FYI, the 1st time I ran combofix it froze on the Preparing Log Report screen, left it running for many hours, so I rebooted and ran it again with success.
ComboFix:
ComboFix 09-07-09.03 - Administrator 07/10/2009 13:44.3.1 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.367 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\sysguard.exe
.
---- Previous Run -------
.
c:\docume~1\ADMINI~1\LOCALS~1\Temp\253984928mmx.dll
c:\docume~1\ADMINI~1\LOCALS~1\Temp\709953932mmx.dll
c:\documents and settings\Administrator\aabnlpq.exe
c:\documents and settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Administrator\Application Data\wiaserva.log
c:\documents and settings\Administrator\Application Data\wiaservg.log
c:\documents and settings\Administrator\Desktop\Advanced Virus Remover.lnk
c:\documents and settings\Administrator\Local Settings\temp\253984928mmx.dll
c:\documents and settings\Administrator\Local Settings\temp\709953932mmx.dll
c:\documents and settings\Administrator\nah_tpya.exe
c:\documents and settings\Administrator\reader_s.exe
c:\documents and settings\Administrator\Start Menu\Advanced Virus Remover.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Startup\fmnupd32.exe
c:\documents and settings\Administrator\Start Menu\Programs\Startup\zqosys32.exe
c:\documents and settings\All Users\Application Data\17137504\17137504 .exe
c:\documents and settings\All Users\Application Data\17137504\17137504
c:\documents and settings\All Users\Application Data\17137504\17137504.exe
c:\documents and settings\Matthew Powell\Application Data\wiaservg.log
c:\documents and settings\Matthew Powell\Desktop\System Security 2009.lnk
c:\documents and settings\Matthew Powell\nah_ptex.exe
c:\documents and settings\Matthew Powell\reader_s.exe
c:\documents and settings\Matthew Powell\Start Menu\Programs\Startup\fmnupd32.exe
C:\ohhvpdqo.exe
c:\program files\AdvancedVirusRemover\PAVRM.exe
c:\program files\Common Files\Real\WeatherBug\MiniBugTransporter.dll
c:\program files\Mozilla Firefox\chrome\amba.jar
c:\recycler\S-1-5-21-6142092865-4660538266-193093519-1911\Desktop.ini
c:\recycler\S-1-5-21-6142092865-4660538266-193093519-1911\wnzip32.exe
c:\windows\010112010146118114.dat
c:\windows\9129837 .exe
c:\windows\9129837.exe
c:\windows\Install.txt
c:\windows\Installer\2a8aa.msi
c:\windows\Installer\301e5.msi
c:\windows\Installer\319d2.msi
c:\windows\Installer\76f71.msi
c:\windows\Installer\9e68cb.msi
c:\windows\Installer\a76f4.msi
c:\windows\Installer\WMEncoder.msi
c:\windows\ld12.exe
c:\windows\msa.exe
c:\windows\sysguard.exe
c:\windows\system32\6to4v32.dll
c:\windows\system32\avast!Antivirus.exe
c:\windows\system32\certstore.dat
c:\windows\system32\comsa32.sys
c:\windows\system32\config\systemprofile\nah_log.dat
c:\windows\system32\drivers\glaide32.sys
c:\windows\system32\drivers\ndis.sys
c:\windows\system32\drivers\smss.exe
c:\windows\system32\dvdyalp.ini
c:\windows\system32\dvdyalp.ini2
c:\windows\system32\dvdyalp.tmp2
c:\windows\system32\FInstall.sys
c:\windows\system32\gsf83iujid.dll
c:\windows\system32\Iasv32.dll
c:\windows\system32\Install.txt
c:\windows\system32\Ipripv32.dll
c:\windows\system32\kr_done1
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\mscetjk.exe
c:\windows\system32\mscgh.exe
c:\windows\system32\mscgjdky.exe
c:\windows\system32\mscgrmus.exe
c:\windows\system32\mscli.exe
c:\windows\system32\mscljz.exe
c:\windows\system32\mscpe.exe
c:\windows\system32\mscqd.exe
c:\windows\system32\msctp.exe
c:\windows\system32\mscxk.exe
c:\windows\system32\msczr.exe
c:\windows\system32\mscztidi.exe
c:\windows\system32\msdejmef.exe
c:\windows\system32\msdetjao.exe
c:\windows\system32\msdfjk.exe
c:\windows\system32\msdkeqa.exe
c:\windows\system32\msdljgbv.exe
c:\windows\system32\msdnzly.exe
c:\windows\system32\msdpv.exe
c:\windows\system32\msdqhrvu.exe
c:\windows\system32\msdqsiu.exe
c:\windows\system32\msdqu.exe
c:\windows\system32\msdsa.exe
c:\windows\system32\msdsc.exe
c:\windows\system32\msdvcjo.exe
c:\windows\system32\msdwj.exe
c:\windows\system32\msdzmo.exe
c:\windows\system32\mseamqr.exe
c:\windows\system32\mseau.exe
c:\windows\system32\msebx.exe
c:\windows\system32\msecjgy.exe
c:\windows\system32\msecqrnc.exe
c:\windows\system32\msecvc.exe
c:\windows\system32\msegqtc.exe
c:\windows\system32\mseiegaw.exe
c:\windows\system32\msejcsfv.exe
c:\windows\system32\msemsl.exe
c:\windows\system32\msephe.exe
c:\windows\system32\msepkicd.exe
c:\windows\system32\mseqyklr.exe
c:\windows\system32\mseryq.exe
c:\windows\system32\msesk.exe
c:\windows\system32\msetnl.exe
c:\windows\system32\msetta.exe
c:\windows\system32\msezagrd.exe
c:\windows\system32\msezwiu.exe
c:\windows\system32\msfdgm.exe
c:\windows\system32\msfdt.exe
c:\windows\system32\msfeb.exe
c:\windows\system32\msffdp.exe
c:\windows\system32\msfhblxv.exe
c:\windows\system32\msfka.exe
c:\windows\system32\msfkqijg.exe
c:\windows\system32\msfksr.exe
c:\windows\system32\msfnll.exe
c:\windows\system32\msfoeng.exe
c:\windows\system32\msfpeur.exe
c:\windows\system32\msfpgo.exe
c:\windows\system32\msfpp.exe
c:\windows\system32\msfrmrj.exe
c:\windows\system32\msfrxro.exe
c:\windows\system32\msfuymxo.exe
c:\windows\system32\msfxu.exe
c:\windows\system32\msfyc.exe
c:\windows\system32\msgek.exe
c:\windows\system32\msgem.exe
c:\windows\system32\msgepoxh.exe
c:\windows\system32\msggbi.exe
c:\windows\system32\msgipq.exe
c:\windows\system32\msglcs.exe
c:\windows\system32\msglq.exe
c:\windows\system32\msglvp.exe
c:\windows\system32\msgmjqcd.exe
c:\windows\system32\msgngmr.exe
c:\windows\system32\msgomxd.exe
c:\windows\system32\msgqr.exe
c:\windows\system32\msgrprqg.exe
c:\windows\system32\msgtjo.exe
c:\windows\system32\msgupnv.exe
c:\windows\system32\msgupu.exe
c:\windows\system32\msgvp.exe
c:\windows\system32\msgwno.exe
c:\windows\system32\msgywnbr.exe
c:\windows\system32\mshbnv.exe
c:\windows\system32\mshbvkm.exe
c:\windows\system32\mshcdd.exe
c:\windows\system32\mshczi.exe
c:\windows\system32\mshdf.exe
c:\windows\system32\mshfep.exe
c:\windows\system32\mshgb.exe
c:\windows\system32\mshhe.exe
c:\windows\system32\mshhkity.exe
c:\windows\system32\mshizo.exe
c:\windows\system32\mshmcntc.exe
c:\windows\system32\mshoozt.exe
c:\windows\system32\mshpgku.exe
c:\windows\system32\mshqc.exe
c:\windows\system32\mshtl.exe
c:\windows\system32\mshtnl.exe
c:\windows\system32\mshuv.exe
c:\windows\system32\mshvey.exe
c:\windows\system32\mshwiv.exe
c:\windows\system32\mshwte.exe
c:\windows\system32\msidv.exe
c:\windows\system32\msiexlu.exe
c:\windows\system32\msifjih.exe
c:\windows\system32\msighi.exe
c:\windows\system32\msigxkmt.exe
c:\windows\system32\msijhrk.exe
c:\windows\system32\msijkx.exe
c:\windows\system32\msijqzz.exe
c:\windows\system32\msimxjl.exe
c:\windows\system32\msipomrx.exe
c:\windows\system32\msipzxb.exe
c:\windows\system32\msisws.exe
c:\windows\system32\msivrp.exe
c:\windows\system32\msiwgw.exe
c:\windows\system32\msixduiw.exe
c:\windows\system32\msiypbv.exe
c:\windows\system32\msiyw.exe
c:\windows\system32\msjawsdm.exe
c:\windows\system32\msjcobud.exe
c:\windows\system32\msjgb.exe
c:\windows\system32\msjhafmi.exe
c:\windows\system32\msjicn.exe
c:\windows\system32\msjkyxj.exe
c:\windows\system32\msjowbzv.exe
c:\windows\system32\msjozil.exe
c:\windows\system32\msjpof.exe
c:\windows\system32\msjqoh.exe
c:\windows\system32\msjrzlm.exe
c:\windows\system32\msjsl.exe
c:\windows\system32\msjtt.exe
c:\windows\system32\msjtxlv.exe
c:\windows\system32\msjtzrh.exe
c:\windows\system32\msjunmer.exe
c:\windows\system32\msjvgh.exe
c:\windows\system32\msjvpd.exe
c:\windows\system32\mskaby.exe
c:\windows\system32\mskbeyvf.exe
c:\windows\system32\mskdglp.exe
c:\windows\system32\mskdlkc.exe
c:\windows\system32\mskelfqw.exe
c:\windows\system32\mskeyw.exe
c:\windows\system32\mskfsbrc.exe
c:\windows\system32\mskhmavk.exe
c:\windows\system32\mskihk.exe
c:\windows\system32\mskinka.exe
c:\windows\system32\mskjv.exe
c:\windows\system32\mskkvh.exe
c:\windows\system32\mskkwmkd.exe
c:\windows\system32\mskleepa.exe
c:\windows\system32\msklinlg.exe
c:\windows\system32\msklk.exe
c:\windows\system32\mskmupk.exe
c:\windows\system32\msknyj.exe
c:\windows\system32\mskozv.exe
c:\windows\system32\mskqctt.exe
c:\windows\system32\mskqgild.exe
c:\windows\system32\mskrw.exe
c:\windows\system32\mskuw.exe
c:\windows\system32\mskwsgr.exe
c:\windows\system32\mskxgo.exe
c:\windows\system32\mslej.exe
c:\windows\system32\msleu.exe
c:\windows\system32\mslfmyzf.exe
c:\windows\system32\mslgfpqj.exe
c:\windows\system32\mslhogr.exe
c:\windows\system32\mslhua.exe
c:\windows\system32\mslivm.exe
c:\windows\system32\msljg.exe
c:\windows\system32\mslji.exe
c:\windows\system32\mslltrgo.exe
c:\windows\system32\mslmwp.exe
c:\windows\system32\mslpglfg.exe
c:\windows\system32\mslqmqkc.exe
c:\windows\system32\mslro.exe
c:\windows\system32\mslslc.exe
c:\windows\system32\mslupkj.exe
c:\windows\system32\mslztag.exe
c:\windows\system32\msmaft.exe
c:\windows\system32\msmcho.exe
c:\windows\system32\msmdxez.exe
c:\windows\system32\msmhvv.exe
c:\windows\system32\msmjus.exe
c:\windows\system32\msmkqo.exe
c:\windows\system32\msmlolpj.exe
c:\windows\system32\msmmh.exe
c:\windows\system32\msmmkpas.exe
c:\windows\system32\msmnqpf.exe
c:\windows\system32\msmoa.exe
c:\windows\system32\msmobim.exe
c:\windows\system32\msmrg.exe
c:\windows\system32\msmsgiku.exe
c:\windows\system32\msmtzye.exe
c:\windows\system32\msmvbf.exe
c:\windows\system32\msmvvn.exe
c:\windows\system32\msmwd.exe
c:\windows\system32\msmwkw.exe
c:\windows\system32\msmxemm.exe
c:\windows\system32\msmygzbe.exe
c:\windows\system32\msnaan.exe
c:\windows\system32\msnau.exe
c:\windows\system32\msncache.dll
c:\windows\system32\msndzxj.exe
c:\windows\system32\msnhirg.exe
c:\windows\system32\msniy.exe
c:\windows\system32\msnkjv.exe
c:\windows\system32\msnlhqu.exe
c:\windows\system32\msnlz.exe
c:\windows\system32\msnmcdbb.exe
c:\windows\system32\msnqcywt.exe
c:\windows\system32\msnqeolu.exe
c:\windows\system32\msnwrma.exe
c:\windows\system32\msnyyre.exe
c:\windows\system32\msobjong.exe
c:\windows\system32\msoblbpr.exe
c:\windows\system32\msobntv.exe
c:\windows\system32\msocrlyf.exe
c:\windows\system32\msocupop.exe
c:\windows\system32\msocx.exe
c:\windows\system32\msodcqln.exe
c:\windows\system32\msofcq.exe
c:\windows\system32\msofl.exe
c:\windows\system32\msogd.exe
c:\windows\system32\msogjua.exe
c:\windows\system32\msogn.exe
c:\windows\system32\msohxanj.exe
c:\windows\system32\msohzxer.exe
c:\windows\system32\msokq.exe
c:\windows\system32\msolh.exe
c:\windows\system32\msoltwn.exe
c:\windows\system32\msolwg.exe
c:\windows\system32\msoneiq.exe
c:\windows\system32\msoqbg.exe
c:\windows\system32\msorifdr.exe
c:\windows\system32\msosax.exe
c:\windows\system32\msotwfx.exe
c:\windows\system32\msotyr.exe
c:\windows\system32\msowe.exe
c:\windows\system32\msoypi.exe
c:\windows\system32\msozkxec.exe
c:\windows\system32\mspanl.exe
c:\windows\system32\mspaodop.exe
c:\windows\system32\mspcrl.exe
c:\windows\system32\mspfxy.exe
c:\windows\system32\mspgv.exe
c:\windows\system32\msphb.exe
c:\windows\system32\msphbn.exe
c:\windows\system32\mspjq.exe
c:\windows\system32\mspjsmzl.exe
c:\windows\system32\mspqvu.exe
c:\windows\system32\mspruo.exe
c:\windows\system32\mspuk.exe
c:\windows\system32\mspxqprd.exe
c:\windows\system32\mspxx.exe
c:\windows\system32\msqcgrr.exe
c:\windows\system32\msqdbohw.exe
c:\windows\system32\msqdeb.exe
c:\windows\system32\msqdvgc.exe
c:\windows\system32\msqer.exe
c:\windows\system32\msqetgaz.exe
c:\windows\system32\msqezph.exe
c:\windows\system32\msqfen.exe
c:\windows\system32\msqina.exe
c:\windows\system32\msqlhoz.exe
c:\windows\system32\msqlskq.exe
c:\windows\system32\msqokv.exe
c:\windows\system32\msqoq.exe
c:\windows\system32\msqor.exe
c:\windows\system32\msqtno.exe
c:\windows\system32\msquss.exe
c:\windows\system32\msqwsf.exe
c:\windows\system32\msqxjgdf.exe
c:\windows\system32\msqybi.exe
c:\windows\system32\msraglg.exe
c:\windows\system32\msrana.exe
c:\windows\system32\msrchily.exe
c:\windows\system32\msrdr.exe
c:\windows\system32\msretoqp.exe
c:\windows\system32\msrgxx.exe
c:\windows\system32\msrhdil.exe
c:\windows\system32\msrjabm.exe
c:\windows\system32\msrkrvjt.exe
c:\windows\system32\msrmo.exe
c:\windows\system32\msrnxlsb.exe
c:\windows\system32\msrpd.exe
c:\windows\system32\msrps.exe
c:\windows\system32\msrpv.exe
c:\windows\system32\msrru.exe
c:\windows\system32\msrtaj.exe
c:\windows\system32\msrtpqxl.exe
c:\windows\system32\msrtsl.exe
c:\windows\system32\msrxz.exe
c:\windows\system32\msrylaem.exe
c:\windows\system32\msryrpmy.exe
c:\windows\system32\msscnzet.exe
c:\windows\system32\mssdjw.exe
c:\windows\system32\mssecgkp.exe
c:\windows\system32\mssep.exe
c:\windows\system32\mssfwxm.exe
c:\windows\system32\msshttr.exe
c:\windows\system32\msskez.exe
c:\windows\system32\mssmc.exe
c:\windows\system32\mssmdc.exe
c:\windows\system32\mssql.exe
c:\windows\system32\mssqqzvw.exe
c:\windows\system32\mssrcr.exe
c:\windows\system32\msssw.exe
c:\windows\system32\msstt.exe
c:\windows\system32\mssvblbh.exe
c:\windows\system32\mssviz.exe
c:\windows\system32\mssvuj.exe
c:\windows\system32\msswa.exe
c:\windows\system32\msswxxqo.exe
c:\windows\system32\mssxymlr.exe
c:\windows\system32\mstaq.exe
c:\windows\system32\mstbtkvj.exe
c:\windows\system32\mstcm.exe
c:\windows\system32\mstcmu.exe
c:\windows\system32\mstdi.exe
c:\windows\system32\mstepw.exe
c:\windows\system32\mstfvd.exe
c:\windows\system32\msthumm.exe
c:\windows\system32\msthx.exe
c:\windows\system32\mstift.exe
c:\windows\system32\mstjnl.exe
c:\windows\system32\mstkwg.exe
c:\windows\system32\mstmcqwu.exe
c:\windows\system32\mstmgy.exe
c:\windows\system32\mstsg.exe
c:\windows\system32\mstufeq.exe
c:\windows\system32\mstuuv.exe
c:\windows\system32\mstvzrc.exe
c:\windows\system32\mstwpn.exe
c:\windows\system32\mstzh.exe
c:\windows\system32\msubertv.exe
c:\windows\system32\msucbdy.exe
c:\windows\system32\msucttar.exe
c:\windows\system32\msudmigo.exe
c:\windows\system32\msufejqk.exe
c:\windows\system32\msufkcc.exe
c:\windows\system32\msufmv.exe
c:\windows\system32\msufq.exe
c:\windows\system32\msuhtdq.exe
c:\windows\system32\msukawry.exe
c:\windows\system32\msumw.exe
c:\windows\system32\msunau.exe
c:\windows\system32\msunj.exe
c:\windows\system32\msuob.exe
c:\windows\system32\msuog.exe
c:\windows\system32\msupjtdh.exe
c:\windows\system32\msuppezi.exe
c:\windows\system32\msupyud.exe
c:\windows\system32\msuqbda.exe
c:\windows\system32\msuqdh.exe
c:\windows\system32\msuqpyap.exe
c:\windows\system32\msurjt.exe
c:\windows\system32\msurzm.exe
c:\windows\system32\msuwip.exe
c:\windows\system32\msuwnsp.exe
c:\windows\system32\msvbczu.exe
c:\windows\system32\msvbram.exe
c:\windows\system32\msvbsjlk.exe
c:\windows\system32\msvbze.exe
c:\windows\system32\msveaqgb.exe
c:\windows\system32\msvfdm.exe
c:\windows\system32\msvfps.exe
c:\windows\system32\msvmcdh.exe
c:\windows\system32\msvnhey.exe
c:\windows\system32\msvnl.exe
c:\windows\system32\msvosxk.exe
c:\windows\system32\msvpbl.exe
c:\windows\system32\msvpd.exe
c:\windows\system32\msvpnvtn.exe
c:\windows\system32\msvsgzhq.exe
c:\windows\system32\msvtoz.exe
c:\windows\system32\msvtvhg.exe
c:\windows\system32\msvvi.exe
c:\windows\system32\msvzngy.exe
c:\windows\system32\mswan.exe
c:\windows\system32\mswbm.exe
c:\windows\system32\mswcetbi.exe
c:\windows\system32\mswgi.exe
c:\windows\system32\mswgjqwi.exe
c:\windows\system32\mswgwv.exe
c:\windows\system32\mswhhxv.exe
c:\windows\system32\mswkfp.exe
c:\windows\system32\mswltnhx.exe
c:\windows\system32\mswobge.exe
c:\windows\system32\mswpfo.exe
c:\windows\system32\mswquv.exe
c:\windows\system32\mswsko.exe
c:\windows\system32\mswuc.exe
c:\windows\system32\mswvudcp.exe
c:\windows\system32\mswwju.exe
c:\windows\system32\mswwlv.exe
c:\windows\system32\msxaf.exe
c:\windows\system32\msxco.exe
c:\windows\system32\msxcy.exe
c:\windows\system32\msxinkl.exe
c:\windows\system32\msxmahcf.exe
c:\windows\system32\msxml71.dll
c:\windows\system32\msxobut.exe
c:\windows\system32\msxojzml.exe
c:\windows\system32\msxoly.exe
c:\windows\system32\msxpmrp.exe
c:\windows\system32\msxpxops.exe
c:\windows\system32\msxrljyj.exe
c:\windows\system32\msxrp.exe
c:\windows\system32\msxsa.exe
c:\windows\system32\msxvuxab.exe
c:\windows\system32\msxwao.exe
c:\windows\system32\msyac.exe
c:\windows\system32\msycp.exe
c:\windows\system32\msydll.exe
c:\windows\system32\msyfwpok.exe
c:\windows\system32\msyhpstz.exe
c:\windows\system32\msyirzkp.exe
c:\windows\system32\msyixni.exe
c:\windows\system32\msymdf.exe
c:\windows\system32\msymkfn.exe
c:\windows\system32\msynbl.exe
c:\windows\system32\msynu.exe
c:\windows\system32\msyoahb.exe
c:\windows\system32\msyor.exe
c:\windows\system32\msyqycw.exe
c:\windows\system32\msyszb.exe
c:\windows\system32\msytii.exe
c:\windows\system32\msytik.exe
c:\windows\system32\msytjn.exe
c:\windows\system32\msytqtx.exe
c:\windows\system32\msytsa.exe
c:\windows\system32\msyvpjj.exe
c:\windows\system32\msyxaezo.exe
c:\windows\system32\msyxerr.exe
c:\windows\system32\msyypm.exe
c:\windows\system32\mszbdoa.exe
c:\windows\system32\mszbnnb.exe
c:\windows\system32\mszbwjrc.exe
c:\windows\system32\mszcbztg.exe
c:\windows\system32\mszci.exe
c:\windows\system32\mszdxqiu.exe
c:\windows\system32\mszew.exe
c:\windows\system32\mszfqow.exe
c:\windows\system32\mszghirh.exe
c:\windows\system32\mszgpmt.exe
c:\windows\system32\mszhatxs.exe
c:\windows\system32\mszjbeo.exe
c:\windows\system32\mszjgi.exe
c:\windows\system32\mszjihkw.exe
c:\windows\system32\mszjkmm.exe
c:\windows\system32\mszkhrdr.exe
c:\windows\system32\mszkzbxr.exe
c:\windows\system32\msznb.exe
c:\windows\system32\mszns.exe
c:\windows\system32\msznzpzl.exe
c:\windows\system32\mszqiqfz.exe
c:\windows\system32\mszrex.exe
c:\windows\system32\mszzfnl.exe
c:\windows\system32\mszzxc.exe
c:\windows\system32\p2hhr.bat
c:\windows\system32\pcmstub.sys
c:\windows\system32\reader_s.exe
c:\windows\system32\sdcvddd.dll
c:\windows\system32\sdjee3inf.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\sopidkc.exe
c:\windows\system32\tpsaxyd.exe
c:\windows\system32\tpszxyd.sys
c:\windows\system32\wbem\grpconv.exe
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\wiawow32.sys
c:\windows\system32\winupdate.exe
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
c:\windows\TEMP\1445095138.exe
c:\windows\TEMP\496061410.exe
c:\windows\system32\grpconv.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\grpconv.exe
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_avast!antivirus
-------\Legacy_GLAIDE32
-------\Legacy_IAS
-------\Legacy_IPRIP
-------\Legacy_MSNCACHE
-------\Legacy_pcmstub
-------\Legacy_sopidkc
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_6to4
-------\Service_avast!antivirus
-------\Service_glaide32
-------\Service_Ias
-------\Service_Iprip
-------\Service_msncache
-------\Service_pcmstub
-------\Service_sopidkc
((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 )))))))))))))))))))))))))))))))
.
2009-07-10 18:58 . 2009-07-10 18:58 43520 ---h--w- c:\windows\system32\secupdat.dat
2009-07-10 18:58 . 2009-07-10 18:58 13312 ---ha-w- c:\documents and settings\Matthew Powell\iydumh.exe
2009-07-10 18:57 . 2008-04-13 18:57 14336 ----a-w- c:\windows\system32\drivers\asyncmac.sys
2009-07-10 18:57 . 2008-04-13 16:39 142592 ----a-w- c:\windows\system32\drivers\aec.sys
2009-07-10 18:55 . 2009-07-10 18:43 182656 ----a-w- c:\windows\system32\dllcache\ndis.sys
2009-07-09 22:07 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-07-09 22:07 . 2008-04-14 00:12 39424 ----a-w- c:\windows\system32\grpconv.exe
2009-07-09 22:04 . 2009-07-10 18:55 182656 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-07-09 21:12 . 2009-07-09 21:12 33280 ----a-w- C:\stfqqym.exe
2009-07-09 21:09 . 2009-07-09 21:08 136704 ----a-w- c:\windows\msd.exe
2009-07-09 18:27 . 2009-07-09 18:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-07-09 18:26 . 2009-07-09 18:27 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-07-09 18:26 . 2009-07-09 18:25 136704 ----a-w- c:\windows\msc.exe
2009-07-09 18:20 . 2009-07-09 18:18 136704 ----a-w- c:\windows\msb.exe
2009-07-09 18:20 . 2009-07-09 18:20 -------- d-s---w- c:\documents and settings\Administrator\UserData
2009-07-07 23:52 . 2009-07-09 21:08 25600 ----a-w- C:\furvsh.exe
2009-07-05 22:56 . 2009-07-08 20:37 -------- d-s---w- c:\windows\system32\config\systemprofile\UserData
2009-07-02 18:32 . 2008-12-11 13:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-07-02 18:31 . 2009-04-03 16:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-07-02 18:31 . 2008-12-18 17:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-02 18:31 . 2009-07-09 21:09 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-02 18:31 . 2009-07-02 18:35 -------- d-----w- c:\program files\Common Files\PC Tools
2009-07-02 18:31 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-07-02 18:31 . 2009-07-02 18:36 -------- d-----w- c:\program files\Spyware Doctor
2009-07-02 18:31 . 2009-07-02 18:31 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-07-02 18:31 . 2009-07-02 18:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
2009-07-02 18:20 . 2009-07-02 18:20 29696 ----a-w- c:\windows\system32\vkfnpx.exe
2009-07-02 18:19 . 2009-07-02 18:19 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-07-02 18:18 . 2009-07-08 20:25 52225 ----a-w- c:\documents and settings\Administrator\reader_s .exe
2009-07-02 17:51 . 2009-07-02 21:10 43008 ----a-w- c:\windows\system32\winupdate .exe
2009-07-02 15:51 . 2009-07-09 18:13 0 ----a-w- c:\windows\system32\drivers\24f03c54.sys
2009-07-02 15:51 . 2009-07-09 21:12 210701 ----a-w- C:\illhtee.exe
2009-07-02 15:51 . 2009-07-08 20:22 52225 ----a-w- c:\windows\system32\reader_s .exe
2009-07-02 15:47 . 2009-07-09 18:13 0 ----a-w- c:\windows\system32\drivers\8669f150.sys
2009-07-02 15:46 . 2009-07-02 15:46 96768 ----a-w- C:\fdvjfx.exe
2009-07-02 15:46 . 2009-07-02 15:46 201467 ----a-w- C:\gklrwl.exe
2009-07-02 15:46 . 2009-07-02 15:46 -------- d-----w- c:\program files\drv
2009-07-02 15:45 . 2009-07-02 15:45 24576 ----a-w- C:\ttrw.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-10 18:57 . 2005-09-29 23:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-09 21:23 . 2009-07-02 16:49 4 ---h--w- c:\windows\Fonts\mlog
2009-07-09 21:19 . 2005-09-30 00:53 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-07-02 15:52 . 2009-05-27 03:05 -------- d-----w- c:\documents and settings\Matthew Powell\Application Data\Skype
2009-07-02 15:52 . 2009-05-27 03:06 -------- d-----w- c:\documents and settings\Matthew Powell\Application Data\skypePM
2009-06-28 19:28 . 2005-11-18 06:03 -------- d-----w- c:\documents and settings\Matthew Powell\Application Data\uTorrent
2009-06-28 19:16 . 2005-08-07 15:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-01 00:05 . 2006-12-29 17:36 -------- d-----w- c:\program files\Starcraft
2009-05-27 03:06 . 2009-05-27 03:06 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-05-27 03:03 . 2009-05-27 03:03 -------- d-----r- c:\program files\Skype
2009-05-27 03:03 . 2009-05-27 03:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-05-27 03:03 . 2009-05-27 03:03 -------- d-----w- c:\program files\Common Files\Skype
2009-05-24 02:06 . 2007-07-24 16:24 -------- d-----w- c:\program files\Steam
2009-05-11 21:23 . 2009-05-11 21:23 -------- d-----w- c:\documents and settings\Matthew Powell\Application Data\Snapfish
2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2004-08-10 17:51 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2004-08-10 17:51 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-12 14:04 . 2009-04-12 14:04 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2008-05-20 21:02 . 2008-05-20 21:02 16088 ----a-w- c:\program files\iPod Software License.rtf
2005-12-06 00:28 . 2005-12-06 00:28 41888 -c----w- c:\program files\dxdllreg_x86.cab
2005-12-06 00:00 . 2005-12-06 00:00 81092 -c----w- c:\program files\dxupdate.cab
2005-12-06 00:00 . 2005-12-06 00:00 74448 -c----w- c:\program files\DSETUP.dll
2005-12-06 00:00 . 2005-12-06 00:00 484560 -c----w- c:\program files\DXSETUP.exe
2005-12-06 00:00 . 2005-12-06 00:00 2247888 -c----w- c:\program files\dsetup32.dll
2005-12-06 00:00 . 2005-12-06 00:00 13265040 -c----w- c:\program files\dxnt.cab
2005-12-06 00:00 . 2005-12-06 00:00 976020 -c----w- c:\program files\BDAXP.cab
2005-12-06 00:00 . 2005-12-06 00:00 703080 ------w- c:\program files\BDA.cab
2005-12-06 00:00 . 2005-12-06 00:00 15493481 ------w- c:\program files\DirectX.cab
2005-12-06 00:00 . 2005-12-06 00:00 1156363 ------w- c:\program files\BDANT.cab
2007-05-11 00:09 . 2007-05-11 00:09 21 --sha-w- c:\windows\WINPROD.DLL
2005-09-14 22:20 . 2005-09-14 12:11 515566 -csh--w- c:\windows\Help\SBSI\sasar.tmp
2007-01-18 01:01 . 2005-09-06 00:47 56 --sh--r- c:\windows\system32\4BD64B4470.sys
2007-01-18 01:01 . 2005-09-17 07:03 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-07-10 25600]
"hsf7husjnfg98gi498aejhiugjkdg4"="c:\docume~1\MATTHE~1\LOCALS~1\Temp\geqco8wb.exe" [2009-07-10 25600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2009-07-09 25600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"vkfnpx"="c:\windows\system32\vkfnpx.exe" [2009-07-02 29696]
c:\documents and settings\Matthew Powell\Start Menu\Programs\Startup\
Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1996-11-17 51984]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ihaupd32.exe [2008-4-13 18944]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-2-9 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Device Detector 2.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2005-9-29 106496]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2006-1-8 315392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\documents and settings\Matthew Powell\iydumh.exe \s"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Matthew Powell^Start Menu^Programs^Startup^Greetings Workshop Reminders.lnk]
path=c:\documents and settings\Matthew Powell\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk
backup=c:\windows\pss\Greetings Workshop Reminders.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mcupdmgr.exe"=3 (0x3)
"McTskshd.exe"=2 (0x2)
"McShield"=2 (0x2)
"McDetect.exe"=2 (0x2)
"SymWSC"=2 (0x2)
"iPodService"=3 (0x3)
"DM1Service"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\StubInstaller.exe"=
"c:\\Documents and Settings\\Matthew Powell\\Desktop\\utorrent.exe"=
"c:\\Program Files\\America's Army\\System\\server.log"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\BitTorrent\\btdownloadgui.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ruckus Player\\Ruckus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\steamapps\\ebelvis\\half-life\\hl.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\fonts\\services.exe"=
"c:\\WINDOWS\\system32\\vkfnpx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1716:UDP"= 1716:UDP:America's Army
"1717:UDP"= 1717:UDP:America's Army2
"1718:UDP"= 1718:UDP:America's Army3
"27900:TCP"= 27900:TCP:America
"27900:UDP"= 27900:UDP:America's Army5
"8777:UDP"= 8777:UDP:America's Army4
"20045:TCP"= 20045:TCP:America's Army7
"20046:TCP"= 20046:TCP:America's Army6
"20025:TCP"= 20025:TCP:America's Army8
"20047:TCP"= 20047:TCP:America's Army9
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/2/2009 1:31 PM 130936]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/9/2009 10:18 PM 24652]
S1 24f03c54;24f03c54;c:\windows\system32\drivers\24f03c54.sys [7/2/2009 10:51 AM 0]
S1 8669f150;8669f150;c:\windows\system32\drivers\8669f150.sys [7/2/2009 10:47 AM 0]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys --> c:\windows\system32\Drivers\avgldx86.sys [?]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys --> c:\windows\system32\Drivers\avgtdix.sys [?]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe --> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe --> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/2/2009 1:31 PM 348752]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4899a9c1-2f94-11db-b7d3-00142262c694}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5abcdf8-2adf-11db-b7d1-00142262c694}]
\Shell\AutoRun\command - I:\stub.exe
.
Contents of the 'Scheduled Tasks' folder
2009-07-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
2009-07-02 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-09-29 16:43]
2009-07-10 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-08-07 17:24]
.
- - - - ORPHANS REMOVED - - - -
BHO-{D76AB2A1-00F3-42BD-F434-00BBC39C8953} - (no file)
HKCU-Run-LowRiskFileTypes - c:\windows\sysguard.exe
HKCU-Run-12CFG515-K641-55SF-N66P - c:\recycler\S-1-5-21-0243636035-3055115376-381863306-1556\pqlmq.exe
HKCU-Run-reader_s - c:\documents and settings\Matthew Powell\reader_s.exe
HKCU-Run-<NO NAME> - c:\docume~1\MATTHE~1\LOCALS~1\Temp\x42qbinrvv.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-Samsung Common SM - c:\windows\Samsung\ComSMMgr\ssmmgr.exe
HKLM-Run-17137504 - c:\documents and settings\All Users\Application Data\17137504\17137504.exe
Notify-AtiExtEvent - (no file)
Notify-avgrsstarter - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
DPF: ActiveGS.cab - hxxp://www.virtualapple.org/activegs.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Matthew Powell\Application Data\Mozilla\Firefox\Profiles\ex9sg2ii.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\documents and settings\Matthew Powell\Application Data\Mozilla\Firefox\Profiles\ex9sg2ii.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-10 13:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
c:\documents and settings\Matthew Powell\iydumh.exe [1172] 0x81CCB7A8
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\secupdat.dat 43520 bytes
c:\windows\system32\lich.dat 0 bytes
c:\windows\system32\lich.exe 86016 bytes executable
scan completed successfully
hidden files: 3
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lich]
"ImagePath"="\"c:\windows\system32\lich.exe\""
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-07-10 14:07 - machine was rebooted [Matthew Powell]
ComboFix-quarantined-files.txt 2009-07-10 19:07
ComboFix2.txt 2008-03-23 19:27
Pre-Run: 2,564,923,392 bytes free
Post-Run: 2,004,901,888 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
830 --- E O F --- 2009-06-11 08:07
DDS:
DDS (Ver_09-06-26.01) - NTFSx86
Run by Matthew Powell at 14:16:55.04 on Fri 07/10/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.142 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\vkfnpx.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Matthew Powell\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: {D76AB2A1-00F3-42BD-F434-00BBC39C8953} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [hsf7husjnfg98gi498aejhiugjkdg4] c:\docume~1\matthe~1\locals~1\temp\geqco8wb.exe
uRun: [Aim6]
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [vkfnpx] c:\windows\system32\vkfnpx.exe \u
StartupFolder: c:\docume~1\matthe~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\device~1.lnk - c:\program files\olympus\devicedetector\DevDtct2.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dlbcserv.lnk - c:\program files\dell photo printer 720\dlbcserv.exe
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: ActiveGS.cab - hxxp://www.virtualapple.org/activegs.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} - hxxp://www.dotphoto.com/ImageUploader4.cab
DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} - hxxp://www.dotphoto.com/DPImageUploader.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxsrvc.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\matthe~1\applic~1\mozilla\firefox\profiles\ex9sg2ii.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\documents and settings\matthew powell\application data\mozilla\firefox\profiles\ex9sg2ii.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-2 130936]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-9 24652]
S1 24f03c54;24f03c54;c:\windows\system32\drivers\24f03c54.sys [2009-7-2 0]
S1 8669f150;8669f150;c:\windows\system32\drivers\8669f150.sys [2009-7-2 0]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys --> c:\windows\system32\drivers\avgldx86.sys [?]
S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys --> c:\windows\system32\drivers\avgmfx86.sys [?]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys --> c:\windows\system32\drivers\avgtdix.sys [?]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe --> c:\progra~1\avg\avg8\avgemc.exe [?]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe --> c:\progra~1\avg\avg8\avgwdsvc.exe [?]
S2 lich;lich;c:\windows\system32\lich.exe [2009-7-2 86016]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-2 348752]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-7-2 1095560]
=============== Created Last 30 ================
2009-07-10 14:12 142,592 a------- c:\windows\system32\drivers\aec.sys
2009-07-10 14:12 14,336 a------- c:\windows\system32\drivers\asyncmac.sys
2009-07-10 14:03 <DIR> --d----- c:\windows\system32\dllcache\cache
2009-07-10 13:58 13,312 a---h--- c:\documents and settings\matthew powell\iydumh.exe
2009-07-10 13:58 43,520 ----h--- c:\windows\system32\secupdat.dat
2009-07-10 13:55 182,656 a------- c:\windows\system32\dllcache\ndis.sys
2009-07-09 17:07 50,176 a------- c:\windows\system32\proquota.exe
2009-07-09 17:07 39,424 a------- c:\windows\system32\grpconv.exe
2009-07-09 17:04 182,656 a------- c:\windows\system32\drivers\ndis.sys
2009-07-09 16:17 161,792 a------- c:\windows\SWREG.exe
2009-07-09 16:17 155,136 a------- c:\windows\PEV.exe
2009-07-09 16:17 98,816 a------- c:\windows\sed.exe
2009-07-09 16:12 33,280 a------- C:\stfqqym.exe
2009-07-09 16:09 136,704 a------- c:\windows\msd.exe
2009-07-09 13:26 136,704 a------- c:\windows\msc.exe
2009-07-09 13:20 136,704 a------- c:\windows\msb.exe
2009-07-07 18:52 25,600 a------- C:\furvsh.exe
2009-07-02 13:32 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
2009-07-02 13:31 130,936 a------- c:\windows\system32\drivers\PCTCore.sys
2009-07-02 13:31 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-02 13:31 <DIR> --d----- c:\program files\common files\PC Tools
2009-07-02 13:31 64,392 a------- c:\windows\system32\drivers\pctplsg.sys
2009-07-02 13:31 <DIR> --d----- c:\program files\Spyware Doctor
2009-07-02 13:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
2009-07-02 13:20 29,696 a------- c:\windows\system32\vkfnpx.exe
2009-07-02 12:51 831 a------- c:\windows\system32\critical_warning.html
2009-07-02 12:51 43,008 a------- c:\windows\system32\winupdate .exe
2009-07-02 10:51 0 a------- c:\windows\system32\drivers\24f03c54.sys
2009-07-02 10:51 210,701 a------- C:\illhtee.exe
2009-07-02 10:51 52,225 a------- c:\windows\system32\reader_s.exe256
2009-07-02 10:51 52,225 a------- c:\windows\system32\reader_s.exe249
2009-07-02 10:51 52,225 a------- c:\windows\system32\reader_s .exe
2009-07-02 10:47 0 a------- c:\windows\system32\drivers\8669f150.sys
2009-07-02 10:46 96,768 a------- C:\fdvjfx.exe
2009-07-02 10:46 201,467 a------- C:\gklrwl.exe
2009-07-02 10:46 <DIR> --d----- c:\program files\drv
2009-07-02 10:46 2 a------- C:\-522083980
2009-07-02 10:45 24,576 a------- C:\ttrw.exe
==================== Find3M ====================
2009-07-10 13:55 182,656 a------- c:\windows\system32\dllcache\cache\ndis.sys
2009-07-09 16:23 4 ----h--- c:\windows\fonts\mlog
2009-05-07 10:32 345,600 a------- c:\windows\system32\localspl.dll
2009-05-07 10:32 345,600 -------- c:\windows\system32\dllcache\localspl.dll
2009-04-28 23:46 3,068,928 -------- c:\windows\system32\dllcache\mshtml.dll
2009-04-28 23:46 666,624 a------- c:\windows\system32\wininet.dll
2009-04-28 23:46 666,624 a------- c:\windows\system32\dllcache\cache\wininet.dll
2009-04-28 23:46 666,624 -------- c:\windows\system32\dllcache\wininet.dll
2009-04-28 23:46 620,032 -------- c:\windows\system32\dllcache\urlmon.dll
2009-04-28 23:46 1,499,136 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-04-28 23:46 81,920 a------- c:\windows\system32\ieencode.dll
2009-04-28 23:46 81,920 -------- c:\windows\system32\dllcache\ieencode.dll
2009-04-17 07:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-17 07:26 1,847,168 -------- c:\windows\system32\dllcache\win32k.sys
2009-04-15 09:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-04-15 09:51 585,216 -------- c:\windows\system32\dllcache\rpcrt4.dll
2008-05-20 16:02 16,088 a------- c:\program files\iPod Software License.rtf
2006-02-15 16:57 32 ac---r-- c:\documents and settings\all users\hash.dat
2005-12-05 19:28 41,888 -c------ c:\program files\dxdllreg_x86.cab
2005-12-05 19:00 2,247,888 -c------ c:\program files\dsetup32.dll
2005-12-05 19:00 484,560 -c------ c:\program files\DXSETUP.exe
2005-12-05 19:00 81,092 -c------ c:\program files\dxupdate.cab
2005-12-05 19:00 74,448 -c------ c:\program files\DSETUP.dll
2005-12-05 19:00 13,265,040 -c------ c:\program files\dxnt.cab
2005-12-05 19:00 976,020 -c------ c:\program files\BDAXP.cab
2005-12-05 19:00 15,493,481 -------- c:\program files\DirectX.cab
2005-12-05 19:00 1,156,363 -------- c:\program files\BDANT.cab
2005-12-05 19:00 703,080 -------- c:\program files\BDA.cab
2007-05-10 19:09 21 a--sh--- c:\windows\WINPROD.DLL
============= FINISH: 14:18:11.79 ===============
Attach:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 8/9/2005 8:30:16 PM
System Uptime: 7/10/2009 2:11:32 PM (0 hours ago)
Motherboard: Dell Computer Corp. | | 0F5949
Processor: Intel(R) Celeron(R) CPU 2.40GHz | Microprocessor | 2392/400mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 71 GiB total, 1.881 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 7/9/2009 5:10:05 PM - System Checkpoint
==== Installed Programs ======================
µTorrent
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Photoshop 7.0
Adobe Reader 7.0
AIM 6
AOL Instant Messenger
AOLIcon
Apple Mobile Device Support
Apple Software Update
ATI Multimedia Center 8.6.0.0
Audacity 1.2.4
AutoUpdate
Bonjour
Broadcom Management Programs
BSPlayer
Counter-Strike
DAO
Dell Driver Reset Tool
Dell Media Experience
Dell Photo Printer 720
Dell Photo Printer 720 Logger
Dell Picture Studio v3.0
Dell Support 3.1
Dell System Restore
DivX
DivX Web Player
Fallout
Finale 2004
Free CD to MP3 Converter
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Intel(R) 537EP V9x DF PCI Modem
Intel(R) Extreme Graphics Driver
Internet Explorer Default Page
iPod for Windows 2005-03-23
iPod for Windows 2005-11-17
iPod for Windows 2006-03-23
IrfanView (remove only)
iScrobbler
iTunes
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Kaspersky Online Scanner
Last.fm 1.5.4.24567
Last.fm Player 1.1.4
Learn2 Player (Uninstall Only)
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player
Macromedia Shockwave Player
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft FrontPage 2000
Microsoft Office 97, Professional Edition
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft Word 2000
mIRC
MMC86
Modem Event Monitor
Modem Helper
Modem On Hold
Move Networks Media Player for Internet Explorer
Mozilla Firefox (3.0.11)
MP3 WAV Converter 3.18
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
My Way Search Assistant
Network Play System (Patching)
Norton Security Center
Photo Click
PowerDVD 5.5
QuickTime
RadLight MPC DirectShow Filter (remove only)
RealPlayer
Rhapsody Player Engine
Riva FLV Encoder 2.0
River Past Audio Converter
River Past Audio Converter Pro
Ruckus Player
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Skype™ 4.0
Sonic DLA
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
Spyware Doctor 6.0
Starcraft
Steam
System Requirements Lab
Team Fortress Classic
TeamSpeak 2 RC2
Train Hunters beta 2.0
TurboTax Deluxe 2005
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Ventrilo Client
Viewpoint Media Player
WebCyberCoach 3.2 Dell
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
WinRAR archiver
WinZip
==== Event Viewer Messages From Past Week ========
7/9/2009 5:10:21 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
7/9/2009 5:10:06 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX IPSec MRxSmb NDIS NetBIOS NetBT NPPTNT2 Tcpip
7/9/2009 5:09:57 PM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The specified procedure could not be found.
7/9/2009 5:09:57 PM, error: Service Control Manager [7023] - The Server service terminated with the following error: The specified procedure could not be found.
7/9/2009 5:09:57 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: %%2147952450
7/9/2009 5:09:57 PM, error: Service Control Manager [7001] - The AVG Free8 E-mail Scanner service depends on the AVG Free8 WatchDog service which failed to start because of the following error: The system cannot find the file specified.
7/9/2009 5:09:56 PM, error: Service Control Manager [7024] - The Workstation service terminated with service-specific error 2250 (0x8CA).
7/9/2009 5:09:56 PM, error: Service Control Manager [7001] - The Wireless Zero Configuration service depends on the NDIS Usermode I/O Protocol service which failed to start because of the following error: The specified procedure could not be found.
7/9/2009 5:09:56 PM, error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector service which failed to start because of the following error: The specified procedure could not be found.
7/9/2009 5:09:56 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
7/9/2009 5:09:56 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/9/2009 5:09:56 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/9/2009 5:09:56 PM, error: Service Control Manager [7001] - The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service has returned a service-specific error code.
7/9/2009 5:09:56 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/9/2009 5:09:56 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/9/2009 5:09:56 PM, error: Service Control Manager [7000] - The WebDav Client Redirector service failed to start due to the following error: The specified procedure could not be found.
7/9/2009 5:09:56 PM, error: Service Control Manager [7000] - The NDIS Usermode I/O Protocol service failed to start due to the following error: The specified procedure could not be found.
7/9/2009 5:09:56 PM, error: Service Control Manager [7000] - The AVG Free8 WatchDog service failed to start due to the following error: The system cannot find the file specified.
7/9/2009 5:09:28 PM, error: Workstation [5727] - Could not load RDR device driver.
7/9/2009 5:09:28 PM, error: Workstation [5727] - Could not load MRxSmb device driver.
7/9/2009 4:19:43 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service McUpdMgr.Exe with arguments "/Embedding" in order to run the server: {C3A036FA-DA7D-45E2-AE16-6CADAAE5D75E}
7/9/2009 4:17:57 PM, error: SRService [104] - The System Restore initialization process failed.
7/8/2009 5:00:50 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer DADSLAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{29D5C063-F053-412. The master browser is stopping or an election is being forced.
7/8/2009 3:21:56 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
7/7/2009 5:15:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
7/7/2009 5:14:44 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
7/7/2009 5:12:18 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
7/7/2009 5:09:30 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
7/10/2009 1:43:09 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm NPPTNT2
7/10/2009 1:22:46 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 AvgTdiX NPPTNT2
==== End Of File ===========================