This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Take a look at my Log FIle!

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:08:16 AM, on 03/05/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Software Master Toolbar - {00725d68-069b-4095-9ff1-e7469c0e95df} - C:\Program Files\Software_Master\prxtbSoft.dll
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
O2 - BHO: Software Master - {00725d68-069b-4095-9ff1-e7469c0e95df} - C:\Program Files\Software_Master\prxtbSoft.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O3 - Toolbar: Software Master Toolbar - {00725d68-069b-4095-9ff1-e7469c0e95df} - C:\Program Files\Software_Master\prxtbSoft.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: AutorunsDisabled
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.5.0_10) -
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{84684C71-A2D3-42EB-BF35-2F709D80A0FA}: NameServer = 192.168.2.1
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG8\Toolbar\ToolbarBroker.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: CLDTVHNService - Unknown owner - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c9316637dc9d00) (gupdate1c9316637dc9d00) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCPalSrvHost - Unknown owner - C:\Program Files\PCPal\PCPalSrvHost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 10470 bytes
what symptoms are you experiencing?
why are you still running SP2? You've been a member of this forum long enough that you should be fully updated, is this your machine?

please do the following

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Yes it is my Desktop PC….I uploaded a log file from the wife's Laptop a while back and the problems were sloved on her unit……As for sp2 Windows XP is updated automatically for me…….If we need to do something there let me know….Thanks!

Here's what you asked for:

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 9:00:34.31 on 03/06/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.301 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\arservice.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
svchost.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Compaq_Administrator\Desktop\dds.com
.
============== Pseudo HJT Report ===============
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Software Master Toolbar: {00725d68-069b-4095-9ff1-e7469c0e95df} - c:\program files\software_master\prxtbSoft.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: IE7pro BHO: {00011268-e188-40df-a514-835fcd78b1bf} - c:\program files\ie7pro\IE7pro.dll
BHO: Software Master Toolbar: {00725d68-069b-4095-9ff1-e7469c0e95df} - c:\program files\software_master\prxtbSoft.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar3.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\webhelper.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: Software Master Toolbar: {00725d68-069b-4095-9ff1-e7469c0e95df} - c:\program files\software_master\prxtbSoft.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\wkcalrem.lnk - c:\program files\common files\microsoft shared\works shared\WkCalRem.exe
StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\autoru~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\autorunsdisabled\wkcalrem.lnk.disabled
StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\autorunsdisabled\wordweb.lnk.disabled
TCP: {84684C71-A2D3-42EB-BF35-2F709D80A0FA} = 192.168.2.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\w14redor.default\
FF - prefs.js: browser.startup.homepage - hxxp://mirostart.com/?cfg=2-365-0-2Miqs
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-9 299984]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2008-1-23 132296]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2008-1-23 25160]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-2-17 67656]
R2 adunidrv;UniDriver for OneCare;c:\windows\system32\drivers\adunidrv.sys [2007-9-25 7168]
R2 advproct;Microsoft Corporation Process Trigger Driver;c:\windows\system32\drivers\advproct.sys [2007-9-25 6656]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R2 CLDTVHNService;CLDTVHNService;c:\program files\directv\directv\kernel\dmp\CLDTVHNService.exe [2009-9-17 75048]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\firewall\cmdagent.exe [2008-1-23 723632]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 ntk_dtv;ntk_dtv;c:\program files\directv\directv\kernel\dmp\ntk_dtv.sys [2009-9-17 119792]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]
S2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\google\update\GoogleUpdate.exe [2008-10-18 133104]
S2 PCPalSrvHost;PCPalSrvHost;c:\program files\pcpal\PCPalSrvHost.exe [2007-10-24 312304]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg8\toolbar\toolbarbroker.exe –> c:\program files\avg\avg8\toolbar\ToolbarBroker.exe [?]
S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\PCD5SRVC.pkms [2006-2-7 21120]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-2-17 12872]
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
.
============= FINISH: 9:02:34.85 ===============



.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 07/13/2006 10:01:56 PM
System Uptime: 03/05/2011 9:18:09 AM (24 hours ago)
.
Motherboard: ASUSTek Computer INC. | | NAGAMI2
Processor: AMD Athlon™ 64 Processor 3800+ | Socket 939 | 2405/199mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 225 GiB total, 196.181 GiB free.
D: is FIXED (FAT32) - 8 GiB total, 0.533 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 93 GiB total, 73.482 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\ABE48311D800
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\ABE48311D800
Service: NIC1394
.
==== System Restore Points ===================
.
RP1: 12/24/2010 10:38:11 AM - System Checkpoint
RP2: 12/24/2010 10:40:20 AM - Restore Operation
RP3: 12/25/2010 11:07:36 AM - System Checkpoint
RP4: 12/26/2010 12:31:44 PM - System Checkpoint
RP5: 12/27/2010 1:39:20 PM - System Checkpoint
RP6: 12/28/2010 2:25:33 PM - System Checkpoint
RP7: 12/29/2010 3:08:29 PM - System Checkpoint
RP8: 12/30/2010 3:17:41 PM - System Checkpoint
RP9: 12/31/2010 3:36:41 PM - System Checkpoint
RP10: 01/01/2011 3:45:54 PM - System Checkpoint
RP11: 01/02/2011 4:45:03 PM - System Checkpoint
RP12: 01/03/2011 5:49:46 PM - System Checkpoint
RP13: 01/04/2011 10:12:33 AM - Restore Operation
RP14: 01/05/2011 12:48:52 PM - System Checkpoint
RP15: 01/06/2011 1:26:05 PM - System Checkpoint
RP16: 01/07/2011 2:40:52 PM - System Checkpoint
RP17: 01/08/2011 2:50:40 PM - System Checkpoint
RP18: 01/09/2011 3:49:34 PM - System Checkpoint
RP19: 01/10/2011 5:41:42 PM - System Checkpoint
RP20: 01/11/2011 6:38:03 PM - System Checkpoint
RP21: 01/12/2011 7:18:34 PM - System Checkpoint
RP22: 01/13/2011 7:33:56 PM - System Checkpoint
RP23: 01/14/2011 7:57:31 PM - System Checkpoint
RP24: 01/15/2011 8:02:59 PM - System Checkpoint
RP25: 01/16/2011 9:02:56 PM - System Checkpoint
RP26: 01/17/2011 9:56:37 PM - System Checkpoint
RP27: 01/18/2011 11:03:31 PM - System Checkpoint
RP28: 01/19/2011 11:56:32 PM - System Checkpoint
RP29: 01/21/2011 12:05:06 AM - System Checkpoint
RP30: 01/22/2011 12:54:31 AM - System Checkpoint
RP31: 01/23/2011 1:54:46 AM - System Checkpoint
RP32: 01/24/2011 2:19:11 AM - System Checkpoint
RP33: 01/25/2011 3:02:46 AM - System Checkpoint
RP34: 01/26/2011 3:23:36 AM - System Checkpoint
RP35: 01/27/2011 3:35:26 AM - System Checkpoint
RP36: 01/28/2011 4:35:25 AM - System Checkpoint
RP37: 01/29/2011 5:35:25 AM - System Checkpoint
RP38: 01/30/2011 5:49:48 AM - System Checkpoint
RP39: 01/31/2011 6:49:48 AM - System Checkpoint
RP40: 02/01/2011 7:49:50 AM - System Checkpoint
RP41: 02/02/2011 8:49:50 AM - System Checkpoint
RP42: 02/03/2011 10:49:47 AM - System Checkpoint
RP43: 02/04/2011 12:26:00 PM - System Checkpoint
RP44: 02/05/2011 2:08:01 PM - System Checkpoint
RP45: 02/06/2011 2:32:23 PM - System Checkpoint
RP46: 02/07/2011 3:30:06 PM - System Checkpoint
RP47: 02/08/2011 4:07:31 PM - System Checkpoint
RP48: 02/09/2011 6:16:31 PM - System Checkpoint
RP49: 02/10/2011 6:59:19 PM - System Checkpoint
RP50: 02/11/2011 7:28:38 PM - System Checkpoint
RP51: 02/12/2011 7:52:25 PM - System Checkpoint
RP52: 02/13/2011 8:40:00 PM - System Checkpoint
RP53: 02/14/2011 10:22:40 PM - System Checkpoint
RP54: 02/15/2011 11:00:04 PM - System Checkpoint
RP55: 02/17/2011 12:00:01 AM - System Checkpoint
RP56: 02/18/2011 12:51:09 AM - System Checkpoint
RP57: 02/19/2011 1:51:08 AM - System Checkpoint
RP58: 02/20/2011 2:51:13 AM - System Checkpoint
RP59: 02/21/2011 3:04:27 AM - System Checkpoint
RP60: 02/22/2011 4:04:35 AM - System Checkpoint
RP61: 02/23/2011 5:04:27 AM - System Checkpoint
RP62: 02/24/2011 6:04:29 AM - System Checkpoint
RP63: 02/25/2011 7:04:29 AM - System Checkpoint
RP64: 02/26/2011 10:52:15 AM - System Checkpoint
RP65: 02/27/2011 11:10:42 AM - System Checkpoint
RP66: 02/28/2011 12:35:41 PM - System Checkpoint
RP67: 03/01/2011 12:37:52 PM - System Checkpoint
RP68: 03/02/2011 1:44:52 PM - System Checkpoint
RP69: 03/03/2011 2:59:04 PM - System Checkpoint
RP70: 03/04/2011 3:07:11 PM - System Checkpoint
RP71: 03/05/2011 3:24:04 PM - System Checkpoint
.
==== Installed Programs ======================
.
1310
1310_Help
1310Tour
1310Trb
Ace Utilities
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.4.2
Advanced WindowsCare Personal
Agere Systems PCI-SV92PP Soft Modem
AiO_Scan
AIOMinimal
AiOSoftware
Apple Application Support
Apple Software Update
ATT-RC Self Support Tool
Audacity 1.2.6
Autodesk MapGuide® Viewer ActiveX Control Release 6.5
AVG 2011
BufferChm
CameraDrivers
CCleaner (remove only)
Chart Navigator
Chinese Traditional Fonts Support For Adobe Reader 8
Chuzzle Deluxe
COMODO Firewall Pro
Compaq Connections (remove only)
Conduit Engine
Cook'n with Pillsbury
Coupon Printer for Windows
CreativeProjects
CreativeProjectsTemplates
CueTour
Customer Experience Enhancement
Destinations
Director
DIRECTV2PC Playback Advisor
DIRECTV2PC™
DISCover
Driver Detective
Enhanced Multimedia Keyboard Solution
ERUNT 1.1j
ESET Online Scanner v3
Extra_POI_Editor_Installer
Fax
Flip Words
Garmin Communicator Plugin
Garmin MapSource
Garmin nRoute
Garmin POI Loader
Garmin Trip and Waypoint Manager v3
Garmin USB Drivers
Garmin WebUpdater
GdiplusUpgrade
Google Desktop
Google Earth
Google Earth Plug-in
Google Update Helper
GPS TrackMaker
Hampton Hotels eDirectory with MultiView Reader
High Definition Audio Driver Package - KB888111
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB893357)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB912024)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Boot Optimizer
HP Driver Diagnostics
HP DVD Play 2.1
HP Image Zone 4.5
HP Photosmart Cameras 4.5
HP Product Assistant
HP PSC & OfficeJet 3.5
HP Rhapsody
HP Software Update
HP Support Overview
HP Update
HpSdpAppCoreApp
HPSystemDiagnostics
IE7pro
Insaniquarium Deluxe
InstantShare
Interactive User’s Guide
iTunes
Java Auto Updater
Java™ 6 Update 21
Kaspersky Online Scanner
LightScribe 1.4.84.1
Mah Jong Quest
Malwarebytes' Anti-Malware
Map of North and Central America
Map of South America
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.0 Hotfix (KB979904)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Away Mode
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Miro
Mozilla Firefox (3.6)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Mystery Case Files
NVIDIA Drivers
NVIDIA nView Desktop Manager
Otto
Outlook Express Quick Backup
Overland
PanoStandAlone
PartyPoker
PC-Doctor 5 for Windows
PCFriendly
PCPal
PDFCreator
Photodex Presenter
PhotoGallery
Poker Superstars
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QFolder
Quicken 2006
Quicken Legal Business Pro 2006
Quicken WillMaker Plus 2006
QuickTime
Readme
RealPlayer
Realtek High Definition Audio Driver
Ricochet Lost Worlds
Scan
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981349)
Serif DrawPlus 4.0
ShareIns
SkinsHP1
Slingo Deluxe
Software Master Toolbar
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spell Checker For OE 2.1
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SpywareBlaster v3.5.1
Super GameHouse Solitaire Vol. 1
SUPERAntiSpyware Free Edition
System Requirements Lab
TaxACT 2006
TaxACT 2007
TaxACT 2008
TaxACT 2008 Georgia
TaxACT 2009
TaxACT 2009 Georgia
TaxACT 2010
TaxACT 2010 Georgia
TaxACT Georgia 2006
TaxACT Georgia 2007
Tennis Titans
TrayApp
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB912945)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB953356)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
VCDS Release 10.6.2
VCDS Release 908.1
Weather Exchange
WebFldrs XP
WebReg
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player Firefox Plugin
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892050
Windows XP Hotfix - KB893066
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB912067
Windows XP Media Center Edition 2005 KB973768
WordWeb
World Championship Checkers (Gold Plus)
WOT for Internet Explorer
.
==== Event Viewer Messages From Past Week ========
.
03/02/2011 7:26:52 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ftsata2
.
==== End Of File ===========================


GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-03-06 09:17:01
Windows 5.1.2600 Service Pack 2 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 WDC_WD2500JS-60NCB1 rev.10.02E02
Running: x8miiwfx.exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kgqiqaob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0xF299CD46]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0xF299C250]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0xF299C8EA]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateKey [0xF299D2C2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0xF299C132]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSection [0xF299E254]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSymbolicLinkObject [0xF299E52C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThread [0xF299BCF8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteKey [0xF299CF2C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteValueKey [0xF299D0DC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDuplicateObject [0xF299BA5A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwLoadDriver [0xF299DED6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0xF299C4D4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenFile [0xF299CB2E]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xF77826C0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenSection [0xF299C764]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenThread [0xF299B902]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRenameKey [0xF299D688]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0xF299D9F0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0xF299DC72]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0xF299E084]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetValueKey [0xF299D488]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0xF299C46E]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSystemDebugControl [0xF299C658]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xF7782770]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xF7782810]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xF77828B0]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 23C8 805012B8 4 Bytes JMP CCF299C8
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF5F92380, 0x550AF5, 0xE8000020]
? C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E1DF4B9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E35203E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E351FBF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E352003 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E351F4B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E351F85 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E352079 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!TrackPopupMenu 7E4650EE 5 Bytes JMP 025595B0 C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Software_Master\tbSoft.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E20176A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] USER32.dll!TrackPopupMenuEx 7E46CD28 5 Bytes JMP 02559710 C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Software_Master\tbSoft.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[732] ole32.dll!OleLoadFromStream 7752A257 5 Bytes JMP 3E35223B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\COMODO\Firewall\cmdagent.exe[1460] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 0040FB50 C:\Program Files\COMODO\Firewall\cmdagent.exe (COMODO Internet Security/COMODO)

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

—- EOF - GMER 1.0.15 —-
Hi

Please do the following:

This next program, ComboFix, is needed to remove the malware entries I see. However…AVG incorrectly targets ComboFix's embedded files. ComboFix will not run with AVG installed. Please uninstall AVG before continuing. You can reinstall it, or another antivirus such as Microsoft Security Essentials, Avira or avast!, after we've used ComboFix to clear the remaining infection.

After uninstalling AVG from the Control Panel, also run the AVG remover from their site.

http://www.avg.com/us-en/download-tools

direct link to the AVG Remover:

http://download.avg.com/filedir/util/suppo…6_2011_1149.exe

You may also use this tool to uninstall AVG:
http://www.appremover.com/appremover/avg/AppRemover.exe

Instructions:
http://www.appremover.com/about/using-appremover.html


NEXT


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 11-03-05.02 - Compaq_Administrator 03/06/2011 10:45:52.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.589 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\z.xml
c:\windows\ST6UNST.000
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2011-02-06 to 2011-03-06 )))))))))))))))))))))))))))))))
.
.
2011-02-15 01:59 . 2011-02-15 02:25 ——– d—–w- C:\ie-spyad_zo
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00725d68-069b-4095-9ff1-e7469c0e95df}"= "c:\program files\Software_Master\prxtbSoft.dll" [2011-01-03 175400]
.
[HKEY_CLASSES_ROOT\clsid\{00725d68-069b-4095-9ff1-e7469c0e95df}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00725d68-069b-4095-9ff1-e7469c0e95df}]
2011-01-03 15:16 175400 —-a-w- c:\program files\Software_Master\prxtbSoft.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-03 15:16 175400 —-a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{00725d68-069b-4095-9ff1-e7469c0e95df}"= "c:\program files\Software_Master\prxtbSoft.dll" [2011-01-03 175400]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-03 175400]
.
[HKEY_CLASSES_ROOT\clsid\{00725d68-069b-4095-9ff1-e7469c0e95df}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{00725D68-069B-4095-9FF1-E7469C0E95DF}"= "c:\program files\Software_Master\prxtbSoft.dll" [2011-01-03 175400]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-03 175400]
.
[HKEY_CLASSES_ROOT\clsid\{00725d68-069b-4095-9ff1-e7469c0e95df}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
WKCALREM.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-6-23 15360]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
wkcalrem.lnk.disabled [2007-9-12 938]
wordweb.lnk.disabled [2007-8-3 1601]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-5-4 27136]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-12-05 15:35 548352 ——w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ SDEarlyDelete \??\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk.disabled]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk.disabled]
backup=c:\windows\pss\Compaq Connections.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk.disabled]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.disabledCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LiveUpdate Notice Service"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)
"LiveUpdate"=3 (0x3)
"ISPwdSvc"=3 (0x3)
"comHost"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
"PCPal"=c:\program files\PCPal\PalAgnt.exe /startup
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"SmartRAM"=e:\advanced windowscare v2\MemCleaner.exe /m
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
""=
"KBD"=c:\hp\KBD\KBD.EXE
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"AlwaysReady Power Message APP"=ARPWRMSG.EXE
"DISCover"=c:\program files\DISC\DISCover.exe
"nwiz"=nwiz.exe /install
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"ehTray"=c:\windows\ehome\ehtray.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" -h
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\DirecTV\\DirecTV\\DIRECTV2PC™.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
.
R2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 133104]
R2 PCPalSrvHost;PCPalSrvHost;c:\program files\PCPal\PCPalSrvHost.exe [2007-10-24 312304]
R3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [2006-02-08 21120]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-12-16 12872]
S1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2009-11-08 132296]
S1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2009-11-08 25160]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-12-16 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-12-16 67656]
S2 adunidrv;UniDriver for OneCare;c:\windows\system32\DRIVERS\adunidrv.sys [2007-09-25 7168]
S2 advproct;Microsoft Corporation Process Trigger Driver;c:\windows\system32\DRIVERS\advproct.sys [2007-09-25 6656]
S2 CLDTVHNService;CLDTVHNService;c:\program files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe [2009-09-17 75048]
S2 ntk_dtv;ntk_dtv;c:\program files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys [2009-09-17 119792]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-03-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2011-03-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2007-11-22 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2007-03-17 20:31]
.
2011-03-06 c:\windows\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 23:36]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: {84684C71-A2D3-42EB-BF35-2F709D80A0FA} = 192.168.2.1
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\
FF - prefs.js: browser.startup.homepage - hxxp://mirostart.com/?cfg=2-365-0-2Miqs
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
Notify-WgaLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-06 11:01
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\PCD5SRVC{8A863ACB-F5F6CC6A-05010003}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3019693388-2064130007-760773113-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(792)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-03-06 11:26:31
ComboFix-quarantined-files.txt 2011-03-06 16:26
ComboFix2.txt 2010-08-16 03:29
.
Pre-Run: 211,539,009,536 bytes free
Post-Run: 211,589,218,304 bytes free
.
- - End Of File - - F9B99148D0DE9EBB0F5306C182CAB0A6
Hi

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5979 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 03/07/2011 7:16:11 AM mbam-log-2011-03-07 (07-16-10).txt Scan type: Quick scan Objects scanned: 172257 Time elapsed: 3 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Esetscan.txt: C:\Documents and Settings\Compaq_Administrator\Application Data\Sun\Java\Deployment\cache\6.0\27\21613a9b-4974af8f multiple threats C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP42\A0006376.exe Win32/SpeedUpMyPC application C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP42\A0006377.exe Win32/SpeedUpMyPC application C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP42\A0006378.exe Win32/SpeedUpMyPC application C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP42\A0006379.exe Win32/SpeedUpMyPC application C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP42\A0006380.exe Win32/SpeedUpMyPC application D:\I386\APPS\APP18921\src\CompaqPresario_Spring06.exe a variant of Win32/AdInstaller application D:\I386\APPS\APP18921\src\HPPavillion_Spring06.exe a variant of Win32/AdInstaller application
Visit ADOBEand download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT


[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 21 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Java cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Download Service Pack 3 from the following location and install it: (It says it is the Windows XP Service Pack 3 Network Installation Package for IT Professionals and Developers , but that is what you want)

http://www.microsoft.com/downloads/en/deta…;displaylang=en

NEXT

Please post a fresh DDS Log and advise how your computer is running now and if there are any outstanding issues
My PC is running much much better now……You did a great job! I knew my unit was infected, because the hard drive would just sit and whine for the longest. Sites were real slow coming up. Things now are back to normal. I have a few programs on board I run now and then to keep thngs clean, but apparently they missed this one……
You can have all the protection on board, and run your software programs to find bugs, etc., but now and then when surfing a bug will get in…..I dumped Comodo a while back and i am using the windows firewall now. I have got to d/load a virus program now. Most likely I will go back to AVG since it's free.

I appreciate WTT. Thanks again for your help.

Lew



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 07/13/2006 10:01:56 PM
System Uptime: 03/07/2011 6:01:59 PM (0 hours ago)
.
Motherboard: ASUSTek Computer INC. | | NAGAMI2
Processor: AMD Athlon™ 64 Processor 3800+ | Socket 939 | 2405/199mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 225 GiB total, 188.211 GiB free.
D: is FIXED (FAT32) - 8 GiB total, 0.533 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 93 GiB total, 73.477 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\ABE48311D800
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\ABE48311D800
Service: NIC1394
.
==== System Restore Points ===================
.
RP1: 12/24/2010 10:38:11 AM - System Checkpoint
RP2: 12/24/2010 10:40:20 AM - Restore Operation
RP3: 12/25/2010 11:07:36 AM - System Checkpoint
RP4: 12/26/2010 12:31:44 PM - System Checkpoint
RP5: 12/27/2010 1:39:20 PM - System Checkpoint
RP6: 12/28/2010 2:25:33 PM - System Checkpoint
RP7: 12/29/2010 3:08:29 PM - System Checkpoint
RP8: 12/30/2010 3:17:41 PM - System Checkpoint
RP9: 12/31/2010 3:36:41 PM - System Checkpoint
RP10: 01/01/2011 3:45:54 PM - System Checkpoint
RP11: 01/02/2011 4:45:03 PM - System Checkpoint
RP12: 01/03/2011 5:49:46 PM - System Checkpoint
RP13: 01/04/2011 10:12:33 AM - Restore Operation
RP14: 01/05/2011 12:48:52 PM - System Checkpoint
RP15: 01/06/2011 1:26:05 PM - System Checkpoint
RP16: 01/07/2011 2:40:52 PM - System Checkpoint
RP17: 01/08/2011 2:50:40 PM - System Checkpoint
RP18: 01/09/2011 3:49:34 PM - System Checkpoint
RP19: 01/10/2011 5:41:42 PM - System Checkpoint
RP20: 01/11/2011 6:38:03 PM - System Checkpoint
RP21: 01/12/2011 7:18:34 PM - System Checkpoint
RP22: 01/13/2011 7:33:56 PM - System Checkpoint
RP23: 01/14/2011 7:57:31 PM - System Checkpoint
RP24: 01/15/2011 8:02:59 PM - System Checkpoint
RP25: 01/16/2011 9:02:56 PM - System Checkpoint
RP26: 01/17/2011 9:56:37 PM - System Checkpoint
RP27: 01/18/2011 11:03:31 PM - System Checkpoint
RP28: 01/19/2011 11:56:32 PM - System Checkpoint
RP29: 01/21/2011 12:05:06 AM - System Checkpoint
RP30: 01/22/2011 12:54:31 AM - System Checkpoint
RP31: 01/23/2011 1:54:46 AM - System Checkpoint
RP32: 01/24/2011 2:19:11 AM - System Checkpoint
RP33: 01/25/2011 3:02:46 AM - System Checkpoint
RP34: 01/26/2011 3:23:36 AM - System Checkpoint
RP35: 01/27/2011 3:35:26 AM - System Checkpoint
RP36: 01/28/2011 4:35:25 AM - System Checkpoint
RP37: 01/29/2011 5:35:25 AM - System Checkpoint
RP38: 01/30/2011 5:49:48 AM - System Checkpoint
RP39: 01/31/2011 6:49:48 AM - System Checkpoint
RP40: 02/01/2011 7:49:50 AM - System Checkpoint
RP41: 02/02/2011 8:49:50 AM - System Checkpoint
RP42: 02/03/2011 10:49:47 AM - System Checkpoint
RP43: 02/04/2011 12:26:00 PM - System Checkpoint
RP44: 02/05/2011 2:08:01 PM - System Checkpoint
RP45: 02/06/2011 2:32:23 PM - System Checkpoint
RP46: 02/07/2011 3:30:06 PM - System Checkpoint
RP47: 02/08/2011 4:07:31 PM - System Checkpoint
RP48: 02/09/2011 6:16:31 PM - System Checkpoint
RP49: 02/10/2011 6:59:19 PM - System Checkpoint
RP50: 02/11/2011 7:28:38 PM - System Checkpoint
RP51: 02/12/2011 7:52:25 PM - System Checkpoint
RP52: 02/13/2011 8:40:00 PM - System Checkpoint
RP53: 02/14/2011 10:22:40 PM - System Checkpoint
RP54: 02/15/2011 11:00:04 PM - System Checkpoint
RP55: 02/17/2011 12:00:01 AM - System Checkpoint
RP56: 02/18/2011 12:51:09 AM - System Checkpoint
RP57: 02/19/2011 1:51:08 AM - System Checkpoint
RP58: 02/20/2011 2:51:13 AM - System Checkpoint
RP59: 02/21/2011 3:04:27 AM - System Checkpoint
RP60: 02/22/2011 4:04:35 AM - System Checkpoint
RP61: 02/23/2011 5:04:27 AM - System Checkpoint
RP62: 02/24/2011 6:04:29 AM - System Checkpoint
RP63: 02/25/2011 7:04:29 AM - System Checkpoint
RP64: 02/26/2011 10:52:15 AM - System Checkpoint
RP65: 02/27/2011 11:10:42 AM - System Checkpoint
RP66: 02/28/2011 12:35:41 PM - System Checkpoint
RP67: 03/01/2011 12:37:52 PM - System Checkpoint
RP68: 03/02/2011 1:44:52 PM - System Checkpoint
RP69: 03/03/2011 2:59:04 PM - System Checkpoint
RP70: 03/04/2011 3:07:11 PM - System Checkpoint
RP71: 03/05/2011 3:24:04 PM - System Checkpoint
RP72: 03/06/2011 10:24:34 AM - Removed AVG 2011
RP73: 03/06/2011 10:26:28 AM - Removed AVG 2011
RP74: 03/07/2011 11:07:48 AM - System Checkpoint
RP75: 03/07/2011 1:51:44 PM - Removed Adobe Reader 9.4.2.
RP76: 03/07/2011 1:52:16 PM - Installed Adobe Reader X (10.0.1).
RP77: 03/07/2011 3:29:26 PM - Installed Windows XP Service Pack 3.
RP78: 03/07/2011 3:42:38 PM - Installed Windows XP KB2229593.
RP79: 03/07/2011 3:43:43 PM - Installed Windows XP KB923561.
RP80: 03/07/2011 3:44:42 PM - Installed Windows XP KB938464.
RP81: 03/07/2011 3:45:45 PM - Installed Windows XP KB946648.
RP82: 03/07/2011 3:46:58 PM - Installed Windows XP KB950762.
RP83: 03/07/2011 3:47:52 PM - Installed Windows XP KB950974.
RP84: 03/07/2011 3:48:49 PM - Installed Windows XP KB951066.
RP85: 03/07/2011 3:49:47 PM - Installed Windows XP KB951376.
RP86: 03/07/2011 3:50:42 PM - Installed Windows XP KB951376-v2.
RP87: 03/07/2011 3:51:43 PM - Installed Windows XP KB951698.
RP88: 03/07/2011 3:52:40 PM - Installed Windows XP KB951748.
RP89: 03/07/2011 3:53:39 PM - Installed Windows XP KB952004.
RP90: 03/07/2011 3:54:40 PM - Installed Windows XP KB952287.
RP91: 03/07/2011 3:55:38 PM - Installed Windows XP KB952954.
RP92: 03/07/2011 3:56:35 PM - Installed Windows XP KB954211.
RP93: 03/07/2011 3:57:41 PM - Installed Windows XP KB954600.
RP94: 03/07/2011 3:58:48 PM - Installed Windows XP KB974112.
RP95: 03/07/2011 3:59:56 PM - Installed Windows XP KB955069.
RP96: 03/07/2011 4:01:12 PM - Installed Windows XP KB973687.
RP97: 03/07/2011 4:02:25 PM - Installed Windows XP KB955759.
RP98: 03/07/2011 4:03:29 PM - Installed Windows XP KB956572.
RP99: 03/07/2011 4:04:36 PM - Installed Windows XP KB956802.
RP100: 03/07/2011 4:05:39 PM - Installed Windows XP KB956803.
RP101: 03/07/2011 4:06:57 PM - Installed Windows XP KB956841.
RP102: 03/07/2011 4:08:06 PM - Installed Windows XP KB956844.
RP103: 03/07/2011 4:09:15 PM - Installed Windows XP KB957095.
RP104: 03/07/2011 4:10:13 PM - Installed Windows XP KB957097.
RP105: 03/07/2011 4:11:19 PM - Installed Windows XP KB958644.
RP106: 03/07/2011 4:12:23 PM - Installed Windows XP KB958687.
RP107: 03/07/2011 4:13:23 PM - Installed Windows XP KB958690.
RP108: 03/07/2011 4:14:31 PM - Installed Windows XP KB959426.
RP109: 03/07/2011 4:15:37 PM - Installed Windows XP KB960225.
RP110: 03/07/2011 4:16:41 PM - Installed Windows XP KB960803.
RP111: 03/07/2011 4:17:48 PM - Installed Windows XP KB960859.
RP112: 03/07/2011 4:18:56 PM - Installed Windows XP KB961118.
RP113: 03/07/2011 4:20:18 PM - Installed Windows XP KB961371.
RP114: 03/07/2011 4:21:22 PM - Installed Windows XP KB961373.
RP115: 03/07/2011 4:22:26 PM - Installed Windows XP KB961501.
RP116: 03/07/2011 4:23:32 PM - Installed Windows XP KB967715.
RP117: 03/07/2011 4:24:36 PM - Installed Windows XP KB968389.
RP118: 03/07/2011 4:25:50 PM - Installed Windows XP KB968537.
RP119: 03/07/2011 4:26:52 PM - Installed Windows XP KB969059.
RP120: 03/07/2011 4:28:07 PM - Installed Windows XP KB969947.
RP121: 03/07/2011 4:29:16 PM - Installed Windows XP KB970238.
RP122: 03/07/2011 4:30:24 PM - Installed Windows XP KB970430.
RP123: 03/07/2011 4:31:31 PM - Installed Windows XP KB971468.
RP124: 03/07/2011 4:32:36 PM - Installed Windows XP KB971486.
RP125: 03/07/2011 4:33:39 PM - Installed Windows XP KB971557.
RP126: 03/07/2011 4:34:42 PM - Installed Windows XP KB971633.
RP127: 03/07/2011 4:35:46 PM - Installed Windows XP KB971657.
RP128: 03/07/2011 4:36:56 PM - Installed Windows XP KB971737.
RP129: 03/07/2011 4:38:09 PM - Installed Windows XP KB972270.
RP130: 03/07/2011 4:39:13 PM - Installed Windows XP KB973354.
RP131: 03/07/2011 4:40:21 PM - Installed Windows XP KB973507.
RP132: 03/07/2011 4:41:34 PM - Installed Windows XP KB973687.
RP133: 03/07/2011 4:42:40 PM - Installed Windows XP KB973815.
RP134: 03/07/2011 4:43:46 PM - Installed Windows XP KB973869.
RP135: 03/07/2011 4:44:58 PM - Installed Windows XP KB974112.
RP136: 03/07/2011 4:46:10 PM - Installed Windows XP KB974318.
RP137: 03/07/2011 4:47:15 PM - Installed Windows XP KB974392.
RP138: 03/07/2011 4:48:24 PM - Installed Windows XP KB974571.
RP139: 03/07/2011 4:49:32 PM - Installed Windows XP KB975025.
RP140: 03/07/2011 4:50:36 PM - Installed Windows XP KB975467.
RP141: 03/07/2011 4:51:42 PM - Installed Windows XP KB975560.
RP142: 03/07/2011 4:52:53 PM - Installed Windows XP KB975561.
RP143: 03/07/2011 4:54:03 PM - Installed Windows XP KB975562.
RP144: 03/07/2011 4:55:07 PM - Installed Windows XP KB975713.
RP145: 03/07/2011 4:56:22 PM - Installed Windows XP KB977165.
RP146: 03/07/2011 4:57:30 PM - Installed Windows XP KB977914.
RP147: 03/07/2011 4:58:46 PM - Installed Windows XP KB978037.
RP148: 03/07/2011 4:59:50 PM - Installed Windows XP KB978251.
RP149: 03/07/2011 5:01:02 PM - Installed Windows XP KB978338.
RP150: 03/07/2011 5:02:07 PM - Installed Windows XP KB978542.
RP151: 03/07/2011 5:03:15 PM - Installed Windows XP KB978601.
RP152: 03/07/2011 5:04:19 PM - Installed Windows XP KB978706.
RP153: 03/07/2011 5:05:25 PM - Installed Windows XP KB979309.
RP154: 03/07/2011 5:06:32 PM - Installed Windows XP KB979482.
RP155: 03/07/2011 5:07:41 PM - Installed Windows XP KB979559.
RP156: 03/07/2011 5:08:56 PM - Installed Windows XP KB979683.
RP157: 03/07/2011 5:10:05 PM - Installed Windows XP KB980218.
RP158: 03/07/2011 5:11:14 PM - Installed Windows XP KB980232.
.
==== Installed Programs ======================
.
1310
1310_Help
1310Tour
1310Trb
Ace Utilities
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader X (10.0.1)
Advanced WindowsCare Personal
Agere Systems PCI-SV92PP Soft Modem
AiO_Scan
AIOMinimal
AiOSoftware
Apple Application Support
Apple Software Update
ATT-RC Self Support Tool
Audacity 1.2.6
Autodesk MapGuide® Viewer ActiveX Control Release 6.5
BufferChm
CameraDrivers
CCleaner (remove only)
Chart Navigator
Chinese Traditional Fonts Support For Adobe Reader 8
Chuzzle Deluxe
Compaq Connections (remove only)
Conduit Engine
Cook'n with Pillsbury
Coupon Printer for Windows
CreativeProjects
CreativeProjectsTemplates
CueTour
Customer Experience Enhancement
Destinations
Director
DIRECTV2PC Playback Advisor
DIRECTV2PC™
DISCover
Driver Detective
Enhanced Multimedia Keyboard Solution
ERUNT 1.1j
ESET Online Scanner v3
Extra_POI_Editor_Installer
Fax
Flip Words
Garmin Communicator Plugin
Garmin MapSource
Garmin nRoute
Garmin POI Loader
Garmin Trip and Waypoint Manager v3
Garmin USB Drivers
Garmin WebUpdater
GdiplusUpgrade
Google Desktop
Google Earth
Google Earth Plug-in
Google Update Helper
GPS TrackMaker
Hampton Hotels eDirectory with MultiView Reader
High Definition Audio Driver Package - KB888111
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Boot Optimizer
HP Driver Diagnostics
HP DVD Play 2.1
HP Image Zone 4.5
HP Photosmart Cameras 4.5
HP Product Assistant
HP PSC & OfficeJet 3.5
HP Rhapsody
HP Software Update
HP Support Overview
HP Update
HpSdpAppCoreApp
HPSystemDiagnostics
IE7pro
Insaniquarium Deluxe
InstantShare
Interactive User’s Guide
iTunes
Java Auto Updater
Java™ 6 Update 21
Kaspersky Online Scanner
LightScribe 1.4.84.1
Mah Jong Quest
Malwarebytes' Anti-Malware
Map of North and Central America
Map of South America
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Away Mode
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Miro
Mozilla Firefox (3.6)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Mystery Case Files
NVIDIA Drivers
NVIDIA nView Desktop Manager
Otto
Outlook Express Quick Backup
overland
PanoStandAlone
PartyPoker
PC-Doctor 5 for Windows
PCFriendly
PCPal
PDFCreator
Photodex Presenter
PhotoGallery
Poker Superstars
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QFolder
Quicken 2006
Quicken Legal Business Pro 2006
Quicken WillMaker Plus 2006
QuickTime
Readme
RealPlayer
Realtek High Definition Audio Driver
Ricochet Lost Worlds
Scan
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981349)
Serif DrawPlus 4.0
ShareIns
SkinsHP1
Slingo Deluxe
Software Master Toolbar
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spell Checker For OE 2.1
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SpywareBlaster v3.5.1
Super GameHouse Solitaire Vol. 1
SUPERAntiSpyware Free Edition
System Requirements Lab
TaxACT 2006
TaxACT 2007
TaxACT 2008
TaxACT 2008 Georgia
TaxACT 2009
TaxACT 2009 Georgia
TaxACT 2010
TaxACT 2010 Georgia
TaxACT Georgia 2006
TaxACT Georgia 2007
Tennis Titans
TrayApp
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB953356)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
VCDS Release 10.6.2
VCDS Release 908.1
Weather Exchange
WebFldrs XP
WebReg
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player Firefox Plugin
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB912067
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
WordWeb
World Championship Checkers (Gold Plus)
WOT for Internet Explorer
.
==== Event Viewer Messages From Past Week ========
.
03/04/2011 8:44:35 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ftsata2
.
==== End Of File ===========================

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 18:09:35.90 on 03/07/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.526 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\arservice.exe
C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\PCPal\PCPalSrvHost.exe
C:\WINDOWS\system32\HPZipm12.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Compaq_Administrator\Desktop\dds.com
.
============== Pseudo HJT Report ===============
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Software Master Toolbar: {00725d68-069b-4095-9ff1-e7469c0e95df} - c:\program files\software_master\prxtbSoft.dll
BHO: IE7pro BHO: {00011268-e188-40df-a514-835fcd78b1bf} - c:\program files\ie7pro\IE7pro.dll
BHO: Software Master Toolbar: {00725d68-069b-4095-9ff1-e7469c0e95df} - c:\program files\software_master\prxtbSoft.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar3.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\webhelper.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: Software Master Toolbar: {00725d68-069b-4095-9ff1-e7469c0e95df} - c:\program files\software_master\prxtbSoft.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…t;ver=10.0.1204
StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\wkcalrem.lnk - c:\program files\common files\microsoft shared\works shared\WkCalRem.exe
StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\autoru~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\autorunsdisabled\wkcalrem.lnk.disabled
StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\autorunsdisabled\wordweb.lnk.disabled
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - {B119EB0C-C021-46CF-85B0-34A760E0D5FE} - c:\program files\ie7pro\IE7pro.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/OnlineScanner.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - hxxp://www.photodex.com/pxplay.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {84684C71-A2D3-42EB-BF35-2F709D80A0FA} = 192.168.2.1
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\w14redor.default\
FF - prefs.js: browser.startup.homepage - hxxp://mirostart.com/?cfg=2-365-0-2Miqs
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-2-17 67656]
R2 adunidrv;UniDriver for OneCare;c:\windows\system32\drivers\adunidrv.sys [2007-9-25 7168]
R2 advproct;Microsoft Corporation Process Trigger Driver;c:\windows\system32\drivers\advproct.sys [2007-9-25 6656]
R2 CLDTVHNService;CLDTVHNService;c:\program files\directv\directv\kernel\dmp\CLDTVHNService.exe [2009-9-17 75048]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 ntk_dtv;ntk_dtv;c:\program files\directv\directv\kernel\dmp\ntk_dtv.sys [2009-9-17 119792]
R2 PCPalSrvHost;PCPalSrvHost;c:\program files\pcpal\PCPalSrvHost.exe [2007-10-24 312304]
S2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\google\update\GoogleUpdate.exe [2008-10-18 133104]
S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\PCD5SRVC.pkms [2006-2-7 21120]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-2-17 12872]
.
=============== Created Last 30 ================
.
2011-03-07 20:41:26 ——– d—–w- c:\windows\LastGood.Tmp
2011-03-07 20:31:55 63663 ——w- c:\windows\system32\drivers\ati1rvxx.sys
2011-03-07 20:28:50 19569 —-a-w- c:\windows\003514_.tmp
2011-03-06 15:43:34 98816 —-a-w- c:\windows\sed.exe
2011-03-06 15:43:34 89088 —-a-w- c:\windows\MBR.exe
2011-03-06 15:43:34 256512 —-a-w- c:\windows\PEV.exe
2011-03-06 15:43:34 161792 —-a-w- c:\windows\SWREG.exe
2011-02-15 01:59:42 ——– d—–w- C:\ie-spyad_zo
.
==================== Find3M ====================
.
2011-03-07 20:38:45 45056 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\uninstallui\eHelpSetup.exe
2011-03-07 20:38:44 61440 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemutil.dll
2011-03-07 20:38:44 44032 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\scripts\devcon.exe
2011-03-07 20:38:44 40960 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\ScDmi.dll
2011-03-07 20:38:44 32768 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\uploadHSC.dll
2011-03-07 20:38:44 32768 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\Scom.dll
2011-03-07 20:38:44 217088 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
2011-03-07 20:38:44 163840 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemcheck.dll
2011-03-07 20:38:43 341048 —-a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\HPBasicDetection3.dll
.
============= FINISH: 18:10:05.74 ===============
Why don't you try Microsoft Security Essentials, it's excellent and it's free.

http://www.microsoft.com/security_essentials/


we just need to clean up our tools

You can delete the DDS and GMER logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
I tried to d/load Windows Esentials earlier, but since SF3 is not the original version for Windows XP, it will not let me d/load…..I ran CMD and ran SFC/scannow and got windows that said some files were not the orginal versions……..I will follow your instructions regarding deleting Combofix, etc. Later. Any advise on getting Window Esentials?
SP3 shouldn't have anything to do with downloading MSSecurity Essentials

can you either give me a screen shot or copy the exact message you are reciving when you try and download it.

go through the genuine advantage validation process.

Once re-validated, you will probably be allowed to download the program.

http://answers.microsoft.com/en-us/protect…0b-ddf812859ca4

http://www.microsoft.com/genuine/validate/…?displaylang=en

work through those resolutions and let me know if that resolves the issue.

(this is something that you need to do regardless if you choose MSSE or not)
I took a look at my scripting and it was enabled when trying to d/load WE. I disabled it and rebooted my machine and enabled it and was able to d/load Windows Esentials…..I can go ahead and remove per your instructions combofix, etc.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI