Unsolved
This post is more than 5 years old
15 Posts
0
4829
December 4th, 2009 18:00
CPU maxed out in a normal boot, Will not boot up in Safe mode
I'm new to this community and a bit of a novice with a computer, so please bear with me.
I have a Dell Dimensions E520 running XP Media Center Edition 2002 SP3. The computer has been getting extremely slow and suspected some Malware. The computer will boot in normal mode, but then appears to hang up. I looked at Task Manager (which took forever to open) and saw the CPU was maxed out by 2 processes (CLI.exe and dsca.exe at about 50% each ). If I end those 2 tasks, it will allow me to move around abit. When I go to the Dell website and try to download updated drivers, the task manager shows dfsvc.exe at 50% and won't download anything or let me open it. If a second dell window opens, I get a second dfsvc.exe at 50% and get hung up again (CPU at 100%). I ran Spy Bot which identified 6 trojans which I deleted, but didn't seem to help. If I try to boot the computer in Safe mode I get the Blue Screen with the following:
Stop: 0x0000007E (0xC0000005, 0x80537009, 0xF789E508, 0XF789E204). If I restart and allow it to boot in normal mode, I go back to the CPU being maxed out as noted above. Since I ran SpyBot and with the CLI.exex and dsca.exe ended, I've been getting occasional misdirection on my internet explorer 7 and get a 400 Bad Request on ther task manager and an Error with a Goggle page showing, sometimes it appears I'll get these randomly, but believe this is caused by some bcakground attempts (i.e. auto updates) that are getting redirected. The following is the HIJACKTHIS file that I was requested to run.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:27 PM, on 12/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - hxxp://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - hxxp://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - hxxp://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1219714647194&h=abfebb99a33d2e792eb3e19a6e51ad64/&filename=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - hxxp://gianteagle.lifepics.com/net/Uploader/LPUploader45.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4902/mcfscan.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
--
End of file - 16863 bytes


1972vet
3.3K Posts
0
December 8th, 2009 01:00
Greetings West7948,

I'm stepping in for Bugbatter who is away on emergency family matters. I'd like you to do the following please:
Step 1
Please download the free utility DDS...You will find a download from Here, Here, or Here.
Disable any script blocker you may have running, then double click dds.scr to run the tool.
Step 2
Download GMER Rootkit Scanner from here or here.
Do NOT take any action on any of these "<--- ROOKIT" entries without proper guidance from an expert user.
Please include the following logs in your next reply, Thanks!:
West7948
15 Posts
0
December 8th, 2009 11:00
Hello 1972 vet!
Thanks for stepping in for bugbatter. Sorry to hear of her emergency. I tried to follow instructions as requested. Not really sure if I have any script blockers running. I figure it would be in my firewall or Explorer. The only thing I could find was in the Advanced settings in Internet Explorer which read "Disable Script Debugging (Internet Explorer) and Disable Script Debugging (other)". Both were checked, so have been running this disabled. Please advise if you think I have this script blocker running and if so, where I need to go to turn off. I don't see anyway to attach the results as files, so will do a cut/paste.
DDS (Ver_09-12-01.01) - NTFSx86
Run by Dennis at 13:48:26.56 on Tue 12/08/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2173 [GMT -5:00]
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\vVX1000.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\qoeapp.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Dennis\Local Settings\Temporary Internet Files\Content.IE5\M9U7AGFN\dds[1].scr
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://my.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [PinnacleDriverCheck] c:\windows\system32\\PSDrvCheck.exe
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [PMX Daemon] ICO.EXE
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [VX1000] c:\windows\vVX1000.exe
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [QOELOADER] "c:\program files\ca\ca internet security suite\ca anti-spam\qsp-5.1.18.0\QOELoader.exe"
mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
mRun: [cafwc] c:\program files\ca\ca internet security suite\ca personal firewall\cafw.exe -cl
mRun: [capfasem] c:\program files\ca\ca internet security suite\ca personal firewall\capfasem.exe
mRun: [ ]
mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imaget~1.lnk - c:\program files\sony corporation\image transfer\SonyTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.5.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1219714647194&h=abfebb99a33d2e792eb3e19a6e51ad64/&filename=jinstall-6u7-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} - hxxp://gianteagle.lifepics.com/net/Uploader/LPUploader45.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4902/mcfscan.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\480\G2AWinLogon.dll
Notify: PFW - UmxWnp.Dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2008-6-24 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2008-6-24 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2008-6-24 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-6-24 115216]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2007-10-8 26352]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2007-10-8 21104]
R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-10-13 739696]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2007-10-8 21488]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2007-10-8 32240]
R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2007-10-8 144960]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-11-26 54752]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-6-24 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-6-24 66576]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2008-6-24 88816]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-10-13 133520]
=============== Created Last 30 ================
2009-12-08 18:45:44 0 d--h--w- c:\windows\PIF
2009-12-05 02:04:41 0 d-----w- c:\program files\Trend Micro
2009-12-02 01:13:38 0 d-----w- c:\program files\CCleaner
2009-11-30 16:47:35 0 d-----w- c:\windows\system32\wbem\Repository
2009-11-27 18:33:33 0 d-----w- c:\documents and settings\dennis\Tracing
2009-11-26 23:44:17 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-11-26 23:42:08 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-11-26 23:41:55 20 ----a-w- c:\windows\ÿÿ
2009-11-26 23:41:55 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-26 23:39:24 0 d-----w- c:\program files\Microsoft
2009-11-26 23:38:58 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-26 18:13:45 0 d-----w- c:\program files\common files\Windows Live
==================== Find3M ====================
2009-12-08 01:03:34 246784 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2009-12-07 03:22:50 185890 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2009-12-01 17:03:08 739696 ----a-w- c:\windows\system32\drivers\vetefile.sys
2009-12-01 17:03:08 32240 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-12-01 17:03:08 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-12-01 17:03:08 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-12-01 17:03:08 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-12-01 17:03:08 133520 ----a-w- c:\windows\system32\drivers\veteboot.sys
2009-10-21 04:08:54 3598336 ------w- c:\windows\system32\dllcache\mshtml.dll
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2007-02-05 22:41:00 1128960 ------w- c:\program files\ehthumbs.db
2006-08-09 17:42:18 3198976 ----a-w- c:\program files\ViewSonicregistration.exe
2007-01-19 21:20:14 88 --sh--r- c:\windows\system32\9650A842F0.sys
2009-02-21 01:42:56 88 --sh--r- c:\windows\system32\A02EC1510F.sys
2009-02-21 01:42:59 3140 --sha-w- c:\windows\system32\KGyGaAvL.sys
2008-08-26 01:23:49 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082520080826\index.dat
============= FINISH: 13:53:01.53 ===============
Attach.txt results:
DDS (Ver_09-12-01.01) - NTFSx86
Run by Dennis at 13:48:26.56 on Tue 12/08/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2173 [GMT -5:00]
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\vVX1000.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\qoeapp.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Dennis\Local Settings\Temporary Internet Files\Content.IE5\M9U7AGFN\dds[1].scr
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://my.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [PinnacleDriverCheck] c:\windows\system32\\PSDrvCheck.exe
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [PMX Daemon] ICO.EXE
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [VX1000] c:\windows\vVX1000.exe
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [QOELOADER] "c:\program files\ca\ca internet security suite\ca anti-spam\qsp-5.1.18.0\QOELoader.exe"
mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
mRun: [cafwc] c:\program files\ca\ca internet security suite\ca personal firewall\cafw.exe -cl
mRun: [capfasem] c:\program files\ca\ca internet security suite\ca personal firewall\capfasem.exe
mRun: [ ]
mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imaget~1.lnk - c:\program files\sony corporation\image transfer\SonyTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.5.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1219714647194&h=abfebb99a33d2e792eb3e19a6e51ad64/&filename=jinstall-6u7-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} - hxxp://gianteagle.lifepics.com/net/Uploader/LPUploader45.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4902/mcfscan.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\480\G2AWinLogon.dll
Notify: PFW - UmxWnp.Dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2008-6-24 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2008-6-24 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2008-6-24 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-6-24 115216]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2007-10-8 26352]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2007-10-8 21104]
R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-10-13 739696]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2007-10-8 21488]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2007-10-8 32240]
R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2007-10-8 144960]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-11-26 54752]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-6-24 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-6-24 66576]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2008-6-24 88816]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-10-13 133520]
=============== Created Last 30 ================
2009-12-08 18:45:44 0 d--h--w- c:\windows\PIF
2009-12-05 02:04:41 0 d-----w- c:\program files\Trend Micro
2009-12-02 01:13:38 0 d-----w- c:\program files\CCleaner
2009-11-30 16:47:35 0 d-----w- c:\windows\system32\wbem\Repository
2009-11-27 18:33:33 0 d-----w- c:\documents and settings\dennis\Tracing
2009-11-26 23:44:17 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-11-26 23:42:08 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-11-26 23:41:55 20 ----a-w- c:\windows\ÿÿ
2009-11-26 23:41:55 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-26 23:39:24 0 d-----w- c:\program files\Microsoft
2009-11-26 23:38:58 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-26 18:13:45 0 d-----w- c:\program files\common files\Windows Live
==================== Find3M ====================
2009-12-08 01:03:34 246784 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2009-12-07 03:22:50 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2009-12-07 03:22:50 185890 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2009-12-01 17:03:08 739696 ----a-w- c:\windows\system32\drivers\vetefile.sys
2009-12-01 17:03:08 32240 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-12-01 17:03:08 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-12-01 17:03:08 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-12-01 17:03:08 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-12-01 17:03:08 133520 ----a-w- c:\windows\system32\drivers\veteboot.sys
2009-10-21 04:08:54 3598336 ------w- c:\windows\system32\dllcache\mshtml.dll
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2007-02-05 22:41:00 1128960 ------w- c:\program files\ehthumbs.db
2006-08-09 17:42:18 3198976 ----a-w- c:\program files\ViewSonicregistration.exe
2007-01-19 21:20:14 88 --sh--r- c:\windows\system32\9650A842F0.sys
2009-02-21 01:42:56 88 --sh--r- c:\windows\system32\A02EC1510F.sys
2009-02-21 01:42:59 3140 --sha-w- c:\windows\system32\KGyGaAvL.sys
2008-08-26 01:23:49 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082520080826\index.dat
============= FINISH: 13:53:01.53 ===============
Results GMER "ark.txt"
GMER 1.0.15.15273 - http://www.gmer.net
Rootkit scan 2009-12-08 14:25:43
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Dennis\LOCALS~1\Temp\fftoapoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwCreateKey [0x929DA6EA]
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys (HIPS Agent Driver/CA) ZwCreateSection [0x97974FD2]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwCreateSymbolicLinkObject [0x929DB40B]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwMakeTemporaryObject [0x929DB75C]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwOpenKey [0x929DA64E]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwOpenSection [0x929DB130]
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys (HIPS Agent Driver/CA) ZwSetInformationProcess [0x97974662]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwSetSystemInformation [0x929DB538]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs KmxFile.sys (HIPS File Guard driver/CA)
AttachedDevice \FileSystem\Ntfs \Ntfs kmxagent.sys (HIPS Agent Driver/CA)
AttachedDevice \FileSystem\Ntfs \Ntfs VET-REC.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)
Device \Driver\Tcpip \Device\Ip kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\Tcp kmxfw.sys (HIPS Firewall Driver/CA)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
Device \Driver\Tcpip \Device\Udp kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\RawIp kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\IPMULTICAST kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\AFD \Device\Afd KmxCF.sys (HIPS Content Filter Driver/CA)
AttachedDevice \FileSystem\Fastfat \Fat KmxFile.sys (HIPS File Guard driver/CA)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
Device -> \Driver\iastor \Device\Harddisk0\DR0 8B09D618
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0x2E 0xE8 0xE1 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xDF 0x20 0x58 0x62 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\drivers\iastor.sys suspicious modification
---- EOF - GMER 1.0.15 ----
Thanks for taking time to look into this.
1972vet
3.3K Posts
0
December 8th, 2009 13:00
May I see the file "Attach.txt" please? You would post it the same way you did the other log. While the file is open, copy the contents and paste it into your next reply. Thanks!
West7948
15 Posts
0
December 8th, 2009 14:00
Sorry. I see I copied the dds file twice. this should be the attached.txt
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\Harddisk0\DP(2)0x36e8e00-0x390816a800+2
Install Date: 11/21/2006 4:13:35 PM
System Uptime: 12/7/2009 8:49:48 AM (29 hours ago)
Motherboard: Dell Inc. | | 0WG864
Processor: Intel(R) Pentium(R) D CPU 2.66GHz | Microprocessor | 2660/533mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 228 GiB total, 173.031 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is FIXED (FAT) - 0 GiB total, 0.046 GiB free.
G: is FIXED (FAT32) - 5 GiB total, 0.456 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1307: 12/5/2009 9:32:45 PM - System Checkpoint
RP1308: 12/5/2009 10:55:05 PM - Software Distribution Service 3.0
RP1309: 12/6/2009 10:22:04 PM - Software Distribution Service 3.0
RP1310: 12/7/2009 10:38:15 PM - System Checkpoint
RP1311: 12/8/2009 3:00:19 AM - Software Distribution Service 3.0
==== Installed Programs ======================
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Help Center 2.1
Adobe Photoshop Elements 5.0
Adobe Reader 9.2
AIM 6
Altair HyperWorks 8.0sr1
AnswerWorks 4.0 Runtime - English
AnswerWorks 5.0 English Runtime
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Control Center
ATI Display Driver
AutoUpdate
Banctec Service Agreement
CA Anti-Spam
CA Anti-Spyware
CA Anti-Virus
CA Internet Security Suite
CA Personal Firewall
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities Digital Photo Professional 2.2
Canon Utilities EOS Utility
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
CCleaner
Compton's Interactive Encyclopedia 1999 Deluxe
Corel Snapfire Plus
Creative MediaSource
Critical Update for Windows Media Player 11 (KB959772)
Dell CinePlayer
Dell Driver Reset Tool
Dell Game Console
Dell Support 3.2
Dell Support Center (Support Software)
Dell System Restore
Digital Content Portal
DiscAPI (Studio 10)
DivX
Documentation & Support Launcher
EarthLink Setup Files
EasyGPS 2.9.6
EducateU
ESPNMotion
eTrust EZ Firewall
Games, Music, & Photos Launcher
GemMaster Mystic
Get High Speed Internet!
Google Desktop
Google Toolbar for Internet Explorer
GoToAssist 8.0.0.480
GSAK 7.2.2.23 (Final)
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix 2050 for SQL Server 2000 ENU (KB948110)
Hotfix 2055 for SQL Server 2000 ENU (KB960082)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Precisionscan Pro 3.1
HP Share-to-Web
Image Transfer
Intel(R) Matrix Storage Manager
Intel(R) PRO Network Connections
Internet Service Offers Launcher
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 7
Junk Mail filter update
MCU
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft LifeCam
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Disc 2
Microsoft Office 2000 Premium
Microsoft Office Word Viewer 2003
Microsoft PhotoDraw 2000
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server Desktop Engine (PINNACLESYS)
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
Mouse Suite for Desktop Computers
MSN
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NetZeroInstallers
OpenOffice.org Installer 1.0
Otto
Pinnacle Instant DVD Recorder
Pinnacle MediaServer
proDAD Heroglyph 2.5
QuickTime
RAPID (Studio 10)
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
SearchAssist
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Segoe UI
SigmaTel Audio
Skype™ 3.5
SmartSound Quicktracks Plugin
Sonic Activation Module
Sonic Advanced Decoder
Sonic Encoders
Sonic Update Manager
Sound Blaster X-Fi
Spelling Dictionaries Support For Adobe Reader 9
Spybot - Search & Destroy
Studio 10
Studio 10 Bonus DVD
TurboTax 2008
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wohiper
TurboTax 2008 wrapper
TurboTax Deluxe 2007
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2006
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
WebCyberCoach 3.2 Dell
WebFldrs XP
WexTech AnswerWorks
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
WinZip 11.1
Yahoo! Music Jukebox
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
12/6/2009 9:12:56 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the MSSQL$PINNACLESYS service to connect.
12/6/2009 9:12:56 AM, error: Service Control Manager [7001] - The Pinnacle Systems Media Service service depends on the MSSQL$PINNACLESYS service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
12/6/2009 9:12:56 AM, error: Service Control Manager [7000] - The MSSQL$PINNACLESYS service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/5/2009 8:23:04 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000007F' while processing the file 'desktop.ini' on the volume 'DP(1)0x7e00-0x36e1000+1'. It has stopped monitoring the volume.
12/2/2009 11:42:06 PM, error: Service Control Manager [7034] - The CAISafe service terminated unexpectedly. It has done this 1 time(s).
12/1/2009 8:57:12 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PPCtlPriv service to connect.
12/1/2009 8:57:12 PM, error: Service Control Manager [7000] - The PPCtlPriv service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 8:57:12 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service PPCtlPriv with arguments "" in order to run the server: {F974178A-A284-440A-BEFC-5B0D11BCDB68}
12/1/2009 8:55:51 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
12/1/2009 8:55:51 PM, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 8:55:16 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
12/1/2009 8:55:16 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 8:43:41 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Pinnacle Systems Media Service service to connect.
12/1/2009 8:43:41 PM, error: Service Control Manager [7000] - The Pinnacle Systems Media Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 8:42:54 PM, error: Service Control Manager [7000] - The Fax service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 8:42:53 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Fax service to connect.
12/1/2009 8:42:21 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Canon Camera Access Library 8 service to connect.
12/1/2009 8:42:21 PM, error: Service Control Manager [7000] - The Canon Camera Access Library 8 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 8:42:15 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Intuit Update Service service to connect.
12/1/2009 8:42:15 PM, error: Service Control Manager [7000] - The Intuit Update Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 4:34:18 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the COM+ System Application service to connect.
12/1/2009 4:34:18 PM, error: Service Control Manager [7000] - The COM+ System Application service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 4:34:17 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service COMSysApp with arguments "" in order to run the server: {ECABAFBC-7F19-11D2-978E-0000F8757E2A}
12/1/2009 4:16:01 PM, error: Service Control Manager [7000] - The SSDP Discovery Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 4:16:00 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the SSDP Discovery Service service to connect.
12/1/2009 4:12:51 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the VET Message Service service to connect.
12/1/2009 4:12:51 PM, error: Service Control Manager [7001] - The Media Center Extender Service service depends on the SSDP Discovery Service service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 4:12:51 PM, error: Service Control Manager [7001] - The Canon Camera Access Library 8 service depends on the SSDP Discovery Service service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
12/1/2009 4:12:51 PM, error: Service Control Manager [7000] - The VET Message Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
==== End Of File ===========================
1972vet
3.3K Posts
0
December 8th, 2009 16:00
Hmmm...I don't see McAfee listed as an installed program but it nonetheless is running one of it's needless components. While you have CA's eTrust Internet Security Suite, which has the same feature, you have no need of McAfee. It's pointless to go looking for it since it's not listed in add/remove so we need to enlist McAfee's assistance to remove it. Use the McAfee Removal Tool to completely uninstall their products.
I wanted to ask, do you use this program?:
GoToAssist 8.0.0.480
...if so, it's fine. I've used it myself. I just wanted to point out that if you have not set up a Strong Password for it, then it would take no time for someone to take control of your computer. If however you don't use it, please uninstall it.
The following software needs to be uninstalled as well:
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 7
OpenOffice.org Installer 1.0
SearchAssist
URL Assistant
...click start-->Control Panel-->Add/Remove Programs. Scroll down the list to locate the program names and click Remove for each. We will install the latest Java and Open Office versions only after we finish cleaning up.
Next, we need to disable Tea Timer to prevent a wrestling contest with our cleanup efforts. To do that:
Please download combofix from This Webpage...and read through the instructions there for running the tool.
***Important Note***
Please read through the guidance on that web page carefully and thoroughly...and install the Recovery Console. Using this tool without the Recovery Console installed is NOT RECOMMENDED.
If you have Windows Vista, you can skip the recovery console step...in Vista it's in the System Recovery Options menu. The System Recovery Options menu is on the Windows Vista installation disc. If Windows doesn't start correctly, you can use these tools to repair startup problems.
The Windows Recovery Console will allow you to boot into a special recovery (repair) mode that is not otherwise available. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It's a simple procedure that will only take a few moments.
Once installed, a blue screen prompt should appear that reads as follows:
The Recovery Console was successfully installed.
When you see that screen, please continue as follows:
When the tool is finished, it will produce a log file for you. Please post that log back here on your next reply. Thanks!
Note:
Do not mouseclick combofix's window while it's running....that may cause the scan to stall
West7948
15 Posts
0
December 8th, 2009 19:00
McAfee was our original Anti-virus, then went to CA. I've not completed all that was request based on the following.
I created a restore point before I started. Got an error when trying to access the Mcafee Removal Tool link. I don't use GoToAssist. I believe it was left from prior work with Dell when computer was under warranty or Roadrunner my ISP. I removed GoTo as well as the others listed. I went to Mcafee website, but still couldn't get the removal tool. I tried downloading Vitual Technician, thinking it might help me, but didn't help. When I tried to remove it, it was taking forever. I ended up going back to my restore point and started over.
At this point I've removed GoTo and those requested, but haven't had sucess with Mcaffe Removal. Do you want me to proceed anyway, or work on Mcafee removal? Any other thoughts on how to do this?
Thanks
1972vet
3.3K Posts
0
December 8th, 2009 19:00
McAfee is notorious for causing problems while Combofix is running. Let's go ahead and run Combofix...we can use THAT to remove McAfee. Post the log and I'll give you more instructions on the McAfee removal via a combofix script we can write up for you. Thanks!
West7948
15 Posts
0
December 9th, 2009 16:00
Tried running combofix, but it never completed the process. Since my last posting, I had disabled Tea Timer and rebooted. Downloaded Combo fix, printed and read thru watchouts and warnings. I couldn't find the procedure on your link to disable CA Security, so went into each CA Anti-virus, Spyware Firewall and Anti-spam and disabled internally.I'm pretty shure I had everything disabled as there were lots of warning flags showing that I was at risk. Started running Combofix, it had me load the MS Windows recovery. At one point it asked if I was running XP "Home Edition". I answered no as it is actually Media Center, but I saw as it was running it indicated "Home Edition SP2 anyway"? It continued on, made a Restore point, then indicated it was going to reboot. It was showing an OK prompt to shutdown, but I figured it was going to be automatic then I got a red X error as follows: "Axwin Frame Window: svchost.exe- application error, The instruction at "0x3dad2337" referenced memory at "0x00000010". The memory could not "read". It asked me to click ok, I waited a bit with nothing happening, so clicked ok, then a short bit later I got a box that read something like "System is shutting down: Windows might not restart because DCOM Server Process Launcher servuice terminated unexpectedly" It had a timer showing a count down and then rebooted on it's own. It looked like a normal reboot, I waited 30 mins, but nothing was happening??? Thoughts?
West7948
15 Posts
0
December 9th, 2009 17:00
I hadn't done anything, it rebooted on it's own after the window might not restart counted down. I thought I'd see a window as described in the combofix write up, but nothing was happening. That's when I posted my last message. Didn't know if I should give it another try or not.
1972vet
3.3K Posts
0
December 9th, 2009 17:00
When the 30 minutes expired, what did you do...a hard reboot?
1972vet
3.3K Posts
0
December 9th, 2009 18:00
If there is no combofix log located in your C:\ drive then yes...let's try it again. But this time, uninstall CA's eTrust completely before you run combofix.
West7948
15 Posts
0
December 9th, 2009 19:00
Went to control panel to remove CA security. It removed all but the firewall in which I got an error "E9039: Unable to remove CA personal firewall". I tried several times, but didn't want to unstall. I went to the corner drop menu and disabled it then ran the combofix. It ran this time as indicated in the write up, but when it did the reboot, it sat for 30 plus mins without doing anything. I know it said not to touch anything, but it looked like it was hung up. I checked the firewall and it had activated on the reboot. I disabled it and the combofix finished creating a report. I'll post it here, but know that I did activate the mouse to disable the firewall after the reboot. If this corrupts the report I'll look to keep trying to remove the firewall and rerun. Currently dont' have any protection on computer except the firewall.
ComboFix 09-12-09.04 - Dennis 12/09/2009 22:03:35.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2543 [GMT -5:00]
Running from: c:\documents and settings\Dennis\Desktop\ComboFix.exe
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\kb913800.exe
c:\windows\system32\drivers\1028_DELL_XPS_Dell DM061 .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DM061 .MRK
C:\Log.txt . . . . failed to delete
Infected copy of c:\windows\system32\drivers\iastor.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 )))))))))))))))))))))))))))))))
.
2009-12-09 02:36 . 2009-12-09 02:36 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-08 18:45 . 2009-12-08 18:45 -------- d--h--w- c:\windows\PIF
2009-12-05 02:04 . 2009-12-05 02:04 -------- d-----w- c:\program files\Trend Micro
2009-12-02 03:17 . 2009-12-02 03:19 -------- d-----w- c:\program files\Windows Live Safety Center
2009-12-02 01:49 . 2009-12-02 01:49 -------- d-----w- c:\documents and settings\Dennis\Local Settings\Application Data\Threat Expert
2009-12-02 01:26 . 2009-12-02 01:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-02 01:13 . 2009-12-02 01:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-12-02 01:13 . 2009-12-02 01:13 -------- d-----w- c:\documents and settings\Dennis\Application Data\Yahoo!
2009-12-02 01:13 . 2009-12-02 01:14 -------- d-----w- c:\program files\CCleaner
2009-11-30 18:45 . 2009-11-30 18:45 -------- d-----w- c:\documents and settings\Kathy\Tracing
2009-11-27 18:33 . 2009-11-27 18:33 -------- d-----w- c:\documents and settings\Dennis\Tracing
2009-11-26 23:44 . 2009-11-28 08:32 -------- d-----w- c:\program files\Microsoft Silverlight
2009-11-26 23:44 . 2009-08-06 03:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-11-26 23:43 . 2009-11-26 23:43 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-11-26 23:42 . 2006-11-29 18:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-11-26 23:41 . 2009-11-26 23:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-26 23:39 . 2009-11-26 23:39 -------- d-----w- c:\program files\Microsoft
2009-11-26 23:38 . 2009-11-26 23:38 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-26 18:13 . 2009-11-26 18:13 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-10 03:16 . 2007-10-10 07:07 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2009-12-10 03:16 . 2007-10-10 07:07 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2009-12-10 03:16 . 2007-10-10 07:07 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2009-12-10 03:16 . 2007-10-10 07:07 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2009-12-10 03:16 . 2007-10-10 07:07 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2009-12-10 03:16 . 2007-10-10 07:07 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2009-12-10 03:16 . 2007-10-10 07:07 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2009-12-10 03:16 . 2007-10-10 07:07 186918 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2009-12-10 02:25 . 2007-02-19 22:58 -------- d-----w- c:\documents and settings\All Users\Application Data\CA
2009-12-09 02:54 . 2006-11-09 21:15 -------- d-----w- c:\program files\Java
2009-12-09 02:12 . 2006-11-09 21:26 -------- d-----w- c:\program files\McAfee
2009-12-09 02:12 . 2006-11-09 21:26 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-08 19:06 . 2008-02-19 18:42 -------- d-----w- c:\documents and settings\Dennis\Application Data\U3
2009-12-08 01:03 . 2006-11-09 20:55 246784 ----a-w- c:\windows\system32\drivers\iastor.sys
2009-12-02 18:45 . 2007-05-23 23:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-12-02 01:13 . 2006-11-09 21:30 -------- d-----w- c:\program files\Yahoo!
2009-12-02 01:01 . 2007-09-23 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-01 23:22 . 2007-09-23 18:27 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-27 18:32 . 2006-11-24 21:40 90160 ----a-w- c:\documents and settings\Dennis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-26 23:44 . 2008-01-06 19:53 -------- d-----w- c:\program files\Windows Live
2009-11-26 18:20 . 2007-10-05 21:49 -------- d-----w- c:\documents and settings\Dennis\Application Data\Skype
2009-11-25 15:40 . 2007-01-14 00:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-13 00:22 . 2009-11-13 00:22 1961720 ----a-w- c:\documents and settings\Dennis\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-10-16 07:03 . 2006-11-09 21:30 -------- d-----w- c:\program files\Microsoft Works
2009-09-11 14:18 . 2005-08-16 10:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2007-02-05 22:41 . 2007-02-05 22:40 1128960 ------w- c:\program files\ehthumbs.db
2006-08-09 17:42 . 2008-05-08 22:19 3198976 ----a-w- c:\program files\ViewSonicregistration.exe
2007-01-19 21:20 . 2007-01-06 16:15 88 --sh--r- c:\windows\system32\9650A842F0.sys
2009-02-21 01:42 . 2007-01-29 02:34 88 --sh--r- c:\windows\system32\A02EC1510F.sys
2009-02-21 01:42 . 2007-01-29 02:34 3140 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-17 389120]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe -1 AudioDrvEmulator"
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup"
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe -start"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime"
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl"
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"CTHelper"="CTHELPER.EXE" [2005-11-08 16384]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 18944]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-11-09 169984]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-11 406016]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-11-07 122940]
"PMX Daemon"="ICO.EXE" [2007-03-08 49152]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-05 707360]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-07-30 177392]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-07-31 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-07-31 259312]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Image Transfer.lnk - c:\program files\Sony Corporation\Image Transfer\SonyTray.exe [2007-5-13 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-8-3 394856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 18:30 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
c:\program files\ATI Technologies\ATI.ACE\cli.exe runtime -Delay
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2007-11-15 14:24 16384 ----a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 6:08 PM 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 6:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 6:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 6:08 PM 115216]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11/26/2009 6:44 PM 54752]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 6:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 6:08 PM 66576]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/4/2007 8:23 AM 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 8:39 AM 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [6/24/2008 6:10 PM 281104]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 6:08 PM 88816]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://my.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
- - - - ORPHANS REMOVED - - - -
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2726737829-1817024321-2020694268-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\UmxWnp.Dll
- - - - - - - > 'explorer.exe'(1744)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\windows\SYSTEM32\CTXFISPI.EXE
c:\program files\Creative\Shared Files\Module Loader\DLLML.exe
c:\program files\Common Files\InstallShield\UpdateService\issch.exe
c:\program files\QuickTime\qttask.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
c:\windows\system32\ICO.EXE
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
.
**************************************************************************
.
Completion time: 2009-12-09 22:26:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-10 03:26
Pre-Run: 186,177,236,992 bytes free
Post-Run: 186,727,440,384 bytes free
- - End Of File - - DB850B8F4FDEAAAD1E7A43F4129CEA38
Thanks
West7948
15 Posts
0
December 10th, 2009 07:00
Hello 1972vet. Since my last post, I was successful in removing the CA personal firewall. Would you want me to rerun combofix or is the log I posted last night with the noted exceptions ok?
Thanks
West7948
15 Posts
0
December 10th, 2009 08:00
Everything appears to have gone smoothly this time. I went to Control Panel -> Add/Remove and found no "Viewpoint" in the list. While the Combofix was running it appeared that it found/deleted Viewpoint under Program files(?). I'm guess it'll be in this report. Look forward to next step. Thanks
ComboFix 09-12-09.04 - Dennis 12/10/2009 11:36:47.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2565 [GMT -5:00]
Running from: c:\documents and settings\Dennis\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dennis\Desktop\CFScript.txt
FILE ::
"c:\windows\system32\9650A842F0.sys"
"c:\windows\system32\A02EC1510F.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\McAfee
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Accounts.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Configuration.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Filters.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Friends.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Logs\Complaints.log
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Logs\Filtering.log
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Logs\System.log
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\MskDetct.dat
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Templates\Templates.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\1\Filters.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\1\Friends.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Back\1\F0000000001.fld
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Back\1\F0000000002.fld
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Back\1\F0000000003.fld
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Back\1\MessageStore.mss
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Filters.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Friends.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\F0000000001.fld
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\F0000000002.fld
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\F0000000003.fld
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000685.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000686.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000687.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000688.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000689.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000690.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000691.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000692.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000693.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000694.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000695.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000696.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000697.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000698.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000699.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000700.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000701.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000702.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000703.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000704.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000705.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000706.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000707.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000708.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000709.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000710.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000711.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000712.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000713.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000714.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000715.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000716.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000717.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000718.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000719.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000720.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000721.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000722.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000723.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000724.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000725.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000726.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000727.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000728.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000729.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000730.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000731.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000732.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000733.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000734.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000735.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000736.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000737.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000738.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000739.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000740.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000741.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000742.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000743.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000744.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000745.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000746.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000747.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000748.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000749.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000750.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000751.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000752.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000753.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000754.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000755.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000756.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000757.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000758.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000759.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000760.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000761.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000762.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000763.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000764.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000765.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000766.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000767.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000768.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000769.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000770.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000771.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000772.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000773.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000774.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000775.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000776.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000777.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000778.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000779.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000780.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000781.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000782.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000783.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000784.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000785.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000786.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000787.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000788.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000789.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000790.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000791.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000792.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000793.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000794.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000795.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000796.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\M0000000797.eml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Front\1\MessageStore.mss
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Nsb-iso-8859-1.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Nsb-iso-8859-15.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Nsb-iso-8859-2.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Nsb-Other.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Nsb-utf-8.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Nsh.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Sb-iso-8859-1.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Sb-iso-8859-15.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Sb-iso-8859-2.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Sb-Other.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Sb-utf-8.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\2\Sh.dct
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\3\Filters.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\3\Friends.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\4\Filters.xml
c:\documents and settings\All Users\Application Data\McAfee\SpamKiller\Users\4\Friends.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\ENGINE\Config\engine_offline.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\ENGINE\registration.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\McContentDB.dat
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\McContentDB.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\Config\supportability_offline.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\Config\supportability_online.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\mvt_sup.sta
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\results\1\result.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\results\1\uploadstatus.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\AS10.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\AS10_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\AS11.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\AS11_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\AS9.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\AS9_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\ASD3.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\ASE85.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\CMAM350.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\CMAU350.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\config.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\connectivity_test.txt
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\difftemplate.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\ePO360.XML
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\ePO361.XML
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\ePO400.XML
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\epo450.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\FEC40.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\FS.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\FS65.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\GSD553.XML
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\GSD653.XML
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\GSD753.XML
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\GSE60.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\GSE60x64.XML
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\GSE70.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\GSE70x64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\HIPC6.0.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\HIPC7.0.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\HIPS6.0.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\HIPS7.0.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\IE7PreApprovedKeys.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\Initialize.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\InstallationCheck.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\KBConsumerProduct.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\KBCorporateProduct.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MAM40.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\mam45.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MAS1_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MAS2_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MAT1.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MAU40.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\mbk_sapphire.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MBK1.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MDFW80_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MDFW85_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\mfp1.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MHN1.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MHN3.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPC11.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPC12.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPE1.0.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPF10.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPF11.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPF8.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPF9.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPFP7_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPS10.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPS10_AOL.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPS8.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MPS9.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MQS10.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\msc10_32.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\msc10_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC5.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC6_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC6_XP_SP2.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC7.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC7_2K.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC7_2K_2.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC7_DellVista.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC7_Vista.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC7_Vista_2.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC7_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC7_XP_2.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC8_2k.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC8_Vista.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC8_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC81_2k.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\msc81_vista.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\msc81_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC9_2k.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC9_Vista_32.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC9_Vista_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSC9_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\msdw_64_75.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\msdw_75.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSK7.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSK7_1.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MSK8.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\msse70.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\msse70_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MVS350_VS.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MVS400_PF.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MVS400_VS.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MVS450_PF.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MVS470_VS.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MVS490_VS.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MVT_DEVIATION_MAP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MVT_KNOWLEDGE_BASE.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MWL2.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\MWL2_2.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\PAA5.0.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\PAA5.0_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\PAA5.1.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\PAA5.1_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\paa5_2.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\paa5_2_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\plugin.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\portal.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\PP111.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\PP150.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\prehealthcheck.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\prehealthcheck_fornormal.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\Prerequisite.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\ProdDetect.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\sc5.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SiteAdvisor.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SiteAdvisor_25.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SiteAdvisor_26.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SiteAdvisor_28.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\siteadvisor_30.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SiteAdvisor_assurant.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SKD521.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SKD621.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SKD721.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SKE21.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SMD7.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SMD7_P1.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\SupportedProducts.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\supporturl.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\tps500_agent.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\tps500_bp.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\tps500_pf.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\tps500_vs32.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\tps500_vs64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VS_8_2k.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VS10_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VS11.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\vs12.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\vs12_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\vs13.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\vs13_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\vs14.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VS14_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VSC451.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VSC451_xp.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VSE71_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VSE80_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VSE80_2K_XP_13.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VSE85_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VSE85_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\VSE87_2K_XP.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\vse87_64.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\WSMTP2K.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XSL\Result.xsl
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\POLICY\Config\SUPPORTABILITY_Offline.xml
c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\POLICY\Policies.xml
c:\documents and settings\All Users\Application Data\Viewpoint
C:\LOG.TXT
c:\program files\McAfee
c:\program files\McAfee\SpamKiller\borlndmm.dll
c:\program files\McAfee\SpamKiller\mcapfbho.dat
c:\program files\McAfee\SpamKiller\MSKColors.dat
c:\program files\McAfee\SpamKiller\MSKDetct.exe
c:\program files\McAfee\SpamKiller\MSKFilte.inf
c:\program files\McAfee\SpamKiller\MSKRescs.dll
c:\program files\Viewpoint
c:\windows\system32\9650A842F0.sys
c:\windows\system32\A02EC1510F.sys
C:\LOG.TXT . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 )))))))))))))))))))))))))))))))
.
2009-12-09 02:36 . 2009-12-09 02:36 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-08 18:45 . 2009-12-08 18:45 -------- d--h--w- c:\windows\PIF
2009-12-05 02:04 . 2009-12-05 02:04 -------- d-----w- c:\program files\Trend Micro
2009-12-02 03:17 . 2009-12-02 03:19 -------- d-----w- c:\program files\Windows Live Safety Center
2009-12-02 01:49 . 2009-12-02 01:49 -------- d-----w- c:\documents and settings\Dennis\Local Settings\Application Data\Threat Expert
2009-12-02 01:26 . 2009-12-02 01:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-02 01:13 . 2009-12-02 01:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-12-02 01:13 . 2009-12-02 01:13 -------- d-----w- c:\documents and settings\Dennis\Application Data\Yahoo!
2009-12-02 01:13 . 2009-12-02 01:14 -------- d-----w- c:\program files\CCleaner
2009-11-30 18:45 . 2009-12-10 15:17 -------- d-----w- c:\documents and settings\Kathy\Tracing
2009-11-27 18:33 . 2009-11-27 18:33 -------- d-----w- c:\documents and settings\Dennis\Tracing
2009-11-26 23:44 . 2009-11-28 08:32 -------- d-----w- c:\program files\Microsoft Silverlight
2009-11-26 23:44 . 2009-08-06 03:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-11-26 23:43 . 2009-11-26 23:43 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-11-26 23:42 . 2006-11-29 18:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-11-26 23:41 . 2009-11-26 23:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-26 23:39 . 2009-11-26 23:39 -------- d-----w- c:\program files\Microsoft
2009-11-26 23:38 . 2009-11-26 23:38 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-26 18:13 . 2009-11-26 18:13 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-10 15:15 . 2007-02-19 22:58 -------- d-----w- c:\documents and settings\All Users\Application Data\CA
2009-12-10 15:15 . 2007-02-19 22:58 -------- d-----w- c:\program files\CA
2009-12-09 02:54 . 2006-11-09 21:15 -------- d-----w- c:\program files\Java
2009-12-08 19:06 . 2008-02-19 18:42 -------- d-----w- c:\documents and settings\Dennis\Application Data\U3
2009-12-08 01:03 . 2006-11-09 20:55 246784 ----a-w- c:\windows\system32\drivers\iastor.sys
2009-12-02 01:13 . 2006-11-09 21:30 -------- d-----w- c:\program files\Yahoo!
2009-12-02 01:01 . 2007-09-23 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-01 23:22 . 2007-09-23 18:27 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-27 18:32 . 2006-11-24 21:40 90160 ----a-w- c:\documents and settings\Dennis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-26 23:44 . 2008-01-06 19:53 -------- d-----w- c:\program files\Windows Live
2009-11-26 18:20 . 2007-10-05 21:49 -------- d-----w- c:\documents and settings\Dennis\Application Data\Skype
2009-11-25 15:40 . 2007-01-14 00:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-13 00:22 . 2009-11-13 00:22 1961720 ----a-w- c:\documents and settings\Dennis\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-10-29 07:46 . 2005-08-16 10:18 832512 ----a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2005-08-16 10:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2005-08-16 10:18 17408 ----a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2005-08-16 10:18 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2005-08-16 10:18 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 05:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-16 07:03 . 2006-11-09 21:30 -------- d-----w- c:\program files\Microsoft Works
2009-10-13 10:30 . 2005-08-16 10:18 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2005-08-16 10:18 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2005-08-16 10:18 79872 ----a-w- c:\windows\system32\raschap.dll
2007-02-05 22:41 . 2007-02-05 22:40 1128960 ------w- c:\program files\ehthumbs.db
2006-08-09 17:42 . 2008-05-08 22:19 3198976 ----a-w- c:\program files\ViewSonicregistration.exe
2009-02-21 01:42 . 2007-01-29 02:34 3140 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-17 389120]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe -1 AudioDrvEmulator"
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup"
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe -start"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime"
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"CTHelper"="CTHELPER.EXE" [2005-11-08 16384]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 18944]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-11-09 169984]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-11 406016]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-11-07 122940]
"PMX Daemon"="ICO.EXE" [2007-03-08 49152]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-05 707360]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Image Transfer.lnk - c:\program files\Sony Corporation\Image Transfer\SonyTray.exe [2007-5-13 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-8-3 394856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
c:\program files\ATI Technologies\ATI.ACE\cli.exe runtime -Delay
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2007-11-15 14:24 16384 ----a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11/26/2009 6:44 PM 54752]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://my.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2726737829-1817024321-2020694268-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4012)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\Creative\Shared Files\Module Loader\DLLML.exe
c:\windows\SYSTEM32\CTXFISPI.EXE
c:\program files\Common Files\InstallShield\UpdateService\issch.exe
c:\program files\QuickTime\qttask.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\windows\system32\ICO.EXE
c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
c:\windows\system32\wscript.exe
.
**************************************************************************
.
Completion time: 2009-12-10 11:53:34 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-10 16:53
ComboFix2.txt 2009-12-10 03:26
Pre-Run: 186,609,504,256 bytes free
Post-Run: 186,581,954,560 bytes free
- - End Of File - - A42ADB6BE1587D3AE74F4B5A7F4F115A
1972vet
3.3K Posts
0
December 10th, 2009 08:00
Look for and uninstall the following software if present:
ViewPoint View Manager
ViewPoint Toolbar
ViewPoint Media Player
ViewPoint View Service
...basically, anything with "ViewPoint" as part of it's name...Click Remove for each one of those located and reboot the computer when finished uninstalling.
Please open a blank Notepad by clicking start-->run
Then, in the run box type Notepad.exe and click "OK".
Copy the below text in Bold and paste it into the blank Notepad. Save it as CFScript.txt...Change the "Save as type" to All Files and save it to your desktop. Now drag the text document over to your Combofix.exe
Combofix will run again automatically. Please post back the new log that will be generated. Thanks!
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
KILLALL::
File::
c:\windows\system32\9650A842F0.sys
c:\windows\system32\A02EC1510F.sys
Folder::
c:\program files\Viewpoint
c:\program files\McAfee
c:\documents and settings\All Users\Application Data\McAfee
c:\documents and settings\All Users\Application Data\Viewpoint
Driver::
9650A842F0
A02EC1510F
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSKDetectorExe"=-