After spybot removes this trojan, it comes back whenever firefox is opened. I also get rundll error messages whenever the computer is restarted and we open windows. I also noticed that we are taken to a wrong website when opening from a google search. PLEASE NOTE: I think I may have run NTREGOPT by mistake in addition to ERUNT. Here is the DDS:
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Internet Content Filter\UpdateService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Steve-Julia\My Documents\Downloads\dds.com
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://swagbucks.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061212
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
{5ca3d70e-1895-11cf-8e15-001234567890}
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101119025859.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Safe &Eyes Toolbar: {430ddb4f-38cc-4e91-af33-4157334ec937} - c:\program files\internet content filter\setoolbar.dll
TB: {61539ECD-CC67-4437-A03C-9AACCBD14326} - No File
TB: {5BED3930-2E9E-76D8-BACC-80DF2188D455} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [A00F12700C0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F12700C0.exe
uRun: [A00FD4F88.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FD4F88.exe
uRun: [A00F274400.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F274400.exe
uRun: [A00F3ACDB.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3ACDB.exe
uRun: [A00F36AF0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F36AF0.exe
uRun: [A00F2725FBE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2725FBE.exe
uRun: [A00F326B805.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F326B805.exe
uRun: [A00F3945694.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3945694.exe
uRun: [A00FA7D9B.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FA7D9B.exe
uRun: [A00F5B5960.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F5B5960.exe
uRun: [A00F358E92.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F358E92.exe
uRun: [A00F64A98.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F64A98.exe
uRun: [A00F12BA01.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F12BA01.exe
uRun: [A00F16C94D3.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F16C94D3.exe
uRun: [A00F40B47.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F40B47.exe
uRun: [A00F818C1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F818C1.exe
uRun: [A00FAE7DE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FAE7DE.exe
uRun: [A00F126ADCE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F126ADCE.exe
uRun: [A00F20DA917.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F20DA917.exe
uRun: [A00F24EE1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F24EE1.exe
uRun: [A00F23BCAE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F23BCAE.exe
uRun: [A00F22D1037.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F22D1037.exe
uRun: [A00F381A4.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F381A4.exe
uRun: [A00F85A793.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F85A793.exe
uRun: [A00F19C8CAB.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F19C8CAB.exe
uRun: [A00F2987D40.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2987D40.exe
uRun: [A00F43BCE1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F43BCE1.exe
uRun: [A00F115DD2D.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F115DD2D.exe
uRun: [A00F166A9B0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F166A9B0.exe
uRun: [A00F20A1D9F.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F20A1D9F.exe
uRun: [A00F20F97E7.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F20F97E7.exe
uRun: [A00F35FA5.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F35FA5.exe
uRun: [A00F1B34794.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1B34794.exe
uRun: [A00F22362BC.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F22362BC.exe
uRun: [A00F5643E39.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F5643E39.exe
uRun: [A00F12DBB78.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F12DBB78.exe
uRun: [A00F1D06C17.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1D06C17.exe
uRun: [A00F273E16D.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F273E16D.exe
uRun: [A00F2837E60.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2837E60.exe
uRun: [A00F2590D2.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2590D2.exe
uRun: [A00F1421BC7.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1421BC7.exe
uRun: [A00F18F7EC0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F18F7EC0.exe
uRun: [A00F606E8.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F606E8.exe
uRun: [A00F39AC09.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F39AC09.exe
uRun: [A00F51CE6.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F51CE6.exe
uRun: [A00F16E8160.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F16E8160.exe
uRun: [A00F457C1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F457C1.exe
uRun: [A00F386E4.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F386E4.exe
uRun: [A00F319BD4.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F319BD4.exe
uRun: [A00F37550.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F37550.exe
uRun: [A00FF6C8C.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FF6C8C.exe
uRun: [A00F302030.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F302030.exe
uRun: [A00F3AFD9.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3AFD9.exe
uRun: [A00F291A7.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F291A7.exe
uRun: [A00F408F5.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F408F5.exe
uRun: [A00F3203B.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3203B.exe
uRun: [A00F89A722.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F89A722.exe
uRun: [A00FC8259C.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FC8259C.exe
uRun: [A00F3388EE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3388EE.exe
uRun: [A00FCB4838.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FCB4838.exe
uRun: [A00F3286547.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3286547.exe
uRun: [A00F41CC055.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F41CC055.exe
uRun: [A00F5691DE7.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F5691DE7.exe
uRun: [A00FA41E416.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FA41E416.exe
uRun: [A00FA75CE01.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FA75CE01.exe
uRun: [A00FB2576D1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FB2576D1.exe
uRun: [A00F36255.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F36255.exe
uRun: [A00F1509EC.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1509EC.exe
uRun: [A00F1F5C52.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1F5C52.exe
uRun: [A00FCDC147.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FCDC147.exe
uRun: [cdloader] "c:\documents and settings\steve-julia\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [A00F44AFEC.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F44AFEC.exe
uRun: [A00F3D30025.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3D30025.exe
uRun: [A00F4A715B9.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F4A715B9.exe
uRun: [A00F644A212.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F644A212.exe
uRun: [A00F2AFFD.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2AFFD.exe
uRun: [A00F294CE0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F294CE0.exe
uRun: [DelayShred] c:\progra~1\mcafee\mshr\shrcl.exe /p7 /q c:\docume~1\steve-~1\locals~1\temp\hsperf~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\1yfauv77\bx7fdb~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\4kemzvwg\bxa404~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\07jjgtda\bx8cd9~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\1yfauv77\bx6617~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\6u2lfv5t\bxe472~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\07jjgtda\bx8fee~1.sh! c:\docume~1\steve-~1\locals~1\temp\FROMCA~2.SH!
uRun: [Gbapewigamewob] rundll32.exe "c:\windows\otxtpr.dll",Startup
mRun: [monitr32] c:\program files\canon\multipass4\monitr32.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Zune Launcher] "e:\justin\ZuneLauncher.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [ICF] "c:\program files\internet content filter\SafeEyes.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe
mRun: [USB2Check] RUNDLL32.EXE "c:\windows\system32\PCLECoInst.dll",CheckUSBController
mRun: [USBToolTip] c:\progra~1\pinnacle\shared~1\programs\usbtip\USBTip.exe
mRun: [Eleqibof] rundll32.exe "c:\windows\adasaxoga.dll",Startup
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRunOnce: [RunNarrator] Narrator.exe
dRunOnce: [Magnify] Magnify.exe
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
dRunOnce: [MPlayer2_FixUp] c:\windows\inf\unregmp2.exe /Fixups
StartupFolder: c:\docume~1\steve-~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\steve-~1\startm~1\programs\startup\pmbmed~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: ICF.dll
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://c:\program files\chessmaster challenge\images\stg_drm.ocx
DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader55.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.com/SnapfishActivia.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.5.cab
DPF: {4ECE056F-E50F-4F9D-B069-EB342D21F26A} - hxxp://www5.snapfish.com/SnapfishActivia3.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1224543082828
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} - hxxp://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file://c:\program files\monopoly\images\armhelper.ocx
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: __c0017FC - c:\windows\system32\__c0017FC.dat
AppInit_DLLs: c:\windows\system32\
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\steve-~1\applic~1\mozilla\firefox\profiles\he9qkdbn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=18&q=
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/?ref=hp
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=18&tid={0BB288F5-EF69-7EA5-11BA-C1FE7ECE81E3}&q=
FF - component: c:\documents and settings\steve-julia\application data\mozilla\firefox\profiles\he9qkdbn.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\steve-julia\application data\mozilla\firefox\profiles\he9qkdbn.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCore.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\mcafee\SiteAdvisor
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: XULRunner: {DDF662D8-F2A4-49C6-90BE-4D2254E65692} - c:\documents and settings\steve-julia\local settings\application data\{DDF662D8-F2A4-49C6-90BE-4D2254E65692}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - %profile%\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-9-5 64160]
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2007-10-5 386840]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-9-7 84072]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-1-16 161064]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-9-25 93320]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-7 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-7 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-7 271480]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-9-7 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-9-7 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-9-7 141792]
R2 seUpdateSvc;Safe Eyes Update Service;c:\program files\internet content filter\UpdateService.exe [2010-3-1 233472]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-5 24652]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-9-7 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2007-10-5 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2007-10-5 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-9-7 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-9-7 88544]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-9 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-9-7 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-9-7 84264]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-10-5 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-10-5 40552]
S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2007-12-1 31872]
.
=============== Created Last 30 ================
.
2011-12-06 22:06:25 -------- d-sh--w- C:\found.002
2011-04-13 10:29:01 -------- d-----w- c:\docume~1\steve-~1\locals~1\applic~1\{DDF662D8-F2A4-49C6-90BE-4D2254E65692}
2011-04-06 15:52:40 1470 ----a-w- c:\windows\awonisixejigulu.dll
2011-04-06 15:35:48 1470 ----a-w- c:\windows\opobugojudoyat.dll
2011-03-27 23:40:45 0 ----a-w- c:\windows\Dsabalumihudusib.bin
.
==================== Find3M ====================
.
2011-02-17 20:34:32 398760 ----a-r- c:\windows\system32\cpnprt2.cid
.
============= FINISH: 10:15:11.01 ===============
I'm sorry I forgot to send this requested attachment. Please let me know if you have any questions.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Internet Content Filter\UpdateService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Steve-Julia\My Documents\Downloads\dds.com
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://swagbucks.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061212
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
{5ca3d70e-1895-11cf-8e15-001234567890}
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101119025859.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Safe &Eyes Toolbar: {430ddb4f-38cc-4e91-af33-4157334ec937} - c:\program files\internet content filter\setoolbar.dll
TB: {61539ECD-CC67-4437-A03C-9AACCBD14326} - No File
TB: {5BED3930-2E9E-76D8-BACC-80DF2188D455} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [A00F12700C0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F12700C0.exe
uRun: [A00FD4F88.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FD4F88.exe
uRun: [A00F274400.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F274400.exe
uRun: [A00F3ACDB.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3ACDB.exe
uRun: [A00F36AF0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F36AF0.exe
uRun: [A00F2725FBE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2725FBE.exe
uRun: [A00F326B805.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F326B805.exe
uRun: [A00F3945694.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3945694.exe
uRun: [A00FA7D9B.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FA7D9B.exe
uRun: [A00F5B5960.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F5B5960.exe
uRun: [A00F358E92.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F358E92.exe
uRun: [A00F64A98.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F64A98.exe
uRun: [A00F12BA01.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F12BA01.exe
uRun: [A00F16C94D3.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F16C94D3.exe
uRun: [A00F40B47.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F40B47.exe
uRun: [A00F818C1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F818C1.exe
uRun: [A00FAE7DE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FAE7DE.exe
uRun: [A00F126ADCE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F126ADCE.exe
uRun: [A00F20DA917.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F20DA917.exe
uRun: [A00F24EE1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F24EE1.exe
uRun: [A00F23BCAE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F23BCAE.exe
uRun: [A00F22D1037.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F22D1037.exe
uRun: [A00F381A4.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F381A4.exe
uRun: [A00F85A793.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F85A793.exe
uRun: [A00F19C8CAB.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F19C8CAB.exe
uRun: [A00F2987D40.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2987D40.exe
uRun: [A00F43BCE1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F43BCE1.exe
uRun: [A00F115DD2D.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F115DD2D.exe
uRun: [A00F166A9B0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F166A9B0.exe
uRun: [A00F20A1D9F.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F20A1D9F.exe
uRun: [A00F20F97E7.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F20F97E7.exe
uRun: [A00F35FA5.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F35FA5.exe
uRun: [A00F1B34794.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1B34794.exe
uRun: [A00F22362BC.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F22362BC.exe
uRun: [A00F5643E39.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F5643E39.exe
uRun: [A00F12DBB78.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F12DBB78.exe
uRun: [A00F1D06C17.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1D06C17.exe
uRun: [A00F273E16D.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F273E16D.exe
uRun: [A00F2837E60.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2837E60.exe
uRun: [A00F2590D2.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2590D2.exe
uRun: [A00F1421BC7.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1421BC7.exe
uRun: [A00F18F7EC0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F18F7EC0.exe
uRun: [A00F606E8.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F606E8.exe
uRun: [A00F39AC09.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F39AC09.exe
uRun: [A00F51CE6.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F51CE6.exe
uRun: [A00F16E8160.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F16E8160.exe
uRun: [A00F457C1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F457C1.exe
uRun: [A00F386E4.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F386E4.exe
uRun: [A00F319BD4.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F319BD4.exe
uRun: [A00F37550.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F37550.exe
uRun: [A00FF6C8C.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FF6C8C.exe
uRun: [A00F302030.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F302030.exe
uRun: [A00F3AFD9.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3AFD9.exe
uRun: [A00F291A7.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F291A7.exe
uRun: [A00F408F5.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F408F5.exe
uRun: [A00F3203B.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3203B.exe
uRun: [A00F89A722.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F89A722.exe
uRun: [A00FC8259C.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FC8259C.exe
uRun: [A00F3388EE.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3388EE.exe
uRun: [A00FCB4838.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FCB4838.exe
uRun: [A00F3286547.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3286547.exe
uRun: [A00F41CC055.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F41CC055.exe
uRun: [A00F5691DE7.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F5691DE7.exe
uRun: [A00FA41E416.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FA41E416.exe
uRun: [A00FA75CE01.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FA75CE01.exe
uRun: [A00FB2576D1.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FB2576D1.exe
uRun: [A00F36255.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F36255.exe
uRun: [A00F1509EC.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1509EC.exe
uRun: [A00F1F5C52.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F1F5C52.exe
uRun: [A00FCDC147.exe] c:\docume~1\steve-~1\locals~1\temp\_A00FCDC147.exe
uRun: [cdloader] "c:\documents and settings\steve-julia\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [A00F44AFEC.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F44AFEC.exe
uRun: [A00F3D30025.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F3D30025.exe
uRun: [A00F4A715B9.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F4A715B9.exe
uRun: [A00F644A212.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F644A212.exe
uRun: [A00F2AFFD.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F2AFFD.exe
uRun: [A00F294CE0.exe] c:\docume~1\steve-~1\locals~1\temp\_A00F294CE0.exe
uRun: [DelayShred] c:\progra~1\mcafee\mshr\shrcl.exe /p7 /q c:\docume~1\steve-~1\locals~1\temp\hsperf~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\1yfauv77\bx7fdb~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\4kemzvwg\bxa404~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\07jjgtda\bx8cd9~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\1yfauv77\bx6617~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\6u2lfv5t\bxe472~1.sh! c:\docume~1\steve-~1\locals~1\tempor~1\content.ie5\07jjgtda\bx8fee~1.sh! c:\docume~1\steve-~1\locals~1\temp\FROMCA~2.SH!
uRun: [Gbapewigamewob] rundll32.exe "c:\windows\otxtpr.dll",Startup
mRun: [monitr32] c:\program files\canon\multipass4\monitr32.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Zune Launcher] "e:\justin\ZuneLauncher.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [ICF] "c:\program files\internet content filter\SafeEyes.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe
mRun: [USB2Check] RUNDLL32.EXE "c:\windows\system32\PCLECoInst.dll",CheckUSBController
mRun: [USBToolTip] c:\progra~1\pinnacle\shared~1\programs\usbtip\USBTip.exe
mRun: [Eleqibof] rundll32.exe "c:\windows\adasaxoga.dll",Startup
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRunOnce: [RunNarrator] Narrator.exe
dRunOnce: [Magnify] Magnify.exe
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
dRunOnce: [MPlayer2_FixUp] c:\windows\inf\unregmp2.exe /Fixups
StartupFolder: c:\docume~1\steve-~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\steve-~1\startm~1\programs\startup\pmbmed~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: ICF.dll
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://c:\program files\chessmaster challenge\images\stg_drm.ocx
DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader55.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.com/SnapfishActivia.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.5.cab
DPF: {4ECE056F-E50F-4F9D-B069-EB342D21F26A} - hxxp://www5.snapfish.com/SnapfishActivia3.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1224543082828
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} - hxxp://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file://c:\program files\monopoly\images\armhelper.ocx
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: __c0017FC - c:\windows\system32\__c0017FC.dat
AppInit_DLLs: c:\windows\system32\
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\steve-~1\applic~1\mozilla\firefox\profiles\he9qkdbn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=18&q=
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/?ref=hp
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=18&tid={0BB288F5-EF69-7EA5-11BA-C1FE7ECE81E3}&q=
FF - component: c:\documents and settings\steve-julia\application data\mozilla\firefox\profiles\he9qkdbn.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\steve-julia\application data\mozilla\firefox\profiles\he9qkdbn.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCore.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\mcafee\SiteAdvisor
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: XULRunner: {DDF662D8-F2A4-49C6-90BE-4D2254E65692} - c:\documents and settings\steve-julia\local settings\application data\{DDF662D8-F2A4-49C6-90BE-4D2254E65692}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - %profile%\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-9-5 64160]
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2007-10-5 386840]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-9-7 84072]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-1-16 161064]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-9-25 93320]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-7 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-7 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-7 271480]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-9-7 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-9-7 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-9-7 141792]
R2 seUpdateSvc;Safe Eyes Update Service;c:\program files\internet content filter\UpdateService.exe [2010-3-1 233472]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-5 24652]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-9-7 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2007-10-5 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2007-10-5 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-9-7 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-9-7 88544]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-9 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-9-7 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-9-7 84264]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-10-5 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-10-5 40552]
S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2007-12-1 31872]
.
=============== Created Last 30 ================
.
2011-12-06 22:06:25 -------- d-sh--w- C:\found.002
2011-04-13 10:29:01 -------- d-----w- c:\docume~1\steve-~1\locals~1\applic~1\{DDF662D8-F2A4-49C6-90BE-4D2254E65692}
2011-04-06 15:52:40 1470 ----a-w- c:\windows\awonisixejigulu.dll
2011-04-06 15:35:48 1470 ----a-w- c:\windows\opobugojudoyat.dll
2011-03-27 23:40:45 0 ----a-w- c:\windows\Dsabalumihudusib.bin
.
==================== Find3M ====================
.
2011-02-17 20:34:32 398760 ----a-r- c:\windows\system32\cpnprt2.cid
.
============= FINISH: 10:15:11.01 ===============
I'm sorry I forgot to send this requested attachment. Please let me know if you have any questions.
Last edited by a moderator: