logs pasted..
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit quick scan 2011-01-30 22:32:03
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e ST3160828AS rev.8.03
Running: pfnse0jh.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fxtdapow.sys
---- Threads - GMER 1.0.15 ----
Thread System [4:116] F773A9B0
Thread System [4:120] F7752D68
Thread System [4:140] F769CCEA
---- Services - GMER 1.0.15 ----
Service (*** hidden *** ) [MANUAL] vbma841d <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 1/29/2011 9:48:44 AM
System Uptime: 1/30/2011 10:23:40 PM (0 hours ago)
Motherboard: Dell Inc. | | 0JC474
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2793/800mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 144 GiB total, 76.9 GiB free.
D: is CDROM (UDF)
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP12: 1/29/2011 11:42:34 AM - Software Distribution Service 3.0
RP13: 1/29/2011 1:36:00 PM - Software Distribution Service 3.0
RP14: 1/29/2011 1:41:31 PM - Software Distribution Service 3.0
==== Installed Programs ======================
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.4.1
Adobe Shockwave Player 11.5
Adobe® Photoshop® Album Starter Edition 3.2
AOLIcon
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATT-PRT22
Bonjour
Business Contact Manager for Microsoft Outlook 2010
CameraHelperMsi
Cars - Radiator Springs Adventures
CCleaner
CCScore
CharlottesWeb (remove only)
Compatibility Pack for the 2007 Office system
Cooking Academy
CouponBar
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CustomerResearchQFolder
Definition update for Microsoft Office 2010 (KB982726)
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Support Center (Support Software)
Dell System Restore
DellSupport
DeviceFunctionQFolder
DeviceManagementQFolder
Digital Content Portal
Direct Show Ogg Vorbis Filter (remove only)
DocumentViewerQFolder
Doggie Dash (remove only)
Dream Day Honeymoon (remove only)
Dream Day Wedding (remove only)
Dress Shop Hop (remove only)
e-Sword
EarthLink setup files
EducateU
erLT
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSTOOLS
essvatgt
eSupportQFolder
Fairy Godmother Tycoon (remove only)
Fast Browser Search (My Face LOL)
FullDPAppQFolder
Google Toolbar for Internet Explorer
Hotfix 2055 for SQL Server 2000 ENU (KB960082)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows XP (KB952287)
HP Update
Intel(R) 537EP V9x DF PCI Modem
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections Drivers
Intel(R) PROSet for Wired Connections
Internet Explorer Default Page
iTunes
Java Auto Updater
Java(TM) 6 Update 23
JS World 2nd Grade
JSWorld2GMain
JSWPFCom
JSWPFGrade2
Junk Mail filter update
Kids Cam Show and Share Creativity Center
Kitty Luv v1.8
Kodak EasyShare software
Learn2 Player (Uninstall Only)
Logitech Vid HD
Logitech Webcam Software
Logitech Webcam Software Driver Package
LWS Facebook
LWS Gallery
LWS Help_main
LWS Launcher
LWS Motion Detection
LWS Pictures And Video
LWS Video Mask Maker
LWS VideoEffects
LWS Webcam Software
LWS WLM Plugin
LWS YouTube Plugin
Malwarebytes' Anti-Malware
Mavis Beacon Teaches Typing 15
MCU
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.0 Hotfix (KB979904)
Microsoft Application Error Reporting
Microsoft Chart Controls for Microsoft .NET Framework 3.5
Microsoft Choice Guard
Microsoft Money 2007
Microsoft Money Shared Libraries
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Communicator 2007 R2
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office Live Add-in 1.4
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Office XP Web Components
Microsoft Plus! Digital Media Edition Installer
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 14
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server 2008
Microsoft SQL Server 2008 Browser
Microsoft SQL Server 2008 Common Files
Microsoft SQL Server 2008 Database Engine Services
Microsoft SQL Server 2008 Database Engine Shared
Microsoft SQL Server 2008 Native Client
Microsoft SQL Server 2008 RsFx Driver
Microsoft SQL Server 2008 Setup Support Files
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
Microsoft SQL Server VSS Writer
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft® Office Language Pack 2010 – English (Business Contact Manager for Microsoft Outlook 2010)
Middle School Reading
Modem Event Monitor
Monopoly Here & Now Edition (remove only)
MSN
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
netbrdg
NHRA Drag Racing
OfotoXMI
Perfect Optimizer 5.2
PowerDVD 5.5
Presto! Forms 3.50.01
Presto! PageManager 7.12.02
Puppy Luv
QuickTime
QuickTime 3.0
RealPlayer
Rocky & Bullwinkle's Know-It-All Quiz Game
Safari
Samsung Master
SanDisk TransferMate
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office 2010 (KB2289078)
Security Update for Microsoft Office 2010 (KB2289161)
Security Update for Microsoft Publisher 2010 (KB2409055)
Security Update for Microsoft Word 2010 (KB2345000)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Segoe UI
Service Pack 1 for SQL Server 2008 (KB968369)
SFR
SHASTA
skin0001
SKINXSDK
SMV transcoder 3.4
Sonic Encoders
SpaceStationSim
Sql Server Customer Experience Improvement Program
staticcr
Subtextual for Microsoft Office Outlook
SureThing Decal Maker
Teacher's Toolbox 4.0
Teddy Factory
The Game Of Life
tooltips
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2010 (KB2202188)
Update for Microsoft Office 2010 (KB2413186)
Update for Microsoft OneNote 2010 (KB2433299)
Update for Microsoft Outlook Social Connector (KB2289116)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
Visual Studio Tools for the Office system 3.0 Runtime
VPRINTOL
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 11
Windows XP Media Center Edition 2005 KB908246
WIRELESS
Yahoo! Internet Mail
Yahoo! Mail Advisor
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update
==== Event Viewer Messages From Past Week ========
1/26/2011 7:10:25 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/26/2011 7:07:39 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/26/2011 7:00:57 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/26/2011 6:23:37 AM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/26/2011 6:11:51 AM, error: Service Control Manager [7000] - The Windows Installer service failed to start due to the following error: Access is denied.
1/26/2011 6:11:51 AM, error: DCOM [10005] - DCOM got error "%5" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
1/26/2011 6:11:26 AM, error: Service Control Manager [7023] - The Network Location Awareness (NLA) service terminated with the following error: The specified procedure could not be found.
1/26/2011 6:03:07 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Imapi
1/26/2011 6:02:17 AM, error: Service Control Manager [7000] - The McAfee Real-time Scanner service failed to start due to the following error: Access is denied.
1/26/2011 6:02:17 AM, error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The system cannot find the path specified.
1/26/2011 6:02:16 AM, error: Service Control Manager [7000] - The avast! Antivirus service failed to start due to the following error: Access is denied.
1/26/2011 6:02:09 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000010' while processing the file '000000c0.sym' on the volume 'ACPI#PNP0303#2&da1a3ff&0'. It has stopped monitoring the volume.
1/25/2011 9:01:18 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
1/25/2011 9:01:08 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
1/25/2011 8:49:39 AM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/25/2011 8:42:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f070: Microsoft .NET Framework 1.0 SP3 Security Update for Windows XP Tablet PC and Media Center (KB979904).
1/25/2011 8:42:18 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB973686).
1/25/2011 8:38:48 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 3.5 SP1 and .NET Framework 2.0 SP2 Update for Windows Server 2003 and Windows XP x86 (KB982524).
1/25/2011 8:38:38 AM, error: Service Control Manager [7034] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s).
1/25/2011 8:29:43 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNASvc with arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
1/25/2011 8:29:37 PM, error: NtServicePack [4373] - Windows XP KB942288-v3 installation failed.
An internal error occurred.
1/25/2011 8:29:09 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f070: Microsoft .NET Framework 1.0 Service Pack 3 Security Update for Windows XP Tablet PC and Media Center (KB953295).
1/25/2011 8:28:40 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL
1/25/2011 8:28:40 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
1/25/2011 8:28:40 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/25/2011 8:28:40 PM, error: Service Control Manager [7001] - The fssfltr service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/25/2011 8:28:40 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/25/2011 8:28:40 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
1/25/2011 8:28:40 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/25/2011 8:28:40 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/25/2011 8:28:17 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
1/25/2011 8:17:48 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Microsoft Windows Installer 3.1.
1/25/2011 8:17:46 PM, error: NtServicePack [4373] - Windows XP KB942288-v3 installation failed.
An internal error occurred.
1/25/2011 8:17:32 PM, error: NtServicePack [4373] - Windows XP KB942288-v3 installation failed.
An internal error occurred.
1/25/2011 8:07:12 PM, error: NtServicePack [4373] - Windows XP KB942288-v3 installation failed.
An internal error occurred.
1/25/2011 7:56:53 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000010' while processing the file '00000001.sym' on the volume 'ACPI#PNP0303#2&da1a3ff&0'. It has stopped monitoring the volume.
1/25/2011 7:45:52 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000010' while processing the file 'L' on the volume 'ACPI#PNP0303#2&da1a3ff&0'. It has stopped monitoring the volume.
1/25/2011 7:37:36 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007054f: Microsoft Windows Installer 3.1.
1/25/2011 7:37:31 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/25/2011 7:37:03 PM, error: Service Control Manager [7034] - The McAfee Security Scan Component Host Service service terminated unexpectedly. It has done this 1 time(s).
1/25/2011 7:03:15 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/25/2011 7:00:36 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/25/2011 6:49:43 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/25/2011 6:45:11 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/25/2011 6:35:54 PM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/25/2011 6:13:48 AM, error: Service Control Manager [7034] - The avast! Web Scanner service terminated unexpectedly. It has done this 1 time(s).
1/25/2011 6:13:48 AM, error: Service Control Manager [7034] - The avast! Mail Scanner service terminated unexpectedly. It has done this 1 time(s).
1/25/2011 6:13:48 AM, error: Service Control Manager [7034] - The avast! Antivirus service terminated unexpectedly. It has done this 1 time(s).
1/25/2011 6:13:48 AM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/25/2011 11:00:31 AM, error: Service Control Manager [7034] - The McAfee Scanner service terminated unexpectedly. It has done this 1 time(s).
1/25/2011 10:59:25 AM, error: Windows Installer 3.1 [4373] - Windows Installer KB893803v2 installation failed.
An internal error occurred.
1/25/2011 10:57:04 AM, error: DCOM [10005] - DCOM got error "%5" attempting to start the service McShield with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
1/24/2011 1:12:37 PM, error: W32Time [34] - The time service has detected that the system time needs to be changed by +165393940 seconds. The time service will not change the system time by more than +54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|192.168.1.97:123->207.46.197.32:123) is working properly.
==== End Of File ===========================
DDS (Ver_10-12-12.02) - NTFSx86 MINIMAL
Run by Administrator at 22:43:43.28 on Sun 01/30/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1740 [GMT -5:00]
AV: McAfee VirusScan *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *Enabled*
============== Running Processes ===============
"\\.\globalroot\Device\svchost.exe\svchost.exe"
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\explorer.exe
C:\0download\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://bfc.myway.com/search/de_srchlft.html
uDefault_Page_URL = hxxp://www.dell4me.com/myway
mSearchAssistant =
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: BrowserHelper Class: {8a9d74f9-560b-4fe7-abeb-3b2e638e5cd6} - c:\program files\sgpsa\SearchAssistant.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Search Assistant: {f0626a63-410b-45e2-99a1-3f2475b2d695} - c:\program files\sgpsa\BHO.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [YMailAdvisor] "c:\program files\yahoo!\common\YMailAdvisor.exe"
mRun: [trioService] "c:\progra~1\freeze.com\3d falling leaves\\trioService.exe "
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [LXCJCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCJtime.dll,_RunDLLEntry@16
mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [Corel Photo Downloader] c:\program files\corel\corel photo album 6\MediaDetect.exe
mRun: [Communicator] "c:\program files\microsoft office communicator\communicator.exe" /fromrunkey
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\npjpi160_23.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
LSP: mswsock.dll
DPF: {0CE0F418-1010-442D-871C-3454827DD539} - hxxp://www.facefun.com/FaceFun_webinstall/FaceFun_product.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/MyFunCardsInitialSetup1.0.1.1.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1295959555953
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://centerforwritingexcellence.webex.com/client/T27LB/webex/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
============= SERVICES / DRIVERS ===============
S1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-5-31 214664]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-4-18 54752]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-26 135664]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2010-7-13 93320]
S2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2010-7-13 359952]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2010-7-13 144704]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2010-7-13 606736]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-7-13 79816]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-7-13 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2010-7-13 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2010-7-13 40552]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-3-30 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
S4 SQLAgent$MSSMLBIZ;SQL Server Agent (MSSMLBIZ);c:\program files\microsoft sql server\mssql10.mssmlbiz\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
=============== Created Last 30 ================
2011-01-31 03:22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-31 03:22:04 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-31 03:22:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-30 13:01:27 -------- d-----w- c:\docume~1\admini~1\applic~1\Avira
2011-01-30 02:52:14 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-30 02:43:50 -------- d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
2011-01-29 23:56:25 -------- d-----w- c:\docume~1\admini~1\applic~1\SUPERAntiSpyware.com
2011-01-29 23:55:39 -------- d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes
2011-01-29 19:49:05 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2011-01-29 16:41:45 -------- d-----w- c:\windows\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
2011-01-29 16:22:55 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-01-29 16:22:17 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-01-29 16:13:16 2186880 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-01-29 16:13:16 2063744 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-01-29 16:13:16 2021888 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-01-29 16:13:15 2143744 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-01-29 16:12:47 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll
2011-01-29 16:12:25 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-01-29 16:12:24 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-01-29 16:12:23 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-01-29 16:12:23 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-01-29 16:12:23 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-01-29 16:12:23 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-01-29 16:12:23 11076096 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-01-29 16:12:00 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll
2011-01-29 16:12:00 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll
2011-01-29 15:30:39 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-01-29 15:09:25 135168 ----a-w- c:\windows\system32\igfxres.dll
2011-01-29 14:47:59 30208 -c--a-w- c:\windows\system32\dllcache\sm81w.dll
2011-01-29 14:46:58 8192 -c--a-w- c:\windows\system32\dllcache\httpmb51.dll
2011-01-29 14:41:14 16384 ----a-w- c:\windows\system32\netfxperf.dll
2011-01-29 14:41:12 131072 ----a-w- c:\windows\system32\mscoree.dll
2011-01-29 14:20:49 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-01-29 14:20:49 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-01-29 14:20:49 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-01-29 14:20:49 13312 ----a-w- c:\windows\system32\irclass.dll
2011-01-29 14:20:42 22339 ----a-r- c:\windows\SET116.tmp
2011-01-29 14:20:42 10559 ----a-r- c:\windows\SET117.tmp
2011-01-29 14:20:30 13753 ----a-r- c:\windows\SETD2.tmp
2011-01-29 14:20:26 1086058 ----a-r- c:\windows\SETC6.tmp
2011-01-29 14:20:26 106147 ----a-r- c:\windows\SETC3.tmp
2011-01-29 12:06:49 2855 ----a-w- c:\windows\system32\msiexec.PIF
2011-01-28 00:51:06 -------- d-----w- c:\program files\FixCleaner
2011-01-28 00:14:46 -------- d-sh--w- c:\documents and settings\administrator\IECompatCache
2011-01-28 00:12:38 -------- d-sh--w- c:\documents and settings\administrator\PrivacIE
2011-01-27 00:55:17 297808 ----a-w- c:\windows\mscoree.dll
2011-01-26 00:08:38 -------- d-----w- c:\program files\Perfect Optimizer
2011-01-25 23:50:33 -------- d-----w- C:\0download
2011-01-25 23:48:04 -------- d-----w- C:\wuagent
2011-01-25 23:37:40 -------- d-----w- c:\docume~1\alluse~1\applic~1\MFAData
2011-01-25 13:21:44 -------- d-----w- c:\program files\CCleaner
2011-01-25 04:52:19 -------- d-s---w- c:\windows\Downloaded Program Files
2011-01-25 04:51:50 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2011-01-25 04:51:50 16384 ----a-w- c:\program files\internet explorer\connection wizard\isignup.exe
2011-01-25 01:58:30 22339 ----a-w- c:\windows\SET114.tmp
2011-01-25 01:58:30 10559 ----a-w- c:\windows\SET115.tmp
2011-01-25 01:58:19 13753 ----a-w- c:\windows\SETD1.tmp
2011-01-25 01:58:17 1086058 ----a-w- c:\windows\SETC5.tmp
2011-01-25 01:58:16 106147 ----a-w- c:\windows\SETC2.tmp
2011-01-25 00:22:12 -------- d-----w- c:\windows\system32\CatRoot_bak
==================== Find3M ====================
2010-11-29 22:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 22:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-17 23:44:36 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2010-11-12 23:53:06 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 21:34:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: ST3160828AS rev.8.03 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x8A56C9C0]
3 CLASSPNP[0xF763805B] -> nt!IofCallDriver[0x804E37D5] -> [0x8A4CB3F0]
\Driver\Disk[0x8A0CC310] -> IRP_MJ_CREATE -> 0xF769C134
kernel: MBR read successfully
_asm { CLI ; MOV AX, 0x0; MOV SS, AX; MOV SP, 0x7c00; STI ; MOV DS, AX; CLD ; MOV CX, 0x80; MOV SI, SP; MOV DI, 0x600; MOV ES, AX; REP MOVSD ; JMP FAR 0x0:0x62f; }
user & kernel MBR OK
============= FINISH: 22:44:00.60 ===============