dakotasjag
New member
Hi. I seem to have picked up a problem of some sort which seems to be recurring even though I get messages saying it has been removed. Sometimes the tools I have run to clean it do not even find it. I have Spybot and free versions AVG, Malware Bytes Anti Malware, Super Anti Spyware, Zone Alarm and Ad-Aware installed with the latest updates.
Sometimes when I boot I see numerous iterations of dos command type windows popup and then go away.
My IE8 browser also seems to get redirected on many of the links I attempt to bring up.
Also it seems all my restore points prior to today in System Restore are no longer available.
I am not sure if this is all being caused by the same thing.
I do recall seeing a popup yesterday (when I first started having problems) about My computer but I killed the window from Task Manager as I recall
I ran the ERUNT registry backup tool as noted and deactivated the Spybot TeaTimer. The Hijack This log file follows this.
Any help would be greatly appreciated. Thanks!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:31 PM, on 8/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
E:\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
E:\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\HistoryKill\histkill.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8118;http=localhost:8118;https=localhost:8118;socks=localhost:9050
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;127.0.0.1
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Adobe Photo Downloader] "E:\apdproxy.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6662] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5152] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA592] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5867] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6046] command.com /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2501] cmd.exe /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3622] command.com /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7159] cmd.exe /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7655] command.com /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6258] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2956] command.com /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8161] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2625] command.com /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8577] cmd.exe /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7734] command.com /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1183] cmd.exe /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA166] command.com /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4762] cmd.exe /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7302] command.com /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2746] cmd.exe /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB4508] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8338] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5273] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2995] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1876] command.com /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8991] cmd.exe /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6452] command.com /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2625] cmd.exe /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4101] command.com /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9590] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB489] command.com /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1684] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9418] command.com /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6939] cmd.exe /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7533] command.com /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5925] cmd.exe /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7856] command.com /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4413] cmd.exe /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB463] command.com /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD589] cmd.exe /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat"
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMidi] MIDIDEF.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMidi] MIDIDEF.EXE (User 'Default user')
O4 - Startup: Epson printer Registration.lnk = H:\E_reg\EPSONREG.EXE
O4 - Startup: ERUNT AutoBackup.lnk = D:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://help.bellsouth.net/sdccommon/download/tgctlcm.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132930528652
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132933956953
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,34
O17 - HKLM\System\CCS\Services\Tcpip\..\{3DCFE92E-C6CA-4F48-BCC9-A281D2F2291C}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{C91E02B2-0B74-407F-A4FD-F4C5B714A471}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - E:\PhotoshopElementsFileAgent.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.5\rthlpsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 15702 bytes
thanks again.
Sometimes when I boot I see numerous iterations of dos command type windows popup and then go away.
My IE8 browser also seems to get redirected on many of the links I attempt to bring up.
Also it seems all my restore points prior to today in System Restore are no longer available.
I am not sure if this is all being caused by the same thing.
I do recall seeing a popup yesterday (when I first started having problems) about My computer but I killed the window from Task Manager as I recall
I ran the ERUNT registry backup tool as noted and deactivated the Spybot TeaTimer. The Hijack This log file follows this.
Any help would be greatly appreciated. Thanks!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:31 PM, on 8/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
E:\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
E:\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\HistoryKill\histkill.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8118;http=localhost:8118;https=localhost:8118;socks=localhost:9050
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;127.0.0.1
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Adobe Photo Downloader] "E:\apdproxy.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6662] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5152] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA592] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5867] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6046] command.com /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2501] cmd.exe /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3622] command.com /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7159] cmd.exe /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7655] command.com /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6258] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2956] command.com /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8161] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2625] command.com /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8577] cmd.exe /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7734] command.com /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1183] cmd.exe /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA166] command.com /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4762] cmd.exe /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7302] command.com /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2746] cmd.exe /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB4508] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8338] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5273] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2995] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETwyvtwcnd.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1876] command.com /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8991] cmd.exe /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6452] command.com /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2625] cmd.exe /c del "C:\WINDOWS\system32\SKYNETjboponmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4101] command.com /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9590] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB489] command.com /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1684] cmd.exe /c del "C:\WINDOWS\system32\SKYNETyuhnxckk.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9418] command.com /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6939] cmd.exe /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7533] command.com /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5925] cmd.exe /c del "C:\WINDOWS\system32\SKYNETmhxdorgr.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7856] command.com /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4413] cmd.exe /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB463] command.com /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD589] cmd.exe /c del "C:\WINDOWS\system32\SKYNETvjyrjfyp.dat"
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMidi] MIDIDEF.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMidi] MIDIDEF.EXE (User 'Default user')
O4 - Startup: Epson printer Registration.lnk = H:\E_reg\EPSONREG.EXE
O4 - Startup: ERUNT AutoBackup.lnk = D:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://help.bellsouth.net/sdccommon/download/tgctlcm.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132930528652
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132933956953
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,34
O17 - HKLM\System\CCS\Services\Tcpip\..\{3DCFE92E-C6CA-4F48-BCC9-A281D2F2291C}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{C91E02B2-0B74-407F-A4FD-F4C5B714A471}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - E:\PhotoshopElementsFileAgent.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.5\rthlpsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 15702 bytes
thanks again.