My name is Rick and my computer is infected with Virtumonde. I have already done the following:
1. Ran newest version (fully updated) of Spybot and fixed everything found.
2. Shut down PC and disconnected from internet.
3. Rebooted and Ran Spybot again and Fixed Virtumonde (only thing found)
4. Reconnected to internet, rebooted and ran Spybot. Virtumonde still detected.
5. Backed up the system registry using ERUNT
6. Ran DDS
First thanks in advance for helping me.
I am attaching the zipped Attach.txt fileand here is the DDS.txt info:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Rick Weaver at 9:49:58.87 on Wed 07/21/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.861 [GMT -5:00]
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\Roland\VSC32\vsc32cnf.exe
C:\Program Files\Roland\VSC32\vscvol.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Rick Weaver\Desktop\dds.com
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.live.com
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://www.dogpile.com/dogpile/ws/iesearch/_iceUrlFlag=11?_IceUrl=true
uStart Page = hxxp://go.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptsn.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [vsc32cnf.exe] c:\program files\roland\vsc32\vsc32cnf.exe
mRun: [vscvol.exe] c:\program files\roland\vsc32\vscvol.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - hxxp://w4s.work4sure.com/c/ge/w4sgeen9.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1265946429113
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1266442551218
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} - hxxp://97.67.116.202:81/xplugLite.cab
Notify: igfxcui - igfxdev.dll
Notify: PCANotify - PCANotify.dll
Notify: winxzq32 - winxzq32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-2-14 340592]
R1 AW_HOST;AW_HOST;c:\windows\system32\drivers\AW_HOST5.sys [2007-3-30 18232]
R1 awlegacy;awlegacy;c:\windows\system32\drivers\AWLEGACY.sys [2007-3-30 17848]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\mcafee\virusscan enterprise\EngineServer.exe [2008-9-29 19456]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-3-14 103744]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2008-9-29 143088]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2008-9-29 62800]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-2-14 67904]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt5x.sys [2010-1-22 22016]
R2 RVIEGVST;VSC VST Engine;c:\program files\roland\virtual sound canvas vst\RVIEg01VST.sys [2010-4-13 188276]
R2 SlingAgentService;SlingAgentService;c:\program files\sling media\slingagent\SlingAgentService.exe [2009-9-25 93960]
R2 WUSB54GPSVC;WUSB54GPSVC;c:\program files\wireless-g portable usb adapter\WLService.exe [2010-6-12 41025]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-2-14 90360]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-2-14 42424]
R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [2010-4-13 951284]
S1 SydexFDD;Sydex Diskette Driver;c:\windows\system32\drives\sydexfdd.sys --> c:\windows\system32\drives\sydexfdd.sys [?]
S3 awhost32;Symantec pcAnywhere Host Service;c:\program files\symantec\pcanywhere_v13\awhost32.exe [2009-2-10 136568]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-2-14 64432]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;c:\windows\system32\drivers\RTLTEAMING.SYS [2010-1-22 28800]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [2010-1-22 17536]
=============== Created Last 30 ================
2010-07-20 23:24:42 0 d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-07-20 23:24:42 0 d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2010-07-20 23:24:42 0 d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2010-07-20 23:24:42 0 d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-07-18 20:43:14 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-18 20:39:49 0 d-----w- c:\program files\Nsasoft
2010-07-18 20:35:00 81408 ----a-w- c:\windows\system32\winxzq32.dll
2010-07-18 20:34:39 81408 ----a-w- c:\windows\system32\wincfg32.dll
2010-07-18 20:34:13 81408 ----a-w- c:\windows\system32\winyyq32.dll
2010-07-18 20:28:56 81408 ----a-w- c:\windows\system32\winvct32.dll
2010-07-18 20:28:31 368912 ----a-r- c:\windows\system32\VBAR332.DLL
2010-07-18 20:28:31 1039360 ----a-r- c:\windows\system32\MSJET35.DLL
2010-07-18 20:28:02 607744 ------w- c:\windows\system32\Decslib.dll
2010-07-18 20:26:43 28252 ------w- c:\windows\corelpf.lrs
2010-07-18 20:26:21 39095 ------w- c:\windows\iccsigs.dat
2010-07-18 20:26:20 112688 ------w- c:\windows\system32\shw32.dll
2010-07-18 20:26:16 211456 ------w- c:\windows\system32\qd3d_ir2.q3x
2010-07-18 20:26:15 909312 ------w- c:\windows\system32\qd3d.dll
2010-07-18 20:26:15 70656 ------w- c:\windows\system32\3dviewer.dll
2010-07-18 20:26:15 553984 ------w- c:\windows\system32\rave.dll
2010-07-18 20:26:05 168448 ------w- c:\windows\system32\Awrtl30.dll
2010-07-18 20:26:05 100864 ------w- c:\windows\system32\awpe.dll
2010-07-18 20:25:55 245760 ------w- c:\windows\system32\Sccomp91.dll
2010-07-18 20:25:55 225280 ------w- c:\windows\system32\Scint91.dll
2010-07-18 20:25:55 110592 ------w- c:\windows\system32\Sccres91.dll
2010-07-18 20:25:48 0 d-----w- c:\windows\Profiles
2010-07-18 18:21:39 0 d-----w- c:\windows\Corel
2010-07-14 18:21:17 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-10 21:29:25 52480 -c--a-w- c:\windows\system32\dllcache\i8042prt.sys
2010-07-10 21:29:25 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2010-07-09 15:16:52 0 d-----w- c:\docume~1\rickwe~1\applic~1\ABBYY
2010-07-09 15:09:17 0 d-----w- C:\QUARANTINE
2010-07-08 23:42:55 0 d-----w- c:\windows\system32\NtmsData
2010-07-06 02:13:05 0 d-----w- c:\windows\system32\appmgmt
2010-07-02 01:37:24 0 d-----w- c:\windows\SQL9_KB970892_ENU
2010-06-30 22:29:04 0 d-----w- c:\program files\eBay
2010-06-30 22:14:26 0 d-----w- c:\program files\Microsoft SQL Server
2010-06-24 23:55:44 0 d-----w- C:\Restoration
2010-06-24 21:00:09 0 d-----w- c:\docume~1\alluse~1\applic~1\Sling Media
==================== Find3M ====================
2010-06-16 21:38:44 1044480 ----a-r- c:\windows\system32\roboex32.dll
2010-06-16 21:38:42 49152 ----a-r- c:\windows\system32\inetwh32.dll
2010-06-12 19:46:26 737280 ----a-w- c:\windows\iun6002.exe
2010-05-06 10:41:53 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 06:34:15 1860352 ----a-w- c:\windows\system32\win32k.sys
============= FINISH: 9:51:16.33 ===============
1. Ran newest version (fully updated) of Spybot and fixed everything found.
2. Shut down PC and disconnected from internet.
3. Rebooted and Ran Spybot again and Fixed Virtumonde (only thing found)
4. Reconnected to internet, rebooted and ran Spybot. Virtumonde still detected.
5. Backed up the system registry using ERUNT
6. Ran DDS
First thanks in advance for helping me.
I am attaching the zipped Attach.txt fileand here is the DDS.txt info:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Rick Weaver at 9:49:58.87 on Wed 07/21/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.861 [GMT -5:00]
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\Roland\VSC32\vsc32cnf.exe
C:\Program Files\Roland\VSC32\vscvol.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Rick Weaver\Desktop\dds.com
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.live.com
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://www.dogpile.com/dogpile/ws/iesearch/_iceUrlFlag=11?_IceUrl=true
uStart Page = hxxp://go.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptsn.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [vsc32cnf.exe] c:\program files\roland\vsc32\vsc32cnf.exe
mRun: [vscvol.exe] c:\program files\roland\vsc32\vscvol.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - hxxp://w4s.work4sure.com/c/ge/w4sgeen9.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1265946429113
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1266442551218
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} - hxxp://97.67.116.202:81/xplugLite.cab
Notify: igfxcui - igfxdev.dll
Notify: PCANotify - PCANotify.dll
Notify: winxzq32 - winxzq32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-2-14 340592]
R1 AW_HOST;AW_HOST;c:\windows\system32\drivers\AW_HOST5.sys [2007-3-30 18232]
R1 awlegacy;awlegacy;c:\windows\system32\drivers\AWLEGACY.sys [2007-3-30 17848]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\mcafee\virusscan enterprise\EngineServer.exe [2008-9-29 19456]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-3-14 103744]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2008-9-29 143088]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2008-9-29 62800]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-2-14 67904]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt5x.sys [2010-1-22 22016]
R2 RVIEGVST;VSC VST Engine;c:\program files\roland\virtual sound canvas vst\RVIEg01VST.sys [2010-4-13 188276]
R2 SlingAgentService;SlingAgentService;c:\program files\sling media\slingagent\SlingAgentService.exe [2009-9-25 93960]
R2 WUSB54GPSVC;WUSB54GPSVC;c:\program files\wireless-g portable usb adapter\WLService.exe [2010-6-12 41025]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-2-14 90360]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-2-14 42424]
R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [2010-4-13 951284]
S1 SydexFDD;Sydex Diskette Driver;c:\windows\system32\drives\sydexfdd.sys --> c:\windows\system32\drives\sydexfdd.sys [?]
S3 awhost32;Symantec pcAnywhere Host Service;c:\program files\symantec\pcanywhere_v13\awhost32.exe [2009-2-10 136568]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-2-14 64432]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;c:\windows\system32\drivers\RTLTEAMING.SYS [2010-1-22 28800]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [2010-1-22 17536]
=============== Created Last 30 ================
2010-07-20 23:24:42 0 d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-07-20 23:24:42 0 d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2010-07-20 23:24:42 0 d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2010-07-20 23:24:42 0 d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-07-18 20:43:14 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-18 20:39:49 0 d-----w- c:\program files\Nsasoft
2010-07-18 20:35:00 81408 ----a-w- c:\windows\system32\winxzq32.dll
2010-07-18 20:34:39 81408 ----a-w- c:\windows\system32\wincfg32.dll
2010-07-18 20:34:13 81408 ----a-w- c:\windows\system32\winyyq32.dll
2010-07-18 20:28:56 81408 ----a-w- c:\windows\system32\winvct32.dll
2010-07-18 20:28:31 368912 ----a-r- c:\windows\system32\VBAR332.DLL
2010-07-18 20:28:31 1039360 ----a-r- c:\windows\system32\MSJET35.DLL
2010-07-18 20:28:02 607744 ------w- c:\windows\system32\Decslib.dll
2010-07-18 20:26:43 28252 ------w- c:\windows\corelpf.lrs
2010-07-18 20:26:21 39095 ------w- c:\windows\iccsigs.dat
2010-07-18 20:26:20 112688 ------w- c:\windows\system32\shw32.dll
2010-07-18 20:26:16 211456 ------w- c:\windows\system32\qd3d_ir2.q3x
2010-07-18 20:26:15 909312 ------w- c:\windows\system32\qd3d.dll
2010-07-18 20:26:15 70656 ------w- c:\windows\system32\3dviewer.dll
2010-07-18 20:26:15 553984 ------w- c:\windows\system32\rave.dll
2010-07-18 20:26:05 168448 ------w- c:\windows\system32\Awrtl30.dll
2010-07-18 20:26:05 100864 ------w- c:\windows\system32\awpe.dll
2010-07-18 20:25:55 245760 ------w- c:\windows\system32\Sccomp91.dll
2010-07-18 20:25:55 225280 ------w- c:\windows\system32\Scint91.dll
2010-07-18 20:25:55 110592 ------w- c:\windows\system32\Sccres91.dll
2010-07-18 20:25:48 0 d-----w- c:\windows\Profiles
2010-07-18 18:21:39 0 d-----w- c:\windows\Corel
2010-07-14 18:21:17 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-10 21:29:25 52480 -c--a-w- c:\windows\system32\dllcache\i8042prt.sys
2010-07-10 21:29:25 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2010-07-09 15:16:52 0 d-----w- c:\docume~1\rickwe~1\applic~1\ABBYY
2010-07-09 15:09:17 0 d-----w- C:\QUARANTINE
2010-07-08 23:42:55 0 d-----w- c:\windows\system32\NtmsData
2010-07-06 02:13:05 0 d-----w- c:\windows\system32\appmgmt
2010-07-02 01:37:24 0 d-----w- c:\windows\SQL9_KB970892_ENU
2010-06-30 22:29:04 0 d-----w- c:\program files\eBay
2010-06-30 22:14:26 0 d-----w- c:\program files\Microsoft SQL Server
2010-06-24 23:55:44 0 d-----w- C:\Restoration
2010-06-24 21:00:09 0 d-----w- c:\docume~1\alluse~1\applic~1\Sling Media
==================== Find3M ====================
2010-06-16 21:38:44 1044480 ----a-r- c:\windows\system32\roboex32.dll
2010-06-16 21:38:42 49152 ----a-r- c:\windows\system32\inetwh32.dll
2010-06-12 19:46:26 737280 ----a-w- c:\windows\iun6002.exe
2010-05-06 10:41:53 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 06:34:15 1860352 ----a-w- c:\windows\system32\win32k.sys
============= FINISH: 9:51:16.33 ===============