It took a long time to get Kaspersky to run to completion owing to my poor internet connection. However it is now done. The system is running well although internet speed is unusually slow. Not sure of the reason. I occasionally get a message saying "ESP NT system service launcher has encountered a problem and needs to close". This seems to temporarily freeze up the internet and also my BP security system.
Here are the log files you asked for:
ComboFix 09-11-02.02 - RW 11/04/2009 16:33.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.526 [GMT 11:00]
Running from: c:\documents and settings\RW\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\RW\Desktop\CFScript.txt
AV: BP Security Anti-Virus *On-access scanning disabled* (Updated) {2565CEEE-6BDB-4A6D-AD6D-F682F2695014}
FW: BP Security Firewall *disabled* {38254411-9AEC-4967-913E-F892C2A4DF89}
.
((((((((((((((((((((((((( Files Created from 2009-10-04 to 2009-11-04 )))))))))))))))))))))))))))))))
.
2009-11-04 02:11 . 2006-06-19 05:19 646 ----a-w- c:\windows\system32\hppapr03.DAT
2009-11-04 02:11 . 2006-06-08 05:20 323584 ----a-w- c:\windows\system32\hppcpr03.DLL
2009-10-31 21:04 . 2009-10-31 21:04 574 ----a-w- C:\cleanup.bat
2009-10-31 21:04 . 2009-10-31 21:04 135168 ----a-w- C:\zip.exe
2009-10-28 09:37 . 2009-10-28 09:37 -------- d-----w- c:\windows\LastGood(12)
2009-10-28 09:36 . 2009-10-28 09:36 -------- d-----w- c:\windows\LastGood(11)
2009-10-28 09:34 . 2009-10-28 09:34 -------- d-----w- c:\windows\LastGood(10)
2009-10-28 01:28 . 2009-10-28 01:28 -------- d-----w- c:\windows\LastGood(9)
2009-10-28 01:26 . 2009-10-28 01:26 -------- d-----w- c:\windows\LastGood(8)
2009-10-28 01:26 . 2009-10-28 01:26 -------- d-----w- c:\windows\LastGood(7)
2009-10-28 01:24 . 2009-10-28 01:24 -------- d-----w- c:\windows\LastGood(6)
2009-10-24 23:28 . 2009-10-24 23:28 -------- d-----w- c:\windows\LastGood(5)
2009-10-24 23:27 . 2009-10-24 23:27 -------- d-----w- c:\windows\LastGood(4)
2009-10-22 23:25 . 2009-10-22 23:25 -------- d-----w- c:\windows\LastGood(3)
2009-10-21 04:35 . 2009-10-21 04:35 -------- d-----w- c:\windows\LastGood(2)
2009-10-19 20:25 . 2009-11-02 23:47 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-19 19:32 . 2009-10-19 20:23 -------- d-----w- c:\windows\BDOSCAN8
2009-10-19 07:27 . 2009-10-19 20:25 -------- dc----w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-19 07:26 . 2009-10-19 20:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-16 20:30 . 2009-11-04 01:23 1324 ----a-w- c:\windows\system32\d3d9caps.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-04 05:13 . 2007-02-04 20:38 -------- d-----w- c:\documents and settings\RW\Application Data\Skype
2009-11-02 23:26 . 2007-02-13 23:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-18 02:14 . 2008-11-22 00:36 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-11 14:18 . 2005-08-15 20:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2005-08-15 20:18 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-03 07:05 . 2007-01-09 10:52 79032 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-03 06:59 . 2009-09-03 06:59 211928 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-29 07:36 . 2005-08-15 20:18 832512 ------w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2005-08-15 20:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2005-08-15 20:18 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2005-08-15 20:19 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 08:24 . 2005-08-15 20:40 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 08:24 . 2005-08-15 20:40 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 08:24 . 2005-08-15 20:40 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 08:24 . 2005-05-25 17:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 08:24 . 2005-08-15 20:40 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 08:24 . 2005-08-15 20:18 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 08:23 . 2005-08-15 20:40 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 08:23 . 2005-08-15 20:40 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-07-10 03:57 . 2009-07-10 03:57 526 ----a-w- c:\program files\Shortcut (2) to ComboFix.exe.lnk
2009-07-10 03:57 . 2009-07-10 03:57 526 ----a-w- c:\program files\Shortcut to ComboFix.exe.lnk
2009-07-10 01:48 . 2009-07-10 01:48 939956 ----a-w- c:\program files\7z465.exe
2009-07-08 13:41 . 2009-07-08 13:41 696 ----a-w- c:\program files\Malwarebytes' Anti-Malware.lnk
.
((((((((((((((((((((((((((((( SnapShot@2009-11-03_00.24.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-04 05:40 . 2009-11-04 05:40 16384 c:\windows\Temp\Perflib_Perfdata_b4.dat
+ 2009-11-04 05:12 . 2006-04-24 19:07 69120 c:\windows\system32\spool\prtprocs\w32x86\hpzpp43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:07 69120 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpzpp43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:07 69120 c:\windows\system32\spool\drivers\w32x86\3\hpzpp43e.dll
+ 2009-11-04 05:13 . 2004-08-04 01:26 619520 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\UNIRES.DLL
+ 2009-11-04 05:13 . 2004-08-04 01:26 197120 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\UNIDRVUI.DLL
+ 2009-11-04 05:12 . 2004-08-04 01:26 264704 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\UNIDRV.DLL
+ 2009-11-04 05:12 . 2004-07-09 16:56 169472 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\pclxl.dll
+ 2009-11-04 05:12 . 2006-04-24 16:39 562688 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpzss43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:07 408576 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpzev43e.dll
+ 2009-11-04 05:12 . 2006-04-28 02:10 663624 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpcdmc32.dll
+ 2009-11-04 05:12 . 2006-04-24 16:39 562688 c:\windows\system32\spool\drivers\w32x86\3\hpzss43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:07 408576 c:\windows\system32\spool\drivers\w32x86\3\hpzev43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:07 2461696 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpzui43e.dll
+ 2009-11-04 05:12 . 2006-04-24 15:31 3950592 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpzst43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:07 1390592 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpzls43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:08 1336320 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpz6r43e.dll
+ 2009-11-04 05:12 . 2006-06-01 09:41 1441792 c:\windows\system32\spool\drivers\w32x86\hewlett_packardhp_co79b4\hpbcfgre.dll
+ 2009-11-04 05:12 . 2006-04-24 19:07 2461696 c:\windows\system32\spool\drivers\w32x86\3\hpzui43e.dll
+ 2009-11-04 05:12 . 2006-04-24 15:31 3950592 c:\windows\system32\spool\drivers\w32x86\3\hpzst43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:07 1390592 c:\windows\system32\spool\drivers\w32x86\3\hpzls43e.dll
+ 2009-11-04 05:12 . 2006-04-24 19:08 1336320 c:\windows\system32\spool\drivers\w32x86\3\hpz6r43e.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-09 20480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-01-29 25370152]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-10 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-09 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-09 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-09 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-09 455168]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]
"CTSVolFE.exe"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2007-01-09 26112]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-07 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-10 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]
"EPSON Stylus Photo R250 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAHP.EXE" [2005-04-25 98304]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-02-23 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-01 155648]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"BigPondWirelessBroadbandCM"="c:\program files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" [2008-02-26 2162688]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-15 236016]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-07 148888]
"ESP"="c:\program files\bigpond\security\app\start.exe" [2009-01-27 62952]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-1-9 24576]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files (x86)\\BMC Software\\AppSight\\Bin\\BBXCOMServer.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Keys Server\\sntlkeyssrvr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 GRFILTER;Authentium NDIS Driver;c:\windows\system32\drivers\GRFilter.sys [1/27/2009 1:24 PM 21000]
R2 GRTdiMon;Authentium TDI Mon;c:\windows\system32\drivers\GRTdiMon.sys [1/27/2009 1:24 PM 39688]
R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;c:\windows\system32\drivers\hnm_wrls_pkt.sys [7/14/2006 4:01 AM 13824]
R2 SentinelKeysServer;Sentinel Keys Server;c:\program files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [7/11/2008 2:02 AM 328992]
R2 wsppkt;Wireless Security Protocol;c:\windows\system32\drivers\wsp_pkt.sys [7/14/2006 4:02 AM 13696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 cmo_bus;Data Modem @ CDMA Composite Device driver (WDM);c:\windows\system32\drivers\cmo_bus.sys [1/30/2007 7:02 PM 57744]
S3 cmo_mdfl;Data Modem @ CDMA Filter;c:\windows\system32\drivers\cmo_mdfl.sys [1/30/2007 7:03 PM 8304]
S3 cmo_mdm;Data Modem @ CDMA Drivers;c:\windows\system32\drivers\cmo_mdm.sys [1/30/2007 7:03 PM 93328]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\RW\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys --> c:\docume~1\RW\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [?]
S3 PAC7311;VGA USB Camera;c:\windows\system32\drivers\PA707UCM.SYS [3/12/2007 12:00 PM 155648]
S3 SWNC8U52;Sierra Wireless MUX NDIS Driver (UMTS52);c:\windows\system32\drivers\swnc8u52.sys [11/19/2007 6:06 PM 164480]
S3 SWUMX52;Sierra Wireless USB MUX Driver (UMTS52);c:\windows\system32\drivers\swumx52.sys [11/19/2007 6:06 PM 140672]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-11-04 c:\windows\Tasks\User_Feed_Synchronization-{FF301D7E-380D-484C-8D3F-4D6686D978DF}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 00:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/advanced_search?hl=en
uInternet Connection Wizard,ShellNext = hxxp://www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070109
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {1B4F9DD7-2D7C-44B5-9126-73206DA0AE75} - hxxp://files.authentium.com/bigpond/bin/wizard.exe
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} - hxxp://furano.miemasu.net:86/SysCamInst.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-04 16:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-792168025-4015722930-3137413640-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(416)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\windows\system32\brss01a.exe
c:\program files\bigpond\security\App\syssvcnt.exe
c:\program files\Common Files\Authentium\AntiVirus\dvpapi.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\system32\stacsv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\CNAB3RPK.EXE
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\bigpond\security\app\Console.exe
c:\program files\Skype\Plugin Manager\SkypePM.exe
.
**************************************************************************
.
Completion time: 2009-11-04 16:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-04 05:46
ComboFix2.txt 2009-11-03 10:25
Pre-Run: 19,052,883,968 bytes free
Post-Run: 18,965,577,728 bytes free
- - End Of File - - 34C80D3E8BD7F0B811E92A9DC38317C9
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, November 5, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, November 05, 2009 07:21:37
Records in database: 3134773
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Objects scanned: 82617
Threats found: 2
Infected objects found: 2
Suspicious objects found: 0
Scan duration: 02:05:10
File name / Threat / Threats count
C:\Documents and Settings\RW\Bin\cute3532.exe Infected: not-a-virus:AdWare.Win32.Aureate 1
C:\Program Files\unix2dos\setup.exe Infected: Trojan.Win32.BHO.abeo 1
Selected area has been scanned.
DDS (Ver_09-09-29.01) - NTFSx86
Run by RW at 22:16:48.03 on Thu 11/05/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.542 [GMT 11:00]
AV: BP Security Anti-Virus *On-access scanning disabled* (Updated) {2565CEEE-6BDB-4A6D-AD6D-F682F2695014}
FW: BP Security Firewall *disabled* {38254411-9AEC-4967-913E-F892C2A4DF89}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\CNAB3RPK.EXE
svchost.exe
c:\Program Files\bigpond\security\App\syssvcnt.exe
c:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
svchost.exe
C:\WINDOWS\system32\stacsv.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\RW\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com.au/advanced_search?hl=en
uInternet Connection Wizard,ShellNext = hxxp://www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070109
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\progra~1\skype\phone\ieplugin\SKYPEI~1.DLL
BHO: AuthPopupBHO01.cBHO: {3c7195f6-d788-4d50-ba72-2ee212edac78} - c:\program files\bigpond\security\app\popupbho01.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~3\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: BigPond Wireless Broadband 2.0 Auto Dial: {db92ec3f-697d-4c3b-9a3b-3abbd23d4a85} - c:\program files\telstra\bigpond wireless broadband 2.0\bpwbb2ad.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: BigPond Security Popup Blocker: {2c0a5f28-48d8-408b-9172-9c6121025bce} - c:\program files\bigpond\security\app\popupbho01.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [EPSON Stylus Photo R250 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAHP.EXE /P30 "EPSON Stylus Photo R250 Series" /O6 "USB001" /M "Stylus Photo R250"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [BigPondWirelessBroadbandCM] "c:\program files\telstra\bigpond wireless broadband 2.0\BigPond_CM.exe" -tsr
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [ESP] "c:\program files\bigpond\security\app\start.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\progra~1\skype\phone\ieplugin\SKYPEI~1.DLL
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~3\SDHelper.dll
DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {1B4F9DD7-2D7C-44B5-9126-73206DA0AE75} - hxxp://files.authentium.com/bigpond/bin/wizard.exe
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} - hxxp://furano.miemasu.net:86/SysCamInst.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R0 GRFILTER;Authentium NDIS Driver;c:\windows\system32\drivers\GRFilter.sys [2009-1-27 21000]
R2 GRTdiMon;Authentium TDI Mon;c:\windows\system32\drivers\GRTdiMon.sys [2009-1-27 39688]
R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;c:\windows\system32\drivers\hnm_wrls_pkt.sys [2006-7-14 13824]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 SentinelKeysServer;Sentinel Keys Server;c:\program files\common files\safenet sentinel\sentinel keys server\sntlkeyssrvr.exe [2008-7-11 328992]
R2 wsppkt;Wireless Security Protocol;c:\windows\system32\drivers\wsp_pkt.sys [2006-7-14 13696]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" --> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
S3 cmo_bus;Data Modem @ CDMA Composite Device driver (WDM);c:\windows\system32\drivers\cmo_bus.sys [2007-1-30 57744]
S3 cmo_mdfl;Data Modem @ CDMA Filter;c:\windows\system32\drivers\cmo_mdfl.sys [2007-1-30 8304]
S3 cmo_mdm;Data Modem @ CDMA Drivers;c:\windows\system32\drivers\cmo_mdm.sys [2007-1-30 93328]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\rw\locals~1\temp\onlinescanner\anti-virus\fsgk.sys --> c:\docume~1\rw\locals~1\temp\onlinescanner\anti-virus\fsgk.sys [?]
S3 PAC7311;VGA USB Camera;c:\windows\system32\drivers\PA707UCM.SYS [2007-3-12 155648]
S3 SWNC8U52;Sierra Wireless MUX NDIS Driver (UMTS52);c:\windows\system32\drivers\swnc8u52.sys [2007-11-19 164480]
S3 SWUMX52;Sierra Wireless USB MUX Driver (UMTS52);c:\windows\system32\drivers\swumx52.sys [2007-11-19 140672]
=============== Created Last 30 ================
2009-11-04 17:08 73,728 a------- c:\windows\system32\javacpl.cpl
2009-11-04 16:31 <DIR> --d----- C:\ComboFix
2009-11-04 13:11 323,584 a------- c:\windows\system32\hppcpr03.DLL
2009-11-04 13:11 646 a------- c:\windows\system32\hppapr03.DAT
2009-11-03 11:13 161,792 a------- c:\windows\SWREG.exe
2009-11-03 11:13 98,816 a------- c:\windows\sed.exe
2009-11-03 11:13 77,312 a------- c:\windows\MBR.exe
2009-11-01 08:04 135,168 a------- C:\zip.exe
2009-11-01 08:04 574 a------- C:\cleanup.bat
2009-10-28 20:37 <DIR> --d----- c:\windows\LastGood(12)
2009-10-28 20:36 <DIR> --d----- c:\windows\LastGood(11)
2009-10-28 20:34 <DIR> --d----- c:\windows\LastGood(10)
2009-10-28 12:28 <DIR> --d----- c:\windows\LastGood(9)
2009-10-28 12:26 <DIR> --d----- c:\windows\LastGood(8)
2009-10-28 12:26 <DIR> --d----- c:\windows\LastGood(7)
2009-10-28 12:24 <DIR> --d----- c:\windows\LastGood(6)
2009-10-25 10:28 <DIR> --d----- c:\windows\LastGood(5)
2009-10-25 10:27 <DIR> --d----- c:\windows\LastGood(4)
2009-10-23 10:25 <DIR> --d----- c:\windows\LastGood(3)
2009-10-21 15:35 <DIR> --d----- c:\windows\LastGood(2)
2009-10-20 07:25 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-10-19 18:27 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-17 07:30 1,324 a------- c:\windows\system32\d3d9caps.dat
==================== Find3M ====================
2009-11-04 17:08 411,368 a------- c:\windows\system32\deploytk.dll
2009-10-11 08:10 236,544 a------- c:\windows\PEV.exe
2009-09-12 01:18 136,192 a------- c:\windows\system32\msv1_0.dll
2009-09-12 01:18 136,192 -------- c:\windows\system32\dllcache\msv1_0.dll
2009-09-05 08:03 58,880 a------- c:\windows\system32\msasn1.dll
2009-09-05 08:03 58,880 -------- c:\windows\system32\dllcache\msasn1.dll
2009-08-28 21:28 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-08-28 21:28 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-08-27 16:18 634,648 -------- c:\windows\system32\dllcache\iexplore.exe
2009-08-27 16:18 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2009-08-26 19:00 247,326 a------- c:\windows\system32\strmdll.dll
2009-08-26 19:00 247,326 -------- c:\windows\system32\dllcache\strmdll.dll
2009-08-14 02:16 512,000 -------- c:\windows\system32\dllcache\jscript.dll
2009-07-10 14:57 526 a------- c:\program files\Shortcut (2) to ComboFix.exe.lnk
2009-07-10 14:57 526 a------- c:\program files\Shortcut to ComboFix.exe.lnk
2009-07-10 12:48 939,956 a------- c:\program files\7z465.exe
2009-07-09 00:41 696 a------- c:\program files\Malwarebytes' Anti-Malware.lnk
2007-01-31 09:48 124 a------- c:\docume~1\rw\applic~1\wklnhst.dat
2008-11-22 12:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008112220081123\index.dat
============= FINISH: 22:17:29.20 ===============