McAfee software recently popped up a warning that a Registry Change had occurred -- I rejected the change. Another similar pop-up appeared to briefly to read. The McAfee Recent Events log shows two accepted changes:
System Guards have allowed a one-time change to your computer.
Rule Type: Registry
Process: c:\WINDOWS\ld08.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtrayc:\WINDOWS\ld08.exe
System Guards have allowed a one-time change to your computer.
Rule Type: Registry
Process: C:\WINDOWS\system32\winlogon.exe
Process description: Windows NT Logon Application
Process publisher: Microsoft Corporation
Process version: 5.1.2600.5512 (xpsp.080413-2113) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit
So I decided to run the virus scan. 10 hours later, the results showed 6 Trojan items detected with Detection Name = Spy-Agent.bw!mem.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|userinit
C:\WINDOWS\system32\ntos.exe
C:\WINDOWS\system32\sdra64.exe
C:\WINDOWS\system32\twex.exe
C:\WINDOWS\system32\twext.exe
C:\WINDOWS\system32\winlogon.exe
The first 4 were removed. The last two were "unable to be quarantined".
I'm now getting periodic spontaneous Explorer pop-ups saying the following:
"Warning!!! Your computer contains various signs of viruses and malware programs presence. Your system requires immediate anti-virus check!System security will perform a quick and free scanning of your PC for viruses and malicious programs."
Each time this appears I've pressed Alt-F4 to abort the process, then another fullscreen Explorer window begins to open and I press Alt-F4 again.
Also McAfee's realtime virus scanning has recently detected and repaired several items similar to the following:
Detection Name: Artemis!45627F40739 (Trojan), Artemis!45627F40739 (Trojan)
File: C:\Documents and Settings\Bruce\Local Settings\Temporary Internet Files\Content.IE5\XWCXZ94A\6244[1].exe
Process: C:\windows\ld08.exe
Process description: C:\windows\ld08.exe
I would really appreciate some counseling as to how to clean my system. Thank you to any respondents. Below is the DDS file.
DDS (Ver_09-05-14.01) - NTFSx86
Run by Bruce at 13:19:26.44 on Tue 05/26/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.245 [GMT -7:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
============== Running Processes ===============
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\MAFWTray.exe
C:\windows\ld08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bruce\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mWinlogon: userinit=userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [TrackPointSrv] tp4serv.exe
mRun: [TP4EX] tp4ex.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [StorageGuard] "c:\program files\veritas software\update manager\sgtray.exe" /r
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [UC_SMB]
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [MimBoot] c:\progra~1\musicm~1\musicm~2\mimboot.exe
mRun: [ZangoOE] c:\program files\zango\bin\10.0.341.0\OEAddOn.exe
mRun: [ZangoSA] "c:\program files\zango\bin\10.0.341.0\ZangoSA.exe"
mRun: [MAFWTaskbarApp] c:\windows\system32\MAFWTray.exe
mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [sysldtray] c:\windows\ld08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\symant~1.lnk - c:\program files\microsoft office\office\1033\OLFSNT40.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: musicmatch.com\online
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165991914828
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1166005894280
DPF: {74FFE28D-2378-11D5-990C-006094235084} - hxxp://www-307.ibm.com/pc/support/IbmEgath.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\bruceh~1\applic~1\mozilla\firefox\profiles\ykda4art.default\
FF - plugin: c:\documents and settings\bruce\application data\mozilla\firefox\profiles\ykda4art.default\extensions\[email protected]\platform\winnt_x86-msvc\plugins\npmnqmp07075003.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
============= SERVICES / DRIVERS ===============
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2006-12-12 2295]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2006-12-13 201320]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2006-12-12 12288]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-5-14 359248]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2006-12-13 144704]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-12-13 79304]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-12-13 35240]
R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [1980-1-1 13055]
S2 Parclass;Parclass;c:\windows\system32\drivers\parclass.sys [2007-2-5 19824]
S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2006-12-13 695624]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-12-13 33832]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-12-13 40488]
S3 pc100;Linksys EtherFast 10/100 PC Card NT Driver;c:\windows\system32\drivers\pc100nds.sys [2007-8-18 30495]
S3 sawjavahostsvc;Siebel Analytics Java Host;c:\siebelanalytics\web\bin\sawjavahostsvc.exe [2007-1-8 73728]
S3 sawsvc;Siebel Analytics Web;c:\siebelanalytics\web\bin\sawserver.exe [2007-1-8 77824]
S3 Siebel Analytics Cluster;Siebel Analytics Cluster;c:\siebelanalytics\bin\NQSClusterController.exe [2007-1-8 28806]
S3 Siebel Analytics Scheduler;Siebel Analytics Scheduler;c:\siebelanalytics\bin\NQScheduler.exe [2007-1-8 90241]
S3 Siebel Analytics Server;Siebel Analytics Server;c:\siebelanalytics\bin\NQSComGateway.exe [2007-1-8 53370]
UnknownUnknown lxqtvyntwrghx;lxqtvyntwrghx; [x]
=============== Created Last 30 ================
2009-05-26 01:19 <DIR> --dsh--- c:\windows\system32\lowsec
2009-05-26 01:18 176 a------- C:\487656.bat
2009-05-26 01:18 14,848 ----h--- c:\windows\ld08.exe
2009-05-21 03:16 <DIR> --d----- c:\program files\MSECache
2009-05-21 02:52 <DIR> --d----- c:\program files\GPLGS
2009-05-21 02:51 87,552 a------- c:\windows\system32\cpwmon2k.dll
2009-05-21 02:51 <DIR> --d----- c:\program files\Acro Software
2009-05-20 20:23 <DIR> --d----- c:\windows\system32\scripting
2009-05-20 20:23 <DIR> --d----- c:\windows\l2schemas
2009-05-20 20:23 <DIR> --d----- c:\windows\system32\en
2009-05-15 11:38 276,992 -------- c:\windows\system32\wmphoto.dll
2009-05-15 11:37 69,120 -------- c:\windows\system32\wlanapi.dll
2009-05-15 11:37 712,704 -------- c:\windows\system32\windowscodecs.dll
2009-05-15 11:37 346,112 -------- c:\windows\system32\windowscodecsext.dll
2009-05-15 11:37 50,688 -------- c:\windows\system32\tspkg.dll
2009-05-15 11:36 10,240 -------- c:\windows\system32\drivers\sffp_mmc.sys
2009-05-15 11:36 32,768 -------- c:\windows\system32\setupn.exe
2009-05-15 11:36 61,952 -------- c:\windows\system32\rasqec.dll
2009-05-15 11:36 76,800 -------- c:\windows\system32\qutil.dll
2009-05-15 11:36 62,464 -------- c:\windows\system32\qcliprov.dll
2009-05-15 11:36 291,328 -------- c:\windows\system32\qagentrt.dll
2009-05-15 11:36 150,528 -------- c:\windows\system32\qagent.dll
2009-05-15 11:35 412,160 -------- c:\windows\system32\photometadatahandler.dll
2009-05-15 11:35 144,384 -------- c:\windows\system32\onex.dll
2009-05-15 11:35 193,024 -------- c:\windows\system32\napmontr.dll
2009-05-15 11:35 176,640 -------- c:\windows\system32\napstat.exe
2009-05-15 11:35 30,208 -------- c:\windows\system32\napipsec.dll
2009-05-15 11:35 1,307,648 -------- c:\windows\system32\msxml6.dll
2009-05-15 11:35 1,307,648 -------- c:\windows\system32\dllcache\msxml6.dll
2009-05-15 11:35 79,872 -------- c:\windows\system32\msxml6r.dll
2009-05-15 11:35 79,872 -------- c:\windows\system32\dllcache\msxml6r.dll
2009-05-15 11:34 155,136 -------- c:\windows\system32\mssha.dll
2009-05-15 11:34 76,800 -------- c:\windows\system32\msshavmsg.dll
2009-05-15 11:34 397,312 -------- c:\windows\system32\mmcex.dll
2009-05-15 11:34 106,496 -------- c:\windows\system32\mmcfxcommon.dll
2009-05-15 11:34 33,792 -------- c:\windows\system32\mmcperf.exe
2009-05-15 11:34 184,320 -------- c:\windows\system32\microsoft.managementconsole.dll
2009-05-15 11:33 37,376 -------- c:\windows\system32\l2gpstore.dll
2009-05-15 11:33 61,440 -------- c:\windows\system32\kmsvc.dll
2009-05-15 11:33 6,144 -------- c:\windows\system32\kbdpash.dll
2009-05-15 11:33 6,144 -------- c:\windows\system32\kbdnepr.dll
2009-05-15 11:33 6,144 -------- c:\windows\system32\kbdiultn.dll
2009-05-15 11:33 6,144 -------- c:\windows\system32\kbdbhc.dll
2009-05-15 11:32 974 -------- c:\windows\system32\pid.inf
2009-05-15 11:31 144,384 -------- c:\windows\system32\drivers\hdaudbus.sys
2009-05-15 11:31 19,569 a------- c:\windows\005991_.tmp
2009-05-15 11:29 7,168 -------- c:\windows\system32\bitsprx4.dll
2009-05-15 11:29 233,472 -------- c:\windows\system32\azroles.dll
2009-05-15 08:31 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-05-15 08:31 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-05-15 08:31 331,776 -------- c:\windows\system32\dllcache\msadce.dll
2009-05-15 08:30 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-05-15 08:29 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-05-15 08:27 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-05-15 08:27 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
2009-05-15 08:22 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-14 23:18 9,200 -------- c:\windows\system32\drivers\cdralw2k.sys
2009-05-14 23:18 9,072 -------- c:\windows\system32\drivers\cdr4_xp.sys
2009-05-14 23:17 <DIR> --d----- c:\windows\system32\IOSUBSYS
2009-05-01 11:30 3,366,912 a------- c:\windows\system32\GPhotos.scr
==================== Find3M ====================
2009-05-20 20:38 92,031 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-03-21 07:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-06 07:22 284,160 -------- c:\windows\system32\dllcache\pdh.dll
2009-03-02 17:18 826,368 a------- c:\windows\system32\wininet.dll
2009-03-02 17:18 826,368 -------- c:\windows\system32\dllcache\wininet.dll
2009-02-27 21:54 636,072 -------- c:\windows\system32\dllcache\iexplore.exe
1998-12-08 19:53 186,368 a------- c:\program files\common files\IRAREG.DLL
1998-12-08 19:53 99,840 a------- c:\program files\common files\IRAABOUT.DLL
1998-12-08 19:53 70,144 a------- c:\program files\common files\IRAMDMTR.DLL
1998-12-08 19:53 48,640 a------- c:\program files\common files\IRALPTTR.DLL
1998-12-08 19:53 31,744 a------- c:\program files\common files\IRAWEBTR.DLL
1998-12-08 19:53 17,920 a------- c:\program files\common files\IRASRIAL.DLL
============= FINISH: 13:21:26.78 ===============
System Guards have allowed a one-time change to your computer.
Rule Type: Registry
Process: c:\WINDOWS\ld08.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtrayc:\WINDOWS\ld08.exe
System Guards have allowed a one-time change to your computer.
Rule Type: Registry
Process: C:\WINDOWS\system32\winlogon.exe
Process description: Windows NT Logon Application
Process publisher: Microsoft Corporation
Process version: 5.1.2600.5512 (xpsp.080413-2113) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\userinit
So I decided to run the virus scan. 10 hours later, the results showed 6 Trojan items detected with Detection Name = Spy-Agent.bw!mem.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|userinit
C:\WINDOWS\system32\ntos.exe
C:\WINDOWS\system32\sdra64.exe
C:\WINDOWS\system32\twex.exe
C:\WINDOWS\system32\twext.exe
C:\WINDOWS\system32\winlogon.exe
The first 4 were removed. The last two were "unable to be quarantined".
I'm now getting periodic spontaneous Explorer pop-ups saying the following:
"Warning!!! Your computer contains various signs of viruses and malware programs presence. Your system requires immediate anti-virus check!System security will perform a quick and free scanning of your PC for viruses and malicious programs."
Each time this appears I've pressed Alt-F4 to abort the process, then another fullscreen Explorer window begins to open and I press Alt-F4 again.
Also McAfee's realtime virus scanning has recently detected and repaired several items similar to the following:
Detection Name: Artemis!45627F40739 (Trojan), Artemis!45627F40739 (Trojan)
File: C:\Documents and Settings\Bruce\Local Settings\Temporary Internet Files\Content.IE5\XWCXZ94A\6244[1].exe
Process: C:\windows\ld08.exe
Process description: C:\windows\ld08.exe
I would really appreciate some counseling as to how to clean my system. Thank you to any respondents. Below is the DDS file.
DDS (Ver_09-05-14.01) - NTFSx86
Run by Bruce at 13:19:26.44 on Tue 05/26/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.245 [GMT -7:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
============== Running Processes ===============
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\MAFWTray.exe
C:\windows\ld08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bruce\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mWinlogon: userinit=userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [TrackPointSrv] tp4serv.exe
mRun: [TP4EX] tp4ex.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [StorageGuard] "c:\program files\veritas software\update manager\sgtray.exe" /r
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [UC_SMB]
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [MimBoot] c:\progra~1\musicm~1\musicm~2\mimboot.exe
mRun: [ZangoOE] c:\program files\zango\bin\10.0.341.0\OEAddOn.exe
mRun: [ZangoSA] "c:\program files\zango\bin\10.0.341.0\ZangoSA.exe"
mRun: [MAFWTaskbarApp] c:\windows\system32\MAFWTray.exe
mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [sysldtray] c:\windows\ld08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\symant~1.lnk - c:\program files\microsoft office\office\1033\OLFSNT40.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: musicmatch.com\online
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165991914828
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1166005894280
DPF: {74FFE28D-2378-11D5-990C-006094235084} - hxxp://www-307.ibm.com/pc/support/IbmEgath.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\bruceh~1\applic~1\mozilla\firefox\profiles\ykda4art.default\
FF - plugin: c:\documents and settings\bruce\application data\mozilla\firefox\profiles\ykda4art.default\extensions\[email protected]\platform\winnt_x86-msvc\plugins\npmnqmp07075003.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
============= SERVICES / DRIVERS ===============
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2006-12-12 2295]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2006-12-13 201320]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2006-12-12 12288]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-5-14 359248]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2006-12-13 144704]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-12-13 79304]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-12-13 35240]
R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [1980-1-1 13055]
S2 Parclass;Parclass;c:\windows\system32\drivers\parclass.sys [2007-2-5 19824]
S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2006-12-13 695624]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-12-13 33832]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-12-13 40488]
S3 pc100;Linksys EtherFast 10/100 PC Card NT Driver;c:\windows\system32\drivers\pc100nds.sys [2007-8-18 30495]
S3 sawjavahostsvc;Siebel Analytics Java Host;c:\siebelanalytics\web\bin\sawjavahostsvc.exe [2007-1-8 73728]
S3 sawsvc;Siebel Analytics Web;c:\siebelanalytics\web\bin\sawserver.exe [2007-1-8 77824]
S3 Siebel Analytics Cluster;Siebel Analytics Cluster;c:\siebelanalytics\bin\NQSClusterController.exe [2007-1-8 28806]
S3 Siebel Analytics Scheduler;Siebel Analytics Scheduler;c:\siebelanalytics\bin\NQScheduler.exe [2007-1-8 90241]
S3 Siebel Analytics Server;Siebel Analytics Server;c:\siebelanalytics\bin\NQSComGateway.exe [2007-1-8 53370]
UnknownUnknown lxqtvyntwrghx;lxqtvyntwrghx; [x]
=============== Created Last 30 ================
2009-05-26 01:19 <DIR> --dsh--- c:\windows\system32\lowsec
2009-05-26 01:18 176 a------- C:\487656.bat
2009-05-26 01:18 14,848 ----h--- c:\windows\ld08.exe
2009-05-21 03:16 <DIR> --d----- c:\program files\MSECache
2009-05-21 02:52 <DIR> --d----- c:\program files\GPLGS
2009-05-21 02:51 87,552 a------- c:\windows\system32\cpwmon2k.dll
2009-05-21 02:51 <DIR> --d----- c:\program files\Acro Software
2009-05-20 20:23 <DIR> --d----- c:\windows\system32\scripting
2009-05-20 20:23 <DIR> --d----- c:\windows\l2schemas
2009-05-20 20:23 <DIR> --d----- c:\windows\system32\en
2009-05-15 11:38 276,992 -------- c:\windows\system32\wmphoto.dll
2009-05-15 11:37 69,120 -------- c:\windows\system32\wlanapi.dll
2009-05-15 11:37 712,704 -------- c:\windows\system32\windowscodecs.dll
2009-05-15 11:37 346,112 -------- c:\windows\system32\windowscodecsext.dll
2009-05-15 11:37 50,688 -------- c:\windows\system32\tspkg.dll
2009-05-15 11:36 10,240 -------- c:\windows\system32\drivers\sffp_mmc.sys
2009-05-15 11:36 32,768 -------- c:\windows\system32\setupn.exe
2009-05-15 11:36 61,952 -------- c:\windows\system32\rasqec.dll
2009-05-15 11:36 76,800 -------- c:\windows\system32\qutil.dll
2009-05-15 11:36 62,464 -------- c:\windows\system32\qcliprov.dll
2009-05-15 11:36 291,328 -------- c:\windows\system32\qagentrt.dll
2009-05-15 11:36 150,528 -------- c:\windows\system32\qagent.dll
2009-05-15 11:35 412,160 -------- c:\windows\system32\photometadatahandler.dll
2009-05-15 11:35 144,384 -------- c:\windows\system32\onex.dll
2009-05-15 11:35 193,024 -------- c:\windows\system32\napmontr.dll
2009-05-15 11:35 176,640 -------- c:\windows\system32\napstat.exe
2009-05-15 11:35 30,208 -------- c:\windows\system32\napipsec.dll
2009-05-15 11:35 1,307,648 -------- c:\windows\system32\msxml6.dll
2009-05-15 11:35 1,307,648 -------- c:\windows\system32\dllcache\msxml6.dll
2009-05-15 11:35 79,872 -------- c:\windows\system32\msxml6r.dll
2009-05-15 11:35 79,872 -------- c:\windows\system32\dllcache\msxml6r.dll
2009-05-15 11:34 155,136 -------- c:\windows\system32\mssha.dll
2009-05-15 11:34 76,800 -------- c:\windows\system32\msshavmsg.dll
2009-05-15 11:34 397,312 -------- c:\windows\system32\mmcex.dll
2009-05-15 11:34 106,496 -------- c:\windows\system32\mmcfxcommon.dll
2009-05-15 11:34 33,792 -------- c:\windows\system32\mmcperf.exe
2009-05-15 11:34 184,320 -------- c:\windows\system32\microsoft.managementconsole.dll
2009-05-15 11:33 37,376 -------- c:\windows\system32\l2gpstore.dll
2009-05-15 11:33 61,440 -------- c:\windows\system32\kmsvc.dll
2009-05-15 11:33 6,144 -------- c:\windows\system32\kbdpash.dll
2009-05-15 11:33 6,144 -------- c:\windows\system32\kbdnepr.dll
2009-05-15 11:33 6,144 -------- c:\windows\system32\kbdiultn.dll
2009-05-15 11:33 6,144 -------- c:\windows\system32\kbdbhc.dll
2009-05-15 11:32 974 -------- c:\windows\system32\pid.inf
2009-05-15 11:31 144,384 -------- c:\windows\system32\drivers\hdaudbus.sys
2009-05-15 11:31 19,569 a------- c:\windows\005991_.tmp
2009-05-15 11:29 7,168 -------- c:\windows\system32\bitsprx4.dll
2009-05-15 11:29 233,472 -------- c:\windows\system32\azroles.dll
2009-05-15 08:31 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-05-15 08:31 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-05-15 08:31 331,776 -------- c:\windows\system32\dllcache\msadce.dll
2009-05-15 08:30 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-05-15 08:29 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-05-15 08:27 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-05-15 08:27 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
2009-05-15 08:22 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-14 23:18 9,200 -------- c:\windows\system32\drivers\cdralw2k.sys
2009-05-14 23:18 9,072 -------- c:\windows\system32\drivers\cdr4_xp.sys
2009-05-14 23:17 <DIR> --d----- c:\windows\system32\IOSUBSYS
2009-05-01 11:30 3,366,912 a------- c:\windows\system32\GPhotos.scr
==================== Find3M ====================
2009-05-20 20:38 92,031 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-03-21 07:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-06 07:22 284,160 -------- c:\windows\system32\dllcache\pdh.dll
2009-03-02 17:18 826,368 a------- c:\windows\system32\wininet.dll
2009-03-02 17:18 826,368 -------- c:\windows\system32\dllcache\wininet.dll
2009-02-27 21:54 636,072 -------- c:\windows\system32\dllcache\iexplore.exe
1998-12-08 19:53 186,368 a------- c:\program files\common files\IRAREG.DLL
1998-12-08 19:53 99,840 a------- c:\program files\common files\IRAABOUT.DLL
1998-12-08 19:53 70,144 a------- c:\program files\common files\IRAMDMTR.DLL
1998-12-08 19:53 48,640 a------- c:\program files\common files\IRALPTTR.DLL
1998-12-08 19:53 31,744 a------- c:\program files\common files\IRAWEBTR.DLL
1998-12-08 19:53 17,920 a------- c:\program files\common files\IRASRIAL.DLL
============= FINISH: 13:21:26.78 ===============
Attachments
-
22.5 KB Views: 64