I ran ComboFix, and the I am not having the redirect problem anymore (although its worth noting that when I previously ran Malware, Spybot and Ad-Aware, the problem went a away for a bit, only to return later). I have posted below the Combo fix report and a new HJT report.
Combofix:
ComboFix 09-07-01.01 - doug 07/01/2009 12:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.495.107 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\SKYNETnylyfvam.sys
c:\windows\system32\SKYNETivmehmqx.dll
c:\windows\system32\SKYNETostjmbrx.dat
c:\windows\system32\SKYNETroltakbi.dat
c:\windows\system32\SKYNETycpxphwh.dll
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\wordpad.exe
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\system volume information\_restore{B1077A57-160B-41EB-95C0-37C016A72306}\RP940\A0126377.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_SKYNETxducfuwb
((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 )))))))))))))))))))))))))))))))
.
2009-07-01 19:28 . 2004-08-04 07:56 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe
2009-07-01 19:28 . 2004-08-04 07:56 50176 —-a-w- c:\windows\system32\proquota.exe
2009-07-01 17:17 . 2009-07-01 17:17 ——– d—–w- C:\spoolerlogs
2009-06-30 00:24 . 2009-06-30 00:23 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-30 00:23 . 2009-06-30 00:23 152576 —-a-w- c:\documents and settings\Doug\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-29 05:43 . 2009-06-29 05:43 ——– d—–w- c:\documents and settings\Doug\Application Data\Notepad++
2009-06-29 05:36 . 2009-06-29 05:36 ——– d—–w- c:\program files\Trend Micro
2009-06-26 21:48 . 2009-06-26 21:19 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-26 21:19 . 2009-06-26 21:18 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-26 21:19 . 2009-06-26 21:19 314200 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-26 21:19 . 2009-06-26 21:19 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-26 21:19 . 2009-06-26 21:19 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-26 21:19 . 2009-06-26 21:19 348496 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-26 21:19 . 2009-06-26 21:19 169312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-26 21:19 . 2009-06-26 21:19 296800 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-26 21:19 . 2009-06-26 21:19 83808 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-26 21:18 . 2009-06-26 21:18 1630048 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-26 21:18 . 2009-06-26 21:18 40288 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-26 21:18 . 2009-06-26 21:18 212848 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-26 21:18 . 2009-06-26 21:18 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-26 21:18 . 2009-06-26 21:18 72704 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-06-26 21:18 . 2009-06-26 21:18 640360 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-26 21:18 . 2009-06-26 21:18 561016 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-26 21:18 . 2009-06-26 21:18 565096 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-26 21:18 . 2009-06-26 21:18 2349384 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-26 21:18 . 2009-06-26 21:18 627536 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-26 21:18 . 2009-06-26 21:18 518488 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-26 21:18 . 2009-06-26 21:18 1003344 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-26 21:16 . 2009-06-26 21:16 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-26 21:16 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-26 21:16 . 2009-06-26 21:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-03 21:17 . 2009-06-03 21:17 ——– d-sh–w- c:\windows\ftpcache
2009-06-03 20:13 . 2007-12-16 19:00 143872 —-a-w- c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
2009-06-03 20:13 . 2007-01-10 19:02 113664 —-a-w- c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
2009-06-03 20:13 . 2009-06-03 20:13 ——– d—–w- c:\documents and settings\All Users\Application Data\EPSON
2009-06-03 20:12 . 2007-12-06 17:08 86528 —-a-w- c:\windows\system32\E_FLBEDA.DLL
2009-06-03 20:12 . 2007-12-06 17:01 78848 —-a-w- c:\windows\system32\E_FD4BEDA.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 18:46 . 2007-07-09 20:08 ——– d—–w- c:\documents and settings\Doug\Application Data\AdobeUM
2009-06-30 00:23 . 2004-12-13 02:31 ——– d—–w- c:\program files\Java
2009-06-29 23:50 . 2004-12-13 03:05 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-29 23:38 . 2007-11-26 22:28 ——– d—–w- c:\documents and settings\Doug\Application Data\StumbleUpon
2009-06-29 22:37 . 2009-04-07 03:06 ——– d—–w- c:\documents and settings\Doug\Application Data\U3
2009-06-29 06:01 . 2009-04-24 01:23 ——– d—–w- c:\program files\e
2009-06-28 21:41 . 2004-12-13 03:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-26 21:16 . 2007-02-06 21:00 ——– d—–w- c:\program files\Lavasoft
2009-06-15 03:18 . 2009-05-24 19:40 ——– d—–w- c:\program files\TweetDeck
2009-05-26 05:16 . 2007-10-01 21:06 ——– d—–w- c:\program files\REALHOUND IP Client
2009-05-24 19:40 . 2009-05-24 19:40 ——– d—–w- c:\documents and settings\Doug\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
2009-05-22 16:35 . 2009-05-22 16:34 ——– d—–w- c:\program files\Flash
2009-05-22 16:34 . 2009-05-16 04:40 ——– d—–w- c:\program files\Charles
2009-05-22 16:34 . 2004-12-13 02:23 ——– d—–w- c:\program files\Google
2009-05-22 16:23 . 2007-02-02 18:51 ——– d—–w- c:\program files\Palm
2009-05-22 16:21 . 2009-01-05 23:29 ——– d—–w- c:\program files\ASREB Exam Guide
2009-05-22 16:17 . 2009-04-28 05:09 ——– d—–w- c:\program files\FileZilla FTP Client
2009-05-22 16:16 . 2009-04-28 19:14 ——– d—–w- c:\program files\xampp
2009-05-18 22:31 . 2009-04-28 05:09 ——– d—–w- c:\documents and settings\Doug\Application Data\FileZilla
2009-05-18 17:48 . 2009-05-18 17:48 ——– d—–w- c:\program files\MetaStream
2009-05-18 17:48 . 2009-05-18 17:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-15 16:59 . 2009-05-15 16:58 161555 —-a-w- c:\program files\uar_v1.8.zip
2009-05-11 03:03 . 2009-05-11 03:03 ——– d—–w- c:\documents and settings\Doug\Application Data\Malwarebytes
2009-05-11 03:03 . 2009-05-11 03:03 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-11 03:03 . 2009-05-11 03:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-06 22:32 . 2009-05-11 03:03 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 22:32 . 2009-05-11 03:03 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2007-02-06 01:10 . 2007-07-05 22:54 5866597 -c–a-w- c:\program files\WIRELESS_V10.5.2.0_WIN_DRIVERS.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-05 68856]
"Google Update"="c:\documents and settings\Doug\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-21 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-10-02 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-10-02 118784]
"PRONoMgr.exe"="c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-10 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-23 94208]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-26 518488]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-30 148888]
c:\documents and settings\Douglas Lazovick\Start Menu\Programs\Startup\
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-3-16 471040]
c:\documents and settings\Doug\Start Menu\Programs\Startup\
Realhound IP Tune and Lube.LNK - c:\program files\REALHOUND IP Client\realhoundiptuneandlube.exe [2007-4-10 339168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2003-12-16 23:49 110592 —-a-w- c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Atheros Client Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Atheros Client Utility.lnk
backup=c:\windows\pss\Atheros Client Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\ACT\\ActUpdt.exe"=
"c:\\Program Files\\Imagistics\\Desktop Document Manager\\FTPServer.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\xampp\\apache\\bin\\httpd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/26/2009 2:19 PM 64160]
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [11/18/2005 3:06 PM 58464]
R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [7/25/2007 12:11 PM 86552]
R2 Apache2.2;Apache2.2;c:\program files\xampp\apache\bin\httpd.exe [4/28/2009 12:17 PM 24636]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [12/10/2004 11:03 PM 25856]
S3 DXE201;Dynex DX-E201 CardBus PC Card;c:\windows\system32\drivers\DXE201.SYS [11/29/2006 11:07 AM 25434]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 1003344]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [7/25/2007 12:10 PM 24876]
— Other Services/Drivers In Memory —
*NewlyCreated* - ENTDRV51
.
Contents of the 'Scheduled Tasks' folder
2009-06-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 21:18]
2009-06-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1158957802-388294154-4222836878-1142Core.job
- c:\documents and settings\Doug\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-21 18:43]
2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1158957802-388294154-4222836878-1142UA.job
- c:\documents and settings\Doug\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-21 18:43]
2009-06-30 c:\windows\Tasks\User_Feed_Synchronization-{B8AAE3F7-D675-4A6D-AE2B-781C86D6FD92}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PRISMSVR.EXE - c:\windows\system32\PRISMSVR.EXE
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 192.168.1.*;127.0.0.*;192.168.0.*;172.16.2.*;172.16.1.*;169.254.32.*;192.168.250
.*
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
TCP: {472AD054-8044-45C4-933D-D87A02DFE99C} = 192.168.1.100,4.2.2.2
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Doug\Application Data\Mozilla\Firefox\Profiles\509283gz.default\
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJPI150.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.
.
——- File Associations ——-
.
txtfile="c:\program files\e\e.exe" "%1"
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-01 12:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1040)
c:\windows\system32\LgNotify.dll
- - - - - - - > 'lsass.exe'(1096)
c:\windows\system32\EntApi.dll
.
Completion time: 2009-07-01 12:36
ComboFix-quarantined-files.txt 2009-07-01 19:35
Pre-Run: 49,179,492,352 bytes free
Post-Run: 49,926,627,328 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
223
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:09:50 PM, on 7/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\xampp\apache\bin\httpd.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\SYSTEM32\DWRCS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\xampp\mysql\bin\mysqld.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\xampp\apache\bin\httpd.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\SYSTEM32\DWRCST.exe
C:\WINDOWS\system32\zshp2600.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Doug\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\zshp2600.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\system32\zshp2600.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Doug\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Doug\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Doug\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.1.*;127.0.0.*;192.168.0.*;172.16.2.*;172.16.1.*;169.254.32.*;192.168.250
.*
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
O1 - Hosts: 94.232.248.66 antivguardian.com
O1 - Hosts: 94.232.248.66 www.antivguardian.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Doug\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Realhound IP Tune and Lube.LNK = C:\Program Files\REALHOUND IP Client\realhoundiptuneandlube.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) -
http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1238522078438
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1238522014255
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = iccre.local
O17 - HKLM\Software\..\Telephony: DomainName = iccre.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{472AD054-8044-45C4-933D-D87A02DFE99C}: NameServer = 192.168.1.100,4.2.2.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = svn-nb.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = iccre.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = iccre.local
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apache2.2 - Apache Software Foundation - C:\Program Files\xampp\apache\bin\httpd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: MySQL - Unknown owner - C:\Program Files\xampp\mysql\bin\mysqld.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
–
End of file - 9447 bytes