Here are the logs for Combofix, Avenger, HJT, Lop S&D, DDS, and the zipped attach.txt.
--------------------------------------------------------------------------------------------------------------------
ComboFix 09-02-01.01 - XOXOX 2009-02-01 15:41:07.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2558.2048 [GMT -8:00]
Running from: c:\documents and settings\XOXOX\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\TDSSorvd.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2009-01-02 to 2009-02-02 )))))))))))))))))))))))))))))))
.
2009-02-01 14:02 . 2009-02-01 14:02 <DIR> d-------- c:\program files\CCleaner
2009-02-01 12:10 . 2009-02-01 15:36 <DIR> d-------- C:\ComboFix
2009-02-01 03:08 . 2009-02-01 03:08 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-02-01 03:02 . 2009-02-01 11:43 <DIR> d-------- c:\program files\NOS
2009-02-01 03:02 . 2009-02-01 11:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-01-31 21:03 . 2009-01-31 21:03 250 --a------ c:\windows\gmer.ini
2009-01-28 16:41 . 2009-01-28 16:41 552 --a------ c:\windows\system32\d3d8caps.dat
2009-01-28 01:30 . 2009-01-28 01:30 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-01-27 21:59 . 2009-01-28 00:30 <DIR> d--hs---- c:\windows\system32\twain32
2009-01-27 21:58 . 2009-01-27 21:58 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-27 21:58 . 2009-01-27 21:58 1,409 --a------ c:\windows\QTFont.for
2009-01-21 20:21 . 2009-01-21 20:21 <DIR> d-------- c:\documents and settings\XOXOX\Application Data\Playrix Entertainment
2009-01-21 20:18 . 2009-01-21 20:18 <DIR> d-------- c:\program files\Playrix Entertainment
2009-01-11 00:10 . 2009-01-23 20:46 <DIR> d-------- c:\documents and settings\XOXOX\Application Data\Home Sweet Home
2009-01-10 23:58 . 2009-01-26 00:09 <DIR> d-------- c:\program files\Gamenext
2009-01-05 18:20 . 2009-01-05 18:25 <DIR> d-------- c:\program files\Dairy Queen Tycoon
2009-01-05 18:20 . 2009-01-18 19:52 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-01-05 14:20 . 2009-01-05 14:20 <DIR> d-------- c:\documents and settings\XOXOX\Application Data\GameInvest
2009-01-05 14:08 . 2009-01-05 14:11 <DIR> d-------- c:\program files\Hospital Hustle
2009-01-05 14:08 . 2009-01-05 14:08 <DIR> d-------- c:\documents and settings\XOXOX\Application Data\SpinTop
2009-01-05 11:02 . 2009-01-05 11:02 <DIR> d-------- c:\documents and settings\XOXOX\Application Data\World-LooM
2009-01-05 11:01 . 2009-01-05 11:01 <DIR> d-------- c:\program files\Fix-it-up - Kates Adventure
2009-01-05 03:16 . 2009-01-05 03:16 0 --a------ c:\windows\Curses-WT.INI
2009-01-04 21:23 . 2009-01-04 21:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\WildTangent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-01 11:07 --------- d-----w c:\program files\Common Files\Adobe
2009-02-01 11:03 --------- d-----w c:\documents and settings\XOXOX\Application Data\AdobeUM
2009-02-01 02:07 --------- d-----w c:\program files\NewsReactor
2009-01-30 09:23 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-30 06:41 98,304 ----a-w c:\windows\DUMP8c71.tmp
2009-01-26 06:23 --------- d-----w c:\documents and settings\XOXOX\Application Data\Ahead
2009-01-15 00:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-15 00:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-05 18:15 --------- d-----w c:\program files\Depths Of Peril
2009-01-05 18:01 --------- d-----w c:\program files\Cooking Academy
2008-12-29 01:51 --------- d-----w c:\program files\Cooking Dash
2008-12-29 01:51 --------- d-----w c:\documents and settings\XOXOX\Application Data\PlayFirst
2008-12-29 01:51 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-18 22:03 --------- d-----w c:\program files\EA GAMES
2008-12-15 03:27 --------- d-----w c:\documents and settings\XOXOX\Application Data\COREL
2008-12-14 17:55 --------- d-----w c:\documents and settings\XOXOX\Application Data\Malwarebytes
2008-12-14 17:54 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-14 10:07 --------- d-----w c:\program files\Windows Live Safety Center
2008-12-14 08:24 --------- d-----w c:\documents and settings\Administrator\Application Data\Lavasoft
2008-12-13 23:38 --------- d-----w c:\program files\MSECache
2008-12-12 08:23 --------- d-----w c:\program files\taged05a
2008-12-12 08:07 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-12 08:00 --------- d-----w c:\documents and settings\XOXOX\Application Data\SanDisk
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2007-12-15 22:58 72,520 -c--a-w c:\documents and settings\XOXOX\Application Data\GDIPFONTCACHEV1.DAT
2007-12-18 07:39 168 --sh--r c:\windows\system32\
0D6536F230.sys
2006-08-29 18:15 56 --sh--r c:\windows\system32\30F236650D.sys
2008-08-20 05:34 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008081920080820\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="c:\documents and settings\XOXOX\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2008-12-12 79872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2004-11-22 307200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2008-07-01 25214]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-07-03 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2004-12-14 01:12 483328 c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 16:52 50736 c:\program files\Common Files\AOL\1170062470\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
--------- 2005-10-11 18:25 1961984 c:\program files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2006-07-03 07:22 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Railroads!\\Railroads.exe"=
"c:\\Program Files\\Common Files\\AOL\\1170062470\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13364:UDP"= 13364:UDP:Print Server Utility
"13107:UDP"= 13107:UDP:Print Server Utility
"69:UDP"= 69:UDP:Print Server Utility
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2008-02-24 2944]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2008-02-24 60416]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [2008-02-24 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [2008-02-24 10368]
.
Contents of the 'Scheduled Tasks' folder
2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2009-02-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-dla - c:\windows\system32\dla\tfswctrl.exe
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-Norton Ghost 10.0 - c:\program files\Norton Ghost\Agent\GhostTray.exe
HKLM-Run-VSOCheckTask - c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe
HKLM-Run-OASClnt - c:\program files\McAfee.com\VSO\oasclnt.exe
HKLM-Run-MSKDetectorExe - c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
HKLM-Run-MSKAGENTEXE - c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe
HKLM-Run-VirusScan Online - c:\program files\McAfee.com\VSO\mcvsshld.exe
HKLM-Run-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
FF - ProfilePath - c:\documents and settings\XOXOX\Application Data\Mozilla\Firefox\Profiles\9c7rnnr2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\NpPopup.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-01 16:22:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3625204808-2033701250-488205976-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\SigmaTel*STacGUI]
"Chksum"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\wanmpsvc.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2009-02-01 16:29:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-02 00:29:04
Pre-Run: 6,202,474,496 bytes free
Post-Run: 6,110,027,776 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
243 --- E O F --- 2009-01-14 05:25:51
-----------------------------------------------------------------------------------------------------------------------------------
Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSmqlt.sys" not found!
Deletion of driver "TDSSmqlt.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\tdss" not found!
Deletion of driver "tdss" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\tdssserv" not found!
Deletion of driver "tdssserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSserv.SYS" not found!
Deletion of driver "TDSSserv.SYS" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\Service_TDSSSERV.SYS" not found!
Deletion of driver "Service_TDSSSERV.SYS" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\Legacy_TDSSSERV.SYS" not found!
Deletion of driver "Legacy_TDSSSERV.SYS" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\msqpdxserv.sys" not found!
Deletion of driver "msqpdxserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\msqpdxserv" not found!
Deletion of driver "msqpdxserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\brsvc01a.exe" not found!
Deletion of file "C:\WINDOWS\system32\brsvc01a.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\brss01a.exe" not found!
Deletion of file "C:\WINDOWS\system32\brss01a.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\SYSTEM32\TDSSixgp.dll" not found!
Deletion of file "C:\WINDOWS\SYSTEM32\TDSSixgp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\SYSTEM32\TDSSproc.log" not found!
Deletion of file "C:\WINDOWS\SYSTEM32\TDSSproc.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\SYSTEM32\TDSSwkod.log" not found!
Deletion of file "C:\WINDOWS\SYSTEM32\TDSSwkod.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: could not open file "C:\Documents and Settings\Chelsea\Local Settings\Temp\TDSSe8db.tmp"
Deletion of file "C:\Documents and Settings\Chelsea\Local Settings\Temp\TDSSe8db.tmp" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
Error: file "c:\windows\system32\drivers\msqpdxserv.sys" not found!
Deletion of file "c:\windows\system32\drivers\msqpdxserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\resycled" not found!
Deletion of file "C:\resycled" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: could not open file "D:\resycled"
Deletion of file "D:\resycled" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
Error: could not open file "e:\resycled"
Deletion of file "e:\resycled" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
Error: could not open file "f:\resycled"
Deletion of file "f:\resycled" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
Error: could not open file "g:\resycled"
Deletion of file "g:\resycled" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
Error: file "c:\windows\system32\TDSSweat.dat" not found!
Deletion of file "c:\windows\system32\TDSSweat.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\drivers\TDSSmqlt.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\TDSSmqlt.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\windows\system32\drivers\tdssserv.sys" not found!
Deletion of file "C:\windows\system32\drivers\tdssserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\drivers\TDSSmact.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\TDSSmact.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSfpmp.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSSfpmp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSwpyd.dat" not found!
Deletion of file "C:\WINDOWS\system32\TDSSwpyd.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSStkdv.log" not found!
Deletion of file "C:\WINDOWS\system32\TDSStkdv.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSotxb.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSSotxb.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSScrrn.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSScrrn.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSbvqh.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSSbvqh.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSjnmx.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSSjnmx.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSShrxr.dll" not found!
Deletion of file "c:\windows\system32\TDSShrxr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSkkbi.log" not found!
Deletion of file "c:\windows\system32\TDSSkkbi.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSlrvd.dat" not found!
Deletion of file "c:\windows\system32\TDSSlrvd.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSlxwp.dll" not found!
Deletion of file "c:\windows\system32\TDSSlxwp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSnmxh.log" not found!
Deletion of file "c:\windows\system32\TDSSnmxh.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSoiqt.dll" not found!
Deletion of file "c:\windows\system32\TDSSoiqt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSrhyp.log" not found!
Deletion of file "c:\windows\system32\TDSSrhyp.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSrtqp.dll" not found!
Deletion of file "c:\windows\system32\TDSSrtqp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSsihc.dll" not found!
Deletion of file "c:\windows\system32\TDSSsihc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSxfum.dll" not found!
Deletion of file "c:\windows\system32\TDSSxfum.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSmtve.dat" not found!
Deletion of file "c:\windows\system32\TDSSmtve.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSnirj.dat" not found!
Deletion of file "c:\windows\system32\TDSSnirj.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\drivers\TDSSmqlt.sys" not found!
Deletion of file "c:\windows\system32\drivers\TDSSmqlt.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSoiqh.dll" not found!
Deletion of file "c:\windows\system32\TDSSoiqh.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSorvd.dat" not found!
Deletion of file "c:\windows\system32\TDSSorvd.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSShrsr.dll" not found!
Deletion of file "c:\windows\system32\TDSShrsr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSriqp.dll" not found!
Deletion of file "c:\windows\system32\TDSSriqp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSxfum.dll" not found!
Deletion of file "c:\windows\system32\TDSSxfum.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSlxwp.dll" not found!
Deletion of file "c:\windows\system32\TDSSlxwp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSnmxh.log" not found!
Deletion of file "c:\windows\system32\TDSSnmxh.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSsihc.dll" not found!
Deletion of file "c:\windows\system32\TDSSsihc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSrhyp.log" not found!
Deletion of file "c:\windows\system32\TDSSrhyp.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\TDSSkkdu.log" not found!
Deletion of file "c:\windows\system32\TDSSkkdu.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDSSserv.sys" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDSSserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tdssserv" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tdssserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdssserv" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdssserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\tdssserv.sys" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\tdssserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\tdssserv.sys" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\tdssserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdssserv" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdssserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\tdss" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\tdss" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Completed script processing.
*******************
Finished! Terminate.
----------------------------------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:47:32 PM, on 2/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\XOXOX\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\hijackthis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [SansaDispatch] C:\Documents and Settings\XOXOX\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_0
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmat...enWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: PackageCab -
http://ak.imgag.com/...tall/AxCtp2.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 9359 bytes
-------------------------------------------------------------------------------------------------------------------------------
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Genuine Intel® CPU T2400 @ 1.83GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A14
USER : XOXOX ( Administrator )
BOOT : Normal boot
Antivirus : McAfee VirusScan (Not Activated)
Firewall : McAfee Personal Firewall (Not Activated)
C:\ (Local Disk) - NTFS - Total:51 Go (Free:5 Go)
E:\ (CD or DVD)
G:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Sun 02/01/2009|16:44 )
--------------------\\ Listing folders in APPLIC~1
[01/28/2009|11:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
[07/03/2006|07:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ATI
[08/10/2004|10:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[07/04/2007|12:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Intel
[12/14/2008|12:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lavasoft
[01/28/2009|01:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Media Player Classic
[01/28/2009|01:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[01/28/2009|01:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Mozilla
[07/03/2006|07:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun
[07/03/2006|07:25] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Symantec
[02/01/2009|03:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[03/09/2008|04:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Ahead
[01/29/2007|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL
[05/12/2007|07:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CanonBJ
[12/17/2007|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Corel
[07/03/2006|07:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CyberLink
[02/27/2008|11:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Dell
[09/15/2008|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FarmFrenzy2
[05/13/2008|06:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FLEXnet
[10/03/2008|10:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FreshGames
[05/21/2008|02:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Fugazo
[05/21/2008|04:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Go Go Gourmet
[07/03/2006|07:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> GTek
[03/30/2008|08:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> HipSoft
[07/03/2006|07:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[07/04/2007|12:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intel
[12/14/2008|09:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
[02/13/2007|02:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee
[02/13/2007|02:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com
[09/17/2008|08:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[06/22/2007|12:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft Help
[10/03/2008|06:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MythPeople
[02/01/2009|11:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NOS
[09/17/2008|06:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Oberon Games
[12/28/2008|05:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PlayFirst
[07/22/2006|01:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> QuickTime
[12/21/2007|09:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> River Past G5
[12/22/2007|12:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Sandlot Games
[08/10/2004|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SBSI
[01/23/2007|10:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Sonic
[01/04/2008|07:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SupportSoft
[07/09/2006|09:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec
[01/18/2009|07:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP
[12/23/2006|05:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Trymedia
[01/22/2007|04:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Viewpoint
[01/04/2009|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WildTangent
[07/07/2006|12:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[07/03/2006|07:35] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ATI
[08/10/2004|10:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[07/04/2007|12:24] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Intel
[07/03/2006|07:11] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[07/03/2006|07:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sun
[07/03/2006|07:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Symantec
[08/23/2006|12:04] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Macromedia
[02/06/2007|12:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[09/18/2006|10:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Mozilla
[01/23/2007|10:58] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Roxio
[09/18/2006|10:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Talkback
[07/04/2007|12:24] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Intel
[08/10/2004|09:57] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
[10/07/2008|07:35] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Adobe
[02/01/2009|03:03] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> AdobeUM
[01/25/2009|10:23] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Ahead
[01/23/2007|12:17] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> AOL
[07/03/2006|07:35] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> ATI
[12/14/2008|07:27] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> COREL
[07/12/2006|10:58] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Corel Photo Album
[07/24/2006|08:02] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> CyberLink
[01/05/2009|02:20] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> GameInvest
[04/10/2007|12:05] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Gtek
[09/14/2006|01:35] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Help
[01/23/2009|08:46] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Home Sweet Home
[08/10/2004|10:08] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Identities
[12/23/2006|05:05] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> InstallShield
[07/04/2007|12:23] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Intel
[07/09/2006|11:40] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Lavasoft
[07/15/2006|01:26] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Leadertech
[08/26/2006|01:30] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Macromedia
[12/14/2008|09:55] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Malwarebytes
[08/05/2006|08:28] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> McAfee
[08/09/2006|01:46] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Media Player Classic
[09/17/2008|08:47] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Microsoft
[07/15/2007|10:09] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Microsoft Games
[08/27/2008|07:54] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Mozilla
[07/27/2006|03:54] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> My Games
[09/17/2008|06:57] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Oberon Games
[10/01/2006|12:31] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Pegasys Inc
[12/28/2008|05:51] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> PlayFirst
[01/21/2009|08:21] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Playrix Entertainment
[03/27/2008|02:13] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> RadLight Company
[07/20/2006|09:20] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Real
[12/21/2007|09:02] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> River Past G5
[12/12/2008|12:00] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> SanDisk
[11/30/2007|12:26] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Snapfish
[07/15/2006|01:26] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Sonic
[01/05/2009|02:08] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> SpinTop
[07/03/2006|07:09] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Sun
[07/03/2006|07:25] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Symantec
[08/19/2006|02:50] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Talkback
[01/22/2007|04:12] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> Viewpoint
[01/05/2009|11:02] C:\DOCUME~1\XOXOX\APPLIC~1\<DIR> World-LooM
--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[10/15/2008 12:07 AM][--a------] C:\WINDOWS\tasks\McDefragTask.job
[02/01/2009 01:10 AM][--a------] C:\WINDOWS\tasks\McQcTask.job
[02/01/2009 04:36 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 02:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing Folders in C:\Program Files
[11/21/2006|09:15] C:\Program Files\<DIR> 2K Games
[02/01/2009|03:08] C:\Program Files\<DIR> Adobe
[02/12/2007|02:21] C:\Program Files\<DIR> Ahead
[07/09/2006|10:47] C:\Program Files\<DIR> Alcohol Soft
[10/24/2007|12:10] C:\Program Files\<DIR> America Online 9.0
[06/05/2007|11:38] C:\Program Files\<DIR> AOL
[07/03/2006|07:22] C:\Program Files\<DIR> AOL Companion
[11/21/2006|03:11] C:\Program Files\<DIR> ATI Technologies
[06/18/2008|08:17] C:\Program Files\<DIR> AVIcodec
[07/03/2006|07:32] C:\Program Files\<DIR> BAE
[07/03/2006|07:15] C:\Program Files\<DIR> Broadcom
[05/12/2007|07:39] C:\Program Files\<DIR> CanonBJ
[02/01/2009|02:02] C:\Program Files\<DIR> CCleaner
[02/01/2009|03:41] C:\Program Files\<DIR> Common Files
[08/10/2004|10:02] C:\Program Files\<DIR> ComPlus Applications
[07/03/2006|07:12] C:\Program Files\<DIR> CONEXANT
[01/05/2009|10:01] C:\Program Files\<DIR> Cooking Academy
[12/28/2008|05:51] C:\Program Files\<DIR> Cooking Dash
[12/17/2007|11:35] C:\Program Files\<DIR> Corel
[07/04/2007|06:24] C:\Program Files\<DIR> CyberLink
[06/10/2007|10:03] C:\Program Files\<DIR> DAEMON Tools
[01/05/2009|06:25] C:\Program Files\<DIR> Dairy Queen Tycoon
[07/03/2006|07:36] C:\Program Files\<DIR> Dell
[01/04/2008|07:23] C:\Program Files\<DIR> Dell Support Center
[04/09/2007|11:36] C:\Program Files\<DIR> DellSupport
[01/05/2009|10:15] C:\Program Files\<DIR> Depths Of Peril
[10/16/2008|12:40] C:\Program Files\<DIR> Diablo II
[07/03/2006|07:17] C:\Program Files\<DIR> Digital Line Detect
[07/13/2006|12:56] C:\Program Files\<DIR> DivX
[08/09/2006|02:54] C:\Program Files\<DIR> DVD Decrypter
[02/21/2007|11:58] C:\Program Files\<DIR> DVDlabPro2
[12/18/2008|02:03] C:\Program Files\<DIR> EA GAMES
[06/18/2008|08:21] C:\Program Files\<DIR> ffdshow
[09/14/2006|08:02] C:\Program Files\<DIR> File Recover
[07/09/2006|12:27] C:\Program Files\<DIR> Firaxis Games
[06/28/2008|02:11] C:\Program Files\<DIR> Firefly Studios
[01/05/2009|11:01] C:\Program Files\<DIR> Fix-it-up - Kates Adventure
[01/26/2009|12:09] C:\Program Files\<DIR> Gamenext
[02/12/2007|02:25] C:\Program Files\<DIR> GoldEsel
[03/19/2008|11:44] C:\Program Files\<DIR> Hawking PrintServer Utilities
[01/31/2009|08:20] C:\Program Files\<DIR> hijackthis
[01/05/2009|02:11] C:\Program Files\<DIR> Hospital Hustle
[12/12/2008|12:07] C:\Program Files\<DIR> InstallShield Installation Information
[07/04/2007|12:40] C:\Program Files\<DIR> Intel
[07/03/2006|07:11] C:\Program Files\<DIR> Intel, Inc
[12/10/2008|05:41] C:\Program Files\<DIR> Internet Explorer
[07/09/2006|11:40] C:\Program Files\<DIR> Lavasoft
[07/03/2006|07:22] C:\Program Files\<DIR> Learn2.com
[01/30/2009|01:23] C:\Program Files\<DIR> Malwarebytes' Anti-Malware
[09/12/2008|05:46] C:\Program Files\<DIR> McAfee
[02/13/2007|02:19] C:\Program Files\<DIR> McAfee.com
[08/19/2008|08:59] C:\Program Files\<DIR> Messenger
[01/03/2008|10:02] C:\Program Files\<DIR> Microsoft ActiveSync
[08/10/2004|10:04] C:\Program Files\<DIR> microsoft frontpage
[07/15/2007|09:53] C:\Program Files\<DIR> Microsoft Games
[12/13/2008|03:38] C:\Program Files\<DIR> Microsoft Office
[01/03/2008|10:02] C:\Program Files\<DIR> Microsoft Visual Studio
[12/07/2007|09:12] C:\Program Files\<DIR> Microsoft.NET
[04/08/2008|06:41] C:\Program Files\<DIR> Mindscape
[07/03/2006|07:16] C:\Program Files\<DIR> Modem Helper
[08/19/2008|08:54] C:\Program Files\<DIR> Movie Maker
[02/01/2009|04:31] C:\Program Files\<DIR> Mozilla Firefox
[12/13/2008|03:38] C:\Program Files\<DIR> MSECache
[08/10/2004|10:01] C:\Program Files\<DIR> MSN
[08/10/2004|10:01] C:\Program Files\<DIR> MSN Gaming Zone
[11/18/2006|03:01] C:\Program Files\<DIR> MSXML 4.0
[08/25/2006|02:02] C:\Program Files\<DIR> MUSICMATCH
[08/19/2008|08:50] C:\Program Files\<DIR> NetMeeting
[07/03/2006|07:16] C:\Program Files\<DIR> NetWaiting
[01/31/2009|06:07] C:\Program Files\<DIR> NewsReactor
[02/01/2009|11:43] C:\Program Files\<DIR> NOS
[08/19/2008|08:50] C:\Program Files\<DIR> Outlook Express
[10/01/2006|12:31] C:\Program Files\<DIR> Pegasys Inc
[01/21/2009|08:18] C:\Program Files\<DIR> Playrix Entertainment
[07/09/2006|11:27] C:\Program Files\<DIR> PopCap Games
[11/28/2008|01:30] C:\Program Files\<DIR> Quicken
[07/13/2006|12:06] C:\Program Files\<DIR> QuickPar
[08/26/2006|11:13] C:\Program Files\<DIR> QuickSFV
[07/03/2006|07:22] C:\Program Files\<DIR> QuickTime
[03/27/2008|02:13] C:\Program Files\<DIR> RadLight Company
[07/03/2006|07:21] C:\Program Files\<DIR> Real
[03/24/2008|06:58] C:\Program Files\<DIR> ReflexiveArcade
[12/21/2007|09:02] C:\Program Files\<DIR> River Past
[11/01/2007|10:34] C:\Program Files\<DIR> SanDisk
[07/03/2006|07:32] C:\Program Files\<DIR> SearchAssist
[07/03/2006|07:12] C:\Program Files\<DIR> Sigmatel
[11/11/2008|11:22] C:\Program Files\<DIR> Strategy First
[07/03/2006|07:14] C:\Program Files\<DIR> Synaptics
[12/12/2008|12:23] C:\Program Files\<DIR> taged05a
[08/10/2004|10:08] C:\Program Files\<DIR> Uninstall Information
[07/03/2006|07:22] C:\Program Files\<DIR> Viewpoint
[07/03/2006|07:24] C:\Program Files\<DIR> WebCyberCoach
[07/03/2006|07:26] C:\Program Files\<DIR> WildTangent
[05/24/2007|10:37] C:\Program Files\<DIR> Winamp
[12/14/2008|02:07] C:\Program Files\<DIR> Windows Live Safety Center
[06/21/2007|01:43] C:\Program Files\<DIR> Windows Media Connect 2
[08/19/2008|08:50] C:\Program Files\<DIR> Windows Media Player
[08/19/2008|08:50] C:\Program Files\<DIR> Windows NT
[08/10/2004|10:02] C:\Program Files\<DIR> WindowsUpdate
[07/07/2006|01:59] C:\Program Files\<DIR> WinRAR
[08/10/2004|10:04] C:\Program Files\<DIR> xerox
--------------------\\ Listing Folders in C:\Program Files\Common Files
[02/01/2009|03:07] C:\Program Files\Common Files\<DIR> Adobe
[02/01/2009|03:08] C:\Program Files\Common Files\<DIR> Adobe AIR
[02/12/2007|02:13] C:\Program Files\Common Files\<DIR> Ahead
[06/06/2007|03:48] C:\Program Files\Common Files\<DIR> AOL
[07/03/2006|07:22] C:\Program Files\Common Files\<DIR> aolshare
[12/17/2007|11:36] C:\Program Files\Common Files\<DIR> Corel
[08/29/2006|11:16] C:\Program Files\Common Files\<DIR> Designer
[07/03/2006|07:22] C:\Program Files\Common Files\<DIR> InstallShield
[10/24/2006|08:48] C:\Program Files\Common Files\<DIR> Intuit
[01/03/2008|10:02] C:\Program Files\Common Files\<DIR> L&H
[06/19/2008|12:31] C:\Program Files\Common Files\<DIR> McAfee
[12/13/2008|03:38] C:\Program Files\Common Files\<DIR> Microsoft Shared
[08/10/2004|10:02] C:\Program Files\Common Files\<DIR> MSSoap
[07/03/2006|07:21] C:\Program Files\Common Files\<DIR> Nullsoft
[08/10/2004|09:57] C:\Program Files\Common Files\<DIR> ODBC
[10/24/2006|08:49] C:\Program Files\Common Files\<DIR> Palo Alto Software
[07/20/2006|09:14] C:\Program Files\Common Files\<DIR> Real
[12/21/2007|09:02] C:\Program Files\Common Files\<DIR> River Past
[02/09/2007|11:13] C:\Program Files\Common Files\<DIR> Roxio Shared
[08/10/2004|10:02] C:\Program Files\Common Files\<DIR> Services
[02/11/2007|03:18] C:\Program Files\Common Files\<DIR> Sonic Shared
[08/10/2004|09:57] C:\Program Files\Common Files\<DIR> SpeechEngines
[01/04/2008|07:23] C:\Program Files\Common Files\<DIR> supportsoft
[10/24/2006|09:15] C:\Program Files\Common Files\<DIR> SWF Studio
[08/19/2008|08:50] C:\Program Files\Common Files\<DIR> System
[07/20/2006|09:14] C:\Program Files\Common Files\<DIR> xing shared
--------------------\\ Process
( 52 Processes )
... OK !
--------------------\\ Searching with S_Lop
No Lop folder found !
--------------------\\ Searching for Lop Files - Folders
No Lop folder found !
--------------------\\ Searching within the Registry
..... OK !
--------------------\\ Checking the Hosts file
Hosts file CLEAN
--------------------\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-01 16:45:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Searching for other infections
No other infections found !
[F:3][D:1]-> C:\DOCUME~1\XOXOX\LOCALS~1\Temp
[F:2][D:0]-> C:\DOCUME~1\XOXOX\Cookies
[F:2][D:0]-> C:\DOCUME~1\XOXOX\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Sun 02/01/2009|16:46 - Option : [1]
--------------------\\ Scan completed at 16:46:56
---------------------------------------------------------------------------------------------------------------------------------
DDS (Ver_09-02-01.01) - NTFSx86
Run by XOXOX at 16:43:09.31 on Sun 02/01/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2558.2043 [GMT -8:00]
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\XOXOX\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\XOXOX\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [SansaDispatch] c:\documents and settings\XOXOX\application data\sandisk\sansa updater\SansaDispatch.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\acrobat\AdobeUpdateManager.exe AcPro7_0_0
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-100000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmat...enWebRadio.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\XOXOX\applic~1\mozilla\firefox\profiles\9c7rnnr2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\mozilla firefox\plugins\NpPopup.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
============= SERVICES / DRIVERS ===============
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2007-2-13 201320]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-2-13 359248]
R2 McShield;McAfee Real-time Scanner;c:\program files\mcafee\virusscan\Mcshield.exe [2007-2-13 144704]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2007-2-13 79304]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2007-2-13 35240]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2008-2-24 2944]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2008-2-24 60416]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [2008-2-24 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [2008-2-24 10368]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-2-13 33832]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-2-13 40488]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2007-2-13 695624]
=============== Created Last 30 ================
2009-02-01 16:31 <DIR> --d-h--- c:\windows\PIF
2009-02-01 15:37 <DIR> a-dshr-- C:\cmdcons
2009-02-01 15:36 286,720 a------- c:\windows\SWREG.exe
2009-02-01 15:36 98,816 a------- c:\windows\sed.exe
2009-02-01 14:02 <DIR> --d----- c:\program files\CCleaner
2009-02-01 12:10 <DIR> --d----- C:\ComboFix
2009-01-31 21:03 250 a------- c:\windows\gmer.ini
2009-01-28 16:41 552 a------- c:\windows\system32\d3d8caps.dat
2009-01-27 21:59 <DIR> --dsh--- c:\windows\system32\twain32
2009-01-27 21:58 54,156 a---h--- c:\windows\QTFont.qfn
2009-01-27 21:58 1,409 a------- c:\windows\QTFont.for
2009-01-21 20:21 <DIR> --d----- c:\docume~1\XOXOX\applic~1\Playrix Entertainment
2009-01-21 20:18 <DIR> --d----- c:\program files\Playrix Entertainment
2009-01-11 00:10 <DIR> --d----- c:\docume~1\XOXOX\applic~1\Home Sweet Home
2009-01-10 23:58 <DIR> --d----- c:\program files\Gamenext
2009-01-05 18:20 <DIR> --d----- c:\program files\Dairy Queen Tycoon
2009-01-05 14:20 <DIR> --d----- c:\docume~1\XOXOX\applic~1\GameInvest
2009-01-05 14:08 <DIR> --d----- c:\program files\Hospital Hustle
2009-01-05 14:08 <DIR> --d----- c:\docume~1\XOXOX\applic~1\SpinTop
2009-01-05 11:02 <DIR> --d----- c:\docume~1\XOXOX\applic~1\World-LooM
2009-01-05 11:01 <DIR> --d----- c:\program files\Fix-it-up - Kates Adventure
2009-01-05 03:16 0 a------- c:\windows\Curses-WT.INI
2009-01-04 21:23 <DIR> --d----- c:\docume~1\alluse~1\applic~1\WildTangent
==================== Find3M ====================
2009-01-29 22:41 98,304 a------- c:\windows\DUMP8c71.tmp
2009-01-14 16:11 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 16:11 15,504 a------- c:\windows\system32\drivers\mbam.sys
2008-12-14 19:21 2,828 a--sh--- c:\windows\system32\KGyGaAvL.sys
2008-12-14 02:51 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-12 22:40 3,593,216 -------- c:\windows\system32\dllcache\mshtml.dll
2008-12-11 02:57 333,952 a------- c:\windows\system32\drivers\srv.sys
2008-12-11 02:57 333,952 -------- c:\windows\system32\dllcache\srv.sys
2007-12-15 14:58 72,520 ac------ c:\docume~1\XOXOX\applic~1\GDIPFONTCACHEV1.DAT
2007-12-17 23:39 168 ---shr-- c:\windows\system32\0D6536F230.sys
2006-08-29 10:15 56 ---shr-- c:\windows\system32\30F236650D.sys
2008-08-19 21:34 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081920080820\index.dat
============= FINISH: 16:43:45.87 ===============
------------------------------------------------------------------------------------------------------------------------------------