Requested Files Attached
ComboFix 09-08-28.05 - Cluffs 08/29/2009 6:38.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2037.1481 [GMT -7:00]
Running from: c:\documents and settings\Cluffs\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cluffs\Desktop\CFScript.txt
FILE ::
"c:\windows\svchast.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ANTIPPRO2009_100
-------\Service_AntipPro2009_100
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-29 )))))))))))))))))))))))))))))))
.
2009-08-29 04:28 . 2004-08-04 10:00 50176 ----a-w- c:\windows\system32\proquota.exe
2009-08-29 04:28 . 2004-08-04 10:00 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-08-26 01:53 . 2009-08-26 01:58 -------- d-----w- c:\documents and settings\Cluffs\logitech
2009-08-26 01:52 . 2009-08-26 01:53 -------- d-----w- c:\program files\Common Files\Remote Control Software Common
2009-08-26 01:52 . 2009-08-26 01:52 -------- d-----w- c:\program files\Common Files\Remote Control USB Driver
2009-08-26 01:52 . 2009-08-26 01:52 127034 ------r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-08-26 01:52 . 2009-08-26 01:52 -------- d-----w- c:\program files\Logitech
2009-08-25 04:25 . 2009-08-25 04:26 -------- d-----w- c:\program files\ERUNT
2009-08-24 00:17 . 2009-08-24 00:17 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-23 23:46 . 2009-08-23 23:46 -------- d-----w- C:\_OTM
2009-08-23 23:38 . 2009-08-23 23:38 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-22 16:44 . 2009-08-22 16:44 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\program files\MSBuild
2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\program files\Reference Assemblies
2009-08-18 05:01 . 2009-08-18 05:01 -------- d-----w- c:\windows\system32\LogFiles
2009-08-12 10:00 . 2009-08-12 10:00 -------- d-----w- c:\windows\ServicePackFiles
2009-08-11 22:20 . 2009-06-05 07:42 655872 ------w- c:\windows\system32\dllcache\mstscax.dll
2009-08-05 09:11 . 2009-08-05 09:11 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 13:43 . 2008-04-15 03:09 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-29 05:25 . 2008-05-05 01:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-26 01:52 . 2008-04-15 03:03 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-24 00:17 . 2009-06-24 02:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-24 00:14 . 2009-07-05 23:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-23 17:39 . 2008-05-04 03:37 133736 ----a-w- c:\documents and settings\Cluffs\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-13 04:25 . 2009-07-05 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-05 09:11 . 2004-08-10 17:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 20:36 . 2009-06-24 02:47 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 20:36 . 2009-06-24 02:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-26 17:17 . 2009-04-18 03:57 -------- d-----w- c:\program files\Palm
2009-07-17 18:55 . 2004-08-10 17:50 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 09:18 . 2004-08-10 17:51 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 03:36 . 2009-07-02 03:28 -------- d-----w- c:\documents and settings\Cluffs\Application Data\Image Zone Express
2009-07-06 01:11 . 2009-07-06 01:11 -------- d-----w- c:\program files\Trend Micro
2009-07-06 00:24 . 2009-07-06 00:24 -------- d-----w- c:\program files\Browser Hijack Recover
2009-07-05 23:50 . 2009-07-05 23:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-05 23:34 . 2009-07-05 23:34 -------- d-----w- c:\program files\CleanUp!
2009-07-05 18:29 . 2009-07-05 18:29 -------- d-----w- c:\program files\AVG
2009-07-03 18:53 . 2008-09-06 15:46 57536 ----a-w- c:\windows\system32\drivers\ftdibus.sys
2009-07-03 18:53 . 2008-09-06 15:46 202048 ----a-w- c:\windows\system32\ftd2xx.dll
2009-07-03 18:53 . 2008-09-06 15:46 185664 ----a-w- c:\windows\system32\FTLang.dll
2009-07-03 18:53 . 2008-09-06 15:46 120128 ----a-w- c:\windows\system32\ftbusui.dll
2009-07-03 18:03 . 2009-07-03 17:46 -------- d-----w- c:\program files\Lame for Audacity
2009-07-03 17:44 . 2009-07-03 17:44 -------- d-----w- c:\program files\Audacity
2009-07-03 17:34 . 2009-07-03 17:34 -------- d-----w- c:\program files\BCS
2009-07-03 17:09 . 2004-08-10 17:51 915456 ------w- c:\windows\system32\wininet.dll
2009-06-25 08:17 . 2004-08-10 17:51 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:17 . 2004-08-10 17:51 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:17 . 2004-08-10 17:51 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:17 . 2004-08-10 17:51 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:17 . 2004-08-10 17:51 729600 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:17 . 2004-08-10 17:51 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-22 11:35 . 2004-08-10 17:51 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:55 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2004-08-10 17:51 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 11:50 . 2004-08-10 17:51 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 2004-08-10 17:50 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 2004-08-10 17:51 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-05 14:43 . 2009-06-05 14:43 1144 ----a-w- c:\windows\checkip.dat
2009-06-05 07:42 . 2004-08-10 18:01 655872 ----a-w- c:\windows\system32\mstscax.dll
2009-06-03 19:27 . 2004-08-10 17:51 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-04-16 04:43 . 2009-04-16 04:12 8081 ----a-w- c:\program files\gsak.ini
2009-04-16 04:41 . 2009-04-16 04:12 29 ----a-w- c:\program files\dbfindex.bif
2009-04-16 04:41 . 2009-04-16 04:12 22528 ----a-w- c:\program files\gsak.db3
2009-04-16 04:12 . 2009-04-16 04:12 5120 ----a-w- c:\program files\POST.NSX
2009-04-16 04:12 . 2009-04-16 04:12 226 ----a-w- c:\program files\POST.DBF
2008-10-01 04:40 . 2008-10-01 04:40 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-29_04.31.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-10 17:51 . 2009-08-29 04:35 71936 c:\windows\system32\perfc009.dat
- 2004-08-10 17:51 . 2009-08-29 04:26 71936 c:\windows\system32\perfc009.dat
+ 2004-08-10 17:51 . 2009-08-29 04:35 442796 c:\windows\system32\perfh009.dat
- 2004-08-10 17:51 . 2009-08-29 04:26 442796 c:\windows\system32\perfh009.dat
+ 2009-08-29 04:32 . 2009-08-29 04:32 180224 c:\windows\ERDNT\AutoBackup\8-28-2009\Users\00000002\UsrClass.dat
+ 2009-08-29 04:32 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\8-28-2009\ERDNT.EXE
+ 2009-08-29 04:32 . 2009-08-29 04:32 7069696 c:\windows\ERDNT\AutoBackup\8-28-2009\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-15 68856]
"cdloader"="c:\documents and settings\Cluffs\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-14 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-14 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-14 138008]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-01 29744]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-01-18 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-14 16384]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"ICF"="c:\program files\Internet Content Filter\SafeEyes.exe" [2008-07-29 1256960]
"PMX Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2006-11-08 49152]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-06-14 16132608]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]
c:\documents and settings\Cluffs\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-4-14 7168]
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2008-1-3 1392640]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-8-25 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\Cluffs\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [5/3/2008 8:31 PM 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [5/3/2008 8:31 PM 14336]
S2 gupdate1c9dbc288d3f3a0;Google Update Service (gupdate1c9dbc288d3f3a0);c:\program files\Google\Update\GoogleUpdate.exe [5/23/2009 9:21 AM 133104]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [4/14/2008 8:05 PM 29744]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57]
2009-08-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-15 15:45]
2009-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-23 16:21]
2009-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-23 16:21]
2009-08-28 c:\windows\Tasks\SyncBack Becs Notebook My Docs.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]
2009-08-28 c:\windows\Tasks\SyncBack Becs Notebook Pics.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]
2009-08-28 c:\windows\Tasks\SyncBack Bk-up Oulook.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]
2009-08-28 c:\windows\Tasks\SyncBack Favorites.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]
2009-08-28 c:\windows\Tasks\SyncBack My Docs.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]
2009-08-29 c:\windows\Tasks\SyncBack My Pictures.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]
2009-08-29 c:\windows\Tasks\User_Feed_Synchronization-{792CECEB-CAD7-4A8C-86D8-9008FECB745A}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: ICF.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
FF - component: c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\extensions\{7E7165E2-0767-448c-852F-5FA8714F2C37}\components\PlainOldFavorites.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\progra~1\Palm\PACKAG~1\NPInstal.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-29 06:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(828)
c:\windows\system32\ICF.dll
- - - - - - - > 'explorer.exe'(524)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\pmxscrll.dll
c:\windows\system32\PMXCOMM.dll
c:\windows\system32\PMXHOOKS.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\pmxmiced.exe
c:\windows\system32\rundll32.exe
c:\program files\Dell Network Assistant\ezi_hnm2.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2009-08-29 6:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-29 13:47
ComboFix2.txt 2009-08-29 04:36
Pre-Run: 21,574,889,472 bytes free
Post-Run: 21,502,197,760 bytes free
261 --- E O F --- 2009-08-26 15:26
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, August 30, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, August 29, 2009 16:20:51
Records in database: 2701691
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
Scan statistics:
Objects scanned: 261884
Threats found: 6
Infected objects found: 7
Suspicious objects found: 2
Scan duration: 03:10:47
File name / Threat / Threats count
C:\Documents and Settings\Cluffs\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Hotmail - Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_SKYNETxeyicomu_.sys.zip Infected: Rootkit.Win32.TDSS.q 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETpvymnmsu.dll.vir Infected: Trojan.Win32.Monder.cpxu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETulkasued.dll.vir Infected: Trojan.Win32.Small.bzc 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP363\A0040736.dll Infected: Trojan.Win32.Monder.cpxu 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP363\A0040737.dll Infected: Trojan.Win32.Small.bzc 1
C:\_OTM\MovedFiles\08232009_164642\WINDOWS\svchast.exe Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.iv 1
C:\_OTM\MovedFiles\08232009_164642\WINDOWS\system32\desot.exe Infected: not-a-virus:FraudTool.Win32.Antivirus2008pro.bq 1
F:\Bk Up Outlook\Hotmail - Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
Selected area has been scanned.
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-07-30.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 5/3/2008 8:37:22 PM
System Uptime: 8/30/2009 1:00:12 PM (6 hours ago)
Motherboard: Dell Inc. | | 0CU409
Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | Socket 775 | 1794/200mhz
Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | Socket 775 | 1795/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 149 GiB total, 19.888 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is FIXED (FAT32) - 466 GiB total, 90.078 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP361: 8/25/2009 6:53:00 PM - Software Distribution Service 3.0
RP362: 8/26/2009 8:26:15 AM - Software Distribution Service 3.0
RP363: 8/27/2009 9:55:43 PM - System Checkpoint
RP364: 8/28/2009 10:03:46 PM - System Checkpoint
RP365: 8/29/2009 6:30:56 AM - Removed J2SE Runtime Environment 5.0 Update 6
RP366: 8/29/2009 6:32:07 AM - Removed Java(TM) 6 Update 5
RP367: 8/29/2009 6:50:15 AM - Installed Java(TM) 6 Update 16
==== Installed Programs ======================
5600
5600_Help
5600Trb
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
Adobe Stock Photos 1.0
AiO_Scan
AiOSoftware
Apple Mobile Device Support
Apple Software Update
Audacity 1.2.6
Batch Watermark Creator 6.1.1
Bonjour
BookSmart™ 1.9.9 1.9.9
Browser Address Error Redirector
Browser Hijack Recover(BHR) 3.0
BufferChm
CDBurnerXP
CleanUp!
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
Dell Driver Reset Tool
Dell Network Assistant
Dell Support Center (Support Software)
Destinations
DeviceManagementQFolder
DocProc
Dragon Tales
Easy Thumbnails (Remove only)
ERUNT 1.1j
eSupportQFolder
ExifPro 1.0 Photo Viewer
Fax
Free RAR Extract Frog 1.00
Garmin POI Loader
Garmin USB Drivers
Garmin WebUpdater
Google Desktop
Google Earth Plugin
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
GSAK 7.6.0.51 (Final)
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB908673)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB921411)
Hotfix for Windows XP (KB924455)
Hotfix for Windows XP (KB934428-v2)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Image Zone Express
HP Imaging Device Functions 5.3
HP PSC & OfficeJet 5.3.B
HP Software Update
HP Solution Center & Imaging Support Tools 5.3
HPProductAssistant
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections 12.1.8.0
iTunes
Java(TM) 6 Update 16
LAME v3.98.2 for Audacity
Logitech Desktop Messenger
Logitech Harmony Remote Software 7
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mouse Suite for Desktop Computers
Move Networks Media Player for Internet Explorer
Mozilla Firefox (3.0.12)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
NewCopy
Palm Desktop by ACCESS
PowerDVD
ProductContext
QuickTime
Readme
Realtek High Definition Audio Driver
Remote Control USB Driver
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Drag-to-Disc
Roxio Express Labeler
Roxio Update Manager
Safe Eyes
Scan
ScannerCopy
SearchAssist
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
SolutionCenter
Sonic Activation Module
Spoiler Sync
Spybot - Search & Destroy
Status
SyncBack
TrayApp
Unload
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows XP (KB894391)
Update for Windows XP (KB896256)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB912945)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
WebFldrs XP
WebReg
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
YourBell
==== Event Viewer Messages From Past Week ========
8/29/2009 6:31:12 AM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
8/28/2009 9:22:21 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
8/28/2009 9:17:42 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
8/26/2009 12:47:01 AM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.102. The machine with the IP address 192.168.1.100 did not allow the name to be claimed by this machine.
8/25/2009 8:09:38 PM, error: Service Control Manager [7024] - The Computer Browser service terminated with service-specific error 2250 (0x8CA).
8/25/2009 8:07:45 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
8/25/2009 8:02:46 PM, error: Service Control Manager [7000] - The AntipyProex service failed to start due to the following error: The system cannot find the file specified.
8/25/2009 8:02:29 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001D0994F944 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
8/25/2009 6:56:46 AM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.103. The machine with the IP address 192.168.1.101 did not allow the name to be claimed by this machine.
8/25/2009 6:54:08 PM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.100. The machine with the IP address 192.168.1.101 did not allow the name to be claimed by this machine.
8/25/2009 6:53:00 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume3'. It has stopped monitoring the volume.
8/25/2009 6:51:09 PM, error: BTHUSB [17] - The local Bluetooth radio has failed in an undetermined manner and will be unloaded.
8/25/2009 6:50:53 PM, error: Dhcp [1002] - The IP address lease 192.168.1.103 for the Network Card with network address 001D0994F944 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
8/25/2009 6:15:01 AM, error: HTTP [15005] - Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number.
8/23/2009 5:35:38 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
8/23/2009 5:09:31 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
8/23/2009 5:09:31 PM, error: Service Control Manager [7022] - The Bonjour Service service hung on starting.
8/23/2009 4:40:12 PM, error: Service Control Manager [7034] - The AntipyProex service terminated unexpectedly. It has done this 1 time(s).
8/23/2009 11:48:01 AM, error: Service Control Manager [7024] - The Background Intelligent Transfer Service service terminated with service-specific error 2147942402 (0x80070002).
8/23/2009 11:47:43 AM, error: Service Control Manager [7038] - The SSDPSRV service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The handle is invalid. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
8/23/2009 11:47:43 AM, error: Service Control Manager [7000] - The SSDP Discovery Service service failed to start due to the following error: The service did not start due to a logon failure.
8/23/2009 11:47:39 AM, error: Service Control Manager [7023] - The Remote Access Connection Manager service terminated with the following error: Incorrect function.
8/23/2009 11:47:39 AM, error: Rasman [20033] - Remote Access Connection Manager failed to start because it could not register with the local security authority. Restart the computer. Incorrect function.
8/23/2009 11:46:28 AM, error: Service Control Manager [7023] - The IPSEC Services service terminated with the following error: The requested service provider could not be loaded or initialized.
8/23/2009 10:40:06 AM, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s).
==== End Of File ===========================
+++++++++++++++++++++++++++++++++++++++++++++++++++
DDS (Ver_09-07-30.01) - NTFSx86
Run by Cluffs at 19:30:48.54 on Sun 08/30/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2037.1224 [GMT -7:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\Pmxmiced.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Cluffs\Local Settings\temp\jkos-Cluffs\binaries\ScanningProcess.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\Cluffs\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
uInternet Settings,ProxyOverride = *.local
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Safe &Eyes Toolbar: {430ddb4f-38cc-4e91-af33-4157334ec937} - c:\program files\internet content filter\setoolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [cdloader] "c:\documents and settings\cluffs\application data\mjusbsp\cdloader2.exe" MAGICJACK
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PMX Daemon] ICO.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [ICF] "c:\program files\internet content filter\SafeEyes.exe"
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellne~1.lnk - c:\windows\installer\{0240bdfb-2995-4a3f-8c96-18d41282b716}\Icon0240BDFB3.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: ICF.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mpix.com/customer/uploading/activex/ImageUploader5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\cluffs\applic~1\mozilla\firefox\profiles\iz669p5k.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
FF - component: c:\documents and settings\cluffs\application data\mozilla\firefox\profiles\iz669p5k.default\extensions\{7e7165e2-0767-448c-852f-5fa8714f2c37}\components\PlainOldFavorites.dll
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-5-3 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-5-3 14336]
S2 gupdate1c9dbc288d3f3a0;Google Update Service (gupdate1c9dbc288d3f3a0);c:\program files\google\update\GoogleUpdate.exe [2009-5-23 133104]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-4-14 29744]
=============== Created Last 30 ================
2009-08-29 06:50 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-29 06:50 73,728 a------- c:\windows\system32\javacpl.cpl
2009-08-28 21:34 <DIR> --d----- c:\windows\system32\dllcache\cache
2009-08-28 21:28 50,176 a------- c:\windows\system32\proquota.exe
2009-08-28 21:28 50,176 a------- c:\windows\system32\dllcache\proquota.exe
2009-08-28 21:16 <DIR> a-dshr-- C:\cmdcons
2009-08-28 21:14 229,376 a------- c:\windows\PEV.exe
2009-08-28 21:14 161,792 a------- c:\windows\SWREG.exe
2009-08-28 21:14 98,816 a------- c:\windows\sed.exe
2009-08-25 18:53 <DIR> --d----- c:\documents and settings\cluffs\logitech
2009-08-25 18:52 <DIR> --d----- c:\program files\common files\Remote Control Software Common
2009-08-25 18:52 <DIR> --d----- c:\program files\common files\Remote Control USB Driver
2009-08-25 18:52 127,034 -----r-- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-08-23 16:46 <DIR> --d----- C:\_OTM
2009-08-23 16:38 664 a------- c:\windows\system32\d3d9caps.dat
2009-08-22 22:01 1,089,601 -------- c:\windows\system32\dllcache\ntprint.cat
2009-08-22 09:44 <DIR> --d----- c:\windows\system32\XPSViewer
2009-08-17 22:01 <DIR> --d----- c:\windows\system32\LogFiles
2009-08-12 03:00 <DIR> --d----- c:\windows\ServicePackFiles
2009-08-11 15:20 128,512 -------- c:\windows\system32\dllcache\dhtmled.ocx
2009-08-11 15:20 655,872 -------- c:\windows\system32\dllcache\mstscax.dll
2009-08-05 02:11 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll
==================== Find3M ====================
2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-03 13:36 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 13:36 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-19 18:48 11,067,392 -------- c:\windows\system32\dllcache\ieframe.dll
2009-07-19 06:18 5,937,152 a------- c:\windows\system32\dllcache\cache\mshtml.dll
2009-07-19 06:18 5,937,152 -------- c:\windows\system32\dllcache\mshtml.dll
2009-07-17 11:55 58,880 a------- c:\windows\system32\atl.dll
2009-07-17 11:55 58,880 -------- c:\windows\system32\dllcache\atl.dll
2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-07-13 02:18 233,472 -------- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-13 02:18 4,960,256 -------- c:\windows\system32\dllcache\wmp.dll
2009-07-10 06:42 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
2009-07-03 11:53 202,048 a------- c:\windows\system32\ftd2xx.dll
2009-07-03 11:53 185,664 a------- c:\windows\system32\FTLang.dll
2009-07-03 11:53 120,128 a------- c:\windows\system32\ftbusui.dll
2009-07-03 11:53 57,536 a------- c:\windows\system32\drivers\ftdibus.sys
2009-07-03 04:01 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-06-25 01:17 729,600 a------- c:\windows\system32\lsasrv.dll
2009-06-25 01:17 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 01:17 168,448 a------- c:\windows\system32\schannel.dll
2009-06-25 01:17 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 01:17 59,392 a------- c:\windows\system32\wdigest.dll
2009-06-25 01:17 56,320 a------- c:\windows\system32\secur32.dll
2009-06-25 01:17 729,600 -------- c:\windows\system32\dllcache\lsasrv.dll
2009-06-25 01:17 301,568 -------- c:\windows\system32\dllcache\kerberos.dll
2009-06-25 01:17 168,448 -------- c:\windows\system32\dllcache\schannel.dll
2009-06-25 01:17 136,192 -------- c:\windows\system32\dllcache\msv1_0.dll
2009-06-25 01:17 59,392 -------- c:\windows\system32\dllcache\wdigest.dll
2009-06-25 01:17 56,320 -------- c:\windows\system32\dllcache\secur32.dll
2009-06-22 04:35 92,544 -------- c:\windows\system32\dllcache\ksecdd.sys
2009-06-16 07:55 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 07:55 82,432 a------- c:\windows\system32\fontsub.dll
2009-06-16 07:55 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-06-16 07:55 82,432 -------- c:\windows\system32\dllcache\fontsub.dll
2009-06-12 04:50 76,288 a------- c:\windows\system32\telnet.exe
2009-06-12 04:50 76,288 -------- c:\windows\system32\dllcache\telnet.exe
2009-06-10 07:21 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 07:21 84,992 -------- c:\windows\system32\dllcache\avifil32.dll
2009-06-09 23:32 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-09 23:32 132,096 -------- c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 00:42 655,872 a------- c:\windows\system32\mstscax.dll
2009-06-03 12:27 1,290,752 a------- c:\windows\system32\quartz.dll
2009-06-03 12:27 1,290,752 -------- c:\windows\system32\dllcache\quartz.dll
2009-06-02 03:12 102,912 -------- c:\windows\system32\dllcache\iecompat.dll
2009-04-15 21:43 8,081 a------- c:\program files\gsak.ini
2009-04-15 21:41 29 a------- c:\program files\dbfindex.bif
2009-04-15 21:41 22,528 a------- c:\program files\gsak.db3
2009-04-15 21:12 5,120 a------- c:\program files\POST.NSX
2009-04-15 21:12 226 a------- c:\program files\POST.DBF
2008-06-25 18:56 17,144 a------- c:\docume~1\cluffs\applic~1\GDIPFONTCACHEV1.DAT
============= FINISH: 19:31:27.18 ===============