This is why I asked you to back up all of your important data before beggining running any tools; when trying to clean a machine as heavily infected as this unexpected things can sometimes happen.
Please scan the machine with DDS and aswMBR again and post the logs in your next reply.
I agree. I'm not concerned about losing any of the data at this point. I've got what I need, so we're ok on that front. Bottom line is that if it is better to format the drive and start from scratch, that is a possibility. I have discs from Dell that came with it. I've never done that and started back from a blank drive. I'll run the two and post the logs.
Have a good evening.
Here is the DDS:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14
Run by [removed] at 17:58:56 on 2012-03-03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.442 [GMT -8:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
svchost.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\server\mysql\bin\mysqld.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: Javaâ„¢ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [PRONoMgr.exe] c:\program files\intel\prosetwireless\ncs\proset\PRONoMgr.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [MozillaAgent] c:\windows\temp\_ex-68.exe
mRun: []
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9f.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~2.lnk - c:\program files\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: mswsock.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228361578657
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{40607D75-274A-4EEC-BACD-1D9C89442FE7} : DhcpNameServer = 192.168.1.254
Notify: Sebring - c:\windows\system32\LgNotify.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\harold\application data\mozilla\firefox\profiles\2myetprq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=20101206013308788&tb_oid=06-12-2010&tb_mrud=06-12-2010
FF - prefs.js: browser.startup.homepage - hxxp://kids.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - component: c:\documents and settings\harold\application data\mozilla\firefox\profiles\2myetprq.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}\components\MailUtil.dll
FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
============= SERVICES / DRIVERS ===============
.
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-2-6 748440]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2011-5-29 233472]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2011-5-29 36608]
R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2003-2-6 59328]
S2 Apache2.2;Apache2.2;c:\server\apache\bin\apache.exe [2008-12-9 24636]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
.
=============== Created Last 30 ================
.
2012-03-03 17:48:33 ——– d-sha-r- C:\cmdcons
2012-03-03 17:46:47 98816 —-a-w- c:\windows\sed.exe
2012-03-03 17:46:47 518144 —-a-w- c:\windows\SWREG.exe
2012-03-03 17:46:47 256000 —-a-w- c:\windows\PEV.exe
2012-03-03 17:46:47 208896 —-a-w- c:\windows\MBR.exe
2012-03-03 17:46:40 ——– d-s—w- C:\ComboFix
2012-03-03 17:44:14 ——– d—–w- c:\windows\system32\appmgmt
2012-03-03 03:44:52 83456 —-a-w- c:\windows\system32\TnMaA74.exe_
2012-03-03 01:26:49 ——– d—–w- C:\TDSSKiller_Quarantine
2012-03-01 04:29:00 83968 —-a-w- c:\documents and settings\all users\application data\J2G0r32Q.exe
2012-02-26 19:07:00 0 –sha-w- c:\windows\system32\dds_trash_log.cmd
2012-02-26 18:58:24 51712 —-a-w- c:\windows\system32\TnMaA74.com
2012-02-26 18:55:14 ——– d—–w- c:\documents and settings\harold\application data\Search Settings
2012-02-26 18:55:05 ——– d—–w- c:\program files\pdfforge Toolbar
2012-02-26 18:55:05 ——– d—–w- c:\program files\common files\Spigot
2012-02-26 18:55:05 ——– d—–w- c:\program files\Application Updater
2012-02-26 18:49:59 316416 —-a-w- c:\documents and settings\harold\local settings\application data\tkn.exe
2012-02-26 18:49:59 316416 —-a-w- c:\documents and settings\harold\local settings\application data\jpi.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\xfd.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\orj.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\htk.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\edc.exe
2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\deb.exe
.
==================== Find3M ====================
.
2012-03-03 01:28:40 49536 —-a-w- c:\windows\system32\drivers\cdrom.sys
2011-12-16 12:47:59 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-12-16 12:47:57 281104 —-a-w- c:\windows\system32\wpcap.dll
2011-12-16 12:47:55 100880 —-a-w- c:\windows\system32\Packet.dll
.
============= FINISH: 17:59:52.65 ===============
Here is the Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/2/2008 10:11:37 PM
System Uptime: 3/3/2012 3:26:34 PM (2 hours ago)
.
Motherboard: Dell Computer Corporation | | 0T1957
Processor: Intel® Pentium® M processor 2.00GHz | Microprocessor | 1993/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 93 GiB total, 62.929 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\237718C1374FC000
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\237718C1374FC000
Service: NIC1394
.
Class GUID:
Description:
Device ID: ROOT\LEGACY_BEEP\XX_NPF_XX
Manufacturer:
Name:
PNP Device ID: ROOT\LEGACY_BEEP\XX_NPF_XX
Service: NPF
.
==== System Restore Points ===================
.
RP237: 12/13/2011 7:46:38 PM - System Checkpoint
RP238: 12/14/2011 11:26:34 PM - System Checkpoint
RP239: 12/15/2011 3:00:45 AM - Software Distribution Service 3.0
RP240: 12/15/2011 6:57:13 AM - Restore Operation
RP241: 12/15/2011 7:06:27 AM - Software Distribution Service 3.0
RP242: 12/15/2011 6:40:55 PM - Software Distribution Service 3.0
RP243: 12/15/2011 7:12:14 PM - Software Distribution Service 3.0
RP244: 2/26/2012 10:54:37 AM - Removed pdfforge Toolbar v4.8.
RP245: 2/26/2012 11:20:10 AM - Software Distribution Service 3.0
RP246: 2/29/2012 7:28:40 PM - Software Distribution Service 3.0
RP247: 3/2/2012 6:53:25 AM - System Checkpoint
RP248: 3/3/2012 9:43:07 AM - Removed Symantec AntiVirus
.
==== Installed Programs ======================
.
Acrobat.com
Adobe Acrobat 8 Professional
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader X
AIM 7
ALPS Touch Pad Driver
AOL Messaging Toolbar
Apple Application Support
Apple Software Update
BlackBerry Desktop Software 4.3
Broadcom Gigabit Integrated Controller
Brother MFL-Pro Suite
C-Major Audio
CampBrain 5.1
CardBus
Compatibility Pack for the 2007 Office system
Conexant D480 MDC V.9x Modem
Dell ResourceCD
Download Updater (AOL LLC)
DYMO Label v.8
DYMO LabelWriter Drivers
Easy CD Creator 5 Basic
Google Talk (remove only)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel® mDriver
Intel® PROSet for Wireless
InterActual Player
InterVideo WinDVD
Java 2 Runtime Environment, SE v1.4.2_03
Javaâ„¢ 6 Update 14
LiveUpdate 3.0 (Symantec Corporation)
McAfee Security Scan Plus
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office File Validation Add-In
Microsoft Office Professional Edition 2003
Microsoft VC9 runtime libraries
MOM Workstation 6.0
Mozilla Firefox 8.0.1 (x86 en-US)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Nancy Drew Dossier: Resorting to Danger
Nancy Drew: Ghost Dogs of Moon Lake
Nancy Drew: Shadow at the Water's Edge
Nancy Drew: The Captive Curse
Nancy Drew: Warnings at Waverly Academy
NVIDIA Drivers
PC Connectivity Solution
PCI 7510 CardBus Controller with SmartCard and Software
PDFCreator
pdfforge Toolbar v5.0
Peachtree Complete Accounting 2005
QuickSet
QuickTime
Roxio Media Manager
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung New PC Studio
SamsungConnectivityCableDriver
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981349)
SimCoaster
SimTheme Park
Spybot - Search & Destroy
Stamps.com
The Hardy Boys - The Hidden Theft
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB898461)
Update for Windows XP (KB904942)
Update for Windows XP (KB925720)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
XAMPP 1.7.0
.
==== Event Viewer Messages From Past Week ========
.
3/2/2012 7:01:00 AM, error: Schedule [7901] - The At64.job command failed to start due to the following error: %%2147942402
3/2/2012 7:01:00 AM, error: Schedule [7901] - The At16.job command failed to start due to the following error: %%2147942402
3/2/2012 6:59:32 AM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 805660cf, parameter3 eb055a40, parameter4 00000000.
3/1/2012 9:19:29 PM, error: Service Control Manager [7023] - The Network Location Awareness (NLA) service terminated with the following error: The specified procedure could not be found.
3/1/2012 9:01:00 PM, error: Schedule [7901] - The At92.job command failed to start due to the following error: %%2147942402
3/1/2012 8:54:17 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Symantec AntiVirus service to connect.
3/1/2012 11:01:03 PM, error: Schedule [7901] - The At96.job command failed to start due to the following error: %%2147942402
3/1/2012 11:01:01 PM, error: Schedule [7901] - The At47.job command failed to start due to the following error: %%2147942402
3/1/2012 10:01:14 PM, error: Schedule [7901] - The At94.job command failed to start due to the following error: %%2147942402
3/1/2012 10:01:07 PM, error: Schedule [7901] - The At46.job command failed to start due to the following error: %%2147942402
2/29/2012 8:01:00 PM, error: Schedule [7901] - The At90.job command failed to start due to the following error: %%2147942402
2/26/2012 12:01:02 PM, error: Schedule [7901] - The At74.job command failed to start due to the following error: %%2147942402
2/26/2012 11:36:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80246007: Windows Malicious Software Removal Tool - December 2011 (KB890830).
2/26/2012 11:36:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Microsoft Office PowerPoint 2007 (KB2596843).
2/26/2012 11:36:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Microsoft Office 2007 suites (KB2596785).
2/26/2012 11:16:56 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher 9 service to connect.
2/26/2012 11:01:00 AM, error: Schedule [7901] - The At72.job command failed to start due to the following error: %%2147942402
2/26/2012 11:01:00 AM, error: Schedule [7901] - The At23.job command failed to start due to the following error: %%2147942402
2/26/2012 10:49:56 AM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 805660cf, parameter3 eed49a40, parameter4 00000000.
.
==== End Of File ===========================
Posting this now and will post the other in a minute.
Hi:
Below I've copied the FSS.txt. From your comments, this is sounding rather challenging. I really am fine with reformatting and starting over fresh if I have what I need. If you can help me do that, then your time will be free to help someone who doesn't have that option. I have the following original discs available:
Drivers & Utilities - Already Installed on your computer - For reinstalling Dell Latitude System Software
Operating System - Already installed on your computer - Re-installation CD MS Windows XP including service pack 2
Application - Already installed…. - For reinstalling Roxio Easy CD Creator 5.3.4. SP8 Basic System Software
WinDVD
I've never reformatted or installed from scratch before.
Below is the FSS.txt
Thanks. Harold
Farbar Service Scanner Version: 01-03-2012
Ran by [removed] (administrator) on 04-03-2012 at 12:05:37
Running from "C:\Documents and Settings\Harold\Desktop"
Microsoft Windows XP Professional Service Pack 2 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
Windows Update:
============
File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys
[2004-08-12 05:17] - [2008-08-14 01:51] - 0138368 ____A (Microsoft Corporation) 55E6E1C51B6D30E54335750955453702
C:\WINDOWS\system32\Drivers\netbt.sys
[2004-08-12 05:24] - [2004-08-12 05:24] - 0162816 ____A (Microsoft Corporation) 0C80E410CD2F47134407EE7DD19CC86B
C:\WINDOWS\system32\Drivers\tcpip.sys
[2004-08-12 05:30] - [2008-06-20 02:45] - 0360320 ____A (Microsoft Corporation) 2A5554FC5B1E04E131230E3CE035C3F9
C:\WINDOWS\system32\Drivers\ipsec.sys
[2004-08-12 05:20] - [2004-08-12 05:20] - 0074752 ____A (Microsoft Corporation) 64537AA5C003A6AFEEE1DF819062D0D1
C:\WINDOWS\system32\dnsrslvr.dll
[2004-08-12 05:18] - [2004-08-12 05:18] - 0045568 ____A (Microsoft Corporation) 7379DE06FD196E396A00AA97B990C00D
C:\WINDOWS\system32\ipnathlp.dll
[2004-08-12 05:20] - [2004-08-12 05:20] - 0331264 ____A (Microsoft Corporation) 36CC8C01B5E50163037BEF56CB96DEFF
C:\WINDOWS\system32\netman.dll
[2004-08-12 05:24] - [2004-08-12 05:24] - 0198144 ____A (Microsoft Corporation) DAB9E6C7105D2EF49876FE92C524F565
C:\WINDOWS\system32\wbem\WMIsvc.dll
[2008-12-02 22:05] - [2004-08-12 05:34] - 0144896 ____A (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E
C:\WINDOWS\system32\srsvc.dll
[2008-12-02 22:06] - [2004-08-12 05:29] - 0170496 ____A (Microsoft Corporation) 92BDF74F12D6CBEC43C94D4B7F804838
C:\WINDOWS\system32\Drivers\sr.sys
[2008-12-02 22:06] - [2004-08-12 05:29] - 0073472 ____A (Microsoft Corporation) E41B6D037D6CD08461470AF04500DC24
C:\WINDOWS\system32\wscsvc.dll
[2004-08-12 05:34] - [2004-08-12 05:34] - 0081408 ____A (Microsoft Corporation) 4D59DAA66C60858CDF4F67A900F42D4A
C:\WINDOWS\system32\wbem\WMIsvc.dll
[2008-12-02 22:05] - [2004-08-12 05:34] - 0144896 ____A (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E
C:\WINDOWS\system32\wuauserv.dll
[2008-12-02 22:07] - [2004-08-12 05:34] - 0006656 ____A (Microsoft Corporation) 13D72740963CBA12D9FF76A7F218BCD8
C:\WINDOWS\system32\qmgr.dll
[2008-12-02 22:07] - [2004-08-12 05:26] - 0382464 ____A (Microsoft Corporation) 2C69EC7E5A311334D10DD95F338FCCEA
C:\WINDOWS\system32\es.dll
[2004-08-12 05:19] - [2008-07-07 12:32] - 0253952 ____A (Microsoft Corporation) 60D1A6342238378BFB7545C81EE3606C
C:\WINDOWS\system32\cryptsvc.dll
[2004-08-12 05:18] - [2004-08-12 05:18] - 0060416 ____A (Microsoft Corporation) 10654F9DDCEA9C46CFB77554231BE73B
C:\WINDOWS\system32\svchost.exe
[2004-08-12 05:30] - [2004-08-12 05:30] - 0014336 ____A (Microsoft Corporation) 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\rpcss.dll
[2004-08-12 05:27] - [2009-02-09 02:20] - 0399360 ____A (Microsoft Corporation) 01095FEBF33BEEA00C2A0730B9B3EC28
C:\WINDOWS\system32\services.exe
[2004-08-12 05:28] - [2009-02-06 09:14] - 0110592 ____A (Microsoft Corporation) 37561F8D4160D62DA86D24AE41FAE8DE
Extra List:
=======
Gpc(3) IPSec(5) MDC8021X(9) NetBT(6) PSched(7) s24trans(8) Tcpip(4)
0x090000000500000001000000020000000300000004000000060000000700000008000000090000
00
IpSec Tag value is correct.
**** End of log ****
If you have no problem with a reset to factory settings or a complete reformat and reinstalation then this would be the thing to do since it will most likely offer the quickest route to removing the infections on the machine.
I have discs from Dell that came with it
The disks you have will probably allow you to perform a factory reset of the machine.
The latest DELL backup and reset guide can be found here
An excellent general guide to reformatting and reinstalling an operating system can be found here
Should you need additional assistance with the procedure, please begin a new thread in our Windows forum located here
Thanks for all of your help. I am reinstalling now.
You'd mentioned that you could recommend a good free anti virus/spyware program. That would still be great if you wouldn't mind.
Thanks for doing what you do. You are all lifesavers.
Harold