This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Troj/MsvcrtHk-B and more

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am running Sophos and Sophos has shown several malware infections most of which have been cleaned up according to the Quarantine options

However, I am having several other symptoms.

Can't boot in safe mood. Get BSOD
Periodic hard locks
recurring malware infections in Sophos
Something wrong with JAVA won't run in trend micro housecall
The above trojan is reported by Sophos in memory. I have followed Sophos trojan removal instructions, but can't get to safe mode. Also, have not downloaded SAv32cli on another computer

I have tried Malware bytes which Also found and removed some malware

I have followed your pre post instructions

Baseline

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:09 AM, on 8/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hometab.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://help.bellsouth.net/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157589360759
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://webaccess.goodwillsavannahga.org/msrdp.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
O18 - Filter hijack: text/html - {c97ba41c-f80e-4055-a51e-70daf2e521c5} - C:\WINDOWS\mark_32.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Update Service (gupdate1c9b3e9dfcb5276) (gupdate1c9b3e9dfcb5276) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
Hello.

We are going to start with DDS, then followed by GMER.

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Download and Run Scan with GMER

We will use GMER to scan for rootkits. This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop. Unzip/extract the file to its own folder. (Click here for information on how to do this if not sure. Win 2000 users click here.

  • Close any and all open programs, as this process may crash your computer.
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • When you have done this, close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.
  • Double-click on Gmer.exe to start the program. Right-click and select Run As Administrator… if you are using Vista
  • Allow the gmer.sys driver to load if asked.
    If it detects rootkit activity, you will receive a prompt (refer below) to run a full scan. Click NO..
    [external image: Posted Image]

  • In the right panel, you will see several boxes that have been checked. Please UNCHECK the following:
    • Sections
    • IAT/EAT
    • Registry
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show all (Don't miss this one!)
  • Click on [external image: Posted Image] and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push [external image: Posted Image] and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.

If GMER doesn't work in Normal Mode try running it in Safe Mode

Note: Do Not run any program while GMER is running
*Note*: Rootkit scans often produce false positives. Do NOT take any actions on "<— ROOKIT" entries

Post back with both logs in your next reply. You may attach the GMER log, if it's too large to post into one reply.

Thanks.

With Regards,
Extremeboy
I anticipated the DDS and did that in advance. DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 7:47:22.28 on Sun 08/16/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.39 [GMT -4:00] AV: Sophos Anti-Virus *On-access scanning enabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD} AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\Explorer.EXE svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\Program Files\Sophos\AutoUpdate\ALsvc.exe svchost.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\stsystra.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Sophos\AutoUpdate\ALMon.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\Bill & Kathy\Local Settings\Temporary Internet Files\Content.IE5\VOHW417H\dds[1].pif ============== Pseudo HJT Report =============== uStart Page = hxxp://hometab.bellsouth.net/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [HelpCenter4.1] c:\program files\bellsouth\helpcenter40b\bin\sprtcmd.exe /P HelpCenter4.1 mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoup~1.lnk - c:\program files\sophos\autoupdate\ALMon.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsons~1.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: musicmatch.com\online DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://help.bellsouth.net/sdccommon/download/tgctlcm.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1157589360759 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} - hxxp://webaccess.goodwillsavannahga.org/msrdp.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/popcaploader_v10.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab Filter: text/html - {c97ba41c-f80e-4055-a51e-70daf2e521c5} - c:\windows\mark_32.dll AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== S1 9f9a7c46.sys;9f9a7c46.sys;\??\c:\windows\system32\drivers\9f9a7c46.sys –> c:\windows\system32\drivers\9f9a7c46.sys [?] =============== Created Last 30 ================ 2009-08-15 00:14 157,712 a——- c:\windows\system32\drivers\tmcomm.sys 2009-08-15 00:03 73,728 a——- c:\windows\system32\javacpl.cpl 2009-08-14 21:08 –d—– C:\SDFix 2009-08-14 20:04 –d—– C:\SAV32CLI 2009-08-14 19:43 –d—– c:\program files\Trend Micro 2009-08-13 20:23 –d—– c:\docume~1\bill&k~1\applic~1\Malwarebytes 2009-08-13 20:23 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-13 20:23 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-13 20:23 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-13 20:23 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-13 20:04 45,344 a——- c:\windows\system32\drivers\krjbecd.sys 2009-08-12 19:16 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx 2009-08-12 19:16 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll 2009-08-07 22:11 54,156 a—h— c:\windows\QTFont.qfn 2009-08-07 22:11 1,409 a——- c:\windows\QTFont.for 2009-08-06 20:10 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat 2009-08-06 03:05 –d—– c:\windows\system32\XPSViewer 2009-08-06 03:04 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-06 03:04 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll 2009-08-06 03:04 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-06 03:04 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-06 03:04 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-06 03:04 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-06 03:04 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-06 03:04 –d—– C:\2aa286fd5e5fe8c08b1513 2009-08-06 03:04 –d—– c:\windows\SxsCaPendDel 2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll ==================== Find3M ==================== 2009-08-15 00:03 411,368 a——- c:\windows\system32\deploytk.dll 2009-08-11 17:20 3,350 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-05 05:01 204,800 a——- c:\windows\system32\dllcache\mswebdvd.dll 2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll 2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll 2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll 2009-07-10 08:31 130,104 a——- c:\windows\system32\sdccoinstaller.dll 2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-29 04:35 634,632 a——- c:\windows\system32\dllcache\iexplore.exe 2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat 2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-25 04:25 730,112 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-25 04:25 301,568 ——– c:\windows\system32\dllcache\kerberos.dll 2009-06-25 04:25 147,456 ——– c:\windows\system32\dllcache\schannel.dll 2009-06-25 04:25 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-06-25 04:25 56,832 ——– c:\windows\system32\dllcache\secur32.dll 2009-06-25 04:25 54,272 ——– c:\windows\system32\dllcache\wdigest.dll 2009-06-24 07:18 92,928 a——- c:\windows\system32\drivers\ksecdd.sys 2009-06-24 07:18 92,928 ——– c:\windows\system32\dllcache\ksecdd.sys 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\dllcache\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\dllcache\fontsub.dll 2009-06-12 08:31 80,896 a——- c:\windows\system32\tlntsess.exe 2009-06-12 08:31 80,896 a——- c:\windows\system32\dllcache\tlntsess.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\dllcache\telnet.exe 2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 10:13 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\dllcache\mstscax.dll 2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-10 02:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-30 14:04 15,688 a——- c:\windows\system32\lsdelete.exe 2008-11-24 08:30 69,328 ac—— c:\docume~1\bill&k~1\applic~1\GDIPFONTCACHEV1.DAT 2007-08-30 19:22 10,385,200 ac—— c:\documents and settings\bill & kathy\HC41SInstaller.exe 2007-06-09 13:54 251 ac—— c:\program files\wt3d.ini 2004-10-19 16:38 11,052,037 ac—— c:\docume~1\bill&k~1\applic~1\HCSetup2.0_IW.5.1.exe 2008-09-05 18:45 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090520080906\index.dat ============= FINISH: 7:48:42.71 ===============
here is the output from Gmer

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2009-08-17 19:17:44
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.12 —-

SSDT \SystemRoot\system32\DRIVERS\savonaccesscontrol.sys ZwCreateKey
SSDT \SystemRoot\system32\DRIVERS\savonaccesscontrol.sys ZwDeleteKey
SSDT 86F3A4A0 ZwDeviceIoControlFile
SSDT \SystemRoot\system32\DRIVERS\savonaccesscontrol.sys ZwSetValueKey

—- Devices - GMER 1.0.12 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 86F35AD0
Device \FileSystem\Mup \Dfs IRP_MJ_CREATE 86F35AD0
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_READ 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_WRITE 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_POWER 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA 86F38740
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA 86F38740
Device \FileSystem\RAW \Device\RawTape IRP_MJ_CREATE 86F35AD0
Device \FileSystem\Lbd \Device\Lbd IRP_MJ_CREATE 86F35AD0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_READ 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_POWER 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA 86F38740
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA 86F38740
Device \Driver\prodrv06 \Device\ProDrv06 IRP_MJ_CREATE E1E0A8A0
Device \Driver\prodrv06 \Device\ProDrv06 IRP_MJ_CLOSE E1E0A8A0
Device \Driver\prodrv06 \Device\ProDrv06 IRP_MJ_DEVICE_CONTROL E1E0A8A0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL [F79DA661] prosync1.sys
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL [F79DA661] prosync1.sys
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL [F79DA661] prosync1.sys
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL [F79DA661] prosync1.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_INTERNAL_DEVICE_CONTROL [F79DA661] prosync1.sys
Device \Driver\prohlp02 \Device\ProHlp02 IRP_MJ_CREATE E1011580
Device \Driver\prohlp02 \Device\ProHlp02 IRP_MJ_CLOSE E1011580
Device \Driver\prohlp02 \Device\ProHlp02 IRP_MJ_DEVICE_CONTROL E1011580
Device \FileSystem\Mup \Device\Mup IRP_MJ_CREATE 86F35AD0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_READ 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_WRITE 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_POWER 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA 86F38740
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_READ 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_POWER 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA 86F38740
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA 86F38740
Device \FileSystem\RAW \Device\RawDisk IRP_MJ_CREATE 86F35AD0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_NAMED_PIPE 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_READ 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_WRITE 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_INFORMATION 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_INFORMATION 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_EA 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_EA 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FLUSH_BUFFERS 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_VOLUME_INFORMATION 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DIRECTORY_CONTROL 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FILE_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_LOCK_CONTROL 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_SECURITY 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_SECURITY 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_POWER 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SYSTEM_CONTROL 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CHANGE 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_QUOTA 86F38740
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_QUOTA 86F38740
Device \FileSystem\RAW \Device\RawCdRom IRP_MJ_CREATE 86F35AD0
Device \FileSystem\Mup \Device\WinDfs\Root IRP_MJ_CREATE 86F35AD0
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [EC1F0912] DLAIFS_M.SYS

—- Threads - GMER 1.0.12 —-

Thread 1468:1528 00FF0000

—- Files - GMER 1.0.12 —-

ADS C:\Documents and Settings\All Users\Application Data\TEMP:40088782
ADS C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@casalemedia[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@casalemedia[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@collective-media[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@decdna[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@dell[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@did-it[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@doubleclick[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@facebook[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@feedpoint[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@foxsports[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@gamblerspalace[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@geekstogo[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@geocities[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@google[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@hitbox[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][3].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@intellitxt[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@kontera[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@linkedin[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@live365[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@live[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@local[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@malwarebytes[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@mediaplex[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@microsoftmachinetranslation.112.2o7[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@microsoftoffice.112.2o7[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@microsofttranslator[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@microsoft[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@msnportal.112.2o7[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@msn[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@netflix[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@netmng[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@overture[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@pcperformanceclinic[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@pctools[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@priceline[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@pro-market[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@quantserve[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@recaptcha[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@regcure[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@revsci[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@rfihub[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@savannahnow[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@scorecardresearch[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][3].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@sharethis[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@sophos[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@speakeasy[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@specificclick[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@specificmedia[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@sun[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@techspot[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@teracent[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@teracent[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@threatexpert[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@tomshardware[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@topix[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@trafficmp[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@trendmicro[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@trialpay[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@tribalfusion[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@tvguide[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@virscan[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@vs[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@whatthetech[2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][3].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][4].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][2].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@xiti[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@yahoo[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@youtube[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&_kathy@zedo[1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\bill_&[removed][1].txt
File C:\Documents and Settings\Bill & Kathy\Cookies\desktop.ini
File C:\Documents and Settings\Bill & Kathy\Cookies\index.dat
ADS C:\Documents and Settings\Bill & Kathy\Favorites\.Jamie Howell Photography..url:favicon
ADS C:\Documents and Settings\Bill & Kathy\Favorites\Acoustic Guitar For Every Player in any style.url:favicon
ADS C:\Documents and Settings\Bill & Kathy\Favorites\Asbury Memorial United Methodist Church, Savannah Georgia.url:favicon
ADS C:\Documents and Settings\Bill & Kathy\Favorites\Baptism of Lauren at church.url:favicon
ADS C:\Documents and Settings\Bill & Kathy\Favorites\Cayman Islands Caribbean Condo Vacations at Discovery Point Club on Seven Mile Beach.url:favicon
ADS C:\Documents and Settings\Bill & Kathy\Favorites\eG Forums - Knife Maintenance and Sharpening.url:favicon
ADS C:\Documents and Settings\Bill & Kathy\Favorites\Free Crosswords - Free Online Crosswords - Free Printable Crosswords.url:favicon
ADS C:\Documents and Settings\Bill & Kathy\Favorites\http–www.asburymemorial.org-data-menslist.txt.url:favicon
ADS C:\Documents and Settings\Bill & Kathy\Favorites\Lodging - Hickory Knob State Resort Park - South Carolina Parks.url:favicon
ADS …

—- EOF - GMER 1.0.12 —-
Hello. That version of GMER you ran is outdated. Please delete the GMER file you currently have. Re-download it and follow the instructions I gave you in my previous post on running it. Post the log once it's done. Please also, provide me with an update of the condition of your machine. With Regards, Extremeboy
I used the first alternate Gmer mirror site you listed. I should have guessed it was out of date when the options on the right didn't match your instructions.

I have successfully followed instruction with the first choice site and here are the results.

GMER 1.0.15.15077 [0pqrt3zy.exe] - http://www.gmer.net
Rootkit scan 2009-08-18 18:05:03
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\savonaccesscontrol.sys (SAV On-access and HIPS for Windows XP (x86)/Sophos Plc) ZwCreateKey [0xEE419FA0]
SSDT \SystemRoot\system32\DRIVERS\savonaccesscontrol.sys (SAV On-access and HIPS for Windows XP (x86)/Sophos Plc) ZwDeleteKey [0xEE41A0F6]
SSDT 86F3A4A0 ZwDeviceIoControlFile
SSDT \SystemRoot\system32\DRIVERS\savonaccesscontrol.sys (SAV On-access and HIPS for Windows XP (x86)/Sophos Plc) ZwSetValueKey [0xEE41A15C]

Code 86F397B0 pIofCompleteRequest

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 86F35AD0

AttachedDevice \FileSystem\Ntfs \Ntfs savonaccessfilter.sys (SAV On-access and HIPS for Windows XP (x86)/Sophos Plc)

Device \FileSystem\Mup \Dfs 86F35AD0
Device \Driver\Tcpip \Device\Ip 86F38740
Device \FileSystem\RAW \Device\RawTape 86F35AD0
Device \FileSystem\Lbd \Device\Lbd 86F35AD0
Device \Driver\Tcpip \Device\Tcp 86F38740

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\prodrv06 \Device\ProDrv06 E1DE0008
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\prohlp02 \Device\ProHlp02 E1789860
Device \FileSystem\Mup \Device\Mup 86F35AD0
Device \Driver\Tcpip \Device\Udp 86F38740
Device \Driver\Tcpip \Device\RawIp 86F38740
Device \FileSystem\RAW \Device\RawDisk 86F35AD0
Device \Driver\Tcpip \Device\IPMULTICAST 86F38740
Device \FileSystem\RAW \Device\RawCdRom 86F35AD0
Device \FileSystem\Mup \Device\WinDfs\Root 86F35AD0
Device \FileSystem\Fastfat \Fat BA7A6D20

AttachedDevice \FileSystem\Fastfat \Fat 86F35AD0
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat savonaccessfilter.sys (SAV On-access and HIPS for Windows XP (x86)/Sophos Plc)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- Threads - GMER 1.0.15 —-

Thread explorer.exe [1468:1484] 00BF0000

—- EOF - GMER 1.0.15 —-

I have also attached it to assist with reading.

The machine is doing better. I am not getting any more hits with malware bytes, adaware or Sophos scans. I have not tried to boot safe lately. When I did scan last night with SOPHOS there are a couple of ie5 temp files which are reported as scan errors and when I explore them, they are listed as unreadeable. Also, My outlook express offers to compress files and when it runs it hard locks📎gmeroutput.txt

I did follow instructions given to others for IE settings for safer surfing, although I think all but one of my settings were as recommended
Hello.

Please continue with the following:

There were a few malicious drive names/files that I see in the DDS logs and some suspicious lines in GMER.

Download and Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

Download Combofix from any of the links below, and save it to your desktop.
Link 1
Link 2

Please refer to this page for full instructions on how to run ComboFix.

  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click ComboFix.exe to start the program. Agree to the prompts.
  • When ComboFix is finished, a log report (C:\ComboFix.txt) will open. Post back with it.
Leave your computer alone while ComboFix is running.

ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.

~Extremeboy
I ran the combofix, but it hard locked after reboot. It found some things and identified the same temp files as inaccessible. Suggested I run chkdsk. Did not creat logfile. Chkdsk will not run.

Here is a new Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:08 PM, on 8/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hometab.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://help.bellsouth.net/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157589360759
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://webaccess.goodwillsavannahga.org/msrdp.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Update Service (gupdate1c9b3e9dfcb5276) (gupdate1c9b3e9dfcb5276) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PEVSystemStart - Unknown owner - cmd /k start /i "/dC:" "C:\ComboFix\HIDEC.exe" "C:\WINDOWS\system32\CF2495.exe" /c RD /S/Q \$RECYCLE.bin \RECYCLER \RECYCLED (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe

–
End of file - 9394 bytes


Tried safe mode. Same troubles

I get a bsod stop with 0x0000007B
Hello.

Please backup your registry with ERUNT first.

Backup Registry with ERUNT

This tool will create a complete backup of your registry. A backup is created to ensure we have backup so encase anything goes wrong we can deal with it. Do not delete these backups until we are finished.
  • Please download erunt-setup.exe to your desktop.
  • Double click erunt-setup.exe. Follow the prompts and allow ERUNT to be installed with the settings at default. If you do not want a Desktop icon, feel free to uncheck that. When asked if you want to create an ERUNT entry in the startup folder, answer Yes. You can delete the installation file after use.
  • Erunt will open when the installation is finished. Check all items to be backed up in the default location and click OK.
You can find a complete guide to using the program here:
http://www.larshederer.homepage.t-online.de/erunt/erunt.txt
–

Uninstall Combofix.

Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Click on your Start Menu, then Run….
  • Now type combofix /u in the runbox and click OK. Notice the space between the "x" and "/".
    [external image: Posted Image]

This will uninstall Combofix.

Try running Combofix again, this time re-name it before saving it.

Download and Run ComboFix (Rename Before Saving)

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2

[external image: Posted Image]

[external image: Posted Image]

Run it again like last time and see how it goes. Please refer to this page for full instructions on how to run ComboFix.

—

Also, I would like to see RootRepeal rootkit scan for me. Instructions are below:

Download and run RootRepeal CR

Please download RootRepeal from the following location and save it to your desktop.


  • Unzip the RootRepeal.zip file it to it's own folder. (If you did not use the "Direct Download" mirror to download RootRepeal).
  • Close/Disable all other programs especially your security programs (anti-spyware, anti-virus, and firewall) Refer to this page, if you are unsure how.
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Double-click on RootRepeal.exe to run it. If you are using Vista, please right-click and run as Administrator…
  • Click the [external image: Posted Image] tab at the bottom.
  • Now press the [external image: Posted Image] button.
  • A box will pop up, check the boxes beside All Seven options/scan area
    🖼Click to load external image (Posted Image)
  • Now click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button. [external image: Posted Image]
  • Save it as RepealScan and save it to your desktop
  • Reconnect to the internet.
  • Post the contents of that log in your reply please.

With Regards,
Extremeboy
I have completed your instructions. Ran combo-fix twice It did run but locked up on create report both times I am switching to nod32 from Sophos b/c it has performed better for me in the past Here is the repealscan ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/21 19:17 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xED66F000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7A6E000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xEB29B000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "Lbd.sys" at address 0xf753287e #: 066 Function Name: NtDeviceIoControlFile Status: Hooked by "" at address 0x86f204a0 #: 247 Function Name: NtSetValueKey Status: Hooked by "Lbd.sys" at address 0xf7532bfe Stealth Objects ——————- Object: Hidden Module [Name: svchost.exe] Process: svchost.exe (PID: 3560) Address: 0x01000000 Size: 20480 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE] Process: System Address: 0x86f1bad0 Size: 1332 Object: Hidden Code [Driver: sr, IRP_MJ_CREATE] Process: System Address: 0x86f1bad0 Size: 1332 Object: Hidden Code [Driver: FltMgr, IRP_MJ_CREATE] Process: System Address: 0x86f1bad0 Size: 1332 Object: Hidden Code [Driver: Mup, IRP_MJ_CREATE] Process: System Address: 0x86f1bad0 Size: 1332 Object: Hidden Code [Driver: prodrv06Ѕఅ瑎獆␘䲘, IRP_MJ_CREATE] Process: System Address: 0xe1db3c30 Size: 976 Object: Hidden Code [Driver: prodrv06Ѕఅ瑎獆␘䲘, IRP_MJ_CLOSE] Process: System Address: 0xe1db3c30 Size: 976 Object: Hidden Code [Driver: prodrv06Ѕఅ瑎獆␘䲘, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0xe1db3c30 Size: 976 Object: Hidden Code [Driver: prohlp02, IRP_MJ_CREATE] Process: System Address: 0xe1789758 Size: 2216 Object: Hidden Code [Driver: prohlp02, IRP_MJ_CLOSE] Process: System Address: 0xe1789758 Size: 2216 Object: Hidden Code [Driver: prohlp02, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0xe1789758 Size: 2216 Object: Hidden Code [Driver: Tcpip, IRP_MJ_CREATE] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_CLOSE] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_READ] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_WRITE] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_SET_INFORMATION] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_QUERY_EA] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_SET_EA] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_SHUTDOWN] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_CLEANUP] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_SET_SECURITY] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_POWER] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Tcpip, IRP_MJ_SET_QUOTA] Process: System Address: 0x86f1e740 Size: 1715 Object: Hidden Code [Driver: Lbd, IRP_MJ_CREATE] Process: System Address: 0x86f1bad0 Size: 1332 Object: Hidden Code [Driver: RAW, IRP_MJ_CREATE] Process: System Address: 0x86f1bad0 Size: 1332 ==EOF==
Hello.

Please take a new DDS run for my review.

Run a scan with Malwarebytes afterwards.
Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

With Regards,
Extremeboy
DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 17:56:31.54 on Sat 08/22/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.593 [GMT -4:00] AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\stsystra.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Digital Line Detect\DLG.exe svchost.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe svchost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\internet explorer\iexplore.exe C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://hometab.bellsouth.net/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [HelpCenter4.1] c:\program files\bellsouth\helpcenter40b\bin\sprtcmd.exe /P HelpCenter4.1 mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice StartupFolder: c:\docume~1\bill&k~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsons~1.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: musicmatch.com\online DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://help.bellsouth.net/sdccommon/download/tgctlcm.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1157589360759 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} - hxxp://webaccess.goodwillsavannahga.org/msrdp.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-25 64160] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-5-14 94360] R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S0 krjbecd;krjbecd;\SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys –> \SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys [?] S1 9f9a7c46.sys;9f9a7c46.sys;\??\c:\windows\system32\drivers\9f9a7c46.sys –> c:\windows\system32\drivers\9f9a7c46.sys [?] S2 gupdate1c9b3e9dfcb5276;Google Update Service (gupdate1c9b3e9dfcb5276);c:\program files\google\update\GoogleUpdate.exe [2009-4-2 133104] S2 PEVSystemStart;PEVSystemStart;cmd /k start /i "/dC:" "c:\combo-fix\hidec.exe" "c:\windows\system32\cf11318.exe" /c rd /s/q \$recycle.bin \recycler \RECYCLED –> cmd [?] S3 vitra;vitra;c:\windows\system32\drivers\vitra.sys –> c:\windows\system32\drivers\vitra.sys [?] =============== Created Last 30 ================ 2009-08-22 17:37 2,812 a——- C:\dds.zip 2009-08-21 21:29 –d—– c:\docume~1\bill&k~1\applic~1\ESET 2009-08-21 19:21 –ds—- C:\Combo-Fix 2009-08-21 19:21 389,120 a——- c:\windows\system32\CF11318.exe 2009-08-21 18:51 228,864 a——- c:\windows\PEV.exe 2009-08-21 18:51 161,792 a——- c:\windows\SWREG.exe 2009-08-21 18:51 98,816 a——- c:\windows\sed.exe 2009-08-21 18:49 –ds—- C:\ComboFix 2009-08-21 17:53 –dsh— C:\found.000 2009-08-19 18:59 a-dshr– C:\cmdcons 2009-08-18 20:35 –d—– c:\program files\AskBarDis 2009-08-18 20:35 –d—– c:\docume~1\bill&k~1\applic~1\GlarySoft 2009-08-18 20:35 –d—– c:\program files\Glary Registry Repair 2009-08-18 20:11 0 a——- c:\windows\iPlayer.INI 2009-08-17 19:09 250 a——- c:\windows\gmer.ini 2009-08-15 00:03 73,728 a——- c:\windows\system32\javacpl.cpl 2009-08-14 20:04 –d—– C:\SAV32CLI 2009-08-14 19:43 –d—– c:\program files\Trend Micro 2009-08-13 20:23 –d—– c:\docume~1\bill&k~1\applic~1\Malwarebytes 2009-08-13 20:23 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-13 20:23 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-13 20:23 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-13 20:23 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-13 20:04 45,344 a——- c:\windows\system32\drivers\krjbecd.sys 2009-08-12 19:16 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx 2009-08-12 19:16 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll 2009-08-07 22:11 54,156 a—h— c:\windows\QTFont.qfn 2009-08-07 22:11 1,409 a——- c:\windows\QTFont.for 2009-08-06 20:10 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat 2009-08-06 03:05 –d—– c:\windows\system32\XPSViewer 2009-08-06 03:04 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-06 03:04 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll 2009-08-06 03:04 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-06 03:04 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-06 03:04 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-06 03:04 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-06 03:04 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-06 03:04 –d—– C:\2aa286fd5e5fe8c08b1513 2009-08-06 03:04 –d—– c:\windows\SxsCaPendDel ==================== Find3M ==================== 2009-08-15 00:03 411,368 a——- c:\windows\system32\deploytk.dll 2009-08-11 17:20 3,350 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-05 05:01 204,800 a——- c:\windows\system32\dllcache\mswebdvd.dll 2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll 2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll 2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll 2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll 2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-29 04:35 634,632 a——- c:\windows\system32\dllcache\iexplore.exe 2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat 2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-25 04:25 730,112 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-25 04:25 301,568 ——– c:\windows\system32\dllcache\kerberos.dll 2009-06-25 04:25 147,456 ——– c:\windows\system32\dllcache\schannel.dll 2009-06-25 04:25 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-06-25 04:25 56,832 ——– c:\windows\system32\dllcache\secur32.dll 2009-06-25 04:25 54,272 ——– c:\windows\system32\dllcache\wdigest.dll 2009-06-24 07:18 92,928 a——- c:\windows\system32\drivers\ksecdd.sys 2009-06-24 07:18 92,928 ——– c:\windows\system32\dllcache\ksecdd.sys 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\dllcache\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\dllcache\fontsub.dll 2009-06-12 08:31 80,896 a——- c:\windows\system32\tlntsess.exe 2009-06-12 08:31 80,896 a——- c:\windows\system32\dllcache\tlntsess.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\dllcache\telnet.exe 2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 10:13 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\dllcache\mstscax.dll 2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-10 02:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-30 14:04 15,688 a——- c:\windows\system32\lsdelete.exe 2008-11-24 08:30 69,328 ac—— c:\docume~1\bill&k~1\applic~1\GDIPFONTCACHEV1.DAT 2007-08-30 19:22 10,385,200 ac—— c:\documents and settings\bill & kathy\HC41SInstaller.exe 2007-06-09 13:54 251 ac—— c:\program files\wt3d.ini 2004-10-19 16:38 11,052,037 ac—— c:\docume~1\bill&k~1\applic~1\HCSetup2.0_IW.5.1.exe 2008-09-05 18:45 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090520080906\index.dat ============= FINISH: 17:57:00.29 =============== DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 17:59:07.20 on Sat 08/22/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.569 [GMT -4:00] AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\stsystra.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Digital Line Detect\DLG.exe svchost.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe svchost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\internet explorer\iexplore.exe C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://hometab.bellsouth.net/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [HelpCenter4.1] c:\program files\bellsouth\helpcenter40b\bin\sprtcmd.exe /P HelpCenter4.1 mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice StartupFolder: c:\docume~1\bill&k~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsons~1.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: musicmatch.com\online DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://help.bellsouth.net/sdccommon/download/tgctlcm.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1157589360759 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} - hxxp://webaccess.goodwillsavannahga.org/msrdp.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-25 64160] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-5-14 94360] R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S0 krjbecd;krjbecd;\SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys –> \SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys [?] S1 9f9a7c46.sys;9f9a7c46.sys;\??\c:\windows\system32\drivers\9f9a7c46.sys –> c:\windows\system32\drivers\9f9a7c46.sys [?] S2 gupdate1c9b3e9dfcb5276;Google Update Service (gupdate1c9b3e9dfcb5276);c:\program files\google\update\GoogleUpdate.exe [2009-4-2 133104] S2 PEVSystemStart;PEVSystemStart;cmd /k start /i "/dC:" "c:\combo-fix\hidec.exe" "c:\windows\system32\cf11318.exe" /c rd /s/q \$recycle.bin \recycler \RECYCLED –> cmd [?] S3 vitra;vitra;c:\windows\system32\drivers\vitra.sys –> c:\windows\system32\drivers\vitra.sys [?] =============== Created Last 30 ================ 2009-08-22 17:37 2,812 a——- C:\dds.zip 2009-08-21 21:29 –d—– c:\docume~1\bill&k~1\applic~1\ESET 2009-08-21 19:21 –ds—- C:\Combo-Fix 2009-08-21 19:21 389,120 a——- c:\windows\system32\CF11318.exe 2009-08-21 18:51 228,864 a——- c:\windows\PEV.exe 2009-08-21 18:51 161,792 a——- c:\windows\SWREG.exe 2009-08-21 18:51 98,816 a——- c:\windows\sed.exe 2009-08-21 18:49 –ds—- C:\ComboFix 2009-08-21 17:53 –dsh— C:\found.000 2009-08-19 18:59 a-dshr– C:\cmdcons 2009-08-18 20:35 –d—– c:\program files\AskBarDis 2009-08-18 20:35 –d—– c:\docume~1\bill&k~1\applic~1\GlarySoft 2009-08-18 20:35 –d—– c:\program files\Glary Registry Repair 2009-08-18 20:11 0 a——- c:\windows\iPlayer.INI 2009-08-17 19:09 250 a——- c:\windows\gmer.ini 2009-08-15 00:03 73,728 a——- c:\windows\system32\javacpl.cpl 2009-08-14 20:04 –d—– C:\SAV32CLI 2009-08-14 19:43 –d—– c:\program files\Trend Micro 2009-08-13 20:23 –d—– c:\docume~1\bill&k~1\applic~1\Malwarebytes 2009-08-13 20:23 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-13 20:23 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-13 20:23 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-13 20:23 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-13 20:04 45,344 a——- c:\windows\system32\drivers\krjbecd.sys 2009-08-12 19:16 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx 2009-08-12 19:16 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll 2009-08-07 22:11 54,156 a—h— c:\windows\QTFont.qfn 2009-08-07 22:11 1,409 a——- c:\windows\QTFont.for 2009-08-06 20:10 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat 2009-08-06 03:05 –d—– c:\windows\system32\XPSViewer 2009-08-06 03:04 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-06 03:04 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll 2009-08-06 03:04 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-06 03:04 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-06 03:04 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-06 03:04 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-06 03:04 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-06 03:04 –d—– C:\2aa286fd5e5fe8c08b1513 2009-08-06 03:04 –d—– c:\windows\SxsCaPendDel ==================== Find3M ==================== 2009-08-15 00:03 411,368 a——- c:\windows\system32\deploytk.dll 2009-08-11 17:20 3,350 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-05 05:01 204,800 a——- c:\windows\system32\dllcache\mswebdvd.dll 2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll 2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll 2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll 2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll 2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-29 04:35 634,632 a——- c:\windows\system32\dllcache\iexplore.exe 2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat 2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-25 04:25 730,112 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-25 04:25 301,568 ——– c:\windows\system32\dllcache\kerberos.dll 2009-06-25 04:25 147,456 ——– c:\windows\system32\dllcache\schannel.dll 2009-06-25 04:25 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-06-25 04:25 56,832 ——– c:\windows\system32\dllcache\secur32.dll 2009-06-25 04:25 54,272 ——– c:\windows\system32\dllcache\wdigest.dll 2009-06-24 07:18 92,928 a——- c:\windows\system32\drivers\ksecdd.sys 2009-06-24 07:18 92,928 ——– c:\windows\system32\dllcache\ksecdd.sys 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\dllcache\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\dllcache\fontsub.dll 2009-06-12 08:31 80,896 a——- c:\windows\system32\tlntsess.exe 2009-06-12 08:31 80,896 a——- c:\windows\system32\dllcache\tlntsess.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\dllcache\telnet.exe 2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 10:13 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\dllcache\mstscax.dll 2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-10 02:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-30 14:04 15,688 a——- c:\windows\system32\lsdelete.exe 2008-11-24 08:30 69,328 ac—— c:\docume~1\bill&k~1\applic~1\GDIPFONTCACHEV1.DAT 2007-08-30 19:22 10,385,200 ac—— c:\documents and settings\bill & kathy\HC41SInstaller.exe 2007-06-09 13:54 251 ac—— c:\program files\wt3d.ini 2004-10-19 16:38 11,052,037 ac—— c:\docume~1\bill&k~1\applic~1\HCSetup2.0_IW.5.1.exe 2008-09-05 18:45 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090520080906\index.dat ============= FINISH: 17:59:19.93 =============== Here are the requested files. I did play a bejeweled today from MSN and malware bytes found and erased it

Attachments:

alwarebytes' Anti-Malware 1.40 Database version: 2679 Windows 5.1.2600 Service Pack 3 8/22/2009 5:46:43 PM mbam-log-2009-08-22 (17-46-43).txt Scan type: Quick Scan Objects scanned: 102325 Time elapsed: 5 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
Hello.

Sorry, I should have asked the log after running DDS.

Please run OTL and we will fix anything after that. AS there are a few things we can remove.

Download and run OTL

  • Download OTL by OldTimer and save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop. If you are using Vista, please right-click and select run as administrator
  • Click the "Scan All Users" checkbox.
  • Push the [external image: Posted Image] button.
  • It will now begin to scan, please be paitent while it scans.
  • Two reports will open once it's done.
  • Please copy and paste them in your next reply:
  • OTL.txt <– Will be opened
  • Extras.txt <– Will be minimized


Let me know how your comptuer is now? What problem or issues/symptoms do you still have?

~Extremeboy
color=#E56717]========== Driver Services (SafeList) ==========

DRV - [2001/08/17 13:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde [Disabled | Stopped])
DRV - [2008/04/13 14:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp [Disabled | Stopped])
DRV - [2001/08/17 13:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc [Disabled | Stopped])
DRV - [2001/08/17 13:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550 [Disabled | Stopped])
DRV - [2006/08/17 23:57:14 | 00,008,552 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM [Auto | Running])
DRV - [2006/06/07 17:08:58 | 01,580,544 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2001/08/17 13:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde [Disabled | Stopped])
DRV - [2001/08/17 13:52:16 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k [Disabled | Stopped])
DRV - [2005/09/08 05:20:00 | 00,025,628 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS – (DLABOIOM [Auto | Running])
DRV - [2005/08/25 12:16:52 | 00,005,628 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS – (DLACDBHM [System | Running])
DRV - [2005/09/08 05:20:00 | 00,002,496 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLADResN.SYS – (DLADResN [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,086,524 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,014,684 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,006,364 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS – (DLAPoolM [Auto | Running])
DRV - [2005/08/25 12:16:16 | 00,022,684 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DLARTL_N.SYS – (DLARTL_N [System | Running])
DRV - [2005/09/08 05:20:00 | 00,094,332 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,087,036 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M [Auto | Running])
DRV - [2005/09/12 03:30:00 | 00,089,264 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB [Boot | Running])
DRV - [2005/08/12 05:20:00 | 00,040,544 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS – (DRVNDDM [Auto | Running])
DRV - [2006/10/05 16:07:28 | 00,004,736 | —- | M] (Gteko Ltd.) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct [On_Demand | Stopped])
DRV - [2007/02/25 12:10:48 | 00,005,376 | –S- | M] (Gteko Ltd.) – C:\WINDOWS\System32\DRIVERS\dsunidrv.sys – (dsunidrv [Auto | Running])
DRV - [2006/10/31 14:15:16 | 00,165,752 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\e100b325.sys – (E100B [On_Demand | Running])
DRV - [2009/05/14 15:41:10 | 00,114,472 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\eamon.sys – (eamon [Auto | Running])
DRV - [2009/05/14 15:47:14 | 00,107,256 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\ehdrv.sys – (ehdrv [System | Running])
DRV - [2009/05/14 15:49:32 | 00,094,360 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\epfwtdir.sys – (epfwtdir [System | Running])
DRV - [2008/04/13 12:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2003/11/17 21:59:20 | 00,212,224 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2 [On_Demand | Running])
DRV - [2003/11/17 21:56:26 | 01,042,432 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2009/08/13 20:04:41 | 00,045,344 | —- | M] () – C:\WINDOWS\System32\drivers\krjbecd.sys – (krjbecd [Boot | Stopped])
DRV - [2009/04/25 14:02:27 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd [Boot | Running])
DRV - [2003/04/09 18:48:08 | 00,011,043 | —- | M] (Conexant) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2001/08/17 13:57:38 | 00,016,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\MODEMCSA.sys – (MODEMCSA [On_Demand | Running])
DRV - [2001/08/17 13:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x [Disabled | Stopped])
DRV - [2009/01/26 18:13:41 | 00,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50 [On_Demand | Stopped])
DRV - [2009/01/26 18:13:39 | 00,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50 [On_Demand | Stopped])
DRV - [2004/08/03 22:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2004/04/08 04:46:50 | 00,054,272 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prodrv06.sys – (prodrv06 [System | Running])
DRV - [2004/04/08 06:06:08 | 00,070,400 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prohlp02.sys – (prohlp02 [Boot | Running])
DRV - [2003/09/06 08:22:08 | 00,006,944 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prosync1.sys – (prosync1 [Boot | Running])
DRV - [2004/08/10 05:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2005/04/25 02:03:00 | 00,020,640 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2001/08/17 13:52:20 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080 [Disabled | Stopped])
DRV - [2001/08/17 13:52:20 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160 [Disabled | Stopped])
DRV - [2001/08/17 13:52:18 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280 [Disabled | Stopped])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2003/12/01 11:20:52 | 00,004,832 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\sfhlp01.sys – (sfhlp01 [Boot | Running])
DRV - [2008/04/13 14:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp [Disabled | Stopped])
DRV - [2001/08/17 14:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2001/08/17 14:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow [Disabled | Stopped])
DRV - [2005/11/16 15:36:00 | 01,047,816 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\System32\drivers\sthda.sys – (STHDA [On_Demand | Running])
DRV - [2001/08/17 14:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810 [Disabled | Stopped])
DRV - [2001/08/17 14:07:36 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx [Disabled | Stopped])
DRV - [2001/08/17 14:07:40 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi [Disabled | Stopped])
DRV - [2001/08/17 14:07:42 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3 [Disabled | Stopped])
DRV - [2008/04/21 20:25:44 | 00,023,600 | —- | M] (EnTech Taiwan) – C:\WINDOWS\System32\DRIVERS\TVICHW32.SYS – (TVICHW32 [On_Demand | Stopped])
DRV - [2001/08/17 13:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra [Disabled | Stopped])
DRV - [2003/11/17 21:58:02 | 00,680,704 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://hometab.bellsouth.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/07 03:01:09 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/08/15 00:03:21 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird


O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\System32\spool\drivers\w32x86\3\E_SRCV02.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://help.bellsouth.net/sdccommon/download/tgctlcm.cab (Reg Error: Key error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1157589360759 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} http://webaccess.goodwillsavannahga.org/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://plugin.driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/08/24 17:41:01 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bill & Kathy\Desktop\OTL.exe
[2009/08/23 17:16:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\Deployment
[2009/08/22 17:37:27 | 00,002,812 | —- | C] () – C:\dds.zip
[2009/08/22 17:33:42 | 00,359,932 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr
[2009/08/21 22:36:23 | 36,065,792 | —- | C] () – C:\Documents and Settings\Bill & Kathy\My Documents\eav_nt32_enu.msi
[2009/08/21 21:29:11 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\ESET
[2009/08/21 21:28:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2009/08/21 19:21:45 | 00,000,000 | –SD | C] – C:\Combo-Fix
[2009/08/21 19:21:44 | 00,389,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF11318.exe
[2009/08/21 19:16:26 | 00,000,000 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\settings.dat
[2009/08/21 19:15:35 | 00,472,064 | —- | C] ( ) – C:\Documents and Settings\Bill & Kathy\Desktop\RootRepeal.exe
[2009/08/21 18:51:14 | 00,228,864 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/21 18:51:14 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/21 18:51:14 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/21 18:51:14 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/21 18:51:14 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/21 18:51:14 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/21 18:51:13 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/21 18:51:13 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/21 18:51:06 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/21 18:50:17 | 03,181,630 | R— | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\Combo-Fix.exe
[2009/08/21 18:49:24 | 00,000,000 | –SD | C] – C:\ComboFix
[2009/08/21 18:48:06 | 00,000,767 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/21 18:48:00 | 00,000,611 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\NTREGOPT.lnk
[2009/08/21 18:48:00 | 00,000,592 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\ERUNT.lnk
[2009/08/21 18:47:59 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/08/21 18:47:13 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Bill & Kathy\Desktop\erunt-setup.exe
[2009/08/21 17:53:52 | 00,000,000 | -HSD | C] – C:\found.000
[2009/08/19 18:59:46 | 00,000,209 | —- | C] () – C:\Boot.bak
[2009/08/19 18:59:43 | 00,260,272 | —- | C] () – C:\cmldr
[2009/08/19 18:59:42 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/08/19 18:55:16 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/18 20:35:38 | 00,000,000 | —D | C] – C:\Program Files\AskBarDis
[2009/08/18 20:35:35 | 00,000,700 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Registry Repair.lnk
[2009/08/18 20:35:35 | 00,000,232 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Utilities Freeware.url
[2009/08/18 20:35:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\GlarySoft
[2009/08/18 20:35:34 | 00,000,000 | —D | C] – C:\Program Files\Glary Registry Repair
[2009/08/18 20:11:55 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/08/18 18:01:55 | 00,288,768 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\0pqrt3zy.exe
[2009/08/17 19:09:24 | 00,000,250 | —- | C] () – C:\WINDOWS\gmer.ini
[2009/08/17 19:09:23 | 00,573,440 | —- | C] () – C:\WINDOWS\gmer.exe
[2009/08/17 19:09:23 | 00,565,311 | —- | C] () – C:\WINDOWS\gmer.dll
[2009/08/17 19:09:23 | 00,068,961 | —- | C] (GMER) – C:\WINDOWS\System32\drivers\gmer.sys
[2009/08/17 19:09:23 | 00,000,080 | —- | C] () – C:\WINDOWS\gmer_uninstall.cmd
[2009/08/15 08:28:10 | 00,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009/08/15 08:28:10 | 00,000,893 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk
[2009/08/15 08:28:10 | 00,000,493 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2009/08/15 00:11:27 | 00,000,036 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\housecall.guid.cache
[2009/08/15 00:03:35 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/08/15 00:03:35 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/08/15 00:03:35 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/08/15 00:03:35 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/08/14 20:04:08 | 00,000,000 | —D | C] – C:\SAV32CLI
[2009/08/14 19:43:29 | 00,001,734 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\HijackThis.lnk
[2009/08/14 19:43:28 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/08/13 20:23:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\Malwarebytes
[2009/08/13 20:23:19 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/13 20:23:16 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/13 20:23:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/08/13 20:23:14 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/13 20:23:14 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/13 20:04:41 | 00,045,344 | —- | C] () – C:\WINDOWS\System32\drivers\krjbecd.sys
[2009/08/12 19:16:54 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/08/12 19:16:27 | 01,315,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msoe.dll
[2009/08/07 22:11:00 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/08/07 22:11:00 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/08/06 20:10:52 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/08/06 03:05:29 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/08/06 03:05:24 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/08/06 03:05:15 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/08/06 03:04:38 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/08/06 03:04:38 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/08/06 03:04:38 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/08/06 03:04:38 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/08/06 03:04:38 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/08/06 03:04:38 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/08/06 03:04:38 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/08/06 03:04:37 | 00,000,000 | —D | C] – C:\2aa286fd5e5fe8c08b1513
[2009/08/06 03:04:13 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2008/07/24 19:30:41 | 00,000,030 | —- | C] () – C:\WINDOWS\capture.ini
[2008/07/24 19:28:56 | 00,000,579 | —- | C] () – C:\WINDOWS\addrbook.ini
[2008/07/24 19:27:52 | 00,000,102 | —- | C] () – C:\WINDOWS\dvr2.ini
[2007/12/11 20:56:35 | 00,000,917 | —- | C] () – C:\WINDOWS\ARCADE2.INI
[2007/08/11 11:01:31 | 00,000,052 | —- | C] () – C:\WINDOWS\rblky.sys
[2006/10/02 20:47:01 | 00,000,088 | RHS- | C] () – C:\WINDOWS\System32\FB24DE712C.sys
[2006/10/02 20:47:00 | 00,003,350 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/09/04 15:04:18 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/26 12:38:55 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/08/26 12:35:48 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/08/26 12:35:47 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2006/08/18 00:11:31 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/08/17 23:30:58 | 00,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 08:56:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/31 12:11:14 | 00,000,442 | —- | C] () – C:\WINDOWS\System32\dlcfplc.ini
[2005/08/16 04:37:24 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 04:18:43 | 00,000,651 | —- | C] () – C:\WINDOWS\win.ini
[2005/08/16 04:18:41 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2005/08/05 14:01:54 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/08/24 17:42:02 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bill & Kathy\Desktop\OTL.exe
[2009/08/24 16:55:00 | 00,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/08/24 14:03:16 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/24 13:44:10 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/08/24 11:16:49 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/08/24 11:16:18 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/08/24 11:16:18 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/24 11:16:15 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/24 11:16:12 | 10,717,96224 | -HS- | M] () – C:\hiberfil.sys
[2009/08/23 10:55:41 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/22 23:41:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/22 17:37:48 | 00,002,812 | —- | M] () – C:\dds.zip
[2009/08/22 17:33:52 | 00,359,932 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr
[2009/08/21 22:36:35 | 36,065,792 | —- | M] () – C:\Documents and Settings\Bill & Kathy\My Documents\eav_nt32_enu.msi
[2009/08/21 19:25:40 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/08/21 19:21:38 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF11318.exe
[2009/08/21 19:16:26 | 00,000,000 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\settings.dat
[2009/08/21 19:15:38 | 00,472,064 | —- | M] ( ) – C:\Documents and Settings\Bill & Kathy\Desktop\RootRepeal.exe
[2009/08/21 18:50:17 | 03,181,630 | R— | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Combo-Fix.exe
[2009/08/21 18:48:06 | 00,000,767 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/21 18:48:00 | 00,000,611 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\NTREGOPT.lnk
[2009/08/21 18:48:00 | 00,000,592 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\ERUNT.lnk
[2009/08/21 18:47:20 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Bill & Kathy\Desktop\erunt-setup.exe
[2009/08/20 22:17:15 | 00,228,864 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/19 19:19:18 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/08/19 18:59:46 | 00,000,279 | -HS- | M] () – C:\boot.ini
[2009/08/18 20:41:44 | 00,000,232 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Utilities Freeware.url
[2009/08/18 20:35:35 | 00,000,700 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Registry Repair.lnk
[2009/08/18 20:28:52 | 00,001,475 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Windows Explorer.lnk
[2009/08/18 20:11:55 | 00,000,000 | —- | M] () – C:\WINDOWS\iPlayer.INI
[2009/08/18 18:01:55 | 00,288,768 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\0pqrt3zy.exe
[2009/08/17 19:12:04 | 00,000,250 | —- | M] () – C:\WINDOWS\gmer.ini
[2009/08/17 19:09:23 | 00,565,311 | —- | M] () – C:\WINDOWS\gmer.dll
[2009/08/17 19:09:23 | 00,068,961 | —- | M] (GMER) – C:\WINDOWS\System32\drivers\gmer.sys
[2009/08/17 19:09:23 | 00,000,080 | —- | M] () – C:\WINDOWS\gmer_uninstall.cmd
[2009/08/17 19:06:36 | 00,573,440 | —- | M] () – C:\WINDOWS\gmer.exe
[2009/08/15 08:28:01 | 00,000,651 | —- | M] () – C:\WINDOWS\win.ini
[2009/08/15 08:28:01 | 00,000,209 | —- | M] () – C:\Boot.bak
[2009/08/15 00:11:27 | 00,000,036 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\housecall.guid.cache
[2009/08/15 00:03:21 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/08/15 00:03:21 | 00,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/08/15 00:03:21 | 00,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/08/15 00:03:21 | 00,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/08/15 00:03:21 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/08/14 22:23:46 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/14 19:43:29 | 00,001,734 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\HijackThis.lnk
[2009/08/13 20:04:41 | 00,045,344 | —- | M] () – C:\WINDOWS\System32\drivers\krjbecd.sys
[2009/08/11 17:20:37 | 00,003,350 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/08/11 17:20:33 | 00,000,088 | RHS- | M] () – C:\WINDOWS\System32\FB24DE712C.sys
[2009/08/11 17:19:58 | 00,069,328 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/08 12:56:06 | 00,011,776 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/07 22:11:00 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/08/06 03:17:11 | 00,266,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/06 03:09:26 | 00,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/08/06 03:09:26 | 00,442,466 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/08/06 03:09:26 | 00,071,732 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mswebdvd.dll
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/29 17:49:16 | 24,281,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/07/27 18:27:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Bill & Kathy\My Documents\dds.txt.txt:SummaryInformation
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:40088782
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
< End of report >
OTL Extras logfile created on: 8/24/2009 5:42:10 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Bill & Kathy\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 626.93 Mb Available Physical Memory | 61.34% Memory free
2.40 Gb Paging File | 2.12 Gb Available in Paging File | 88.40% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 54.67 Gb Free Space | 78.34% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OAKLEY
Current User Name: Bill & Kathy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:\Program Files\Vsk3Demo\Vsk3Demo.exe" = C:\Program Files\Vsk3Demo\Vsk3Demo.exe:*:Enabled:Vsk3Demo – File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\networkdvr\remote.exe" = C:\networkdvr\remote.exe:*:Enabled:remote – ()
"C:\Program Files\Enlight\Virtual Skipper 3\Vsk3.exe" = C:\Program Files\Enlight\Virtual Skipper 3\Vsk3.exe:*:Disabled:Vsk3 – ()
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{162D2FB8-60A3-4871-B6A1-5C744CD34FF5}" = 725plc32
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 15
"{2EEBAC31-3EEF-4118-91CB-1A286A507DB2}" = ESET NOD32 Antivirus
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{7D3A6B8F-45C1-4814-967E-6D84BBB868CD}" = ATI Catalyst Control Center
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist
"{E0D51394-1D45-460A-B62D-383BC4F8B335}" = QuickTime
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"651956B7-1969-42AA-9453-E0B813019D54" = Polar Golfer
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"All ATI Software" = ATI - Software Uninstall Utility
"Ask Toolbar_is1" = Ask Toolbar
"ATI Display Driver" = ATI Display Driver
"ATT-PRT22" = ATT-PRT22
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"BellsouthHelpCenter4.0b_is1" = FastAccess® DSL Help Center 4.1
"C2D8F0E2-6978-4409-8351-BA8785DA11EE" = FATE
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Game Console" = Dell Game Console
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"EPSON Printer and Utilities" = EPSON Printer Software
"ERUNT_is1" = ERUNT 1.1j
"ESPNMotion" = ESPNMotion
"Glary Registry Repair_is1" = Glary Registry Repair 3.2.0.828
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PartyPoker" = PartyPoker
"Photodex Presenter" = Photodex Presenter
"PingPlotter" = PingPlotter
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer Basic
"Return of Arcade 2.0" = Return of Arcade Anniversary Edition
"Sibelius Scorch Plugin" = Sibelius Scorch Plugin
"Solero Music Viewer_is1" = Solero Music Viewer 8.0.25.332
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TibetSystem - Uninstall Seemore DVR Client" = Uninstall Seemore DVR Client
"ViewpointMediaPlayer" = Viewpoint Media Player
"Virtual Skipper 3_is1" = Virtual Skipper 3
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/6/2009 3:16:21 AM | Computer Name = OAKLEY | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: C:\Program Files\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe
. Error code = 0x80131047

Error - 8/6/2009 4:23:35 AM | Computer Name = OAKLEY | Source = Media Center Phone Service | ID = 8
Description = Initializing the telephony service failed with error 0x80040005.

Error - 8/12/2009 8:17:43 PM | Computer Name = OAKLEY | Source = Media Center Phone Service | ID = 8
Description = Initializing the telephony service failed with error 0x80040005.

Error - 8/13/2009 4:17:44 AM | Computer Name = OAKLEY | Source = Media Center Phone Service | ID = 8
Description = Initializing the telephony service failed with error 0x80040005.

Error - 8/13/2009 8:15:32 PM | Computer Name = OAKLEY | Source = Sophos Anti-Virus | ID = 131078
Description =

Error - 8/13/2009 8:15:32 PM | Computer Name = OAKLEY | Source = Sophos Anti-Virus | ID = 131078
Description =

Error - 8/13/2009 9:22:06 PM | Computer Name = OAKLEY | Source = Sophos Anti-Virus | ID = 131078
Description =

Error - 8/13/2009 9:22:07 PM | Computer Name = OAKLEY | Source = Sophos Anti-Virus | ID = 131078
Description =

Error - 8/13/2009 10:29:11 PM | Computer Name = OAKLEY | Source = Media Center Phone Service | ID = 8
Description = Initializing the telephony service failed with error 0x80040005.

Error - 8/14/2009 1:00:37 PM | Computer Name = OAKLEY | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16876, faulting
module urlmon.dll, version 7.0.6000.16876, fault address 0x0009fb4c.

[ System Events ]
Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058

Error - 8/19/2009 7:01:36 PM | Computer Name = OAKLEY | Source = Service Control Manager | ID = 7001
Description = The Remote Access Connection Manager service depends on the Telephony
service which failed to start because of the following error: %%1058


< End of report >

The computer scans clean on everything I have tried. I also ran the Microsoft scanning tool on full scan.

I did play a popcap game from Msn.com before the scan yesterday and it was picked up and eliminated by Malware Bytes.

I still have the safe boot issue and I am getting 2 different BSOD's intermittently 0x000000D1 and 0x00000050

Otherwise, it seems to work OK, but those screens are annoying

Bill

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI