This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Dell Inspiron "timing out"

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

All:


My wife's Dell Inspiron E1505 (Windows XP) is hanging up after 20-30 minutes, and not respondoing. I tried to run a full virus scan (Trend Micro Internet Security Pro), and it hangs up after anywhere from 20 to 40 minutes run time. I've gotten about 85% completed–no further. This didn't happen until this last weekend. We loaded some HP printer software, and were at a Holiday Inn for an event using the computer and printer. I don't know when (I'm certain it's not if) the machine was on the hotel's high-speed internet access.

I've noticed that the IE browser keeps trying to go to an antivirus site I know nothing about. Firefox is running OK

I've run HJT and am attaching the log after this message.


–Tom vonHatten


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:10:36 PM, on 03/03/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\clclean.0001
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Timex\Data Link USB\DataLinkLauncher.exe
C:\Program Files\Timex\Timex Trainer\TBEggLaunch.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\Rpcnet.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6061116
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6061116
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe 1
O4 - HKLM\..\Run: [WinCalendar] "C:\Program Files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" /q /c
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [acyymisc] C:\Documents and Settings\Grace\Local Settings\Application Data\ximhwj\ysbksftav.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WinCalendar] "C:\Program Files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe /q /c"
O4 - HKUS\S-1-5-18\..\Run: [WinCalendar] "C:\Program Files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" /q /c (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [WinCalendar] "C:\Program Files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" /q /c (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Timex Data Link USB Launcher.lnk = C:\Program Files\Timex\Data Link USB\DataLinkLauncher.exe
O4 - Global Startup: Timex Trainer Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {700EF03F-A472-4D26-8ACB-300F4D04FD96} (Recovery ActiveX Control Module) - http://www.lojackforlaptops.com/ctmweb/testoc.cab
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Remote Procedure Call (RPC) Net (Rpcnet) - Absolute Software Corp. - C:\WINDOWS\SYSTEM32\Rpcnet.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 11350 bytes
hi tvhevh, sounds like you could be infected with a virus/spyware. I Suggest booting up into safe mode (tap F8 at the laptop starts up) and choose Safe Mode, which will load the basic drivers to get you into the system. From there, run your AV along with Ad-Aware, or Malwarebytes and hopefully they should pick up any nasties causing the issue. It's important you try safe mode. Good luck, write back with results. 'Bob
I'm booting up in Safe Mode. I don't have Ad-Aware or Malwarebytes loaded on the machine. The AntiVirus with Trend Micro Internet Security Pro finally ran a full scan earlier, and indicated nothing. I'm going to run it again in Safe Mode. I'll let you know the results. –Tom vonHatten
Hi, There are signs of malware in your HJT log, I will move this topic to the Infections Removal Forum Please don't do anything else to your system till assisted by a helper in the infections forum thanks
Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I have run DDS. Here is the DDS.txt file, followed by the Attach.txt file: DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 21:15:06.53 on 03/03/2010 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1123 [GMT -6:00] AV: Trend Micro Internet Security Pro *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} FW: Trend Micro Personal Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\WINDOWS\system32\svchost.exe -k HPService C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\SYSTEM32\Rpcnet.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\UStorSrv.exe C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\stsystra.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Creative\VoiceCenter\AndreaVC.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\DOCUME~1\Family\LOCALS~1\Temp\clclean.0001 C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Canon\MyPrinter\BJMyPrt.exe C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe C:\Program Files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\NetWaiting\netWaiting.exe C:\Program Files\Dell Support\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\Program Files\Timex\Data Link USB\DataLinkLauncher.exe C:\Program Files\Timex\Timex Trainer\TBEggLaunch.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Trend Micro\Internet Security\TmPfw.exe C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Documents and Settings\Family\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6061116 uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6061116 uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8 uInternet Settings,ProxyServer = http=127.0.0.1:5555 uInternet Settings,ProxyOverride = uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: TSToolbarBHO: {43c6d902-a1c5-45c9-91f6-fd9e90337e18} - c:\program files\trend micro\trendsecure\tisprotoolbar\TSToolbar.dll BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Trend Micro Toolbar: {ccac5586-44d7-4c43-b64a-f042461a97d2} - c:\program files\trend micro\trendsecure\tisprotoolbar\TSToolbar.dll uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe uRun: [SetDefaultMIDI] MIDIDef.exe uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WinCalendar] "c:\program files\sapro systems wincalendar\WinCalendar_SysTray.exe /q /c" mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [CTSysVol] c:\program files\creative\sbaudigy\surround mixer\CTSysVol.exe /r mRun: [MBMon] Rundll32 CTMBHA.DLL,MBMon mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [VoiceCenter] "c:\program files\creative\voicecenter\AndreaVC.exe" /tray mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon mRun: [] mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1 mRun: [WinCalendar] "c:\program files\sapro systems wincalendar\WinCalendar_SysTray.exe" /q /c mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe" mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [acyymisc] c:\documents and settings\grace\local settings\application data\ximhwj\ysbksftav.exe dRun: [WinCalendar] "c:\program files\sapro systems wincalendar\WinCalendar_SysTray.exe" /q /c StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\timexd~1.lnk - c:\program files\timex\data link usb\DataLinkLauncher.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\timext~1.lnk - c:\program files\timex\timex trainer\TBEggLaunch.exe IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {700EF03F-A472-4D26-8ACB-300F4D04FD96} - hxxp://www.lojackforlaptops.com/ctmweb/testoc.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - c:\program files\trend micro\trendsecure\tisprotoolbar\TSToolbar.dll Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\family\applic~1\mozilla\firefox\profiles\sw6khvia.default\ FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - component: c:\program files\trend micro\trendsecure\tisprotoolbar\firefoxextension\components\FFTMUFEHelper.dll FF - component: c:\program files\trend micro\trendsecure\tisprotoolbar\firefoxextension\components\FFToolbarComm.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-3-3 64288] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1229232] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2009-12-16 36368] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2009-12-16 339984] R3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2009-12-16 50704] R3 TmPfw;Trend Micro Personal Firewall;c:\program files\trend micro\internet security\TmPfw.exe [2009-12-16 497008] R3 TmProxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2009-12-16 689416] S3 USA19W;USA19W;c:\windows\system32\drivers\usa19w2k.sys [2007-2-6 292920] S3 USA19w2KP;Keyspan High Speed USB Serial Adapter Port Driver;c:\windows\system32\drivers\usa19w2kp.sys [2007-2-6 40848] =============== Created Last 30 ================ 2010-03-04 03:00:36 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys 2010-03-04 03:00:29 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-03-04 02:56:43 0 dc-h–w- c:\docume~1\alluse~1\applic~1\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6} 2010-03-04 02:56:18 0 d—–w- c:\program files\Lavasoft 2010-03-01 02:38:38 0 d—–w- c:\windows\U5ENW5ENW5ENW5EN 2010-02-27 11:55:09 0 d—–w- c:\windows\system32\Service 2010-02-27 07:06:01 0 d—–w- c:\program files\Avery Dennison 2010-02-24 16:47:55 0 d—–w- c:\docume~1\alluse~1\applic~1\WEBREG 2010-02-24 16:45:14 16496 —-a-r- c:\windows\system32\drivers\HPZipr12.sys 2010-02-24 16:45:06 49920 —-a-r- c:\windows\system32\drivers\HPZid412.sys 2010-02-24 16:44:49 118272 —-a-w- c:\windows\system32\hpf3l082.dll 2010-02-24 16:44:48 271704 —-a-r- c:\windows\system32\hpzids01.dll 2010-02-24 16:44:42 21568 —-a-r- c:\windows\system32\drivers\HPZius12.sys 2010-02-24 16:44:31 309760 —-a-r- c:\windows\system32\difxapi.dll 2010-02-24 16:44:30 966656 —-a-r- c:\windows\system32\hpwtiop4.dll 2010-02-24 16:44:30 741376 —-a-r- c:\windows\system32\hpwwiax5.dll 2010-02-24 16:44:30 364544 —-a-r- c:\windows\system32\hppldcoi.dll 2010-02-24 16:44:30 294912 —-a-r- c:\windows\system32\hpovst11.dll 2010-02-24 16:44:29 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys 2010-02-24 16:44:29 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys 2010-02-24 16:43:36 2979 ——w- c:\windows\hpwmdl22.dat.temp 2010-02-24 04:58:26 0 d—–w- c:\windows\hpojp8500a909 2010-02-24 04:49:59 0 d—–w- c:\program files\common files\HP 2010-02-24 04:49:57 0 d—–w- c:\program files\common files\Hewlett-Packard 2010-02-24 04:36:10 188920 —-a-w- c:\windows\hpwins22.dat 2010-02-24 04:36:09 2979 ——w- c:\windows\hpwmdl22.dat 2010-02-19 17:06:04 764868 ——w- c:\windows\system32\dllcache\apph_sp.sdb 2010-02-19 17:06:04 217118 ——w- c:\windows\system32\dllcache\apphelp.sdb 2010-02-19 17:05:40 0 d—–w- c:\program files\Windows Media Connect 2 2010-02-19 17:03:14 0 d—–w- c:\windows\system32\LogFiles 2010-02-16 03:20:33 0 d—–w- C:\swmeets3 2010-02-16 03:18:19 0 d—–w- c:\program files\common files\dao 2010-02-16 03:18:19 0 d—–w- c:\program files\common files\Business Objects 2010-02-16 03:18:19 0 d—–w- C:\Hy-Sport ==================== Find3M ==================== 2010-03-04 03:05:20 17408 —-a-w- c:\windows\system32\rpcnetp.exe 2010-03-04 03:05:15 56680 —-a-w- c:\windows\system32\Rpcnet.dll 2010-03-04 03:05:15 17408 —-a-w- c:\windows\system32\rpcnetp.dll 2010-01-22 23:16:35 2828 –sha-w- c:\windows\system32\KGyGaAvL.sys 2009-12-31 16:14:12 352640 ——w- c:\windows\system32\dllcache\srv.sys 2009-12-31 15:33:06 70656 ——w- c:\windows\system32\dllcache\ie4uinit.exe 2009-12-31 15:33:06 13824 ——w- c:\windows\system32\dllcache\ieudinit.exe 2009-12-18 13:05:43 634648 ——w- c:\windows\system32\dllcache\iexplore.exe 2009-12-18 13:04:09 161792 ——w- c:\windows\system32\dllcache\ieakui.dll 2009-12-16 12:58:04 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-16 12:58:04 343040 ——w- c:\windows\system32\dllcache\mspaint.exe 2009-12-14 07:35:35 33280 —-a-w- c:\windows\system32\csrsrv.dll 2009-12-14 07:35:35 33280 ——w- c:\windows\system32\dllcache\csrsrv.dll 2009-12-08 18:14:02 2185984 ——w- c:\windows\system32\dllcache\ntoskrnl.exe 2009-12-08 18:11:44 2142720 —-a-w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:11:44 2142720 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-12-08 17:35:25 2020864 —-a-w- c:\windows\system32\ntkrnlpa.exe 2009-12-08 17:35:25 2020864 ——w- c:\windows\system32\dllcache\ntkrpamp.exe 2009-12-08 17:35:22 2063104 ——w- c:\windows\system32\dllcache\ntkrnlpa.exe 2009-12-08 08:59:48 474112 ——w- c:\windows\system32\dllcache\shlwapi.dll 2009-12-04 14:41:55 453760 ——w- c:\windows\system32\dllcache\mrxsmb.sys ============= FINISH: 21:16:16.21 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 11/21/2006 4:56:13 PM System Uptime: 03/03/2010 9:04:10 PM (0 hours ago) Motherboard: Dell Inc. | | 0XD720 Processor: Intel® Core™2 CPU T7200 @ 2.00GHz | Microprocessor | 1995/166mhz Processor: Intel® Core™2 CPU T7200 @ 2.00GHz | Microprocessor | 1995/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 88 GiB total, 64.638 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP237: 12/16/2009 1:00:23 PM - Removed Trend Micro PC-cillin Internet Security 12 RP238: 12/16/2009 1:01:19 PM - Removed TMASOEDL RP239: 12/16/2009 1:01:28 PM - Removed TMASOLDL RP240: 12/16/2009 1:07:39 PM - Installed Trend Micro Internet Security RP241: 12/17/2009 8:18:01 AM - Software Distribution Service 3.0 RP242: 12/18/2009 9:30:14 AM - System Checkpoint RP243: 12/19/2009 3:33:35 PM - System Checkpoint RP244: 12/21/2009 1:47:16 PM - System Checkpoint RP245: 12/25/2009 6:17:24 PM - System Checkpoint RP246: 12/26/2009 10:16:01 PM - System Checkpoint RP247: 12/28/2009 12:12:00 PM - System Checkpoint RP248: 12/30/2009 1:18:26 PM - System Checkpoint RP249: 01/03/2010 3:14:43 PM - System Checkpoint RP250: 01/15/2010 2:07:36 PM - System Checkpoint RP251: 01/18/2010 9:11:02 PM - System Checkpoint RP252: 01/20/2010 11:16:17 AM - System Checkpoint RP253: 01/21/2010 6:23:25 PM - Software Distribution Service 3.0 RP254: 01/22/2010 5:17:02 PM - Software Distribution Service 3.0 RP255: 01/24/2010 2:26:44 AM - System Checkpoint RP256: 01/25/2010 2:30:43 PM - System Checkpoint RP257: 02/02/2010 9:23:52 PM - System Checkpoint RP258: 02/03/2010 9:56:45 PM - System Checkpoint RP259: 02/05/2010 8:19:05 AM - System Checkpoint RP260: 02/06/2010 10:25:24 AM - System Checkpoint RP261: 02/09/2010 6:56:26 PM - System Checkpoint RP262: 02/10/2010 11:36:12 AM - Software Distribution Service 3.0 RP263: 02/11/2010 3:32:43 PM - System Checkpoint RP264: 02/12/2010 5:10:51 PM - System Checkpoint RP265: 02/15/2010 9:18:04 PM - Installed MEET MANAGER 3.0 for Swimming RP266: 02/19/2010 9:14:53 AM - System Checkpoint RP267: 02/19/2010 11:00:48 AM - Installed Windows Media Player 11 RP268: 02/19/2010 11:02:05 AM - Software Distribution Service 3.0 RP269: 02/19/2010 12:18:26 PM - Software Distribution Service 3.0 RP270: 02/23/2010 1:06:36 AM - Software Distribution Service 3.0 RP271: 02/24/2010 10:45:49 AM - Printer Driver HP Officejet Pro 8500 A909a Series fax Installed RP272: 02/27/2010 1:04:29 AM - Installed DesignPro 5.4 Limited Edition RP273: 02/27/2010 6:22:21 AM - Configured DesignPro 5.4 Limited Edition RP274: 02/27/2010 9:14:35 AM - Configured DesignPro 5.4 Limited Edition RP275: 02/28/2010 5:23:48 PM - System Checkpoint RP276: 03/02/2010 2:19:29 PM - System Checkpoint RP277: 03/03/2010 9:43:23 AM - Software Distribution Service 3.0 ==== Installed Programs ====================== 32 Bit HP CIO Components Installer 8500A909_eDocs 8500A909_Help 8500A909a Ad-Aware Ad-Aware Email Scanner for Outlook Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 7.0.8 Adobe Shockwave Player 11.5 Age of Mythology Andrea VoiceCenter ATI Catalyst Control Center ATI Display Driver BPD_DSWizards bpd_scan BPDSoftware BPDSoftware_Ini Broadcom Management Programs BufferChm Canon iP1700 Canon iP1700 User Registration Canon My Printer Canon Utilities Easy-PhotoPrint Conexant HDA D110 MDC V.92 Modem Consumer Complete Care Services Agreement Corel Snapfire Plus Creative Audio Pack Creative MediaSource 5 Dell Game Console Dell Support 3.2 Dell System Restore Dell Wireless WLAN Card DesignPro 5.4 Limited Edition Destination Component DeviceDiscovery Digital Content Portal Digital Line Detect Disney's Extremely Goofy Skateboarding Preview DivX Content Uploader DivX Web Player DocMgr DocProc Documentation & Support Launcher EarthLink Setup Files Easy-WebPrint Edu-Track Home School EducateU Fax Games, Music, & Photos Launcher Get High Speed Internet! Google Desktop Google Toolbar for Internet Explorer GPBaseService2 High Definition Audio Driver Package - KB835221 Higher Score on the ACT Higher Score on the SAT/PSAT HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB896256) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB908673) Hotfix for Windows XP (KB909095) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) HP Customer Participation Program 12.0 HP Document Manager 2.0 HP Imaging Device Functions 12.0 HP LaserJet P1000 series HP Photosmart Essential 3.5 HP Smart Web Printing HP Solution Center 12.0 HP Update HPCarePackCore HPCarePackProducts HPPhotoSmartDiscLabelContent1 HPPhotosmartEssential hppMSRedist HPProductAssistant hppusgP1000 HPSSupply Hy-Tek's MEET MANAGER 2.0 for Swimming Imation Disk Manager II Service Inspiration 7.6 Internet Service Offers Launcher J2SE Runtime Environment 5.0 Update 6 Keyspan High Speed USB Serial Adapter MarketResearch MediaDirect MEET MANAGER 3.0 for Swimming Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Outlook 2003 with Business Contact Manager Update Microsoft Office Small Business Edition 2003 Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ) Microsoft Text-to-Speech Engine 4.0 (English) Microsoft User-Mode Driver Framework Feature Pack 1.0 Modem Helper Mozilla Firefox (3.6) MPM MrvlUsgTracking MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML4 Parser NetWaiting Network NetZeroInstallers OCR Software by I.R.I.S. 12.0 Officejet Pro 8500 A909 Series OutlookAddinSetup Perfect Scrapbook Maker Express ProductContext Qualxserve Service Agreement QuickSet QuickTime Radioshack USB-to-Serial Cable Driver Installer Readerware Roll Scan SCRABBLE SearchAssist Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944533) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB947864) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978706) Shop for HP Supplies SmartWebPrinting SolutionCenter Sonic Copy Module Sonic DLA Sonic Express Labeler Sonic MyDVD Plus Sonic RecordNow Audio Sonic RecordNow Data Sonic Update Manager Sound Blaster ADVANCED MB Drivers Sound Blaster Audigy ADVANCED MB Sound Blaster Audigy ADVANCED MB Product Registration Status Synaptics Pointing Device Driver The Number Devil Timex Data Link USB Timex Trainer Toolbox Tradewinds TrayApp Trend Micro Internet Security Pro UnloadSupport Update for Windows Internet Explorer 7 (KB976749) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) URL Assistant Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP WebReg WildTangent Web Driver WinCalendar Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885855 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB889673 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB892627 Windows XP Hotfix - KB893056 Yahoo! Music Jukebox YOU DON'T KNOW JACK Television ==== Event Viewer Messages From Past Week ======== 03/03/2010 9:03:15 PM, error: Service Control Manager [7000] - The Lbd service failed to start due to the following error: The system cannot find the file specified. 03/03/2010 6:42:25 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 03/03/2010 6:40:40 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip tmtdi 03/03/2010 6:40:40 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 03/03/2010 6:40:40 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 03/03/2010 6:40:40 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 03/03/2010 6:40:40 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 03/03/2010 6:40:14 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 03/03/2010 6:40:07 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 03/03/2010 12:21:42 PM, error: System Error [1003] - Error code 1000000a, parameter1 00000000, parameter2 00000002, parameter3 00000001, parameter4 804e237f. ==== End Of File =========================== I will now use the GMER Rootkit Scanner. –Tom vonHatten
The machine hung up when I tried to save the gmer.txt file. I couldn't get it to save. I got a constant tone from the machine, and hgad to shut it down manually. I'll reboot and try this again. –Tom vonHatten
Finally–here's the GMER.txt info:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-04 02:13:12
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Family\LOCALS~1\Temp\pgldypoc.sys


—- System - GMER 1.0.15 —-

SSDT 89227D60 ZwCreateKey
SSDT 89228F00 ZwCreateMutant
SSDT 89227260 ZwCreateProcess
SSDT 89227520 ZwCreateProcessEx
SSDT 89228BC0 ZwCreateThread
SSDT 892282E0 ZwDeleteKey
SSDT 892285A0 ZwDeleteValueKey
SSDT 89228D60 ZwLoadDriver
SSDT 892277E0 ZwOpenProcess
SSDT 892290A0 ZwSetSystemInformation
SSDT 89228020 ZwSetValueKey
SSDT 89227AA0 ZwTerminateProcess
SSDT 89228A20 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\ACPI \Device\00000050 89A9A210
Device \Driver\ACPI \Device\00000055 89A9A210
Device \Driver\ACPI \Device\00000061 89A9A210

AttachedDevice \Driver\Tcpip \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)

Device \Driver\ACPI \Device\00000056 89A9A210
Device \Driver\ACPI \Device\00000062 89A9A210
Device \Driver\ACPI \Device\00000057 89A9A210
Device \Driver\ACPI \Device\00000063 89A9A210
Device \Driver\ACPI \Device\00000070 89A9A210
Device \Driver\ACPI \Device\00000058 89A9A210
Device \Driver\ACPI \Device\00000065 89A9A210
Device \Driver\ACPI \Device\00000059 89A9A210
Device \Driver\ACPI \Device\00000066 89A9A210
Device \Driver\ACPI \Device\00000073 89A9A210
Device \Driver\ACPI \Device\00000067 89A9A210
Device \Driver\ACPI \Device\00000081 89A9A210
Device \Driver\ACPI \Device\00000083 89A9A210
Device \Driver\ACPI \Device\0000004a 89A9A210
Device \Driver\ACPI \Device\00000079 89A9A210
Device \Driver\ACPI \Device\0000004c 89A9A210
Device \Driver\ACPI \Device\0000004d 89A9A210
Device \Driver\ACPI \Device\0000005a 89A9A210
Device \Driver\ACPI \Device\0000004e 89A9A210
Device \Driver\ACPI \Device\0000005c 89A9A210
Device \Driver\ACPI \Device\0000004f 89A9A210

AttachedDevice \Driver\Tcpip \Device\Udp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)

Device \Driver\ACPI \Device\0000007b 89A9A210
Device \Driver\ACPI \Device\0000006f 89A9A210
Device \Driver\ACPI \Device\0000007d 89A9A210
Device \Driver\ACPI \Device\0000007f 89A9A210

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR

—- EOF - GMER 1.0.15 —-


–Tom vonHatten
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Ran ComboFix. There are multiple users on this machine, so I selected the one I ran ComboFix in when the machine rebooted. It didn't seem to cause any problems. I'm taking the machine off the LAN until told it's OK. The Trend Micro Antivirus and firewall are off right now.

Here is the ComboFix.txt log file:


ComboFix 10-03-03.07 - Family 03/04/2010 9:09.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1149 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro Internet Security Pro *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Family\LOCALS~1\Temp\clclean.0001.dir.0006\~df394b.tmp
c:\documents and settings\Family\Local Settings\Temp\clclean.0001.dir.0006\~df394b.tmp
c:\documents and settings\Grace\Local Settings\Application Data\ximhwj
c:\documents and settings\Grace\Local Settings\Application Data\ximhwj\ysbksftav.exe
c:\windows\system32\Data
c:\windows\system32\service
c:\windows\system32\service\03032010_TIS17_SfFniAU.log
c:\windows\system32\service\27022010_TIS17_SfFniAU.log
c:\windows\usp10.dll

Infected copy of c:\windows\system32\autochk.exe was found and disinfected
Restored copy from - c:\i386\autochk.exe

.
original MBR restored successfully !
.
((((((((((((((((((((((((( Files Created from 2010-02-04 to 2010-03-04 )))))))))))))))))))))))))))))))
.

2010-03-04 03:00 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-03-04 03:00 . 2010-03-04 03:00 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-04 02:56 . 2010-03-04 02:56 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-03-04 02:56 . 2010-03-04 03:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-03-04 02:56 . 2010-03-04 02:56 ——– d—–w- c:\program files\Lavasoft
2010-03-03 04:53 . 2010-03-03 04:53 ——– d—–w- c:\documents and settings\HelpAssistant\WINDOWS
2010-03-03 04:53 . 2010-03-03 04:53 ——– d—–w- c:\documents and settings\HelpAssistant\UserData
2010-03-03 04:53 . 2010-03-03 04:53 ——– d—–w- c:\documents and settings\HelpAssistant\outlook express contact
2010-03-01 02:38 . 2010-03-01 02:38 ——– d—–w- c:\windows\U5ENW5ENW5ENW5EN
2010-03-01 02:38 . 2010-03-01 02:38 762 —-a-w- c:\documents and settings\Family\Local Settings\Application Data\syssvc.exe
2010-02-28 14:49 . 2010-02-28 14:54 ——– d—–w- c:\documents and settings\Grace\Application Data\HPAppData
2010-02-28 07:23 . 2010-02-28 07:23 ——– d—–w- c:\documents and settings\Rose\Local Settings\Application Data\Trend Micro
2010-02-27 07:06 . 2010-02-27 07:06 ——– d—–w- c:\program files\Avery Dennison
2010-02-27 07:05 . 2010-02-27 07:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Avery
2010-02-26 21:01 . 2010-03-03 18:27 ——– d—–w- c:\documents and settings\Family\Application Data\HPAppData
2010-02-24 16:47 . 2010-02-24 16:47 ——– d—–w- c:\documents and settings\All Users\Application Data\WEBREG
2010-02-24 16:46 . 2010-02-24 16:46 ——– d—–w- c:\documents and settings\Family\Local Settings\Application Data\HP
2010-02-24 16:45 . 2007-07-09 18:13 16496 —-a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-02-24 16:45 . 2007-07-09 18:13 49920 —-a-r- c:\windows\system32\drivers\HPZid412.sys
2010-02-24 16:44 . 2008-08-12 16:58 314880 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp082.dll
2010-02-24 16:44 . 2008-08-12 16:58 118272 —-a-w- c:\windows\system32\hpf3l082.dll
2010-02-24 16:44 . 2008-08-22 12:24 271704 —-a-r- c:\windows\system32\hpzids01.dll
2010-02-24 16:44 . 2007-07-09 18:13 21568 —-a-r- c:\windows\system32\drivers\HPZius12.sys
2010-02-24 16:44 . 2007-07-09 18:13 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-02-24 16:44 . 2008-10-06 19:11 741376 —-a-r- c:\windows\system32\hpwwiax5.dll
2010-02-24 16:44 . 2008-10-06 19:11 966656 —-a-r- c:\windows\system32\hpwtiop4.dll
2010-02-24 16:44 . 2007-07-09 18:13 364544 —-a-r- c:\windows\system32\hppldcoi.dll
2010-02-24 16:44 . 2007-07-06 18:48 294912 —-a-r- c:\windows\system32\hpovst11.dll
2010-02-24 16:44 . 2004-08-04 04:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-24 16:44 . 2004-08-04 04:58 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2010-02-24 05:11 . 2010-02-24 05:11 ——– d—–w- c:\documents and settings\Family\Application Data\HP
2010-02-24 05:03 . 2010-02-24 05:03 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-02-24 04:58 . 2010-02-24 04:58 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-02-24 04:58 . 2010-02-24 04:58 ——– d—–w- c:\windows\hpojp8500a909
2010-02-24 04:49 . 2010-02-24 04:49 ——– d—–w- c:\program files\Common Files\HP
2010-02-24 04:49 . 2010-02-24 04:49 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2010-02-24 04:49 . 2010-02-24 04:49 ——– d—–w- c:\program files\Hewlett-Packard
2010-02-24 04:49 . 2010-03-04 03:00 ——– dc—-w- c:\windows\system32\DRVSTORE
2010-02-24 04:36 . 2010-02-24 16:54 188920 —-a-w- c:\windows\hpwins22.dat
2010-02-24 04:36 . 2008-10-25 09:40 2979 ——w- c:\windows\hpwmdl22.dat
2010-02-19 17:05 . 2010-02-19 17:05 ——– d—–w- c:\program files\Windows Media Connect 2
2010-02-19 17:03 . 2010-02-19 17:04 ——– d—–w- c:\windows\system32\drivers\UMDF
2010-02-19 17:03 . 2010-02-19 17:03 ——– d—–w- c:\windows\system32\LogFiles
2010-02-16 03:20 . 2010-02-17 23:56 ——– d—–w- C:\swmeets3
2010-02-16 03:18 . 2010-02-16 03:18 ——– d—–w- c:\program files\Common Files\dao
2010-02-16 03:18 . 2010-02-16 03:18 ——– d—–w- c:\program files\Common Files\Business Objects
2010-02-16 03:18 . 2010-02-16 03:18 ——– d—–w- C:\Hy-Sport

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-04 15:17 . 2007-01-30 03:13 17408 —-a-w- c:\windows\system32\rpcnetp.exe
2010-03-04 15:17 . 2006-11-28 16:46 56680 —-a-w- c:\windows\system32\Rpcnet.dll
2010-03-04 14:51 . 2007-01-30 03:14 17408 —-a-w- c:\windows\system32\rpcnetp.dll
2010-03-04 03:00 . 2010-03-04 03:00 95024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-03-04 03:00 . 2010-03-04 03:00 598368 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-03-04 03:00 . 2010-03-04 03:00 884176 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-03-04 03:00 . 2010-03-04 03:00 566608 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2010-03-04 03:00 . 2010-03-04 03:00 15880 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-03-04 03:00 . 2010-03-04 03:00 211064 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-03-04 03:00 . 2010-03-04 03:00 393896 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-03-04 02:59 . 2010-03-04 02:59 562272 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-03-04 02:59 . 2010-03-04 02:59 221408 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-03-04 02:59 . 2010-03-04 02:59 390320 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-03-04 02:59 . 2010-03-04 02:59 167312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-03-04 02:59 . 2010-03-04 02:59 1230160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-03-04 02:59 . 2010-03-04 02:59 247120 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-03-04 02:59 . 2010-03-04 02:59 6330848 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-03-04 02:59 . 2010-03-04 02:59 329048 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-03-04 02:59 . 2010-03-04 02:59 94712 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-03-04 02:59 . 2010-03-04 02:59 17480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-03-04 02:59 . 2010-03-04 02:59 961984 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-03-04 02:58 . 2010-03-04 02:58 835312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-03-04 02:58 . 2010-03-04 02:58 842992 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-03-04 02:58 . 2010-03-04 02:58 1593320 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-03-04 02:58 . 2010-03-04 02:58 815184 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-03-04 02:58 . 2010-03-04 02:58 1229232 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-03-03 22:10 . 2006-11-16 18:35 ——– d—–w- c:\program files\Trend Micro
2010-03-03 17:11 . 2006-11-16 18:36 ——– d—–w- c:\program files\Google
2010-02-28 22:35 . 2006-11-21 23:06 124416 —-a-w- c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-28 14:49 . 2006-12-14 21:46 124416 —-a-w- c:\documents and settings\Grace\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-24 05:03 . 2009-02-13 20:27 ——– d—–w- c:\program files\HP
2010-02-17 23:52 . 2006-11-22 19:28 ——– d—–w- c:\documents and settings\Family\Application Data\U3
2010-02-16 03:19 . 2010-02-16 03:19 9662 —-a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{ED1D569E-3DA4-4D59-A1C2-80DFF72C962F}\SwimMM3.exe1_ED1D569E3DA44D59A1C280DFF72C962F.exe
2010-02-16 03:19 . 2010-02-16 03:19 9662 —-a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{ED1D569E-3DA4-4D59-A1C2-80DFF72C962F}\ARPPRODUCTICON.exe
2010-02-04 15:53 . 2010-03-04 02:56 2954656 -c–a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-01-22 23:16 . 2007-11-11 15:35 2828 –sha-w- c:\windows\system32\KGyGaAvL.sys
2010-01-22 23:01 . 2007-11-02 19:08 ——– d—–w- c:\documents and settings\Family\Application Data\Corel
2010-01-22 23:00 . 2007-11-11 15:35 88 –sh–r- c:\windows\system32\49C0C3FFF3.sys
2010-01-05 10:00 . 2004-08-11 23:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-11 23:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-11 23:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-01-03 21:44 . 2009-12-16 17:48 ——– d—–w- c:\program files\Readerware
2009-12-31 16:14 . 2004-08-11 23:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 18:58 . 2009-12-16 19:11 59920 —-a-w- c:\windows\system32\drivers\tmactmon.sys
2009-12-16 18:58 . 2009-12-16 19:11 50704 —-a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-12-16 18:58 . 2009-12-16 19:11 158224 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-12-16 18:58 . 2009-12-16 18:58 89872 —-a-w- c:\windows\system32\drivers\tmtdi.sys
2009-12-16 18:58 . 2009-12-16 18:58 36368 —-a-w- c:\windows\system32\drivers\tmpreflt.sys
2009-12-16 18:58 . 2009-12-16 18:58 339984 —-a-w- c:\windows\system32\drivers\TM_CFW.sys
2009-12-16 18:58 . 2009-12-16 18:58 225808 —-a-w- c:\windows\system32\drivers\tmxpflt.sys
2009-12-16 18:58 . 2009-12-16 18:58 1223832 —-a-w- c:\windows\system32\drivers\vsapint.sys
2009-12-16 12:58 . 2004-08-11 23:11 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2004-08-11 23:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:11 . 2004-08-11 23:00 2142720 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 17:35 . 2004-08-04 04:59 2020864 —-a-w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 24576]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-17 389120]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-20 68856]
"WinCalendar"="c:\program files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" [2009-01-08 74928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-09-13 1384448]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 282624]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-09 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"MBMon"="CTMBHA.DLL" [2006-06-29 1355042]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2006-02-16 1118208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-11-16 169984]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-08-22 184320]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-22 1191936]
"hpbdfawep"="c:\program files\HP\Dfawep\bin\hpbdfawep.exe" [2007-04-25 954368]
"WinCalendar"="c:\program files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" [2009-01-08 74928]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-12-16 1020248]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"WinCalendar"="c:\program files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" [2009-01-08 74928]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-16 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
Timex Data Link USB Launcher.lnk - c:\program files\Timex\Data Link USB\DataLinkLauncher.exe [2007-3-3 40960]
Timex Trainer Launcher.lnk - c:\program files\Timex\Timex Trainer\TBEggLaunch.exe [2007-3-30 61440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"3246:TCP"= 3246:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [03/03/2010 9:00 PM 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [02/04/2010 9:52 AM 1229232]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [12/16/2009 12:58 PM 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [12/16/2009 12:58 PM 339984]
R3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [12/16/2009 1:11 PM 50704]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [12/16/2009 1:11 PM 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [12/16/2009 1:11 PM 689416]
S3 USA19W;USA19W;c:\windows\system32\drivers\usa19w2k.sys [02/06/2007 4:29 PM 292920]
S3 USA19w2KP;Keyspan High Speed USB Serial Adapter Port Driver;c:\windows\system32\drivers\usa19w2kp.sys [02/06/2007 4:29 PM 40848]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-03-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 15:52]

2010-02-24 c:\windows\Tasks\WebReg Officejet Pro 8500 A909a Series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2008-10-17 01:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6061116
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Family\Application Data\Mozilla\Firefox\Profiles\sw6khvia.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFTMUFEHelper.dll
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFToolbarComm.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-acyymisc - c:\documents and settings\Grace\Local Settings\Application Data\ximhwj\ysbksftav.exe
AddRemove-Imation Disk Manager II Service - c:\docume~1\Family\LOCALS~1\Temp\Imation Disk Manager II.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-04 09:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A4002A8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecfc3
\Driver\ACPI -> 0x8a4002a8
\Driver\atapi -> atapi.sys @ 0xb9f117b4
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x80581684
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x80581684
NDIS: Broadcom 440x 10/100 Integrated Controller -> SendCompleteHandler -> 0x898d6690
PacketIndicateHandler -> NDIS.sys @ 0xb9e15b21
SendHandler -> NDIS.sys @ 0xb9df387b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 61 !
copy of MBR has been found in sector 0x0BA50E41
malicious code @ sector 0x0BA50E44 !
PE file found in sector at 0x0BA50E5A !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1356)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(4688)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\SYSTEM32\Rpcnet.exe
c:\program files\Trend Micro\Internet Security\SfCtlCom.exe
c:\windows\system32\UStorSrv.exe
c:\windows\system32\fxssvc.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
c:\program files\Trend Micro\BM\TMBMSRV.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\stsystra.exe
c:\windows\system32\Rundll32.exe
c:\docume~1\Family\LOCALS~1\Temp\clclean.0001
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2010-03-04 09:30:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-04 15:30

Pre-Run: 69,241,004,032 bytes free
Post-Run: 69,975,052,288 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 4914C8BFBAF43A7CBB39D1E03E84C65D



–Tom vonHatten
Hi,

Unfortunately you are infected with a rootkit infection which is not easy to clean.

I will be asking for a number of scans with different tools often asking you to repeat the steps several times.

If you stick with me through it, it can be cleaned.

Be very careful about hard shut downs, try not to do them if you can help it.

First we'll clean up what we can see with combofix, then we will set about cleaning the rootkit infection.

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Dell_Inspiron_timing_out_t110672.html&view=findpost&p=638243#entry638243

Collect::
c:\documents and settings\Family\Local Settings\Application Data\syssvc.exe

Folder::
c:\windows\U5ENW5ENW5ENW5EN

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"=-
"52344:TCP"=-
"3246:TCP"=-
"2479:TCP"=-
"3389:TCP"=-

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = 

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Ran ComboFix with the script.

Here's the file–TvH


ComboFix 10-03-03.07 - Family 03/04/2010 10:40:49.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1308 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Family\Desktop\CFScript.txt
AV: Trend Micro Internet Security Pro *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}

file zipped: c:\documents and settings\Family\Local Settings\Application Data\syssvc.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Family\LOCALS~1\Temp\clclean.0001.dir.0001\~df394b.tmp
c:\documents and settings\Family\Local Settings\Application Data\syssvc.exe
c:\documents and settings\Family\Local Settings\Temp\clclean.0001.dir.0001\~df394b.tmp
c:\windows\U5ENW5ENW5ENW5EN

.
original MBR restored successfully !
.
((((((((((((((((((((((((( Files Created from 2010-02-04 to 2010-03-04 )))))))))))))))))))))))))))))))
.

2010-03-04 03:00 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-03-04 03:00 . 2010-03-04 03:00 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-04 03:00 . 2010-03-04 03:00 95024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-03-04 03:00 . 2010-03-04 03:00 598368 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-03-04 03:00 . 2010-03-04 03:00 884176 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-03-04 03:00 . 2010-03-04 03:00 566608 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2010-03-04 03:00 . 2010-03-04 03:00 15880 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-03-04 03:00 . 2010-03-04 03:00 211064 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-03-04 03:00 . 2010-03-04 03:00 393896 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-03-04 02:59 . 2010-03-04 02:59 562272 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-03-04 02:59 . 2010-03-04 02:59 221408 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-03-04 02:59 . 2010-03-04 02:59 390320 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-03-04 02:59 . 2010-03-04 02:59 167312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-03-04 02:59 . 2010-03-04 02:59 1230160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-03-04 02:59 . 2010-03-04 02:59 247120 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-03-04 02:59 . 2010-03-04 02:59 6330848 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-03-04 02:59 . 2010-03-04 02:59 329048 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-03-04 02:59 . 2010-03-04 02:59 94712 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-03-04 02:59 . 2010-03-04 02:59 17480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-03-04 02:59 . 2010-03-04 02:59 961984 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-03-04 02:58 . 2010-03-04 02:58 835312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-03-04 02:58 . 2010-03-04 02:58 842992 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-03-04 02:58 . 2010-03-04 02:58 1593320 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-03-04 02:58 . 2010-03-04 02:58 815184 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-03-04 02:58 . 2010-03-04 02:58 1229232 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-03-04 02:56 . 2010-03-04 02:56 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-03-04 02:56 . 2010-02-04 15:53 2954656 -c–a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-03-04 02:56 . 2010-03-04 03:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-03-04 02:56 . 2010-03-04 02:56 ——– d—–w- c:\program files\Lavasoft
2010-03-03 04:53 . 2010-03-03 04:53 ——– d—–w- c:\documents and settings\HelpAssistant\WINDOWS
2010-03-03 04:53 . 2010-03-03 04:53 ——– d—–w- c:\documents and settings\HelpAssistant\UserData
2010-03-03 04:53 . 2010-03-03 04:53 ——– d—–w- c:\documents and settings\HelpAssistant\outlook express contact
2010-02-28 14:49 . 2010-02-28 14:54 ——– d—–w- c:\documents and settings\Grace\Application Data\HPAppData
2010-02-28 07:23 . 2010-02-28 07:23 ——– d—–w- c:\documents and settings\Rose\Local Settings\Application Data\Trend Micro
2010-02-27 07:06 . 2010-02-27 07:06 ——– d—–w- c:\program files\Avery Dennison
2010-02-27 07:05 . 2010-02-27 07:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Avery
2010-02-26 21:01 . 2010-03-03 18:27 ——– d—–w- c:\documents and settings\Family\Application Data\HPAppData
2010-02-24 16:47 . 2010-02-24 16:47 ——– d—–w- c:\documents and settings\All Users\Application Data\WEBREG
2010-02-24 16:46 . 2010-02-24 16:46 ——– d—–w- c:\documents and settings\Family\Local Settings\Application Data\HP
2010-02-24 16:45 . 2007-07-09 18:13 16496 —-a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-02-24 16:45 . 2007-07-09 18:13 49920 —-a-r- c:\windows\system32\drivers\HPZid412.sys
2010-02-24 16:44 . 2008-08-12 16:58 314880 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp082.dll
2010-02-24 16:44 . 2008-08-12 16:58 118272 —-a-w- c:\windows\system32\hpf3l082.dll
2010-02-24 16:44 . 2008-08-22 12:24 271704 —-a-r- c:\windows\system32\hpzids01.dll
2010-02-24 16:44 . 2007-07-09 18:13 21568 —-a-r- c:\windows\system32\drivers\HPZius12.sys
2010-02-24 16:44 . 2007-07-09 18:13 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-02-24 16:44 . 2008-10-06 19:11 741376 —-a-r- c:\windows\system32\hpwwiax5.dll
2010-02-24 16:44 . 2008-10-06 19:11 966656 —-a-r- c:\windows\system32\hpwtiop4.dll
2010-02-24 16:44 . 2007-07-09 18:13 364544 —-a-r- c:\windows\system32\hppldcoi.dll
2010-02-24 16:44 . 2007-07-06 18:48 294912 —-a-r- c:\windows\system32\hpovst11.dll
2010-02-24 16:44 . 2004-08-04 04:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-24 16:44 . 2004-08-04 04:58 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2010-02-24 05:11 . 2010-02-24 05:11 ——– d—–w- c:\documents and settings\Family\Application Data\HP
2010-02-24 05:03 . 2010-02-24 05:03 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-02-24 04:58 . 2010-02-24 04:58 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-02-24 04:58 . 2010-02-24 04:58 ——– d—–w- c:\windows\hpojp8500a909
2010-02-24 04:49 . 2010-02-24 04:49 ——– d—–w- c:\program files\Common Files\HP
2010-02-24 04:49 . 2010-02-24 04:49 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2010-02-24 04:49 . 2010-02-24 04:49 ——– d—–w- c:\program files\Hewlett-Packard
2010-02-24 04:49 . 2010-03-04 03:00 ——– dc—-w- c:\windows\system32\DRVSTORE
2010-02-24 04:36 . 2010-02-24 16:54 188920 —-a-w- c:\windows\hpwins22.dat
2010-02-24 04:36 . 2008-10-25 09:40 2979 ——w- c:\windows\hpwmdl22.dat
2010-02-19 17:05 . 2010-02-19 17:05 ——– d—–w- c:\program files\Windows Media Connect 2
2010-02-19 17:03 . 2010-02-19 17:04 ——– d—–w- c:\windows\system32\drivers\UMDF
2010-02-19 17:03 . 2010-02-19 17:03 ——– d—–w- c:\windows\system32\LogFiles
2010-02-16 03:20 . 2010-02-17 23:56 ——– d—–w- C:\swmeets3
2010-02-16 03:19 . 2010-02-16 03:19 9662 —-a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{ED1D569E-3DA4-4D59-A1C2-80DFF72C962F}\SwimMM3.exe1_ED1D569E3DA44D59A1C280DFF72C962F.exe
2010-02-16 03:19 . 2010-02-16 03:19 9662 —-a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{ED1D569E-3DA4-4D59-A1C2-80DFF72C962F}\ARPPRODUCTICON.exe
2010-02-16 03:18 . 2010-02-16 03:18 ——– d—–w- c:\program files\Common Files\dao
2010-02-16 03:18 . 2010-02-16 03:18 ——– d—–w- c:\program files\Common Files\Business Objects
2010-02-16 03:18 . 2010-02-16 03:18 ——– d—–w- C:\Hy-Sport

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-04 16:35 . 2007-01-30 03:13 17408 —-a-w- c:\windows\system32\rpcnetp.exe
2010-03-04 16:35 . 2006-11-28 16:46 56680 —-a-w- c:\windows\system32\Rpcnet.dll
2010-03-04 14:51 . 2007-01-30 03:14 17408 —-a-w- c:\windows\system32\rpcnetp.dll
2010-03-03 22:10 . 2006-11-16 18:35 ——– d—–w- c:\program files\Trend Micro
2010-03-03 17:11 . 2006-11-16 18:36 ——– d—–w- c:\program files\Google
2010-02-28 22:35 . 2006-11-21 23:06 124416 —-a-w- c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-28 14:49 . 2006-12-14 21:46 124416 —-a-w- c:\documents and settings\Grace\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-24 05:03 . 2009-02-13 20:27 ——– d—–w- c:\program files\HP
2010-02-17 23:52 . 2006-11-22 19:28 ——– d—–w- c:\documents and settings\Family\Application Data\U3
2010-01-22 23:16 . 2007-11-11 15:35 2828 –sha-w- c:\windows\system32\KGyGaAvL.sys
2010-01-22 23:01 . 2007-11-02 19:08 ——– d—–w- c:\documents and settings\Family\Application Data\Corel
2010-01-22 23:00 . 2007-11-11 15:35 88 –sh–r- c:\windows\system32\49C0C3FFF3.sys
2010-01-05 10:00 . 2004-08-11 23:00 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-11 23:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-11 23:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-01-03 21:44 . 2009-12-16 17:48 ——– d—–w- c:\program files\Readerware
2009-12-31 16:14 . 2004-08-11 23:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 18:58 . 2009-12-16 19:11 59920 —-a-w- c:\windows\system32\drivers\tmactmon.sys
2009-12-16 18:58 . 2009-12-16 19:11 50704 —-a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-12-16 18:58 . 2009-12-16 19:11 158224 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-12-16 18:58 . 2009-12-16 18:58 89872 —-a-w- c:\windows\system32\drivers\tmtdi.sys
2009-12-16 18:58 . 2009-12-16 18:58 36368 —-a-w- c:\windows\system32\drivers\tmpreflt.sys
2009-12-16 18:58 . 2009-12-16 18:58 339984 —-a-w- c:\windows\system32\drivers\TM_CFW.sys
2009-12-16 18:58 . 2009-12-16 18:58 225808 —-a-w- c:\windows\system32\drivers\tmxpflt.sys
2009-12-16 18:58 . 2009-12-16 18:58 1223832 —-a-w- c:\windows\system32\drivers\vsapint.sys
2009-12-16 12:58 . 2004-08-11 23:11 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2004-08-11 23:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:11 . 2004-08-11 23:00 2142720 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 17:35 . 2004-08-04 04:59 2020864 ——w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 24576]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-17 389120]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-20 68856]
"WinCalendar"="c:\program files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" [2009-01-08 74928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-09-13 1384448]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 282624]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-09 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"MBMon"="CTMBHA.DLL" [2006-06-29 1355042]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2006-02-16 1118208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-11-16 169984]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-08-22 184320]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-22 1191936]
"hpbdfawep"="c:\program files\HP\Dfawep\bin\hpbdfawep.exe" [2007-04-25 954368]
"WinCalendar"="c:\program files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" [2009-01-08 74928]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-12-16 1020248]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"WinCalendar"="c:\program files\Sapro Systems WinCalendar\WinCalendar_SysTray.exe" [2009-01-08 74928]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-16 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
Timex Data Link USB Launcher.lnk - c:\program files\Timex\Data Link USB\DataLinkLauncher.exe [2007-3-3 40960]
Timex Trainer Launcher.lnk - c:\program files\Timex\Timex Trainer\TBEggLaunch.exe [2007-3-30 61440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [03/03/2010 9:00 PM 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [02/04/2010 9:52 AM 1229232]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [12/16/2009 12:58 PM 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [12/16/2009 12:58 PM 339984]
R3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [12/16/2009 1:11 PM 50704]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [12/16/2009 1:11 PM 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [12/16/2009 1:11 PM 689416]
S3 USA19W;USA19W;c:\windows\system32\drivers\usa19w2k.sys [02/06/2007 4:29 PM 292920]
S3 USA19w2KP;Keyspan High Speed USB Serial Adapter Port Driver;c:\windows\system32\drivers\usa19w2kp.sys [02/06/2007 4:29 PM 40848]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-03-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 15:52]

2010-02-24 c:\windows\Tasks\WebReg Officejet Pro 8500 A909a Series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2008-10-17 01:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=6061116
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Family\Application Data\Mozilla\Firefox\Profiles\sw6khvia.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFTMUFEHelper.dll
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFToolbarComm.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-04 10:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x89AAF308]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecfc3
\Driver\ACPI -> 0x89aaf308
\Driver\atapi -> atapi.sys @ 0xb9f117b4
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x80581684
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x80581684
NDIS: Broadcom 440x 10/100 Integrated Controller -> SendCompleteHandler -> 0x8991d690
PacketIndicateHandler -> NDIS.sys @ 0xb9e15b21
SendHandler -> NDIS.sys @ 0xb9df387b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x0BA50E41
malicious code @ sector 0x0BA50E44 !
PE file found in sector at 0x0BA50E5A !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1348)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2010-03-04 10:47:20
ComboFix-quarantined-files.txt 2010-03-04 16:47
ComboFix2.txt 2010-03-04 15:30

Pre-Run: 69,843,058,688 bytes free
Post-Run: 69,805,895,680 bytes free

- - End Of File - - 40137C0B791531824D13091BBB351115
Upload was successful
Hi,

Please do the following:

You may want to write down or print the following for reference.

Please download this file to your desktop.

Close out all other open programs and windows.

Double click the file to run it and follow any prompts.


When the tool completes, click Start>Run and type the following bolded command, then hit Enter.

mbr -f

Now, please do the Start>Run>mbr -f command a second time.

Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.

Give it about 5 minutes, then click Start>Run and type the following bolded command, then hit Enter.

helpasst -mbrt

Make sure you leave a space between helpasst and -mbrt !

When it completes, a log will open.
Please post the contents of that log
Followed the instructions you gave me.

The log file follows–TvH

C:\Documents and Settings\Family\Desktop\HelpAsst_mebroot_fix.exe
03/04/2010 at 12:24:41.82

HelpAssistant account was found to be Active ~ attempting to de-activate

Full Name Remote Desktop Help Assistant Account
Account active Yes
Local Group Memberships *Administrators
The command completed successfully.

HelpAssistant account successfully set inactive
termsrv32.dll found ~ attempting to remove
termsrv32.dll successfully removed
HelpAssistant profile found in registry ~ backing up and removing S-1-5-21-1762281929-1702226215-140787564-1005.bak
HelpAssistant profile directory exists at C:\Documents and Settings\HelpAssistant ~ attempting to remove

~ Not all HelpAssistant files sucessfully Moved ~
Remove on reboot: C:\DOCUME~1\HELPAS~1\NTUSER.DAT
Remove on reboot: C:\DOCUME~1\HELPAS~1\NTUSER~1.LOG
Remove on reboot: C:\Documents and Settings\HelpAssistant

mbr infection detected ~ running mbr -f

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\ACPI -> 0x8a4ddbf8
NDIS: Broadcom 440x 10/100 Integrated Controller -> SendCompleteHandler -> 0x89935690
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x0BA50E41
malicious code @ sector 0x0BA50E44 !
PE file found in sector at 0x0BA50E5A !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
original MBR restored successfully !

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on 03/04/2010 at 13:02:34.10

Full Name Remote Desktop Help Assistant Account
Account active No
Local Group Memberships
The command completed successfully.

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x0BA50E41
malicious code @ sector 0x0BA50E44 !
PE file found in sector at 0x0BA50E5A !


~~ EOF ~~
Yes, that looks good. Please run DDS and provide a fresh DDS Log also advise how your computer is running and if you have any outstanding issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI