Top level this. hitting it with a big stick. I seem to have my google back. Frankly its a mystery to me but I'm impressed.
Right
Rkill log:
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Jules on 31/03/2010 at 18:15:16.
Processes terminated by Rkill or while it was running:
C:\Windows\system32\rundll32.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Backup Direct\Connected\Agent.exe
C:\Users\Jules\Downloads\rkill.pif
Rkill completed on 31/03/2010 at 18:15:21.
comfix log:
ComboFix 10-03-29.04 - Jules 31/03/2010 18:24:45.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2036.552 [GMT 1:00]
Running from: c:\users\Jules\Downloads\Comfix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1054.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1212.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1274.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc13F9.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1444.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc14CA.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1726.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1797.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc187E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1A8.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1B2B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1BBF.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1C2F.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1CA7.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1DC5.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1E82.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1F2C.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1FE1.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2169.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc21E1.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2475.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc24FE.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2695.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc26C7.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2AD3.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2B0A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2B7.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2BD6.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2C35.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2CE0.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2E65.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc305A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc311B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc31B3.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc31EF.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3378.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3468.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc37AD.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3917.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc39EB.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3AF9.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3BE9.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3C1A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3C5D.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3D9B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4338.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4350.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4368.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc44CA.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc47AC.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc47AF.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc47B7.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc47D9.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc485F.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc48C2.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc49C3.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc49DD.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4A7A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4BCE.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5083.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5156.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5161.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc516C.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5290.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc550.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc554C.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5758.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc587A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc596B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc59F3.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5A4A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5A70.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5B28.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5B45.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5B57.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5C3D.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5CC3.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5CC7.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5D28.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5E77.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6044.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6116.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc611D.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6184.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc635A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc63AF.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6479.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc65AA.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc65C4.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc65DC.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6686.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc66C3.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc685D.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6D5B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6EB5.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6F6E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc718E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc72E7.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7358.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc75A8.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc774B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7797.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc786B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7C84.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7DB1.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7DF1.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7E5F.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7E98.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7FE7.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8072.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8131.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8133.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc81CE.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8209.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc821A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc82A1.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc82BD.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc831E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc83AB.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc87A6.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc889.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc892.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8AB0.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8C5E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8D7F.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8DBE.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8E5C.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9066.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc90B8.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9134.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9246.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc92CB.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc936.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9492.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc94E2.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc953C.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc967B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc96EE.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9708.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9784.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc97F0.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9840.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc985E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc98AA.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc98DE.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9A24.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9A5.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9A5D.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9C5E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9D80.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9DE9.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA12C.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA257.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA30E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA604.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA7CC.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA9D1.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAAEF.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAAF2.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccABA2.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAD87.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAF19.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAFF8.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB1BC.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB723.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB725.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB93F.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB965.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB973.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBAD5.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBC2E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBE15.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC013.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC1E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC656.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC767.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC8DC.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC9FE.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCCF4.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCE56.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCF52.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCFE5.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD050.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD12E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD1E1.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD26F.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD3D0.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD400.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD7A3.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD864.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDAF4.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDBF2.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDD15.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDD1D.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDD9E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE477.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE499.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE4AB.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE566.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE5A8.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE678.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE944.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE9A1.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEB80.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEC69.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEEF7.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF0B3.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF144.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF1AD.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF507.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF524.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF617.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF70B.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF803.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF82A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF86D.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFA2A.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFC37.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFD4E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFE8E.tmp
c:\users\Jules\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFFF8.tmp
c:\users\Jules\Documents\TaskMan.exe
D:\resycled
Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ndisrd
((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-31 )))))))))))))))))))))))))))))))
.
2010-03-31 17:36 . 2010-03-31 17:39 -------- d-----w- c:\users\Jules\AppData\Local\temp
2010-03-31 17:36 . 2010-03-31 17:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-31 17:36 . 2010-03-31 17:36 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-03-25 18:09 . 2010-03-27 12:51 -------- dc----w- c:\windows\system32\DRVSTORE
2010-03-25 18:09 . 2010-03-25 18:09 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-25 12:21 . 2010-03-31 14:56 -------- d-----w- c:\program files\Panda Security
2010-03-25 07:20 . 2010-03-25 07:20 -------- d-----w- c:\program files\AVG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-31 17:41 . 2009-01-06 17:00 1682 --sha-w- c:\programdata\KGyGaAvL.sys
2010-03-31 17:41 . 2009-01-06 17:00 1682 --sha-w- c:\programdata\KGyGaAvL.sys
2010-03-31 17:40 . 2010-02-04 10:10 -------- d-----w- c:\program files\Lx_cats
2010-03-31 17:13 . 2009-01-08 18:36 -------- d-----w- c:\users\Jules\AppData\Roaming\BitTorrent
2010-03-31 08:17 . 2009-03-11 09:52 -------- d-----w- c:\program files\McAfee
2010-03-28 16:37 . 2009-01-17 09:43 1356 ----a-w- c:\users\Jules\AppData\Local\d3d9caps.dat
2010-03-28 01:02 . 2009-12-23 10:35 1109 ----a-w- c:\users\Jules\AppData\Roaming\Genie-Soft\GBMPro8\Jobs\jULES NEW COMP\00000001\maindata.sys
2010-03-27 12:51 . 2009-01-14 17:11 -------- d-----w- c:\programdata\Lavasoft
2010-03-26 08:24 . 2010-03-26 08:24 1741521 ----a-w- c:\programdata\SPL5C6.tmp
2010-03-19 14:19 . 2009-01-09 18:24 -------- d-----w- c:\users\Jules\AppData\Roaming\Snappy Fax
2010-03-19 13:59 . 2009-01-09 18:24 -------- d-----w- c:\program files\Snappy Fax Version 4
2010-03-18 13:08 . 2009-01-30 10:58 692 ----a-w- c:\users\Jules\AppData\Roaming\wklnhst.dat
2010-03-12 08:42 . 2008-12-23 13:00 -------- d-----w- c:\program files\Common Files\Java
2010-03-12 08:41 . 2008-12-23 13:00 -------- d-----w- c:\program files\Java
2010-03-01 14:07 . 2009-01-06 20:45 -------- d-----w- c:\program files\divx
2010-03-01 14:06 . 2008-12-23 13:12 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-03-01 14:06 . 2010-03-01 14:05 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-02-27 10:11 . 2010-02-27 10:11 102248 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-02-27 10:10 . 2009-11-26 18:23 8224 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-25 23:12 . 2009-01-15 10:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 23:07 . 2009-11-15 17:14 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-02-17 18:20 . 2010-02-17 18:20 738776 ----a-w- c:\programdata\SPL4EB9.tmp
2010-02-17 07:43 . 2009-01-08 18:35 -------- d-----w- c:\users\Jules\AppData\Roaming\DNA
2010-02-15 18:24 . 2009-01-14 14:09 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-02-15 10:26 . 2009-01-08 18:35 -------- d-----w- c:\program files\DNA
2010-02-15 09:37 . 2009-01-08 08:47 -------- d-----w- c:\programdata\Microsoft Help
2010-02-10 08:26 . 2010-02-10 08:26 9864508 ----a-w- c:\programdata\SPLA734.tmp
2010-02-08 14:09 . 2010-02-04 10:11 -------- d-----w- c:\users\Jules\AppData\Roaming\5400 Series
2010-02-07 09:25 . 2009-01-06 16:39 102248 ----a-w- c:\users\Jules\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-04 16:59 . 2009-03-05 15:53 -------- d-----w- c:\users\Jules\AppData\Roaming\Genie-Soft
2010-02-04 14:46 . 2010-02-04 14:46 40685572 ----a-w- c:\programdata\SPL832B.tmp
2010-02-04 10:14 . 2010-02-04 10:02 -------- d-----w- c:\program files\Lexmark 5400 Series
2010-02-04 10:04 . 2010-02-04 10:04 -------- d-----w- c:\programdata\5400 Series
2010-02-04 10:04 . 2010-02-04 10:04 -------- d-----w- c:\program files\Lexmark Toolbar
2010-02-01 19:40 . 2009-07-10 11:13 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-01 19:39 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-01 15:31 . 2009-11-26 17:51 -------- d-----w- c:\users\Jules\AppData\Roaming\Teleca
2010-02-01 15:29 . 2010-02-01 15:29 -------- d-----w- c:\program files\Common Files\Teleca Shared
2010-02-01 15:29 . 2010-02-01 15:29 -------- d-----w- c:\programdata\HTC
2010-02-01 15:29 . 2010-02-01 15:29 -------- d-----w- c:\programdata\Teleca
2010-02-01 15:29 . 2009-11-26 17:46 -------- d-----w- c:\program files\HTC
2010-02-01 14:51 . 2010-02-01 14:51 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-02-01 14:30 . 2009-11-26 18:24 -------- d-----w- c:\users\Administrator\AppData\Roaming\Teleca
2010-02-01 13:47 . 2010-02-01 13:47 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_androidusb_01005.Wdf
2010-01-31 10:23 . 2009-01-06 20:45 -------- d-----w- c:\program files\mhead32
2010-01-31 10:23 . 2010-01-31 10:23 -------- d-----w- c:\program files\Common Files\MachineheadSoftware
2010-01-31 10:22 . 2010-01-31 10:22 364544 ------w- c:\windows\Setup1.exe
2010-01-31 10:22 . 2010-01-31 10:22 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-01-30 23:52 . 2008-12-23 13:05 -------- d-----w- c:\program files\Google
2010-01-29 02:01 . 2010-01-29 08:04 1109 ----a-w- c:\users\Jules\AppData\Roaming\Genie-Soft\GBMPro8\Jobs\New Backup Job(2)\00000000\maindata.sys
2010-01-07 16:07 . 2009-01-15 10:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 . 2009-01-15 10:19 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 06:38 . 2010-01-22 15:50 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 15:50 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-22 15:50 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-22 15:50 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-16 18:32 . 2009-01-15 10:31 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-12-10 15:01 . 2009-10-19 16:24 83312 ----a-w- c:\program files\mozilla firefox\components\ppReaderLaunch.dll
2008-12-23 20:31 . 2008-12-23 20:30 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-23 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 4452352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-22 133656]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"AgentUiRunKey"="c:\program files\Backup Direct\Connected\Agent.exe" [2008-11-09 244536]
"Private Post Tray v4"="c:\program files\Trend Micro\Email Encryption Client\ppTray.exe" [2009-12-10 226664]
"Act! Preloader"="c:\program files\ACT\Act for Windows\ActSage.exe" [2009-08-24 331776]
"lxctmon.exe"="c:\program files\Lexmark 5400 Series\lxctmon.exe" [2006-11-22 291760]
"LXCTCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-11-21 106496]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]
c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-12-23 13:13 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Jules^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\users\Jules\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2008-04-23 02:08 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Act.Outlook.Service]
2009-08-24 20:09 28672 ----a-w- c:\program files\ACT\Act for Windows\Act.Outlook.Service.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 02:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-11-08 07:56 323392 ----a-w- c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2007-02-15 14:29 622592 ------w- c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_McciTrayApp]
2009-09-14 16:56 1584640 ----a-w- c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_wcm_McciTrayApp]
2008-08-28 19:33 1516032 ----a-w- c:\program files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CompanionLink]
2009-12-29 12:46 13737984 ----a-w- c:\program files\CompanionLink\CompanionLink.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2006-07-19 14:51 65536 ------w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2008-10-04 13:58 206064 ----a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
2006-11-22 10:11 82864 ----a-w- c:\program files\Lexmark 5400 Series\ezprint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GBMPro8Agent]
2007-07-11 05:23 214512 ----a-w- c:\program files\genie-soft\GBMPro8\GBMAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2009-12-16 18:32 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2005-03-17 14:45 40960 ----a-w- c:\program files\scansoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 5400 Series Fax Server]
2006-11-22 10:12 304048 ----a-w- c:\program files\Lexmark 5400 Series\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-01-07 16:07 1394000 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mobile Connectivity Suite]
2009-05-27 15:46 598016 ----a-r- c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2005-03-17 14:25 57393 ----a-w- c:\program files\scansoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrintDisp]
2009-04-07 08:29 871936 ----a-w- c:\windows\System32\PrintDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Snappy Fax Printer virtual printer agent]
2007-07-19 04:01 94208 ----a-w- c:\program files\Snappy Fax Version 4\sfpagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-10-14 10:22 155648 ----a-r- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 11:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-12-23 13:06 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-08-25 16:27 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAB]
2009-12-02 08:17 18432 ----a-w- c:\users\Jules\AppData\Roaming\Macromedia\Common\039fe09219.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management]
2007-05-31 09:21 648072 ----a-w- c:\windows\WindowsMobile\wmdcBase.exe
R2 ACT! Scheduler;ACT! Scheduler;c:\program files\ACT\Act for Windows\Act.Scheduler.exe [2009-08-24 81920]
R2 ddnt;ddnt;c:\windows\system32\drivers\ddnt.sys [2009-11-04 8544]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 135664]
R2 srenum;srenum;c:\windows\system32\DRIVERS\srenum.sys [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2009-06-09 24576]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-16 30192]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-06-09 24576]
S2 AgentService;AgentService;c:\program files\Backup Direct\Connected\AgentService.exe [2008-11-09 6608192]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-09-23 155648]
S2 LV_Tracker;LV_Tracker;c:\windows\system32\DRIVERS\LV_Tracker.sys [2008-11-09 45384]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-12-08 93320]
S2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
S2 ppAuxSrv;ppAuxSrv;c:\program files\Trend Micro\Email Encryption Client\ppAuxSrv.exe [2009-12-10 87400]
S2 Printer Control;Printer Control;c:\windows\system32\PrintCtrl.exe [2008-10-11 73728]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
S3 ppSrv;ppSrv;c:\program files\Trend Micro\Email Encryption Client\ppSrv.exe [2009-12-10 79184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2010-03-28 c:\windows\Tasks\GBM - jULES NEW COMP-Full.job
- c:\program files\Genie-Soft\GBMPro8\GBM8.exe [2009-03-05 05:20]
2010-03-28 c:\windows\Tasks\GBM - New Backup Job(2)-Full.job
- c:\program files\Genie-Soft\GBMPro8\GBM8.exe [2009-03-05 05:20]
2010-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 23:52]
2010-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 23:52]
2010-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 11:22]
2010-03-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 11:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bbc.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar =
uInternet Settings,ProxyOverride = 127.0.0.1;<local>
uCustomizeSearch =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: adviserzone.com\www
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: motive.com\pbttbc.bt
Trusted Zone: standardlife.com\online
Trusted Zone: standardlife.com\online4
DPF: {8E95B0CA-EB6F-11D3-979B-00508B64538B} - hxxp://exweb.exchange.uk.com/clientBinaries/VersionInfo.CAB
DPF: {91F82BFF-F70C-11D2-BB68-0008C7E9C2C6} - hxxp://exweb.exchange.uk.com/texonline/core_services/new_business_processing/texnbshell.cab
DPF: {CB830891-2E18-11D1-B8CF-00A0C9259304} - hxxp://exweb.exchange.uk.com/texonline/core_services/new_business_processing/FDFFILES.CAB
FF - ProfilePath - c:\users\Jules\AppData\Roaming\Mozilla\Firefox\Profiles\zjpxd6pn.default\
FF - prefs.js: browser.startup.homepage - www.bbc.co.uk
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Snappy Fax Printer Agent - (no file)
SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-SRService
MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCTCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5924)
c:\program files\Trend Micro\Email Encryption Client\PPTrayHk.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\program files\Trend Micro\Email Encryption Client\ppOEHk.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\brss01a.exe
c:\windows\system32\lxctcoms.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\windows\system32\rundll32.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
.
**************************************************************************
.
Completion time: 2010-03-31 18:46:48 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-31 17:46
Pre-Run: 64,292,192,256 bytes free
Post-Run: 64,131,915,776 bytes free
- - End Of File - - EE1444C50FFD38577A4DC9171C636A00
I assume it all means something.