DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by SXR0621 at 12:21:20 on 2011-11-08
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2712 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
.
============== Pseudo HJT Report ===============
.
uWindow Title = Windows Internet Explorer provided by Stanley Black & Decker
uStart Page = hxxp://ecentral.stanleyblackanddecker.com
uDefault_Page_URL = hxxp://ecentral.stanleyblackanddecker.com
uInternet Settings,ProxyOverride = <local>
mSearchAssistant = hxxp://search.live.com/sphome.aspx
uURLSearchHooks: H - No File
BHO: {0ca976d7-64df-4db5-b339-7a4fc1263d92} - c:\documents and settings\sxr0621\local settings\application data\NetworkWin32.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Privacy Protection] c:\documents and settings\all users\application data\privacy.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Communicator] "c:\program files\microsoft office communicator\communicator.exe" /fromrunkey
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [NuTCSetupEnviron] c:\progra~1\mkstoo~1\bin\ncoeenv.exe
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\sxr0621\startm~1\programs\startup\launch~1.lnk - c:\documents and settings\sxr0621\application data\verizon\ua_ar\UtilityApplication.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{f3c1de9e-5e16-4ba9-b854-7b53a45e3579}\Icon3E5562ED7.ico
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
uPolicies-explorer: ForceActiveDesktopOn = 1 (0x1)
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
uPolicies-system: WallpaperStyle = 0
uPolicies-system: Wallpaper = c:\sbd-helpdesk\wallpapers\B1_North_America.bmp
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: %SystemRoot%\system32\nutafun4.dll
Trusted Zone: mcafee.com
Trusted Zone: stanleyworks.com\reset
Trusted Zone: mcafee.com
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxps://www.apple.com/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230565262639
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1230565259755
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8BA1621C-F6E9-47C5-A55D-2F4BAB913B2B} - hxxps://reset.stanleyworks.com/CachedCredUtil.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{6722E379-1377-45EB-B90D-3DC2F83DEC66} : DhcpNameServer = 10.128.7.192 10.108.254.27 10.111.254.27
TCP: Interfaces\{B445EB3A-1716-443A-A861-83C36B4F8C86} : DhcpNameServer = 192.168.0.1
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: {72B7C0F0-6036-48D7-A0C9-4FF886785E15} - "c:\program files\hummingbird\connectivity\13.00\accessories\HumSettings.exe" INSTALL=ALL NoFreeWhenWOW64=1 LOGGINGLEVEL=5
mASetup: {D9B934D0-6A20-450E-9F69-F5595636C28E} - "c:\program files\hummingbird\connectivity\13.00\accessories\HumSettings.exe" INSTALL=ALL NoFreeWhenWOW64=1 LOGGINGLEVEL=5
.
============= SERVICES / DRIVERS ===============
.
R0 a320raid;a320raid;c:\windows\system32\drivers\a320raid.sys [2007-7-18 218112]
S0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-9-29 344712]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2009-10-5 65584]
S2 ASCLCSSrv;DataStage Multi-Client Manager Service;c:\ibm\informationserver\mcm\ClientSwitcherService.exe [2011-9-29 69632]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-6-1 55152]
S2 McAfeeEngineService;McAfee Engine Service;c:\program files\mcafee\virusscan enterprise\engineserver.exe [2010-8-25 22816]
S2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2010-10-15 120128]
S2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\mcshield.exe [2010-8-25 147984]
S2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\vstskmgr.exe [2010-8-25 66880]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-9-29 69192]
S2 MKSAUTH;MKSAUTH;c:\windows\system32\mksauth.exe [2007-7-25 94168]
S2 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\microsoft sql server\100\dts\binn\MsDtsSrvr.exe [2008-7-10 218136]
S2 NuTCRACKERService;NuTCRACKER Service;c:\windows\system32\nutsrv4.exe [2008-3-28 336168]
S2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2009-7-19 4446752]
S2 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\microsoft sql server\msrs10.mssqlserver\reporting services\reportserver\bin\ReportingServicesService.exe [2008-7-10 1106968]
S2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2010-6-11 59904]
S3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [2010-6-10 42672]
S3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2008-10-15 113664]
S3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2008-10-15 32808]
S3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [2010-6-10 167080]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2008-10-14 244368]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
S3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2007-8-27 87936]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2010-6-10 235520]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-10-15 110080]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-9-29 91896]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-9-29 43192]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-9-29 66536]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
S4 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\microsoft sql server\mssql10.mssqlserver\mssql\binn\fdlauncher.exe [2008-7-10 31256]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
.
=============== Created Last 30 ================
.
2011-11-08 16:39:43 0 ---ha-w- c:\windows\system32\xodjpgqxfg.tmp
2011-11-08 16:32:47 -------- d-----w- c:\documents and settings\sxr0621\application data\Malwarebytes
2011-11-08 16:32:43 -------- d-----w- c:\documents and settings\all users\application data\PC Tools
2011-11-08 16:21:18 0 ----a-w- c:\windows\system32\w32apiw.dll
2011-11-08 16:21:16 -------- d-----w- c:\documents and settings\sxr0621\application data\nCleaner
2011-11-08 16:21:10 -------- d-----w- c:\program files\NKProds
2011-11-08 13:54:37 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-11-08 09:14:42 843264 ----a-w- c:\documents and settings\all users\application data\privacy.exe
2011-11-07 11:43:52 271360 ----a-w- c:\documents and settings\sxr0621\local settings\application data\NetworkWin32.dll
2011-11-07 01:29:56 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-11-07 01:29:56 -------- d-----w- c:\windows\system32\wbem\Repository
2011-11-04 10:42:52 -------- d-----w- c:\documents and settings\sxr0621\application data\8CA7D
2011-11-03 01:57:52 -------- d-----w- c:\documents and settings\sxr0621\application data\DFBE8
2011-11-03 01:57:51 -------- d-----w- c:\program files\LP
2011-11-02 22:42:12 -------- d-----w- c:\documents and settings\sxr0621\application data\DriverCure
2011-11-02 22:42:11 -------- d-----w- c:\documents and settings\sxr0621\application data\ParetoLogic
2011-11-01 22:35:15 -------- d-----w- c:\windows\pss
2011-10-28 12:44:28 294912 ----a-w- c:\documents and settings\sxr0621\local settings\application data\SystemWin32.dll
2011-10-28 12:44:28 129024 ----a-w- c:\documents and settings\all users\application data\AppleOnlineTray.dll
2011-10-21 19:16:51 57344 ----a-r- c:\documents and settings\sxr0621\application data\microsoft\installer\{fc4de34e-da9e-4f02-9837-2e65f73a0234}\NewShortcut11_97115261D719453B993A7ECEF93C483C.exe
2011-10-21 19:16:51 57344 ----a-r- c:\documents and settings\sxr0621\application data\microsoft\installer\{fc4de34e-da9e-4f02-9837-2e65f73a0234}\NewShortcut1_33418FF5CFFC4162B49A01B3130DF581.exe
2011-10-21 19:16:51 53248 ----a-r- c:\documents and settings\sxr0621\application data\microsoft\installer\{fc4de34e-da9e-4f02-9837-2e65f73a0234}\ARPPRODUCTICON.exe
2011-10-21 19:16:47 -------- d-----w- c:\documents and settings\sxr0621\application data\Verizon
2011-10-21 19:15:34 -------- d-----w- c:\program files\SAMSUNG
2011-10-21 19:15:17 -------- d-----w- c:\documents and settings\all users\application data\Samsung
2011-10-19 23:04:23 -------- d-----w- c:\documents and settings\sxr0621\local settings\application data\WinZip
2011-10-19 15:25:49 -------- d-----w- c:\documents and settings\sxr0621\local settings\application data\Apple Computer
2011-10-13 19:54:23 -------- d-----w- c:\documents and settings\sxr0621\local settings\application data\IsolatedStorage
2011-10-13 19:53:55 -------- d-----w- c:\documents and settings\sxr0621\local settings\application data\IBM
2011-10-13 12:39:00 79432 ----a-w- c:\program files\internet explorer\plugins\nphclx.dll
2011-10-13 12:18:10 -------- d-----w- c:\documents and settings\sxr0621\application data\Hummingbird
2011-10-13 12:17:37 -------- d-----w- c:\program files\Hummingbird
2011-10-13 12:17:37 -------- d-----w- c:\documents and settings\all users\application data\Hummingbird
2011-10-13 12:15:19 -------- d-----w- c:\program files\Hummingbird Electronic Full Media
.
==================== Find3M ====================
.
2011-10-04 00:39:42 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-29 20:30:14 32768 ----a-w- c:\windows\system32\userwin32.dll
2011-09-29 16:57:56 21393 ----a-w- c:\windows\system32\drivers\iPassP.sys
2011-09-26 15:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48:55 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48:54 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48:54 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56:39 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49:54 138496 ----a-w- c:\windows\system32\drivers\afd.sys
.
============= FINISH: 12:22:15.50 ===============
Attached File(s)
-
attach.txt (15.29K)
Number of downloads: 0 -
ark.txt (1.07K)
Number of downloads: 0

Help
This topic is locked

Back to top










