Hi,
Hope you don't mind wading through all this. Your efforts are much appreciated
DDS (Ver_09-06-26.01) - NTFSx86
Run by RW at 20:11:03.29 on Sun 07/05/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.355 [GMT 10:00]
AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\system32\CNAB3RPK.EXE
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\hpb2ksrv.exe
C:\WINDOWS\system32\hpbhksrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
svchost.exe
C:\WINDOWS\system32\stacsv.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHP.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\hpnra.exe
C:\WINDOWS\system32\hpstatus.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\HPBSPSVR.EXE
C:\WINDOWS\system32\HPBJDSNT.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Documents and Settings\RW\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com.au/advanced_search?hl=en
uSearch Page = hxxp://www.telstra.com/
uSearch Bar = hxxp://www.google.com.au/hws/sb/dell-row/en/side.html?channel=au
uDefault_Page_URL =
www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070109
uWindow Title = Telstra BigPond Home Internet Explorer
uInternet Connection Wizard,ShellNext = hxxp://www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070109
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\progra~1\skype\phone\ieplugin\SKYPEI~1.DLL
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.0.0.125\IPSBHO.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: BigPond Wireless Broadband 2.0 Auto Dial: {db92ec3f-697d-4c3b-9a3b-3abbd23d4a85} - c:\program files\telstra\bigpond wireless broadband 2.0\bpwbb2ad.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [EPSON Stylus Photo R250 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAHP.EXE /P30 "EPSON Stylus Photo R250 Series" /O6 "USB001" /M "Stylus Photo R250"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Network Registry Agent] c:\windows\system32\hpnra.exe
mRun: [HP Status] c:\windows\system32\hpstatus.exe
mRun: [HPLJ Config] c:\program files\hewlett-packard\clj2500\SetConfig.exe
mRun: [HP Proxy Server] c:\program files\hewlett-packard\proxyservice\ProxyService.lnk
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [BigPondWirelessBroadbandCM] "c:\program files\telstra\bigpond wireless broadband 2.0\BigPond_CM.exe" -tsr
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [WMDM PMSP Service] c:\windows\system32\cssrss.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\progra~1\skype\phone\ieplugin\SKYPEI~1.DLL
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} - hxxp://furano.miemasu.net:86/SysCamInst.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
TCP: NameServer = 208.67.220.220,208.67.222.222
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1000000.07d\SymEFA.sys [2009-6-24 309296]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1000000.07d\BHDrvx86.sys [2009-6-24 254512]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1000000.07d\ccHPx86.sys [2009-6-24 362544]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090625.003\IDSXpx86.sys [2009-7-1 276344]
R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;c:\windows\system32\drivers\hnm_wrls_pkt.sys [2006-7-14 13824]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.0.0.125\ccSvcHst.exe [2009-6-24 115560]
R2 wsppkt;Wireless Security Protocol;c:\windows\system32\drivers\wsp_pkt.sys [2006-7-14 13696]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-6-23 101936]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090704.020\NAVENG.SYS [2009-7-5 89104]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090704.020\NAVEX15.SYS [2009-7-5 876144]
S1 etpde65;etpde65;c:\windows\system32\drivers\etpde65.sys [2009-6-10 33856]
S2 aspimgr;Microsoft ASPI Manager;c:\windows\system32\aspimgr.exe --> c:\windows\system32\aspimgr.exe [?]
S3 cmo_bus;Data Modem @ CDMA Composite Device driver (WDM);c:\windows\system32\drivers\cmo_bus.sys [2007-1-30 57744]
S3 cmo_mdfl;Data Modem @ CDMA Filter;c:\windows\system32\drivers\cmo_mdfl.sys [2007-1-30 8304]
S3 cmo_mdm;Data Modem @ CDMA Drivers;c:\windows\system32\drivers\cmo_mdm.sys [2007-1-30 93328]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2007-11-16 34064]
S3 PAC7311;VGA USB Camera;c:\windows\system32\drivers\PA707UCM.SYS [2007-3-12 155648]
S3 SWNC8U52;Sierra Wireless MUX NDIS Driver (UMTS52);c:\windows\system32\drivers\swnc8u52.sys [2007-11-19 164480]
S3 SWUMX52;Sierra Wireless USB MUX Driver (UMTS52);c:\windows\system32\drivers\swumx52.sys [2007-11-19 140672]
=============== Created Last 30 ================
2009-06-25 16:53 <DIR> --d-h--- c:\windows\PIF
2009-06-24 17:48 <DIR> --d--r-- c:\program files\Norton Support
2009-06-24 15:40 35,888 a----r-- c:\windows\system32\drivers\SymIM.sys
2009-06-24 15:40 124,464 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-24 15:40 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2009-06-24 15:40 10,635 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-24 15:40 806 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-24 15:40 <DIR> --d----- c:\program files\Symantec
2009-06-24 15:40 <DIR> --d----- c:\program files\common files\Symantec Shared
2009-06-24 15:39 <DIR> --d----- c:\windows\system32\drivers\NAV
2009-06-24 15:39 <DIR> --d----- c:\program files\Norton AntiVirus
2009-06-24 15:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Norton
2009-06-24 15:39 <DIR> --d----- c:\program files\NortonInstaller
2009-06-24 15:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-06-24 15:04 <DIR> --d----- c:\program files\Trend Micro
2009-06-10 22:45 33,856 a------- c:\windows\system32\drivers\etpde65.sys
2009-06-06 20:17 <DIR> --d----- c:\windows\system32\wbem\Repository
2009-06-06 20:17 <DIR> --d----- C:\Digital Pictures
2009-06-06 20:17 <DIR> --d----- C:\Mary Graduation pics
2009-06-06 20:17 <DIR> --d----- C:\Hot Flashes
==================== Find3M ====================
2007-01-31 08:48 124 a------- c:\docume~1\rw\applic~1\wklnhst.dat
2008-11-22 11:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008112220081123\index.dat
============= FINISH: 20:11:59.62 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 1/17/2007 2:35:26 PM
System Uptime: 7/5/2009 7:29:58 PM (1 hours ago)
Motherboard: Dell Inc. | | 0RT486
Processor: Intel(R) Core(TM)2 CPU T5600 @ 1.83GHz | Microprocessor | 1830/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 68 GiB total, 26.306 GiB free.
D: is CDROM ()
F: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\3C74D038424FC000
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\3C74D038424FC000
Service: NIC1394
==== System Restore Points ===================
RP1: 7/5/2009 8:02:02 PM - System Checkpoint
==== Installed Programs ======================
Ad-Aware SE Personal
Adobe Flash Player ActiveX
Adobe Reader 8.1.5
ArcSoft PhotoStudio 5.5
BigPond Wireless Broadband 2.10.5
BlackBerry Desktop Software 4.3
Broadcom Management Programs
Canon iP1300
Canon iP4200
CCleaner (remove only)
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
DataView
Dell Support 3.2.1
Dell System Restore
Digital Line Detect
doPDF 5.3 printer
EPSON Easy Photo Print
EPSON Printer Software
ERUNT 1.1j
ESPR250 User's Guide
ffvfw (uninstall only)
FLV Player 2.0, build 23
GemMaster Mystic
Google Desktop
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB952287)
hp color LaserJet 2500 Uninstaller
Intel(R) Graphics Media Accelerator Driver
Intel(R) PROSet/Wireless Software
iTunes
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 11
Java(TM) 6 Update 5
Java(TM) 6 Update 7
KB408682
MapInfo Professional 8.5
mCore
MCU
mDrWiFi
MediaDirect
MetaFrame Presentation Server Web Client for Win32
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Works
mIWA
Mixer
mLogView
mMHouse
Modem Helper
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
mWlsSafe
mWMI
mXML
mZConfig
NetWaiting
Norton AntiVirus
OutlookAddinSetup
Petrosys 15.3 for Windows
PetroView
PetroView MapInfo
QuickSet
QuickTime
RealPlayer Basic
Roxio DLA
Roxio Media Manager
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
RunAlyzer
SearchAssist
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Sentinel Protection Installer 7.2.2
Skype 3.0
Skype add-on for IE
Skype Plugin Manager
Sonic Encoders
Sonic Update Manager
Sound Blaster Audigy ADVANCED MB Demo
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
Synaptics Pointing Device Driver
Telstra ISDN Setup Program
The KINGDOM Software 8.0 (32-bit)
Ulead VideoStudio 8.0 SE DVD
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
VGA USB Camera
Viewpoint Media Player (Remove Only)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB912067
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
7/5/2009 8:11:08 PM, error: Service Control Manager [7016] - The BrSplService service has reported an invalid current state 0.
7/4/2009 9:31:09 AM, error: NtServicePack [4379] - Windows XP Hotfix KB961501 installation failed.
KB961501 installation did not complete.
7/4/2009 9:30:58 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969898 installation failed.
KB969898 installation did not complete.
7/4/2009 9:30:45 AM, error: NtServicePack [4379] - Windows XP Hotfix KB970238 installation failed.
KB970238 installation did not complete.
7/4/2009 9:30:33 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969897-IE7 installation failed.
KB969897 installation did not complete.
7/4/2009 9:29:28 AM, error: NtServicePack [4379] - Windows XP Hotfix KB968537 installation failed.
KB968537 installation did not complete.
7/4/2009 9:09:27 AM, error: Service Control Manager [7000] - The HTTP SSL service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/4/2009 9:09:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.
7/4/2009 9:00:19 AM, error: Dhcp [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 0019D200119E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
7/3/2009 9:40:52 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f01f: Windows Genuine Advantage Validation Tool (KB892130).
7/3/2009 9:40:47 AM, error: WGA [4379] - Windows XP Hotfix KB892130 installation failed.
Failed to add registry entry.
7/3/2009 8:19:53 PM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 0019D200119E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
7/3/2009 3:01:50 AM, error: NtServicePack [4379] - Windows XP Hotfix KB961501 installation failed.
KB961501 installation did not complete.
7/3/2009 3:01:42 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969898 installation failed.
KB969898 installation did not complete.
7/3/2009 3:01:35 AM, error: NtServicePack [4379] - Windows XP Hotfix KB970238 installation failed.
KB970238 installation did not complete.
7/3/2009 3:01:26 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969897-IE7 installation failed.
KB969897 installation did not complete.
7/3/2009 3:00:53 AM, error: NtServicePack [4379] - Windows XP Hotfix KB968537 installation failed.
KB968537 installation did not complete.
7/3/2009 11:34:05 AM, error: Service Control Manager [7022] - The DCOM Server Process Launcher service hung on starting.
7/3/2009 10:27:56 PM, error: NtServicePack [4379] - Windows XP Hotfix KB961501 installation failed.
KB961501 installation did not complete.
7/3/2009 10:27:50 PM, error: NtServicePack [4379] - Windows XP Hotfix KB969898 installation failed.
KB969898 installation did not complete.
7/3/2009 10:27:42 PM, error: NtServicePack [4379] - Windows XP Hotfix KB970238 installation failed.
KB970238 installation did not complete.
7/3/2009 10:27:32 PM, error: NtServicePack [4379] - Windows XP Hotfix KB969897-IE7 installation failed.
KB969897 installation did not complete.
7/3/2009 10:27:03 PM, error: NtServicePack [4379] - Windows XP Hotfix KB968537 installation failed.
KB968537 installation did not complete.
7/2/2009 9:24:35 AM, error: NtServicePack [4379] - Windows XP Hotfix KB961501 installation failed.
KB961501 installation did not complete.
7/2/2009 9:24:09 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969898 installation failed.
KB969898 installation did not complete.
7/2/2009 9:23:48 AM, error: NtServicePack [4379] - Windows XP Hotfix KB970238 installation failed.
KB970238 installation did not complete.
7/2/2009 9:23:17 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969897-IE7 installation failed.
KB969897 installation did not complete.
7/2/2009 9:21:12 AM, error: NtServicePack [4379] - Windows XP Hotfix KB968537 installation failed.
KB968537 installation did not complete.
7/2/2009 9:14:35 AM, error: Service Control Manager [7000] - The Microsoft ASPI Manager service failed to start due to the following error: The system cannot find the file specified.
7/2/2009 9:12:23 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
7/2/2009 9:12:10 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
7/2/2009 5:22:19 PM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 0019D200119E has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
7/2/2009 2:16:14 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the DCOM Server Process Launcher service to connect.
7/2/2009 2:16:14 PM, error: Service Control Manager [7000] - The DCOM Server Process Launcher service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
7/2/2009 10:03:10 PM, error: Dhcp [1002] - The IP address lease 192.168.0.106 for the Network Card with network address 0019D200119E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
7/1/2009 9:46:38 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV BHDrvx86 ccHP eeCtrl Fips IDSxpx86 intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SRTSP SRTSPX SYMTDI Tcpip
7/1/2009 9:46:38 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
7/1/2009 9:46:38 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/1/2009 9:46:38 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/1/2009 9:46:38 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
7/1/2009 12:37:00 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f01f: Security Update for Windows XP (KB961501).
7/1/2009 12:37:00 AM, error: NtServicePack [4379] - Windows XP Hotfix KB961501 installation failed.
KB961501 installation did not complete.
7/1/2009 12:36:53 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f01f: Update Rollup for ActiveX Killbits for Windows XP (KB969898).
7/1/2009 12:36:52 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969898 installation failed.
KB969898 installation did not complete.
7/1/2009 12:36:45 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f01f: Security Update for Windows XP (KB970238).
7/1/2009 12:36:45 AM, error: NtServicePack [4379] - Windows XP Hotfix KB970238 installation failed.
KB970238 installation did not complete.
7/1/2009 12:36:35 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f01f: Cumulative Security Update for Internet Explorer 7 for Windows XP (KB969897).
7/1/2009 12:36:35 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969897-IE7 installation failed.
KB969897 installation did not complete.
7/1/2009 12:36:05 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f01f: Security Update for Windows XP (KB968537).
7/1/2009 12:36:05 AM, error: NtServicePack [4379] - Windows XP Hotfix KB968537 installation failed.
KB968537 installation did not complete.
7/1/2009 11:35:15 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
6/30/2009 12:53:14 AM, error: NtServicePack [4379] - Windows XP Hotfix KB961501 installation failed.
KB961501 installation did not complete.
6/30/2009 12:53:03 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969898 installation failed.
KB969898 installation did not complete.
6/30/2009 12:52:52 AM, error: NtServicePack [4379] - Windows XP Hotfix KB970238 installation failed.
KB970238 installation did not complete.
6/30/2009 12:52:41 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969897-IE7 installation failed.
KB969897 installation did not complete.
6/30/2009 12:52:05 AM, error: NtServicePack [4379] - Windows XP Hotfix KB968537 installation failed.
KB968537 installation did not complete.
6/29/2009 8:54:54 PM, error: NtServicePack [4379] - Windows XP Hotfix KB961501 installation failed.
KB961501 installation did not complete.
6/29/2009 8:54:47 PM, error: NtServicePack [4379] - Windows XP Hotfix KB969898 installation failed.
KB969898 installation did not complete.
6/29/2009 8:54:40 PM, error: NtServicePack [4379] - Windows XP Hotfix KB970238 installation failed.
KB970238 installation did not complete.
6/29/2009 8:54:31 PM, error: NtServicePack [4379] - Windows XP Hotfix KB969897-IE7 installation failed.
KB969897 installation did not complete.
6/29/2009 8:53:50 PM, error: NtServicePack [4379] - Windows XP Hotfix KB968537 installation failed.
KB968537 installation did not complete.
6/29/2009 3:02:25 AM, error: NtServicePack [4379] - Windows XP Hotfix KB961501 installation failed.
KB961501 installation did not complete.
6/29/2009 3:02:17 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969898 installation failed.
KB969898 installation did not complete.
6/29/2009 3:02:10 AM, error: NtServicePack [4379] - Windows XP Hotfix KB970238 installation failed.
KB970238 installation did not complete.
6/29/2009 3:02:00 AM, error: NtServicePack [4379] - Windows XP Hotfix KB969897-IE7 installation failed.
KB969897 installation did not complete.
6/29/2009 3:01:31 AM, error: NtServicePack [4379] - Windows XP Hotfix KB968537 installation failed.
KB968537 installation did not complete.
==== End Of File ===========================
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-07-05 23:52:58
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT 86E05688 ZwAlertResumeThread
SSDT 86B91D98 ZwAlertThread
SSDT 86E039F0 ZwAllocateVirtualMemory
SSDT 86B280D8 ZwAssignProcessToJobObject
SSDT 86BB77D0 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xAA108020]
SSDT 8695D810 ZwCreateMutant
SSDT 86B3BCF0 ZwCreateSymbolicLinkObject
SSDT 869BD748 ZwCreateThread
SSDT 86B5FAB0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xAA1082A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAA108800]
SSDT 869F5078 ZwDuplicateObject
SSDT 860529E0 ZwEnumerateValueKey
SSDT 86A11CB8 ZwFreeVirtualMemory
SSDT 86B36BD8 ZwImpersonateAnonymousToken
SSDT 86B96C38 ZwImpersonateThread
SSDT 86E31E80 ZwLoadDriver
SSDT 86C5C600 ZwMapViewOfSection
SSDT 86B4E110 ZwOpenEvent
SSDT 869F53D8 ZwOpenProcess
SSDT 86E43CD8 ZwOpenProcessToken
SSDT 86B677F8 ZwOpenSection
SSDT 869F5248 ZwOpenThread
SSDT 86B747B8 ZwProtectVirtualMemory
SSDT 869D9228 ZwResumeThread
SSDT 86B96910 ZwSetContextThread
SSDT 86A11918 ZwSetInformationProcess
SSDT 86BAA690 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAA108A50]
SSDT 86B59238 ZwSuspendProcess
SSDT 86B682B0 ZwSuspendThread
SSDT 86B64D90 ZwTerminateProcess
SSDT 86B66BA0 ZwTerminateThread
SSDT 86E41D40 ZwUnmapViewOfSection
SSDT 86E03620 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
? SYMEFA.SYS The system cannot find the file specified. !
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8604EAD0
Device \FileSystem\Mup \Dfs 8604EAD0
Device \Driver\Tcpip \Device\Ip 860513F0
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
Device \FileSystem\RAW \Device\RawTape 8604EAD0
Device \FileSystem\DLACDBHM \Device\sscdbhook1 8604EAD0
Device \Driver\Tcpip \Device\Tcp 860513F0
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \FileSystem\SRTSP \Device\NAVAP 8604EAD0
Device \FileSystem\Mup \Device\Mup 8604EAD0
Device \Driver\Tcpip \Device\Udp 860513F0
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\Tcpip \Device\RawIp 860513F0
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \FileSystem\SRTSP \Device\SAVRT 8604EAD0
Device \FileSystem\RAW \Device\RawDisk 8604EAD0
Device \FileSystem\SymEFA \Device\SYMEFA 8604EAD0
Device \Driver\Tcpip \Device\IPMULTICAST 860513F0
Device \FileSystem\SRTSP \Device\SRTSP 8604EAD0
Device \FileSystem\RAW \Device\RawCdRom 8604EAD0
Device \FileSystem\Mup \Device\WinDfs\Root 8604EAD0
AttachedDevice \FileSystem\Fastfat \Fat 8604EAD0
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
---- Threads - GMER 1.0.15 ----
Thread System [4:644] 86052670
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@PromoReg C:\WINDOWS\System32\svchost.exe
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
---- EOF - GMER 1.0.15 ----