This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Troj/MsvcrtHk-B and more

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello.

Sorry for the delay. I thought I replied back already.

The OTL doesn't look complete.

Combofix was updated recently, referring to this page see if you can get Combofix to run. If not, that's okay, let me know.

Please post back wtih the OTL log once it's done. Also, please give me an update of the current condition your machine? In your first post you said you can't boot into safe mode etc… what's the condition right now?

With Regards,
Extremeboy
combofix did run fully, unfortunately, I closed the logfile without saving. Here is a created text file, combofix.txt. Hope it helps.

OTL would not run fully but did create this file.

I responded to your question in my last post. Still multiple BSOD's, Java problems not much in virus detection but the system seems more unstable.

Combofix found and deleted catchme.dll in two places.

OTL logfile created on: 8/28/2009 12:31:32 PM - Run 3
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Bill & Kathy\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 568.86 Mb Available Physical Memory | 55.66% Memory free
2.40 Gb Paging File | 2.10 Gb Available in Paging File | 87.22% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 54.23 Gb Free Space | 77.70% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OAKLEY
Current User Name: Bill & Kathy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2006/06/07 17:03:20 | 00,409,600 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2005/03/22 17:20:44 | 00,339,968 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe
PRC - [2005/06/10 10:44:02 | 00,081,920 | —- | M] (InstallShield Software Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2007/06/28 19:02:08 | 00,198,184 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
PRC - [2005/09/29 14:01:14 | 00,067,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\ehtray.exe
PRC - [2006/05/03 03:12:00 | 00,098,304 | —- | M] () – C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2005/09/08 05:20:00 | 00,122,940 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLACTRLW.EXE
PRC - [2006/01/02 17:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2009/05/14 15:47:08 | 02,029,640 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2003/10/29 02:06:00 | 00,024,576 | R— | M] (BVRP Software) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe
PRC - [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe
PRC - [2009/05/14 15:47:54 | 00,731,840 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2001/08/09 02:01:00 | 00,090,112 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
PRC - [2009/01/26 18:13:52 | 00,303,104 | —- | M] (Motive Communications, Inc.) – C:\Program Files\Common Files\Motive\McciCMService.exe
PRC - [2005/08/05 13:27:08 | 00,099,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe
PRC - [2008/04/13 20:12:41 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wscntfy.exe
PRC - [2005/08/05 13:56:28 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehmsas.exe
PRC - [2006/01/02 17:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2009/08/24 17:42:02 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bill & Kathy\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2006/06/07 17:03:20 | 00,409,600 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2006/07/28 17:47:00 | 00,520,192 | —- | M] () – C:\WINDOWS\System32\ati2sgag.exe – (ATI Smart [Auto | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2007/03/07 15:47:46 | 00,076,848 | —- | M] () – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService [On_Demand | Stopped])
SRV - [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe – (ehRecvr [Auto | Running])
SRV - [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe – (ehSched [Auto | Running])
SRV - [2009/05/14 15:54:22 | 00,020,680 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe – (EhttpSrv [On_Demand | Stopped])
SRV - [2009/05/14 15:47:54 | 00,731,840 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe – (ekrn [Auto | Running])
SRV - [2001/08/09 02:01:00 | 00,090,112 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe – (EPSONStatusAgent2 [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/04/02 19:22:10 | 00,133,104 | —- | M] (Google Inc.) – C:\Program Files\Google\Update\GoogleUpdate.exe – (gupdate1c9b3e9dfcb5276 [Auto | Stopped])
SRV - [2009/04/02 19:20:46 | 00,183,280 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2009/08/15 00:03:21 | 00,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Stopped])
SRV - [2009/07/04 14:03:33 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Stopped])
SRV - [2009/01/26 18:13:52 | 00,303,104 | —- | M] (Motive Communications, Inc.) – C:\Program Files\Common Files\Motive\McciCMService.exe – (McciCMService [Auto | Running])
SRV - [2005/08/05 13:27:08 | 00,099,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe – (McrdSvc [Auto | Running])
SRV - [2003/06/20 03:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe – (MDM [Auto | Stopped])
SRV - [2004/08/10 04:11:50 | 00,085,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mhn.dll – (MHN [On_Demand | Stopped])
SRV - [2004/11/19 11:26:40 | 00,147,456 | —- | M] (Intel® Corporation) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe – (NetSvc [On_Demand | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [Auto | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2001/08/17 13:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde [Disabled | Stopped])
DRV - [2008/04/13 14:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp [Disabled | Stopped])
DRV - [2001/08/17 13:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc [Disabled | Stopped])
DRV - [2001/08/17 13:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550 [Disabled | Stopped])
DRV - [2006/08/17 23:57:14 | 00,008,552 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM [Auto | Running])
DRV - [2006/06/07 17:08:58 | 01,580,544 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - File not found – – (catchme [On_Demand | Running])
DRV - [2001/08/17 13:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde [Disabled | Stopped])
DRV - [2001/08/17 13:52:16 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k [Disabled | Stopped])
DRV - [2005/09/08 05:20:00 | 00,025,628 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS – (DLABOIOM [Auto | Running])
DRV - [2005/08/25 12:16:52 | 00,005,628 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS – (DLACDBHM [System | Running])
DRV - [2005/09/08 05:20:00 | 00,002,496 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLADResN.SYS – (DLADResN [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,086,524 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,014,684 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,006,364 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS – (DLAPoolM [Auto | Running])
DRV - [2005/08/25 12:16:16 | 00,022,684 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DLARTL_N.SYS – (DLARTL_N [System | Running])
DRV - [2005/09/08 05:20:00 | 00,094,332 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,087,036 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M [Auto | Running])
DRV - [2005/09/12 03:30:00 | 00,089,264 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB [Boot | Running])
DRV - [2005/08/12 05:20:00 | 00,040,544 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS – (DRVNDDM [Auto | Running])
DRV - [2006/10/05 16:07:28 | 00,004,736 | —- | M] (Gteko Ltd.) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct [On_Demand | Stopped])
DRV - [2007/02/25 12:10:48 | 00,005,376 | –S- | M] (Gteko Ltd.) – C:\WINDOWS\System32\DRIVERS\dsunidrv.sys – (dsunidrv [Auto | Running])
DRV - [2006/10/31 14:15:16 | 00,165,752 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\e100b325.sys – (E100B [On_Demand | Running])
DRV - [2009/05/14 15:41:10 | 00,114,472 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\eamon.sys – (eamon [Auto | Running])
DRV - [2009/05/14 15:47:14 | 00,107,256 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\ehdrv.sys – (ehdrv [System | Running])
DRV - [2009/05/14 15:49:32 | 00,094,360 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\epfwtdir.sys – (epfwtdir [System | Running])
DRV - [2008/04/13 12:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2003/11/17 21:59:20 | 00,212,224 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2 [On_Demand | Running])
DRV - [2003/11/17 21:56:26 | 01,042,432 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2009/08/13 20:04:41 | 00,045,344 | —- | M] () – C:\WINDOWS\System32\drivers\krjbecd.sys – (krjbecd [Boot | Stopped])
DRV - [2009/04/25 14:02:27 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd [Boot | Running])
DRV - [2003/04/09 18:48:08 | 00,011,043 | —- | M] (Conexant) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2001/08/17 13:57:38 | 00,016,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\MODEMCSA.sys – (MODEMCSA [On_Demand | Running])
DRV - [2001/08/17 13:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x [Disabled | Stopped])
DRV - [2009/01/26 18:13:41 | 00,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50 [On_Demand | Stopped])
DRV - [2009/01/26 18:13:39 | 00,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50 [On_Demand | Stopped])
DRV - [2004/08/03 22:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2004/04/08 04:46:50 | 00,054,272 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prodrv06.sys – (prodrv06 [System | Running])
DRV - [2004/04/08 06:06:08 | 00,070,400 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prohlp02.sys – (prohlp02 [Boot | Running])
DRV - [2003/09/06 08:22:08 | 00,006,944 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prosync1.sys – (prosync1 [Boot | Running])
DRV - [2004/08/10 05:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2005/04/25 02:03:00 | 00,020,640 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2001/08/17 13:52:20 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080 [Disabled | Stopped])
DRV - [2001/08/17 13:52:20 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160 [Disabled | Stopped])
DRV - [2001/08/17 13:52:18 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280 [Disabled | Stopped])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2003/12/01 11:20:52 | 00,004,832 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\sfhlp01.sys – (sfhlp01 [Boot | Running])
DRV - [2008/04/13 14:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp [Disabled | Stopped])
DRV - [2001/08/17 14:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2001/08/17 14:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow [Disabled | Stopped])
DRV - [2005/11/16 15:36:00 | 01,047,816 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\System32\drivers\sthda.sys – (STHDA [On_Demand | Running])
DRV - [2001/08/17 14:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810 [Disabled | Stopped])
DRV - [2001/08/17 14:07:36 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx [Disabled | Stopped])
DRV - [2001/08/17 14:07:40 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi [Disabled | Stopped])
DRV - [2001/08/17 14:07:42 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3 [Disabled | Stopped])
DRV - [2008/04/21 20:25:44 | 00,023,600 | —- | M] (EnTech Taiwan) – C:\WINDOWS\System32\DRIVERS\TVICHW32.SYS – (TVICHW32 [On_Demand | Stopped])
DRV - [2001/08/17 13:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra [Disabled | Stopped])
DRV - [2003/11/17 21:58:02 | 00,680,704 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://hometab.bellsouth.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/07 03:01:09 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/08/15 00:03:21 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird


O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\System32\spool\drivers\w32x86\3\E_SRCV02.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://help.bellsouth.net/sdccommon/download/tgctlcm.cab (Reg Error: Key error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1157589360759 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} http://webaccess.goodwillsavannahga.org/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://plugin.driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/08/28 12:27:30 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/08/28 12:26:31 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\linkinfo.dll
[2009/08/28 12:20:20 | 00,229,376 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/28 12:20:20 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/28 12:20:20 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/28 12:20:20 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/28 12:20:20 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/28 12:20:20 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/28 12:20:20 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/28 12:20:20 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/28 12:20:13 | 00,000,000 | –SD | C] – C:\ComboFix
[2009/08/28 12:20:09 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/28 12:19:26 | 03,187,017 | R— | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\ComboFix.exe
[2009/08/27 21:07:48 | 00,000,000 | –SD | C] – C:\Combo-Fix
[2009/08/27 20:24:18 | 01,614,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/08/27 20:24:18 | 00,574,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntfs.sys
[2009/08/27 20:24:18 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/08/27 20:24:18 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\es.dll
[2009/08/27 20:24:18 | 00,249,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tapisrv.dll
[2009/08/27 20:24:18 | 00,245,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mswsock.dll
[2009/08/27 20:24:18 | 00,198,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netman.dll
[2009/08/27 20:24:18 | 00,192,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\schedsvc.dll
[2009/08/27 20:24:18 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\upnphost.dll
[2009/08/27 20:24:18 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\srsvc.dll
[2009/08/27 20:24:18 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\shsvcs.dll
[2009/08/27 20:24:18 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\xmlprov.dll
[2009/08/27 20:24:18 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/08/27 20:24:18 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\browser.dll
[2009/08/27 20:24:18 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ssdpsrv.dll
[2009/08/27 20:24:18 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\cryptsvc.dll
[2009/08/27 20:24:18 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\regsvc.dll
[2009/08/27 20:24:18 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mspmsnsv.dll
[2009/08/27 20:24:18 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wscntfy.exe
[2009/08/27 20:24:17 | 03,597,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mshtml.dll
[2009/08/27 20:24:17 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/08/27 20:24:17 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/08/27 20:24:17 | 01,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/08/27 20:24:17 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/08/27 20:24:17 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/08/27 20:24:17 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/08/27 20:24:17 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/08/27 20:24:17 | 00,409,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\qmgr.dll
[2009/08/27 20:24:17 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netlogon.dll
[2009/08/27 20:24:17 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/08/27 20:24:17 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/08/27 20:24:17 | 00,182,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/08/27 20:24:17 | 00,181,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\scecli.dll
[2009/08/27 20:24:17 | 00,142,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\aec.sys
[2009/08/27 20:24:17 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/08/27 20:24:17 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/08/27 20:24:17 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/08/27 20:24:17 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\eventlog.dll
[2009/08/27 20:24:17 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/08/27 20:24:17 | 00,036,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/08/27 20:24:17 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/08/27 20:24:17 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/08/27 20:24:17 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/08/27 20:24:17 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/08/27 20:24:17 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/08/27 20:24:17 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/08/27 20:24:17 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\asyncmac.sys
[2009/08/27 20:24:17 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/08/27 20:24:17 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/08/27 20:24:17 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/08/27 20:24:17 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/08/27 20:24:17 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/08/27 20:24:16 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/08/27 20:24:16 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/08/27 20:24:16 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/08/27 20:24:16 | 00,361,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/08/27 20:24:16 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/08/27 20:24:16 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/08/27 20:24:16 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/08/24 17:41:01 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bill & Kathy\Desktop\OTL.exe
[2009/08/23 17:16:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\Deployment
[2009/08/22 17:37:27 | 00,002,812 | —- | C] () – C:\dds.zip
[2009/08/22 17:33:42 | 00,359,932 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr
[2009/08/21 22:36:23 | 36,065,792 | —- | C] () – C:\Documents and Settings\Bill & Kathy\My Documents\eav_nt32_enu.msi
[2009/08/21 21:29:11 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\ESET
[2009/08/21 21:28:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2009/08/21 19:16:26 | 00,000,000 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\settings.dat
[2009/08/21 19:15:35 | 00,472,064 | —- | C] ( ) – C:\Documents and Settings\Bill & Kathy\Desktop\RootRepeal.exe
[2009/08/21 18:48:06 | 00,000,767 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/21 18:48:00 | 00,000,611 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\NTREGOPT.lnk
[2009/08/21 18:48:00 | 00,000,592 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\ERUNT.lnk
[2009/08/21 18:47:59 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/08/21 18:47:13 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Bill & Kathy\Desktop\erunt-setup.exe
[2009/08/21 17:53:52 | 00,000,000 | -HSD | C] – C:\found.000
[2009/08/19 18:59:46 | 00,000,209 | —- | C] () – C:\Boot.bak
[2009/08/19 18:59:43 | 00,260,272 | —- | C] () – C:\cmldr
[2009/08/19 18:59:42 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/08/19 18:55:16 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/18 20:35:38 | 00,000,000 | —D | C] – C:\Program Files\AskBarDis
[2009/08/18 20:35:35 | 00,000,700 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Registry Repair.lnk
[2009/08/18 20:35:35 | 00,000,232 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Utilities Freeware.url
[2009/08/18 20:35:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\GlarySoft
[2009/08/18 20:35:34 | 00,000,000 | —D | C] – C:\Program Files\Glary Registry Repair
[2009/08/18 20:11:55 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/08/18 18:01:55 | 00,288,768 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\0pqrt3zy.exe
[2009/08/17 19:09:24 | 00,000,250 | —- | C] () – C:\WINDOWS\gmer.ini
[2009/08/17 19:09:23 | 00,573,440 | —- | C] () – C:\WINDOWS\gmer.exe
[2009/08/17 19:09:23 | 00,565,311 | —- | C] () – C:\WINDOWS\gmer.dll
[2009/08/17 19:09:23 | 00,068,961 | —- | C] (GMER) – C:\WINDOWS\System32\drivers\gmer.sys
[2009/08/17 19:09:23 | 00,000,080 | —- | C] () – C:\WINDOWS\gmer_uninstall.cmd
[2009/08/15 08:28:10 | 00,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009/08/15 08:28:10 | 00,000,893 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk
[2009/08/15 08:28:10 | 00,000,493 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2009/08/15 00:11:27 | 00,000,036 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\housecall.guid.cache
[2009/08/15 00:03:35 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/08/15 00:03:35 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/08/15 00:03:35 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/08/15 00:03:35 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/08/14 20:04:08 | 00,000,000 | —D | C] – C:\SAV32CLI
[2009/08/14 19:43:29 | 00,001,734 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\HijackThis.lnk
[2009/08/14 19:43:28 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/08/13 20:23:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\Malwarebytes
[2009/08/13 20:23:19 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/13 20:23:16 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/13 20:23:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/08/13 20:23:14 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/13 20:23:14 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/13 20:04:41 | 00,045,344 | —- | C] () – C:\WINDOWS\System32\drivers\krjbecd.sys
[2009/08/12 19:16:54 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/08/12 19:16:27 | 01,315,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msoe.dll
[2009/08/07 22:11:00 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/08/07 22:11:00 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/08/06 20:10:52 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/08/06 03:05:29 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/08/06 03:05:24 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/08/06 03:05:15 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/08/06 03:04:38 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/08/06 03:04:38 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/08/06 03:04:38 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/08/06 03:04:38 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/08/06 03:04:38 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/08/06 03:04:38 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/08/06 03:04:38 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/08/06 03:04:37 | 00,000,000 | —D | C] – C:\2aa286fd5e5fe8c08b1513
[2009/08/06 03:04:13 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2008/07/24 19:30:41 | 00,000,030 | —- | C] () – C:\WINDOWS\capture.ini
[2008/07/24 19:28:56 | 00,000,579 | —- | C] () – C:\WINDOWS\addrbook.ini
[2008/07/24 19:27:52 | 00,000,102 | —- | C] () – C:\WINDOWS\dvr2.ini
[2007/12/11 20:56:35 | 00,000,917 | —- | C] () – C:\WINDOWS\ARCADE2.INI
[2007/08/11 11:01:31 | 00,000,052 | —- | C] () – C:\WINDOWS\rblky.sys
[2006/10/02 20:47:01 | 00,000,088 | RHS- | C] () – C:\WINDOWS\System32\FB24DE712C.sys
[2006/10/02 20:47:00 | 00,003,350 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/09/04 15:04:18 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/26 12:38:55 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/08/26 12:35:48 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/08/26 12:35:47 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2006/08/18 00:11:31 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/08/17 23:30:58 | 00,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 08:56:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/31 12:11:14 | 00,000,442 | —- | C] () – C:\WINDOWS\System32\dlcfplc.ini
[2005/08/16 04:37:24 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 04:18:43 | 00,000,651 | —- | C] () – C:\WINDOWS\win.ini
[2005/08/16 04:18:41 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2005/08/05 14:01:54 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/08/28 12:27:28 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/28 12:26:12 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/08/28 12:19:58 | 03,187,017 | R— | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\ComboFix.exe
[2009/08/28 12:14:18 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/08/28 12:13:56 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/08/28 12:13:35 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/08/28 12:13:32 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/28 12:13:29 | 10,717,96224 | -HS- | M] () – C:\hiberfil.sys
[2009/08/28 11:55:00 | 00,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/08/24 17:42:02 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bill & Kathy\Desktop\OTL.exe
[2009/08/24 14:03:16 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/23 10:55:41 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/23 03:09:13 | 00,229,376 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/22 23:41:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/22 17:37:48 | 00,002,812 | —- | M] () – C:\dds.zip
[2009/08/22 17:33:52 | 00,359,932 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr
[2009/08/21 22:36:35 | 36,065,792 | —- | M] () – C:\Documents and Settings\Bill & Kathy\My Documents\eav_nt32_enu.msi
[2009/08/21 19:16:26 | 00,000,000 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\settings.dat
[2009/08/21 19:15:38 | 00,472,064 | —- | M] ( ) – C:\Documents and Settings\Bill & Kathy\Desktop\RootRepeal.exe
[2009/08/21 18:48:06 | 00,000,767 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/21 18:48:00 | 00,000,611 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\NTREGOPT.lnk
[2009/08/21 18:48:00 | 00,000,592 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\ERUNT.lnk
[2009/08/21 18:47:20 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Bill & Kathy\Desktop\erunt-setup.exe
[2009/08/19 19:19:18 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/08/19 18:59:46 | 00,000,279 | -HS- | M] () – C:\boot.ini
[2009/08/18 20:41:44 | 00,000,232 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Utilities Freeware.url
[2009/08/18 20:35:35 | 00,000,700 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Registry Repair.lnk
[2009/08/18 20:28:52 | 00,001,475 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Windows Explorer.lnk
[2009/08/18 20:11:55 | 00,000,000 | —- | M] () – C:\WINDOWS\iPlayer.INI
[2009/08/18 18:01:55 | 00,288,768 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\0pqrt3zy.exe
[2009/08/17 19:12:04 | 00,000,250 | —- | M] () – C:\WINDOWS\gmer.ini
[2009/08/17 19:09:23 | 00,565,311 | —- | M] () – C:\WINDOWS\gmer.dll
[2009/08/17 19:09:23 | 00,068,961 | —- | M] (GMER) – C:\WINDOWS\System32\drivers\gmer.sys
[2009/08/17 19:09:23 | 00,000,080 | —- | M] () – C:\WINDOWS\gmer_uninstall.cmd
[2009/08/17 19:06:36 | 00,573,440 | —- | M] () – C:\WINDOWS\gmer.exe
[2009/08/15 08:28:01 | 00,000,651 | —- | M] () – C:\WINDOWS\win.ini
[2009/08/15 08:28:01 | 00,000,209 | —- | M] () – C:\Boot.bak
[2009/08/15 00:11:27 | 00,000,036 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\housecall.guid.cache
[2009/08/15 00:03:21 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/08/15 00:03:21 | 00,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/08/15 00:03:21 | 00,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/08/15 00:03:21 | 00,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/08/15 00:03:21 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/08/14 22:23:46 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/14 19:43:29 | 00,001,734 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\HijackThis.lnk
[2009/08/13 20:04:41 | 00,045,344 | —- | M] () – C:\WINDOWS\System32\drivers\krjbecd.sys
[2009/08/11 17:20:37 | 00,003,350 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/08/11 17:20:33 | 00,000,088 | RHS- | M] () – C:\WINDOWS\System32\FB24DE712C.sys
[2009/08/11 17:19:58 | 00,069,328 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/08 12:56:06 | 00,011,776 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/07 22:11:00 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/08/06 03:17:11 | 00,266,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/06 03:09:26 | 00,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/08/06 03:09:26 | 00,442,466 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/08/06 03:09:26 | 00,071,732 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mswebdvd.dll
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/29 17:49:16 | 24,281,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Bill & Kathy\My Documents\dds.txt.txt:SummaryInformation
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:40088782
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
< End of report >
ComboFix 09-08-27.A3 - Bill & Kathy 08/28/2009 12:21.6.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.634 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\BILL&K;~1\LOCALS~1\Temp\catchme.dll
c:\documents and settings\Bill & Kathy\Local Settings\Temp\catchme.dll

.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-28 )))))))))))))))))))))))))))))))
.

2009-08-19 00:35 . 2009-08-21 10:14 ——– d—–w- c:\program files\AskBarDis
2009-08-19 00:35 . 2009-08-19 00:35 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\GlarySoft
2009-08-19 00:35 . 2009-08-19 00:35 ——– d—–w- c:\program files\Glary Registry Repair
2009-08-15 02:24 . 2009-08-15 02:24 3942047 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-15 01:18 . 2009-08-15 03:59 152576 —-a-w- c:\documents and settings\Bill & Kathy\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-15 00:04 . 2009-08-15 00:04 ——– d—–w- C:\SAV32CLI
2009-08-14 23:43 . 2009-08-14 23:43 ——– d—–w- c:\program files\Trend Micro
2009-08-14 00:23 . 2009-08-14 00:23 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\Malwarebytes
2009-08-14 00:23 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-14 00:23 . 2009-08-14 00:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-14 00:23 . 2009-08-15 02:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-14 00:23 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-14 00:04 . 2009-08-14 00:04 45344 —-a-w- c:\windows\system32\drivers\krjbecd.sys
2009-08-12 23:16 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\program files\MSBuild
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\program files\Reference Assemblies
2009-08-06 07:04 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 07:04 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-06 07:04 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 07:04 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-06 07:04 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 07:04 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-06 07:04 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 07:04 . 2009-08-06 07:05 ——– d—–w- C:\2aa286fd5e5fe8c08b1513
2009-08-06 07:04 . 2009-08-06 07:17 ——– d—–w- c:\windows\SxsCaPendDel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 18:19 . 2009-04-02 23:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-22 21:37 . 2009-08-22 21:37 2812 —-a-w- C:\dds.zip
2009-08-22 02:37 . 2009-08-22 01:28 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2009-08-22 02:37 . 2006-08-26 18:29 ——– d—–w- c:\program files\ESET
2009-08-22 01:29 . 2009-08-22 01:29 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\ESET
2009-08-21 22:48 . 2009-08-21 22:47 ——– d—–w- c:\program files\ERUNT
2009-08-19 00:16 . 2006-09-07 03:05 ——– d—–w- c:\program files\Windows Media Connect 2
2009-08-15 04:03 . 2009-02-11 23:55 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-15 04:03 . 2006-08-18 03:48 ——– d—–w- c:\program files\Java
2009-08-15 03:13 . 2006-12-25 18:58 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-11 23:29 . 2006-08-26 21:24 ——– d—–w- c:\program files\PartyGaming
2009-08-11 21:20 . 2006-10-03 00:47 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-11 21:20 . 2006-10-03 00:47 88 –sh–r- c:\windows\system32\FB24DE712C.sys
2009-08-11 21:19 . 2006-08-25 01:46 69328 —-a-w- c:\documents and settings\Bill & Kathy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-06 07:17 . 2009-06-13 16:28 ——– d—–w- c:\program files\Microsoft Silverlight
2009-08-05 09:01 . 2005-08-16 08:18 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-23 14:07 . 2006-08-26 18:20 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\AdobeUM
2009-07-17 19:01 . 2005-08-16 08:18 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2005-08-16 08:19 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-11 18:06 . 2009-06-20 18:03 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-07-11 18:06 . 2009-06-20 18:03 1630560 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-07-11 18:06 . 2009-06-20 18:03 2353480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-07-11 15:52 . 2009-07-11 15:47 ——– d—–w- c:\program files\ATT-PRT22-WISE
2009-07-11 15:50 . 2009-07-11 15:50 ——– d—–w- c:\program files\att-prt22
2009-07-11 15:50 . 2009-07-11 15:47 ——– d—–w- c:\program files\Common Files\Motive
2009-07-11 15:48 . 2009-07-11 15:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Motive
2009-06-29 16:56 . 2009-06-26 18:50 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\U3
2009-06-29 16:12 . 2005-08-16 08:18 827392 ——w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2005-08-16 08:18 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-08-16 08:18 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2005-08-16 08:18 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2005-08-16 08:18 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2005-08-16 08:18 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2005-08-16 08:18 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2005-08-16 08:18 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2005-08-16 08:18 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2005-08-16 08:18 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-23 00:40 . 2009-06-12 00:49 152576 —-a-w- c:\documents and settings\Bill & Kathy\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-16 14:36 . 2005-08-16 08:18 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 08:18 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2005-08-16 08:18 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-08-16 08:18 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2005-08-16 08:18 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-08-16 08:37 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2005-08-16 08:18 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2005-08-16 08:18 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-30 18:04 . 2009-05-30 18:04 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-05-30 18:04 . 2009-04-25 18:10 15688 —-a-w- c:\windows\system32\lsdelete.exe
2007-06-09 17:54 . 2007-06-09 17:54 251 -c–a-w- c:\program files\wt3d.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 21:20 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-01 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-15 149280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"HelpCenter4.1"="c:\program files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 198184]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 98304]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-04 520024]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968]

c:\documents and settings\Bill & Kathy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-17 24576]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2006-8-26 135680]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\networkdvr\\remote.exe"=
"c:\\Program Files\\Enlight\\Virtual Skipper 3\\Vsk3.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/25/2009 2:03 PM 64160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [5/14/2009 3:49 PM 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840]
S0 krjbecd;krjbecd;\SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys –> \SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys [?]
S1 9f9a7c46.sys;9f9a7c46.sys;\??\c:\windows\System32\drivers\9f9a7c46.sys –> c:\windows\System32\drivers\9f9a7c46.sys [?]
S2 gupdate1c9b3e9dfcb5276;Google Update Service (gupdate1c9b3e9dfcb5276);c:\program files\Google\Update\GoogleUpdate.exe [4/2/2009 7:22 PM 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
S3 vitra;vitra;c:\windows\system32\drivers\vitra.sys –> c:\windows\system32\drivers\vitra.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-08-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:03]

2009-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]

2009-08-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-02 23:20]

2009-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:22]

2009-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://hometab.bellsouth.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
.

**************************************************************************

disk not found C:\

please note that you need administrator rights to perform deep scan
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-847351272-1449424622-3853843411-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\AutorunsDisabled]
"Appinit_Dlls"="c:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL"
.
Completion time: 2009-08-28 12:27
ComboFix-quarantined-files.txt 2009-08-28 16:27
ComboFix2.txt 2009-08-28 00:26

Pre-Run: 58,240,577,536 bytes free
Post-Run: 58,203,652,096 bytes free

195 — E O F — 2009-08-26 07:00
Hello.

Please delete the existing Combofix you currently have. Re-download it from one of the links below and save it to your desktop.

Run ComboFix with CFScript

We will run ComboFix again. This time, the instructions are slightly different.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste the text in the quotebox below into it:
    Driver::
    vitra
    9f9a7c46.sys
    krjbecd
    RegLockDel::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\AutorunsDisabled]
    File::
    C:\Windows\System32\drivers\krjbecd.sys
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)
    [external image: Posted Image]
    Refering to the picture above, drag CFScript into ComboFix.exe.
When finished, it shall produce a log for you at "C:\ComboFix.txt". Post back with that log.

Do not mouseclick ComboFix's window while it's running. That may cause it to stall

Update and Scan with MalwareBytes Anti-Malware

  • Launch Malwarebytes' Anti-Malware
  • Go to the Update tab
  • Select Check for Update and let MBAM download and install any available updates.
  • After the update is complete go to the Scanner tab.
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

With regards,
Extremeboy
I am now getting the machine to boot in safe mode. I ran an up to date Sophos SAv32cli and it found a virus called JSRedir-G which it removed. Still getting a bunch of BSOD's and hard locks. Here is the new Combofix.txt ComboFix 09-08-30.01 - Bill & Kathy 08/30/2009 18:58.7.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.611 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\BILL&K~1\LOCALS~1\Temp\catchme.dll c:\documents and settings\Bill & Kathy\Local Settings\Temp\catchme.dll . ((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-30 ))))))))))))))))))))))))))))))) . 2009-08-19 00:35 . 2009-08-19 00:35 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\GlarySoft 2009-08-19 00:35 . 2009-08-19 00:35 ——– d—–w- c:\program files\Glary Registry Repair 2009-08-15 02:24 . 2009-08-15 02:24 3942047 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-08-15 01:18 . 2009-08-15 03:59 152576 —-a-w- c:\documents and settings\Bill & Kathy\Application Data\Sun\Java\jre1.6.0_15\lzma.dll 2009-08-15 00:04 . 2009-08-15 00:04 ——– d—–w- C:\SAV32CLI 2009-08-14 00:23 . 2009-08-14 00:23 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\Malwarebytes 2009-08-14 00:23 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-14 00:23 . 2009-08-14 00:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-08-14 00:23 . 2009-08-15 02:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-08-14 00:23 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-08-14 00:04 . 2009-08-14 00:04 45344 —-a-w- c:\windows\system32\drivers\krjbecd.sys 2009-08-12 23:16 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll 2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\windows\system32\XPSViewer 2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\program files\MSBuild 2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\program files\Reference Assemblies 2009-08-06 07:04 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-06 07:04 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll 2009-08-06 07:04 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-06 07:04 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll 2009-08-06 07:04 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll 2009-08-06 07:04 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll 2009-08-06 07:04 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-06 07:04 . 2009-08-06 07:05 ——– d—–w- C:\2aa286fd5e5fe8c08b1513 2009-08-06 07:04 . 2009-08-06 07:17 ——– d—–w- c:\windows\SxsCaPendDel . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-29 22:41 . 2009-04-02 23:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater 2009-08-29 16:29 . 2009-08-29 16:29 552 —-a-w- c:\windows\system32\d3d8caps.dat 2009-08-22 02:37 . 2009-08-22 01:28 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET 2009-08-22 02:37 . 2006-08-26 18:29 ——– d—–w- c:\program files\ESET 2009-08-22 01:29 . 2009-08-22 01:29 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\ESET 2009-08-19 00:16 . 2006-09-07 03:05 ——– d—–w- c:\program files\Windows Media Connect 2 2009-08-15 04:03 . 2009-02-11 23:55 411368 —-a-w- c:\windows\system32\deploytk.dll 2009-08-15 04:03 . 2006-08-18 03:48 ——– d—–w- c:\program files\Java 2009-08-15 03:13 . 2006-12-25 18:58 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-08-11 23:29 . 2006-08-26 21:24 ——– d—–w- c:\program files\PartyGaming 2009-08-11 21:20 . 2006-10-03 00:47 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys 2009-08-11 21:20 . 2006-10-03 00:47 88 –sh–r- c:\windows\system32\FB24DE712C.sys 2009-08-11 21:19 . 2006-08-25 01:46 69328 —-a-w- c:\documents and settings\Bill & Kathy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-08-06 07:17 . 2009-06-13 16:28 ——– d—–w- c:\program files\Microsoft Silverlight 2009-08-05 09:01 . 2005-08-16 08:18 204800 —-a-w- c:\windows\system32\mswebdvd.dll 2009-07-23 14:07 . 2006-08-26 18:20 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\AdobeUM 2009-07-17 19:01 . 2005-08-16 08:18 58880 —-a-w- c:\windows\system32\atl.dll 2009-07-14 03:43 . 2005-08-16 08:19 286208 —-a-w- c:\windows\system32\wmpdxm.dll 2009-07-11 18:06 . 2009-06-20 18:03 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll 2009-07-11 18:06 . 2009-06-20 18:03 1630560 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll 2009-07-11 18:06 . 2009-06-20 18:03 2353480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe 2009-07-11 15:52 . 2009-07-11 15:47 ——– d—–w- c:\program files\ATT-PRT22-WISE 2009-07-11 15:50 . 2009-07-11 15:50 ——– d—–w- c:\program files\att-prt22 2009-07-11 15:50 . 2009-07-11 15:47 ——– d—–w- c:\program files\Common Files\Motive 2009-07-11 15:48 . 2009-07-11 15:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Motive 2009-06-29 16:12 . 2005-08-16 08:18 827392 ——w- c:\windows\system32\wininet.dll 2009-06-29 16:12 . 2005-08-16 08:18 78336 —-a-w- c:\windows\system32\ieencode.dll 2009-06-29 16:12 . 2005-08-16 08:18 17408 —-a-w- c:\windows\system32\corpol.dll 2009-06-25 08:25 . 2005-08-16 08:18 54272 —-a-w- c:\windows\system32\wdigest.dll 2009-06-25 08:25 . 2005-08-16 08:18 56832 —-a-w- c:\windows\system32\secur32.dll 2009-06-25 08:25 . 2005-08-16 08:18 147456 —-a-w- c:\windows\system32\schannel.dll 2009-06-25 08:25 . 2005-08-16 08:18 136192 —-a-w- c:\windows\system32\msv1_0.dll 2009-06-25 08:25 . 2005-08-16 08:18 730112 —-a-w- c:\windows\system32\lsasrv.dll 2009-06-25 08:25 . 2005-08-16 08:18 301568 —-a-w- c:\windows\system32\kerberos.dll 2009-06-24 11:18 . 2005-08-16 08:18 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2009-06-23 00:40 . 2009-06-12 00:49 152576 —-a-w- c:\documents and settings\Bill & Kathy\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-06-16 14:36 . 2005-08-16 08:18 119808 —-a-w- c:\windows\system32\t2embed.dll 2009-06-16 14:36 . 2005-08-16 08:18 81920 —-a-w- c:\windows\system32\fontsub.dll 2009-06-12 12:31 . 2005-08-16 08:18 80896 —-a-w- c:\windows\system32\tlntsess.exe 2009-06-12 12:31 . 2005-08-16 08:18 76288 —-a-w- c:\windows\system32\telnet.exe 2009-06-10 14:13 . 2005-08-16 08:18 84992 —-a-w- c:\windows\system32\avifil32.dll 2009-06-10 13:19 . 2005-08-16 08:37 2066432 —-a-w- c:\windows\system32\mstscax.dll 2009-06-10 06:14 . 2005-08-16 08:18 132096 —-a-w- c:\windows\system32\wkssvc.dll 2009-06-03 19:09 . 2005-08-16 08:18 1291264 —-a-w- c:\windows\system32\quartz.dll 2007-06-09 17:54 . 2007-06-09 17:54 251 -c–a-w- c:\program files\wt3d.ini . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-15 149280] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856] "HelpCenter4.1"="c:\program files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 198184] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 98304] "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064] "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-04 520024] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640] "MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-14 169984] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-17 24576] EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2006-8-26 135680] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\networkdvr\\remote.exe"= "c:\\Program Files\\Enlight\\Virtual Skipper 3\\Vsk3.exe"= R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/25/2009 2:03 PM 64160] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [5/14/2009 3:49 PM 94360] R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840] S0 krjbecd;krjbecd;\SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys –> \SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys [?] S1 9f9a7c46.sys;9f9a7c46.sys;\??\c:\windows\System32\drivers\9f9a7c46.sys –> c:\windows\System32\drivers\9f9a7c46.sys [?] S2 gupdate1c9b3e9dfcb5276;Google Update Service (gupdate1c9b3e9dfcb5276);c:\program files\Google\Update\GoogleUpdate.exe [4/2/2009 7:22 PM 133104] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456] S3 vitra;vitra;c:\windows\system32\drivers\vitra.sys –> c:\windows\system32\drivers\vitra.sys [?] . Contents of the 'Scheduled Tasks' folder 2009-08-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:03] 2009-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57] 2009-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:22] 2009-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:22] . . ——- Supplementary Scan ——- . uStart Page = hxxp://hometab.bellsouth.net/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000 Trusted Zone: musicmatch.com\online . ************************************************************************** disk not found C:\ please note that you need administrator rights to perform deep scan scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-847351272-1449424622-3853843411-1005\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\AutorunsDisabled] "Appinit_Dlls"="c:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL" . Completion time: 2009-08-30 19:04 ComboFix-quarantined-files.txt 2009-08-30 23:04 ComboFix2.txt 2009-08-28 16:27 Pre-Run: 58,955,108,352 bytes free Post-Run: 58,930,872,320 bytes free 172 — E O F — 2009-08-26 07:00 I will post the updated Malwarebytes in a few minutes.
Malwarebytes' Anti-Malware 1.40 Database version: 2719 Windows 5.1.2600 Service Pack 3 8/30/2009 8:29:43 PM mbam-log-2009-08-30 (20-29-43).txt Scan type: Quick Scan Objects scanned: 102383 Time elapsed: 5 minute(s), 2 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
I believe I didn't follow instructions properly the first time. Here is a new log:

ComboFix 09-08-31.03 - Bill & Kathy 08/31/2009 18:37.8.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.623 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Bill & Kathy\Desktop\CFScript.txt
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

FILE ::
"c:\windows\System32\drivers\krjbecd.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\BILL&K~1\LOCALS~1\Temp\catchme.dll
c:\documents and settings\Bill & Kathy\Local Settings\Temp\catchme.dll
c:\windows\System32\drivers\krjbecd.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_VITRA
——-\Service_9f9a7c46.sys
——-\Service_krjbecd
——-\Service_vitra


((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.

2009-08-29 16:29 . 2009-08-29 16:29 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-08-23 21:16 . 2009-08-23 21:16 ——– d—–w- c:\documents and settings\Bill & Kathy\Local Settings\Application Data\Deployment
2009-08-22 01:29 . 2009-08-22 01:29 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\ESET
2009-08-22 01:28 . 2009-08-22 02:37 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2009-08-21 21:53 . 2009-08-21 21:53 ——– d-sh–w- C:\found.000
2009-08-19 00:35 . 2009-08-19 00:35 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\GlarySoft
2009-08-19 00:35 . 2009-08-19 00:35 ——– d—–w- c:\program files\Glary Registry Repair
2009-08-15 02:24 . 2009-08-15 02:24 3942047 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-15 01:18 . 2009-08-15 03:59 152576 —-a-w- c:\documents and settings\Bill & Kathy\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-15 00:04 . 2009-08-15 00:04 ——– d—–w- C:\SAV32CLI
2009-08-14 00:23 . 2009-08-14 00:23 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\Malwarebytes
2009-08-14 00:23 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-14 00:23 . 2009-08-14 00:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-14 00:23 . 2009-08-15 02:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-14 00:23 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-12 23:16 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\program files\MSBuild
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\program files\Reference Assemblies
2009-08-06 07:04 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 07:04 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-06 07:04 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 07:04 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-06 07:04 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 07:04 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-06 07:04 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 07:04 . 2009-08-06 07:05 ——– d—–w- C:\2aa286fd5e5fe8c08b1513
2009-08-06 07:04 . 2009-08-06 07:17 ——– d—–w- c:\windows\SxsCaPendDel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-31 16:43 . 2009-04-02 23:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-31 00:36 . 2006-08-25 01:46 65792 —-a-w- c:\documents and settings\Bill & Kathy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-22 02:37 . 2006-08-26 18:29 ——– d—–w- c:\program files\ESET
2009-08-19 00:16 . 2006-09-07 03:05 ——– d—–w- c:\program files\Windows Media Connect 2
2009-08-15 04:03 . 2009-02-11 23:55 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-15 04:03 . 2006-08-18 03:48 ——– d—–w- c:\program files\Java
2009-08-15 03:13 . 2006-12-25 18:58 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-11 23:29 . 2006-08-26 21:24 ——– d—–w- c:\program files\PartyGaming
2009-08-11 21:20 . 2006-10-03 00:47 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-11 21:20 . 2006-10-03 00:47 88 –sh–r- c:\windows\system32\FB24DE712C.sys
2009-08-06 07:17 . 2009-06-13 16:28 ——– d—–w- c:\program files\Microsoft Silverlight
2009-08-05 09:01 . 2005-08-16 08:18 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-23 14:07 . 2006-08-26 18:20 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\AdobeUM
2009-07-17 19:01 . 2005-08-16 08:18 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2005-08-16 08:19 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-11 18:06 . 2009-06-20 18:03 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-07-11 18:06 . 2009-06-20 18:03 1630560 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-07-11 18:06 . 2009-06-20 18:03 2353480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-07-11 15:52 . 2009-07-11 15:47 ——– d—–w- c:\program files\ATT-PRT22-WISE
2009-07-11 15:50 . 2009-07-11 15:50 ——– d—–w- c:\program files\att-prt22
2009-07-11 15:50 . 2009-07-11 15:47 ——– d—–w- c:\program files\Common Files\Motive
2009-07-11 15:48 . 2009-07-11 15:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Motive
2009-06-29 16:12 . 2005-08-16 08:18 827392 ——w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2005-08-16 08:18 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-08-16 08:18 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2005-08-16 08:18 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2005-08-16 08:18 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2005-08-16 08:18 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2005-08-16 08:18 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2005-08-16 08:18 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2005-08-16 08:18 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2005-08-16 08:18 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-23 00:40 . 2009-06-12 00:49 152576 —-a-w- c:\documents and settings\Bill & Kathy\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-16 14:36 . 2005-08-16 08:18 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 08:18 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2005-08-16 08:18 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-08-16 08:18 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2005-08-16 08:18 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-08-16 08:37 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2005-08-16 08:18 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2005-08-16 08:18 1291264 —-a-w- c:\windows\system32\quartz.dll
2007-06-09 17:54 . 2007-06-09 17:54 251 -c–a-w- c:\program files\wt3d.ini
.

((((((((((((((((((((((((((((( SnapShot@2009-08-30_23.03.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-31 22:43 . 2009-08-31 22:43 16384 c:\windows\temp\Perflib_Perfdata_548.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-15 149280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"HelpCenter4.1"="c:\program files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 198184]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 98304]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-04 520024]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-14 169984]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-17 24576]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2006-8-26 135680]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\networkdvr\\remote.exe"=
"c:\\Program Files\\Enlight\\Virtual Skipper 3\\Vsk3.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/25/2009 2:03 PM 64160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [5/14/2009 3:49 PM 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
S2 gupdate1c9b3e9dfcb5276;Google Update Service (gupdate1c9b3e9dfcb5276);c:\program files\Google\Update\GoogleUpdate.exe [4/2/2009 7:22 PM 133104]
.
Contents of the 'Scheduled Tasks' folder

2009-08-31 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:03]

2009-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]

2009-08-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-02 23:20]

2009-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:22]

2009-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://hometab.bellsouth.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-31 18:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-847351272-1449424622-3853843411-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\AutorunsDisabled]
"Appinit_Dlls"="c:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3184)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-08-31 18:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-31 22:47
ComboFix2.txt 2009-08-30 23:04
ComboFix3.txt 2009-08-28 16:27

Pre-Run: 58,924,924,928 bytes free
Post-Run: 58,841,575,424 bytes free

216 — E O F — 2009-08-26 07:00
Well done.

The second one was the correct Combofix log.

Let's run an online scan and see if there's anything else.

Download and Run ATFCleaner

Please download ATF Cleaner by Atribune. This program will clear out temporary files and settings. You will likely be logged out of the forum where you are recieving help.

  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
If you use Firefox browser also…
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser also…
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Run ESET Online Scan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
You can refer to this animation by neomage if needed.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
With Regards,
Extremeboy
Happy to tell you ESET scanned with no findings. I ran the recovery console FMBR switch last night. It found a non-standard MBR and I took the plunge and had it fix the MBR. It came out fine. I am presently symptom free. Here are the DDS scans DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 19:15:36.41 on Tue 09/01/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.613 [GMT -4:00] AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\stsystra.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Digital Line Detect\DLG.exe svchost.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe svchost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://hometab.bellsouth.net/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [HelpCenter4.1] c:\program files\bellsouth\helpcenter40b\bin\sprtcmd.exe /P HelpCenter4.1 mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsons~1.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: musicmatch.com\online DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://help.bellsouth.net/sdccommon/download/tgctlcm.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1157589360759 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} - hxxp://webaccess.goodwillsavannahga.org/msrdp.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-25 64160] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-5-14 94360] R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S2 gupdate1c9b3e9dfcb5276;Google Update Service (gupdate1c9b3e9dfcb5276);c:\program files\google\update\GoogleUpdate.exe [2009-4-2 133104] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456] =============== Created Last 30 ================ 2009-08-29 12:29 552 a——- c:\windows\system32\d3d8caps.dat 2009-08-27 20:24 –d—– c:\windows\system32\dllcache\cache 2009-08-21 21:29 –d—– c:\docume~1\bill&k~1\applic~1\ESET 2009-08-21 17:53 –dsh— C:\found.000 2009-08-19 18:59 a-dshr– C:\cmdcons 2009-08-18 20:35 –d—– c:\docume~1\bill&k~1\applic~1\GlarySoft 2009-08-18 20:35 –d—– c:\program files\Glary Registry Repair 2009-08-18 20:11 0 a——- c:\windows\iPlayer.INI 2009-08-17 19:09 250 a——- c:\windows\gmer.ini 2009-08-15 00:03 73,728 a——- c:\windows\system32\javacpl.cpl 2009-08-14 20:04 –d—– C:\SAV32CLI 2009-08-13 20:23 –d—– c:\docume~1\bill&k~1\applic~1\Malwarebytes 2009-08-13 20:23 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-13 20:23 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-13 20:23 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-13 20:23 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-12 19:16 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx 2009-08-12 19:16 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll 2009-08-07 22:11 54,156 a—h— c:\windows\QTFont.qfn 2009-08-07 22:11 1,409 a——- c:\windows\QTFont.for 2009-08-06 20:10 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat 2009-08-06 03:05 –d—– c:\windows\system32\XPSViewer 2009-08-06 03:04 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-06 03:04 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll 2009-08-06 03:04 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-06 03:04 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-06 03:04 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-06 03:04 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-06 03:04 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-06 03:04 –d—– C:\2aa286fd5e5fe8c08b1513 2009-08-06 03:04 –d—– c:\windows\SxsCaPendDel ==================== Find3M ==================== 2009-08-15 00:03 411,368 a——- c:\windows\system32\deploytk.dll 2009-08-11 17:20 3,350 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-05 05:01 204,800 a——- c:\windows\system32\dllcache\mswebdvd.dll 2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll 2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\cache\mshtml.dll 2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll 2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll 2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll 2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-29 04:35 634,632 a——- c:\windows\system32\dllcache\iexplore.exe 2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat 2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2009-06-25 04:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 04:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 04:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-25 04:25 730,112 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-25 04:25 301,568 ——– c:\windows\system32\dllcache\kerberos.dll 2009-06-25 04:25 147,456 ——– c:\windows\system32\dllcache\schannel.dll 2009-06-25 04:25 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-06-25 04:25 56,832 ——– c:\windows\system32\dllcache\secur32.dll 2009-06-25 04:25 54,272 ——– c:\windows\system32\dllcache\wdigest.dll 2009-06-24 07:18 92,928 ——– c:\windows\system32\dllcache\ksecdd.sys 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 119,808 a——- c:\windows\system32\dllcache\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\dllcache\fontsub.dll 2009-06-12 08:31 80,896 a——- c:\windows\system32\tlntsess.exe 2009-06-12 08:31 80,896 a——- c:\windows\system32\dllcache\tlntsess.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\telnet.exe 2009-06-12 08:31 76,288 a——- c:\windows\system32\dllcache\telnet.exe 2009-06-10 10:13 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 10:13 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-06-10 09:19 2,066,432 a——- c:\windows\system32\dllcache\mstscax.dll 2009-06-10 02:14 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-10 02:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll 2008-11-24 08:30 69,328 ac—— c:\docume~1\bill&k~1\applic~1\GDIPFONTCACHEV1.DAT 2007-08-30 19:22 10,385,200 ac—— c:\documents and settings\bill & kathy\HC41SInstaller.exe 2007-06-09 13:54 251 ac—— c:\program files\wt3d.ini 2004-10-19 16:38 11,052,037 ac—— c:\docume~1\bill&k~1\applic~1\HCSetup2.0_IW.5.1.exe 2008-09-05 18:45 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090520080906\index.dat ============= FINISH: 19:16:02.88 ===============

Attachments:

Hello.

That's good to hear. The logs also looks good too. :)

Well done. Just one program that you should uninstall.

Java 2 Runtime Environment, SE v1.4.2_03

It's an older version of Java and is a security risk while it's still installed on your system when you already have the latest version of Java installed. We can cleanup now.
–
Please follow/read the steps below to remove the tools we used and for some more information. :)

Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Click on your Start Menu, then Run….
  • Now type combofix /u in the runbox and click OK. Notice the space between the "x" and "/".
    [external image: Posted Image]
  • You will then recieve a message letting you know that Combofix was uninstalled Successfully.

This will remove files/folders assoicated with combofix and uninstall it.

Download and Run OTC

We will now remove the tools we used during this fix using OTC.


System A bit Slow? Try StartupLight

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.

Congratulations! You now appear clean! :woot: :D

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.

Vist the WindowsUpdate Site Regularly

I recommend you regularly visit the Windows Update Site!
  • Lots of Hacking/Trojans use the methods found (plugged by the updates) that have not been stopped by people not updating.
  • Update ALL Critical updates and any other Windows updates for services/programs that you use.
  • If you wish to turn on automatic updates then you will find here is a nice little article about turning on automatic updates.
  • Note that it will download them for you, but you still have to actually click install.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

If you have no more questions, comments or problems please tell us, so we can close off the topic.

Thanks :)

With Regards,
Extremeboy
I am grateful for all of your help. You have been patient and effective and I hope we never need to correspond again!! :-) I will follow up at home this evening with your recommendations. Regards, Bill Oakley
No problem. Glad I was able to help. :) Let me know once you have completed the instructions and then if you have more questions, comments or concerns you wish to ask feel free to do so. :) With Regards, Extremeboy
I have completed the instructions and everything went well. I was surprised at how out of date my Adobe was, I think it took about 4 passes to bring it up to date. I simply removed the realplayer as I don't use it and don't think I will need it again. Thanks again, all seems well. Bill Oakley
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI