I RAN THE NEW COMBOFIX AND THE DDS PROGRAM. IT WASN'T CLEAR TO ME WHETHER TO PASTE THE LOG CONTENTS INTO THIS POST OR ATTACH THE FILES, SO I'M GONNA DO BOTH...
---------------------------------------------------
ComboFix 09-03-01.01 - David Almond 2009-03-01 16:59:12.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1006.432 [GMT -8:00]
Running from: c:\documents and settings\David Almond\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\System\Uninstall
.
((((((((((((((((((((((((( Files Created from 2009-02-02 to 2009-03-02 )))))))))))))))))))))))))))))))
.
2009-02-27 12:13 . 2009-02-27 12:13 <DIR> d-------- c:\program files\Java
2009-02-27 12:13 . 2009-02-27 12:13 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-27 12:13 . 2009-02-27 12:13 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-24 20:44 . 2009-02-24 20:44 <DIR> d-------- c:\program files\CCleaner
2009-02-24 09:01 . 2009-02-24 09:01 51,520 --a------ c:\windows\system32\drivers\TfFsMon.sys
2009-02-24 09:01 . 2009-02-24 09:01 38,208 --a------ c:\windows\system32\drivers\TfSysMon.sys
2009-02-24 09:01 . 2009-02-24 09:01 33,088 --a------ c:\windows\system32\drivers\TfNetMon.sys
2009-02-24 09:01 . 2009-02-24 09:01 12,608 --a------ c:\windows\system32\drivers\TfKbMon.sys
2009-02-22 15:15 . 2009-02-22 15:23 246 --a------ c:\windows\hpntwksetup.ini
2009-02-22 15:08 . 2009-02-22 14:09 102,833 --------- c:\windows\HPFins09.dat.temp
2009-02-22 15:08 . 2005-11-01 17:29 3,732 --------- c:\windows\hpfmdl09.dat.temp
2009-02-22 13:44 . 2005-03-14 12:03 278,584 --a------ c:\windows\system32\HPZidr12.dll
2009-02-22 13:44 . 2005-03-14 12:05 204,800 --a------ c:\windows\system32\HPZipr12.dll
2009-02-22 13:44 . 2005-03-08 11:55 94,208 --a------ c:\windows\system32\HPZipt12.dll
2009-02-22 13:44 . 2005-03-14 12:05 69,632 --a------ c:\windows\system32\HPZipm12.exe
2009-02-22 13:44 . 2005-03-14 13:39 65,536 --a------ c:\windows\system32\HPZinw12.exe
2009-02-22 13:44 . 2005-03-08 11:55 57,344 --a------ c:\windows\system32\HPZisn12.dll
2009-02-22 13:43 . 2009-02-22 13:44 <DIR> d-------- c:\program files\HP
2009-02-22 13:42 . 2009-02-22 15:09 104,016 --a------ c:\windows\HPFins09.dat
2009-02-22 13:42 . 2005-09-09 15:28 98,304 --a------ c:\windows\system32\hpzjsn01.dll
2009-02-22 13:42 . 2005-11-01 17:29 3,732 --------- c:\windows\hpfmdl09.dat
2009-02-16 09:58 . 2009-02-16 09:58 <DIR> d-------- c:\program files\Trend Micro
2009-02-13 12:16 . 2009-02-13 12:16 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 12:16 . 2009-02-13 12:16 <DIR> d-------- c:\documents and settings\David Almond\Application Data\Malwarebytes
2009-02-13 12:16 . 2009-02-13 12:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-13 12:16 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 12:16 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-10 09:18 . 2009-02-10 09:01 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-10 08:56 . 2009-02-10 08:56 <DIR> d-------- c:\program files\Lavasoft
2009-02-10 08:56 . 2009-02-10 09:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-10 08:56 . 2009-02-10 08:56 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-07 22:08 . 2009-02-07 22:08 <DIR> d-------- c:\program files\DivX
2009-02-06 14:02 . 2009-02-22 15:15 <DIR> d-------- C:\temp
2009-02-06 14:01 . 2009-02-06 14:01 <DIR> d-------- c:\program files\www
2009-02-06 14:01 . 2009-02-06 15:16 <DIR> d-------- c:\program files\Common Files\supportsoft
2009-02-04 11:20 . 2009-02-24 09:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2009-02-04 11:20 . 2009-02-04 11:15 160,792 --a------ c:\windows\system32\drivers\pctfw2.sys
2009-02-04 11:11 . 2009-02-04 11:20 <DIR> d-------- c:\program files\Common Files\PC Tools
2009-02-04 10:08 . 2009-03-01 17:03 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-04 10:07 . 2009-03-01 16:45 <DIR> d-------- c:\program files\Spyware Doctor
2009-02-04 10:07 . 2009-02-04 10:07 <DIR> d-------- c:\documents and settings\David Almond\Application Data\PC Tools
2009-02-04 10:07 . 2004-03-09 01:00 1,081,616 --a------ c:\windows\system32\MSCOMCTL.OCX
2009-02-04 10:07 . 2008-08-25 12:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-02-04 10:07 . 2008-08-25 12:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-02-04 10:07 . 2008-08-25 12:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-02-04 10:07 . 2008-06-02 16:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-02-03 19:57 . 2009-02-27 14:41 <DIR> d-------- c:\documents and settings\LocalService\Application Data\SACore
2009-02-03 14:22 . 2009-03-01 16:51 12,619 --a------ c:\windows\system32\Config.MPF
2009-02-03 14:21 . 2009-02-03 14:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-02-03 14:12 . 2009-01-09 12:03 79,304 --a------ c:\windows\system32\drivers\mfeavfk.sys
2009-02-03 14:12 . 2009-01-09 12:03 40,552 --a------ c:\windows\system32\drivers\mfesmfk.sys
2009-02-03 14:12 . 2009-01-09 12:03 35,272 --a------ c:\windows\system32\drivers\mfebopk.sys
2009-02-03 14:11 . 2008-10-23 13:08 120,136 --a------ c:\windows\system32\drivers\Mpfp.sys
2009-02-03 14:07 . 2009-02-03 14:12 <DIR> d-------- c:\program files\Common Files\McAfee
2009-02-03 13:48 . 2009-02-03 13:56 <DIR> d-------- c:\documents and settings\David Almond\Application Data\Twain
2009-02-03 13:43 . 2009-02-03 20:56 <DIR> d-------- c:\program files\WebShow
2009-02-03 13:29 . 2009-01-09 12:03 34,216 --a------ c:\windows\system32\drivers\mferkdk.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-02 00:06 --------- d-----w c:\documents and settings\David Almond\Application Data\skypePM
2009-02-27 07:00 --------- d-----w c:\program files\Palm
2009-02-25 00:14 --------- d-----w c:\documents and settings\David Almond\Application Data\OpenOffice.org2
2009-02-24 01:44 --------- d-----w c:\documents and settings\David Almond\Application Data\Skype
2009-02-14 05:12 --------- d-----w c:\documents and settings\David Almond\Application Data\dvdcss
2009-02-06 05:35 7,518 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-02-05 07:43 --------- d-----w c:\program files\McAfee
2009-02-03 22:29 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-02-03 22:27 --------- d-----w c:\program files\McAfee.com
2009-02-03 22:27 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee.com
2009-01-17 05:35 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-01-12 07:10 578,560 ----a-w c:\windows\system32\user32.DLL
2009-01-12 07:10 578,560 ----a-w c:\windows\system32\dllcache\user32.dll
2009-01-09 20:03 213,640 ----a-w c:\windows\system32\drivers\mfehidk.sys
2008-12-19 09:10 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2006-05-06 16:42 7,260,160 ----a-w c:\program files\mozilla firefox\plugins\libvlc.dll
2008-09-16 17:22 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091620080917\index.dat
.
((((((((((((((((((((((((((((( SnapShot_2009-02-24_13.29.14.16 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-24 18:33:10 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-03-01 20:39:57 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-24 18:33:10 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-01 20:39:57 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-24 18:33:10 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-01 20:39:57 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-17 19:02:19 8,461,312 ------w c:\windows\system32\dllcache\shell32.dll
- 2003-11-19 21:36:26 24,681 ----a-w c:\windows\system32\java.exe
+ 2009-02-27 20:13:28 144,792 ----a-w c:\windows\system32\java.exe
- 2003-11-19 21:36:30 28,779 ----a-w c:\windows\system32\javaw.exe
+ 2009-02-27 20:13:28 144,792 ----a-w c:\windows\system32\javaw.exe
+ 2009-02-27 20:13:28 148,888 ----a-w c:\windows\system32\javaws.exe
- 2008-04-14 00:12:05 8,461,312 ----a-w c:\windows\system32\shell32.dll
+ 2008-06-17 19:02:19 8,461,312 ----a-w c:\windows\system32\shell32.dll
+ 2009-03-01 20:34:43 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_280.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-05 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2006-04-06 49152]
"Creative WebCam Tray"="c:\program files\Creative\Shared Files\CAMTRAY.EXE" [2003-06-26 184320]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-09 185896]
"M-Audio Taskbar Icon"="c:\windows\System32\M-AudioTaskBarIcon.exe" [2006-03-16 99840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-08 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-10 509784]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-08-25 1168264]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-27 148888]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2004-06-09 471040]
NkvMon.exe.lnk - c:\program files\Nikon\NkView6\NkvMon.exe [2006-09-28 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi2"= usbnp4x4.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-02-24 51520]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-02-24 38208]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-02-04 160792]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
R2 MAudioAudiophileService;M-Audio Audiophile Installer;c:\program files\M-Audio\Audiophile USB\MAUSBAPInst.exe [2006-12-27 57344]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-03 206096]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-02-04 356920]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-02-24 33088]
R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 MADFU003;MADFU003;c:\windows\system32\drivers\MADFU003.sys [2006-12-27 69248]
S3 MAUSBAP;Service for M-Audio Audiophile (WDM);c:\windows\system32\drivers\mausbap.sys [2006-12-27 103424]
S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [2006-09-21 759050]
S3 USBNP4X4;M-Audio Audiophile USB Midi;c:\windows\system32\drivers\usbnp4x4.sys [2006-12-27 22336]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-02-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-10 09:01]
2009-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-02-03 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-09 10:53]
2009-02-03 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-09 10:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.nytimes.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
Trusted Zone: aol.com\free
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\David Almond\Application Data\Mozilla\Firefox\Profiles\5vr66n6i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www13.yoog.com/search.php?q=
FF - prefs.js: browser.search.selectedEngine - Yoog Search
FF - prefs.js: browser.startup.homepage - hxxp://www.nytimes.com/
FF - prefs.js: keyword.URL - hxxp://www13.yoog.com/search.php?q=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvlc.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www13.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: keyword.URL - hxxp://www13.yoog.com/search.php?q=
FF - user.js: keyword.enabled - true
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-01 17:03:29
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\windows\System32\BCMLogon.dll
c:\program files\Spyware Doctor\TFEngine\TFNI.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll
c:\windows\system32\igfxdev.dll
- - - - - - - > 'lsass.exe'(892)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
- - - - - - - > 'explorer.exe'(6012)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
.
Completion time: 2009-03-01 17:06:24
ComboFix-quarantined-files.txt 2009-03-02 01:06:18
ComboFix2.txt 2009-02-24 21:30:35
ComboFix3.txt 2009-02-23 00:13:47
Pre-Run: 15,244,386,304 bytes free
Post-Run: 15,297,449,984 bytes free
262 --- E O F --- 2009-02-24 22:31:13
------------------------------------------------------------------
NOW THE DDS LOG FILE:
DDS (Ver_09-02-01.01) - NTFSx86
Run by David Almond at 17:12:09.36 on Sun 03/01/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1006.316 [GMT -8:00]
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\M-Audio\Audiophile USB\MAUSBAPInst.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\David Almond\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.nytimes.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [Creative WebCam Tray] c:\program files\creative\shared files\CAMTRAY.EXE
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [M-Audio Taskbar Icon] c:\windows\system32\M-AudioTaskBarIcon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkvmon~1.lnk - c:\program files\nikon\nkview6\NkvMon.exe
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
Trusted Zone: aol.com\free
Trusted Zone: musicmatch.com\online
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk/6u12-b04/jinstall-6u12-windows-i586-jc.cab?e=1235765582064&h=29abd7be93193cf3251a7aa114c15d13/&filename=jinstall-6u12-windows-i586-jc.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\davida~1\applic~1\mozilla\firefox\profiles\5vr66n6i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www13.yoog.com/search.php?q=
FF - prefs.js: browser.search.selectedEngine - Yoog Search
FF - prefs.js: browser.startup.homepage - hxxp://www.nytimes.com/
FF - prefs.js: keyword.URL - hxxp://www13.yoog.com/search.php?q=
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npvlc.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www13.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: keyword.URL - hxxp://www13.yoog.com/search.php?q=
FF - user.js: keyword.enabled - true
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2009-2-4 40840]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-2-24 51520]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-2-24 38208]
R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2009-2-4 66952]
R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2009-2-4 81288]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-9 213640]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-2-4 160792]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 950096]
R2 MAudioAudiophileService;M-Audio Audiophile Installer;c:\program files\m-audio\audiophile usb\MAUSBAPInst.exe [2006-12-27 57344]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-2-3 206096]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-2-3 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-2-3 144704]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-2-4 356920]
R2 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-2-4 1079176]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-2-3 79304]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-2-3 35272]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-2-24 33088]
R3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]
S3 MADFU003;MADFU003;c:\windows\system32\drivers\MADFU003.sys [2006-12-27 69248]
S3 MAUSBAP;Service for M-Audio Audiophile (WDM);c:\windows\system32\drivers\mausbap.sys [2006-12-27 103424]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-2-3 34216]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-2-3 40552]
S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [2006-9-21 759050]
S3 USBNP4X4;M-Audio Audiophile USB Midi;c:\windows\system32\drivers\usbnp4x4.sys [2006-12-27 22336]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-2-3 606736]
=============== Created Last 30 ================
2009-02-27 12:13 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-27 12:13 73,728 a------- c:\windows\system32\javacpl.cpl
2009-02-24 20:44 <DIR> --d----- c:\program files\CCleaner
2009-02-24 13:15 161,792 a------- c:\windows\SWREG.exe
2009-02-24 13:15 98,816 a------- c:\windows\sed.exe
2009-02-24 09:01 38,208 a------- c:\windows\system32\drivers\TfSysMon.sys
2009-02-24 09:01 33,088 a------- c:\windows\system32\drivers\TfNetMon.sys
2009-02-24 09:01 51,520 a------- c:\windows\system32\drivers\TfFsMon.sys
2009-02-24 09:01 12,608 a------- c:\windows\system32\drivers\TfKbMon.sys
2009-02-22 15:56 <DIR> a-dshr-- C:\cmdcons
2009-02-22 15:15 246 a------- c:\windows\hpntwksetup.ini
2009-02-22 15:08 102,833 -------- c:\windows\HPFins09.dat.temp
2009-02-22 15:08 3,732 -------- c:\windows\hpfmdl09.dat.temp
2009-02-22 13:44 65,536 a------- c:\windows\system32\HPZinw12.exe
2009-02-22 13:44 69,632 a------- c:\windows\system32\HPZipm12.exe
2009-02-22 13:44 94,208 a------- c:\windows\system32\HPZipt12.dll
2009-02-22 13:44 57,344 a------- c:\windows\system32\HPZisn12.dll
2009-02-22 13:44 204,800 a------- c:\windows\system32\HPZipr12.dll
2009-02-22 13:44 278,584 a------- c:\windows\system32\HPZidr12.dll
2009-02-22 13:43 <DIR> --d----- c:\program files\HP
2009-02-22 13:42 104,016 a------- c:\windows\HPFins09.dat
2009-02-22 13:42 3,732 -------- c:\windows\hpfmdl09.dat
2009-02-22 13:42 98,304 a------- c:\windows\system32\hpzjsn01.dll
2009-02-16 09:58 <DIR> --d----- c:\program files\Trend Micro
2009-02-13 12:16 <DIR> --d----- c:\docume~1\davida~1\applic~1\Malwarebytes
2009-02-13 12:16 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-13 12:16 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 12:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-13 12:16 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-10 09:18 15,688 a------- c:\windows\system32\lsdelete.exe
2009-02-10 08:56 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-10 08:56 <DIR> --d----- c:\program files\Lavasoft
2009-02-07 22:08 <DIR> --d----- c:\program files\DivX
2009-02-06 14:02 <DIR> --d----- C:\temp
2009-02-06 14:01 <DIR> --d----- c:\program files\common files\supportsoft
2009-02-06 14:01 <DIR> --d----- c:\program files\www
2009-02-04 11:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
2009-02-04 11:20 160,792 a------- c:\windows\system32\drivers\pctfw2.sys
2009-02-04 11:11 <DIR> --d----- c:\program files\common files\PC Tools
2009-02-04 10:07 81,288 a------- c:\windows\system32\drivers\iksyssec.sys
2009-02-04 10:07 66,952 a------- c:\windows\system32\drivers\iksysflt.sys
2009-02-04 10:07 40,840 a------- c:\windows\system32\drivers\ikfilesec.sys
2009-02-04 10:07 29,576 a------- c:\windows\system32\drivers\kcom.sys
2009-02-04 10:07 <DIR> --d----- c:\program files\Spyware Doctor
2009-02-04 10:07 <DIR> --d----- c:\docume~1\davida~1\applic~1\PC Tools
2009-02-04 10:07 1,081,616 a------- c:\windows\system32\MSCOMCTL.OCX
2009-02-03 14:22 12,619 a------- c:\windows\system32\Config.MPF
2009-02-03 14:12 40,552 a------- c:\windows\system32\drivers\mfesmfk.sys
2009-02-03 14:12 79,304 a------- c:\windows\system32\drivers\mfeavfk.sys
2009-02-03 14:12 35,272 a------- c:\windows\system32\drivers\mfebopk.sys
2009-02-03 14:11 120,136 a------- c:\windows\system32\drivers\Mpfp.sys
2009-02-03 14:07 <DIR> --d----- c:\program files\common files\McAfee
2009-02-03 13:48 <DIR> --d----- c:\docume~1\davida~1\applic~1\Twain
2009-02-03 13:43 <DIR> --d----- c:\program files\WebShow
2009-02-03 13:29 34,216 a------- c:\windows\system32\drivers\mferkdk.sys
==================== Find3M ====================
2009-02-05 21:35 7,518 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-01-16 21:35 3,594,752 a------- c:\windows\system32\dllcache\mshtml.dll
2009-01-11 23:10 578,560 a------- c:\windows\system32\user32.DLL
2009-01-11 23:10 578,560 a------- c:\windows\system32\dllcache\user32.dll
2009-01-09 12:03 213,640 a------- c:\windows\system32\drivers\mfehidk.sys
2008-12-19 01:10 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 01:10 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-12-18 21:25 634,024 a------- c:\windows\system32\dllcache\iexplore.exe
2008-12-18 21:23 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2008-12-11 02:57 333,952 -------- c:\windows\system32\dllcache\srv.sys
2008-09-16 09:22 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091620080917\index.dat
============= FINISH: 17:12:59.47 ===============
NOW THE "ATTACH" LOG FILE:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-02-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 5/31/2006 5:39:27 PM
System Uptime: 3/1/2009 12:58:53 PM (5 hours ago)
Motherboard: DELL SYSTEM | | 0WF016
Processor: Intel® Pentium® M processor 1.70GHz | U1 | 1694/100mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 53 GiB total, 14.259 GiB free.
D: is FIXED (NTFS) - 19 GiB total, 0.166 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\7847AA0081221400
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\7847AA0081221400
Service: NIC1394
==== System Restore Points ===================
RP508: 2/2/2009 8:30:19 PM - System Checkpoint
RP509: 2/4/2009 10:41:49 AM - Spyware Doctor: Cleaning Threats
RP510: 2/5/2009 10:46:39 PM - System Checkpoint
RP511: 2/7/2009 8:40:56 PM - System Checkpoint
RP512: 2/10/2009 10:52:11 PM - System Checkpoint
RP513: 2/15/2009 4:32:34 PM - System Checkpoint
RP514: 2/16/2009 10:59:50 AM - Ad-Aware Checkpoint
RP515: 2/19/2009 11:38:22 AM - System Checkpoint
RP516: 2/22/2009 2:33:47 PM - System Checkpoint
RP517: 2/22/2009 3:46:16 PM - ComboFix created restore point
RP518: 2/22/2009 4:38:47 PM - Software Distribution Service 3.0
RP519: 2/24/2009 11:42:02 AM - System Checkpoint
RP520: 2/24/2009 1:15:33 PM - ComboFix created restore point
RP521: 2/24/2009 2:29:38 PM - Software Distribution Service 3.0
RP522: 2/24/2009 4:32:30 PM - Removed Java 2 Runtime Environment, SE v1.4.2_03
RP523: 2/25/2009 7:53:34 PM - System Checkpoint
RP524: 2/27/2009 12:13:13 PM - Installed Java 6 Update 12
RP525: 3/1/2009 1:32:37 PM - System Checkpoint
RP526: 3/1/2009 4:58:19 PM - ComboFix created restore point
==== Installed Programs ======================
Ad-Aware
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0
AOLIcon
Apple Mobile Device Support
Apple Software Update
ArcSoft Software Suite
Audiophile USB
Azureus
Banctec Service Agreement
Bonjour
Broadcom Management Programs
Canon MP Drivers 6.0
Canon MP Navigator 1.0
Canon ScanGear Starter
Canon Utilities Easy-PhotoPrint
CCleaner (remove only)
Conexant D480 MDC V.9x Modem
Contextual Platform Worldadmarketplace
Corel Paint Shop Pro X
Corel Photo Album 6
Creative PC-CAM Center
Creative WebCam Monitor
Creative WebCam NX Ultra Driver (1.00.06.0919)
Creative WebCam NX Ultra User's Guide (English)
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Game Console
Dell Media Experience
Dell System Restore
Dell Wireless WLAN Card
DellSupport
Diagnosaurus
Digital Content Portal
Digital Line Detect
DivX Web Player
Documentation & Support Launcher
Easy-WebPrint
EducateU
ELIcon
Epocrates Essentials
Games, Music, & Photos Launcher
Handmark® MobileDB for Palm OS
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
HP Deskjet 6900 series
Intel® Extreme Graphics 2 Driver
InterActual Player
iTunes
Java 6 Update 12
LiveUpdate 2.6 (Symantec Corporation)
Malwarebytes' Anti-Malware
McAfee SecurityCenter
McAfee Uninstaller
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Visual C Runtime
MobileMe Control Panel
Modem Helper
Mozilla Firefox (3.0.6)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musicmatch® Jukebox
NetWaiting
Nikon View 6
OmniPage SE 2.0
OpenOffice.org 2.1
Palm
PCIxx20
Performance Solution Worldadmarketplace
Photo Click
PowerDVD 5.9
Presto! PageManager 6.03
QFolder
QuickTime
Rapid Access Facts Tool - Palm Edition
RealPlayer
Registry Mechanic 8.0
Rhapsody Player Engine
Safari
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960715)
Skype™ 3.8
Sonic DLA
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SplashPhoto
Spyware Doctor 6.0
Synaptics Pointing Device Driver
TBS WMP Plug-in
Texas Instruments PCIxx20 drivers.
The French Tutorial Personal Edition
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
URL Assistant
VC80CRTRedist - 8.0.50727.762
VideoLAN VLC media player 0.8.5
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebCyberCoach 3.2 Dell
WebFldrs XP
WildTangent Web Driver
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
2/24/2009 12:55:53 PM, error: Service Control Manager [7000] - The Dell Wireless WLAN Tray Service service failed to start due to the following error: The system cannot find the path specified.
2/24/2009 12:50:52 PM, error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 11:17:16 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
2/24/2009 9:12:44 AM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
2/24/2009 9:12:44 AM, error: Service Control Manager [7000] - The TfNetMon service failed to start due to the following error: Insufficient system resources exist to complete the requested service.
2/22/2009 8:43:46 PM, error: Dhcp [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 0014A58DCEA8 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
2/22/2009 4:05:38 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/22/2009 4:04:33 PM, error: Service Control Manager [7000] - The PC Tools Security Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/22/2009 4:04:33 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PC Tools Security Service service to connect.
2/22/2009 3:41:15 PM, error: Tcpip [4199] - The system detected an address conflict for IP address 10.0.1.3 with the system having network hardware address 00:17:A4:69:A7:7B. Network operations on this system may be disrupted as a result.
2/24/2009 1:07:22 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer RMFCAGIG that believes that it is the master browser for the domain on transport NetBT_Tcpip_{C3C1F4E0-FC78-4ADC-. The master browser is stopping or an election is being forced.
2/24/2009 1:17:04 PM, error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
2/24/2009 1:17:04 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/24/2009 1:17:04 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The M-Audio Audiophile Installer service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The PC Tools Auxiliary Service service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 1:17:04 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/24/2009 1:17:04 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/24/2009 1:17:04 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/24/2009 1:17:04 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program.
2/24/2009 1:17:04 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
2/24/2009 3:20:04 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the ThreatFire service to connect.
2/24/2009 3:20:06 PM, error: Service Control Manager [7000] - The ThreatFire service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/25/2009 6:48:32 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the mcmscsvc service.
2/28/2009 6:49:00 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the McAfee SystemGuards service to connect.
2/28/2009 6:49:00 PM, error: Service Control Manager [7000] - The McAfee SystemGuards service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
==== End Of File ===========================
THANK YOU AGAIN FOR YOUR HELP. I ASSUME I SHOULD ALWAYS TURN OFF VIRUS/MALWARE/FIREWALL SOFTWARE PRIOR TO RUNNING THESE VARIOUS SCANS. THANK YOU.