DDS (Ver_09-05-14.01) - NTFSx86
Run by Big Bad Jean at 9:47:47.68 on Sat 06/13/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.53 [GMT -4:00]
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
============== Running Processes ===============
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Documents and Settings\Big Bad Jean\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe
mRun: [capfasem] c:\program files\ca\ca internet security suite\ca personal firewall\capfasem.exe
mRun: [cafwc] c:\program files\ca\ca internet security suite\ca personal firewall\cafw.exe -cl
mRun: [AtiPTA] atiptaxx.exe
dRun: [tempo-setup2.exe] c:\windows\system32\tempo-setup2.exe
uPolicies-system: NoDispBackgroundPage = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: NoDispBackgroundPage = 1 (0x1)
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: c:\windows\system32\VetRedir.dll
TCP: NameServer = 85.255.112.101,85.255.112.113
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: PFW - UmxWnp.Dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\bigbad~1\applic~1\mozilla\firefox\profiles\u5oyro29.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - component: c:\program files\free download manager\firefox\extension\components\vmsfdmff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
============= SERVICES / DRIVERS ===============
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2008-6-24 93712]
R1 atitray;atitray;c:\program files\radeon omega drivers\v4.8.442\ati tray tools\atitray.sys [2009-1-19 17952]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2008-6-24 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2008-6-24 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-6-24 115216]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-12-4 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-12-4 55024]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2009-2-18 26376]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2009-2-18 21128]
R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-2-18 880560]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2009-2-18 21512]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2009-2-18 32264]
R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2009-2-18 144960]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-6-24 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-6-24 66576]
R2 UmxAgent;HIPS Event Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxAgent.exe [2007-10-18 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\ca\sharedcomponents\hipsengine\UmxCfg.exe [2007-10-18 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxPol.exe [2008-6-24 281104]
R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2009-2-18 242952]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2008-6-24 88816]
R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2007-8-16 189704]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-2-18 108368]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-12-4 7408]
=============== Created Last 30 ================
2009-06-12 21:20 142,592 a------- c:\windows\system32\drivers\sp_rsdrv2.sys
2009-06-12 21:20
--d----- c:\docume~1\bigbad~1\applic~1\Spyware Terminator
2009-06-12 19:11 161,792 a------- c:\windows\SWREG.exe
2009-06-12 19:11 154,624 a------- c:\windows\PEV.exe
2009-06-12 19:11 98,816 a------- c:\windows\sed.exe
2009-06-12 19:11 --ds---- C:\Combo-Fix
2009-06-12 19:11 389,120 a------- c:\windows\system32\CF13664.exe
2009-06-12 19:06 116,623 a------- C:\MGlogs.zip
2009-06-12 18:30 --d----- C:\!KillBox
2009-06-12 18:27 1,066,176 a------- c:\windows\system32\MSCOMCTL.OCX
2009-06-12 16:40 6,315 a------- c:\windows\28534hacktooz1a29.cpl
2009-06-11 17:48 3,388 a------- c:\windows\4570spamb9t23z.cpl
2009-06-11 16:58 --d----- c:\docume~1\alluse~1\applic~1\RegCure
2009-06-11 12:23 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-06-11 12:23 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-06-11 12:23 1,985,024 -c------ c:\windows\system32\dllcache\iertutil.dll
2009-06-11 12:23 11,064,832 -c------ c:\windows\system32\dllcache\ieframe.dll
2009-06-11 12:14 6,512 a------- c:\windows\1686back5oor79z.exe
2009-06-10 22:44 4,214 a------- c:\windows\system32\5a129hzeat20081.dll
2009-06-09 16:50 --d----- c:\windows\pss
2009-06-07 18:46 6,339 a------- c:\windows\system32\3952not-a-viru5z46.exe
2009-06-07 15:10 --d----- C:\MGtools
2009-06-07 15:10 1,342,151 a------- C:\MGtools.exe
2009-06-07 12:59 451,655 a------- c:\temp\RootRepeal.zip
2009-06-07 09:18 --d-h--- c:\windows\system32\GroupPolicy
2009-06-07 08:55 --d----- c:\program files\Spyware Terminator
2009-06-07 08:55 --d----- c:\docume~1\alluse~1\applic~1\Spyware Terminator
2009-06-07 02:16 14,105 a------- c:\windows\29851hackt9ol6f3z.bin
2009-06-06 00:08 --d----- c:\program files\Trend Micro
2009-06-05 23:36 --d----- C:\_OTM
2009-06-05 22:37 10,614 a------- c:\windows\649atzrea525717.cpl
2009-06-04 17:57 40,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-04 17:57 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-06-04 17:57 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-04 17:57 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-06-04 00:51 8,658 a------- c:\windows\z6175sp9mbot5f7.ocx
2009-06-01 08:25 7,766 a------- c:\windows\system32\459zth9ef2036.cpl
2009-05-30 09:58 --d----- c:\program files\PluginVideo
2009-05-27 15:19 18,083 a------- c:\windows\system32\209789zrus5d1.cpl
2009-05-26 18:41 --dsh--- c:\documents and settings\big bad jean\PrivacIE
2009-05-26 16:32 4,870 a------- c:\windows\28beb9ck5oorz04.dll
2009-05-25 09:10 --dsh--- c:\documents and settings\big bad jean\IECompatCache
2009-05-25 06:03 3,183 a------- c:\windows\system32\18zfs9eal2553.cpl
2009-05-22 23:51 4,403 a------- c:\windows\39f4t5ief14z9.exe
2009-05-22 17:36 --dsh--- c:\documents and settings\big bad jean\IETldCache
2009-05-22 17:00 --d----- c:\windows\ie8updates
2009-05-22 17:00 102,400 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-05-22 16:58 -cd-h--- c:\windows\ie8
2009-05-20 15:11 10,999 a------- c:\windows\49435ownloader1199z.bin
2009-05-20 10:23 14,591 a------- c:\windows\b7dtzi952572.dll
2009-05-20 06:30 8,851 a------- c:\windows\system32\c2359arsz2453.cpl
2009-05-18 10:16 2,744 a------- c:\windows\21968not-a5viru97dz.cpl
2009-05-17 00:50 8,696 a------- c:\windows\system32\9d7db5ckdozr1815.dll
==================== Find3M ====================
2009-06-12 23:26 90,586 a------- c:\windows\system32\drivers\kmxcfg.u2k0
2009-06-12 23:26 64 a------- c:\windows\system32\drivers\kmxcfg.u2k7
2009-06-12 23:26 64 a------- c:\windows\system32\drivers\kmxcfg.u2k6
2009-06-12 23:26 64 a------- c:\windows\system32\drivers\kmxcfg.u2k5
2009-06-12 23:26 64 a------- c:\windows\system32\drivers\kmxcfg.u2k4
2009-06-12 23:26 64 a------- c:\windows\system32\drivers\kmxcfg.u2k3
2009-06-12 23:26 64 a------- c:\windows\system32\drivers\kmxcfg.u2k2
2009-06-12 23:26 64 a------- c:\windows\system32\drivers\kmxcfg.u2k1
2009-05-13 13:45 7,874 a------- c:\windows\system32\5z19ad9ware1405.exe
2009-05-13 01:15 915,456 a------- c:\windows\system32\wininet.dll
2009-05-12 23:11 16,440 a------- c:\windows\system32\246edoznl95der1935.exe
2009-05-12 16:59 17,083 a------- c:\windows\system32\5z688spambot19.exe
2009-05-09 09:56 6,325 a------- c:\windows\system32\14643woz955a.dll
2009-05-08 09:42 10,026 a------- c:\windows\system32\68dcsp5zs92170.bin
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-05-05 21:34 8,937 a------- c:\windows\5e299oznloader2550.bin
2009-05-02 03:03 10,004 a------- c:\windows\system32\9598not-a-virus59az.bin
2009-05-01 09:16 3,380 a------- c:\windows\system32\z5235pambot690.bin
2009-04-27 04:12 14,585 a------- c:\windows\system32\6c875ownloa9er2163z.bin
2009-04-26 19:29 8,689 a------- c:\windows\5z735o9m14a.bin
2009-04-25 04:21 3,185 a------- c:\windows\system32\9372hacktzol62b5.exe
2009-04-22 15:06 10,138 a------- c:\windows\9z99troj55.bin
2009-04-18 10:41 12,174 a------- c:\windows\287fspyw5r91839z.dll
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 23:05 5,049 a------- c:\windows\26859vizu91ab.bin
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-04-14 03:01 13,752 a------- c:\windows\6f99zpywar95235.bin
2009-04-11 10:20 18,076 a------- c:\windows\system32\23657s5ambot3ze9.dll
2009-04-10 20:06 2,913 a------- c:\windows\system32\3a61thizf9485.exe
2009-04-09 21:53 9,646 a------- c:\windows\2b64spywzr51690.dll
2009-04-09 15:48 17,943 a------- c:\windows\4b6adownload5r17z69.bin
2009-04-08 13:41 7,433 a------- c:\windows\system32\395fa5zware1113.exe
2009-04-05 13:19 14,676 a------- c:\windows\system32\15439not-z-5irus7bb.dll
2009-04-05 10:28 68,268 a------- c:\windows\hpoins05.dat
2009-04-02 17:19 4,128 a------- c:\windows\237995orm3d7z.dll
2009-04-01 09:27 13,971 a------- c:\windows\595zir2774.dll
2009-03-26 19:33 15,409 a------- c:\windows\852spars92z85.exe
2009-03-23 19:34 11,417 a------- c:\windows\system32\190465rojzb9.exe
2009-03-22 21:02 3,042 a------- c:\windows\e1bthreat901z75.exe
2009-03-22 16:10 11,988 a------- c:\windows\system32\2b89backz5or16089.exe
2009-03-22 02:22 3,148 a------- c:\windows\system32\29954spz3dc.exe
2009-03-20 19:26 9,436 a------- c:\windows\193365zamb9t421.dll
2009-03-20 17:20 11,412 a------- c:\windows\45abz9k5oor2647.bin
2009-03-17 14:56 13,822 a------- c:\windows\system32\39f5vir500z.exe
2009-03-16 11:37 7,956 a------- c:\windows\system32\5d95addware314z.bin
2009-03-16 09:41 8,446 a------- c:\windows\56159oznloader2148.bin
2004-12-07 13:13 3,578,547 a------- c:\program files\ManagedDX.CAB
2004-12-07 13:13 1,156,363 a------- c:\program files\BDANT.cab
2004-12-07 13:13 703,080 a------- c:\program files\BDA.cab
2004-12-07 13:13 479,432 a------- c:\program files\dxsetup.exe
2004-12-07 13:13 13,265,040 a----r-- c:\program files\dxnt.cab
2004-12-07 13:13 2,249,416 a------- c:\program files\dsetup32.dll
2004-12-07 13:13 69,832 a------- c:\program files\DSETUP.dll
2004-12-07 13:13 15,493,481 a------- c:\program files\DirectX.cab
2004-12-07 13:13 976,020 a------- c:\program files\BDAXP.cab
2004-12-07 12:47 20,717 a------- c:\program files\DirectX SDK EULA.txt
============= FINISH: 9:49:02.10 ===============