Deucehearts

Members
  • Content Count

    75
  • Joined

  • Last visited

Posts posted by Deucehearts

  1. Here is my HIJack log. Any help would be Great. Friends Laptop running XP Home with SP3. I ran AVG and Spybot with out any luck.

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 4:07:23 PM, on 5/25/2008

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

    C:\WINDOWS\Explorer.EXE

    C:\PROGRA~1\AVG\AVG8\avgrsx.exe

    C:\WINDOWS\mrofinu333.exe

    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe

    C:\WINDOWS\system32\carpserv.exe

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\PROGRA~1\AVG\AVG8\avgtray.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\PROGRA~1\AVG\AVG8\avgemc.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

    O2 - BHO: (no name) - {800A0C44-E788-419C-B8B5-1B4964C56785} - C:\WINDOWS\system32\iifeddb.dll (file missing)

    O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3C64B~1\Bar888.dll (file missing)

    O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3C64B~1\Bar888.dll (file missing)

    O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu333.exe 61A847B5BBF728113198284503996897C881250221C8670836AC4FA7C88332017491394661A64DB7

    C8F0287E55E246220D9E728F86C07B5670CA3B5571E744AB97

    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe

    O4 - HKLM\..\Run: [CARPService] carpserv.exe

    O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKUS\S-1-5-18\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe (User 'SYSTEM')

    O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{6C64B92E-07C9-1033-0403-030303180001}] "C:\Program Files\Common Files\{6C64B92E-07C9-1033-0403-030303180001}\Update.exe" mc-110-12-0000501 (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe (User 'Default user')

    O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{6C64B92E-07C9-1033-0403-030303180001}] "C:\Program Files\Common Files\{6C64B92E-07C9-1033-0403-030303180001}\Update.exe" mc-110-12-0000501 (User 'Default user')

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: Refresh Pa≥ with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html

    O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1211324596551

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

    O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll,avgrsstx.dll

    O20 - Winlogon Notify: iifeddb - iifeddb.dll (file missing)

    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

    O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\System32\svchosts.exe (file missing)

    --

    End of file - 4824 bytes

  2. I found a fix that has been working for a couple hours now. Apparently the firmware for my TS-L462C 24x cdrw/dvd combo drive conflicts with my sound drivers when updated to DE07. I ended up installing firmware DE05 and the audio now works perfectly fine. I found the fix at the following link.

    I will paste the fix from his link as well in case the link goes down for any reason. Fix link.

    The solution that I finally found...is to roll back the DE07 firmware to DE05.

    Which at first, doesn't seem that easy because the DE05 flashes the firmware from a floppy boot-disk, and my B130 didn't come with a floppy drive.

    So here's how I did it ...

    1. If you don't already have it, you'll need the DE07 firmware utility that comes with the upgrade.

    Get it here .... TS-L462C DE07 firmware

    Follow the instruction to download and unzip, but don't install ... we just need the windows flash utility.

    2. Download and unzip the DE05 firmware.

    Get it here ... TS-L462C DE05 firmware

    Write down the location of this folder, as we need the .bin file from this folder.

    Mine unzipped to here ... C:\dell\drivers\R114334

    3. Now, open(double click) on the DE07 firmware updater called SFDNWIN.exe

    and follow the instructions to update ...

    a. Click on "Download File Open" button at left corner.

    b. Do not click on the DE07_060525.bin, but instead browse to the folder that has the DE05.bin, which in mine is located at C:\dell\drivers\R114334, to select it. Click on "Open".

    c. Click on "Start Download" button at middle.

    d. Click on "Restart Windows".

    e. System will restart after flash is complete.

    I hope that this was helpful, and not too confusing, but this worked wonderfully for me!

  3. I did a fresh install and first install the modem driver and then the Sigma Tel driver and the sound worked great. I installed the video driver and it was still good. I then installed Ricoh memory card driver and the sound started cracking and popping again. I then did a system restore to a time before I installed any drivers and then reinstalled the modem and sigma tel drivers and the sound issue is still there.

  4. Recently had filled up my hard drive on my Dell E1505 and purchased a new one. On my new hard drive I created 2 partitions. On one partition I loaded an Image of my previous install. On the other partition I did a fresh install of Windows XP Media Center 2005. I then reformated the old harddrive and did a fresh install of Media Center 2005.

    Now the issue. On all three partitions I used the drivers supplied on the Dell website for my Laptop and have all windows updates installed. On the imaged partition the sounds works perfectly. On the other partition and other hard drive the sound pops and cracks and chops constantly(intervals of every ~2 secs) for any sound output(cd, dvd, files on computer).

    The laptop is almost 2 years old. I am running Media Center 2005 with 1 gb of memory. All partitions have at least 60% of the space free.

    I am doing anther fresh install of the old hard as we speak. Any ideas would be great. Thank you for your time.

  5. The computer is running a lot better now, thanks for all your help. Here is another hijackthis log.

    Logfile of HijackThis v1.99.1

    Scan saved at 11:34:46 AM, on 12/14/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    C:\Program Files\Alwil Software\Avast4\ashServ.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\Program Files\Comodo\Firewall\cmdagent.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\Program Files\CyberLink\Shared files\RichVideo.exe

    C:\WINDOWS\ehome\RMSvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\ZuneBusEnum.exe

    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\WINDOWS\eHome\ehmsas.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\WINDOWS\stsystra.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    C:\Program Files\Transcode360\Transcode360Tray.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\Zune\ZuneLauncher.exe

    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe

    C:\Program Files\Comodo\Firewall\cfp.exe

    C:\Program Files\Microsoft ActiveSync\Wcescomm.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\PROGRA~1\MI3AA1~1\rapimgr.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\WINDOWS\ehome\RMSysTry.exe

    C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe

    C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe

    C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe

    C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe

    C:\WINDOWS\system32\msiexec.exe

    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/campaign.asp?cid=16313

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll

    O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

    O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll

    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

    O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    O4 - HKLM\..\Run: [Transcode360] C:\Program Files\Transcode360\Transcode360Tray.exe

    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

    O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"

    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\cfp.exe" -s

    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"

    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll

    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O9 - Extra button: FreshDownload - {46E72E01-FAB2-42AD-92BE-08BE4E092B5A} - C:\Program Files\FreshDevices\FreshDownload\fd.exe

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab

    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab

    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

    O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/Activ...iveXClient1.cab

    O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab

    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab

    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bejewel...aploader_v6.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...065/mcfscan.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{329A3B50-741F-48E7-8D89-85E949C8982C}: NameServer = 192.168.0.1

    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe

    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

    O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

  6. -------------------------------------------------------------------------------

    KASPERSKY ONLINE SCANNER REPORT

    Thursday, December 13, 2007 5:26:18 PM

    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)

    Kaspersky Online Scanner version: 5.0.98.0

    Kaspersky Anti-Virus database last update: 13/12/2007

    Kaspersky Anti-Virus database records: 481147

    -------------------------------------------------------------------------------

    Scan Settings:

    Scan using the following antivirus database: extended

    Scan Archives: true

    Scan Mail Bases: true

    Scan Target - My Computer:

    C:\

    D:\

    E:\

    Scan Statistics:

    Total number of scanned objects: 98558

    Number of viruses found: 5

    Number of infected objects: 10

    Number of suspicious objects: 0

    Duration of the scan process: 01:17:07

    Infected Object Name / Virus Name / Last Action

    C:\Documents and Settings\All Users\Application Data\Comodo\Firewall Pro\cfplogdb.sdb Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\41136c33078ae7c8a252278a39d2e7e5_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5bfc75b932a68a56cdbd906b4f4013a9_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a51ad57536c82cf0d05bc788b8b7de39_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped

    C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp Object is locked skipped

    C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\Application Data\$_hpcst$.hpc Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\Local Settings\Application Data\ApplicationHistory\Transcode360Tray.exe.c666da10.ini.inuse Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\Local Settings\Temp\WCESLog.log Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\ntuser.dat Object is locked skipped

    C:\Documents and Settings\Dustin Ogilvie\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\MCX3\ntuser.dat Object is locked skipped

    C:\Documents and Settings\MCX3\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Zune\ZuneNSSStore.sdf Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

    C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped

    C:\Program Files\Transcode360\Transcode360_071212_1541_30328.log Object is locked skipped

    C:\qoobox\Quarantine\C\Program Files\ryvibatg\pufoxgpu.dll.vir Infected: Trojan-Downloader.Win32.Zlob.fec skipped

    C:\qoobox\Quarantine\C\WINDOWS\system32\vtutqnn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.blv skipped

    C:\qoobox\Quarantine\catchme2007-12-12_154026.09.zip/hggdbcc.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.blv skipped

    C:\qoobox\Quarantine\catchme2007-12-12_154026.09.zip ZIP: infected - 1 skipped

    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP440\A0061553.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.blw skipped

    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP440\A0061554.exe Infected: Trojan.Win32.Dialer.yz skipped

    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP441\A0061895.dll Infected: Trojan-Downloader.Win32.Zlob.fec skipped

    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP441\A0061896.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.blv skipped

    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP441\A0061901.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.blv skipped

    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP442\change.log Object is locked skipped

    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.a skipped

    C:\WINDOWS\ModemLog_Conexant HDA D110 MDC V.92 Modem.txt Object is locked skipped

    C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{DBAF74EE-6F97-4F54-8FD8-3BBC8FFB60F8}.crmlog Object is locked skipped

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\EventCache\{62761B12-F535-4CA1-BD94-366F6F07398E}.bin Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\EventCache\{6E00FD28-478B-4E8F-9CB5-430017BF3745}.bin Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

    C:\WINDOWS\Sti_Trace.log Object is locked skipped

    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

    C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

    C:\WINDOWS\system32\config\default.LOG Object is locked skipped

    C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped

    C:\WINDOWS\system32\config\SAM Object is locked skipped

    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

    C:\WINDOWS\system32\config\software.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

    C:\WINDOWS\system32\config\system.LOG Object is locked skipped

    C:\WINDOWS\system32\h323log.txt Object is locked skipped

    C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log Object is locked skipped

    C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    C:\WINDOWS\Temp\Perflib_Perfdata_1e4.dat Object is locked skipped

    C:\WINDOWS\Temp\Perflib_Perfdata_848.dat Object is locked skipped

    C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped

    C:\WINDOWS\Temp\_av_proI.tm~a04944\dld1.tmp Object is locked skipped

    C:\WINDOWS\Temp\_av_proI.tm~a04944\setup.lok Object is locked skipped

    C:\WINDOWS\wiadebug.log Object is locked skipped

    C:\WINDOWS\wiaservc.log Object is locked skipped

    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    Scan process completed.

  7. Here is my new Hijackthis log.

    Logfile of HijackThis v1.99.1

    Scan saved at 3:46:46 PM, on 12/12/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    C:\Program Files\Alwil Software\Avast4\ashServ.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\Program Files\Comodo\Firewall\cmdagent.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\Program Files\CyberLink\Shared files\RichVideo.exe

    C:\WINDOWS\ehome\RMSvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\ZuneBusEnum.exe

    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\WINDOWS\eHome\ehmsas.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\WINDOWS\stsystra.exe

    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\Program Files\Transcode360\Transcode360Tray.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\Program Files\Zune\ZuneLauncher.exe

    C:\Program Files\Comodo\Firewall\cfp.exe

    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe

    C:\Program Files\Microsoft ActiveSync\Wcescomm.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\PROGRA~1\MI3AA1~1\rapimgr.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\WINDOWS\ehome\RMSysTry.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/campaign.asp?cid=16313

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll

    O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

    O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll

    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

    O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    O4 - HKLM\..\Run: [Transcode360] C:\Program Files\Transcode360\Transcode360Tray.exe

    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

    O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"

    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\cfp.exe" -s

    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"

    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O9 - Extra button: FreshDownload - {46E72E01-FAB2-42AD-92BE-08BE4E092B5A} - C:\Program Files\FreshDevices\FreshDownload\fd.exe

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab

    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

    O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/Activ...iveXClient1.cab

    O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab

    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab

    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bejewel...aploader_v6.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...065/mcfscan.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{329A3B50-741F-48E7-8D89-85E949C8982C}: NameServer = 192.168.0.1

    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe

    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

    O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

  8. ComboFix 07-12-12.3 - Dustin Ogilvie 2007-12-11 15:15:56.1 - NTFSx86

    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.481 [GMT -6:00]

    Running from: C:\Documents and Settings\Dustin Ogilvie\Desktop\ComboFix.exe

    * Created a new restore point

    .

    The following files were disabled during the run:

    C:\WINDOWS\system32\guard32.dll

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    C:\Program Files\ryvibatg

    C:\Program Files\ryvibatg\pufoxgpu.dll

    C:\Program Files\SecCenter

    C:\Program Files\SecCenter\scprot4.exe

    C:\Program Files\SecCenter\scprot4.exe.bak

    C:\WINDOWS\system32\hggdbcc.dll

    C:\WINDOWS\system32\vtutqnn.dll

    .

    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    -------\nm

    ((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))

    .

    2007-12-11 14:46 . 2007-12-11 14:47 <DIR> d-------- C:\WINDOWS\ERUNT

    2007-12-11 12:22 . 2007-12-11 12:24 <DIR> d-------- C:\Program Files\Zaxtcqft

    2007-12-11 00:22 . 2007-12-11 00:22 <DIR> d-------- C:\WINDOWS\system32\hlvbfwoq

    2007-12-11 00:22 . 2007-12-11 00:22 <DIR> d-------- C:\Program Files\Vsdcxnpb

    2007-12-11 00:15 . 2007-12-11 00:16 <DIR> d-------- C:\Program Files\CyberLink

    2007-12-10 19:54 . 2007-12-10 20:48 <DIR> d-------- C:\Documents and Settings\Dustin Ogilvie\Application Data\GetRightToGo

    2007-11-23 04:15 . 2007-11-23 04:15 139,008 --a------ C:\WINDOWS\system32\guard32.dll.vir

    2007-11-23 04:15 . 2007-11-23 04:15 79,096 --a------ C:\WINDOWS\system32\drivers\cmdGuard.sys

    2007-11-23 04:15 . 2007-11-23 04:15 23,672 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys

    2007-11-15 20:55 . 2007-11-15 21:04 <DIR> d-------- C:\Documents and Settings\Dustin Ogilvie\Application Data\Mp3tag

    2007-11-15 20:54 . 2007-11-15 20:54 <DIR> d-------- C:\Program Files\Mp3tag

    2007-11-13 12:18 . 2007-11-13 12:18 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf

    2007-11-13 12:18 . 2007-11-13 12:18 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_01005.Wdf

    2007-11-13 12:16 . 2007-11-13 12:19 <DIR> d-------- C:\Program Files\Zune

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2007-12-12 21:41 --------- d-----w C:\Program Files\Transcode360

    2007-12-11 06:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink

    2007-12-11 02:48 --------- d--h--w C:\Program Files\InstallShield Installation Information

    2007-12-11 02:48 --------- d-----w C:\Documents and Settings\Dustin Ogilvie\Application Data\uTorrent

    2007-12-09 19:40 --------- d-----w C:\Program Files\a-squared HiJackFree

    2007-12-06 17:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\My Movies

    2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys

    2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys

    2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys

    2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys

    2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys

    2007-12-03 18:19 --------- d-----w C:\Program Files\SpywareBlaster

    2007-12-03 02:05 4,788 ----a-w C:\Documents and Settings\Dustin Ogilvie\Application Data\wklnhst.dat

    2007-12-03 00:17 --------- d-----w C:\Program Files\Bodog Poker

    2007-11-25 21:07 --------- d-----w C:\Program Files\MUSICMATCH

    2007-11-25 20:10 --------- d-----w C:\Program Files\Google

    2007-11-23 10:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Comodo

    2007-11-23 10:15 --------- d-----w C:\Documents and Settings\Dustin Ogilvie\Application Data\Comodo

    2007-11-08 07:40 --------- d-----w C:\Program Files\Common Files\xing shared

    2007-11-08 07:40 --------- d-----w C:\Program Files\Common Files\Real

    2007-11-07 00:58 40,832 ----a-w C:\WINDOWS\system32\drivers\zumbus.sys

    2007-11-04 23:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\PopCap

    2007-10-22 21:19 --------- d-----w C:\Program Files\Plato DVD Ripper Pro

    2007-10-22 18:44 --------- d-----w C:\Program Files\DIFX

    2007-10-22 18:44 --------- d-----w C:\Program Files\Common Files\ComponentOne

    2007-10-16 16:41 --------- d-----w C:\Documents and Settings\MCX4\Application Data\DivX

    2007-10-15 22:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink

    2007-10-15 04:25 --------- d-----w C:\Program Files\AviSynth 2.5

    2007-10-15 04:25 --------- d-----w C:\Program Files\AutoGK

    2007-10-15 04:24 --------- d-----w C:\Program Files\Gabest

    2007-10-15 02:53 --------- d-----w C:\Program Files\DivX

    2007-10-13 19:18 --------- d-----w C:\Program Files\AC3Filter

    2007-10-12 22:08 --------- d-----w C:\Program Files\MCE

    2006-11-01 15:23 60,736 ----a-w C:\Documents and Settings\Dustin Ogilvie\Application Data\GDIPFONTCACHEV1.DAT

    2006-04-05 15:49 251 -c--a-w C:\Program Files\wt3d.ini

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 12:39]

    "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09]

    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01]

    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43]

    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 11:48]

    "ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44]

    "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44]

    "Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-16 21:41]

    "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 04:33]

    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-12 00:47]

    "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 16:30 C:\WINDOWS\stsystra.exe]

    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 10:19]

    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 10:17]

    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 19:17]

    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 19:13]

    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 19:17]

    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00]

    "Transcode360"="C:\Program Files\Transcode360\Transcode360Tray.exe" [2006-05-02 11:01]

    "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 21:01]

    "Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09]

    "COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\cfp.exe" [2007-11-23 04:15]

    "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 22:17]

    C:\Documents and Settings\Dustin Ogilvie\Start Menu\Programs\Startup\

    Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe [2007-07-20 11:57:16]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]

    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-28 20:45:50]

    Extender Resource Monitor.lnk - C:\WINDOWS\ehome\RMSysTry.exe [2005-10-20 18:55:40]

    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

    "AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll

    R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys

    R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys

    R1 vcdrom;Virtual CD-ROM Device Driver;\??\C:\WINDOWS\system32\drivers\VCdRom.sys

    R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe

    R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys

    R2 ZuneBusEnum;Zune Bus Enumerator;C:\WINDOWS\system32\ZuneBusEnum.exe

    S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe -k QWAVE

    S3 QWAVEDRV;QWAVE driver;C:\WINDOWS\system32\DRIVERS\qwavedrv.sys

    S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\WINDOWS\system32\ZuneWlanCfgSvc.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    QWAVE REG_MULTI_SZ QWAVE

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19c6153f-2977-11dc-b6fc-0013021b3f00}]

    \Shell\AutoRun\command - F:\.\Start.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a182c8b6-1a36-11dc-b6f4-0015c5093a62}]

    \Shell\AutoRun\command - F:\LaunchU3.exe -a

    .

    **************************************************************************

    catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2007-12-12 15:40:45

    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully

    hidden files: 0

    **************************************************************************

    .

    Completion time: 2007-12-12 15:43:23 - machine was rebooted

    .

    2007-11-14 02:49:02 --- E O F ---

  9. SDFix: Version 1.118

    Run by Dustin Ogilvie on Tue 12/11/2007 at 02:48 PM

    Microsoft Windows XP [Version 5.1.2600]

    Running From: C:\SDFix

    Safe Mode:

    Checking Services:

    Restoring Windows Registry Values

    Restoring Windows Default Hosts File

    Rebooting...

    Normal Mode:

    Checking Files:

    No Trojan Files Found

    Removing Temp Files...

    ADS Check:

    C:\WINDOWS

    No streams found.

    C:\WINDOWS\system32

    No streams found.

    C:\WINDOWS\system32\svchost.exe

    No streams found.

    C:\WINDOWS\system32\ntoskrnl.exe

    No streams found.

    Final Check:

    catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2007-12-11 15:00:59

    Windows 5.1.2600 Service Pack 2 NTFS

    detected NTDLL code modification:

    ZwClose

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    scan completed successfully

    hidden processes: 0

    hidden services: 0

    hidden files: 0

    Remaining Services:

    ------------------

    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"

    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"

    "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"

    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"

    "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"

    "C:\\Program Files\\Common Files\\AOL\\1144267985\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1144267985\\ee\\aolsoftware.exe:*:Enabled:AOL Services"

    "C:\\Program Files\\Common Files\\AOL\\1144267985\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1144267985\\ee\\aim6.exe:*:Enabled:AIM"

    "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"

    "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"

    "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

    "C:\\Documents and Settings\\Dustin Ogilvie\\Desktop\\utorrent.exe"="C:\\Documents and Settings\\Dustin Ogilvie\\Desktop\\utorrent.exe:*:Enabled:æTorrent"

    "C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox"

    "C:\\WINDOWS\\ehome\\ehshell.exe"="C:\\WINDOWS\\ehome\\ehshell.exe:LocalSubNet:Enabled:Media Center"

    "C:\\Program Files\\Transcode360\\Transcode360Tray.exe"="C:\\Program Files\\Transcode360\\Transcode360Tray.exe:*:Enabled: "

    "C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"="C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"

    "C:\\DOCUME~1\\DUSTIN~1\\LOCALS~1\\Temp\\win93.exe"="C:\\DOCUME~1\\DUSTIN~1\\LOCALS~1\\Temp\\win93.exe:*:Enabled:win93"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"

    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"

    "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"

    "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"

    "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"

    "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

    Remaining Files:

    ---------------

    Files with Hidden Attributes:

    Tue 4 Apr 2006 56 A.SHR --- "C:\i386\9691018285.sys"

    Tue 4 Apr 2006 3,766 A.SH. --- "C:\i386\KGyGaAvL.sys"

    Fri 7 Dec 2007 88 ..SHR --- "C:\WINDOWS\system32\8582019196.sys"

    Sat 24 Nov 2007 104 ..SHR --- "C:\WINDOWS\system32\9691018285.sys"

    Fri 7 Dec 2007 6,580 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"

    Fri 7 Oct 2005 1,847,296 ...HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\LAUNCHER.EXE"

    Fri 7 Oct 2005 62,464 ...HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\MNYINSTA.DLL"

    Fri 7 Oct 2005 95,232 ...HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\RMVSUITE.EXE"

    Fri 7 Oct 2005 36,864 ...HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\SETUPLNG.DLL"

    Fri 7 Oct 2005 20,480 ...HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\UNREGWTR.EXE"

    Mon 22 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

    Thu 7 Dec 2006 3,096,576 A..H. --- "C:\Documents and Settings\Dustin Ogilvie\Application Data\U3\temp\Launchpad Removal.exe"

    Mon 24 Apr 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"

    Tue 14 Aug 2007 8 A..H. --- "C:\Documents and Settings\Dustin Ogilvie\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"

    Tue 14 Aug 2007 8 A..H. --- "C:\Documents and Settings\Dustin Ogilvie\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"

    Tue 14 Aug 2007 8 A..H. --- "C:\Documents and Settings\Dustin Ogilvie\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"

    Tue 14 Aug 2007 8 A..H. --- "C:\Documents and Settings\Dustin Ogilvie\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

    Finished!

  10. A little icon showed up in my notification bar and is said there has been a trojan detected. It looked wrong so I closed it and ran hijackthis. Thanks for your help.

    Logfile of HijackThis v1.99.1

    Scan saved at 12:52:25 AM, on 12/11/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    C:\Program Files\Alwil Software\Avast4\ashServ.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\Program Files\Comodo\Firewall\cmdagent.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\WINDOWS\ehome\RMSvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\ZuneBusEnum.exe

    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\ehome\ehtray.exe

    C:\WINDOWS\eHome\ehmsas.exe

    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\WINDOWS\stsystra.exe

    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\Program Files\Transcode360\Transcode360Tray.exe

    C:\Program Files\Zune\ZuneLauncher.exe

    C:\Program Files\Comodo\Firewall\cfp.exe

    C:\Program Files\Microsoft ActiveSync\Wcescomm.exe

    C:\Program Files\Windows Media Player\WMPNSCFG.exe

    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe

    C:\PROGRA~1\MI3AA1~1\rapimgr.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\WINDOWS\ehome\RMSysTry.exe

    C:\Program Files\CyberLink\Shared files\RichVideo.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\SecCenter\scprot4.exe

    C:\Program Files\Alwil Software\Avast4\ashSimpl.exe

    C:\Hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/campaign.asp?cid=16313

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll

    O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

    O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll

    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

    O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    O4 - HKLM\..\Run: [Transcode360] C:\Program Files\Transcode360\Transcode360Tray.exe

    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

    O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"

    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\cfp.exe" -s

    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

    O4 - HKLM\..\Run: [wdevwhuz] rundll32.exe "C:\Program Files\ryvibatg\pufoxgpu.dll",Init

    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"

    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

    O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll

    O9 - Extra button: FreshDownload - {46E72E01-FAB2-42AD-92BE-08BE4E092B5A} - C:\Program Files\FreshDevices\FreshDownload\fd.exe

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab

    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

    O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/Activ...iveXClient1.cab

    O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab

    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab

    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bejewel...aploader_v6.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...065/mcfscan.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{329A3B50-741F-48E7-8D89-85E949C8982C}: NameServer = 192.168.0.1

    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll

    O20 - Winlogon Notify: hggdbcc - C:\WINDOWS\SYSTEM32\hggdbcc.dll

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O20 - Winlogon Notify: winmmt32 - C:\WINDOWS\SYSTEM32\winmmt32.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe

    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

    O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

  11. Logfile of HijackThis v1.99.1

    Scan saved at 11:17:12 AM, on 12/2/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

    C:\WINDOWS\eHome\ehmsas.exe

    C:\WINDOWS\stsystra.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\DellSupport\DSAgnt.exe

    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.wisc.edu/portal/index.jsp

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R3 - URLSearchHook: (no name) - - (no file)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {4991EFD5-91EC-450A-8E0C-F868007FDC9B} - C:\Program Files\Common Files\meqo43855.dll (file missing)

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O2 - BHO: (no name) - {69D1138B-EA15-4764-B837-511A31894C80} - C:\WINDOWS\system32\mljgf.dll (file missing)

    O2 - BHO: (no name) - {71DC6AF1-96F7-484C-867E-A10AD075D213} - \

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

    O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

    O4 - HKLM\..\Run: [showLOMControl]

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe

    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"

    O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [czwqaqrA] C:\WINDOWS\czwqaqrA.exe

    O4 - HKLM\..\Run: [{70-0B-BD-D4-ZN}] C:\windows\system32\podsregn.exe SKY003

    O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

    O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)

    O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

    O20 - Winlogon Notify: rqrrspn - rqrrspn.dll (file missing)

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

  12. I did not install Empire poker and am unable to find it on the computer to uninstall as well. Here are my new logs.

    ComboFix 07-12-02.5 - Michelle 2007-12-02 11:08:35.1 - NTFSx86

    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.525 [GMT -6:00]

    Running from: C:\Documents and Settings\Michelle\Desktop\ComboFix.exe

    * Created a new restore point

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    C:\Documents and Settings\All Users\Application Data.\salesmonitor

    C:\Documents and Settings\All Users\Application Data.\winantispyware 2007

    C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\Abbr

    C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCode

    C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr

    C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode

    C:\Documents and Settings\Michelle\err.log

    C:\Program Files\winpop

    C:\Program Files\winpop\UnInstall.exe

    C:\temp\0b9

    C:\temp\0b9\tmpTF.log

    C:\temp\iee

    C:\temp\iee\tmpZTF.log

    C:\temp\tn3

    C:\WINDOWS\cookies.ini

    C:\WINDOWS\cs_cache.ini

    C:\WINDOWS\retadpu.exe.bin

    C:\WINDOWS\system32\advbkprt.exe

    C:\WINDOWS\system32\amxdvmxh.exe

    C:\WINDOWS\system32\bdlaaybt.exe

    C:\WINDOWS\system32\bhvgoenh.exe

    C:\WINDOWS\system32\bjabuaql.exe

    C:\WINDOWS\system32\deurmhxu.exe

    C:\WINDOWS\system32\dfcbrmxa.exe

    C:\WINDOWS\system32\drivers\core.cache.dsk

    C:\WINDOWS\system32\drivers\core.sys

    C:\WINDOWS\system32\eaqbkbgc.exe

    C:\WINDOWS\system32\eotuexja.exe

    C:\WINDOWS\system32\fmduefeu.dll

    C:\WINDOWS\system32\fwtaeyyn.dll

    C:\WINDOWS\system32\gsokujbd.exe

    C:\WINDOWS\system32\gyxydcan.exe

    C:\WINDOWS\system32\H1

    C:\WINDOWS\system32\H1\wbb22.exe

    C:\WINDOWS\system32\H2

    C:\WINDOWS\system32\H3

    C:\WINDOWS\system32\H4

    C:\WINDOWS\system32\H5

    C:\WINDOWS\system32\H5\bk53.exe

    C:\WINDOWS\system32\hrjopuxj.exe

    C:\WINDOWS\system32\iguxkhlm.exe

    C:\WINDOWS\system32\jaknmcyk.ini

    C:\WINDOWS\system32\jiysmrhd.exe

    C:\WINDOWS\system32\jwxsltfc.exe

    C:\WINDOWS\system32\kdxorlik.exe

    C:\WINDOWS\system32\kmkpgjos.exe

    C:\WINDOWS\system32\kttapgov.exe

    C:\WINDOWS\system32\kwgprmty.exe

    C:\WINDOWS\system32\kycmnkaj.dll

    C:\WINDOWS\system32\lgohpndo.exe

    C:\WINDOWS\system32\mcgocunv.exe

    C:\WINDOWS\system32\mdmksnng.exe

    C:\WINDOWS\system32\mluxowxl.exe

    C:\WINDOWS\system32\nsrnpnih.exe

    C:\WINDOWS\system32\nyyeatwf.ini

    C:\WINDOWS\system32\o02PrEz

    C:\WINDOWS\system32\o02PrEz\o02PrEz1065.exe

    C:\WINDOWS\system32\otiyorse.dll

    C:\WINDOWS\system32\oxapsvmr.dll

    C:\WINDOWS\system32\piqoibxy.exe

    C:\WINDOWS\system32\pmihorwn.exe

    C:\WINDOWS\system32\qghkhqdw.dll

    C:\WINDOWS\system32\qoehhmhm.exe

    C:\WINDOWS\system32\rjesrnuv.exe

    C:\WINDOWS\system32\trfhhjxq.exe

    C:\WINDOWS\system32\ttxuyuxw.exe

    C:\WINDOWS\system32\txgcxlmg.exe

    C:\WINDOWS\system32\uemqyvhx.exe

    C:\WINDOWS\system32\uiubbpim.exe

    C:\WINDOWS\system32\ujwnjgby.exe

    C:\WINDOWS\system32\urxqhrpd.exe

    C:\WINDOWS\system32\utyhvldo.exe

    C:\WINDOWS\system32\vjgauirb.exe

    C:\WINDOWS\system32\wdqhkhgq.ini

    C:\WINDOWS\system32\win

    C:\WINDOWS\system32\xjlvqjxo.exe

    C:\WINDOWS\system32\xkbnyrot.dll

    C:\WINDOWS\system32\xluriaha.exe

    C:\WINDOWS\system32\xphkphnu.exe

    C:\WINDOWS\system32\xrvctqbq.exe

    C:\WINDOWS\system32\ywldlruo.exe

    .

    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    -------\LEGACY_CORE

    -------\LEGACY_NETWORK_MONITOR

    -------\LEGACY_WINDOWS_OVERLAY_COMPONENTS

    -------\core

    ((((((((((((((((((((((((( Files Created from 2007-11-02 to 2007-12-02 )))))))))))))))))))))))))))))))

    .

    2007-12-02 02:40 . 2007-12-02 02:40 <DIR> d-------- C:\Deckard

    2007-12-02 01:52 . 2007-12-02 02:37 <DIR> d-------- C:\VundoFix Backups

    2007-12-02 00:57 . 2007-12-02 01:19 <DIR> d-------- C:\WINDOWS\system32\ActiveScan

    2007-12-02 00:57 . 2007-12-02 00:57 30,590 --a------ C:\WINDOWS\system32\pavas.ico

    2007-12-02 00:57 . 2007-12-02 00:57 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico

    2007-12-02 00:57 . 2007-12-02 00:57 1,406 --a------ C:\WINDOWS\system32\Help.ico

    2007-12-02 00:45 . 2007-12-02 02:46 <DIR> d-------- C:\hijackthis

    2007-12-01 11:24 . 2007-12-02 00:41 687,777 ---hs---- C:\WINDOWS\system32\ujarennp.ini

    2007-11-29 22:20 . 2007-12-01 11:22 735,961 ---hs---- C:\WINDOWS\system32\mitckhrk.ini

    2007-11-28 22:20 . 2007-11-29 21:30 860,784 ---hs---- C:\WINDOWS\system32\vxpjocqr.ini

    2007-11-28 15:27 . 2007-11-28 15:27 54,156 --ah----- C:\WINDOWS\QTFont.qfn

    2007-11-28 15:27 . 2007-11-28 15:27 1,409 --a------ C:\WINDOWS\QTFont.for

    2007-11-27 22:13 . 2007-11-28 22:13 989,051 ---hs---- C:\WINDOWS\system32\psxksrrc.ini

    2007-11-26 22:17 . 2007-11-27 22:06 991,583 ---hs---- C:\WINDOWS\system32\qfywnhfo.ini

    2007-11-25 14:44 . 2007-11-26 22:12 1,013,146 ---hs---- C:\WINDOWS\system32\fbaejpvh.ini

    2007-11-20 18:56 . 2007-11-25 14:37 1,010,942 ---hs---- C:\WINDOWS\system32\iyhemfdy.ini

    2007-11-19 18:59 . 2007-11-20 16:57 686,628 ---hs---- C:\WINDOWS\system32\onxvlymy.ini

    2007-11-18 18:59 . 2007-11-19 16:02 622,988 ---hs---- C:\WINDOWS\system32\qpyqxpxu.ini

    2007-11-17 18:56 . 2007-11-18 18:56 622,808 ---hs---- C:\WINDOWS\system32\cguwwpay.ini

    2007-11-16 13:21 . 2007-11-16 13:21 1,203 --a------ C:\WINDOWS\mozver.dat

    2007-11-16 13:16 . 2007-11-17 18:51 622,628 ---hs---- C:\WINDOWS\system32\hfdpccyq.ini

    2007-11-15 12:54 . 2007-11-16 13:11 734,232 ---hs---- C:\WINDOWS\system32\ldlilitm.ini

    2007-11-14 12:52 . 2007-11-15 12:53 655,446 ---hs---- C:\WINDOWS\system32\yvedjivk.ini

    2007-11-13 11:22 . 2007-11-14 12:23 655,942 ---hs---- C:\WINDOWS\system32\chvokniv.ini

    2007-11-12 10:52 . 2007-11-13 11:18 669,654 ---hs---- C:\WINDOWS\system32\kuksxxcb.ini

    2007-11-11 09:48 . 2007-11-12 10:47 590,836 ---hs---- C:\WINDOWS\system32\cplnhcva.ini

    2007-11-10 00:21 . 2007-11-11 09:33 584,656 ---hs---- C:\WINDOWS\system32\tshasmqt.ini

    2007-11-07 12:50 . 2007-11-08 22:16 583,060 ---hs---- C:\WINDOWS\system32\btrbhmjv.ini

    2007-11-05 10:41 . 2007-11-05 10:41 <DIR> d-------- C:\Documents and Settings\Michelle\Application Data\Template

    2007-11-04 19:48 . 2007-11-06 09:52 1,124,394 ---hs---- C:\WINDOWS\system32\ciyhycsy.ini

    2007-11-02 10:38 . 2007-11-04 19:43 1,148,154 ---hs---- C:\WINDOWS\system32\iipifjeg.ini

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2007-12-02 07:46 --------- d-----w C:\Program Files\Bonjour

    2007-12-02 07:46 --------- d-----w C:\Program Files\BAE

    2007-12-01 17:25 --------- d-----w C:\Program Files\SpywareBlaster

    2007-11-30 17:55 18,698 ----a-w C:\Documents and Settings\Michelle\Application Data\wklnhst.dat

    2007-11-27 18:18 --------- d--h--w C:\Documents and Settings\Michelle\Application Data\Move Networks

    2007-10-21 00:55 --------- d-----w C:\Program Files\Lavasoft

    2007-10-21 00:55 --------- d-----w C:\Documents and Settings\Michelle\Application Data\Lavasoft

    2007-10-21 00:54 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

    2007-10-21 00:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft

    2007-10-21 00:32 --------- d-----w C:\Program Files\Google

    2007-01-29 02:03 58,600 ----a-w C:\Documents and Settings\Michelle\Application Data\GDIPFONTCACHEV1.DAT

    2005-07-29 21:24 472 --sha-r C:\WINDOWS\TWljaGVsbGU\nq53u3pPv3o.vbs

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4991EFD5-91EC-450A-8E0C-F868007FDC9B}]

    C:\Program Files\Common Files\meqo43855.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69D1138B-EA15-4764-B837-511A31894C80}]

    C:\WINDOWS\system32\mljgf.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{71DC6AF1-96F7-484C-867E-A10AD075D213}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 19:39]

    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]

    "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 13:01]

    "SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 16:48]

    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 10:55]

    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 10:56]

    "ShowLOMControl"="1 (0x1)" []

    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 11:48]

    "DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 19:29]

    "RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-12 16:27]

    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-12 16:28]

    "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 00:05]

    "ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 09:44]

    "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 09:44]

    "MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 18:20]

    "pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 15:30]

    "Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-11-16 18:08]

    "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 16:30 C:\WINDOWS\stsystra.exe]

    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 19:17]

    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 19:13]

    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 19:17]

    "czwqaqrA"="C:\WINDOWS\czwqaqrA.exe" []

    "{70-0B-BD-D4-ZN}"="C:\windows\system32\podsregn.exe" []

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]

    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-12 16:24:40]

    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrrspn]

    rqrrspn.dll

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]

    \Shell\AutoRun\command - E:\setup.exe

    .

    **************************************************************************

    catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2007-12-02 11:12:50

    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully

    hidden files: 0

    **************************************************************************

    .

    Completion time: 2007-12-02 11:14:11 - machine was rebooted

    .

    --- E O F ---

  13. Here is my new hijack log. Thanks once again.

    Logfile of HijackThis v1.99.1

    Scan saved at 2:46:04 AM, on 12/2/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe

    C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe

    C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

    C:\WINDOWS\stsystra.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe

    C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\DellSupport\DSAgnt.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\eHome\ehmsas.exe

    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe

    c:\program files\common files\installshield\updateservice\isuspm.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.wisc.edu/portal/index.jsp

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R3 - URLSearchHook: (no name) - - (no file)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {4991EFD5-91EC-450A-8E0C-F868007FDC9B} - C:\Program Files\Common Files\meqo43855.dll (file missing)

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O2 - BHO: (no name) - {69D1138B-EA15-4764-B837-511A31894C80} - C:\WINDOWS\system32\mljgf.dll (file missing)

    O2 - BHO: (no name) - {71DC6AF1-96F7-484C-867E-A10AD075D213} - \

    O2 - BHO: {e203e144-d106-21bb-9464-6665727865d9} - {9d568727-5666-4649-bb12-601d441e302e} - C:\WINDOWS\system32\otiyorse.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

    O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

    O4 - HKLM\..\Run: [showLOMControl]

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: [iSUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe

    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"

    O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [czwqaqrA] C:\WINDOWS\czwqaqrA.exe

    O4 - HKLM\..\Run: [{70-0B-BD-D4-ZN}] C:\windows\system32\podsregn.exe SKY003

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O4 - HKLM\..\Run: [4ca70b7b] rundll32.exe "C:\WINDOWS\system32\fwtaeyyn.dll",b

    O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup

    O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

    O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)

    O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

    O20 - Winlogon Notify: rqrrspn - rqrrspn.dll (file missing)

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\ixanhtum.exe (file missing)

    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

  14. Deckard's System Scanner v20071014.68

    Extra logfile - please post this as an attachment with your post.

    --------------------------------------------------------------------------------

    -- System Information ----------------------------------------------------------

    Microsoft Windows XP Professional (build 2600) SP 2.0

    Architecture: X86; Language: English

    CPU 0: Genuine Intel® CPU T2400 @ 1.83GHz

    CPU 1: Genuine Intel® CPU T2400 @ 1.83GHz

    Percentage of Memory in Use: 48%

    Physical Memory (total/avail): 1014.37 MiB / 526.38 MiB

    Pagefile Memory (total/avail): 2441.45 MiB / 2051.66 MiB

    Virtual Memory (total/avail): 2047.88 MiB / 1926.43 MiB

    C: is Fixed (NTFS) - 49.7 GiB total, 38.15 GiB free.

    D: is CDROM (No Media)

    \\.\PHYSICALDRIVE0 - Hitachi HTS541060G9SA00 - 54.49 GiB - 3 partitions

    \PARTITION0 - Unknown - 39.19 MiB

    \PARTITION1 (bootable) - Installable File System - 49.7 GiB - C:

    \PARTITION2 - Unknown - 4.74 GiB

    -- Security Center -------------------------------------------------------------

    AUOptions is scheduled to auto-install.

    Windows Internal Firewall is enabled.

    FirstRunDisabled is set.

    FW: Trend Micro PC-cillin Internet Security (Firewall) v12 (Trend Micro, Inc.)

    AV: Trend Micro PC-cillin Internet Security v12.7.1019 (Trend Micro, Inc.) Outdated

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"

    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"

    "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"

    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"

    "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"

    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"

    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"

    "C:\\Program Files\\Ruckus Player\\Ruckus.exe"="C:\\Program Files\\Ruckus Player\\Ruckus.exe:*:Enabled:Ruckus Player"

    "C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"="C:\\Program Files\\QuickTime\\QuickTimePlayer.exe:*:Enabled:QuickTime Player"

    "C:\\WINDOWS\\system32\\ixanhtum.exe"="C:\\WINDOWS\\system32\\ixa"

    -- Environment Variables -------------------------------------------------------

    ALLUSERSPROFILE=C:\Documents and Settings\All Users

    APPDATA=C:\Documents and Settings\Michelle\Application Data

    CLIENTNAME=Console

    CommonProgramFiles=C:\Program Files\Common Files

    COMPUTERNAME=MICKI

    ComSpec=C:\WINDOWS\system32\cmd.exe

    FP_NO_HOST_CHECK=NO

    HOMEDRIVE=C:

    HOMEPATH=\Documents and Settings\Michelle

    LOGONSERVER=\\MICKI

    NUMBER_OF_PROCESSORS=2

    OS=Windows_NT

    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem

    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH

    PROCESSOR_ARCHITECTURE=x86

    PROCESSOR_IDENTIFIER=x86 Family 6 Model 14 Stepping 8, GenuineIntel

    PROCESSOR_LEVEL=6

    PROCESSOR_REVISION=0e08

    ProgramFiles=C:\Program Files

    PROMPT=$P$G

    SESSIONNAME=Console

    SonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\

    SystemDrive=C:

    SystemRoot=C:\WINDOWS

    TEMP=C:\DOCUME~1\Michelle\LOCALS~1\Temp

    TMP=C:\DOCUME~1\Michelle\LOCALS~1\Temp

    USERDOMAIN=MICKI

    USERNAME=Michelle

    USERPROFILE=C:\Documents and Settings\Michelle

    windir=C:\WINDOWS

    -- User Profiles ---------------------------------------------------------------

    Michelle (admin)

    Administrator (admin)

    -- Add/Remove Programs ---------------------------------------------------------

    --> C:\PROGRA~1\RUCKUS~1\UNWISE.EXE /a C:\PROGRA~1\RUCKUS~1\INSTALL.LOG

    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}

    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}

    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}

    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}

    --> MsiExec.exe /I{95D9B4D8-B091-4fab-80EA-313EB4B82FD6}

    --> MsiExec.exe /I{EB997E90-5EB0-4eb5-90D0-90B1D2F0CA03}

    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf

    Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}

    Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q

    Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe

    Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}

    Banctec Service Agreement --> MsiExec.exe /X{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}

    Bejeweled 2 Deluxe --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\989E4C3B-B2C9-4486-9A09-D5A8F953837C\Uninstall.exe"

    Blasterball 2 --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\D1A6F3FD-7B40-443F-8767-BADB25A0D222\Uninstall.exe"

    Bonjour Core for Windows --> MsiExec.exe /I{56DF5C9E-6392-46D3-B366-297B14E1DAAF}

    Broadcom Management Programs --> MsiExec.exe /I{26E1BFB0-E87E-4696-9F89-B467F01F81E5}

    Conexant HDA D110 MDC V.92 Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3\HXFSETUP.EXE -U -Idel1028p.inf

    Corel Paint Shop Pro X --> MsiExec.exe /I{1A15507A-8551-4626-915D-3D5FA095CC1B}

    Corel Photo Album 6 --> MsiExec.exe /X{8A9B8148-DDD7-448F-BD6C-358386D32354}

    Dell Digital Jukebox Driver --> C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s

    Dell Game Console --> "C:\Program Files\WildTangent\Apps\Dell Game Console\Uninstall.exe"

    DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}

    Digital Content Portal --> MsiExec.exe /I{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}

    Digital Line Detect --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel

    DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN

    EducateU --> MsiExec.exe /I{A683A2C0-821C-486F-858C-FA634DB5E864}

    ESPNMotion --> C:\PROGRA~1\ESPNMO~1\UNWISE.EXE /u C:\PROGRA~1\ESPNMO~1\INSTALL.LOG

    FATE --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\C2D8F0E2-6978-4409-8351-BA8785DA11EE\Uninstall.exe"

    GemMaster Mystic --> "C:\Program Files\GemMaster\uninstallgemmaster.exe"

    High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe

    HijackThis 1.99.1 --> C:\hijackthis\HijackThis.exe /uninstall

    Intel® Graphics Media Accelerator Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_27A6 PCI\VEN_8086&DEV_27A2

    Intel® PROSet/Wireless Software --> C:\WINDOWS\Installer\iProInst.exe

    Internal Network Card Power Management --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F528948-0E80-4C96-B455-DE4167CB1DF7}\setup.exe" -l0x9 UNINSTALL APPDRVNT4

    Java 2 Runtime Environment, SE v1.4.2_03 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}

    Learn2 Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe

    Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log

    mCore --> MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}

    mDrWiFi --> MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}

    mHlpDell --> MsiExec.exe /I{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}

    Microsoft Digital Image Standard 2006 --> "C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=PREM VERSION=11

    Microsoft Encarta Encyclopedia Standard 2006 --> MsiExec.exe /I{06040048-3E21-46D6-9A91-D927BA08F41D}

    Microsoft Money 2006 --> "C:\Program Files\Microsoft Money 2006\MNYCoreFiles\Setup\uninst.exe" /s:120

    Microsoft Plus! Digital Media Edition Installer --> MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}

    Microsoft Plus! Photo Story 2 LE --> MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}

    Microsoft Streets & Trips 2006 --> MsiExec.exe /I{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}

    Microsoft Word 2002 --> MsiExec.exe /I{911B0409-6000-11D3-8CFE-0050048383C9}

    Microsoft Works --> MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}

    Microsoft Works Suite 2006 Setup Launcher --> C:\Program Files\Microsoft Works Suite 2006\Setup\Launcher.exe /ARP D:\

    Microsoft Works Suite Add-in for Microsoft Word --> MsiExec.exe /I{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}

    mIWA --> MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}

    mLogView --> MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}

    mMHouse --> MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}

    Modem Helper --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel

    Move Networks Media Player for Internet Explorer --> C:\Documents and Settings\Michelle\Application Data\Move Networks\ie_bin\Uninst.exe

    Move Networks Player for Internet Explorer --> "C:\Documents and Settings\Michelle\Application Data\Move Networks\ie_bin\unins000.exe"

    Mozilla Firefox (2.0.0.10) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe

    mPfMgr --> MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}

    mPfWiz --> MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}

    mProSafe --> MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}

    mSSO --> MsiExec.exe /I{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}

    Musicmatch® Jukebox --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst

    mWlsSafe --> MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}

    mWMI --> MsiExec.exe /I{63DB9CCD-2B56-4217-9A3D-507AC78320CA}

    mXML --> MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}

    mZConfig --> MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}

    NetWaiting --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel

    Otto --> "C:\Program Files\EnglishOtto\uninstallotto.exe"

    Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan

    PowerDVD 5.7 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall

    QuickSet --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe" -l0x9 APPDRVNT4

    QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log

    RealPlayer Basic --> C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0

    Ruckus Player --> C:\PROGRA~1\RUCKUS~1\UNWISE.EXE C:\PROGRA~1\RUCKUS~1\INSTALL.LOG

    SCRABBLE --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA\Uninstall.exe"

    Search Assist --> MsiExec.exe /X{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}

    SigmaTel Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\101\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly

    Sonic DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}

    Sonic Encoders --> MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}

    Sonic RecordNow Audio --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}

    Sonic RecordNow Copy --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}

    Sonic RecordNow Data --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}

    Sonic Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}

    Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"

    SpywareBlaster v3.5.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"

    Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall

    Trend Micro PC-cillin Internet Security 12 --> MsiExec.exe /X{7698EDA5-A90F-4205-99CB-8FF6F9048ED9}

    Update Rollup 2 for Windows XP Media Center Edition 2005 --> C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe

    URL Assistant --> regsvr32 /u /s "c:\Program Files\BAE\BAE.dll"

    Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u

    WebCyberCoach 3.2 Dell --> "C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"

    Windows XP Media Center Edition 2005 KB908246 --> "C:\WINDOWS\$NtUninstallKB908246$\spuninst\spuninst.exe"

    Windows XP Media Center Edition 2005 KB908250 -->

    WinPop --> C:\Program Files\WinPop\UnInstall.exe

    -- Application Event Log -------------------------------------------------------

    Event Record #/Type18436 / Warning

    Event Submitted/Written: 12/02/2007 02:37:16 AM

    Event ID/Source: 1001 / MsiInstaller

    Event Description:

    Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum' failed during request for component '{D2D7B4BF-6CCA-11D5-8B3F-00105A9846E9}'

    Event Record #/Type18435 / Warning

    Event Submitted/Written: 12/02/2007 02:37:16 AM

    Event ID/Source: 1004 / MsiInstaller

    Event Description:

    Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum', component '{25F669D8-9DC1-44D1-A06B-28E42E930387}' failed. The resource 'HKEY_CURRENT_USER\Software\Corel\Auto Update\{8A9B8148-DDD7-448F-BD6C-358386D32354}\Interval' does not exist.

    Event Record #/Type18434 / Warning

    Event Submitted/Written: 12/02/2007 02:37:16 AM

    Event ID/Source: 1001 / MsiInstaller

    Event Description:

    Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum' failed during request for component '{D2D7B4BF-6CCA-11D5-8B3F-00105A9846E9}'

    Event Record #/Type18433 / Warning

    Event Submitted/Written: 12/02/2007 02:37:16 AM

    Event ID/Source: 1004 / MsiInstaller

    Event Description:

    Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum', component '{25F669D8-9DC1-44D1-A06B-28E42E930387}' failed. The resource 'HKEY_CURRENT_USER\Software\Corel\Auto Update\{8A9B8148-DDD7-448F-BD6C-358386D32354}\Interval' does not exist.

    Event Record #/Type18432 / Warning

    Event Submitted/Written: 12/02/2007 02:37:16 AM

    Event ID/Source: 1001 / MsiInstaller

    Event Description:

    Detection of product '{8A9B8148-DDD7-448F-BD6C-358386D32354}', feature 'PaintShopPhotoAlbum' failed during request for component '{D2D7B4BF-6CCA-11D5-8B3F-00105A9846E9}'

    -- Security Event Log ----------------------------------------------------------

    No Errors/Warnings found.

    -- System Event Log ------------------------------------------------------------

    Event Record #/Type26320 / Error

    Event Submitted/Written: 12/02/2007 00:16:53 AM

    Event ID/Source: 1003 / System Error

    Event Description:

    Error code 100000ce, parameter1 aa11a74e, parameter2 00000008, parameter3 aa11a74e, parameter4 00000000.

    Event Record #/Type26293 / Error

    Event Submitted/Written: 12/01/2007 11:54:19 PM

    Event ID/Source: 1000 / Dhcp

    Event Description:

    Your computer has lost the lease to its IP address 204.15.111.227 on the

    Network Card with network address 001302198D7B.

    Event Record #/Type26292 / Warning

    Event Submitted/Written: 12/01/2007 11:54:19 PM

    Event ID/Source: 1003 / Dhcp

    Event Description:

    Your computer was not able to renew its address from the network (from the

    DHCP Server) for the Network Card with network address 001302198D7B. The following

    error occurred:

    %%121.

    Your computer will continue to try and obtain an address on its own from

    the network address (DHCP) server.

    Event Record #/Type26288 / Error

    Event Submitted/Written: 12/01/2007 06:57:19 PM

    Event ID/Source: 1000 / Dhcp

    Event Description:

    Your computer has lost the lease to its IP address 204.15.111.227 on the

    Network Card with network address 001302198D7B.

    Event Record #/Type26287 / Warning

    Event Submitted/Written: 12/01/2007 06:57:19 PM

    Event ID/Source: 1003 / Dhcp

    Event Description:

    Your computer was not able to renew its address from the network (from the

    DHCP Server) for the Network Card with network address 001302198D7B. The following

    error occurred:

    %%121.

    Your computer will continue to try and obtain an address on its own from

    the network address (DHCP) server.

    -- End of Deckard's System Scanner: finished at 2007-12-02 02:42:38 ------------

  15. Deckard's System Scanner v20071014.68

    Run by Michelle on 2007-12-02 02:40:28

    Computer is in Normal Mode.

    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.

    -- Last 5 Restore Point(s) --

    25: 2007-12-02 08:40:35 UTC - RP90 - Deckard's System Scanner Restore Point

    24: 2007-11-30 18:38:05 UTC - RP89 - System Checkpoint

    23: 2007-11-29 03:30:55 UTC - RP88 - System Checkpoint

    22: 2007-11-24 22:51:51 UTC - RP87 - System Checkpoint

    21: 2007-11-21 20:15:30 UTC - RP86 - System Checkpoint

    -- First Restore Point --

    1: 2007-10-11 12:58:56 UTC - RP66 - Software Distribution Service 3.0

    Backed up registry hives.

    Performed disk cleanup.

    -- HijackThis (run as Michelle.exe) --------------------------------------------

    Unable to find log (file not found); running clone.

    -- HijackThis Clone ------------------------------------------------------------

    Emulating logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 2007-12-02 02:42:10

    Platform: Windows XP Service Pack 2 (5.01.2600)

    MSIE: Internet Explorer (6.00.2900.2180)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\system32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\WINDOWS\explorer.exe

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe

    C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

    C:\Program Files\Real\RealPlayer\realplay.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe

    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe

    C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

    C:\WINDOWS\stsystra.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe

    C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\DellSupport\DSAgnt.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\WINDOWS\ehome\ehrecvr.exe

    C:\WINDOWS\ehome\ehSched.exe

    C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe

    C:\Program Files\Trend Micro\Internet Security 12\PcCtlCom.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\Program Files\Trend Micro\Internet Security 12\Tmntsrv.exe

    C:\Program Files\Trend Micro\Internet Security 12\tmproxy.exe

    C:\Program Files\Trend Micro\Internet Security 12\TmPfw.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\ehome\ehmsas.exe

    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe

    C:\Documents and Settings\Michelle\Desktop\dss.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl...&channel=us

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.wisc.edu/portal/index.jsp

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.com/ig/dell?hl=en&cl...&channel=us

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl...&channel=us

    R3 - URLSearchHook: (no name) - - (no file)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {4991EFD5-91EC-450A-8E0C-F868007FDC9B} - C:\Program Files\Common Files\meqo43855.dll (file missing)

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O2 - BHO: (no name) - {69D1138B-EA15-4764-B837-511A31894C80} - C:\WINDOWS\system32\mljgf.dll (file missing)

    O2 - BHO: (no name) - {71DC6AF1-96F7-484C-867E-A10AD075D213} - \

    O2 - BHO: {e203e144-d106-21bb-9464-6665727865d9} - {9d568727-5666-4649-bb12-601d441e302e} - C:\WINDOWS\system32\otiyorse.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll

    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

    O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

    O4 - HKLM\..\Run: [showLOMControl] 1

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: [iSUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe

    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"

    O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [czwqaqrA] C:\WINDOWS\czwqaqrA.exe

    O4 - HKLM\..\Run: [{70-0B-BD-D4-ZN}] C:\windows\system32\podsregn.exe SKY003

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O4 - HKLM\..\Run: [4ca70b7b] rundll32.exe "C:\WINDOWS\system32\fwtaeyyn.dll",b

    O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup

    O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)

    O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - (file missing)

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O15 - Trusted Zone: https://online.musicmatch.com (HKLM)

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab

    O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL

    O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll

    O20 - Winlogon Notify: rqrrspn - C:\WINDOWS\system32\rqrrspn.dll (file missing)

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\ixanhtum.exe /service

    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe

    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security 12\PcCtlCom.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security 12\Tmntsrv.exe

    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security 12\TmPfw.exe

    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security 12\tmproxy.exe

    O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe

    --

    End of file - 10873 bytes

    -- File Associations -----------------------------------------------------------

    All associations okay.

    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>

    R1 core - c:\windows\system32\drivers\core.sys

    R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>

    R1 tmtdi (Trend Micro TDI Driver) - c:\windows\system32\drivers\tmtdi.sys <Not Verified; Trend Micro Inc.; Trend Micro Network Security Component 1.0>

    R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.4.9.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.4.9.0>

    R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>

    R2 s24trans (WLAN Transport) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>

    R2 tm_cfw (Common Firewall Driver) - c:\windows\system32\drivers\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Network Security Component 1.0>

    R3 DSproct - c:\program files\dellsupport\gtaction\triggers\dsproct.sys <Not Verified; Gteko Ltd.; processt>

    S3 UIUSys (Conexant Setup API) - c:\windows\system32\drivers\uiusys.sys (file missing)

    S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)

    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>

    R2 NICCONFIGSVC - c:\program files\dell\nicconfigsvc\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>

    R2 PcCtlCom (Trend Micro Central Control Component) - c:\progra~1\trendm~1\intern~1\pcctlcom.exe <Not Verified; Trend Micro Incorporated.; Trend Micro Internet Security>

    R2 RegSrvc (Intel® PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; Intel® PROSet/Wireless Registry Service>

    R2 Tmntsrv (Trend Micro Real-time Service) - c:\progra~1\trendm~1\intern~1\tmntsrv.exe <Not Verified; Trend Micro Incorporated.; Trend Micro Internet Security>

    R2 TmPfw (Trend Micro Personal Firewall) - c:\progra~1\trendm~1\intern~1\tmpfw.exe <Not Verified; Trend Micro Inc.; Trend Network Security Component 1.0>

    R2 tmproxy (Trend Micro Proxy Service) - c:\progra~1\trendm~1\intern~1\tmproxy.exe <Not Verified; Trend Micro Inc.; Trend Micro Network Security Components 1.0>

    R2 WLANKEEPER (Intel® PROSet/Wireless SSO Service) - c:\program files\intel\wireless\bin\wlkeeper.exe <Not Verified; Intel® Corporation; SSO Service>

    S2 DomainService - c:\windows\system32\ixanhtum.exe /service (file missing)

    -- Device Manager: Disabled ----------------------------------------------------

    No disabled devices found.

    -- Files created between 2007-11-02 and 2007-12-02 -----------------------------

    2007-12-02 01:52:46 0 d-------- C:\VundoFix Backups

    2007-12-02 00:57:06 0 d-------- C:\WINDOWS\system32\ActiveScan

    2007-12-02 00:47:48 85056 --a------ C:\WINDOWS\system32\fwtaeyyn.dll

    2007-12-02 00:45:22 0 d-------- C:\hijackthis

    2007-12-02 00:44:45 76864 --a------ C:\WINDOWS\system32\otiyorse.dll

    2007-12-02 00:44:44 71232 --a------ C:\WINDOWS\system32\mluxowxl.exe <Not Verified; ; DDC>

    2007-12-01 12:21:46 78400 --a------ C:\WINDOWS\system32\fmduefeu.dll

    2007-12-01 11:23:24 71232 --a------ C:\WINDOWS\system32\dfcbrmxa.exe <Not Verified; ; DDC>

    2007-11-29 22:14:30 71232 --a------ C:\WINDOWS\system32\piqoibxy.exe <Not Verified; ; DDC>

    2007-11-28 22:14:37 71232 --a------ C:\WINDOWS\system32\rjesrnuv.exe <Not Verified; ; DDC>

    2007-11-27 22:13:18 71232 --a------ C:\WINDOWS\system32\lgohpndo.exe <Not Verified; ; DDC>

    2007-11-26 22:13:18 71232 --a------ C:\WINDOWS\system32\uemqyvhx.exe <Not Verified; ; DDC>

    2007-11-25 14:37:59 71232 --a------ C:\WINDOWS\system32\urxqhrpd.exe <Not Verified; ; DDC>

    2007-11-24 14:37:40 71232 --a------ C:\WINDOWS\system32\mdmksnng.exe <Not Verified; ; DDC>

    2007-11-20 18:53:39 71232 --a------ C:\WINDOWS\system32\ttxuyuxw.exe <Not Verified; ; DDC>

    2007-11-19 18:53:25 71232 --a------ C:\WINDOWS\system32\kdxorlik.exe <Not Verified; ; DDC>

    2007-11-18 18:53:45 71232 --a------ C:\WINDOWS\system32\kwgprmty.exe <Not Verified; ; DDC>

    2007-11-17 18:52:25 71232 --a------ C:\WINDOWS\system32\deurmhxu.exe <Not Verified; ; DDC>

    2007-11-16 13:21:06 1203 --a------ C:\WINDOWS\mozver.dat

    2007-11-16 13:12:20 71232 --a------ C:\WINDOWS\system32\xluriaha.exe <Not Verified; ; DDC>

    2007-11-15 12:48:03 71232 --a------ C:\WINDOWS\system32\hrjopuxj.exe <Not Verified; ; DDC>

    2007-11-14 12:49:43 71232 --a------ C:\WINDOWS\system32\bdlaaybt.exe <Not Verified; ; DDC>

    2007-11-13 11:18:50 71232 --a------ C:\WINDOWS\system32\gyxydcan.exe <Not Verified; ; DDC>

    2007-11-12 10:48:40 71232 --a------ C:\WINDOWS\system32\kmkpgjos.exe <Not Verified; ; DDC>

    2007-11-11 09:42:15 71232 --a------ C:\WINDOWS\system32\xrvctqbq.exe <Not Verified; ; DDC>

    2007-11-10 09:40:26 71232 --a------ C:\WINDOWS\system32\ujwnjgby.exe <Not Verified; ; DDC>

    2007-11-10 00:15:55 71232 --a------ C:\WINDOWS\system32\ywldlruo.exe <Not Verified; ; DDC>

    2007-11-08 22:21:00 86080 --a------ C:\WINDOWS\system32\kycmnkaj.dll

    2007-11-08 22:18:00 71232 --a------ C:\WINDOWS\system32\uiubbpim.exe <Not Verified; ; DDC>

    2007-11-08 22:16:11 71232 --a------ C:\WINDOWS\system32\xjlvqjxo.exe <Not Verified; ; DDC>

    2007-11-07 12:43:53 71232 --a------ C:\WINDOWS\system32\trfhhjxq.exe <Not Verified; ; DDC>

    2007-11-07 12:41:09 71232 --a------ C:\WINDOWS\system32\advbkprt.exe <Not Verified; ; DDC>

    2007-11-06 09:54:07 87104 --a------ C:\WINDOWS\system32\qghkhqdw.dll

    2007-11-06 09:53:02 71232 --a------ C:\WINDOWS\system32\bhvgoenh.exe <Not Verified; ; DDC>

    2007-11-05 10:41:57 0 d-------- C:\Documents and Settings\Michelle\Application Data\Template

    2007-11-04 19:45:43 75328 --a------ C:\WINDOWS\system32\pmihorwn.exe <Not Verified; ; DDC>

    2007-11-02 10:38:33 75328 --a------ C:\WINDOWS\system32\jwxsltfc.exe <Not Verified; ; DDC>

    -- Find3M Report ---------------------------------------------------------------

    2007-12-02 01:46:30 0 d-------- C:\Program Files\Bonjour

    2007-12-02 01:46:29 0 d-------- C:\Program Files\BAE

    2007-12-01 12:19:53 0 d-------- C:\Program Files\WinPop

    2007-12-01 12:19:53 0 d-------- C:\Program Files\Common Files

    2007-12-01 11:25:42 0 d-------- C:\Program Files\SpywareBlaster

    2007-11-30 11:55:29 18698 --a------ C:\Documents and Settings\Michelle\Application Data\wklnhst.dat

    2007-11-28 22:26:33 3766 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys

    2007-11-28 22:26:28 56 -r-hs---- C:\WINDOWS\system32\A816F5A9F5.sys

    2007-11-27 12:18:07 0 d--h----- C:\Documents and Settings\Michelle\Application Data\Move Networks

    2007-10-31 21:49:54 75328 --a------ C:\WINDOWS\system32\iguxkhlm.exe <Not Verified; ; DDC>

    2007-10-30 21:48:48 75328 --a------ C:\WINDOWS\system32\eaqbkbgc.exe <Not Verified; ; DDC>

    2007-10-29 11:35:50 75328 --a------ C:\WINDOWS\system32\txgcxlmg.exe <Not Verified; ; DDC>

    2007-10-28 10:17:52 75328 --a------ C:\WINDOWS\system32\eotuexja.exe <Not Verified; ; DDC>

    2007-10-26 14:42:40 75328 --a------ C:\WINDOWS\system32\vjgauirb.exe <Not Verified; ; DDC>

    2007-10-25 12:34:14 75328 --a------ C:\WINDOWS\system32\amxdvmxh.exe <Not Verified; ; DDC>

    2007-10-25 12:31:42 75328 --a------ C:\WINDOWS\system32\xphkphnu.exe <Not Verified; ; DDC>

    2007-10-24 11:29:20 75328 --a------ C:\WINDOWS\system32\mcgocunv.exe <Not Verified; ; DDC>

    2007-10-22 07:51:28 75328 --a------ C:\WINDOWS\system32\jiysmrhd.exe <Not Verified; ; DDC>

    2007-10-20 18:55:36 0 d-------- C:\Program Files\Lavasoft

    2007-10-20 18:55:34 0 d-------- C:\Documents and Settings\Michelle\Application Data\Lavasoft

    2007-10-20 18:54:06 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard

    2007-10-20 18:36:07 75328 --a------ C:\WINDOWS\system32\qoehhmhm.exe <Not Verified; ; DDC>

    2007-10-20 18:32:29 0 d-------- C:\Program Files\Google

    2007-10-19 20:22:02 75328 --a------ C:\WINDOWS\system32\gsokujbd.exe <Not Verified; ; DDC>

    2007-10-18 08:26:37 77376 --a------ C:\WINDOWS\system32\xkbnyrot.dll

    2007-10-18 08:26:00 75328 --a------ C:\WINDOWS\system32\utyhvldo.exe <Not Verified; ; DDC>

    2007-10-11 07:56:54 75328 --a------ C:\WINDOWS\system32\bjabuaql.exe <Not Verified; ; DDC>

    2007-10-11 06:57:01 75328 --a------ C:\WINDOWS\system32\nsrnpnih.exe <Not Verified; ; DDC>

    2007-09-14 10:17:42 70208 --a------ C:\WINDOWS\system32\oxapsvmr.dll

    2007-09-14 10:08:41 75328 --a------ C:\WINDOWS\system32\kttapgov.exe <Not Verified; ; DDC>

    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4991EFD5-91EC-450A-8E0C-F868007FDC9B}]

    C:\Program Files\Common Files\meqo43855.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69D1138B-EA15-4764-B837-511A31894C80}]

    C:\WINDOWS\system32\mljgf.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{71DC6AF1-96F7-484C-867E-A10AD075D213}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9d568727-5666-4649-bb12-601d441e302e}]

    12/02/2007 12:44 AM 76864 --a------ C:\WINDOWS\system32\otiyorse.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [09/29/2005 01:01 PM]

    "SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [11/19/2003 04:48 PM]

    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [12/28/2005 10:55 AM]

    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [12/28/2005 10:56 AM]

    "ShowLOMControl"="1 (0x1)" []

    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [03/08/2006 11:48 AM]

    "DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [12/09/2005 07:29 PM]

    "RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [04/12/2006 04:27 PM]

    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/12/2006 04:28 PM]

    "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 12:05 AM]

    "ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [06/10/2005 09:44 AM]

    "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 09:44 AM]

    "MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [09/08/2005 06:20 PM]

    "pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [08/30/2005 03:30 PM]

    "Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [11/16/2005 06:08 PM]

    "SigmatelSysTrayApp"="stsystra.exe" [03/24/2006 04:30 PM C:\WINDOWS\stsystra.exe]

    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [03/23/2006 07:17 PM]

    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [03/23/2006 07:13 PM]

    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [03/23/2006 07:17 PM]

    "czwqaqrA"="C:\WINDOWS\czwqaqrA.exe" []

    "{70-0B-BD-D4-ZN}"="C:\windows\system32\podsregn.exe" []

    "KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []

    "4ca70b7b"="C:\WINDOWS\system32\fwtaeyyn.dll" [12/02/2007 12:47 AM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [04/11/2006 07:39 PM]

    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 10:24 AM]

    "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 10:09 AM]

    "WinPop"="C:\Program Files\WinPop\winpop.exe" []

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]

    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [4/12/2006 4:24:40 PM]

    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 12:01:04 AM]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

    "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrrspn]

    rqrrspn.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    @="Service"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]

    AutoRun\command- E:\setup.exe

    -- End of Deckard's System Scanner: finished at 2007-12-02 02:42:38 ------------

  16. VundoFix V6.7.0

    Checking Java version...

    Java version is 1.4.2.3

    Old versions of java are exploitable and should be removed.

    Scan started at 1:52:46 AM 12/2/2007

    Listing files found while scanning....

    C:\windows\system32\fgjlm.bak1

    C:\WINDOWS\system32\fgjlm.bak2

    C:\WINDOWS\system32\fgjlm.ini

    C:\windows\system32\fiyngnrv.ini

    C:\WINDOWS\system32\lujktfbu.exe

    C:\WINDOWS\system32\mljgf.dll

    C:\WINDOWS\system32\rqrrspn.dll

    C:\windows\system32\vrngnyif.dll

    Beginning removal...

    Attempting to delete C:\windows\system32\fgjlm.bak1

    C:\windows\system32\fgjlm.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\fgjlm.bak2

    C:\WINDOWS\system32\fgjlm.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\fgjlm.ini

    C:\WINDOWS\system32\fgjlm.ini Has been deleted!

    Attempting to delete C:\windows\system32\fiyngnrv.ini

    C:\windows\system32\fiyngnrv.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\lujktfbu.exe

    C:\WINDOWS\system32\lujktfbu.exe Has been deleted!

    Attempting to delete C:\WINDOWS\system32\mljgf.dll

    C:\WINDOWS\system32\mljgf.dll Has been deleted!

    Attempting to delete C:\windows\system32\vrngnyif.dll

    C:\windows\system32\vrngnyif.dll Has been deleted!

    Performing Repairs to the registry.

    Done!

  17. I have run adaware and spybot s&d numerous times cleaning everything they find. When cleaning in Spybot S&D I keep getting the blue screen of death. I am also unable to run most online scans. The laptop I am working with is running Windows XP media edition with all the updates. Any help would be great, thanks for your time in advance.

    Logfile of HijackThis v1.99.1

    Scan saved at 12:46:26 AM, on 12/2/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\savedump.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe

    C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

    C:\WINDOWS\stsystra.exe

    C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\eHome\ehmsas.exe

    c:\program files\common files\installshield\updateservice\isuspm.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe

    C:\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.wisc.edu/portal/index.jsp

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R3 - URLSearchHook: (no name) - - (no file)

    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

    O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

    O4 - HKLM\..\Run: [showLOMControl]

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: [iSUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe

    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"

    O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [czwqaqrA] C:\WINDOWS\czwqaqrA.exe

    O4 - HKLM\..\Run: [{70-0B-BD-D4-ZN}] C:\windows\system32\podsregn.exe SKY003

    O4 - HKLM\..\Run: [4ca70b7b] rundll32.exe "C:\WINDOWS\system32\pnneraju.dll",b

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup

    O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

    O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)

    O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\ixanhtum.exe (file missing)

    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe

    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

  18. Sorry this took so long to post. Just to let you know I uninstalled AOL since the AOLServiceHost.exe was using 80% of the prossesor when aol was closed. Computer is much faster now.

    Ad-Aware SE Personal

    Adobe Flash Player 9 ActiveX

    Adobe Reader 7.0

    AOL Uninstaller

    AOL You've Got Pictures Screensaver

    AVG Anti-Spyware 7.5

    BigFix

    Canon PC1200/iC D600/iR1200G

    CC_ccProxyExt

    ccCommon

    ccPxyCore

    Conexant AC-Link Audio

    Google Toolbar for Internet Explorer

    HijackThis 1.99.1

    HP Deskjet 3900 series

    HP Extended Capabilities 5.0

    HP Image Zone Express

    HP Imaging Device Functions 5.0

    HP Software Update

    HP Solution Center & Imaging Support Tools 5.0

    Intel® Graphics Media Accelerator Driver for Mobile

    iPod for Windows 2005-02-07

    iTunes

    J2SE Runtime Environment 5.0 Update 2

    J2SE Runtime Environment 5.0 Update 6

    Kaspersky Online Scanner

    LiveReg (Symantec Corporation)

    LiveUpdate 2.5 (Symantec Corporation)

    Microsoft .NET Framework 1.1

    Microsoft .NET Framework 1.1

    Microsoft .NET Framework 1.1 Hotfix (KB886903)

    Microsoft Digital Image Starter Edition 2006

    Microsoft Money 2005

    Microsoft Office Standard Edition 2003

    Microsoft Streets and Trips 2005 with USB GPS

    Microsoft Works

    MSRedist

    MSXML 4.0 SP2 (KB927978)

    Napster

    Napster Burn Engine

    Nero BurnRights

    Nero OEM

    Norton AntiSpam

    Norton AntiSpam

    Norton AntiVirus 2005

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security

    Norton Internet Security 2005 (Symantec Corporation)

    Norton Security Center

    Norton WMI Update

    Norton WMI Update

    Panda ActiveScan

    PowerDVD

    QuickTime

    RealPlayer Basic

    Remote_J2K

    Security Update for Windows Media Player (KB911564)

    Security Update for Windows Media Player 10 (KB911565)

    Security Update for Windows Media Player 10 (KB917734)

    Security Update for Windows Media Player 6.4 (KB925398)

    Security Update for Windows XP (KB893756)

    Security Update for Windows XP (KB896358)

    Security Update for Windows XP (KB896423)

    Security Update for Windows XP (KB896424)

    Security Update for Windows XP (KB899587)

    Security Update for Windows XP (KB899591)

    Security Update for Windows XP (KB900725)

    Security Update for Windows XP (KB901017)

    Security Update for Windows XP (KB902400)

    Security Update for Windows XP (KB904706)

    Security Update for Windows XP (KB905414)

    Security Update for Windows XP (KB905749)

    Security Update for Windows XP (KB905915)

    Security Update for Windows XP (KB908519)

    Security Update for Windows XP (KB908531)

    Security Update for Windows XP (KB911562)

    Security Update for Windows XP (KB911567)

    Security Update for Windows XP (KB911927)

    Security Update for Windows XP (KB912812)

    Security Update for Windows XP (KB912919)

    Security Update for Windows XP (KB913446)

    Security Update for Windows XP (KB913580)

    Security Update for Windows XP (KB914388)

    Security Update for Windows XP (KB914389)

    Security Update for Windows XP (KB916281)

    Security Update for Windows XP (KB917159)

    Security Update for Windows XP (KB917344)

    Security Update for Windows XP (KB917422)

    Security Update for Windows XP (KB917953)

    Security Update for Windows XP (KB918439)

    Security Update for Windows XP (KB918899)

    Security Update for Windows XP (KB919007)

    Security Update for Windows XP (KB920213)

    Security Update for Windows XP (KB920214)

    Security Update for Windows XP (KB920670)

    Security Update for Windows XP (KB920683)

    Security Update for Windows XP (KB920685)

    Security Update for Windows XP (KB921398)

    Security Update for Windows XP (KB921883)

    Security Update for Windows XP (KB922616)

    Security Update for Windows XP (KB922760)

    Security Update for Windows XP (KB922819)

    Security Update for Windows XP (KB923191)

    Security Update for Windows XP (KB923414)

    Security Update for Windows XP (KB923689)

    Security Update for Windows XP (KB923694)

    Security Update for Windows XP (KB923980)

    Security Update for Windows XP (KB924191)

    Security Update for Windows XP (KB924270)

    Security Update for Windows XP (KB924496)

    Security Update for Windows XP (KB925454)

    Security Update for Windows XP (KB925486)

    Security Update for Windows XP (KB926255)

    Soft Data Fax Modem with SmartCP

    SPBBC

    Spybot - Search & Destroy 1.4

    SpywareBlaster v3.5.1

    Symantec pcAnywhere

    Symantec Script Blocking Installer

    SymNet

    Synaptics Pointing Device Driver

    Texas Instruments PCIxx21/x515 drivers.

    TurboTax Deluxe 2005

    TurboTax ItsDeductible 2005

    Update for Windows XP (KB894391)

    Update for Windows XP (KB898461)

    Update for Windows XP (KB900485)

    Update for Windows XP (KB910437)

    Update for Windows XP (KB911280)

    Update for Windows XP (KB916595)

    Update for Windows XP (KB920872)

    Update for Windows XP (KB922582)

    Viewpoint Media Player

    WexTech AnswerWorks

    Windows Backup Utility

    Windows Media Format Runtime

    Windows Media Player 10

    Windows XP Hotfix - KB886185

    Windows XP Hotfix - KB887472

    Windows XP Hotfix - KB887742

    Yahoo! Mail Quick Select Tool (PhotoMail)

  19. Here is a new Hijackthis log I ran after a few more scans.

    Logfile of HijackThis v1.99.1

    Scan saved at 12:16:01 PM, on 11/28/2006

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Norton Internet Security\ISSVC.exe

    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\CAPM1RSK.EXE

    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe

    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\igfxtray.exe

    C:\Program Files\Common Files\AOL\1132887282\ee\AOLHostManager.exe

    C:\Program Files\Common Files\AOL\1132887282\ee\AOLServiceHost.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1LAK.EXE

    C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE

    C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe

    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll

    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1132887282\ee\AOLHostManager.exe

    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run

    O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe

    O4 - Global Startup: Canon PC1200 iC D600 iR1200G Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1LAK.EXE

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing

    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

    O16 - DPF: {8569D715-FF88-44BA-8D1D-AD3E59543DDE} (ActiveReports Viewer2) - https://reports.paychoiceonline.com/pcoreports/arview2.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

    O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll

    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe

    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe

    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe