009-06-02 20:43 <DIR> --d----- C:\CPQSYSTEM
2009-06-02 20:28 <DIR> --d----- C:\DriveKey
2009-06-01 00:09 1,089,593 -------- c:\windows\system32\dllcache\ntprint.cat
2009-05-31 23:50 <DIR> --d----- c:\windows\SHELLNEW
2009-05-31 22:48 <DIR> --d----- c:\docume~1\chrisw~1\applic~1\GetRightToGo
2009-05-31 21:35 <DIR> --d----- c:\windows\system32\XPSViewer
2009-05-31 21:32 597,504 -------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-05-31 21:32 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-05-31 21:32 575,488 -------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-05-31 21:32 117,760 -------- c:\windows\system32\prntvpt.dll
2009-05-31 21:32 89,088 -------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-05-31 21:32 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-05-31 21:32 1,676,288 -------- c:\windows\system32\dllcache\xpssvcs.dll
2009-05-31 21:32 <DIR> --d----- C:\4f748c821ba0cde614dc12ff8f905541
2009-05-30 20:37 492 a------- C:\hpfr5550.xml
2009-05-30 20:34 800 a------- c:\windows\hpinfo.lnk
2009-05-30 20:34 <DIR> --d----- c:\program files\hp deskjet 5550 series
2009-05-30 20:33 147,512 a------- c:\windows\system32\hpzlnt07.dll
2009-05-30 20:14 25,856 a------- c:\windows\system32\drivers\usbprint.sys
2009-05-27 21:29 <DIR> --d----- c:\program files\Trend Micro
2009-05-27 17:03 2 ----h--- c:\windows\sonce122712.dat
2009-05-26 09:17 <DIR> --d----- c:\program files\SkillSoft
2009-05-26 09:17 <DIR> --d----- C:\SSTemp
2009-05-25 22:14 <DIR> --d----- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-05-25 22:14 <DIR> --d----- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-05-25 22:14 <DIR> --d----- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-05-25 22:14 <DIR> --d----- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-05-25 22:05 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-05-25 22:05 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-05-25 21:06 17,408 a------- c:\windows\system32\oldSYSDLL.exe
2009-05-25 21:06 2 ----h--- c:\windows\sonce122730.dat
2009-05-25 21:04 32 a--s---- c:\windows\system32\2159569980.dat
2009-05-25 21:04 51,712 ---shr-- c:\windows\system32\apphelpc.exe
2009-05-23 16:37 12,160 a------- c:\windows\system32\drivers\mouhid.sys
2009-05-23 16:37 10,368 a------- c:\windows\system32\drivers\hidusb.sys
2009-05-18 10:26 <DIR> --dsh--- c:\documents and settings\chris wiswell\PrivacIE
2009-05-18 10:26 <DIR> --dsh--- c:\documents and settings\chris wiswell\IETldCache
2009-05-18 09:40 <DIR> --d----- c:\windows\ie8updates
2009-05-18 09:37 <DIR> -cd-h--- c:\windows\ie8
2009-05-18 09:35 102,400 -------- c:\windows\system32\dllcache\iecompat.dll
2009-05-12 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2009-05-12 14:06 208,744 a------- c:\windows\system32\muweb.dll
2009-05-12 14:06 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-05-11 12:45 1,672 a------- c:\docume~1\chrisw~1\applic~1\wklnhst.dat
2009-05-11 05:04 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-05-11 05:02 247,326 -------- c:\windows\system32\dllcache\strmdll.dll
2009-05-11 05:01 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-05-11 05:01 1,106,944 -------- c:\windows\system32\dllcache\msxml3.dll
2009-05-11 04:58 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-05-11 04:58 1,203,922 -------- c:\windows\system32\dllcache\sysmain.sdb
2009-05-11 04:58 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
2009-05-11 04:57 <DIR> --d----- c:\windows\system32\PreInstall
2009-05-11 00:45 221,184 a------- c:\windows\system32\wmpns.dll
2009-05-11 00:43 <DIR> --d----- c:\documents and settings\chris wiswell\Bluetooth Software
2009-05-11 00:43 <DIR> --d----- c:\docume~1\chrisw~1\applic~1\TMP
2009-05-11 00:43 <DIR> --d----- c:\documents and settings\Chris Wiswell
2009-05-11 00:43 873,134 a------- c:\windows\system32\oem1.inf
2009-05-11 00:27 185,344 a------- c:\windows\system32\Thawbrkr.dll
2009-05-11 00:27 10,752 a------- c:\windows\system32\c_iscii.dll
2009-05-11 00:27 66,594 a------- c:\windows\system32\c_864.nls
2009-05-11 00:27 66,594 a------- c:\windows\system32\c_720.nls
2009-05-11 00:27 66,082 a------- c:\windows\system32\c_708.nls
2009-05-11 00:27 66,082 a------- c:\windows\system32\C_28596.NLS
2009-05-11 00:27 66,082 a------- c:\windows\system32\c_10004.nls
2009-05-11 00:27 5,632 a------- c:\windows\system32\kbdusa.dll
2009-05-11 00:27 66,594 a------- c:\windows\system32\c_862.nls
2009-05-11 00:27 66,082 a------- c:\windows\system32\c_10005.nls
2009-05-11 00:27 66,082 a------- c:\windows\system32\c_10021.nls
2009-05-11 00:27 6,144 a------- c:\windows\system32\ftlx041e.dll
2009-05-11 00:26 8,192 a------- c:\windows\REGLOCS.OLD
2009-05-10 20:08 272,128 -------- c:\windows\system32\drivers\bthport.sys
2009-05-10 20:08 272,128 -------- c:\windows\system32\dllcache\bthport.sys
2009-05-10 20:06 203,136 -------- c:\windows\system32\dllcache\rmcast.sys
2009-05-10 20:06 331,776 -------- c:\windows\system32\dllcache\msadce.dll
2009-05-10 20:06 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-05-10 20:04 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
==================== Find3M ====================
2009-03-21 07:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
2009-03-08 14:09 638,816 a------- c:\windows\system32\dllcache\iexplore.exe
2009-03-08 14:09 391,536 a------- c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 04:41 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll
2009-03-08 04:39 11,063,808 a------- c:\windows\system32\dllcache\ieframe.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\dllcache\wininet.dll
2009-03-08 04:34 1,206,784 a------- c:\windows\system32\dllcache\urlmon.dll
2009-03-08 04:34 236,544 a------- c:\windows\system32\dllcache\webcheck.dll
2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 04:34 43,008 -------- c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 04:34 105,984 a------- c:\windows\system32\dllcache\url.dll
2009-03-08 04:34 193,536 a------- c:\windows\system32\dllcache\msrating.dll
2009-03-08 04:34 109,568 a------- c:\windows\system32\dllcache\occache.dll
2009-03-08 04:33 759,296 a------- c:\windows\system32\dllcache\VGX.dll
2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 04:33 18,944 -------- c:\windows\system32\dllcache\corpol.dll
2009-03-08 04:33 25,600 a------- c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 04:33 726,528 a------- c:\windows\system32\dllcache\jscript.dll
2009-03-08 04:33 229,376 a------- c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\dllcache\vbscript.dll
2009-03-08 04:33 125,952 a------- c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 04:32 72,704 -------- c:\windows\system32\dllcache\admparse.dll
2009-03-08 04:32 173,056 a------- c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 04:32 163,840 a------- c:\windows\system32\dllcache\ieakui.dll
2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 04:32 55,808 a------- c:\windows\system32\dllcache\iernonce.dll
2009-03-08 04:32 71,680 -------- c:\windows\system32\dllcache\iesetup.dll
2009-03-08 04:32 128,512 a------- c:\windows\system32\dllcache\advpack.dll
2009-03-08 04:32 94,720 -------- c:\windows\system32\dllcache\inseng.dll
2009-03-08 04:32 594,432 a------- c:\windows\system32\dllcache\msfeeds.dll
2009-03-08 04:32 1,985,024 a------- c:\windows\system32\dllcache\iertutil.dll
2009-03-08 04:32 611,840 a------- c:\windows\system32\dllcache\mstime.dll
2009-03-08 04:24 68,608 -------- c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll
2009-03-08 04:22 156,160 -------- c:\windows\system32\dllcache\msls31.dll
2009-03-08 04:11 445,952 a------- c:\windows\system32\dllcache\ieapfltr.dll
2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-06 07:22 284,160 -------- c:\windows\system32\dllcache\pdh.dll
2008-06-24 10:17 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat
============= FINISH: 21:35:46.70 ===============
Combofix:
ComboFix 09-06-01.03 - Chris Wiswell 06/02/2009 21:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.675 [GMT -7:00]
Running from: c:\documents and settings\Chris Wiswell\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Chris Wiswell\Chris Wiswell.exe
c:\windows\9g2234wesdf3dfgjf23
c:\windows\ld08.exe
c:\windows\new_drv.sys
c:\windows\system32\digiwet.dll
c:\windows\system32\drivers\amd64si.sys
c:\windows\system32\drivers\ksi32sk.sys
c:\windows\system32\drivers\port135sik.sys
c:\windows\system32\drivers\securentm.sys
c:\windows\system32\drivers\systemntmi.sys
c:\windows\system32\drivers\ws2_32sik.sys
c:\windows\system32\sysloc
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_KSI32SK
-------\Legacy_NEW_DRV
-------\Legacy_PORT135SIK
-------\Legacy_SECURENTM
-------\Legacy_SYSTEMNTMI
-------\Legacy_WS2_32SIK
-------\Service_ksi32sk
-------\Service_port135sik
-------\Service_securentm
-------\Service_systemntmi
-------\Service_ws2_32sik
((((((((((((((((((((((((( Files Created from 2009-05-03 to 2009-06-03 )))))))))))))))))))))))))))))))
.
2009-06-03 03:44 . 2009-06-03 03:44 -------- d-----w- c:\program files\Compaq
2009-06-03 03:43 . 2009-06-03 03:44 -------- d-----w- C:\CPQSYSTEM
2009-06-03 03:28 . 2009-06-03 03:28 -------- d-----w- C:\DriveKey
2009-06-01 07:55 . 2009-06-01 07:55 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-06-01 06:55 . 2009-06-01 06:55 -------- d-----w- c:\program files\Microsoft.NET
2009-06-01 06:50 . 2009-06-01 06:52 -------- d-----w- c:\windows\SHELLNEW
2009-06-01 06:49 . 2009-06-01 06:49 -------- d-----w- c:\documents and settings\Chris Wiswell\Local Settings\Application Data\Microsoft Help
2009-06-01 06:48 . 2009-06-01 07:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-01 06:47 . 2009-06-01 06:47 -------- d--h--r- C:\MSOCache
2009-06-01 05:48 . 2009-06-01 06:48 -------- d-----w- c:\documents and settings\Chris Wiswell\Application Data\GetRightToGo
2009-06-01 04:59 . 2009-06-01 04:59 -------- d-----w- c:\documents and settings\Chris Wiswell\Local Settings\Application Data\PCHealth
2009-06-01 04:35 . 2009-06-01 04:35 -------- d-----w- c:\windows\system32\XPSViewer
2009-06-01 04:35 . 2009-06-01 04:35 -------- d-----w- c:\program files\MSBuild
2009-06-01 04:34 . 2009-06-01 04:34 -------- d-----w- c:\program files\Reference Assemblies
2009-06-01 04:32 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-01 04:32 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-06-01 04:32 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-01 04:32 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-06-01 04:32 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-01 04:32 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-06-01 04:32 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-01 04:32 . 2009-06-01 04:33 -------- d-----w- C:\4f748c821ba0cde614dc12ff8f905541
2009-05-31 03:34 . 2009-05-31 03:34 -------- d-----w- c:\program files\hp deskjet 5550 series
2009-05-31 03:33 . 2002-12-10 00:19 147512 ----a-w- c:\windows\system32\hpzlnt07.dll
2009-05-31 03:31 . 2009-06-01 04:02 -------- d-----w- c:\documents and settings\BB443B11-7D12-450c-9F85-2D32804655F9\temp
2009-05-31 03:31 . 2009-05-31 03:31 -------- d-----w- c:\documents and settings\BB443B11-7D12-450c-9F85-2D32804655F9
2009-05-31 03:14 . 2008-04-14 07:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-05-29 21:12 . 2009-05-29 21:12 -------- d-----w- c:\program files\ERUNT
2009-05-28 04:29 . 2009-05-28 04:29 -------- d-----w- c:\program files\Trend Micro
2009-05-28 04:23 . 2009-05-28 04:26 -------- d-----w- c:\program files\Windows Live Safety Center
2009-05-28 04:01 . 2009-05-28 04:01 -------- d-----w- c:\documents and settings\Chris Wiswell\Local Settings\Application Data\WMTools Downloaded Files
2009-05-28 00:03 . 2009-05-28 00:03 2 ---h--w- c:\windows\sonce122712.dat
2009-05-26 16:17 . 2009-05-26 16:17 -------- d-----w- c:\program files\SkillSoft
2009-05-26 16:17 . 2009-05-26 16:18 -------- d-----w- C:\SSTemp
2009-05-26 05:14 . 2009-05-26 05:14 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-05-26 05:14 . 2009-05-26 05:14 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-05-26 05:14 . 2009-05-26 05:14 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-05-26 05:14 . 2009-05-26 05:14 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-05-26 05:05 . 2009-05-26 06:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-26 05:05 . 2009-05-26 05:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-26 04:31 . 2009-05-26 04:31 48352 ----a-w- c:\documents and settings\Maurie Wiswell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-26 04:31 . 2009-05-26 04:31 -------- d-----w- c:\program files\Windows Defender
2009-05-26 04:27 . 2009-05-26 04:27 -------- d-sh--w- c:\documents and settings\Maurie Wiswell\PrivacIE
2009-05-26 04:27 . 2009-05-26 04:27 -------- d-sh--w- c:\documents and settings\Maurie Wiswell\IETldCache
2009-05-26 04:06 . 2009-05-26 04:44 17408 ----a-w- c:\windows\system32\oldSYSDLL.exe
2009-05-26 04:06 . 2009-05-26 04:06 2 ---h--w- c:\windows\sonce122730.dat
2009-05-26 04:04 . 2009-05-26 04:05 32 --s-a-w- c:\windows\system32\2159569980.dat
2009-05-26 04:04 . 2009-05-26 04:04 51712 --sh--r- c:\windows\system32\apphelpc.exe
2009-05-23 23:37 . 2001-08-17 20:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-05-23 23:37 . 2008-04-14 07:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-05-18 17:26 . 2009-05-18 17:26 -------- d-sh--w- c:\documents and settings\Chris Wiswell\PrivacIE
2009-05-18 17:26 . 2009-05-18 17:26 -------- d-sh--w- c:\documents and settings\Chris Wiswell\IETldCache
2009-05-18 16:40 . 2009-05-18 16:40 -------- d-----w- c:\windows\ie8updates
2009-05-18 16:37 . 2009-05-18 16:39 -------- dc-h--w- c:\windows\ie8
2009-05-18 16:35 . 2009-04-25 05:30 102400 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-05-17 17:15 . 2009-05-26 04:27 -------- d-----w- c:\documents and settings\Maurie Wiswell
2009-05-17 17:15 . 2008-12-19 07:31 -------- d-----w- c:\documents and settings\Maurie Wiswell\Local Settings\Application Data\Microsoft
2009-05-13 04:33 . 2009-05-13 04:33 -------- d-----w- c:\windows\Sun
2009-05-13 04:08 . 2009-06-01 14:16 52928 ----a-w- c:\documents and settings\Chris Wiswell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 21:06 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-05-12 21:06 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-05-11 19:45 . 2009-05-11 19:45 -------- d-----w- c:\documents and settings\Chris Wiswell\Application Data\Template
2009-05-11 12:04 . 2008-04-11 19:04 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-05-11 12:02 . 2008-10-03 10:02 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-05-11 12:01 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-05-11 12:01 . 2008-09-04 17:15 1106944 ------w- c:\windows\system32\dllcache\msxml3.dll
2009-05-11 11:58 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-05-11 11:58 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-05-11 11:57 . 2009-05-11 11:57 -------- d-----w- c:\documents and settings\Chris Wiswell\Local Settings\Application Data\Identities
