Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: Win32.TDSS.rtk problem

  1. #1
    Junior Member
    Join Date
    Aug 2009
    Posts
    7

    Default Win32.TDSS.rtk problem

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:28:06 PM, on 8/24/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\Internet Content Filter\SafeEyes.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\Pmxmiced.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
    C:\Program Files\Palm\Hotsync.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Dell Network Assistant\hnm_svc.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lds.org/ldsorg/v/index.jsp?vg...001f5e340aRCRD
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://partnerpage.google.com/smallb...mb&ibd=6080415
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - Default URLSearchHook is missing
    O1 - Hosts: ::1 localhost
    O1 - Hosts: 209.44.111.57 prosoft.microsoft.com
    O1 - Hosts: 209.44.111.57 antivir-systempro.com
    O1 - Hosts: 209.44.111.57 www.antivir-systempro.com
    O1 - Hosts: 70.38.19.201 www.review.2009softwarereviews.com
    O1 - Hosts: 70.38.19.201 review.2009softwarereviews.com
    O1 - Hosts: 70.38.19.201 a1.review.zdnet.com
    O1 - Hosts: 70.38.19.201 www.d1.reviews.cnet.com
    O1 - Hosts: 70.38.19.201 www.reviews.toptenreviews.com
    O1 - Hosts: 70.38.19.201 reviews.toptenreviews.com
    O1 - Hosts: 70.38.19.201 www.reviews.download.com
    O1 - Hosts: 70.38.19.201 reviews.download.com
    O1 - Hosts: 70.38.19.201 www.reviews.pcadvisor.c.uk
    O1 - Hosts: 70.38.19.201 reviews.pcadvisor.co.uk
    O1 - Hosts: 70.38.19.201 www.reviews.pcmag.com
    O1 - Hosts: 70.38.19.201 reviews.pcmag.com
    O1 - Hosts: 70.38.19.201 www.reviews.pcpro.co.uk
    O1 - Hosts: 70.38.19.201 reviews.pcpro.co.uk
    O1 - Hosts: 70.38.19.201 www.reviews.reevoo.com
    O1 - Hosts: 70.38.19.201 reviews.reevoo.com
    O1 - Hosts: 70.38.19.201 www.reviews.riverstreams.co.uk
    O1 - Hosts: 70.38.19.201 reviews.riverstreams.co.uk
    O1 - Hosts: 70.38.19.201 www.reviews.techradar.com
    O1 - Hosts: 70.38.19.201 reviews.techradar.com
    O1 - Hosts: 70.38.19.201 d1.reviews.cnet.com
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
    O3 - Toolbar: Safe &Eyes Toolbar - {430DDB4F-38CC-4E91-AF33-4157334EC937} - C:\Program Files\Internet Content Filter\setoolbar.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ICF] "C:\Program Files\Internet Content Filter\SafeEyes.exe"
    O4 - HKLM\..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Cluffs\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Global Startup: Dell Network Assistant.lnk = ?
    O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O10 - Unknown file in Winsock LSP: icf.dll
    O10 - Unknown file in Winsock LSP: icf.dll
    O10 - Unknown file in Winsock LSP: icf.dll
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
    O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.mpix.com/customer/uploadi...eUploader5.cab
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AntipyProex (AntipPro2009_100) - Unknown owner - C:\WINDOWS\svchast.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Update Service (gupdate1c9dbc288d3f3a0) (gupdate1c9dbc288d3f3a0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

    --
    End of file - 11858 bytes

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi there,

    Download DDS and save it to your desktop from here or here or here.
    Disable any script blocker, and then double click dds.scr to run the tool.
    • When done, DDS will open two (2) logs:
      1. DDS.txt
      2. Attach.txt
    • Save both reports to your desktop. Post them back to your topic.


    Download GMER here by clicking download exe -button and then saving it your desktop:
    • Double-click .exe that you downloaded
    • Click rootkit-tab and then scan.
    • Don't check
      Show All
      box while scanning in progress!
    • When scanning is ready, click Copy.
    • This copies log to clipboard
    • Post log in your reply.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Junior Member
    Join Date
    Aug 2009
    Posts
    7

    Default

    Thanks for responding. I will do those things tonight when I get back home from work and post the logs.

  4. #4
    Junior Member
    Join Date
    Aug 2009
    Posts
    7

    Default Here are the Requested Logs

    Here are the requested logs. Let me know if you need anything else.


    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Cluffs at 21:36:40.95 on Thu 08/27/2009
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_05
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2037.1381 [GMT -7:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    svchost.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\Pmxmiced.exe
    C:\Program Files\Internet Content Filter\SafeEyes.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
    C:\Program Files\Palm\Hotsync.exe
    C:\Program Files\Dell Network Assistant\hnm_svc.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Cluffs\Desktop\dds.pif

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb
    uWindow Title =
    mWindow Title =
    uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
    uInternet Settings,ProxyOverride = *.local
    mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    TB: Safe &Eyes Toolbar: {430ddb4f-38cc-4e91-af33-4157334ec937} - c:\program files\internet content filter\setoolbar.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [cdloader] "c:\documents and settings\cluffs\application data\mjusbsp\cdloader2.exe" MAGICJACK
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
    mRun: [PMX Daemon] ICO.EXE
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
    mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [ICF] "c:\program files\internet content filter\SafeEyes.exe"
    mRun: [HotSync] "c:\program files\palmsource\desktop\HotSync.exe" -AllUsers
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellne~1.lnk - c:\windows\installer\{0240bdfb-2995-4a3f-8c96-18d41282b716}\Icon0240BDFB3.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    uPolicies-system: EnableProfileQuota = 1 (0x1)
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    LSP: ICF.dll
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mpix.com/customer/uploading/activex/ImageUploader5.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Notify: igfxcui - igfxdev.dll
    AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL

    ================= FIREFOX ===================

    FF - ProfilePath -
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============


    =============== Created Last 30 ================


    ==================== Find3M ====================


    ============= FINISH: 21:38:10.20 ===============



    *******************************************************************************************************************



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 5/3/2008 8:37:22 PM
    System Uptime: 8/27/2009 9:23:12 PM (0 hours ago)

    Motherboard: Dell Inc. | | 0CU409
    Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | Socket 775 | 1795/200mhz
    Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | Socket 775 | 1795/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 149 GiB total, 19.162 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is FIXED (FAT32) - 466 GiB total, 90.079 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP361: 8/25/2009 6:53:00 PM - Software Distribution Service 3.0
    RP362: 8/26/2009 8:26:15 AM - Software Distribution Service 3.0

    ==== Installed Programs ======================


    ==== Event Viewer Messages From Past Week ========


    ==== End Of File ===========================


    ********************************************************************************************************************

    GMER 1.0.15.14972 - http://www.gmer.net
    Rootkit scan 2009-08-28 04:07:07
    Windows 5.1.2600 Service Pack 2


    ---- System - GMER 1.0.15 ----

    Code 89728618 ZwEnumerateKey
    Code 8973A790 ZwFlushInstructionCache
    Code 89759216 IofCallDriver
    Code 8974C66E IofCompleteRequest

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!IofCallDriver 804EF1A0 5 Bytes JMP 8975921B
    .text ntkrnlpa.exe!IofCompleteRequest 804EF230 5 Bytes JMP 8974C673
    PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B5642 5 Bytes JMP 8973A794
    PAGE ntkrnlpa.exe!ZwEnumerateKey 80622DE0 5 Bytes JMP 8972861C

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\svchost.exe[184] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0075000A
    .text C:\WINDOWS\system32\svchost.exe[420] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0075000A
    .text C:\WINDOWS\system32\igfxtray.exe[532] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08AA000A
    .text C:\WINDOWS\system32\hkcmd.exe[540] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 08AA000A
    .text C:\WINDOWS\system32\igfxpers.exe[556] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A3000A
    .text ...
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!UnhookWindowsHookEx 7E41F21E 5 Bytes JMP 3E2543F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!CallNextHookEx 7E41F85B 5 Bytes JMP 3E2DCB69 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!SetWindowsHookExW 7E42DDB5 5 Bytes JMP 3E2E9521 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 3E2ED408 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[1240] ole32.dll!OleLoadFromStream 7752A257 5 Bytes JMP 3E3E3F78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\WINDOWS\system32\Pmxmiced.exe[1256] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 009E000A
    .text C:\WINDOWS\system32\rundll32.exe[1276] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 009C000A
    .text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1300] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00A5000A
    .text C:\WINDOWS\system32\ctfmon.exe[1304] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 088E000A
    .text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[1340] ntdll.dll!LdrLoadDll 7C915CD3 3 Bytes JMP 0092000A
    .text ...
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2504] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\WINDOWS\system32\HPZipm12.exe[2556] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 003D000A
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!UnhookWindowsHookEx 7E41F21E 5 Bytes JMP 3E2543F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!CallNextHookEx 7E41F85B 5 Bytes JMP 3E2DCB69 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!SetWindowsHookExW 7E42DDB5 5 Bytes JMP 3E2E9521 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 3E2ED408 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\iexplore.exe[2840] ole32.dll!OleLoadFromStream 7752A257 5 Bytes JMP 3E3E3F78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\WINDOWS\system32\svchost.exe[2968] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0075000A
    .text C:\Program Files\iPod\bin\iPodService.exe[3656] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0080000A
    .text C:\WINDOWS\system32\wscntfy.exe[4004] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0085000A

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Program Files\Internet Explorer\iexplore.exe[1240] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 0901B467
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 0901B27A
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 09016CA8
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 09017881
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CloseHandle] 0901962B
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 0901804D
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 09017A66
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileW] 09018EA6
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 0901AB0E
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalLock] 0901AB3E
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 0901B681
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 0901A868
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 090195BB
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] 0901870D
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 09017E61
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 090183A9
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 0901B9AD
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!ReadFile] 090190A5
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 090194B7
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 09019BFA
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 090198EA
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 09019BA8
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 0901A1E4
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 09019CF2
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] 09017C75
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 09018662
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 0901ABE9
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 090199AC
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileSize] 0901956E
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!WriteFile] 090192E2
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileType] 090196BB
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetACP] 0901B68D
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileMappingA] 09019881
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadIconW] 0901B812
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadCursorW] 0901B7E0
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateDialogParamW] 0901B935
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DialogBoxParamW] 0901B991
    IAT C:\Program Files\Dell Network Assistant\ezi_hnm2.exe[1792] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadStringW] 0901B87E
    IAT C:\Program Files\Internet Explorer\iexplore.exe[2840] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    Device \Driver\BTHUSB \Device\00000078 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
    Device \Driver\BTHUSB \Device\00000078 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
    Device \Driver\BTHUSB \Device\0000007a bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
    Device \Driver\BTHUSB \Device\0000007a bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
    Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

    ---- Services - GMER 1.0.15 ----

    Service C:\WINDOWS\system32\drivers\SKYNETxeyicomu.sys (*** hidden *** ) [SYSTEM] SKYNETrdvbrpxn <-- ROOTKIT !!!

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272c28428
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn@start 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn@type 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn@group file system
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn@imagepath \systemroot\system32\drivers\SKYNETxeyicomu.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\main
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\main@aid 10096
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\main@sid 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\main@cmddelay 14400
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\main\delete
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\main\injector
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\main\injector@* SKYNETwsp.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\main\tasks
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\modules
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETxeyicomu.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\modules@SKYNETcmd.dll \systemroot\system32\SKYNETpvymnmsu.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\modules@SKYNETlog.dat \systemroot\system32\SKYNETbfrkdldo.dat
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\modules@SKYNETwsp.dll \systemroot\system32\SKYNETulkasued.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETrdvbrpxn\modules@SKYNET.dat \systemroot\system32\SKYNETcjsmetqi.dat
    Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000272c28428
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn@start 1
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn@type 1
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn@group file system
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn@imagepath \systemroot\system32\drivers\SKYNETxeyicomu.sys
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\main
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\main@aid 10096
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\main@sid 0
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\main@cmddelay 14400
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\main\delete
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\main\injector
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\main\injector@* SKYNETwsp.dll
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\main\tasks
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\modules
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETxeyicomu.sys
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\modules@SKYNETcmd.dll \systemroot\system32\SKYNETpvymnmsu.dll
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\modules@SKYNETlog.dat \systemroot\system32\SKYNETbfrkdldo.dat
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\modules@SKYNETwsp.dll \systemroot\system32\SKYNETulkasued.dll
    Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETrdvbrpxn\modules@SKYNET.dat \systemroot\system32\SKYNETcjsmetqi.dat

    ---- Files - GMER 1.0.15 ----

    File C:\WINDOWS\system32\drivers\SKYNETxeyicomu.sys 69120 bytes executable <-- ROOTKIT !!!
    File C:\WINDOWS\system32\SKYNETbfrkdldo.dat 827862 bytes
    File C:\WINDOWS\system32\SKYNETcjsmetqi.dat 91 bytes
    File C:\WINDOWS\system32\SKYNETpvymnmsu.dll 45056 bytes executable
    File C:\WINDOWS\system32\SKYNETulkasued.dll 20992 bytes executable

    ---- EOF - GMER 1.0.15 ----

  5. #5
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Thanks for the logs Some further instructions next.


    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:

    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.


    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds.txt log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  6. #6
    Junior Member
    Join Date
    Aug 2009
    Posts
    7

    Default Additional Logs Requested

    Here are the additional logs requested. Thanks.


    ComboFix 09-08-28.01 - Cluffs 08/28/2009 21:22.1.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2037.1674 [GMT -7:00]
    Running from: c:\documents and settings\Cluffs\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\AB
    c:\documents and settings\Cluffs\Application Data\EurekaLog
    c:\documents and settings\Cluffs\Application Data\EurekaLog\EurekaLog.ini
    c:\program files\driver
    c:\windows\Fonts\Wphv07nb.ttf
    c:\windows\Installer\1ed659.msi
    c:\windows\Installer\1ed65a.msp
    c:\windows\Installer\1ed65b.msp
    c:\windows\Installer\1ed65c.msp
    c:\windows\Installer\1ed65d.msp
    c:\windows\Installer\1ed65e.msp
    c:\windows\Installer\1ed65f.msp
    c:\windows\Installer\1ed660.msp
    c:\windows\Installer\1ed661.msp
    c:\windows\Installer\1ed662.msp
    c:\windows\Installer\1ed663.msp
    c:\windows\system32\drivers\SKYNETxeyicomu.sys
    c:\windows\system32\SKYNETbfrkdldo.dat
    c:\windows\system32\SKYNETcjsmetqi.dat
    c:\windows\system32\SKYNETpvymnmsu.dll
    c:\windows\system32\SKYNETulkasued.dll

    c:\windows\system32\proquota.exe was missing
    Restored copy from - c:\i386\proquota.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_SKYNETrdvbrpxn
    -------\Legacy_SKYNETrdvbrpxn
    -------\Legacy_DRIVER
    -------\Legacy_DRIVERDRV


    ((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-29 )))))))))))))))))))))))))))))))
    .

    2009-08-29 04:28 . 2004-08-04 10:00 50176 ----a-w- c:\windows\system32\proquota.exe
    2009-08-29 04:28 . 2004-08-04 10:00 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
    2009-08-26 01:53 . 2009-08-26 01:58 -------- d-----w- c:\documents and settings\Cluffs\logitech
    2009-08-26 01:52 . 2009-08-26 01:53 -------- d-----w- c:\program files\Common Files\Remote Control Software Common
    2009-08-26 01:52 . 2009-08-26 01:52 -------- d-----w- c:\program files\Common Files\Remote Control USB Driver
    2009-08-26 01:52 . 2009-08-26 01:52 127034 ------r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
    2009-08-26 01:52 . 2009-08-26 01:52 -------- d-----w- c:\program files\Logitech
    2009-08-25 04:25 . 2009-08-25 04:26 -------- d-----w- c:\program files\ERUNT
    2009-08-24 00:17 . 2009-08-24 00:17 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
    2009-08-23 23:46 . 2009-08-23 23:46 -------- d-----w- C:\_OTM
    2009-08-23 23:38 . 2009-08-23 23:38 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2009-08-22 16:44 . 2009-08-22 16:44 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
    2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\windows\system32\XPSViewer
    2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\program files\MSBuild
    2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\program files\Reference Assemblies
    2009-08-18 05:01 . 2009-08-18 05:01 -------- d-----w- c:\windows\system32\LogFiles
    2009-08-12 10:00 . 2009-08-12 10:00 -------- d-----w- c:\windows\ServicePackFiles
    2009-08-11 22:20 . 2009-06-05 07:42 655872 ------w- c:\windows\system32\dllcache\mstscax.dll
    2009-08-05 09:11 . 2009-08-05 09:11 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-08-29 04:32 . 2008-04-15 03:09 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-08-28 04:24 . 2008-05-05 01:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
    2009-08-26 01:52 . 2008-04-15 03:03 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-08-24 00:17 . 2009-06-24 02:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-08-24 00:14 . 2009-07-05 23:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-23 17:39 . 2008-05-04 03:37 133736 ----a-w- c:\documents and settings\Cluffs\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-08-13 04:25 . 2009-07-05 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2009-08-05 09:11 . 2004-08-10 17:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-03 20:36 . 2009-06-24 02:47 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 20:36 . 2009-06-24 02:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-07-26 17:17 . 2009-04-18 03:57 -------- d-----w- c:\program files\Palm
    2009-07-17 18:55 . 2004-08-10 17:50 58880 ----a-w- c:\windows\system32\atl.dll
    2009-07-13 09:18 . 2004-08-10 17:51 233472 ----a-w- c:\windows\system32\wmpdxm.dll
    2009-07-09 03:36 . 2009-07-02 03:28 -------- d-----w- c:\documents and settings\Cluffs\Application Data\Image Zone Express
    2009-07-06 01:11 . 2009-07-06 01:11 -------- d-----w- c:\program files\Trend Micro
    2009-07-06 00:24 . 2009-07-06 00:24 -------- d-----w- c:\program files\Browser Hijack Recover
    2009-07-05 23:50 . 2009-07-05 23:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-07-05 23:34 . 2009-07-05 23:34 -------- d-----w- c:\program files\CleanUp!
    2009-07-05 18:29 . 2009-07-05 18:29 -------- d-----w- c:\program files\AVG
    2009-07-03 18:53 . 2008-09-06 15:46 57536 ----a-w- c:\windows\system32\drivers\ftdibus.sys
    2009-07-03 18:53 . 2008-09-06 15:46 202048 ----a-w- c:\windows\system32\ftd2xx.dll
    2009-07-03 18:53 . 2008-09-06 15:46 185664 ----a-w- c:\windows\system32\FTLang.dll
    2009-07-03 18:53 . 2008-09-06 15:46 120128 ----a-w- c:\windows\system32\ftbusui.dll
    2009-07-03 18:03 . 2009-07-03 17:46 -------- d-----w- c:\program files\Lame for Audacity
    2009-07-03 17:44 . 2009-07-03 17:44 -------- d-----w- c:\program files\Audacity
    2009-07-03 17:34 . 2009-07-03 17:34 -------- d-----w- c:\program files\BCS
    2009-07-03 17:09 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
    2009-06-25 08:17 . 2004-08-10 17:51 59392 ----a-w- c:\windows\system32\wdigest.dll
    2009-06-25 08:17 . 2004-08-10 17:51 56320 ----a-w- c:\windows\system32\secur32.dll
    2009-06-25 08:17 . 2004-08-10 17:51 168448 ----a-w- c:\windows\system32\schannel.dll
    2009-06-25 08:17 . 2004-08-10 17:51 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-06-25 08:17 . 2004-08-10 17:51 729600 ----a-w- c:\windows\system32\lsasrv.dll
    2009-06-25 08:17 . 2004-08-10 17:51 301568 ----a-w- c:\windows\system32\kerberos.dll
    2009-06-22 11:35 . 2004-08-10 17:51 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2009-06-16 14:55 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
    2009-06-16 14:55 . 2004-08-10 17:51 82432 ----a-w- c:\windows\system32\fontsub.dll
    2009-06-12 11:50 . 2004-08-10 17:51 76288 ----a-w- c:\windows\system32\telnet.exe
    2009-06-10 14:21 . 2004-08-10 17:50 84992 ----a-w- c:\windows\system32\avifil32.dll
    2009-06-10 06:32 . 2004-08-10 17:51 132096 ----a-w- c:\windows\system32\wkssvc.dll
    2009-06-05 14:43 . 2009-06-05 14:43 1144 ----a-w- c:\windows\checkip.dat
    2009-06-05 07:42 . 2004-08-10 18:01 655872 ----a-w- c:\windows\system32\mstscax.dll
    2009-06-03 19:27 . 2004-08-10 17:51 1290752 ----a-w- c:\windows\system32\quartz.dll
    2009-04-16 04:43 . 2009-04-16 04:12 8081 ----a-w- c:\program files\gsak.ini
    2009-04-16 04:41 . 2009-04-16 04:12 29 ----a-w- c:\program files\dbfindex.bif
    2009-04-16 04:41 . 2009-04-16 04:12 22528 ----a-w- c:\program files\gsak.db3
    2009-04-16 04:12 . 2009-04-16 04:12 5120 ----a-w- c:\program files\POST.NSX
    2009-04-16 04:12 . 2009-04-16 04:12 226 ----a-w- c:\program files\POST.DBF
    2008-10-01 04:40 . 2008-10-01 04:40 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-15 68856]
    "cdloader"="c:\documents and settings\Cluffs\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-14 142104]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-14 162584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-14 138008]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
    "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
    "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-01 29744]
    "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-01-18 17920]
    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-14 16384]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
    "ICF"="c:\program files\Internet Content Filter\SafeEyes.exe" [2008-07-29 1256960]
    "PMX Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2006-11-08 49152]
    "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-06-14 16132608]
    "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]

    c:\documents and settings\Cluffs\Start Menu\Programs\Startup\
    Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-4-14 7168]
    HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2008-1-3 1392640]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
    Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-8-25 67128]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
    "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Documents and Settings\\Cluffs\\Application Data\\mjusbsp\\magicJack.exe"=
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
    "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
    "c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
    "10426:UDP"= 10426:UDP:SingleClick ICC

    R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [5/3/2008 8:31 PM 18432]
    R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [5/3/2008 8:31 PM 14336]
    S2 AntipPro2009_100;AntipyProex;c:\windows\svchast.exe --> c:\windows\svchast.exe [?]
    S2 gupdate1c9dbc288d3f3a0;Google Update Service (gupdate1c9dbc288d3f3a0);c:\program files\Google\Update\GoogleUpdate.exe [5/23/2009 9:21 AM 133104]
    S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [4/14/2008 8:05 PM 29744]

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    .
    Contents of the 'Scheduled Tasks' folder

    2009-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57]

    2009-08-29 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-15 15:45]

    2009-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-23 16:21]

    2009-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-23 16:21]

    2009-08-28 c:\windows\Tasks\SyncBack Becs Notebook My Docs.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack Becs Notebook Pics.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack Bk-up Oulook.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack Favorites.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack My Docs.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack My Pictures.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-29 c:\windows\Tasks\User_Feed_Synchronization-{792CECEB-CAD7-4A8C-86D8-9008FECB745A}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    HKLM-Run-HotSync - c:\program files\PalmSource\Desktop\HotSync.exe


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    mWindow Title =
    uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    LSP: ICF.dll
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    FF - ProfilePath - c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    FF - component: c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\extensions\{7E7165E2-0767-448c-852F-5FA8714F2C37}\components\PlainOldFavorites.dll
    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
    FF - plugin: c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - plugin: c:\progra~1\Palm\PACKAG~1\NPInstal.dll
    FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-08-28 21:31
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'lsass.exe'(828)
    c:\windows\system32\ICF.dll

    - - - - - - - > 'explorer.exe'(3312)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\pmxscrll.dll
    c:\windows\system32\PMXCOMM.dll
    c:\windows\system32\PMXHOOKS.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Dell Network Assistant\hnm_svc.exe
    c:\program files\CDBurnerXP\NMSAccessU.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\igfxsrvc.exe
    c:\windows\system32\pmxmiced.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Dell Support Center\gs_agent\dsc.exe
    c:\program files\Dell Network Assistant\ezi_hnm2.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\HP\Digital Imaging\bin\hpqste08.exe
    c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    .
    **************************************************************************
    .
    Completion time: 2009-08-29 21:36 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-08-29 04:35

    Pre-Run: 20,463,857,664 bytes free
    Post-Run: 21,507,186,688 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    287 --- E O F --- 2009-08-26 15:26




    ********************************************************



    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Cluffs at 21:40:20.39 on Fri 08/28/2009
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_05
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2037.1440 [GMT -7:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    svchost.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Dell Network Assistant\hnm_svc.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\Pmxmiced.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Internet Content Filter\SafeEyes.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Dell Support Center\gs_agent\dsc.exe
    C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
    C:\Program Files\Palm\Hotsync.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Cluffs\Desktop\dds.pif

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    mWindow Title =
    uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
    uInternet Settings,ProxyOverride = *.local
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    TB: Safe &Eyes Toolbar: {430ddb4f-38cc-4e91-af33-4157334ec937} - c:\program files\internet content filter\setoolbar.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [cdloader] "c:\documents and settings\cluffs\application data\mjusbsp\cdloader2.exe" MAGICJACK
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
    mRun: [PMX Daemon] ICO.EXE
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
    mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [ICF] "c:\program files\internet content filter\SafeEyes.exe"
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellne~1.lnk - c:\windows\installer\{0240bdfb-2995-4a3f-8c96-18d41282b716}\Icon0240BDFB3.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    LSP: ICF.dll
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mpix.com/customer/uploading/activex/ImageUploader5.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Notify: igfxcui - igfxdev.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\cluffs\applic~1\mozilla\firefox\profiles\iz669p5k.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    FF - component: c:\documents and settings\cluffs\application data\mozilla\firefox\profiles\iz669p5k.default\extensions\{7e7165e2-0767-448c-852f-5fa8714f2c37}\components\PlainOldFavorites.dll
    FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    FF - plugin: c:\documents and settings\cluffs\application data\mozilla\firefox\profiles\iz669p5k.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll
    FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-5-3 18432]
    R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-5-3 14336]
    S2 AntipPro2009_100;AntipyProex;c:\windows\svchast.exe --> c:\windows\svchast.exe [?]
    S2 gupdate1c9dbc288d3f3a0;Google Update Service (gupdate1c9dbc288d3f3a0);c:\program files\google\update\GoogleUpdate.exe [2009-5-23 133104]
    S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-4-14 29744]

    =============== Created Last 30 ================

    2009-08-28 21:34 <DIR> --d----- c:\windows\system32\dllcache\cache
    2009-08-28 21:28 50,176 a------- c:\windows\system32\proquota.exe
    2009-08-28 21:28 50,176 a------- c:\windows\system32\dllcache\proquota.exe
    2009-08-28 21:16 <DIR> a-dshr-- C:\cmdcons
    2009-08-28 21:14 229,376 a------- c:\windows\PEV.exe
    2009-08-28 21:14 161,792 a------- c:\windows\SWREG.exe
    2009-08-28 21:14 98,816 a------- c:\windows\sed.exe
    2009-08-25 18:53 <DIR> --d----- c:\documents and settings\cluffs\logitech
    2009-08-25 18:52 <DIR> --d----- c:\program files\common files\Remote Control Software Common
    2009-08-25 18:52 <DIR> --d----- c:\program files\common files\Remote Control USB Driver
    2009-08-25 18:52 127,034 -----r-- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
    2009-08-23 16:46 <DIR> --d----- C:\_OTM
    2009-08-23 16:38 664 a------- c:\windows\system32\d3d9caps.dat
    2009-08-22 22:01 1,089,601 -------- c:\windows\system32\dllcache\ntprint.cat
    2009-08-22 09:44 <DIR> --d----- c:\windows\system32\XPSViewer
    2009-08-17 22:01 <DIR> --d----- c:\windows\system32\LogFiles
    2009-08-12 03:00 <DIR> --d----- c:\windows\ServicePackFiles
    2009-08-11 15:20 128,512 -------- c:\windows\system32\dllcache\dhtmled.ocx
    2009-08-11 15:20 655,872 -------- c:\windows\system32\dllcache\mstscax.dll
    2009-08-05 02:11 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll

    ==================== Find3M ====================

    2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll
    2009-08-03 13:36 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 13:36 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-07-19 18:48 11,067,392 -------- c:\windows\system32\dllcache\ieframe.dll
    2009-07-19 06:18 5,937,152 a------- c:\windows\system32\dllcache\cache\mshtml.dll
    2009-07-19 06:18 5,937,152 -------- c:\windows\system32\dllcache\mshtml.dll
    2009-07-17 11:55 58,880 a------- c:\windows\system32\atl.dll
    2009-07-17 11:55 58,880 -------- c:\windows\system32\dllcache\atl.dll
    2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
    2009-07-13 02:18 233,472 -------- c:\windows\system32\dllcache\wmpdxm.dll
    2009-07-13 02:18 4,960,256 -------- c:\windows\system32\dllcache\wmp.dll
    2009-07-10 06:42 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
    2009-07-03 11:53 202,048 a------- c:\windows\system32\ftd2xx.dll
    2009-07-03 11:53 185,664 a------- c:\windows\system32\FTLang.dll
    2009-07-03 11:53 120,128 a------- c:\windows\system32\ftbusui.dll
    2009-07-03 11:53 57,536 a------- c:\windows\system32\drivers\ftdibus.sys
    2009-07-03 04:01 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
    2009-06-25 01:17 729,600 a------- c:\windows\system32\lsasrv.dll
    2009-06-25 01:17 301,568 a------- c:\windows\system32\kerberos.dll
    2009-06-25 01:17 168,448 a------- c:\windows\system32\schannel.dll
    2009-06-25 01:17 136,192 a------- c:\windows\system32\msv1_0.dll
    2009-06-25 01:17 59,392 a------- c:\windows\system32\wdigest.dll
    2009-06-25 01:17 56,320 a------- c:\windows\system32\secur32.dll
    2009-06-25 01:17 729,600 -------- c:\windows\system32\dllcache\lsasrv.dll
    2009-06-25 01:17 301,568 -------- c:\windows\system32\dllcache\kerberos.dll
    2009-06-25 01:17 168,448 -------- c:\windows\system32\dllcache\schannel.dll
    2009-06-25 01:17 136,192 -------- c:\windows\system32\dllcache\msv1_0.dll
    2009-06-25 01:17 59,392 -------- c:\windows\system32\dllcache\wdigest.dll
    2009-06-25 01:17 56,320 -------- c:\windows\system32\dllcache\secur32.dll
    2009-06-22 04:35 92,544 -------- c:\windows\system32\dllcache\ksecdd.sys
    2009-06-16 07:55 119,808 a------- c:\windows\system32\t2embed.dll
    2009-06-16 07:55 82,432 a------- c:\windows\system32\fontsub.dll
    2009-06-16 07:55 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
    2009-06-16 07:55 82,432 -------- c:\windows\system32\dllcache\fontsub.dll
    2009-06-12 04:50 76,288 a------- c:\windows\system32\telnet.exe
    2009-06-12 04:50 76,288 -------- c:\windows\system32\dllcache\telnet.exe
    2009-06-10 07:21 84,992 a------- c:\windows\system32\avifil32.dll
    2009-06-10 07:21 84,992 -------- c:\windows\system32\dllcache\avifil32.dll
    2009-06-09 23:32 132,096 a------- c:\windows\system32\wkssvc.dll
    2009-06-09 23:32 132,096 -------- c:\windows\system32\dllcache\wkssvc.dll
    2009-06-05 00:42 655,872 a------- c:\windows\system32\mstscax.dll
    2009-06-03 12:27 1,290,752 a------- c:\windows\system32\quartz.dll
    2009-06-03 12:27 1,290,752 -------- c:\windows\system32\dllcache\quartz.dll
    2009-06-02 03:12 102,912 -------- c:\windows\system32\dllcache\iecompat.dll
    2009-04-15 21:43 8,081 a------- c:\program files\gsak.ini
    2009-04-15 21:41 29 a------- c:\program files\dbfindex.bif
    2009-04-15 21:41 22,528 a------- c:\program files\gsak.db3
    2009-04-15 21:12 5,120 a------- c:\program files\POST.NSX
    2009-04-15 21:12 226 a------- c:\program files\POST.DBF
    2008-06-25 18:56 17,144 a------- c:\docume~1\cluffs\applic~1\GDIPFONTCACHEV1.DAT

    ============= FINISH: 21:40:39.06 ===============

  7. #7
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    Driver::
    AntipPro2009_100
    File::
    c:\windows\svchast.exe
    DDS::
    mWindow Title =

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.


    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.



    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 16.
    • Click the
      Download
      button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u16-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.



    Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


    Post back its report, fresh DDS logs (both created ones) and above mentioned ComboFix resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  8. #8
    Junior Member
    Join Date
    Aug 2009
    Posts
    7

    Default Requested Files Attached

    ComboFix 09-08-28.05 - Cluffs 08/29/2009 6:38.2.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2037.1481 [GMT -7:00]
    Running from: c:\documents and settings\Cluffs\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Cluffs\Desktop\CFScript.txt

    FILE ::
    "c:\windows\svchast.exe"
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_ANTIPPRO2009_100
    -------\Service_AntipPro2009_100


    ((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-29 )))))))))))))))))))))))))))))))
    .

    2009-08-29 04:28 . 2004-08-04 10:00 50176 ----a-w- c:\windows\system32\proquota.exe
    2009-08-29 04:28 . 2004-08-04 10:00 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
    2009-08-26 01:53 . 2009-08-26 01:58 -------- d-----w- c:\documents and settings\Cluffs\logitech
    2009-08-26 01:52 . 2009-08-26 01:53 -------- d-----w- c:\program files\Common Files\Remote Control Software Common
    2009-08-26 01:52 . 2009-08-26 01:52 -------- d-----w- c:\program files\Common Files\Remote Control USB Driver
    2009-08-26 01:52 . 2009-08-26 01:52 127034 ------r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
    2009-08-26 01:52 . 2009-08-26 01:52 -------- d-----w- c:\program files\Logitech
    2009-08-25 04:25 . 2009-08-25 04:26 -------- d-----w- c:\program files\ERUNT
    2009-08-24 00:17 . 2009-08-24 00:17 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
    2009-08-23 23:46 . 2009-08-23 23:46 -------- d-----w- C:\_OTM
    2009-08-23 23:38 . 2009-08-23 23:38 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2009-08-22 16:44 . 2009-08-22 16:44 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
    2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\windows\system32\XPSViewer
    2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\program files\MSBuild
    2009-08-22 16:44 . 2009-08-22 16:44 -------- d-----w- c:\program files\Reference Assemblies
    2009-08-18 05:01 . 2009-08-18 05:01 -------- d-----w- c:\windows\system32\LogFiles
    2009-08-12 10:00 . 2009-08-12 10:00 -------- d-----w- c:\windows\ServicePackFiles
    2009-08-11 22:20 . 2009-06-05 07:42 655872 ------w- c:\windows\system32\dllcache\mstscax.dll
    2009-08-05 09:11 . 2009-08-05 09:11 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-08-29 13:43 . 2008-04-15 03:09 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-08-29 05:25 . 2008-05-05 01:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
    2009-08-26 01:52 . 2008-04-15 03:03 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-08-24 00:17 . 2009-06-24 02:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-08-24 00:14 . 2009-07-05 23:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-23 17:39 . 2008-05-04 03:37 133736 ----a-w- c:\documents and settings\Cluffs\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-08-13 04:25 . 2009-07-05 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2009-08-05 09:11 . 2004-08-10 17:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-03 20:36 . 2009-06-24 02:47 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 20:36 . 2009-06-24 02:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-07-26 17:17 . 2009-04-18 03:57 -------- d-----w- c:\program files\Palm
    2009-07-17 18:55 . 2004-08-10 17:50 58880 ----a-w- c:\windows\system32\atl.dll
    2009-07-13 09:18 . 2004-08-10 17:51 233472 ----a-w- c:\windows\system32\wmpdxm.dll
    2009-07-09 03:36 . 2009-07-02 03:28 -------- d-----w- c:\documents and settings\Cluffs\Application Data\Image Zone Express
    2009-07-06 01:11 . 2009-07-06 01:11 -------- d-----w- c:\program files\Trend Micro
    2009-07-06 00:24 . 2009-07-06 00:24 -------- d-----w- c:\program files\Browser Hijack Recover
    2009-07-05 23:50 . 2009-07-05 23:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-07-05 23:34 . 2009-07-05 23:34 -------- d-----w- c:\program files\CleanUp!
    2009-07-05 18:29 . 2009-07-05 18:29 -------- d-----w- c:\program files\AVG
    2009-07-03 18:53 . 2008-09-06 15:46 57536 ----a-w- c:\windows\system32\drivers\ftdibus.sys
    2009-07-03 18:53 . 2008-09-06 15:46 202048 ----a-w- c:\windows\system32\ftd2xx.dll
    2009-07-03 18:53 . 2008-09-06 15:46 185664 ----a-w- c:\windows\system32\FTLang.dll
    2009-07-03 18:53 . 2008-09-06 15:46 120128 ----a-w- c:\windows\system32\ftbusui.dll
    2009-07-03 18:03 . 2009-07-03 17:46 -------- d-----w- c:\program files\Lame for Audacity
    2009-07-03 17:44 . 2009-07-03 17:44 -------- d-----w- c:\program files\Audacity
    2009-07-03 17:34 . 2009-07-03 17:34 -------- d-----w- c:\program files\BCS
    2009-07-03 17:09 . 2004-08-10 17:51 915456 ------w- c:\windows\system32\wininet.dll
    2009-06-25 08:17 . 2004-08-10 17:51 59392 ----a-w- c:\windows\system32\wdigest.dll
    2009-06-25 08:17 . 2004-08-10 17:51 56320 ----a-w- c:\windows\system32\secur32.dll
    2009-06-25 08:17 . 2004-08-10 17:51 168448 ----a-w- c:\windows\system32\schannel.dll
    2009-06-25 08:17 . 2004-08-10 17:51 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-06-25 08:17 . 2004-08-10 17:51 729600 ----a-w- c:\windows\system32\lsasrv.dll
    2009-06-25 08:17 . 2004-08-10 17:51 301568 ----a-w- c:\windows\system32\kerberos.dll
    2009-06-22 11:35 . 2004-08-10 17:51 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2009-06-16 14:55 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
    2009-06-16 14:55 . 2004-08-10 17:51 82432 ----a-w- c:\windows\system32\fontsub.dll
    2009-06-12 11:50 . 2004-08-10 17:51 76288 ----a-w- c:\windows\system32\telnet.exe
    2009-06-10 14:21 . 2004-08-10 17:50 84992 ----a-w- c:\windows\system32\avifil32.dll
    2009-06-10 06:32 . 2004-08-10 17:51 132096 ----a-w- c:\windows\system32\wkssvc.dll
    2009-06-05 14:43 . 2009-06-05 14:43 1144 ----a-w- c:\windows\checkip.dat
    2009-06-05 07:42 . 2004-08-10 18:01 655872 ----a-w- c:\windows\system32\mstscax.dll
    2009-06-03 19:27 . 2004-08-10 17:51 1290752 ----a-w- c:\windows\system32\quartz.dll
    2009-04-16 04:43 . 2009-04-16 04:12 8081 ----a-w- c:\program files\gsak.ini
    2009-04-16 04:41 . 2009-04-16 04:12 29 ----a-w- c:\program files\dbfindex.bif
    2009-04-16 04:41 . 2009-04-16 04:12 22528 ----a-w- c:\program files\gsak.db3
    2009-04-16 04:12 . 2009-04-16 04:12 5120 ----a-w- c:\program files\POST.NSX
    2009-04-16 04:12 . 2009-04-16 04:12 226 ----a-w- c:\program files\POST.DBF
    2008-10-01 04:40 . 2008-10-01 04:40 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-08-29_04.31.37 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2004-08-10 17:51 . 2009-08-29 04:35 71936 c:\windows\system32\perfc009.dat
    - 2004-08-10 17:51 . 2009-08-29 04:26 71936 c:\windows\system32\perfc009.dat
    + 2004-08-10 17:51 . 2009-08-29 04:35 442796 c:\windows\system32\perfh009.dat
    - 2004-08-10 17:51 . 2009-08-29 04:26 442796 c:\windows\system32\perfh009.dat
    + 2009-08-29 04:32 . 2009-08-29 04:32 180224 c:\windows\ERDNT\AutoBackup\8-28-2009\Users\00000002\UsrClass.dat
    + 2009-08-29 04:32 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\8-28-2009\ERDNT.EXE
    + 2009-08-29 04:32 . 2009-08-29 04:32 7069696 c:\windows\ERDNT\AutoBackup\8-28-2009\Users\00000001\NTUSER.DAT
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-15 68856]
    "cdloader"="c:\documents and settings\Cluffs\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-14 142104]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-14 162584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-14 138008]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
    "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
    "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-01 29744]
    "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-01-18 17920]
    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-14 16384]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
    "ICF"="c:\program files\Internet Content Filter\SafeEyes.exe" [2008-07-29 1256960]
    "PMX Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2006-11-08 49152]
    "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-06-14 16132608]
    "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]

    c:\documents and settings\Cluffs\Start Menu\Programs\Startup\
    Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-4-14 7168]
    HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2008-1-3 1392640]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
    Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-8-25 67128]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
    "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Documents and Settings\\Cluffs\\Application Data\\mjusbsp\\magicJack.exe"=
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
    "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
    "c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
    "10426:UDP"= 10426:UDP:SingleClick ICC

    R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [5/3/2008 8:31 PM 18432]
    R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [5/3/2008 8:31 PM 14336]
    S2 gupdate1c9dbc288d3f3a0;Google Update Service (gupdate1c9dbc288d3f3a0);c:\program files\Google\Update\GoogleUpdate.exe [5/23/2009 9:21 AM 133104]
    S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [4/14/2008 8:05 PM 29744]

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    .
    Contents of the 'Scheduled Tasks' folder

    2009-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57]

    2009-08-29 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-15 15:45]

    2009-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-23 16:21]

    2009-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-23 16:21]

    2009-08-28 c:\windows\Tasks\SyncBack Becs Notebook My Docs.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack Becs Notebook Pics.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack Bk-up Oulook.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack Favorites.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-28 c:\windows\Tasks\SyncBack My Docs.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-29 c:\windows\Tasks\SyncBack My Pictures.job
    - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-05-05 18:19]

    2009-08-29 c:\windows\Tasks\User_Feed_Synchronization-{792CECEB-CAD7-4A8C-86D8-9008FECB745A}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    LSP: ICF.dll
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    FF - ProfilePath - c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    FF - component: c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\extensions\{7E7165E2-0767-448c-852F-5FA8714F2C37}\components\PlainOldFavorites.dll
    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
    FF - plugin: c:\documents and settings\Cluffs\Application Data\Mozilla\Firefox\Profiles\iz669p5k.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - plugin: c:\progra~1\Palm\PACKAG~1\NPInstal.dll
    FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-08-29 06:42
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'lsass.exe'(828)
    c:\windows\system32\ICF.dll

    - - - - - - - > 'explorer.exe'(524)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\pmxscrll.dll
    c:\windows\system32\PMXCOMM.dll
    c:\windows\system32\PMXHOOKS.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Dell Network Assistant\hnm_svc.exe
    c:\program files\CDBurnerXP\NMSAccessU.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\igfxsrvc.exe
    c:\windows\system32\pmxmiced.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Dell Network Assistant\ezi_hnm2.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\HP\Digital Imaging\bin\hpqste08.exe
    c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    .
    **************************************************************************
    .
    Completion time: 2009-08-29 6:47 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-08-29 13:47
    ComboFix2.txt 2009-08-29 04:36

    Pre-Run: 21,574,889,472 bytes free
    Post-Run: 21,502,197,760 bytes free

    261 --- E O F --- 2009-08-26 15:26


    ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++




    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Sunday, August 30, 2009
    Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Saturday, August 29, 2009 16:20:51
    Records in database: 2701691
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\
    F:\

    Scan statistics:
    Objects scanned: 261884
    Threats found: 6
    Infected objects found: 7
    Suspicious objects found: 2
    Scan duration: 03:10:47


    File name / Threat / Threats count
    C:\Documents and Settings\Cluffs\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Hotmail - Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_SKYNETxeyicomu_.sys.zip Infected: Rootkit.Win32.TDSS.q 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETpvymnmsu.dll.vir Infected: Trojan.Win32.Monder.cpxu 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETulkasued.dll.vir Infected: Trojan.Win32.Small.bzc 1
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP363\A0040736.dll Infected: Trojan.Win32.Monder.cpxu 1
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP363\A0040737.dll Infected: Trojan.Win32.Small.bzc 1
    C:\_OTM\MovedFiles\08232009_164642\WINDOWS\svchast.exe Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.iv 1
    C:\_OTM\MovedFiles\08232009_164642\WINDOWS\system32\desot.exe Infected: not-a-virus:FraudTool.Win32.Antivirus2008pro.bq 1
    F:\Bk Up Outlook\Hotmail - Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1

    Selected area has been scanned.



    ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++




    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 5/3/2008 8:37:22 PM
    System Uptime: 8/30/2009 1:00:12 PM (6 hours ago)

    Motherboard: Dell Inc. | | 0CU409
    Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | Socket 775 | 1794/200mhz
    Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | Socket 775 | 1795/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 149 GiB total, 19.888 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is FIXED (FAT32) - 466 GiB total, 90.078 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP361: 8/25/2009 6:53:00 PM - Software Distribution Service 3.0
    RP362: 8/26/2009 8:26:15 AM - Software Distribution Service 3.0
    RP363: 8/27/2009 9:55:43 PM - System Checkpoint
    RP364: 8/28/2009 10:03:46 PM - System Checkpoint
    RP365: 8/29/2009 6:30:56 AM - Removed J2SE Runtime Environment 5.0 Update 6
    RP366: 8/29/2009 6:32:07 AM - Removed Java(TM) 6 Update 5
    RP367: 8/29/2009 6:50:15 AM - Installed Java(TM) 6 Update 16

    ==== Installed Programs ======================

    5600
    5600_Help
    5600Trb
    Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
    Adobe Bridge 1.0
    Adobe Common File Installer
    Adobe Flash Player ActiveX
    Adobe Flash Player Plugin
    Adobe Help Center 1.0
    Adobe Photoshop CS2
    Adobe Reader 8.1.2
    Adobe Reader 8.1.2 Security Update 1 (KB403742)
    Adobe Stock Photos 1.0
    AiO_Scan
    AiOSoftware
    Apple Mobile Device Support
    Apple Software Update
    Audacity 1.2.6
    Batch Watermark Creator 6.1.1
    Bonjour
    BookSmart™ 1.9.9 1.9.9
    Browser Address Error Redirector
    Browser Hijack Recover(BHR) 3.0
    BufferChm
    CDBurnerXP
    CleanUp!
    CP_Package_Variety1
    CP_Package_Variety2
    CP_Package_Variety3
    Dell Driver Reset Tool
    Dell Network Assistant
    Dell Support Center (Support Software)
    Destinations
    DeviceManagementQFolder
    DocProc
    Dragon Tales
    Easy Thumbnails (Remove only)
    ERUNT 1.1j
    eSupportQFolder
    ExifPro 1.0 Photo Viewer
    Fax
    Free RAR Extract Frog 1.00
    Garmin POI Loader
    Garmin USB Drivers
    Garmin WebUpdater
    Google Desktop
    Google Earth Plugin
    Google Toolbar for Internet Explorer
    Google Update Helper
    Google Updater
    GSAK 7.6.0.51 (Final)
    High Definition Audio Driver Package - KB835221
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows XP (KB906569)
    Hotfix for Windows XP (KB908673)
    Hotfix for Windows XP (KB909095)
    Hotfix for Windows XP (KB914440)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB921411)
    Hotfix for Windows XP (KB924455)
    Hotfix for Windows XP (KB934428-v2)
    Hotfix for Windows XP (KB935448)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    HP Image Zone Express
    HP Imaging Device Functions 5.3
    HP PSC & OfficeJet 5.3.B
    HP Software Update
    HP Solution Center & Imaging Support Tools 5.3
    HPProductAssistant
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) PRO Network Connections 12.1.8.0
    iTunes
    Java(TM) 6 Update 16
    LAME v3.98.2 for Audacity
    Logitech Desktop Messenger
    Logitech Harmony Remote Software 7
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Professional
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Mouse Suite for Desktop Computers
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.0.12)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 6 Service Pack 2 (KB954459)
    NewCopy
    Palm Desktop by ACCESS
    PowerDVD
    ProductContext
    QuickTime
    Readme
    Realtek High Definition Audio Driver
    Remote Control USB Driver
    Roxio Creator Audio
    Roxio Creator BDAV Plugin
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator DE
    Roxio Creator Tools
    Roxio Drag-to-Disc
    Roxio Express Labeler
    Roxio Update Manager
    Safe Eyes
    Scan
    ScannerCopy
    SearchAssist
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB941693)
    Security Update for Windows XP (KB942615)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944338)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB947864)
    Security Update for Windows XP (KB948590)
    Security Update for Windows XP (KB948881)
    Security Update for Windows XP (KB950749)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958470)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    SolutionCenter
    Sonic Activation Module
    Spoiler Sync
    Spybot - Search & Destroy
    Status
    SyncBack
    TrayApp
    Unload
    Update for Windows Internet Explorer 8 (KB971930)
    Update for Windows XP (KB894391)
    Update for Windows XP (KB896256)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB904942)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB912945)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB925720)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB932823-v3)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB946627)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB973815)
    WebFldrs XP
    WebReg
    Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB885884
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB889673
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    YourBell

    ==== Event Viewer Messages From Past Week ========

    8/29/2009 6:31:12 AM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
    8/28/2009 9:22:21 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
    8/28/2009 9:17:42 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
    8/26/2009 12:47:01 AM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.102. The machine with the IP address 192.168.1.100 did not allow the name to be claimed by this machine.
    8/25/2009 8:09:38 PM, error: Service Control Manager [7024] - The Computer Browser service terminated with service-specific error 2250 (0x8CA).
    8/25/2009 8:07:45 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
    8/25/2009 8:02:46 PM, error: Service Control Manager [7000] - The AntipyProex service failed to start due to the following error: The system cannot find the file specified.
    8/25/2009 8:02:29 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001D0994F944 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    8/25/2009 6:56:46 AM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.103. The machine with the IP address 192.168.1.101 did not allow the name to be claimed by this machine.
    8/25/2009 6:54:08 PM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.100. The machine with the IP address 192.168.1.101 did not allow the name to be claimed by this machine.
    8/25/2009 6:53:00 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume3'. It has stopped monitoring the volume.
    8/25/2009 6:51:09 PM, error: BTHUSB [17] - The local Bluetooth radio has failed in an undetermined manner and will be unloaded.
    8/25/2009 6:50:53 PM, error: Dhcp [1002] - The IP address lease 192.168.1.103 for the Network Card with network address 001D0994F944 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    8/25/2009 6:15:01 AM, error: HTTP [15005] - Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number.
    8/23/2009 5:35:38 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
    8/23/2009 5:09:31 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    8/23/2009 5:09:31 PM, error: Service Control Manager [7022] - The Bonjour Service service hung on starting.
    8/23/2009 4:40:12 PM, error: Service Control Manager [7034] - The AntipyProex service terminated unexpectedly. It has done this 1 time(s).
    8/23/2009 11:48:01 AM, error: Service Control Manager [7024] - The Background Intelligent Transfer Service service terminated with service-specific error 2147942402 (0x80070002).
    8/23/2009 11:47:43 AM, error: Service Control Manager [7038] - The SSDPSRV service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The handle is invalid. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
    8/23/2009 11:47:43 AM, error: Service Control Manager [7000] - The SSDP Discovery Service service failed to start due to the following error: The service did not start due to a logon failure.
    8/23/2009 11:47:39 AM, error: Service Control Manager [7023] - The Remote Access Connection Manager service terminated with the following error: Incorrect function.
    8/23/2009 11:47:39 AM, error: Rasman [20033] - Remote Access Connection Manager failed to start because it could not register with the local security authority. Restart the computer. Incorrect function.
    8/23/2009 11:46:28 AM, error: Service Control Manager [7023] - The IPSEC Services service terminated with the following error: The requested service provider could not be loaded or initialized.
    8/23/2009 10:40:06 AM, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s).

    ==== End Of File ===========================



    +++++++++++++++++++++++++++++++++++++++++++++++++++




    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Cluffs at 19:30:48.54 on Sun 08/30/2009
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2037.1224 [GMT -7:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    svchost.exe
    C:\Program Files\Dell Network Assistant\hnm_svc.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\Pmxmiced.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Internet Content Filter\SafeEyes.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
    C:\Program Files\Palm\Hotsync.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Java\jre6\bin\java.exe
    C:\Documents and Settings\Cluffs\Local Settings\temp\jkos-Cluffs\binaries\ScanningProcess.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Documents and Settings\Cluffs\Desktop\dds.pif

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
    uInternet Settings,ProxyOverride = *.local
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Safe &Eyes Toolbar: {430ddb4f-38cc-4e91-af33-4157334ec937} - c:\program files\internet content filter\setoolbar.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [cdloader] "c:\documents and settings\cluffs\application data\mjusbsp\cdloader2.exe" MAGICJACK
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [PMX Daemon] ICO.EXE
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
    mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [ICF] "c:\program files\internet content filter\SafeEyes.exe"
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellne~1.lnk - c:\windows\installer\{0240bdfb-2995-4a3f-8c96-18d41282b716}\Icon0240BDFB3.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    LSP: ICF.dll
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mpix.com/customer/uploading/activex/ImageUploader5.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Notify: igfxcui - igfxdev.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\cluffs\applic~1\mozilla\firefox\profiles\iz669p5k.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    FF - component: c:\documents and settings\cluffs\application data\mozilla\firefox\profiles\iz669p5k.default\extensions\{7e7165e2-0767-448c-852f-5fa8714f2c37}\components\PlainOldFavorites.dll
    FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-5-3 18432]
    R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-5-3 14336]
    S2 gupdate1c9dbc288d3f3a0;Google Update Service (gupdate1c9dbc288d3f3a0);c:\program files\google\update\GoogleUpdate.exe [2009-5-23 133104]
    S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-4-14 29744]

    =============== Created Last 30 ================

    2009-08-29 06:50 411,368 a------- c:\windows\system32\deploytk.dll
    2009-08-29 06:50 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-08-28 21:34 <DIR> --d----- c:\windows\system32\dllcache\cache
    2009-08-28 21:28 50,176 a------- c:\windows\system32\proquota.exe
    2009-08-28 21:28 50,176 a------- c:\windows\system32\dllcache\proquota.exe
    2009-08-28 21:16 <DIR> a-dshr-- C:\cmdcons
    2009-08-28 21:14 229,376 a------- c:\windows\PEV.exe
    2009-08-28 21:14 161,792 a------- c:\windows\SWREG.exe
    2009-08-28 21:14 98,816 a------- c:\windows\sed.exe
    2009-08-25 18:53 <DIR> --d----- c:\documents and settings\cluffs\logitech
    2009-08-25 18:52 <DIR> --d----- c:\program files\common files\Remote Control Software Common
    2009-08-25 18:52 <DIR> --d----- c:\program files\common files\Remote Control USB Driver
    2009-08-25 18:52 127,034 -----r-- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
    2009-08-23 16:46 <DIR> --d----- C:\_OTM
    2009-08-23 16:38 664 a------- c:\windows\system32\d3d9caps.dat
    2009-08-22 22:01 1,089,601 -------- c:\windows\system32\dllcache\ntprint.cat
    2009-08-22 09:44 <DIR> --d----- c:\windows\system32\XPSViewer
    2009-08-17 22:01 <DIR> --d----- c:\windows\system32\LogFiles
    2009-08-12 03:00 <DIR> --d----- c:\windows\ServicePackFiles
    2009-08-11 15:20 128,512 -------- c:\windows\system32\dllcache\dhtmled.ocx
    2009-08-11 15:20 655,872 -------- c:\windows\system32\dllcache\mstscax.dll
    2009-08-05 02:11 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll

    ==================== Find3M ====================

    2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll
    2009-08-03 13:36 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 13:36 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-07-19 18:48 11,067,392 -------- c:\windows\system32\dllcache\ieframe.dll
    2009-07-19 06:18 5,937,152 a------- c:\windows\system32\dllcache\cache\mshtml.dll
    2009-07-19 06:18 5,937,152 -------- c:\windows\system32\dllcache\mshtml.dll
    2009-07-17 11:55 58,880 a------- c:\windows\system32\atl.dll
    2009-07-17 11:55 58,880 -------- c:\windows\system32\dllcache\atl.dll
    2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
    2009-07-13 02:18 233,472 -------- c:\windows\system32\dllcache\wmpdxm.dll
    2009-07-13 02:18 4,960,256 -------- c:\windows\system32\dllcache\wmp.dll
    2009-07-10 06:42 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
    2009-07-03 11:53 202,048 a------- c:\windows\system32\ftd2xx.dll
    2009-07-03 11:53 185,664 a------- c:\windows\system32\FTLang.dll
    2009-07-03 11:53 120,128 a------- c:\windows\system32\ftbusui.dll
    2009-07-03 11:53 57,536 a------- c:\windows\system32\drivers\ftdibus.sys
    2009-07-03 04:01 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
    2009-06-25 01:17 729,600 a------- c:\windows\system32\lsasrv.dll
    2009-06-25 01:17 301,568 a------- c:\windows\system32\kerberos.dll
    2009-06-25 01:17 168,448 a------- c:\windows\system32\schannel.dll
    2009-06-25 01:17 136,192 a------- c:\windows\system32\msv1_0.dll
    2009-06-25 01:17 59,392 a------- c:\windows\system32\wdigest.dll
    2009-06-25 01:17 56,320 a------- c:\windows\system32\secur32.dll
    2009-06-25 01:17 729,600 -------- c:\windows\system32\dllcache\lsasrv.dll
    2009-06-25 01:17 301,568 -------- c:\windows\system32\dllcache\kerberos.dll
    2009-06-25 01:17 168,448 -------- c:\windows\system32\dllcache\schannel.dll
    2009-06-25 01:17 136,192 -------- c:\windows\system32\dllcache\msv1_0.dll
    2009-06-25 01:17 59,392 -------- c:\windows\system32\dllcache\wdigest.dll
    2009-06-25 01:17 56,320 -------- c:\windows\system32\dllcache\secur32.dll
    2009-06-22 04:35 92,544 -------- c:\windows\system32\dllcache\ksecdd.sys
    2009-06-16 07:55 119,808 a------- c:\windows\system32\t2embed.dll
    2009-06-16 07:55 82,432 a------- c:\windows\system32\fontsub.dll
    2009-06-16 07:55 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
    2009-06-16 07:55 82,432 -------- c:\windows\system32\dllcache\fontsub.dll
    2009-06-12 04:50 76,288 a------- c:\windows\system32\telnet.exe
    2009-06-12 04:50 76,288 -------- c:\windows\system32\dllcache\telnet.exe
    2009-06-10 07:21 84,992 a------- c:\windows\system32\avifil32.dll
    2009-06-10 07:21 84,992 -------- c:\windows\system32\dllcache\avifil32.dll
    2009-06-09 23:32 132,096 a------- c:\windows\system32\wkssvc.dll
    2009-06-09 23:32 132,096 -------- c:\windows\system32\dllcache\wkssvc.dll
    2009-06-05 00:42 655,872 a------- c:\windows\system32\mstscax.dll
    2009-06-03 12:27 1,290,752 a------- c:\windows\system32\quartz.dll
    2009-06-03 12:27 1,290,752 -------- c:\windows\system32\dllcache\quartz.dll
    2009-06-02 03:12 102,912 -------- c:\windows\system32\dllcache\iecompat.dll
    2009-04-15 21:43 8,081 a------- c:\program files\gsak.ini
    2009-04-15 21:41 29 a------- c:\program files\dbfindex.bif
    2009-04-15 21:41 22,528 a------- c:\program files\gsak.db3
    2009-04-15 21:12 5,120 a------- c:\program files\POST.NSX
    2009-04-15 21:12 226 a------- c:\program files\POST.DBF
    2008-06-25 18:56 17,144 a------- c:\docume~1\cluffs\applic~1\GDIPFONTCACHEV1.DAT

    ============= FINISH: 19:31:27.18 ===============

  9. #9
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Check email messages in C:\Documents and Settings\Cluffs\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Hotmail - Inbox.dbx mailbox and delete suspicious looking ones.

    Get update 8.1.6 for Adobe Reader here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.


    Uninstall vulnerable Flash versions by following instructions here. Fresh version can be obtained here.

    Post a fresh dds.txt log. How's the system running?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  10. #10
    Junior Member
    Join Date
    Aug 2009
    Posts
    7

    Default

    My computer is running much better! It no longer tries to install bogus anti-virus software and it no longer redirects me to different websites that I don't want to go to when I click on links from doing a search.

    Here are the logs you requested.


    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Cluffs at 18:40:42.00 on Mon 08/31/2009
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2037.1291 [GMT -7:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    svchost.exe
    C:\Program Files\Dell Network Assistant\hnm_svc.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\Pmxmiced.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Internet Content Filter\SafeEyes.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
    C:\Program Files\Palm\Hotsync.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\wuauclt.exe
    c:\progra~1\common~1\instal~1\update~1\isuspm.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\DllHost.exe
    C:\WINDOWS\System32\svchost.exe -k getPlusHelper
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Cluffs\Desktop\dds.pif

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080415
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Safe &Eyes Toolbar: {430ddb4f-38cc-4e91-af33-4157334ec937} - c:\program files\internet content filter\setoolbar.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [cdloader] "c:\documents and settings\cluffs\application data\mjusbsp\cdloader2.exe" MAGICJACK
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [PMX Daemon] ICO.EXE
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
    mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [ICF] "c:\program files\internet content filter\SafeEyes.exe"
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /Get1noarp
    StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\cluffs\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellne~1.lnk - c:\windows\installer\{0240bdfb-2995-4a3f-8c96-18d41282b716}\Icon0240BDFB3.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    LSP: ICF.dll
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mpix.com/customer/uploading/activex/ImageUploader5.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Notify: igfxcui - igfxdev.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\cluffs\applic~1\mozilla\firefox\profiles\iz669p5k.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.lds.org/ldsorg/v/index.jsp?vgnextoid=e419fb40e21cef00VgnVCM1000001f5e340aRCRD
    FF - component: c:\documents and settings\cluffs\application data\mozilla\firefox\profiles\iz669p5k.default\extensions\{7e7165e2-0767-448c-852f-5fa8714f2c37}\components\PlainOldFavorites.dll
    FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    FF - plugin: c:\documents and settings\cluffs\application data\mozilla\firefox\profiles\iz669p5k.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll
    FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-10 14336]
    R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-5-3 18432]
    R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-5-3 14336]
    S2 gupdate1c9dbc288d3f3a0;Google Update Service (gupdate1c9dbc288d3f3a0);c:\program files\google\update\GoogleUpdate.exe [2009-5-23 133104]
    S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-4-14 29744]

    =============== Created Last 30 ================

    2009-08-30 19:33 388,608 a------- c:\windows\system32\CF32348.exe
    2009-08-29 06:50 411,368 a------- c:\windows\system32\deploytk.dll
    2009-08-29 06:50 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-08-28 21:34 <DIR> --d----- c:\windows\system32\dllcache\cache
    2009-08-28 21:28 50,176 a------- c:\windows\system32\proquota.exe
    2009-08-28 21:28 50,176 a------- c:\windows\system32\dllcache\proquota.exe
    2009-08-28 21:16 <DIR> a-dshr-- C:\cmdcons
    2009-08-25 18:53 <DIR> --d----- c:\documents and settings\cluffs\logitech
    2009-08-25 18:52 <DIR> --d----- c:\program files\common files\Remote Control Software Common
    2009-08-25 18:52 <DIR> --d----- c:\program files\common files\Remote Control USB Driver
    2009-08-25 18:52 127,034 -----r-- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
    2009-08-23 16:46 <DIR> --d----- C:\_OTM
    2009-08-23 16:38 664 a------- c:\windows\system32\d3d9caps.dat
    2009-08-22 22:01 1,089,601 -------- c:\windows\system32\dllcache\ntprint.cat
    2009-08-22 09:44 <DIR> --d----- c:\windows\system32\XPSViewer
    2009-08-17 22:01 <DIR> --d----- c:\windows\system32\LogFiles
    2009-08-12 03:00 <DIR> --d----- c:\windows\ServicePackFiles
    2009-08-11 15:20 128,512 -------- c:\windows\system32\dllcache\dhtmled.ocx
    2009-08-11 15:20 655,872 -------- c:\windows\system32\dllcache\mstscax.dll
    2009-08-05 02:11 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll

    ==================== Find3M ====================

    2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll
    2009-08-03 13:36 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 13:36 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-07-19 18:48 11,067,392 -------- c:\windows\system32\dllcache\ieframe.dll
    2009-07-19 06:18 5,937,152 a------- c:\windows\system32\dllcache\cache\mshtml.dll
    2009-07-19 06:18 5,937,152 -------- c:\windows\system32\dllcache\mshtml.dll
    2009-07-17 11:55 58,880 a------- c:\windows\system32\atl.dll
    2009-07-17 11:55 58,880 -------- c:\windows\system32\dllcache\atl.dll
    2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
    2009-07-13 02:18 233,472 -------- c:\windows\system32\dllcache\wmpdxm.dll
    2009-07-13 02:18 4,960,256 -------- c:\windows\system32\dllcache\wmp.dll
    2009-07-10 06:42 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
    2009-07-03 11:53 202,048 a------- c:\windows\system32\ftd2xx.dll
    2009-07-03 11:53 185,664 a------- c:\windows\system32\FTLang.dll
    2009-07-03 11:53 120,128 a------- c:\windows\system32\ftbusui.dll
    2009-07-03 11:53 57,536 a------- c:\windows\system32\drivers\ftdibus.sys
    2009-07-03 04:01 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
    2009-06-25 01:17 729,600 a------- c:\windows\system32\lsasrv.dll
    2009-06-25 01:17 301,568 a------- c:\windows\system32\kerberos.dll
    2009-06-25 01:17 168,448 a------- c:\windows\system32\schannel.dll
    2009-06-25 01:17 136,192 a------- c:\windows\system32\msv1_0.dll
    2009-06-25 01:17 59,392 a------- c:\windows\system32\wdigest.dll
    2009-06-25 01:17 56,320 a------- c:\windows\system32\secur32.dll
    2009-06-25 01:17 729,600 -------- c:\windows\system32\dllcache\lsasrv.dll
    2009-06-25 01:17 301,568 -------- c:\windows\system32\dllcache\kerberos.dll
    2009-06-25 01:17 168,448 -------- c:\windows\system32\dllcache\schannel.dll
    2009-06-25 01:17 136,192 -------- c:\windows\system32\dllcache\msv1_0.dll
    2009-06-25 01:17 59,392 -------- c:\windows\system32\dllcache\wdigest.dll
    2009-06-25 01:17 56,320 -------- c:\windows\system32\dllcache\secur32.dll
    2009-06-22 04:35 92,544 -------- c:\windows\system32\dllcache\ksecdd.sys
    2009-06-16 07:55 119,808 a------- c:\windows\system32\t2embed.dll
    2009-06-16 07:55 82,432 a------- c:\windows\system32\fontsub.dll
    2009-06-16 07:55 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
    2009-06-16 07:55 82,432 -------- c:\windows\system32\dllcache\fontsub.dll
    2009-06-12 04:50 76,288 a------- c:\windows\system32\telnet.exe
    2009-06-12 04:50 76,288 -------- c:\windows\system32\dllcache\telnet.exe
    2009-06-10 07:21 84,992 a------- c:\windows\system32\avifil32.dll
    2009-06-10 07:21 84,992 -------- c:\windows\system32\dllcache\avifil32.dll
    2009-06-09 23:32 132,096 a------- c:\windows\system32\wkssvc.dll
    2009-06-09 23:32 132,096 -------- c:\windows\system32\dllcache\wkssvc.dll
    2009-06-05 00:42 655,872 a------- c:\windows\system32\mstscax.dll
    2009-06-03 12:27 1,290,752 a------- c:\windows\system32\quartz.dll
    2009-06-03 12:27 1,290,752 -------- c:\windows\system32\dllcache\quartz.dll
    2009-04-15 21:43 8,081 a------- c:\program files\gsak.ini
    2009-04-15 21:41 29 a------- c:\program files\dbfindex.bif
    2009-04-15 21:41 22,528 a------- c:\program files\gsak.db3
    2009-04-15 21:12 5,120 a------- c:\program files\POST.NSX
    2009-04-15 21:12 226 a------- c:\program files\POST.DBF
    2008-06-25 18:56 17,144 a------- c:\docume~1\cluffs\applic~1\GDIPFONTCACHEV1.DAT

    ============= FINISH: 18:40:58.67 ===============



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 5/3/2008 8:37:22 PM
    System Uptime: 8/30/2009 1:00:12 PM (29 hours ago)

    Motherboard: Dell Inc. | | 0CU409
    Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | Socket 775 | 1794/200mhz
    Processor: Intel(R) Pentium(R) Dual CPU E2160 @ 1.80GHz | Socket 775 | 1795/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 149 GiB total, 19.496 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is FIXED (FAT32) - 466 GiB total, 90.078 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP361: 8/25/2009 6:53:00 PM - Software Distribution Service 3.0
    RP362: 8/26/2009 8:26:15 AM - Software Distribution Service 3.0
    RP363: 8/27/2009 9:55:43 PM - System Checkpoint
    RP364: 8/28/2009 10:03:46 PM - System Checkpoint
    RP365: 8/29/2009 6:30:56 AM - Removed J2SE Runtime Environment 5.0 Update 6
    RP366: 8/29/2009 6:32:07 AM - Removed Java(TM) 6 Update 5
    RP367: 8/29/2009 6:50:15 AM - Installed Java(TM) 6 Update 16
    RP368: 8/30/2009 7:58:01 PM - System Checkpoint
    RP369: 8/31/2009 6:59:40 AM - Removed Adobe Reader 8.1.2
    RP370: 8/31/2009 6:28:31 PM - Installed Adobe Reader 9.1.

    ==== Installed Programs ======================

    5600
    5600_Help
    5600Trb
    Acrobat.com
    Adobe AIR
    Adobe Bridge 1.0
    Adobe Common File Installer
    Adobe Download Manager
    Adobe Flash Player 10 ActiveX
    Adobe Help Center 1.0
    Adobe Photoshop CS2
    Adobe Reader 9.1
    Adobe Stock Photos 1.0
    AiO_Scan
    AiOSoftware
    Apple Mobile Device Support
    Apple Software Update
    Audacity 1.2.6
    Batch Watermark Creator 6.1.1
    Bonjour
    BookSmart™ 1.9.9 1.9.9
    Browser Address Error Redirector
    Browser Hijack Recover(BHR) 3.0
    BufferChm
    CDBurnerXP
    CleanUp!
    CP_Package_Variety1
    CP_Package_Variety2
    CP_Package_Variety3
    Dell Driver Reset Tool
    Dell Network Assistant
    Dell Support Center (Support Software)
    Destinations
    DeviceManagementQFolder
    DocProc
    Dragon Tales
    Easy Thumbnails (Remove only)
    ERUNT 1.1j
    eSupportQFolder
    ExifPro 1.0 Photo Viewer
    Fax
    Free RAR Extract Frog 1.00
    Garmin POI Loader
    Garmin USB Drivers
    Garmin WebUpdater
    Google Desktop
    Google Earth Plugin
    Google Toolbar for Internet Explorer
    Google Update Helper
    Google Updater
    GSAK 7.6.0.51 (Final)
    High Definition Audio Driver Package - KB835221
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows XP (KB906569)
    Hotfix for Windows XP (KB908673)
    Hotfix for Windows XP (KB909095)
    Hotfix for Windows XP (KB914440)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB921411)
    Hotfix for Windows XP (KB924455)
    Hotfix for Windows XP (KB934428-v2)
    Hotfix for Windows XP (KB935448)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    HP Image Zone Express
    HP Imaging Device Functions 5.3
    HP PSC & OfficeJet 5.3.B
    HP Software Update
    HP Solution Center & Imaging Support Tools 5.3
    HPProductAssistant
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) PRO Network Connections 12.1.8.0
    iTunes
    Java(TM) 6 Update 16
    LAME v3.98.2 for Audacity
    Logitech Desktop Messenger
    Logitech Harmony Remote Software 7
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Professional
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Mouse Suite for Desktop Computers
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.0.12)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 6 Service Pack 2 (KB954459)
    NewCopy
    Palm Desktop by ACCESS
    PowerDVD
    ProductContext
    QuickTime
    Readme
    Realtek High Definition Audio Driver
    Remote Control USB Driver
    Roxio Creator Audio
    Roxio Creator BDAV Plugin
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator DE
    Roxio Creator Tools
    Roxio Drag-to-Disc
    Roxio Express Labeler
    Roxio Update Manager
    Safe Eyes
    Scan
    ScannerCopy
    SearchAssist
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB941693)
    Security Update for Windows XP (KB942615)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944338)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB947864)
    Security Update for Windows XP (KB948590)
    Security Update for Windows XP (KB948881)
    Security Update for Windows XP (KB950749)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958470)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    SolutionCenter
    Sonic Activation Module
    Spoiler Sync
    Spybot - Search & Destroy
    Status
    SyncBack
    TrayApp
    Unload
    Update for Windows Internet Explorer 8 (KB971930)
    Update for Windows XP (KB894391)
    Update for Windows XP (KB896256)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB904942)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB912945)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB925720)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB932823-v3)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB946627)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB973815)
    WebFldrs XP
    WebReg
    Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB885884
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB889673
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    YourBell

    ==== Event Viewer Messages From Past Week ========

    8/29/2009 6:31:16 AM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
    8/28/2009 9:46:13 PM, error: Service Control Manager [7024] - The Computer Browser service terminated with service-specific error 2250 (0x8CA).
    8/28/2009 9:46:09 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
    8/28/2009 9:31:25 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
    8/28/2009 9:31:17 PM, error: Service Control Manager [7000] - The AntipyProex service failed to start due to the following error: The system cannot find the file specified.
    8/28/2009 9:27:20 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
    8/28/2009 9:22:21 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
    8/28/2009 10:42:48 PM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.102. The machine with the IP address 192.168.1.100 did not allow the name to be claimed by this machine.
    8/25/2009 8:02:29 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001D0994F944 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    8/25/2009 6:56:46 AM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.103. The machine with the IP address 192.168.1.101 did not allow the name to be claimed by this machine.
    8/25/2009 6:54:08 PM, error: NetBT [4321] - The name "BEC_NOTEBOOK :0" could not be registered on the Interface with IP address 192.168.1.100. The machine with the IP address 192.168.1.101 did not allow the name to be claimed by this machine.
    8/25/2009 6:53:00 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume3'. It has stopped monitoring the volume.
    8/25/2009 6:51:09 PM, error: BTHUSB [17] - The local Bluetooth radio has failed in an undetermined manner and will be unloaded.
    8/25/2009 6:50:53 PM, error: Dhcp [1002] - The IP address lease 192.168.1.103 for the Network Card with network address 001D0994F944 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    8/25/2009 6:15:01 AM, error: HTTP [15005] - Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number.

    ==== End Of File ===========================

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •