Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 7093
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/12/2011 9:07:59 PM
mbam-log-2011-07-12 (21-07-59).txt
Scan type: Quick scan
Objects scanned: 258767
Time elapsed: 37 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
GMER 1.0.15.15640 - http://www.gmer.net
Rootkit quick scan 2011-07-12 22:23:35
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 WDC_WD1600JD-75HBB0 rev.08.02D08
Running: wvbgr6ux.exe; Driver: C:\DOCUME~1\Bryan\LOCALS~1\Temp\pwtdapod.sys
---- System - GMER 1.0.15 ----
Code fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation) IoCreateDevice
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \Driver\Tcpip \Device\Ip fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\Tcp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\Udp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\RawIp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Run by Bryan at 22:29:38 on 2011-07-12
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.387 [GMT -5:00]
.
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: Charter Security Suite 9.01 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Charter Security Suite 9.01 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Charter Security Suite\Common\FSMA32.EXE
C:\Program Files\Charter Security Suite\Anti-Virus\FSGK32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Charter Security Suite\Common\FSHDLL32.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fsav32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Charter Security Suite\Common\FSM32.EXE
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\PIXELA\ImageMixer 3 SE Ver.4.5\Transfer Utility\CameraMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Documents and Settings\Bryan\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\dlbucoms.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.charter.net/
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
uURLSearchHooks: N/A: {d73f49b6-b51b-4d32-a3b7-bd04b8342f53} - c:\program files\morpheusbar\srchastt\2.bin\MBSRCAS.DLL
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PCTools Site Guard: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - c:\progra~1\spywar~1\tools\iesdsg.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: My Web Search Bar BHO: {8eab99c1-f9ec-4b64-a4ba-d9bcae8779c2} - c:\program files\mywebsearchwb\bar\1.bin\W6BAR.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Browsing Protection Class: {c6867eb7-8350-4856-877f-93cf8ae3dc9c} - c:\program files\charter security suite\nrs\iescript\baselitmus.dll
BHO: {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers\YontooIEClient.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: Morpheus Toolbar: {3f3714a9-89a4-46be-8af3-d0c9d1fb03f9} - c:\program files\morpheusbar\bar\2.bin\MORPHBAR.DLL
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Browsing Protection Toolbar: {265eee8e-3228-44d3-aea5-f7fdf5860049} - c:\program files\charter security suite\nrs\iescript\baselitmus.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Sonic RecordNow!]
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [ZingSpooler] c:\program files\easy upload tools\drivers\spooler\ZingSpooler.exe
mRun: [MimBoot] c:\progra~1\musicm~1\musicm~2\mimboot.exe
mRun: [WildTangent CDA] "c:\program files\wildtangent\apps\cda\gamedrvr.exe" /startup "c:\program files\wildtangent\apps\cda\cdaEngine0500.dll"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Dell Photo AIO Printer 942] "c:\program files\dell photo aio printer 942\dlbubmgr.exe"
mRun: [DellMCM]
mRun: [DLBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLBUtime.dll,_RunDLLEntry@16
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [F-Secure Manager] "c:\program files\charter security suite\common\FSM32.EXE" /splash
mRun: [F-Secure TNB] "c:\program files\charter security suite\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\bryan\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\bryan\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\documents and settings\bryan\start menu\programs\startup\PowerReg Scheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imagem~1.lnk - c:\program files\pixela\imagemixer 3 se ver.4.5\transfer utility\CameraMonitor.exe
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\PowerReg Scheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicke~1.lnk - c:\program files\quicken\bagent.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: c:\program files\charter security suite\fsps\program\FSLSP.DLL
Trusted Zone: musicmatch.com\online
DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} - hxxps://install.charter.com/diskless/bin/ssctlsma.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://myvpn.ford.com/dana-cached/setup/JuniperSetupSP1.cab
DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} - hxxp://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,38
TCP: DhcpNameServer = 24.159.64.23 97.81.22.195 66.189.0.100
TCP: Interfaces\{344CA7AE-E4CE-4917-86A7-5B01A7F57C2F} : DhcpNameServer = 24.159.64.23 97.81.22.195 66.189.0.100
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: orkxaa.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, dblstssp.dll
.
============= SERVICES / DRIVERS ===============
.
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2011-7-10 42664]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2011-7-10 82120]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-5-3 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-5-3 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-5-3 656320]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\charter security suite\hips\drivers\fshs.sys [2011-7-10 68064]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2011-5-3 233976]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS;c:\program files\charter security suite\anti-virus\fsgk32st.exe [2011-7-10 215648]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-9-26 88176]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-4-19 993848]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-4-19 399416]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-8-1 24652]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\charter security suite\anti-virus\minifilter\fsgk.sys [2011-7-10 148648]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\charter security suite\orsp client\fsorsp.exe [2011-7-10 61088]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
R3 WinDriver;WinDriver kernel module;c:\windows\system32\drivers\windrvr.sys [2004-7-11 215640]
S0 fnyozi;fnyozi;c:\windows\system32\drivers\qpedfh.sys --> c:\windows\system32\drivers\qpedfh.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-6 135664]
S2 mrtRate;mrtRate; [x]
S3 ba304;ba304;\??\c:\docume~1\bryan\locals~1\temp\ba304.sys --> c:\docume~1\bryan\locals~1\temp\ba304.sys [?]
S3 cpuz132;cpuz132;\??\c:\docume~1\bryan\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\bryan\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 CVDMINDV;CVDMINDV;\??\c:\docume~1\bryan\locals~1\temp\cvdmindv.sys --> c:\docume~1\bryan\locals~1\temp\CVDMINDV.SYS [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-6 135664]
S3 imsfs;imsfs;c:\docume~1\kaylie\locals~1\temp\imsfs.sys [2007-7-14 17920]
S3 iserial;iserial;\??\c:\docume~1\bryan\locals~1\temp\iserial.sys --> c:\docume~1\bryan\locals~1\temp\iserial.sys [?]
S3 lpsched;lpsched;\??\c:\docume~1\bryan\locals~1\temp\lpsched.sys --> c:\docume~1\bryan\locals~1\temp\lpsched.sys [?]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-8-1 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-8-1 40552]
S3 omouhid;omouhid;\??\c:\docume~1\bryan\locals~1\temp\omouhid.sys --> c:\docume~1\bryan\locals~1\temp\omouhid.sys [?]
S3 qtape;qtape;\??\c:\docume~1\bryan\locals~1\temp\qtape.sys --> c:\docume~1\bryan\locals~1\temp\qtape.sys [?]
S3 rati1tux;rati1tux;c:\docume~1\kaylie\locals~1\temp\rati1tux.sys [2005-12-6 17920]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-1-12 371472]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-1-12 1117144]
S3 ssmbali;ssmbali;\??\c:\docume~1\bryan\locals~1\temp\ssmbali.sys --> c:\docume~1\bryan\locals~1\temp\ssmbali.sys [?]
S3 ta311;ta311;\??\c:\docume~1\bryan\locals~1\temp\ta311.sys --> c:\docume~1\bryan\locals~1\temp\ta311.sys [?]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2001-1-8 15576]
S3 xusbuhci;xusbuhci;\??\c:\docume~1\bryan\locals~1\temp\xusbuhci.sys --> c:\docume~1\bryan\locals~1\temp\xusbuhci.sys [?]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\charter security suite\anti-virus\win2k\fsfilter.sys [2011-7-10 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\charter security suite\anti-virus\win2k\fsrec.sys [2011-7-10 25184]
.
=============== Created Last 30 ================
.
2011-07-13 00:48:02 -------- d-----w- C:\savw_97_sa
2011-07-10 18:42:03 42664 ----a-w- c:\windows\system32\drivers\fsbts.sys
2011-07-10 18:38:39 82120 ----a-w- c:\windows\system32\drivers\fsdfw.sys
2011-07-10 18:24:53 -------- d-----w- c:\program files\Charter Security Suite
2011-07-10 18:18:20 -------- d-----w- c:\documents and settings\all users\application data\fssg
2011-07-10 18:16:39 -------- d-----w- c:\documents and settings\all users\application data\f-secure
.
==================== Find3M ====================
.
2011-06-18 14:35:16 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-04 14:13:33 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-06-04 14:13:29 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-29 14:11:30 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 14:11:20 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-29 00:57:17 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2005-10-02 12:26:15 774144 ----a-w- c:\program files\RngInterstitial.dll
.
============= FINISH: 22:35:13.85 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 7/9/2004 9:39:54 PM
System Uptime: 7/12/2011 7:00:52 PM (3 hours ago)
.
Motherboard: Dell Computer Corp. | | 0F4491
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2992/800mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 79.516 GiB free.
D: is CDROM (CDFS)
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is FIXED (NTFS) - 932 GiB total, 815.995 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP2441: 5/14/2011 5:40:34 AM - System Checkpoint
RP2442: 5/14/2011 8:06:12 PM - System Checkpoint
RP2443: 5/15/2011 8:41:56 PM - System Checkpoint
RP2444: 5/16/2011 10:14:11 PM - System Checkpoint
RP2445: 5/17/2011 10:29:15 PM - System Checkpoint
RP2446: 5/18/2011 11:20:11 PM - System Checkpoint
RP2447: 5/20/2011 8:56:11 AM - System Checkpoint
RP2448: 5/21/2011 12:30:02 PM - System Checkpoint
RP2449: 5/22/2011 1:20:16 PM - System Checkpoint
RP2450: 5/23/2011 4:43:35 PM - System Checkpoint
RP2451: 5/24/2011 5:21:26 PM - System Checkpoint
RP2452: 5/25/2011 6:21:23 PM - System Checkpoint
RP2453: 5/26/2011 6:43:15 PM - System Checkpoint
RP2454: 5/27/2011 7:43:15 PM - System Checkpoint
RP2455: 5/28/2011 9:25:37 PM - System Checkpoint
RP2456: 5/29/2011 9:55:25 PM - System Checkpoint
RP2457: 5/30/2011 10:44:21 PM - System Checkpoint
RP2458: 6/1/2011 1:13:29 AM - System Checkpoint
RP2459: 6/2/2011 1:37:39 AM - System Checkpoint
RP2460: 6/3/2011 10:04:58 AM - System Checkpoint
RP2461: 6/4/2011 9:49:01 AM - Removed Adobe Reader 8.2.6
RP2462: 6/4/2011 9:51:51 AM - Installed Adobe Reader X (10.0.1).
RP2463: 6/5/2011 11:05:52 AM - System Checkpoint
RP2464: 6/6/2011 11:42:03 AM - System Checkpoint
RP2465: 6/7/2011 11:49:16 AM - System Checkpoint
RP2466: 6/8/2011 7:12:05 PM - System Checkpoint
RP2467: 6/9/2011 11:01:31 PM - System Checkpoint
RP2468: 6/11/2011 7:41:07 PM - System Checkpoint
RP2469: 6/13/2011 9:55:50 AM - System Checkpoint
RP2470: 6/15/2011 9:49:48 AM - System Checkpoint
RP2471: 6/16/2011 6:13:31 PM - System Checkpoint
RP2472: 6/17/2011 6:52:32 PM - System Checkpoint
RP2473: 6/25/2011 10:05:09 AM - System Checkpoint
RP2474: 6/26/2011 10:55:42 AM - System Checkpoint
RP2475: 6/27/2011 12:22:58 PM - System Checkpoint
RP2476: 6/28/2011 12:48:04 PM - System Checkpoint
RP2477: 6/29/2011 2:39:13 PM - System Checkpoint
RP2478: 6/30/2011 2:40:52 PM - System Checkpoint
RP2479: 7/1/2011 2:49:56 PM - System Checkpoint
RP2480: 7/2/2011 3:12:21 PM - System Checkpoint
RP2481: 7/3/2011 3:38:36 PM - System Checkpoint
RP2482: 7/4/2011 5:16:14 PM - System Checkpoint
RP2483: 7/5/2011 6:33:21 PM - System Checkpoint
RP2484: 7/6/2011 8:45:10 PM - System Checkpoint
RP2485: 7/7/2011 8:09:48 PM - Removed Ask Toolbar.
RP2486: 7/7/2011 8:12:13 PM - Removed WeatherBug
RP2487: 7/8/2011 8:30:28 PM - System Checkpoint
RP2488: 7/9/2011 8:44:26 PM - System Checkpoint
RP2489: 7/10/2011 1:24:34 PM - psc 9.01 build 105 Installation
RP2490: 7/11/2011 2:18:34 PM - System Checkpoint
RP2491: 7/12/2011 6:20:03 PM - System Checkpoint
RP2492: 7/12/2011 7:02:35 PM - Restore Operation
.
==== Installed Programs ======================
.
3D Groove Playback Engine
Acrobat.com
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Reader X (10.1.0)
Adobe Shockwave Player 11.6
Adobe® Photoshop® Album Starter Edition 3.0
Alohabob PC Relocator Ultra Control
America Online (Choose which version to remove)
An American Tail MB
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Camera Suite 1.3
Arthur's Reading Games
Audacity 1.2.6
Audit Support Center 1.0
Banctec Service Agreement
BankshotBilliards
Barbie(TM) as The Princess and the Pauper Demo
Barbie(TM) Diaries High School Mystery
Barbie(TM) Fashion Show(TM) CD-ROM
BlackBerry App World Browser Plugin
BlackBerry Desktop Software 6.0.1
Bonjour
Cache Cleaner 4.2.0
Camera Support Core Library
Camera Window
Canon Camera Support Core Library
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon Utilities ZoomBrowser EX
Charter High Speed Internet Self-Installation Wizard
Charter Security Suite
Classic PhoneTools
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Dell Driver Download Manager
Dell Media Experience
Dell Networking Guide
Dell Photo AIO Printer 942
Dell Solution Center
Dell Support Center (Support Software)
DellSupport
Delta Force - Black Hawk Down
Digital Line Detect
Dinosaur Adventure 3-D
Disney's Daily Blast 2.0
Disney's Princess Fashion Boutique
Dream House 3D
Driver Whiz
Dropbox
DVDSentry
eMusic Download Manager
Express Burn
Express Rip
F-Secure PSC Prerequisites
Get High Speed Internet!
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Help and Support Customization
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows Media Format SDK (KB910998)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
ImageMixer 3 SE Ver.4.5 Transfer Utility
ImageMixer 3 SE Ver.4.5 Video Tools
ImageStation Easy Upload Tools
Intel(R) Extreme Graphics 2 Driver
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet
Internet Explorer Default Page
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Java Auto Updater
Java(TM) 6 Update 24
Juniper Networks Cache Cleaner 6.0.0
Learn2 Player (Uninstall Only)
Let's Ride 3 Day Eventing - Championship Season
Lets Ride Corral Club
Malwarebytes' Anti-Malware version 1.51.0.1200
Managed DirectX (0900)
McAfee Shredder
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Halo Trial
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Small Business Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
MixPad Audio Mixer
MobileMe Control Panel
Modem Helper
Morpheus Toolbar
Move Media Player
MovieEdit Task
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
Music Editor Free
Music Transfer Utility Ver.1.5
Musicmatch® Jukebox
Nancy Drew: Danger by Design
Nancy Drew: Danger on Deception Island
Nancy Drew: Ghost Dogs of Moon Lake
Nancy Drew: Last Train to Blue Moon Canyon
Nancy Drew: Legend of the Crystal Skull
Nancy Drew: Message in a Haunted Mansion
Nancy Drew: Ransom of the Seven Ships
Nancy Drew: Secret of Shadow Ranch
Nancy Drew: Secret of the Old Clock
Nancy Drew: Secret of the Scarlet Hand
Nancy Drew: Secrets Can Kill
Nancy Drew: Shadow at the Water's Edge
Nancy Drew: Stay Tuned For Danger
Nancy Drew: The Creature of Kapu Cave
Nancy Drew: The Curse of Blackmoor Manor
Nancy Drew: The Final Scene
Nancy Drew: The Haunted Carousel
Nancy Drew: The Haunting of Castle Malloy
Nancy Drew: The Phantom of Venice
Nancy Drew: Trail of the Twister
Nancy Drew: Treasure in the Royal Tower
Nancy Drew: Warnings at Waverly Academy
NCH Toolbox
NetWaiting
PhotoStitch
PowerDVD
Quicken 2004
Quicken Legal Business Pro 2004
QuickTime
RAW Image Task 1.1
RealArcade
RealPlayer
Rex!
Riding Star
RollerCoaster Tycoon 2 Triple Thrill Pack
Safari
SeaWorld Adventure Park Tycoon
Secunia PSI (2.0.0.3003)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Sesame Street Elmo's Art Workshop
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spirit (remove only)
Spyware Doctor with AntiVirus 8.0
Strawberry Shortcake - Amazing Cookie Party
Switch Sound File Converter
swMSM
Tarzan Activity Center
Terayon DOCSIS Modem
The Land Before Time Kindergarten Adventure
The White Wolf of Icicle Creek
Unity Web Player
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WavePad Sound Editor
WeatherBug Browser Bar - powered by MyWebSearch
WebFldrs XP
WildTangent Web Driver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
You Can Fly! with Tinker Bell
Zoo Tycoon 2 - African Adventure
Zoo Tycoon: Complete Collection
.
==== Event Viewer Messages From Past Week ========
.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 4:59:36 PM, error: Service Control Manager [7000] - The mrtRate service failed to start due to the following error: The system cannot find the file specified.
7/12/2011 6:01:37 PM, error: Print [6161] - The document Microsoft Word - resumedonna.doc owned by Bryan failed to print on printer Dell Photo AIO Printer 942. Data type: LEMF. Size of the spool file in bytes: 1387886. Number of bytes printed: 1387886. Total number of pages in the document: 1. Number of pages printed: 0. Client machine: \\OFFICE. Win32 error code returned by the print processor: 535 (0x217).
7/11/2011 8:06:41 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 000CF1F9DDAD has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
7/11/2011 12:13:54 AM, error: PlugPlayManager [11] - The device Root\LEGACY_FSBL\0000 disappeared from the system without first being prepared for removal.
7/10/2011 3:02:28 PM, error: F-Secure Gatekeeper [1] -
.
==== End Of File ===========================
www.malwarebytes.org
Database version: 7093
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/12/2011 9:07:59 PM
mbam-log-2011-07-12 (21-07-59).txt
Scan type: Quick scan
Objects scanned: 258767
Time elapsed: 37 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
GMER 1.0.15.15640 - http://www.gmer.net
Rootkit quick scan 2011-07-12 22:23:35
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 WDC_WD1600JD-75HBB0 rev.08.02D08
Running: wvbgr6ux.exe; Driver: C:\DOCUME~1\Bryan\LOCALS~1\Temp\pwtdapod.sys
---- System - GMER 1.0.15 ----
Code fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation) IoCreateDevice
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \Driver\Tcpip \Device\Ip fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\Tcp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\Udp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
Device \Driver\Tcpip \Device\RawIp fsdfw.sys (F-Secure Internet Shield Driver/F-Secure Corporation)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Run by Bryan at 22:29:38 on 2011-07-12
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.387 [GMT -5:00]
.
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: Charter Security Suite 9.01 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Charter Security Suite 9.01 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Charter Security Suite\Common\FSMA32.EXE
C:\Program Files\Charter Security Suite\Anti-Virus\FSGK32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Charter Security Suite\Common\FSHDLL32.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fsav32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Charter Security Suite\Common\FSM32.EXE
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\PIXELA\ImageMixer 3 SE Ver.4.5\Transfer Utility\CameraMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Documents and Settings\Bryan\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\dlbucoms.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.charter.net/
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
uURLSearchHooks: N/A: {d73f49b6-b51b-4d32-a3b7-bd04b8342f53} - c:\program files\morpheusbar\srchastt\2.bin\MBSRCAS.DLL
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PCTools Site Guard: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - c:\progra~1\spywar~1\tools\iesdsg.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: My Web Search Bar BHO: {8eab99c1-f9ec-4b64-a4ba-d9bcae8779c2} - c:\program files\mywebsearchwb\bar\1.bin\W6BAR.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Browsing Protection Class: {c6867eb7-8350-4856-877f-93cf8ae3dc9c} - c:\program files\charter security suite\nrs\iescript\baselitmus.dll
BHO: {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers\YontooIEClient.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: Morpheus Toolbar: {3f3714a9-89a4-46be-8af3-d0c9d1fb03f9} - c:\program files\morpheusbar\bar\2.bin\MORPHBAR.DLL
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Browsing Protection Toolbar: {265eee8e-3228-44d3-aea5-f7fdf5860049} - c:\program files\charter security suite\nrs\iescript\baselitmus.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Sonic RecordNow!]
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [ZingSpooler] c:\program files\easy upload tools\drivers\spooler\ZingSpooler.exe
mRun: [MimBoot] c:\progra~1\musicm~1\musicm~2\mimboot.exe
mRun: [WildTangent CDA] "c:\program files\wildtangent\apps\cda\gamedrvr.exe" /startup "c:\program files\wildtangent\apps\cda\cdaEngine0500.dll"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Dell Photo AIO Printer 942] "c:\program files\dell photo aio printer 942\dlbubmgr.exe"
mRun: [DellMCM]
mRun: [DLBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLBUtime.dll,_RunDLLEntry@16
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [F-Secure Manager] "c:\program files\charter security suite\common\FSM32.EXE" /splash
mRun: [F-Secure TNB] "c:\program files\charter security suite\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\bryan\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\bryan\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\documents and settings\bryan\start menu\programs\startup\PowerReg Scheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imagem~1.lnk - c:\program files\pixela\imagemixer 3 se ver.4.5\transfer utility\CameraMonitor.exe
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\PowerReg Scheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicke~1.lnk - c:\program files\quicken\bagent.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: c:\program files\charter security suite\fsps\program\FSLSP.DLL
Trusted Zone: musicmatch.com\online
DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} - hxxps://install.charter.com/diskless/bin/ssctlsma.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://myvpn.ford.com/dana-cached/setup/JuniperSetupSP1.cab
DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} - hxxp://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,38
TCP: DhcpNameServer = 24.159.64.23 97.81.22.195 66.189.0.100
TCP: Interfaces\{344CA7AE-E4CE-4917-86A7-5B01A7F57C2F} : DhcpNameServer = 24.159.64.23 97.81.22.195 66.189.0.100
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: orkxaa.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, dblstssp.dll
.
============= SERVICES / DRIVERS ===============
.
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2011-7-10 42664]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2011-7-10 82120]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-5-3 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-5-3 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-5-3 656320]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\charter security suite\hips\drivers\fshs.sys [2011-7-10 68064]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2011-5-3 233976]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS;c:\program files\charter security suite\anti-virus\fsgk32st.exe [2011-7-10 215648]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-9-26 88176]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-4-19 993848]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-4-19 399416]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-8-1 24652]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\charter security suite\anti-virus\minifilter\fsgk.sys [2011-7-10 148648]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\charter security suite\orsp client\fsorsp.exe [2011-7-10 61088]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
R3 WinDriver;WinDriver kernel module;c:\windows\system32\drivers\windrvr.sys [2004-7-11 215640]
S0 fnyozi;fnyozi;c:\windows\system32\drivers\qpedfh.sys --> c:\windows\system32\drivers\qpedfh.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-6 135664]
S2 mrtRate;mrtRate; [x]
S3 ba304;ba304;\??\c:\docume~1\bryan\locals~1\temp\ba304.sys --> c:\docume~1\bryan\locals~1\temp\ba304.sys [?]
S3 cpuz132;cpuz132;\??\c:\docume~1\bryan\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\bryan\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 CVDMINDV;CVDMINDV;\??\c:\docume~1\bryan\locals~1\temp\cvdmindv.sys --> c:\docume~1\bryan\locals~1\temp\CVDMINDV.SYS [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-6 135664]
S3 imsfs;imsfs;c:\docume~1\kaylie\locals~1\temp\imsfs.sys [2007-7-14 17920]
S3 iserial;iserial;\??\c:\docume~1\bryan\locals~1\temp\iserial.sys --> c:\docume~1\bryan\locals~1\temp\iserial.sys [?]
S3 lpsched;lpsched;\??\c:\docume~1\bryan\locals~1\temp\lpsched.sys --> c:\docume~1\bryan\locals~1\temp\lpsched.sys [?]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-8-1 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-8-1 40552]
S3 omouhid;omouhid;\??\c:\docume~1\bryan\locals~1\temp\omouhid.sys --> c:\docume~1\bryan\locals~1\temp\omouhid.sys [?]
S3 qtape;qtape;\??\c:\docume~1\bryan\locals~1\temp\qtape.sys --> c:\docume~1\bryan\locals~1\temp\qtape.sys [?]
S3 rati1tux;rati1tux;c:\docume~1\kaylie\locals~1\temp\rati1tux.sys [2005-12-6 17920]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-1-12 371472]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-1-12 1117144]
S3 ssmbali;ssmbali;\??\c:\docume~1\bryan\locals~1\temp\ssmbali.sys --> c:\docume~1\bryan\locals~1\temp\ssmbali.sys [?]
S3 ta311;ta311;\??\c:\docume~1\bryan\locals~1\temp\ta311.sys --> c:\docume~1\bryan\locals~1\temp\ta311.sys [?]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2001-1-8 15576]
S3 xusbuhci;xusbuhci;\??\c:\docume~1\bryan\locals~1\temp\xusbuhci.sys --> c:\docume~1\bryan\locals~1\temp\xusbuhci.sys [?]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\charter security suite\anti-virus\win2k\fsfilter.sys [2011-7-10 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\charter security suite\anti-virus\win2k\fsrec.sys [2011-7-10 25184]
.
=============== Created Last 30 ================
.
2011-07-13 00:48:02 -------- d-----w- C:\savw_97_sa
2011-07-10 18:42:03 42664 ----a-w- c:\windows\system32\drivers\fsbts.sys
2011-07-10 18:38:39 82120 ----a-w- c:\windows\system32\drivers\fsdfw.sys
2011-07-10 18:24:53 -------- d-----w- c:\program files\Charter Security Suite
2011-07-10 18:18:20 -------- d-----w- c:\documents and settings\all users\application data\fssg
2011-07-10 18:16:39 -------- d-----w- c:\documents and settings\all users\application data\f-secure
.
==================== Find3M ====================
.
2011-06-18 14:35:16 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-04 14:13:33 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-06-04 14:13:29 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-29 14:11:30 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 14:11:20 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-29 00:57:17 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2005-10-02 12:26:15 774144 ----a-w- c:\program files\RngInterstitial.dll
.
============= FINISH: 22:35:13.85 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 7/9/2004 9:39:54 PM
System Uptime: 7/12/2011 7:00:52 PM (3 hours ago)
.
Motherboard: Dell Computer Corp. | | 0F4491
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2992/800mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 79.516 GiB free.
D: is CDROM (CDFS)
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is FIXED (NTFS) - 932 GiB total, 815.995 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP2441: 5/14/2011 5:40:34 AM - System Checkpoint
RP2442: 5/14/2011 8:06:12 PM - System Checkpoint
RP2443: 5/15/2011 8:41:56 PM - System Checkpoint
RP2444: 5/16/2011 10:14:11 PM - System Checkpoint
RP2445: 5/17/2011 10:29:15 PM - System Checkpoint
RP2446: 5/18/2011 11:20:11 PM - System Checkpoint
RP2447: 5/20/2011 8:56:11 AM - System Checkpoint
RP2448: 5/21/2011 12:30:02 PM - System Checkpoint
RP2449: 5/22/2011 1:20:16 PM - System Checkpoint
RP2450: 5/23/2011 4:43:35 PM - System Checkpoint
RP2451: 5/24/2011 5:21:26 PM - System Checkpoint
RP2452: 5/25/2011 6:21:23 PM - System Checkpoint
RP2453: 5/26/2011 6:43:15 PM - System Checkpoint
RP2454: 5/27/2011 7:43:15 PM - System Checkpoint
RP2455: 5/28/2011 9:25:37 PM - System Checkpoint
RP2456: 5/29/2011 9:55:25 PM - System Checkpoint
RP2457: 5/30/2011 10:44:21 PM - System Checkpoint
RP2458: 6/1/2011 1:13:29 AM - System Checkpoint
RP2459: 6/2/2011 1:37:39 AM - System Checkpoint
RP2460: 6/3/2011 10:04:58 AM - System Checkpoint
RP2461: 6/4/2011 9:49:01 AM - Removed Adobe Reader 8.2.6
RP2462: 6/4/2011 9:51:51 AM - Installed Adobe Reader X (10.0.1).
RP2463: 6/5/2011 11:05:52 AM - System Checkpoint
RP2464: 6/6/2011 11:42:03 AM - System Checkpoint
RP2465: 6/7/2011 11:49:16 AM - System Checkpoint
RP2466: 6/8/2011 7:12:05 PM - System Checkpoint
RP2467: 6/9/2011 11:01:31 PM - System Checkpoint
RP2468: 6/11/2011 7:41:07 PM - System Checkpoint
RP2469: 6/13/2011 9:55:50 AM - System Checkpoint
RP2470: 6/15/2011 9:49:48 AM - System Checkpoint
RP2471: 6/16/2011 6:13:31 PM - System Checkpoint
RP2472: 6/17/2011 6:52:32 PM - System Checkpoint
RP2473: 6/25/2011 10:05:09 AM - System Checkpoint
RP2474: 6/26/2011 10:55:42 AM - System Checkpoint
RP2475: 6/27/2011 12:22:58 PM - System Checkpoint
RP2476: 6/28/2011 12:48:04 PM - System Checkpoint
RP2477: 6/29/2011 2:39:13 PM - System Checkpoint
RP2478: 6/30/2011 2:40:52 PM - System Checkpoint
RP2479: 7/1/2011 2:49:56 PM - System Checkpoint
RP2480: 7/2/2011 3:12:21 PM - System Checkpoint
RP2481: 7/3/2011 3:38:36 PM - System Checkpoint
RP2482: 7/4/2011 5:16:14 PM - System Checkpoint
RP2483: 7/5/2011 6:33:21 PM - System Checkpoint
RP2484: 7/6/2011 8:45:10 PM - System Checkpoint
RP2485: 7/7/2011 8:09:48 PM - Removed Ask Toolbar.
RP2486: 7/7/2011 8:12:13 PM - Removed WeatherBug
RP2487: 7/8/2011 8:30:28 PM - System Checkpoint
RP2488: 7/9/2011 8:44:26 PM - System Checkpoint
RP2489: 7/10/2011 1:24:34 PM - psc 9.01 build 105 Installation
RP2490: 7/11/2011 2:18:34 PM - System Checkpoint
RP2491: 7/12/2011 6:20:03 PM - System Checkpoint
RP2492: 7/12/2011 7:02:35 PM - Restore Operation
.
==== Installed Programs ======================
.
3D Groove Playback Engine
Acrobat.com
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Reader X (10.1.0)
Adobe Shockwave Player 11.6
Adobe® Photoshop® Album Starter Edition 3.0
Alohabob PC Relocator Ultra Control
America Online (Choose which version to remove)
An American Tail MB
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Camera Suite 1.3
Arthur's Reading Games
Audacity 1.2.6
Audit Support Center 1.0
Banctec Service Agreement
BankshotBilliards
Barbie(TM) as The Princess and the Pauper Demo
Barbie(TM) Diaries High School Mystery
Barbie(TM) Fashion Show(TM) CD-ROM
BlackBerry App World Browser Plugin
BlackBerry Desktop Software 6.0.1
Bonjour
Cache Cleaner 4.2.0
Camera Support Core Library
Camera Window
Canon Camera Support Core Library
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon Utilities ZoomBrowser EX
Charter High Speed Internet Self-Installation Wizard
Charter Security Suite
Classic PhoneTools
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Dell Driver Download Manager
Dell Media Experience
Dell Networking Guide
Dell Photo AIO Printer 942
Dell Solution Center
Dell Support Center (Support Software)
DellSupport
Delta Force - Black Hawk Down
Digital Line Detect
Dinosaur Adventure 3-D
Disney's Daily Blast 2.0
Disney's Princess Fashion Boutique
Dream House 3D
Driver Whiz
Dropbox
DVDSentry
eMusic Download Manager
Express Burn
Express Rip
F-Secure PSC Prerequisites
Get High Speed Internet!
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Help and Support Customization
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows Media Format SDK (KB910998)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
ImageMixer 3 SE Ver.4.5 Transfer Utility
ImageMixer 3 SE Ver.4.5 Video Tools
ImageStation Easy Upload Tools
Intel(R) Extreme Graphics 2 Driver
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet
Internet Explorer Default Page
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Java Auto Updater
Java(TM) 6 Update 24
Juniper Networks Cache Cleaner 6.0.0
Learn2 Player (Uninstall Only)
Let's Ride 3 Day Eventing - Championship Season
Lets Ride Corral Club
Malwarebytes' Anti-Malware version 1.51.0.1200
Managed DirectX (0900)
McAfee Shredder
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Halo Trial
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Small Business Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
MixPad Audio Mixer
MobileMe Control Panel
Modem Helper
Morpheus Toolbar
Move Media Player
MovieEdit Task
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
Music Editor Free
Music Transfer Utility Ver.1.5
Musicmatch® Jukebox
Nancy Drew: Danger by Design
Nancy Drew: Danger on Deception Island
Nancy Drew: Ghost Dogs of Moon Lake
Nancy Drew: Last Train to Blue Moon Canyon
Nancy Drew: Legend of the Crystal Skull
Nancy Drew: Message in a Haunted Mansion
Nancy Drew: Ransom of the Seven Ships
Nancy Drew: Secret of Shadow Ranch
Nancy Drew: Secret of the Old Clock
Nancy Drew: Secret of the Scarlet Hand
Nancy Drew: Secrets Can Kill
Nancy Drew: Shadow at the Water's Edge
Nancy Drew: Stay Tuned For Danger
Nancy Drew: The Creature of Kapu Cave
Nancy Drew: The Curse of Blackmoor Manor
Nancy Drew: The Final Scene
Nancy Drew: The Haunted Carousel
Nancy Drew: The Haunting of Castle Malloy
Nancy Drew: The Phantom of Venice
Nancy Drew: Trail of the Twister
Nancy Drew: Treasure in the Royal Tower
Nancy Drew: Warnings at Waverly Academy
NCH Toolbox
NetWaiting
PhotoStitch
PowerDVD
Quicken 2004
Quicken Legal Business Pro 2004
QuickTime
RAW Image Task 1.1
RealArcade
RealPlayer
Rex!
Riding Star
RollerCoaster Tycoon 2 Triple Thrill Pack
Safari
SeaWorld Adventure Park Tycoon
Secunia PSI (2.0.0.3003)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Sesame Street Elmo's Art Workshop
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spirit (remove only)
Spyware Doctor with AntiVirus 8.0
Strawberry Shortcake - Amazing Cookie Party
Switch Sound File Converter
swMSM
Tarzan Activity Center
Terayon DOCSIS Modem
The Land Before Time Kindergarten Adventure
The White Wolf of Icicle Creek
Unity Web Player
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WavePad Sound Editor
WeatherBug Browser Bar - powered by MyWebSearch
WebFldrs XP
WildTangent Web Driver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
You Can Fly! with Tinker Bell
Zoo Tycoon 2 - African Adventure
Zoo Tycoon: Complete Collection
.
==== Event Viewer Messages From Past Week ========
.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 8:09:39 AM, error: Service Control Manager [7031] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
7/5/2011 4:59:36 PM, error: Service Control Manager [7000] - The mrtRate service failed to start due to the following error: The system cannot find the file specified.
7/12/2011 6:01:37 PM, error: Print [6161] - The document Microsoft Word - resumedonna.doc owned by Bryan failed to print on printer Dell Photo AIO Printer 942. Data type: LEMF. Size of the spool file in bytes: 1387886. Number of bytes printed: 1387886. Total number of pages in the document: 1. Number of pages printed: 0. Client machine: \\OFFICE. Win32 error code returned by the print processor: 535 (0x217).
7/11/2011 8:06:41 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 000CF1F9DDAD has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
7/11/2011 12:13:54 AM, error: PlugPlayManager [11] - The device Root\LEGACY_FSBL\0000 disappeared from the system without first being prepared for removal.
7/10/2011 3:02:28 PM, error: F-Secure Gatekeeper [1] -
.
==== End Of File ===========================