Combofix log and new dds log
It started running much better yesterday, I think. Anyway it was after the day I was using Google Chrome to access internet. Then I started using IE and it was slow, but allowed me internet access w/out issues. My computer is booting more smoothly (I went in and found out how to disable several programs from coming up in the start menu). It would take my computer so long just to run all the start menu programs and I'd have to wait to do anything. Once we get this cleared up, then I have some questions for you. Oh also, this time when I ran ComboFix, copied and closed out the log, I did not have to reboot...yeah! The last couple of times I rebooted (I failed to read you post saying how to disable things in the task manager)...my bad.
ComboFix 09-03-06.02 - Tina 2009-03-10 14:55:04.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.166 [GMT -5:00]
Running from: c:\documents and settings\Tina\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Tina\Desktop\CFScript.txt
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-02-10 to 2009-03-10 )))))))))))))))))))))))))))))))
.
2100-02-23 15:35 . 2001-02-22 10:54 768 --a------ c:\program files\x73_lut.dat
2100-02-08 16:03 . 2001-05-11 11:39 53,248 --a------ c:\program files\ACMonitor_X73.exe
2009-03-09 23:06 . 2009-03-09 23:06 268 --ah----- C:\sqmdata17.sqm
2009-03-09 23:06 . 2009-03-09 23:06 244 --ah----- C:\sqmnoopt17.sqm
2009-03-09 11:39 . 2009-03-09 11:39 268 --ah----- C:\sqmdata16.sqm
2009-03-09 11:39 . 2009-03-09 11:39 244 --ah----- C:\sqmnoopt16.sqm
2009-03-08 01:51 . 2009-03-08 01:51 268 --ah----- C:\sqmdata15.sqm
2009-03-08 01:51 . 2009-03-08 01:51 244 --ah----- C:\sqmnoopt15.sqm
2009-03-08 01:35 . 2009-03-08 01:35 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-07 09:32 . 2009-03-07 09:32 268 --ah----- C:\sqmdata14.sqm
2009-03-07 09:32 . 2009-03-07 09:32 244 --ah----- C:\sqmnoopt14.sqm
2009-03-06 17:25 . 2009-03-06 17:25 268 --ah----- C:\sqmdata13.sqm
2009-03-06 17:25 . 2009-03-06 17:25 244 --ah----- C:\sqmnoopt13.sqm
2009-03-06 14:11 . 2009-03-06 14:17 664 --a------ c:\windows\system32\d3d9caps.dat
2009-03-06 13:44 . 2009-03-06 13:44 268 --ah----- C:\sqmdata12.sqm
2009-03-06 13:44 . 2009-03-06 13:44 244 --ah----- C:\sqmnoopt12.sqm
2009-03-05 20:11 . 2009-03-05 20:11 <DIR> d-------- c:\program files\WinZip Self-Extractor
2009-03-05 20:11 . 2009-03-05 20:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\WinZipSE
2009-03-03 23:21 . 2009-03-03 23:21 268 --ah----- C:\sqmdata11.sqm
2009-03-03 23:21 . 2009-03-03 23:21 244 --ah----- C:\sqmnoopt11.sqm
2009-03-03 18:27 . 2009-03-03 18:27 51,520 --a------ c:\windows\system32\drivers\TfFsMon.sys
2009-03-03 18:27 . 2009-03-03 18:27 38,208 --a------ c:\windows\system32\drivers\TfSysMon.sys
2009-03-03 18:27 . 2009-03-03 18:27 33,088 --a------ c:\windows\system32\drivers\TfNetMon.sys
2009-03-03 18:27 . 2009-03-03 18:27 12,608 --a------ c:\windows\system32\drivers\TfKbMon.sys
2009-03-03 17:44 . 2009-03-03 17:44 244 --ah----- C:\sqmnoopt10.sqm
2009-03-03 17:44 . 2009-03-03 17:44 232 --ah----- C:\sqmdata10.sqm
2009-03-03 15:46 . 2009-03-03 15:46 <DIR> d-------- c:\program files\Trend Micro
2009-03-03 15:42 . 2009-03-03 15:42 <DIR> d-------- c:\program files\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-09 16:41 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-08 06:35 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 04:19 --------- d-----w c:\program files\Spyware Doctor
2009-03-07 15:57 --------- d-----w c:\program files\Common Files\Adobe
2009-03-07 15:31 --------- d-----w c:\program files\Java
2009-03-06 18:39 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-05 22:02 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-04 18:06 2,516 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-03-03 23:39 --------- d-----w c:\documents and settings\All Users\Application Data\PC Tools
2009-02-26 13:22 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-09 06:34 --------- d-----w c:\program files\Windows Defender
2009-02-09 01:57 --------- d-----w c:\program files\AIMTunes
2009-01-27 21:09 --------- d-----w c:\program files\Common Files\PC Tools
2009-01-27 21:09 --------- d-----w c:\documents and settings\Administrator\Application Data\PC Tools
2009-01-27 20:58 --------- d-----w c:\program files\Common Files\Download Manager
2009-01-27 19:23 --------- d-----w c:\documents and settings\Administrator\Application Data\Windows Desktop Search
2009-01-27 19:22 --------- d-----w c:\documents and settings\Administrator\Application Data\Windows Search
2009-01-24 17:20 --------- d-----w c:\documents and settings\Sydney\Application Data\Gtek
2009-01-24 17:12 --------- d-----w c:\documents and settings\Sydney\Application Data\Windows Desktop Search
2009-01-24 17:01 --------- d-----w c:\documents and settings\Steve\Application Data\Windows Desktop Search
2009-01-19 01:50 --------- d-----w c:\program files\MySpace
2009-01-17 03:35 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-01-14 20:44 --------- d-----w c:\documents and settings\Tina\Application Data\Move Networks
2008-12-19 09:10 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-12-13 01:44 690,969 ----a-w c:\windows\unins000.exe
2008-12-12 18:41 60,032 ----a-w c:\windows\system32\ZuneBusEnum.exe
2008-12-12 18:41 243,840 ----a-w c:\windows\system32\ZuneWlanCfgSvc.exe
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2008-09-30 19:35 61,224 ----a-w c:\documents and settings\Tina\GoToAssistDownloadHelper.exe
2008-05-05 18:54 56,912 ----a-w c:\documents and settings\Tina\g2mdlhlpx.exe
2006-03-13 16:16 630,784 ----a-w c:\documents and settings\Tina\chatlnk.exe
2001-07-26 22:58 47 ----a-w c:\program files\ACMonitor_X73.ini
2001-07-05 18:46 8,116 ----a-w c:\program files\OSLO3071b2.USB
2001-05-08 21:36 114,688 ----a-w c:\program files\lxarscan.dll
2001-04-23 20:22 1,437 ----a-w c:\program files\gtx73.ini
.
((((((((((((((((((((((((((((( SnapShot@2009-03-06_15.46.16.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-21 02:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2007-12-12 21:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
- 2000-08-31 14:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 13:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2000-08-31 14:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 13:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2008-12-10 17:14:17 144,792 ----a-w c:\windows\system32\java.exe
+ 2009-03-08 06:35:11 144,792 ----a-w c:\windows\system32\java.exe
- 2008-12-10 17:14:17 144,792 ----a-w c:\windows\system32\javaw.exe
+ 2009-03-08 06:35:11 144,792 ----a-w c:\windows\system32\javaw.exe
- 2008-12-10 17:14:17 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2009-03-08 06:35:11 148,888 ----a-w c:\windows\system32\javaws.exe
- 2009-01-26 21:43:52 79,034 ----a-w c:\windows\system32\perfc009.dat
+ 2009-03-10 03:34:39 79,034 ----a-w c:\windows\system32\perfc009.dat
- 2009-01-26 21:43:52 464,010 ----a-w c:\windows\system32\perfh009.dat
+ 2009-03-10 03:34:39 464,010 ----a-w c:\windows\system32\perfh009.dat
+ 2009-03-10 12:23:57 16,384 ----atw c:\windows\temp\Perflib_Perfdata_b4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\Tina\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-16 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 344064]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"Java Sabre Server (JSERVER)"="c:\sabre\Apps\Portal\JServer.exe" [2004-07-30 57344]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-03-12 11776]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2006-04-06 49152]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-16 28672]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-22 185896]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-06 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-06 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-06 114688]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"USB2Check"="c:\windows\system32\PCLECoInst.dll" [2006-11-06 81920]
"FlyMonitor"="c:\program files\Leapfrog\FlyWorld\bin\FlyMonitor.exe" [2008-05-13 664904]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe" [2003-12-22 98304]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2004-11-02 1063424]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-08-22 1306624]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\STSYSTRA.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2006-05-03 331776]
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02 546288]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\1133459717\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1133459717\\ee\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Common Files\\AOL\\1133459717\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\WINDOWS\\sabserv.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LeapFrog\\FlyWorld\\bin\\FLYMonitor.exe"=
"c:\\Program Files\\LeapFrog\\FlyWorld\\bin\\FLYWorld.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\WatchGuard\\Mobile User VPN\\IreIKE.exe"=
"c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe"= c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog
"c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe"= c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp
"c:\program files\WatchGuard\Mobile User VPN\vpn.exe"= c:\program files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-03-03 51520]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-03-03 38208]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-01-27 160792]
R2 CfgSrvc;Config Service Helper;c:\windows\system32\CfgSrvc.exe [2005-09-15 55296]
R2 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [2005-09-07 521786]
R2 HsspConfig;HSSP Configuration Module;c:\windows\system32\CfgSrvc.exe [2005-09-15 55296]
R2 IPSECDRV;SafeNet IPSec Plugin;c:\windows\system32\drivers\IpSecDrv.sys [2005-09-07 119864]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [2008-02-28 18944]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-04-03 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\drivers\vap.sys [2005-09-07 36188]
S3 DockingGroup;LeapFrog WDM USB Device Driver;c:\windows\system32\drivers\MS20022K.sys [2005-09-25 14781]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2008-09-15 18560]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-25 356920]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-03-03 33088]
S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S4 SabrePrint;Sabre Printing Module;c:\sabre\Apps\OADP\Oadp.exe [2005-09-15 487424]
S4 SDMan;Sabre Device Manager;c:\windows\sdman.exe [2005-09-15 106496]
.
Contents of the 'Scheduled Tasks' folder
2009-03-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1890334925-1687483848-3338308614-1006.job
- c:\documents and settings\Tina\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-16 19:19]
2009-03-10 c:\windows\Tasks\Kodak AiO Scheduled Maintenance.job
- c:\program files\Kodak\Printer\Center\Kodak.Statistics.exe [2008-02-28 17:57]
2009-03-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 20:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell4me.com/myway
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*
http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = www-ad-proxy.sabre.com:80
uInternet Settings,ProxyOverride = *.local;<local>
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*
http://www.yahoo.com
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: west.com
Trusted Zone: westathome.com
Trusted Zone: westathome.net
Trusted Zone: workathomeagent.com
Trusted Zone: workathomeagent.net
Trusted Zone: workathomeagent.net\connect
Trusted Zone: musicmatch.com\online
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {2D36AF92-04D3-11D8-B719-0000865F231B} - hxxps://my.sabre.com/jars/TMinReqX.dll
DPF: {68CDB19A-6305-4589-8C35-41E3502CD451} - hxxp://dishsmart-test.echostar.com/Administration/16279/applets/SiebelOptionPack.cab
DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://scan.wslive.com/sre/ICSScanner.cab
DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB
DPF: {BE7DBB5F-6377-405E-9040-F8C95C6997B6} - hxxps://invite.mshow.com/(qbph5r45uuajry2cucqgi145)/ShowSetup6.cab
DPF: {D8EE8DC0-F193-11D0-B1E5-08005A885319} - hxxp://www.workathomeagent.net/walldata/curVersion/hostexpress.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-10 14:59:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,4a,d1,3a,e0,e1,
b4,f3,d1,e2,63,26,f1,3f,c8,ff,68,80,fd,8a,2d,aa,ad,7c,d6,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:46,47,15,b0,92,4b,c7,ef,28,15,f9,e0,f3,
35,fe,bc,6a,9c,d6,61,af,45,84,18,99,f9,80,f9,e1,b0,76,ee,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,58,0c,ad,12,8f,
f0,88,f6,ff,7c,85,e0,43,d4,0e,fe,47,16,7c,a3,c4,6e,6c,64,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,d9,68,65,00,b0,
c0,e4,4e,86,8c,21,01,be,91,eb,e7,3c,69,6b,25,4a,f6,ed,bd,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,6c,68,04,b1,3c,
3d,71,83,f5,1d,4d,73,a8,13,5c,05,20,38,b5,68,81,59,44,c2,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,5b,8a,d1,7e,63,
37,75,df,df,20,58,62,78,6b,cf,c8,e1,f1,59,e9,47,c1,c7,d9,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:97,20,4e,9a,c7,f1,35,ee,6e,2a,84,7f,02,
e5,2f,ab,fb,a7,78,e6,12,2f,9a,ea,21,09,cb,62,c5,03,32,24,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,a7,a4,7a,ce,f0,
15,ea,c8,01,3a,48,fc,e8,04,4a,f1,ff,39,73,4a,ba,f3,ff,d8,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,a1,7f,83,02,95,
84,c0,15,f6,0f,4e,58,98,5b,89,c9,9a,f9,cf,38,b8,3a,46,fb,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,14,80,46,91,19,
0f,27,c5,3d,ce,ea,26,2d,45,aa,78,dd,9a,ef,12,ac,00,c3,c7,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,be,fa,63,08,a2,
2f,1c,68,2a,b7,cc,b5,b9,7f,41,e7,20,ca,6b,6a,6a,1d,10,34,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,8d,84,2f,84,b7,
5f,53,1e,6c,43,2d,1e,aa,22,2f,9c,df,c5,f2,e4,8f,d8,3c,07,6c,43,2d,1e,aa,22,\
.
Completion time: 2009-03-10 15:03:02
ComboFix-quarantined-files.txt 2009-03-10 20:02:44
ComboFix2.txt 2009-03-10 12:08:21
ComboFix3.txt 2009-03-08 04:33:49
ComboFix4.txt 2009-03-07 04:30:13
ComboFix5.txt 2009-03-10 19:53:13
Pre-Run: 46,674,370,560 bytes free
Post-Run: 46,669,123,584 bytes free
317 --- E O F --- 2009-03-10 11:16:36
DDS (Ver_09-02-01.01) - NTFSx86
Run by Tina at 15:15:43.29 on Tue 03/10/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.130 [GMT -5:00]
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CfgSrvc.exe
C:\WINDOWS\system32\CfgSrvc.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\MrobeService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\javaw.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Leapfrog\FlyWorld\bin\FlyMonitor.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Tina\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\javaw.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\sdman.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Tina\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.dell4me.com/myway
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*
http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = www-ad-proxy.sabre.com:80
uInternet Settings,ProxyOverride = *.local;<local>
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*
http://www.yahoo.com
{02478d38-c3f9-4efb-9b51-7695eca05670}
BHO: NoExplorer - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: PCTools Site Guard: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - c:\progra~1\spywar~1\tools\iesdsg.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\tina\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [Java Sabre Server (JSERVER)] c:\sabre\apps\portal\JServer.exe
mRun: [MimBoot] c:\progra~1\musicm~1\musicm~3\mimboot.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [IPHSend] c:\program files\common files\aol\iphsend\IPHSend.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [USB2Check] RUNDLL32.EXE "c:\windows\system32\PCLECoInst.dll",CheckUSBController
mRun: [FlyMonitor] "c:\program files\leapfrog\flyworld\bin\FlyMonitor.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [MCAgentExe] c:\progra~1\mcafee.com\agent\mcagent.exe
mRun: [MCUpdateExe] c:\progra~1\mcafee.com\agent\mcupdate.exe
mRun: [MSKAGENTEXE] c:\progra~1\mcafee\spamki~1\MskAgent.exe
mRun: [MSKDetectorExe] c:\progra~1\mcafee\spamki~1\MSKDetct.exe /startup
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\eventr~1.lnk - c:\program files\broderbund\printmaster\pmremind.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\oadput~1.lnk - c:\sabre\apps\oadp\OadpUtil.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223}
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: west.com
Trusted Zone: westathome.com
Trusted Zone: westathome.net
Trusted Zone: workathomeagent.com
Trusted Zone: workathomeagent.net
Trusted Zone: workathomeagent.net\connect
Trusted Zone: musicmatch.com\online
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxps://support.dell.com/systemprofiler/SysPro.CAB
DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} - hxxp://housecall60.trendmicro.com/housecall/xscan60.cab
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/F/D/9/FD9E437D-5BC8-4264-A093-DFA2C39D197E/LegitCheckControl.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {2D36AF92-04D3-11D8-B719-0000865F231B} - hxxps://my.sabre.com/jars/TMinReqX.dll
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {68CDB19A-6305-4589-8C35-41E3502CD451} - hxxp://dishsmart-test.echostar.com/Administration/16279/applets/SiebelOptionPack.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126231344343
DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://scan.wslive.com/sre/ICSScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxps://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - hxxp://pictures04.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB
DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab
DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - hxxp://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
DPF: {BE7DBB5F-6377-405E-9040-F8C95C6997B6} - hxxps://invite.mshow.com/(qbph5r45uuajry2cucqgi145)/ShowSetup6.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
DPF: {D8EE8DC0-F193-11D0-B1E5-08005A885319} - hxxp://www.workathomeagent.net/walldata/curVersion/hostexpress.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://workingsol.webex.com/client/T23L/webex/ieatgpc.cab
DPF: {E7D2588A-7FB5-47DC-8830-832605661009} - hxxp://livenj02.rightnowtech.com/7502-b145h/rnl/java/RntX.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5221/mcfscan.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
============= SERVICES / DRIVERS ===============
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-3-3 51520]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-3-3 38208]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-1-27 160792]
R2 CfgSrvc;Config Service Helper;c:\windows\system32\CfgSrvc.exe [2005-9-15 55296]
R2 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [2005-9-7 521786]
R2 HsspConfig;HSSP Configuration Module;c:\windows\system32\CfgSrvc.exe [2005-9-15 55296]
R2 IPSECDRV;SafeNet IPSec Plugin;c:\windows\system32\drivers\IpSecDrv.sys [2005-9-7 119864]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\printer\center\KodakSvc.exe [2008-2-28 18944]
R2 McDetect.exe;McAfee WSC Integration;c:\program files\mcafee.com\agent\Mcdetect.exe [2008-9-20 126976]
R2 McTskshd.exe;McAfee Task Scheduler;c:\progra~1\mcafee.com\agent\mctskshd.exe [2008-9-20 122368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-4-3 24652]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\drivers\vap.sys [2005-9-7 36188]
S3 DockingGroup;LeapFrog WDM USB Device Driver;c:\windows\system32\drivers\MS20022K.sys [2005-9-25 14781]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2008-9-15 18560]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-8-18 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-8-18 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-8-18 81288]
S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager;c:\progra~1\mcafee.com\agent\mcupdmgr.exe [2008-9-19 245760]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-1-25 356920]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-1-25 1079176]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-3-3 33088]
S3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]
S4 SabrePrint;Sabre Printing Module;c:\sabre\apps\oadp\Oadp.exe [2005-9-15 487424]
S4 SDMan;Sabre Device Manager;c:\windows\sdman.exe [2005-9-15 106496]
=============== Created Last 30 ================
2009-03-09 23:06 268 a---h--- C:\sqmdata17.sqm
2009-03-09 23:06 244 a---h--- C:\sqmnoopt17.sqm
2009-03-09 11:39 268 a---h--- C:\sqmdata16.sqm
2009-03-09 11:39 244 a---h--- C:\sqmnoopt16.sqm
2009-03-08 01:51 268 a---h--- C:\sqmdata15.sqm
2009-03-08 01:51 244 a---h--- C:\sqmnoopt15.sqm
2009-03-08 01:35 73,728 a------- c:\windows\system32\javacpl.cpl
2009-03-07 09:32 268 a---h--- C:\sqmdata14.sqm
2009-03-07 09:32 244 a---h--- C:\sqmnoopt14.sqm
2009-03-06 17:25 268 a---h--- C:\sqmdata13.sqm
2009-03-06 17:25 244 a---h--- C:\sqmnoopt13.sqm
2009-03-06 16:26 <DIR> a-dshr-- C:\cmdcons
2009-03-06 16:23 161,792 a------- c:\windows\SWREG.exe
2009-03-06 16:23 98,816 a------- c:\windows\sed.exe
2009-03-06 14:11 664 a------- c:\windows\system32\d3d9caps.dat
2009-03-06 13:44 268 a---h--- C:\sqmdata12.sqm
2009-03-06 13:44 244 a---h--- C:\sqmnoopt12.sqm
2009-03-05 20:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\WinZipSE
2009-03-05 20:11 <DIR> --d----- c:\program files\WinZip Self-Extractor
2009-03-03 23:21 268 a---h--- C:\sqmdata11.sqm
2009-03-03 23:21 244 a---h--- C:\sqmnoopt11.sqm
2009-03-03 18:27 38,208 a------- c:\windows\system32\drivers\TfSysMon.sys
2009-03-03 18:27 33,088 a------- c:\windows\system32\drivers\TfNetMon.sys
2009-03-03 18:27 12,608 a------- c:\windows\system32\drivers\TfKbMon.sys
2009-03-03 18:27 51,520 a------- c:\windows\system32\drivers\TfFsMon.sys
2009-03-03 17:44 244 a---h--- C:\sqmnoopt10.sqm
2009-03-03 17:44 232 a---h--- C:\sqmdata10.sqm
2009-03-03 15:46 <DIR> --d----- c:\program files\Trend Micro
==================== Find3M ====================
2009-03-08 01:35 410,984 a------- c:\windows\system32\deploytk.dll
2009-03-04 13:06 2,516 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-01-16 22:35 3,594,752 a------- c:\windows\system32\dllcache\mshtml.dll
2008-12-19 04:10 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 04:10 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 00:25 634,024 -------- c:\windows\system32\dllcache\iexplore.exe
2008-12-19 00:23 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2008-12-12 20:44 690,969 a------- c:\windows\unins000.exe
2008-12-12 13:41 243,840 a------- c:\windows\system32\ZuneWlanCfgSvc.exe
2008-12-12 13:41 60,032 a------- c:\windows\system32\ZuneBusEnum.exe
2008-12-11 05:57 333,952 -------- c:\windows\system32\dllcache\srv.sys
2008-09-30 14:35 61,224 a------- c:\documents and settings\tina\GoToAssistDownloadHelper.exe
2008-05-05 13:54 56,912 a------- c:\documents and settings\tina\g2mdlhlpx.exe
2006-03-13 11:16 630,784 a------- c:\documents and settings\tina\chatlnk.exe
2001-07-26 17:58 47 a------- c:\program files\ACMonitor_X73.ini
2001-07-05 13:46 8,116 a------- c:\program files\OSLO3071b2.USB
2001-05-11 11:39 53,248 a------- c:\program files\ACMonitor_X73.exe
2001-05-08 16:36 114,688 a------- c:\program files\lxarscan.dll
2001-04-23 15:22 1,437 a------- c:\program files\gtx73.ini
2001-02-22 10:54 768 a------- c:\program files\x73_lut.dat
============= FINISH: 15:16:24.73 ===============