2009-05-11 07:45 . 2008-04-15 04:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-05-11 07:41 . 2008-12-19 07:51 -------- d-----w- c:\windows\system32\config\systemprofile\Bluetooth Software
2009-05-11 07:41 . 2008-12-19 07:51 -------- d-----w- c:\documents and settings\Default User\Bluetooth Software
2009-05-11 07:27 . 2008-04-14 20:00 185344 ----a-w- c:\windows\system32\Thawbrkr.dll
2009-05-11 07:27 . 2008-04-14 20:00 10752 ----a-w- c:\windows\system32\c_iscii.dll
2009-05-11 07:27 . 2008-04-14 20:00 5632 ----a-w- c:\windows\system32\kbdusa.dll
2009-05-11 07:27 . 2008-04-14 20:00 6144 ----a-w- c:\windows\system32\ftlx041e.dll
2009-05-11 03:08 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-05-11 03:08 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-05-11 03:06 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-05-11 03:06 . 2008-05-01 14:33 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2009-05-11 03:06 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2009-05-11 03:04 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-03 03:28 . 2008-12-19 07:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-01 06:48 . 2009-05-11 19:45 1672 ----a-w- c:\documents and settings\Chris Wiswell\Application Data\wklnhst.dat
2009-05-31 03:31 . 2008-12-19 07:48 -------- d-----w- c:\program files\Hewlett-Packard
2009-03-08 11:34 . 2007-08-14 09:54 914944 ----a-w- c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2007-08-14 09:44 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2008-04-15 04:00 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2008-04-15 04:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2007-08-14 09:39 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2007-08-14 09:39 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 11:31 . 2007-08-14 09:36 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2007-08-14 09:01 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2007-08-14 09:32 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2007-08-14 09:54 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2008-04-15 04:00 284160 ----a-w- c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-30 442477]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2008-08-28 471040]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-31 1343488]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"HP Mobile Broadband"="c:\swsetup\HPQWWAN\HPMobileBroadband.exe" [2008-07-08 439600]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-12-10 188416]
"IDTSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2008-08-30 442477]
c:\documents and settings\Chris Wiswell\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-7-30 604776]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [12/19/2008 12:48 AM 112128]
S2 amd64si;amd64si;\??\c:\windows\system32\drivers\amd64si.sys --> c:\windows\system32\drivers\amd64si.sys [?]
S2 MSDTCdmserver;Distributed Transaction Coordinator MSDTCdmserver;c:\windows\system32\apphelpc.exe srv --> c:\windows\system32\apphelpc.exe srv [?]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-21 c:\windows\Tasks\User_Feed_Synchronization-{B1F49AD2-9F9C-4279-A3B5-B260CFC4E382}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mail.google.com/mail/?shva=1#inbox
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-02 21:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2484)
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\IDT\WDM\stacsv.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
.
**************************************************************************
.
Completion time: 2009-06-03 21:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-03 04:28
Pre-Run: 6,984,871,936 bytes free
Post-Run: 7,053,950,976 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
237 --- E O F --- 2009-06-02 16:25