Ok, here are all the logs.
ComboFix log:
ComboFix 09-03-06.02 - Jorge Torres 2009-03-08 18:22:10.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.473 [GMT -4:00]
Running from: c:\documents and settings\Jorge Torres\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jorge Torres\Desktop\CFscript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated)
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
* Created a new restore point
FILE ::
c:\sysprep\PEDrv.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SVRPEDRV
-------\Service_SVRPEDRV
((((((((((((((((((((((((( Files Created from 2009-02-08 to 2009-03-08 )))))))))))))))))))))))))))))))
.
2009-03-07 16:12 . 2001-08-17 14:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-03-07 16:12 . 2001-08-17 14:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-03-07 16:12 . 2008-04-13 15:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-03-07 16:12 . 2008-04-13 15:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-03-07 02:13 . 2009-03-07 02:13 <DIR> d-------- c:\program files\Microsoft ActiveSync
2009-03-05 19:09 . 2009-03-05 19:09 <DIR> d-------- c:\program files\G4box
2009-03-05 18:47 . 2009-03-05 18:47 <DIR> d-------- C:\CFLog
2009-03-05 18:47 . 2009-02-16 20:39 2,736,890 --a------ c:\windows\system32\GameMon.des
2009-03-05 18:45 . 2003-07-17 05:17 5,174 --a------ c:\windows\system32\nppt9x.vxd
2009-03-05 18:45 . 2004-12-31 20:43 4,682 --a------ c:\windows\system32\npptNT2.sys
2009-03-05 18:44 . 2009-03-05 18:44 <DIR> d-------- c:\program files\Common Files\INCA Shared
2009-03-04 16:21 . 2009-03-04 16:21 <DIR> d-------- c:\program files\Crawler
2009-03-01 23:20 . 2009-03-01 23:20 <DIR> d-------- c:\program files\7-Zip
2009-03-01 14:56 . 2009-03-01 15:04 <DIR> d-------- c:\program files\SpywareBlaster
2009-03-01 12:59 . 2009-03-01 12:59 <DIR> d-------- c:\program files\IObit
2009-03-01 12:59 . 2009-03-01 12:59 <DIR> d-------- c:\documents and settings\Jorge Torres\Application Data\IObit
2009-02-28 17:24 . 2009-02-28 17:24 23,600 --a------ c:\windows\system32\drivers\TVICHW32.SYS
2009-02-26 23:56 . 2009-02-26 23:56 <DIR> d-------- c:\program files\HDD Health
2009-02-20 22:14 . 2009-02-20 20:34 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-20 20:34 . 2009-02-20 20:34 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-20 20:32 . 2009-02-20 20:32 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-20 20:31 . 2009-02-20 20:31 <DIR> d-------- c:\program files\Lavasoft
2009-02-20 20:31 . 2009-02-20 20:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-19 13:03 . 2009-02-19 13:03 579,464 --a------ c:\windows\system32\SymNeti.dll
2009-02-19 13:03 . 2009-02-19 13:03 207,240 --a------ c:\windows\system32\SymRedir.dll
2009-02-19 12:31 . 2009-02-19 12:31 184,496 --a------ c:\windows\system32\drivers\symtdi.sys
2009-02-19 12:31 . 2009-02-19 12:31 96,560 --a------ c:\windows\system32\drivers\symfw.sys
2009-02-19 12:31 . 2009-02-19 12:31 41,008 --a------ c:\windows\system32\drivers\symndisv.sys
2009-02-19 12:31 . 2009-02-19 12:31 38,576 --a------ c:\windows\system32\drivers\symids.sys
2009-02-19 12:31 . 2009-02-19 12:31 37,424 --a------ c:\windows\system32\drivers\symndis.sys
2009-02-19 12:31 . 2009-02-19 12:31 31,280 --a------ c:\windows\system32\drivers\SymIM.sys
2009-02-19 12:31 . 2009-02-19 12:31 22,320 --a------ c:\windows\system32\drivers\symredrv.sys
2009-02-19 12:31 . 2009-02-19 12:31 13,616 --a------ c:\windows\system32\drivers\symdns.sys
2009-02-19 12:31 . 2009-02-19 12:31 9,844 --a------ c:\windows\system32\drivers\SymRedir.cat
2009-02-19 12:31 . 2009-02-19 12:31 1,611 --a------ c:\windows\system32\drivers\SymRedir.inf
2009-02-18 11:43 . 2009-02-18 11:45 <DIR> d-------- c:\windows\system32\Adobe
2009-02-13 22:04 . 2009-02-13 22:06 <DIR> d-------- c:\program files\Common Files\PC Tools
2009-02-13 22:04 . 2009-03-04 16:33 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-13 22:04 . 2008-07-28 13:29 160,792 --a------ c:\windows\system32\drivers\pctfw2.sys
2009-02-13 22:04 . 2008-08-25 13:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-02-13 22:04 . 2008-08-25 13:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-02-13 22:04 . 2008-08-25 13:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-02-13 22:04 . 2008-06-02 17:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-02-13 22:03 . 2009-03-04 16:32 <DIR> d-------- c:\program files\Spyware Doctor
2009-02-13 22:03 . 2009-02-13 22:03 <DIR> d-------- c:\documents and settings\Jorge Torres\Application Data\PC Tools
2009-02-13 22:03 . 2009-02-13 22:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2009-02-12 12:20 . 2009-02-12 12:20 <DIR> d-------- c:\program files\Ashampoo
2009-02-12 12:20 . 2009-02-12 12:20 <DIR> d-------- c:\documents and settings\Jorge Torres\Application Data\Ashampoo
2009-02-12 12:20 . 2009-02-12 12:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\ashampoo
2009-02-08 11:23 . 2009-02-13 12:13 <DIR> d-------- c:\program files\KeyScrambler
2009-02-08 11:23 . 2009-01-18 17:24 114,024 --a------ c:\windows\system32\drivers\keyscrambler.sys
2009-02-08 11:03 . 2009-03-03 07:58 <DIR> d-------- c:\program files\PeerGuardian2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-08 22:28 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-08 21:57 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-08 00:47 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-04 03:52 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\WIPE
2009-03-04 03:46 --------- d-----w c:\program files\Common Files\AVSMedia
2009-03-04 03:46 --------- d-----w c:\program files\AVS4YOU
2009-03-04 03:43 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\uTorrent
2009-03-04 01:42 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\U3
2009-03-02 17:05 --------- d-----w c:\program files\Norton SystemWorks Basic Edition
2009-03-01 00:33 --------- d-----w c:\program files\Google
2009-02-28 22:57 --------- d-----w c:\documents and settings\All Users\Application Data\YAHOO
2009-02-28 21:49 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\dvdcss
2009-02-28 17:28 --------- d-----w c:\program files\SUPERAntiSpyware
2009-02-14 05:08 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-12 16:08 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-02-11 23:32 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-11 15:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-08 00:39 --------- d-----w c:\program files\Sandboxie
2009-02-07 15:02 --------- d-----w c:\program files\Alwil Software
2009-02-07 01:20 --------- d-----w c:\program files\Trend Micro
2009-02-05 19:10 --------- d-----w c:\program files\CCleaner
2009-02-05 17:10 --------- d-----w c:\program files\Wipe
2009-02-05 00:12 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-03 16:29 --------- d-----w c:\program files\iTunes
2009-02-03 16:29 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-03 16:28 --------- d-----w c:\program files\QuickTime
2009-02-03 16:28 --------- d-----w c:\program files\iPod
2009-02-03 16:28 --------- d-----w c:\program files\Common Files\Apple
2009-02-03 16:27 --------- d-----w c:\program files\Apple Software Update
2009-02-03 16:27 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-03 16:26 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-01-30 16:51 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\Deskperience
2009-01-30 16:51 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\AVS4YOU
2009-01-30 16:51 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\Apple Computer
2009-01-30 16:51 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\AdobeUM
2009-01-30 16:51 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\acccore
2009-01-15 04:22 --------- d-----w c:\documents and settings\Jorge Torres\Application Data\Malwarebytes
2009-01-15 04:22 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-03-14 21:36 34,744 ----a-w c:\documents and settings\Jorge Torres\Application Data\GDIPFONTCACHEV1.DAT
2007-08-25 03:52 300,400 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-09-10 16:07 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091020080911\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-05_13.07.10.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2008-01-19 16:45:47 2,560 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2009-03-07 06:13:32 2,560 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2008-01-19 16:45:47 34,304 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2009-03-07 06:13:31 34,304 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2008-01-19 16:45:47 8,192 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2009-03-07 06:13:32 8,192 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2008-01-19 16:45:47 3,584 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2009-03-07 06:13:32 3,584 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2008-01-19 16:45:47 16,384 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2009-03-07 06:13:32 16,384 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2008-01-19 16:45:47 22,528 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2009-03-07 06:13:32 22,528 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2008-01-19 16:45:47 45,056 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2009-03-07 06:13:31 45,056 ----a-r c:\windows\Installer\{901B0409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2000-08-31 13:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 12:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2000-08-31 13:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 12:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2009-02-28 19:59:16 64,602 ----a-w c:\windows\system32\perfc009.dat
+ 2009-03-08 15:17:47 64,602 ----a-w c:\windows\system32\perfc009.dat
- 2009-02-28 19:59:16 408,238 ----a-w c:\windows\system32\perfh009.dat
+ 2009-03-08 15:17:47 408,238 ----a-w c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2009-01-05 336896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TFncKy"="c:\program files\TOSHIBA\TOSHIBA Controls\TFncKy.exe" [2005-08-16 188416]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 82009]
"NDSTray.exe"="c:\program files\TOSHIBA\ConfigFree\NDSTray.exe" [2005-11-02 978944]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 122880]
"dla"="c:\windows\system32\dla\DLACTRLW.exe" [2005-10-06 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 151552]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"NSWosCheck"="c:\program files\Norton SystemWorks Basic Edition\osCheck.exe" [2007-09-18 25472]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-25 714608]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl04a\BrStDvPt.exe" [2004-05-25 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-20 509784]
"TDispVol"="TDispVol.exe" [2005-03-11 c:\windows\system32\TDispVol.exe]
"TPSMain"="TPSMain.exe" [2005-06-01 c:\windows\system32\TPSMain.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 c:\windows\agrsmmsg.exe]
c:\documents and settings\Jorge Torres\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2004-06-12 59080]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-02-15 155648]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2008-02-22 819200]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-01 18:39 356352 c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
--a------ 2004-07-20 10:34 851968 c:\program files\Brother\ControlCenter2\brctrcen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2004-08-18 07:37 184320 c:\program files\ltmoh\ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-20 64160]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-02-13 160792]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-04 55024]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2007-08-25 149352]
R2 NProtectService;Norton UnErase Protection;c:\progra~1\NORTON~2\NORTON~1\NPROTECT.EXE [2005-11-03 95832]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-01 101936]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2009-02-08 114024]
R3 SbieDrv;SbieDrv;c:\program files\Sandboxie\SbieDrv.sys [2009-01-05 103936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-05-29 23888]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-02-13 356920]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68d0835b-139c-11dc-928d-00a0d15356b8}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-03-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-20 20:34]
2009-03-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-03 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Jorge Torres.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 21:19]
2009-03-02 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Norton SystemWorks Basic Edition\OBC.exe [2007-09-18 11:22]
2009-03-02 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-13 19:15]
2009-03-02 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\ [2009-03-01 12:59]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Connection Wizard,ShellNext = hxxp://sam2003.course.com/
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
TCP: {BE6062F5-D44A-4405-8D70-1843B38A7DAE} = 4.2.2.1,4.2.2.2
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Jorge Torres\Application Data\Mozilla\Firefox\Profiles\np4nnp6k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\Jorge Torres\Application Data\Mozilla\Firefox\Profiles\np4nnp6k.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-08 18:27:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2179568005-3368781205-3588060182-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@DACL=(02 0000)
@SACL=
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1012)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'lsass.exe'(1072)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\brss01a.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\windows\system32\Brmfrmps.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sandboxie\SbieSvc.exe
c:\program files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
c:\progra~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Synaptics\SynTP\Toshiba.exe
c:\windows\system32\TPSBattM.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-03-08 18:32:42 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-08 22:32:38
ComboFix2.txt 2009-03-05 18:08:26
Pre-Run: 63,636,742,144 bytes free
Post-Run: 64,262,955,008 bytes free
336 --- E O F --- 2009-02-25 18:01:21
MBAM log:
Malwarebytes' Anti-Malware 1.34
Database version: 1827
Windows 5.1.2600 Service Pack 3
3/8/2009 7:04:41 PM
mbam-log-2009-03-08 (19-04-41).txt
Scan type: Quick Scan
Objects scanned: 68544
Time elapsed: 5 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
DDS.txt:
DDS (Ver_09-02-01.01) - NTFSx86
Run by Jorge Torres at 19:29:23.04 on Sun 03/08/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.457 [GMT -4:00]
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Jorge Torres\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Connection Wizard,ShellNext = hxxp://sam2003.course.com/
uURLSearchHooks: H - No File
BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\toolbar\ctbr.dll
BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.0\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.0\CoIEPlg.dll
TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\toolbar\ctbr.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe"
mRun: [TFncKy] c:\program files\toshiba\toshiba controls\TFncKy.exe
mRun: [TDispVol] TDispVol.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [NDSTray.exe] c:\program files\toshiba\configfree\NDSTray.exe
mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe
mRun: [TPSMain] TPSMain.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [dla] c:\windows\system32\dla\DLACTRLW.exe
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [NSWosCheck] "c:\program files\norton systemworks basic edition\osCheck.exe"
mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [SetDefPrt] c:\program files\brother\brmfl04a\BrStDvPt.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
StartupFolder: c:\docume~1\jorget~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\status~1.lnk - c:\program files\brother\brmfcmon\BrMfcWnd.exe
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {5E638779-1818-4754-A595-EF1C63B87A56} - c:\program files\norton systemworks basic edition\norton cleanup\WCQuick.lnk
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
TCP: {BE6062F5-D44A-4405-8D70-1843B38A7DAE} = 4.2.2.1,4.2.2.2
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\crawler\toolbar\ctbr.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jorget~1\applic~1\mozilla\firefox\profiles\np4nnp6k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\jorge torres\application data\mozilla\firefox\profiles\np4nnp6k.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
FF - component: c:\program files\crawler\toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\crawler\toolbar\firefox\components\xshared.dll
FF - component: c:\program files\crawler\toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\crawler\toolbar\firefox\components\xwsg.dll
FF - component: c:\program files\mozilla firefox\components\coFFPlgn.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-20 64160]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-2-13 160792]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-12-4 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-12-4 55024]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 NProtectService;Norton UnErase Protection;c:\progra~1\norton~2\norton~1\NPROTECT.EXE [2005-11-3 95832]
R3 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
R3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-5-29 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-1 101936]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2009-2-8 114024]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090308.003\NAVENG.SYS [2009-3-8 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090308.003\NAVEX15.SYS [2009-3-8 876144]
R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2009-1-5 103936]
R3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-6-5 1251720]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 950096]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2009-2-13 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2009-2-13 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2009-2-13 81288]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-4 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-2-13 356920]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-2-13 1079176]
=============== Created Last 30 ================
2009-03-08 18:20 <DIR> --d----- C:\ComboFix
2009-03-07 16:12 12,160 ac------ c:\windows\system32\dllcache\mouhid.sys
2009-03-07 16:12 12,160 a------- c:\windows\system32\drivers\mouhid.sys
2009-03-07 16:12 10,368 ac------ c:\windows\system32\dllcache\hidusb.sys
2009-03-07 16:12 10,368 a------- c:\windows\system32\drivers\hidusb.sys
2009-03-07 02:13 <DIR> --d----- c:\program files\Microsoft ActiveSync
2009-03-05 19:09 <DIR> --d----- c:\program files\G4box
2009-03-05 18:47 <DIR> --d----- C:\CFLog
2009-03-05 18:47 2,736,890 a------- c:\windows\system32\GameMon.des
2009-03-05 18:45 4,682 a------- c:\windows\system32\npptNT2.sys
2009-03-05 18:45 5,174 a------- c:\windows\system32\nppt9x.vxd
2009-03-05 18:44 <DIR> --d----- c:\program files\common files\INCA Shared
2009-03-05 13:57 <DIR> a-dshr-- C:\cmdcons
2009-03-05 13:55 161,792 a------- c:\windows\SWREG.exe
2009-03-05 13:55 98,816 a------- c:\windows\sed.exe
2009-03-04 16:21 <DIR> --d----- c:\program files\Crawler
2009-03-01 14:56 <DIR> --d----- c:\program files\SpywareBlaster
2009-03-01 12:59 <DIR> --d----- c:\docume~1\jorget~1\applic~1\IObit
2009-03-01 12:59 <DIR> --d----- c:\program files\IObit
2009-02-28 17:24 23,600 a------- c:\windows\system32\drivers\TVICHW32.SYS
2009-02-26 23:56 <DIR> --d----- c:\program files\HDD Health
2009-02-20 22:14 15,688 a------- c:\windows\system32\lsdelete.exe
2009-02-20 20:34 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-02-20 20:32 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-20 20:31 <DIR> --d----- c:\program files\Lavasoft
2009-02-19 13:03 579,464 a------- c:\windows\system32\SymNeti.dll
2009-02-19 13:03 207,240 a------- c:\windows\system32\SymRedir.dll
2009-02-19 12:31 31,280 a------- c:\windows\system32\drivers\SymIM.sys
2009-02-19 12:31 9,844 a------- c:\windows\system32\drivers\SymRedir.cat
2009-02-19 12:31 1,611 a------- c:\windows\system32\drivers\SymRedir.inf
2009-02-19 12:31 41,008 a------- c:\windows\system32\drivers\symndisv.sys
2009-02-19 12:31 184,496 a------- c:\windows\system32\drivers\symtdi.sys
2009-02-19 12:31 96,560 a------- c:\windows\system32\drivers\symfw.sys
2009-02-19 12:31 38,576 a------- c:\windows\system32\drivers\symids.sys
2009-02-19 12:31 37,424 a------- c:\windows\system32\drivers\symndis.sys
2009-02-19 12:31 22,320 a------- c:\windows\system32\drivers\symredrv.sys
2009-02-19 12:31 13,616 a------- c:\windows\system32\drivers\symdns.sys
2009-02-18 11:43 <DIR> --d----- c:\windows\system32\Adobe
2009-02-13 22:04 160,792 a------- c:\windows\system32\drivers\pctfw2.sys
2009-02-13 22:04 <DIR> --d----- c:\program files\common files\PC Tools
2009-02-13 22:04 81,288 a------- c:\windows\system32\drivers\iksyssec.sys
2009-02-13 22:04 66,952 a------- c:\windows\system32\drivers\iksysflt.sys
2009-02-13 22:04 40,840 a------- c:\windows\system32\drivers\ikfilesec.sys
2009-02-13 22:04 29,576 a------- c:\windows\system32\drivers\kcom.sys
2009-02-13 22:03 <DIR> --d----- c:\program files\Spyware Doctor
2009-02-13 22:03 <DIR> --d----- c:\docume~1\jorget~1\applic~1\PC Tools
2009-02-13 22:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
2009-02-12 12:20 <DIR> --d----- c:\docume~1\jorget~1\applic~1\Ashampoo
2009-02-12 12:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ashampoo
2009-02-12 12:20 <DIR> --d----- c:\program files\Ashampoo
2009-02-08 11:23 114,024 a------- c:\windows\system32\drivers\keyscrambler.sys
2009-02-08 11:23 <DIR> --d----- c:\program files\KeyScrambler
2009-02-08 11:03 <DIR> --d----- c:\program files\PeerGuardian2
2009-02-07 20:51 <DIR> --d----- C:\Sandbox
2009-02-07 20:39 1,496 a------- c:\windows\Sandboxie.ini
2009-02-07 20:39 <DIR> --d----- c:\program files\Sandboxie
2009-02-06 21:20 <DIR> --d----- c:\program files\Trend Micro
==================== Find3M ====================
2009-02-12 12:08 717,296 a------- c:\windows\system32\drivers\sptd.sys
2009-02-11 11:19 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 11:19 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-01-06 13:07 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2008-12-20 19:15 826,368 a------- c:\windows\system32\wininet.dll
2008-03-14 17:36 34,744 a------- c:\docume~1\jorget~1\applic~1\GDIPFONTCACHEV1.DAT
2008-09-10 12:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091020080911\index.dat
============= FINISH: 19:29:57.89 ===============
Attach.txt:
DDS (Ver_09-02-01.01) - NTFSx86
Run by Jorge Torres at 19:29:23.04 on Sun 03/08/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.457 [GMT -4:00]
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *disabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Jorge Torres\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Connection Wizard,ShellNext = hxxp://sam2003.course.com/
uURLSearchHooks: H - No File
BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\toolbar\ctbr.dll
BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.0\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.0\CoIEPlg.dll
TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\toolbar\ctbr.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe"
mRun: [TFncKy] c:\program files\toshiba\toshiba controls\TFncKy.exe
mRun: [TDispVol] TDispVol.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [NDSTray.exe] c:\program files\toshiba\configfree\NDSTray.exe
mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe
mRun: [TPSMain] TPSMain.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [dla] c:\windows\system32\dla\DLACTRLW.exe
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [NSWosCheck] "c:\program files\norton systemworks basic edition\osCheck.exe"
mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [SetDefPrt] c:\program files\brother\brmfl04a\BrStDvPt.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
StartupFolder: c:\docume~1\jorget~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\status~1.lnk - c:\program files\brother\brmfcmon\BrMfcWnd.exe
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {5E638779-1818-4754-A595-EF1C63B87A56} - c:\program files\norton systemworks basic edition\norton cleanup\WCQuick.lnk
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
TCP: {BE6062F5-D44A-4405-8D70-1843B38A7DAE} = 4.2.2.1,4.2.2.2
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\crawler\toolbar\ctbr.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jorget~1\applic~1\mozilla\firefox\profiles\np4nnp6k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\jorge torres\application data\mozilla\firefox\profiles\np4nnp6k.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
FF - component: c:\program files\crawler\toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\crawler\toolbar\firefox\components\xshared.dll
FF - component: c:\program files\crawler\toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\crawler\toolbar\firefox\components\xwsg.dll
FF - component: c:\program files\mozilla firefox\components\coFFPlgn.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-20 64160]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-2-13 160792]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-12-4 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-12-4 55024]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 NProtectService;Norton UnErase Protection;c:\progra~1\norton~2\norton~1\NPROTECT.EXE [2005-11-3 95832]
R3 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352]
R3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-5-29 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-1 101936]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2009-2-8 114024]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090308.003\NAVENG.SYS [2009-3-8 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090308.003\NAVEX15.SYS [2009-3-8 876144]
R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2009-1-5 103936]
R3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-6-5 1251720]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 950096]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2009-2-13 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2009-2-13 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2009-2-13 81288]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-4 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-2-13 356920]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-2-13 1079176]
=============== Created Last 30 ================
2009-03-08 18:20 <DIR> --d----- C:\ComboFix
2009-03-07 16:12 12,160 ac------ c:\windows\system32\dllcache\mouhid.sys
2009-03-07 16:12 12,160 a------- c:\windows\system32\drivers\mouhid.sys
2009-03-07 16:12 10,368 ac------ c:\windows\system32\dllcache\hidusb.sys
2009-03-07 16:12 10,368 a------- c:\windows\system32\drivers\hidusb.sys
2009-03-07 02:13 <DIR> --d----- c:\program files\Microsoft ActiveSync
2009-03-05 19:09 <DIR> --d----- c:\program files\G4box
2009-03-05 18:47 <DIR> --d----- C:\CFLog
2009-03-05 18:47 2,736,890 a------- c:\windows\system32\GameMon.des
2009-03-05 18:45 4,682 a------- c:\windows\system32\npptNT2.sys
2009-03-05 18:45 5,174 a------- c:\windows\system32\nppt9x.vxd
2009-03-05 18:44 <DIR> --d----- c:\program files\common files\INCA Shared
2009-03-05 13:57 <DIR> a-dshr-- C:\cmdcons
2009-03-05 13:55 161,792 a------- c:\windows\SWREG.exe
2009-03-05 13:55 98,816 a------- c:\windows\sed.exe
2009-03-04 16:21 <DIR> --d----- c:\program files\Crawler
2009-03-01 14:56 <DIR> --d----- c:\program files\SpywareBlaster
2009-03-01 12:59 <DIR> --d----- c:\docume~1\jorget~1\applic~1\IObit
2009-03-01 12:59 <DIR> --d----- c:\program files\IObit
2009-02-28 17:24 23,600 a------- c:\windows\system32\drivers\TVICHW32.SYS
2009-02-26 23:56 <DIR> --d----- c:\program files\HDD Health
2009-02-20 22:14 15,688 a------- c:\windows\system32\lsdelete.exe
2009-02-20 20:34 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-02-20 20:32 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-20 20:31 <DIR> --d----- c:\program files\Lavasoft
2009-02-19 13:03 579,464 a------- c:\windows\system32\SymNeti.dll
2009-02-19 13:03 207,240 a------- c:\windows\system32\SymRedir.dll
2009-02-19 12:31 31,280 a------- c:\windows\system32\drivers\SymIM.sys
2009-02-19 12:31 9,844 a------- c:\windows\system32\drivers\SymRedir.cat
2009-02-19 12:31 1,611 a------- c:\windows\system32\drivers\SymRedir.inf
2009-02-19 12:31 41,008 a------- c:\windows\system32\drivers\symndisv.sys
2009-02-19 12:31 184,496 a------- c:\windows\system32\drivers\symtdi.sys
2009-02-19 12:31 96,560 a------- c:\windows\system32\drivers\symfw.sys
2009-02-19 12:31 38,576 a------- c:\windows\system32\drivers\symids.sys
2009-02-19 12:31 37,424 a------- c:\windows\system32\drivers\symndis.sys
2009-02-19 12:31 22,320 a------- c:\windows\system32\drivers\symredrv.sys
2009-02-19 12:31 13,616 a------- c:\windows\system32\drivers\symdns.sys
2009-02-18 11:43 <DIR> --d----- c:\windows\system32\Adobe
2009-02-13 22:04 160,792 a------- c:\windows\system32\drivers\pctfw2.sys
2009-02-13 22:04 <DIR> --d----- c:\program files\common files\PC Tools
2009-02-13 22:04 81,288 a------- c:\windows\system32\drivers\iksyssec.sys
2009-02-13 22:04 66,952 a------- c:\windows\system32\drivers\iksysflt.sys
2009-02-13 22:04 40,840 a------- c:\windows\system32\drivers\ikfilesec.sys
2009-02-13 22:04 29,576 a------- c:\windows\system32\drivers\kcom.sys
2009-02-13 22:03 <DIR> --d----- c:\program files\Spyware Doctor
2009-02-13 22:03 <DIR> --d----- c:\docume~1\jorget~1\applic~1\PC Tools
2009-02-13 22:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
2009-02-12 12:20 <DIR> --d----- c:\docume~1\jorget~1\applic~1\Ashampoo
2009-02-12 12:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ashampoo
2009-02-12 12:20 <DIR> --d----- c:\program files\Ashampoo
2009-02-08 11:23 114,024 a------- c:\windows\system32\drivers\keyscrambler.sys
2009-02-08 11:23 <DIR> --d----- c:\program files\KeyScrambler
2009-02-08 11:03 <DIR> --d----- c:\program files\PeerGuardian2
2009-02-07 20:51 <DIR> --d----- C:\Sandbox
2009-02-07 20:39 1,496 a------- c:\windows\Sandboxie.ini
2009-02-07 20:39 <DIR> --d----- c:\program files\Sandboxie
2009-02-06 21:20 <DIR> --d----- c:\program files\Trend Micro
==================== Find3M ====================
2009-02-12 12:08 717,296 a------- c:\windows\system32\drivers\sptd.sys
2009-02-11 11:19 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 11:19 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-01-06 13:07 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2008-12-20 19:15 826,368 a------- c:\windows\system32\wininet.dll
2008-03-14 17:36 34,744 a------- c:\docume~1\jorget~1\applic~1\GDIPFONTCACHEV1.DAT
2008-09-10 12:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091020080911\index.dat
============= FINISH: 19:29:57.89 ===============