This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] links redirecting

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Links from google and yahoo are redirecting to ad and search pages. I downloaded and installed Malwarebytes. On its first run it found two problems, which I removed. Here's that log. Malwarebytes' Anti-Malware 1.42 Database version: 3345 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 12/11/2009 10:09:41 AM mbam-log-2009-12-11 (10-09-41).txt Scan type: Quick Scan Objects scanned: 126118 Time elapsed: 10 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\martinde\Local Settings\Temp\579.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\spool\prtprocs\w32x86\3A.tmp (Malware.Packer) -> Quarantined and deleted successfully. After a reboot, the problem persisted and I found this web site. I followed the instructions are ran the ATF cleaner and then reran the Malwarebytes software. This time it found nothing - here's that log Malwarebytes' Anti-Malware 1.42 Database version: 3345 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 12/11/2009 10:47:07 AM mbam-log-2009-12-11 (10-47-07).txt Scan type: Quick Scan Objects scanned: 122481 Time elapsed: 7 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) And the problem is still there. Any suggestions for what I should do now?
Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Here are the two files from the first program:

Attach.txt

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/17/2009 12:11:51 PM
System Uptime: 12/11/2009 3:49:47 PM (2 hours ago)

Motherboard: Hewlett-Packard | | 099C
Processor: Intel® Pentium® M processor 2.00GHz | JP12 | 1995/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 56 GiB total, 20.712 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA

==== System Restore Points ===================

RP1: 8/17/2009 12:11:58 PM - System Checkpoint
RP2: 8/17/2009 12:14:25 PM - Installed HP Quick Launch Buttons
RP3: 8/17/2009 12:15:14 PM - Installed Windows XP Wdf01005.
RP4: 8/17/2009 2:33:08 PM - Installed Cisco Systems VPN Client 5.0.04.0300
RP5: 8/17/2009 2:35:41 PM - Installed Microsoft Visio Professional 2002 [English]
RP6: 8/17/2009 3:21:57 PM - Software Distribution Service 3.0
RP7: 8/17/2009 3:25:51 PM - Software Distribution Service 3.0
RP8: 8/17/2009 3:26:51 PM - Software Distribution Service 3.0
RP9: 8/17/2009 3:29:16 PM - Software Distribution Service 3.0
RP10: 8/17/2009 3:31:20 PM - Software Distribution Service 3.0
RP11: 8/17/2009 3:33:08 PM - Software Distribution Service 3.0
RP12: 8/17/2009 3:34:43 PM - Software Distribution Service 3.0
RP13: 8/17/2009 3:37:44 PM - Software Distribution Service 3.0
RP14: 8/17/2009 3:39:17 PM - Software Distribution Service 3.0
RP15: 8/17/2009 3:44:21 PM - Software Distribution Service 3.0
RP16: 8/17/2009 3:46:18 PM - Software Distribution Service 3.0
RP17: 8/17/2009 3:48:42 PM - Software Distribution Service 3.0
RP18: 8/17/2009 3:50:34 PM - Software Distribution Service 3.0
RP19: 8/17/2009 3:51:28 PM - Software Distribution Service 3.0
RP20: 8/17/2009 3:58:05 PM - Software Distribution Service 3.0
RP21: 8/17/2009 3:59:58 PM - Software Distribution Service 3.0
RP22: 8/17/2009 4:02:42 PM - Software Distribution Service 3.0
RP23: 8/17/2009 4:03:59 PM - Software Distribution Service 3.0
RP24: 8/17/2009 4:11:05 PM - Software Distribution Service 3.0
RP25: 8/17/2009 4:12:14 PM - Software Distribution Service 3.0
RP26: 8/17/2009 4:22:37 PM - Software Distribution Service 3.0
RP27: 8/18/2009 3:19:28 AM - Software Distribution Service 3.0
RP28: 8/18/2009 3:20:20 AM - Software Distribution Service 3.0
RP29: 8/18/2009 3:21:19 AM - Software Distribution Service 3.0
RP30: 8/19/2009 2:06:50 PM - Installed Rational Suite AnalystStudio
RP31: 8/20/2009 2:56:12 PM - Unsigned driver install
RP32: 8/24/2009 8:56:24 AM - Software Distribution Service 3.0
RP33: 8/24/2009 9:02:39 AM - Software Distribution Service 3.0
RP34: 9/30/2009 11:41:43 AM - Software Distribution Service 3.0
RP35: 9/30/2009 11:45:19 AM - Software Distribution Service 3.0
RP36: 9/30/2009 11:46:53 AM - Software Distribution Service 3.0
RP37: 9/30/2009 11:48:37 AM - Software Distribution Service 3.0
RP38: 9/30/2009 11:50:01 AM - Software Distribution Service 3.0
RP39: 9/30/2009 11:51:36 AM - Software Distribution Service 3.0
RP40: 9/30/2009 11:53:09 AM - Software Distribution Service 3.0
RP41: 9/30/2009 11:54:15 AM - Software Distribution Service 3.0
RP42: 10/31/2009 9:07:55 AM - Software Distribution Service 3.0
RP43: 10/31/2009 9:10:39 AM - Software Distribution Service 3.0
RP44: 10/31/2009 9:12:39 AM - Software Distribution Service 3.0
RP45: 10/31/2009 9:16:59 AM - Software Distribution Service 3.0
RP46: 11/3/2009 9:28:37 AM - Software Distribution Service 3.0
RP47: 11/3/2009 9:31:23 AM - Software Distribution Service 3.0
RP48: 11/3/2009 9:32:32 AM - Software Distribution Service 3.0
RP49: 11/3/2009 9:33:33 AM - Software Distribution Service 3.0
RP50: 11/13/2009 7:02:16 AM - Software Distribution Service 3.0
RP51: 11/13/2009 7:06:39 AM - Installed Windows XP KB915865.
RP52: 11/13/2009 7:07:15 AM - Installed Windows NLSDownlevelMapping.
RP53: 11/13/2009 7:07:41 AM - Installed Windows IDNMitigationAPIs.
RP54: 11/13/2009 7:09:17 AM - Installed Windows Internet Explorer 7.
RP55: 11/13/2009 7:10:06 AM - Software Distribution Service 3.0
RP56: 11/13/2009 8:05:37 AM - Software Distribution Service 3.0
RP57: 11/16/2009 8:59:02 AM - Software Distribution Service 3.0
RP58: 11/29/2009 3:33:25 PM - Installed iTunes

==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Reader 7.0.8
Adobe Shockwave Player 11
Agere Systems AC'97 Modem
Amazon MP3 Downloader 1.0.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
Canon FAXPHONE L80
Chinese (Traditional) Language Support
Cisco Systems VPN Client 5.0.04.0300
Clarify ClearConfigurator 10.1.1
Clarify eFrontOffice10.1 SR1 Client for Oracle 8i
Clarify eFrontOffice10.1 SR1 eBusiness Client
Compatibility Pack for the 2007 Office system
Corel WinDVD 9
CutePDF Writer 2.7
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB297694)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB910678)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB970653-v3)
HP Quick Launch Buttons 6.40 F1
HP Wireless Assistant
Intel PROSet Wireless
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless WiFi Software
iTunes
J2SE Runtime Environment 5.0 Update 14
Japanese Language Support
Java 2 Runtime Environment, SE v1.4.2_12
Java™ 6 Update 3
Java™ 6 Update 6
LocalAdminWMIProvider
Malwarebytes' Anti-Malware
McAfee Agent
McAfee AntiSpyware Enterprise Module
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Visio Viewer 2007
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visio Professional 2002 [English]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Move Media Player
Mozilla Firefox (3.5.5)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
QuickTime
Rational Suite AnalystStudio
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
SMS Advanced Client
Synaptics Pointing Device Driver
Time Zone Data Update Tool for Microsoft Office Outlook
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911164)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB916846)
Update for Windows XP (KB920342)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925876)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB973815)
VNC Free Edition 4.1.3
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB897327
WinZip 11.2

==== Event Viewer Messages From Past Week ========

12/7/2009 8:29:18 AM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
12/5/2009 8:20:07 AM, error: DCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.
12/4/2009 7:59:34 AM, error: NETLOGON [5719] - No Domain Controller is available for domain ARCHQ due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
12/11/2009 7:33:36 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Rational Web Platform, HTTP server service to connect.
12/11/2009 10:12:05 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
12/10/2009 6:11:37 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
12/10/2009 6:11:37 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
12/10/2009 4:03:25 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/10/2009 4:01:00 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

==== End Of File ===========================

DDS.txt

DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 17:52:21.00 on Fri 12/11/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.5.0_14
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.344 [GMT -5:00]

AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Rational\ClearQuest\cqweb\cqregsvr\cqregsvr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Rational\common\java\jre\bin\java.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rational\common\rwp\bin\jk_nt_service.exe
C:\Program Files\Rational\common\rwp\bin\jk_nt_service.exe
C:\Program Files\Rational\common\java\jre\bin\java.exe
C:\Program Files\Rational\common\java\jre\bin\java.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Rational\ClearQuest\cqweb\cqserver\requestmgr.exe
C:\Program Files\Rational\common\java\jre\bin\java.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Network Associates\Common Framework\udaterui.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
c:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\martinde\Local Settings\Temporary Internet Files\Content.IE5\XUG2KM71\dds[1].pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uWindow Title = Microsoft Internet Explorer provided by American Red Cross, IE6
uInternet Settings,ProxyOverride = ;*.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
uRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [McAfeeUpdaterUI] "c:\program files\network associates\common framework\udaterui.exe" /StartedFromRunKey
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [SoDA Startup] c:\program files\rational\sodaword\wizards\SodaStartup.exe StartUp
mRun: [MpsOnn] c:\windows\system32\spool\drivers\w32x86\3\MpsOnn.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRunOnce: [NoIE4StubProcessing] c:\windows\system32\reg.exe delete "hklm\software\microsoft\active setup\Installed Components" /v "NoIE4StubProcessing" /f
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{51fb15f4-ad27-43bc-ad4b-dd0354fb6bbd}\Icon3E5562ED7.ico
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: NoStrCmpLogical = 1 (0x1)
mPolicies-explorer: NoWebServices = 1 (0x1)
mPolicies-explorer: NoOnlinePrintsWizard = 1 (0x1)
mPolicies-explorer: NoPublishingWizard = 1 (0x1)
mPolicies-explorer: DisableLocalMachineRunOnce = 1 (0x1)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-explorer: PreXPSP2ShellProtocolBehavior = 0 (0x0)
mPolicies-system: LogonType = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: bionet.org
Trusted Zone: redcross.net
Trusted Zone: redcross.org
Trusted Zone: bionet.org
Trusted Zone: redcross.net
Trusted Zone: redcross.org
Trusted Zone: redcross.org\crossnet
Trusted Zone: redcross.org\Newcrossnet
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\martinde\applic~1\mozilla\firefox\profiles\3jq1ljcn.default\
FF - plugin: c:\documents and settings\martinde\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJPI150_14.dll
FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPOJI610.dll

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2008-10-6 31816]
R2 cqregsvr;Rational ClearQuest Registry Server;c:\program files\rational\clearquest\cqweb\cqregsvr\cqregsvr.exe [2003-2-20 74112]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2009-1-16 103744]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2008-10-6 144704]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2008-10-6 54608]
R2 Rational_Web_Platform_Tomcat;Rational Web Platform, servlet engine;c:\program files\rational\common\rwp\bin\jk_nt_service.exe [2003-3-28 66416]
R2 Rational_Web_Platform_Tomcat_ReqWeb;Rational Web Platform, ReqWeb servlet engine;c:\program files\rational\common\rwp\bin\jk_nt_service.exe [2003-3-28 66416]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R2 requestmgr;Rational ClearQuest Request Manager;c:\program files\rational\clearquest\cqweb\cqserver\requestmgr.exe [2003-2-20 74112]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-8-17 193840]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2009-1-18 87808]
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2009-11-30 72904]
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2009-11-30 34344]
R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2009-11-30 177672]
R3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S2 Rational_Web_Platform;Rational Web Platform, HTTP server;c:\program files\rational\common\rwp\bin\rwp.exe [2003-3-28 11648]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\bin\ONRSD.EXE [2000-10-19 411244]

=============== Created Last 30 ================

2009-12-11 14:56:16 0 d—–w- c:\docume~1\martinde\applic~1\Malwarebytes
2009-12-11 14:55:47 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-11 14:55:44 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-11 14:55:43 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-11 14:55:42 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 19:46:02 0 d—–w- C:\Quarantine
2009-11-30 18:08:38 72904 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-11-30 18:08:38 64488 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2009-11-30 18:08:38 34344 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-11-30 18:08:37 52136 —-a-w- c:\windows\system32\drivers\mfetdik.sys
2009-11-30 18:08:37 177672 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-11-30 18:07:38 0 d—–w- c:\program files\McAfee
2009-11-30 18:07:38 0 d—–w- c:\program files\common files\McAfee
2009-11-30 15:28:07 0 d—–w- c:\program files\Amazon
2009-11-29 20:38:42 55404 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-29 20:34:54 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-29 20:34:54 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-11-29 20:33:35 0 d—–w- c:\program files\iPod
2009-11-29 20:33:31 0 d—–w- c:\program files\iTunes
2009-11-29 20:33:31 0 d—–w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-29 20:33:05 0 d—–w- c:\program files\Bonjour
2009-11-29 20:29:48 40448 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-11-29 20:29:48 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-11-13 12:03:24 0 d—–w- c:\windows\network diagnostic
2009-11-13 12:01:40 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-13 12:01:40 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2009-11-13 12:01:40 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-11-13 12:01:39 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2009-11-13 12:01:39 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-13 12:01:39 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2009-11-13 12:01:38 991232 -c—-w- c:\windows\system32\dllcache\ieframe.dll.mui
2009-11-13 12:01:38 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2009-11-13 12:01:37 6067200 -c—-w- c:\windows\system32\dllcache\ieframe.dll

==================== Find3M ====================


============= FINISH: 17:55:52.93 ===============

and here's the last file gmer.txt
GMER 1.0.15.15279 - http://www.gmer.net
Rootkit scan 2009-12-12 11:34:35
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\martinde\LOCALS~1\Temp\kwddrfoc.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xA94EF1AB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xA94EF12B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xA94EF1D5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xA94EF13F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xA94EF16B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xA94EF1FF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xA94EF117]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xA94EF1BF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xA94EF155]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xA94EF181]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xA94EF197]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xA94EF215]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xA94EF1E9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device -> \Driver\atapi \Device\Harddisk0\DR0 8651A618

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
I am running McAfee and don't seem to have the option to turn it off. When I right click on the M symbol, there's no option to exit and if I select Virus Scan enterprise from the submenu that opens, the option to disable On Access scan is greyed out. This computer was set up by my employer so I assume they set it up to prevent me from disabling the virus scan.
Hi,

try this:

Open McAfee Security Centre
  • Under Common Tasks click on Home
  • Click Computer Files
  • Click Configure
  • Make sure the following are disabled by ticking the "Off" button.

    Virus protection
    Spyware protection
    System Guards Protection
    Script Scanning Protection (you may have to scroll down to see it)

  • Next, select never for "When to re-enable real time scanning"
  • and click OK.
I don't see McAfee Security Center either when I right click the icon or on the list of programs from the start menu. When I select McAffe there, my only choice are: On Access scan, on demand scan and virus scan console. And I don't see any options for turning anything off on any of those choices.
I wasn't able to turn it off from task manager either - said I didn't have access - so I proceeded with the run of combo fix. Here is the log file from that:

ComboFix 09-12-11.05 - MartinDe 12/12/2009 13:23:48.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.556 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

hxxp://NHQDTCSMS3.archq.ri.redcross.net:80
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-11-12 to 2009-12-12 )))))))))))))))))))))))))))))))
.

2009-12-11 16:28 . 2009-12-11 16:28 0 —-a-w- c:\windows\nsreg.dat
2009-12-11 16:28 . 2009-12-11 16:28 ——– d—–w- c:\documents and settings\martinde\Local Settings\Application Data\Mozilla
2009-12-11 14:56 . 2009-12-11 14:56 ——– d—–w- c:\documents and settings\martinde\Application Data\Malwarebytes
2009-12-11 14:55 . 2009-12-03 21:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-11 14:55 . 2009-12-11 14:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-11 14:55 . 2009-12-03 21:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-11 14:55 . 2009-12-11 14:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 19:46 . 2009-12-12 18:23 ——– d—–w- C:\Quarantine
2009-11-30 18:09 . 2009-11-30 18:09 265348 —-a-w- c:\documents and settings\All Users\Application Data\Network Associates\Common Framework\Current\VSEMAS850000\Install\0000\VSE85MAS.exe
2009-11-30 18:08 . 2008-10-07 01:50 72904 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-11-30 18:08 . 2008-10-07 01:50 64488 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2009-11-30 18:08 . 2008-10-07 01:50 34344 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-11-30 18:08 . 2008-10-07 01:50 52136 —-a-w- c:\windows\system32\drivers\mfetdik.sys
2009-11-30 18:08 . 2008-10-07 01:50 177672 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-11-30 18:08 . 2009-11-30 18:08 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-30 18:07 . 2009-11-30 18:07 ——– d—–w- c:\program files\McAfee
2009-11-30 18:07 . 2009-11-30 18:07 ——– d—–w- c:\program files\Common Files\McAfee
2009-11-30 18:07 . 2009-11-30 18:07 2585872 —-a-w- c:\documents and settings\All Users\Application Data\Network Associates\Common Framework\Current\VIRUSCAN8600\Install\0000\WindowsInstaller-KB893803-v2-x86.exe
2009-11-30 18:03 . 2009-11-30 18:03 114176 —-a-w- c:\documents and settings\All Users\Application Data\Network Associates\Common Framework\Current\VIRUSCAN8600\Install\0000\UnInstX64.exe
2009-11-30 18:03 . 2009-11-30 18:03 106496 —-a-w- c:\documents and settings\All Users\Application Data\Network Associates\Common Framework\Current\VIRUSCAN8600\Install\0000\UnInst.exe
2009-11-30 18:03 . 2009-11-30 18:03 95568 —-a-w- c:\documents and settings\All Users\Application Data\Network Associates\Common Framework\Current\VIRUSCAN8600\Install\0000\setupvse.exe
2009-11-30 15:29 . 2009-11-30 15:29 ——– d—–w- c:\documents and settings\martinde\Application Data\Amazon
2009-11-30 15:28 . 2009-11-30 15:28 ——– d—–w- c:\program files\Amazon
2009-11-29 20:38 . 2009-11-29 20:38 55404 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-29 20:35 . 2009-11-29 20:37 ——– d—–w- c:\documents and settings\martinde\Application Data\Apple Computer
2009-11-29 20:34 . 2009-05-18 19:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-29 20:34 . 2008-04-17 18:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-11-29 20:33 . 2009-11-29 20:33 ——– d—–w- c:\program files\iPod
2009-11-29 20:33 . 2009-11-29 20:34 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-29 20:33 . 2009-11-29 20:34 ——– d—–w- c:\program files\iTunes
2009-11-29 20:33 . 2009-11-29 20:33 ——– d—–w- c:\program files\Bonjour
2009-11-29 20:31 . 2009-11-29 20:32 ——– d—–w- c:\program files\QuickTime
2009-11-29 20:30 . 2009-11-29 20:30 ——– d—–w- c:\documents and settings\martinde\Local Settings\Application Data\Apple
2009-11-29 20:30 . 2009-11-29 20:30 ——– d—–w- c:\program files\Apple Software Update
2009-11-29 20:29 . 2009-08-29 00:42 40448 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-11-29 20:29 . 2009-08-29 00:42 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-11-29 20:28 . 2009-11-29 20:33 ——– d—–w- c:\program files\Common Files\Apple
2009-11-29 20:28 . 2009-11-29 20:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-11-28 18:48 . 2009-11-28 18:48 ——– d—–w- c:\documents and settings\martinde\Local Settings\Application Data\Help
2009-11-13 12:01 . 2009-08-29 07:36 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-13 12:01 . 2009-08-29 07:36 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-11-13 12:01 . 2009-08-29 07:36 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2009-11-13 12:01 . 2009-08-29 07:36 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-13 12:01 . 2009-08-29 07:36 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2009-11-13 12:01 . 2009-08-28 10:28 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2009-11-13 12:01 . 2009-06-29 08:33 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2009-11-13 12:01 . 2009-08-29 07:36 6067200 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-11-12 22:07 . 2009-11-12 22:07 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-11 16:28 . 2009-10-24 14:29 ——– d—–w- c:\documents and settings\martinde\Application Data\Move Networks
2009-11-30 18:09 . 2007-10-18 17:50 ——– d—–w- c:\program files\Network Associates
2009-11-30 18:08 . 2007-10-18 17:50 ——– d—–w- c:\program files\Common Files\Network Associates
2009-11-29 20:33 . 2007-12-31 17:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-24 14:29 . 2009-10-24 14:29 127872 —-a-w- c:\documents and settings\martinde\Application Data\Move Networks\uninstall.exe
2009-10-24 14:29 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\martinde\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-10-05 16:12 . 2009-10-05 16:12 71600 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-27 18:06 . 2009-09-27 18:06 1961720 —-a-w- c:\documents and settings\martinde\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\udaterui.exe" [2009-01-16 136512]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"AGRSMMSG"="AGRSMMSG.exe" [2004-08-24 88363]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-06-03 177456]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1310720]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2008-08-20 1191936]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SoDA Startup"="c:\program files\Rational\SoDAWord\Wizards\SodaStartup.exe" [2004-06-18 135168]
"MpsOnn"="c:\windows\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe" [2007-05-14 28232]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-10-07 111952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
VPN Client.lnk - c:\windows\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico [2009-8-17 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
"NoWebServices"= 1 (0x1)
"NoOnlinePrintsWizard"= 1 (0x1)
"NoPublishingWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"PreXPSP2ShellProtocolBehavior"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1981611971-3051485146-2440493642-1024\Scripts\Logon\0\0]
"Script"=LocalUserLogon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1981611971-3051485146-2440493642-500\Scripts\Logon\0\0]
"Script"=LocalUserLogon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2026909314-1939897469-926709054-6946\Scripts\Logon\0\0]
"Script"=LocalUserLogon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2026909314-1939897469-926709054-9392\Scripts\Logon\0\0]
"Script"=LocalUserLogon.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowOutboundDestinationUnreachable"= 1 (0x1)

R2 regi;regi;c:\windows\system32\drivers\regi.sys [4/17/2007 7:09 PM 11032]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [1/18/2009 9:08 AM 87808]
S2 cqregsvr;Rational ClearQuest Registry Server;c:\program files\Rational\ClearQuest\cqweb\cqregsvr\cqregsvr.exe [2/20/2003 10:04 PM 74112]
S2 Rational_Web_Platform;Rational Web Platform, HTTP server;c:\program files\Rational\Common\rwp\bin\rwp.exe [3/28/2003 9:17 AM 11648]
S2 Rational_Web_Platform_Tomcat;Rational Web Platform, servlet engine;c:\program files\Rational\Common\rwp\bin\jk_nt_service.exe [3/28/2003 9:16 AM 66416]
S2 Rational_Web_Platform_Tomcat_ReqWeb;Rational Web Platform, ReqWeb servlet engine;c:\program files\Rational\Common\rwp\bin\jk_nt_service.exe [3/28/2003 9:16 AM 66416]
S2 requestmgr;Rational ClearQuest Request Manager;c:\program files\Rational\ClearQuest\cqweb\cqserver\requestmgr.exe [2/20/2003 10:04 PM 74112]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/17/2009 11:14 AM 193840]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ORA81\bin\ONRSD.EXE [10/19/2000 10:55 AM 411244]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Trusted Zone: bionet.org
Trusted Zone: redcross.net
Trusted Zone: redcross.org
Trusted Zone: bionet.org
Trusted Zone: redcross.net
Trusted Zone: redcross.org
Trusted Zone: redcross.org\crossnet
Trusted Zone: redcross.org\Newcrossnet
FF - ProfilePath - c:\documents and settings\martinde\Application Data\Mozilla\Firefox\Profiles\3jq1ljcn.default\
FF - plugin: c:\documents and settings\martinde\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJPI150_14.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPOJI610.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-12 13:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-12-12 13:35:28
ComboFix-quarantined-files.txt 2009-12-12 18:35

Pre-Run: 22,134,140,928 bytes free
Post-Run: 22,153,527,296 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 981A537ED77288166145F21A890EDF62
Hi,

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
wow - that last one took over 4 hours to run. Here are the two reports, first from MBAM Malwarebytes' Anti-Malware 1.42 Database version: 3350 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 12/12/2009 2:56:38 PM mbam-log-2009-12-12 (14-56-38).txt Scan type: Quick Scan Objects scanned: 124060 Time elapsed: 8 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) And from Kas: KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, December 12, 2009 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, December 12, 2009 20:03:46 Records in database: 3364065 Scan settings scan using the following database extended Scan archives yes Scan e-mail databases yes Scan area My Computer C:\ D:\ F:\ K:\ O:\ Scan statistics Objects scanned 90878 Threats found 2 Infected objects found 6 Suspicious objects found 0 Scan duration 05:09:57 File name Threat Threats count C:\Program Files\RealVNC\VNC4\WinVNC4.exe/C:\Program Files\RealVNC\VNC4\WinVNC4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1 C:\Documents and Settings\martinde\My Documents\vnc-4_1_3-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 2 C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1 C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.TDSS.y 1 Selected area has been scanned.
Hi, The items found by kaspersky are either in quarantine, or not a concern. Please post a fresh DDS and attach.txt and advise how your computer is running now and if there are any outstanding issues.
It seems to be behaving properly now. Here are the two files you requested from DDS Attach.txt UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 8/17/2009 12:11:51 PM System Uptime: 12/12/2009 1:51:58 PM (8 hours ago) Motherboard: Hewlett-Packard | | 099C Processor: Intel® Pentium® M processor 2.00GHz | JP12 | 1995/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 56 GiB total, 20.501 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Cisco Systems VPN Adapter Device ID: ROOT\NET\0000 Manufacturer: Cisco Systems Name: Cisco Systems VPN Adapter PNP Device ID: ROOT\NET\0000 Service: CVirtA ==== System Restore Points =================== RP1: 8/17/2009 12:11:58 PM - System Checkpoint RP2: 8/17/2009 12:14:25 PM - Installed HP Quick Launch Buttons RP3: 8/17/2009 12:15:14 PM - Installed Windows XP Wdf01005. RP4: 8/17/2009 2:33:08 PM - Installed Cisco Systems VPN Client 5.0.04.0300 RP5: 8/17/2009 2:35:41 PM - Installed Microsoft Visio Professional 2002 [English] RP6: 8/17/2009 3:21:57 PM - Software Distribution Service 3.0 RP7: 8/17/2009 3:25:51 PM - Software Distribution Service 3.0 RP8: 8/17/2009 3:26:51 PM - Software Distribution Service 3.0 RP9: 8/17/2009 3:29:16 PM - Software Distribution Service 3.0 RP10: 8/17/2009 3:31:20 PM - Software Distribution Service 3.0 RP11: 8/17/2009 3:33:08 PM - Software Distribution Service 3.0 RP12: 8/17/2009 3:34:43 PM - Software Distribution Service 3.0 RP13: 8/17/2009 3:37:44 PM - Software Distribution Service 3.0 RP14: 8/17/2009 3:39:17 PM - Software Distribution Service 3.0 RP15: 8/17/2009 3:44:21 PM - Software Distribution Service 3.0 RP16: 8/17/2009 3:46:18 PM - Software Distribution Service 3.0 RP17: 8/17/2009 3:48:42 PM - Software Distribution Service 3.0 RP18: 8/17/2009 3:50:34 PM - Software Distribution Service 3.0 RP19: 8/17/2009 3:51:28 PM - Software Distribution Service 3.0 RP20: 8/17/2009 3:58:05 PM - Software Distribution Service 3.0 RP21: 8/17/2009 3:59:58 PM - Software Distribution Service 3.0 RP22: 8/17/2009 4:02:42 PM - Software Distribution Service 3.0 RP23: 8/17/2009 4:03:59 PM - Software Distribution Service 3.0 RP24: 8/17/2009 4:11:05 PM - Software Distribution Service 3.0 RP25: 8/17/2009 4:12:14 PM - Software Distribution Service 3.0 RP26: 8/17/2009 4:22:37 PM - Software Distribution Service 3.0 RP27: 8/18/2009 3:19:28 AM - Software Distribution Service 3.0 RP28: 8/18/2009 3:20:20 AM - Software Distribution Service 3.0 RP29: 8/18/2009 3:21:19 AM - Software Distribution Service 3.0 RP30: 8/19/2009 2:06:50 PM - Installed Rational Suite AnalystStudio RP31: 8/20/2009 2:56:12 PM - Unsigned driver install RP32: 8/24/2009 8:56:24 AM - Software Distribution Service 3.0 RP33: 8/24/2009 9:02:39 AM - Software Distribution Service 3.0 RP34: 9/30/2009 11:41:43 AM - Software Distribution Service 3.0 RP35: 9/30/2009 11:45:19 AM - Software Distribution Service 3.0 RP36: 9/30/2009 11:46:53 AM - Software Distribution Service 3.0 RP37: 9/30/2009 11:48:37 AM - Software Distribution Service 3.0 RP38: 9/30/2009 11:50:01 AM - Software Distribution Service 3.0 RP39: 9/30/2009 11:51:36 AM - Software Distribution Service 3.0 RP40: 9/30/2009 11:53:09 AM - Software Distribution Service 3.0 RP41: 9/30/2009 11:54:15 AM - Software Distribution Service 3.0 RP42: 10/31/2009 9:07:55 AM - Software Distribution Service 3.0 RP43: 10/31/2009 9:10:39 AM - Software Distribution Service 3.0 RP44: 10/31/2009 9:12:39 AM - Software Distribution Service 3.0 RP45: 10/31/2009 9:16:59 AM - Software Distribution Service 3.0 RP46: 11/3/2009 9:28:37 AM - Software Distribution Service 3.0 RP47: 11/3/2009 9:31:23 AM - Software Distribution Service 3.0 RP48: 11/3/2009 9:32:32 AM - Software Distribution Service 3.0 RP49: 11/3/2009 9:33:33 AM - Software Distribution Service 3.0 RP50: 11/13/2009 7:02:16 AM - Software Distribution Service 3.0 RP51: 11/13/2009 7:06:39 AM - Installed Windows XP KB915865. RP52: 11/13/2009 7:07:15 AM - Installed Windows NLSDownlevelMapping. RP53: 11/13/2009 7:07:41 AM - Installed Windows IDNMitigationAPIs. RP54: 11/13/2009 7:09:17 AM - Installed Windows Internet Explorer 7. RP55: 11/13/2009 7:10:06 AM - Software Distribution Service 3.0 RP56: 11/13/2009 8:05:37 AM - Software Distribution Service 3.0 RP57: 11/16/2009 8:59:02 AM - Software Distribution Service 3.0 RP58: 11/29/2009 3:33:25 PM - Installed iTunes ==== Installed Programs ====================== 32 Bit HP CIO Components Installer Adobe Flash Player 10 ActiveX Adobe Reader 7.0.8 Adobe Shockwave Player 11 Agere Systems AC'97 Modem Amazon MP3 Downloader 1.0.5 Apple Application Support Apple Mobile Device Support Apple Software Update Bonjour Canon FAXPHONE L80 Chinese (Traditional) Language Support Cisco Systems VPN Client 5.0.04.0300 Clarify ClearConfigurator 10.1.1 Clarify eFrontOffice10.1 SR1 Client for Oracle 8i Clarify eFrontOffice10.1 SR1 eBusiness Client Compatibility Pack for the 2007 Office system Corel WinDVD 9 CutePDF Writer 2.7 High Definition Audio Driver Package - KB888111 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB297694) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB910678) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB970653-v3) HP Quick Launch Buttons 6.40 F1 HP Wireless Assistant Intel PROSet Wireless Intel® Graphics Media Accelerator Driver Intel® PROSet/Wireless WiFi Software iTunes J2SE Runtime Environment 5.0 Update 14 Japanese Language Support Java 2 Runtime Environment, SE v1.4.2_12 Java™ 6 Update 3 Java™ 6 Update 6 LocalAdminWMIProvider Malwarebytes' Anti-Malware McAfee Agent McAfee AntiSpyware Enterprise Module McAfee VirusScan Enterprise Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Office Visio Viewer 2007 Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visio Professional 2002 [English] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Move Media Player Mozilla Firefox (3.5.5) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) QuickTime Rational Suite AnalystStudio Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944533) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) SMS Advanced Client Synaptics Pointing Device Driver Time Zone Data Update Tool for Microsoft Office Outlook Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911164) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB916846) Update for Windows XP (KB920342) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB925876) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955839) Update for Windows XP (KB973815) VNC Free Edition 4.1.3 WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB883667 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB897327 WinZip 11.2 ==== Event Viewer Messages From Past Week ======== 12/7/2009 8:29:18 AM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period. 12/5/2009 8:20:07 AM, error: DCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. 12/5/2009 8:17:43 AM, error: NETLOGON [5719] - No Domain Controller is available for domain ARCHQ due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator. 12/12/2009 1:22:44 PM, error: Service Control Manager [7034] - The Rational ClearQuest Request Manager service terminated unexpectedly. It has done this 1 time(s). 12/12/2009 1:15:28 PM, error: Service Control Manager [7034] - The Rational Web Platform, HTTP server service terminated unexpectedly. It has done this 1 time(s). 12/12/2009 1:15:25 PM, error: Service Control Manager [7034] - The Rational Web Platform, servlet engine service terminated unexpectedly. It has done this 1 time(s). 12/12/2009 1:15:25 PM, error: Service Control Manager [7034] - The Rational Web Platform, ReqWeb servlet engine service terminated unexpectedly. It has done this 1 time(s). 12/12/2009 1:15:25 PM, error: Service Control Manager [7034] - The Rational ClearQuest Registry Server service terminated unexpectedly. It has done this 1 time(s). 12/11/2009 7:33:36 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Rational Web Platform, HTTP server service to connect. 12/11/2009 10:12:05 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 12/10/2009 6:11:37 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory. 12/10/2009 6:11:37 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver. 12/10/2009 4:03:25 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 12/10/2009 4:01:00 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. ==== End Of File =========================== and DDS.txt DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 21:39:15.42 on Sat 12/12/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.5.0_14 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.523 [GMT -5:00] AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\WiFi\bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Rational\ClearQuest\cqweb\cqregsvr\cqregsvr.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Rational\common\java\jre\bin\java.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Rational\common\rwp\bin\jk_nt_service.exe C:\Program Files\Rational\common\rwp\bin\jk_nt_service.exe C:\Program Files\Rational\common\java\jre\bin\java.exe C:\Program Files\Rational\common\java\jre\bin\java.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files\Rational\ClearQuest\cqweb\cqserver\requestmgr.exe C:\Program Files\Rational\common\java\jre\bin\java.exe C:\Program Files\RealVNC\VNC4\WinVNC4.exe C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe C:\WINDOWS\system32\CCM\CcmExec.exe C:\Program Files\Rational\common\rwp\bin\rwp.exe C:\Program Files\Rational\common\rwp\bin\rotatelogs.exe C:\Program Files\Rational\common\rwp\bin\rotatelogs.exe C:\Program Files\Rational\common\rwp\bin\rwp.exe C:\Program Files\Rational\common\rwp\bin\rotatelogs.exe C:\Program Files\Rational\common\rwp\bin\rotatelogs.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Network Associates\Common Framework\udaterui.exe C:\Program Files\Network Associates\Common Framework\McTray.exe C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe c:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\martinde\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = ;*.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll uRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [McAfeeUpdaterUI] "c:\program files\network associates\common framework\udaterui.exe" /StartedFromRunKey mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [SoDA Startup] c:\program files\rational\sodaword\wizards\SodaStartup.exe StartUp mRun: [MpsOnn] c:\windows\system32\spool\drivers\w32x86\3\MpsOnn.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{51fb15f4-ad27-43bc-ad4b-dd0354fb6bbd}\Icon3E5562ED7.ico uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: NoStrCmpLogical = 1 (0x1) mPolicies-explorer: NoWebServices = 1 (0x1) mPolicies-explorer: NoOnlinePrintsWizard = 1 (0x1) mPolicies-explorer: NoPublishingWizard = 1 (0x1) mPolicies-explorer: NoWelcomeScreen = 1 (0x1) mPolicies-explorer: PreXPSP2ShellProtocolBehavior = 0 (0x0) mPolicies-system: LogonType = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL Trusted Zone: bionet.org Trusted Zone: redcross.net Trusted Zone: redcross.org Trusted Zone: bionet.org Trusted Zone: redcross.net Trusted Zone: redcross.org Trusted Zone: redcross.org\crossnet Trusted Zone: redcross.org\Newcrossnet DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_14-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\martinde\applic~1\mozilla\firefox\profiles\3jq1ljcn.default\ FF - plugin: c:\documents and settings\martinde\application data\move networks\plugins\npqmp071503000010.dll FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava11.dll FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava12.dll FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava13.dll FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava14.dll FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJava32.dll FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPJPI150_14.dll FF - plugin: c:\program files\java\jre1.5.0_14\bin\NPOJI610.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2008-10-6 31816] R2 cqregsvr;Rational ClearQuest Registry Server;c:\program files\rational\clearquest\cqweb\cqregsvr\cqregsvr.exe [2003-2-20 74112] R2 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2009-1-16 103744] R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2008-10-6 144704] R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2008-10-6 54608] R2 Rational_Web_Platform;Rational Web Platform, HTTP server;c:\program files\rational\common\rwp\bin\rwp.exe [2003-3-28 11648] R2 Rational_Web_Platform_Tomcat;Rational Web Platform, servlet engine;c:\program files\rational\common\rwp\bin\jk_nt_service.exe [2003-3-28 66416] R2 Rational_Web_Platform_Tomcat_ReqWeb;Rational Web Platform, ReqWeb servlet engine;c:\program files\rational\common\rwp\bin\jk_nt_service.exe [2003-3-28 66416] R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032] R2 requestmgr;Rational ClearQuest Request Manager;c:\program files\rational\clearquest\cqweb\cqserver\requestmgr.exe [2003-2-20 74112] R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-8-17 193840] R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2009-1-18 87808] R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2009-11-30 72904] R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2009-11-30 34344] R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2009-11-30 177672] S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\bin\ONRSD.EXE [2000-10-19 411244] S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952] =============== Created Last 30 ================ 2009-12-12 18:12:40 0 d-sha-r- C:\cmdcons 2009-12-12 18:10:32 77312 —-a-w- c:\windows\MBR.exe 2009-12-12 18:10:29 261632 —-a-w- c:\windows\PEV.exe 2009-12-12 18:10:29 161792 —-a-w- c:\windows\SWREG.exe 2009-12-12 18:10:28 98816 —-a-w- c:\windows\sed.exe 2009-12-11 14:56:16 0 d—–w- c:\docume~1\martinde\applic~1\Malwarebytes 2009-12-11 14:55:47 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-11 14:55:44 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-12-11 14:55:43 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-12-11 14:55:42 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-11-30 19:46:02 0 d—–w- C:\Quarantine 2009-11-30 18:08:38 72904 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2009-11-30 18:08:38 64488 —-a-w- c:\windows\system32\drivers\mfeapfk.sys 2009-11-30 18:08:38 34344 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2009-11-30 18:08:37 52136 —-a-w- c:\windows\system32\drivers\mfetdik.sys 2009-11-30 18:08:37 177672 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2009-11-30 18:07:38 0 d—–w- c:\program files\McAfee 2009-11-30 18:07:38 0 d—–w- c:\program files\common files\McAfee 2009-11-30 15:28:07 0 d—–w- c:\program files\Amazon 2009-11-29 20:38:42 55404 —ha-w- c:\windows\system32\mlfcache.dat 2009-11-29 20:34:54 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-11-29 20:34:54 107368 —-a-w- c:\windows\system32\GEARAspi.dll 2009-11-29 20:33:35 0 d—–w- c:\program files\iPod 2009-11-29 20:33:31 0 d—–w- c:\program files\iTunes 2009-11-29 20:33:31 0 d—–w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-11-29 20:33:05 0 d—–w- c:\program files\Bonjour 2009-11-29 20:29:48 40448 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2009-11-29 20:29:48 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll 2009-11-13 12:03:24 0 d—–w- c:\windows\network diagnostic 2009-11-13 12:01:40 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll 2009-11-13 12:01:40 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll 2009-11-13 12:01:40 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll 2009-11-13 12:01:39 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll 2009-11-13 12:01:39 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll 2009-11-13 12:01:39 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe 2009-11-13 12:01:38 991232 -c—-w- c:\windows\system32\dllcache\ieframe.dll.mui 2009-11-13 12:01:38 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat 2009-11-13 12:01:37 6067200 -c—-w- c:\windows\system32\dllcache\ieframe.dll ==================== Find3M ==================== ============= FINISH: 21:40:06.76 ===============

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI