HoosierDave
New member
I am working on a friend's PC that has the Smitfraud problem. The PC runs very slow when booted in normal mode and won't open MS IE, instead when the MS IE icon is clicked an icon called "Copy of MS IE" is created. I have run Spybot in Safe mode and it has reported to be clean. I was not able to run the Kaspersky Online scan because of the MS IE problems.
I have run the HJT and the log is attached:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:23:43 PM, on 5/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6061214
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6061214
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6061214
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://antispywareupdates.net/?aid=496.cbcbcb
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: (no name) - {313399B0-245E-1FFF-5712-5D00C9C6DCCE} - C:\WINDOWS\system32\esg.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {548E1154-FA99-4B77-9FC5-02C9D8C9D24D} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: BatBHO - {63F7460B-C831-4142-A4AA-5EC303EC4343} - C:\Program Files\Batco\bat.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: BndAero6 IE Helper - {82E5E2FF-9260-4d88-B0C6-7CC358C5D418} - C:\Program Files\QdrDrive\QdrDrive11.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (file missing)
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA78] command /c del "C:\Program Files\AMSys\guid.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3663] cmd /c del "C:\Program Files\AMSys\guid.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9864] command /c del "C:\Program Files\AMSys\ijl15.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8716] cmd /c del "C:\Program Files\AMSys\ijl15.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6414] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Terms.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3579] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Terms.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7758] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5698] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7985] command /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8628] cmd /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4434] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingC390] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1406] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6042] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4276] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1236] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3836] command /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC33] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7362] command /c del "C:\WINDOWS\b116.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4689] cmd /c del "C:\WINDOWS\b116.exe_old"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB1307] command /c del "C:\Program Files\AMSys\guid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3120] cmd /c del "C:\Program Files\AMSys\guid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5782] command /c del "C:\Program Files\AMSys\ijl15.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6571] cmd /c del "C:\Program Files\AMSys\ijl15.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4943] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Terms.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6150] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Terms.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1173] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1158] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8708] command /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3416] cmd /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB931] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4191] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5409] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2126] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingB192] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2565] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1621] command /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2340] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3528] command /c del "C:\WINDOWS\b116.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9935] cmd /c del "C:\WINDOWS\b116.exe_old"
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [SearchAndDestroyMFC] (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB1307] command /c del "C:\Program Files\AMSys\guid.dat" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB1173] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD1158] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB8708] command /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD3416] cmd /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB931] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD4191] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB5409] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD2126] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB192] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD2565] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB1621] command /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD2340] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB3528] command /c del "C:\WINDOWS\b116.exe_old" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD9935] cmd /c del "C:\WINDOWS\b116.exe_old" (User '?')
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1186968263234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186968226937
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.4.cab
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 15534 bytes
I have run the HJT and the log is attached:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:23:43 PM, on 5/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6061214
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6061214
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6061214
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://antispywareupdates.net/?aid=496.cbcbcb
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: (no name) - {313399B0-245E-1FFF-5712-5D00C9C6DCCE} - C:\WINDOWS\system32\esg.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {548E1154-FA99-4B77-9FC5-02C9D8C9D24D} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: BatBHO - {63F7460B-C831-4142-A4AA-5EC303EC4343} - C:\Program Files\Batco\bat.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: BndAero6 IE Helper - {82E5E2FF-9260-4d88-B0C6-7CC358C5D418} - C:\Program Files\QdrDrive\QdrDrive11.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (file missing)
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA78] command /c del "C:\Program Files\AMSys\guid.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3663] cmd /c del "C:\Program Files\AMSys\guid.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9864] command /c del "C:\Program Files\AMSys\ijl15.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8716] cmd /c del "C:\Program Files\AMSys\ijl15.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6414] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Terms.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3579] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Terms.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7758] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5698] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7985] command /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8628] cmd /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4434] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingC390] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1406] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6042] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4276] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1236] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3836] command /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC33] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7362] command /c del "C:\WINDOWS\b116.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4689] cmd /c del "C:\WINDOWS\b116.exe_old"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB1307] command /c del "C:\Program Files\AMSys\guid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3120] cmd /c del "C:\Program Files\AMSys\guid.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5782] command /c del "C:\Program Files\AMSys\ijl15.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6571] cmd /c del "C:\Program Files\AMSys\ijl15.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4943] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Terms.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6150] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Terms.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1173] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1158] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8708] command /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3416] cmd /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB931] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4191] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5409] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2126] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingB192] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2565] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1621] command /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2340] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3528] command /c del "C:\WINDOWS\b116.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9935] cmd /c del "C:\WINDOWS\b116.exe_old"
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [SearchAndDestroyMFC] (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB1307] command /c del "C:\Program Files\AMSys\guid.dat" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB1173] command /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD1158] cmd /c del "C:\Documents and Settings\Karen\Start Menu\Programs\Outerinfo\Uninstall.lnk" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB8708] command /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD3416] cmd /c del "C:\Program Files\Search And Destroy\Search And Destroy.exe" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB931] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD4191] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG1.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB5409] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD2126] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG2.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB192] command /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD2565] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\IRIMG3.JPG" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB1621] command /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD2340] cmd /c del "C:\Program Files\Search And Destroy\Uninstall\uninstall.dat" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingB3528] command /c del "C:\WINDOWS\b116.exe_old" (User '?')
O4 - HKUS\S-1-5-21-122960559-3393139398-1281873024-500\..\RunOnce: [SpybotDeletingD9935] cmd /c del "C:\WINDOWS\b116.exe_old" (User '?')
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1186968263234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186968226937
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.4.cab
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 15534 bytes