1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive [InActive] Redirected web searches and programs won't load

Discussion in 'Malware and Virus Removal Archive' started by dawgyjay, 2009/03/27.

  1. 2009/03/27
    dawgyjay

    dawgyjay Inactive Thread Starter

    Joined:
    2009/03/27
    Messages:
    4
    Likes Received:
    0
    Chalk me amongst the people who've run into the issue where when doing a web search it redirects you to less than desirable sites. When the problem started, it turned off my anti-virus protection. I uninstalled and reinstalled it and it's not working properly. I've tried to download and run some malware programs. They install fine but won't open. When I tried a system restore, it wouldn't compelte. When rebooting, the system often freezes and doesn't complete the boot. I also tried a Kaspersky online scan and it wouldn't install. Any help would be appreciated. Thanks. Here are my logs:

    DDS (Ver_09-03-16.01) - NTFSx86
    Run by Compaq_Owner at 19:54:23.43 on Fri 03/27/2009
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.29 [GMT -4:00]

    FW: Norton AntiVirus *enabled*

    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
    C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\HP\Digital Imaging\bin\hpobnz08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpoevm08.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\HP\Digital Imaging\Bin\hpoSTS08.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    c:\windows\system\hpsysdrv.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
    C:\Documents and Settings\Compaq_Owner\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.yahoo.com/
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=yie7c
    uWindow Title = Windows Internet Explorer provided by Yahoo!
    uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
    uInternet Connection Wizard,ShellNext = hxxp://register.hp.com/servlet/WebReg.servlets.ProdReg1Servlet?appID=java_wreg_wreg_genpg&prodOS=011&gwCountry=US&language=en&PURCH_DT_MONTH=08&PURCH_DT_DAY=07&PURCH_DT_YEAR=2006&PROD_SERIAL_ID=CNH6252YF0&application=305&modelID=EX321AA&LF=red
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn5\yt.dll
    uURLSearchHooks: New York Yankees Toolbar: {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - c:\program files\new_york_yankees\tbNew1.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn5\yt.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: Verizon Broadband Toolbar: {4e7bd74f-2b8d-469e-d0fc-e57af4d5fa7d} - c:\windows\downlo~1\vzbb.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
    BHO: New York Yankees Toolbar: {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - c:\program files\new_york_yankees\tbNew1.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn5\YTSingleInstance.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn5\yt.dll
    TB: Verizon Broadband Toolbar: {4e7bd74f-2b8d-469e-d0fc-e57af4d5fa7d} - c:\windows\downlo~1\vzbb.dll
    TB: New York Yankees Toolbar: {c7e292f8-1f8d-40a6-8fa6-e6e83d51e7e1} - c:\program files\new_york_yankees\tbNew1.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
    TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
    uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
    uRun: [BitTorrent] "c:\program files\bittorrent\bittorrent.exe" --force_start_minimized
    uRun: [YSearchProtection] c:\program files\yahoo!\search protection\SearchProtection.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
    uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
    mRun: [PCDrProfiler]
    mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe "
    mRun: [VerizonServicepoint.exe] c:\program files\verizon\servicepoint\VerizonServicepoint.exe
    mRun: [TotalRecorderScheduler] "c:\program files\highcriteria\totalrecorder\TotRecSched.exe "
    mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe "
    mRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
    mRun: [MBBalloon] c:\program files\hotalbummybox\MBBalloon.exe
    mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll "
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc2~1.lnk - c:\program files\hp\digital imaging\bin\hpobnz08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hp\digital imaging\bin\hpotdd01.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mediac~1.lnk - c:\program files\hotalbummybox\MediaChecker.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
    IE: Open in new background tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/229?0a30b1b201f94ebaa822bbf638c84d90
    IE: Open in new foreground tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/230?0a30b1b201f94ebaa822bbf638c84d90
    IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
    IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
    DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
    DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - hxxp://mediaplayer.walmart.com/installer/install.cab
    DPF: {8646A6AF-0AE4-4BF8-B716-DB1513803972} - hxxp://riteaid.storefront.com/images/global/activex/SFImageUpload1_8.CAB
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} - hxxp://wegmansphoto.lifepics.com/net/Uploader/LPUploader45.cab
    DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} - hxxp://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
    DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://cvs.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
    TCP: NameServer = 85.255.112.99,85.255.112.228
    TCP: {54447FFE-C659-4C76-ADC6-EF8BA2A7E213} = 85.255.112.99
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ============= SERVICES / DRIVERS ===============

    R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [2008-8-1 15172]
    R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
    R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-8-7 1245064]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652]
    R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]

    =============== Created Last 30 ================

    2009-03-26 22:30 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
    2009-03-26 21:57 <DIR> --d----- c:\program files\CA Yahoo! Anti-Spy
    2009-03-26 21:09 <DIR> --d----- c:\program files\Norton Support
    2009-03-26 20:42 <DIR> --d----- c:\windows\system32\drivers\NAV
    2009-03-26 19:52 381 ---shr-- C:\autorun.inf
    2009-03-22 21:10 <DIR> --d----- c:\documents and settings\compaq_owner\Tracing
    2009-03-22 20:59 <DIR> --d----- c:\program files\Microsoft
    2009-03-22 20:59 <DIR> --d----- c:\program files\Windows Live SkyDrive
    2009-03-22 20:54 <DIR> --d----- c:\program files\common files\Windows Live
    2009-03-22 14:39 <DIR> --dsh--- c:\documents and settings\compaq_owner\IECompatCache
    2009-03-22 07:33 1,089,593 -------- c:\windows\system32\dllcache\ntprint.cat
    2009-03-21 13:21 <DIR> --d----- c:\windows\system32\XPSViewer
    2009-03-21 13:19 597,504 -------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
    2009-03-21 13:19 117,760 -------- c:\windows\system32\prntvpt.dll
    2009-03-21 13:19 89,088 -------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
    2009-03-21 13:19 575,488 -------- c:\windows\system32\xpsshhdr.dll
    2009-03-21 13:19 575,488 -------- c:\windows\system32\dllcache\xpsshhdr.dll
    2009-03-21 13:19 1,676,288 -------- c:\windows\system32\xpssvcs.dll
    2009-03-21 13:19 1,676,288 -------- c:\windows\system32\dllcache\xpssvcs.dll
    2009-03-21 13:19 <DIR> --d----- C:\872e4bc5fd6c12d349a77f6b9e00c1b3
    2009-03-21 10:48 <DIR> --dsh--- c:\documents and settings\compaq_owner\PrivacIE
    2009-03-21 10:42 <DIR> --dsh--- c:\documents and settings\compaq_owner\IETldCache
    2009-03-21 10:37 <DIR> --d----- c:\windows\ie8updates
    2009-03-21 10:29 <DIR> -cd-h--- c:\windows\ie8
    2009-03-21 10:26 105,984 -------- c:\windows\system32\dllcache\iecompat.dll
    2009-03-17 20:37 <DIR> --d----- c:\program files\iTunes
    2009-03-17 20:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
    2009-03-17 20:34 <DIR> --d----- c:\program files\Bonjour
    2009-03-08 14:22 49,152 -------- c:\windows\system32\msrating.dll.mui
    2009-03-08 14:22 2,560 -------- c:\windows\system32\mshta.exe.mui
    2009-03-08 14:21 4,096 -------- c:\windows\system32\ie4uinit.exe.mui
    2009-03-08 14:20 81,920 -------- c:\windows\system32\iedkcs32.dll.mui
    2009-03-08 04:33 18,944 -------- c:\windows\system32\dllcache\corpol.dll

    ==================== Find3M ====================

    2009-03-08 14:09 638,816 a------- c:\windows\system32\dllcache\iexplore.exe
    2009-03-08 14:09 391,536 a------- c:\windows\system32\dllcache\iedkcs32.dll
    2009-03-08 04:41 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll
    2009-03-08 04:39 11,063,808 a------- c:\windows\system32\dllcache\ieframe.dll
    2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll
    2009-03-08 04:34 914,944 a------- c:\windows\system32\dllcache\wininet.dll
    2009-03-08 04:34 1,206,784 a------- c:\windows\system32\dllcache\urlmon.dll
    2009-03-08 04:34 236,544 a------- c:\windows\system32\dllcache\webcheck.dll
    2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll
    2009-03-08 04:34 43,008 a------- c:\windows\system32\dllcache\licmgr10.dll
    2009-03-08 04:34 105,984 a------- c:\windows\system32\dllcache\url.dll
    2009-03-08 04:34 193,536 a------- c:\windows\system32\dllcache\msrating.dll
    2009-03-08 04:34 109,568 a------- c:\windows\system32\dllcache\occache.dll
    2009-03-08 04:33 759,296 a------- c:\windows\system32\dllcache\VGX.dll
    2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll
    2009-03-08 04:33 25,600 a------- c:\windows\system32\dllcache\jsproxy.dll
    2009-03-08 04:33 726,528 a------- c:\windows\system32\dllcache\jscript.dll
    2009-03-08 04:33 229,376 a------- c:\windows\system32\dllcache\ieaksie.dll
    2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll
    2009-03-08 04:33 420,352 a------- c:\windows\system32\dllcache\vbscript.dll
    2009-03-08 04:33 125,952 a------- c:\windows\system32\dllcache\ieakeng.dll
    2009-03-08 04:32 72,704 a------- c:\windows\system32\dllcache\admparse.dll
    2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll
    2009-03-08 04:32 173,056 a------- c:\windows\system32\dllcache\ie4uinit.exe
    2009-03-08 04:32 163,840 a------- c:\windows\system32\dllcache\ieakui.dll
    2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll
    2009-03-08 04:32 71,680 a------- c:\windows\system32\dllcache\iesetup.dll
    2009-03-08 04:32 55,808 a------- c:\windows\system32\dllcache\iernonce.dll
    2009-03-08 04:32 128,512 a------- c:\windows\system32\dllcache\advpack.dll
    2009-03-08 04:32 94,720 a------- c:\windows\system32\dllcache\inseng.dll
    2009-03-08 04:32 594,432 a------- c:\windows\system32\dllcache\msfeeds.dll
    2009-03-08 04:32 1,985,024 a------- c:\windows\system32\dllcache\iertutil.dll
    2009-03-08 04:32 611,840 a------- c:\windows\system32\dllcache\mstime.dll
    2009-03-08 04:24 68,608 a------- c:\windows\system32\dllcache\hmmapi.dll
    2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll
    2009-03-08 04:22 156,160 a------- c:\windows\system32\dllcache\msls31.dll
    2009-03-08 04:11 445,952 a------- c:\windows\system32\dllcache\ieapfltr.dll
    2009-02-09 07:13 1,846,784 a------- c:\windows\system32\win32k.sys
    2009-02-09 07:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
    2009-02-06 21:07 3,698,584 a------- c:\windows\system32\dllcache\ieapfltr.dat
    2009-02-06 18:52 49,504 a------- c:\windows\system32\sirenacm.dll
    2009-01-07 18:21 26,144 a------- c:\windows\system32\spupdsvc.exe
    2009-01-07 18:20 134,144 -------- c:\windows\system32\dllcache\sqmapi.dll
    2009-01-07 18:20 1,497,088 -------- c:\windows\system32\dllcache\shdocvw.dll
    2009-01-07 18:20 1,022,976 -------- c:\windows\system32\dllcache\browseui.dll
    2009-01-07 18:20 474,112 -------- c:\windows\system32\dllcache\shlwapi.dll
    2009-01-07 18:20 24,576 a------- c:\windows\system32\nlsdl.dll
    2009-01-07 18:20 26,112 a------- c:\windows\system32\idndl.dll
    2009-01-07 18:20 23,552 a------- c:\windows\system32\normaliz.dll
    2009-01-07 18:20 265,720 a------- c:\windows\system32\msdbg2.dll
    2008-10-30 20:09 64,552 a------- c:\docume~1\compaq~1\applic~1\GDIPFONTCACHEV1.DAT
    2006-09-06 21:36 162 a------- c:\docume~1\compaq~1\applic~1\wklnhst.dat
    2006-08-07 13:21 22 a--sh--- c:\windows\sminst\HPCD.sys
    2008-08-31 13:44 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008083120080901\index.dat

    ============= FINISH: 19:55:03.10 ===============



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-03-16.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 8/7/2006 11:53:38 AM
    System Uptime: 3/27/2009 7:44:31 PM (0 hours ago)

    Motherboard: ASUSTeK Computer INC. | | Altair
    Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz | Socket 775 | 3066/133mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 179 GiB total, 87.445 GiB free.
    D: is FIXED (FAT32) - 7 GiB total, 0.339 GiB free.
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP972: 12/27/2008 4:48:42 PM - System Checkpoint
    RP973: 12/28/2008 5:35:26 PM - System Checkpoint
    RP974: 12/29/2008 6:23:26 PM - System Checkpoint
    RP975: 12/30/2008 7:31:50 PM - System Checkpoint
    RP976: 12/31/2008 7:36:32 PM - System Checkpoint
    RP977: 1/1/2009 8:29:45 PM - System Checkpoint
    RP978: 1/2/2009 11:07:32 PM - System Checkpoint
    RP979: 1/4/2009 2:01:23 AM - System Checkpoint
    RP980: 1/5/2009 2:47:22 AM - System Checkpoint
    RP981: 1/6/2009 5:40:57 AM - System Checkpoint
    RP982: 1/7/2009 5:59:24 AM - System Checkpoint
    RP983: 1/8/2009 6:18:16 AM - System Checkpoint
    RP984: 1/9/2009 8:20:35 AM - System Checkpoint
    RP985: 1/10/2009 8:39:21 AM - System Checkpoint
    RP986: 1/11/2009 8:40:27 AM - System Checkpoint
    RP987: 1/12/2009 9:27:22 AM - System Checkpoint
    RP988: 1/13/2009 11:03:53 AM - System Checkpoint
    RP989: 1/14/2009 3:00:45 AM - Software Distribution Service 3.0
    RP990: 1/15/2009 4:02:18 AM - System Checkpoint
    RP991: 1/16/2009 6:20:14 AM - System Checkpoint
    RP992: 1/17/2009 7:19:42 AM - System Checkpoint
    RP993: 1/18/2009 8:26:37 AM - System Checkpoint
    RP994: 1/19/2009 9:34:59 AM - System Checkpoint
    RP995: 1/20/2009 9:50:37 AM - System Checkpoint
    RP996: 1/21/2009 11:26:37 AM - System Checkpoint
    RP997: 1/22/2009 4:14:53 PM - System Checkpoint
    RP998: 1/23/2009 4:39:41 PM - System Checkpoint
    RP999: 1/24/2009 5:02:35 PM - System Checkpoint
    RP1000: 1/25/2009 6:24:43 PM - System Checkpoint
    RP1001: 1/26/2009 7:03:39 PM - System Checkpoint
    RP1002: 1/27/2009 7:24:37 PM - System Checkpoint
    RP1003: 1/28/2009 8:02:18 PM - System Checkpoint
    RP1004: 1/29/2009 9:42:45 PM - System Checkpoint
    RP1005: 1/30/2009 10:18:42 PM - System Checkpoint
    RP1006: 2/1/2009 6:01:18 AM - System Checkpoint
    RP1007: 2/2/2009 6:05:05 AM - System Checkpoint
    RP1008: 2/3/2009 7:22:08 AM - System Checkpoint
    RP1009: 2/4/2009 7:27:53 AM - System Checkpoint
    RP1010: 2/5/2009 7:30:39 AM - System Checkpoint
    RP1011: 2/6/2009 8:29:07 AM - System Checkpoint
    RP1012: 2/7/2009 8:30:07 AM - System Checkpoint
    RP1013: 2/8/2009 8:48:12 AM - System Checkpoint
    RP1014: 2/9/2009 9:24:12 AM - System Checkpoint
    RP1015: 2/10/2009 10:12:12 AM - System Checkpoint
    RP1016: 2/11/2009 3:00:22 AM - Software Distribution Service 3.0
    RP1017: 2/12/2009 4:03:19 AM - System Checkpoint
    RP1018: 2/13/2009 7:33:47 PM - System Checkpoint
    RP1019: 2/14/2009 8:19:15 PM - System Checkpoint
    RP1020: 2/15/2009 8:43:54 PM - System Checkpoint
    RP1021: 2/16/2009 11:12:43 PM - System Checkpoint
    RP1022: 2/18/2009 12:15:20 AM - System Checkpoint
    RP1023: 2/19/2009 12:51:17 AM - System Checkpoint
    RP1024: 2/20/2009 1:27:18 AM - System Checkpoint
    RP1025: 2/21/2009 2:22:18 AM - System Checkpoint
    RP1026: 2/22/2009 2:51:14 AM - System Checkpoint
    RP1027: 2/23/2009 3:52:14 AM - System Checkpoint
    RP1028: 2/24/2009 4:15:14 AM - System Checkpoint
    RP1029: 2/25/2009 3:01:05 AM - Software Distribution Service 3.0
    RP1030: 2/26/2009 3:29:09 AM - System Checkpoint
    RP1031: 2/27/2009 3:53:09 AM - System Checkpoint
    RP1032: 2/28/2009 6:37:51 AM - System Checkpoint
    RP1033: 2/28/2009 9:56:17 AM - Removed Verizon Media Manager
    RP1034: 2/28/2009 9:56:34 AM - Installed Verizon Media Manager.
    RP1035: 3/1/2009 10:01:41 AM - System Checkpoint
    RP1036: 3/2/2009 10:15:21 AM - System Checkpoint
    RP1037: 3/3/2009 10:51:19 AM - System Checkpoint
    RP1038: 3/4/2009 11:27:21 AM - System Checkpoint
    RP1039: 3/5/2009 3:00:21 AM - Software Distribution Service 3.0
    RP1040: 3/6/2009 6:53:49 AM - System Checkpoint
    RP1041: 3/7/2009 7:37:34 AM - System Checkpoint
    RP1042: 3/8/2009 7:43:33 AM - System Checkpoint
    RP1043: 3/9/2009 8:43:36 AM - System Checkpoint
    RP1044: 3/10/2009 9:30:00 AM - System Checkpoint
    RP1045: 3/11/2009 2:00:21 AM - Software Distribution Service 3.0
    RP1046: 3/12/2009 6:22:52 AM - System Checkpoint
    RP1047: 3/13/2009 7:36:31 AM - System Checkpoint
    RP1048: 3/14/2009 8:22:16 AM - System Checkpoint
    RP1049: 3/15/2009 10:04:47 AM - System Checkpoint
    RP1050: 3/16/2009 3:00:24 AM - Software Distribution Service 3.0
    RP1051: 3/17/2009 3:27:42 AM - System Checkpoint
    RP1052: 3/18/2009 8:09:31 AM - System Checkpoint
    RP1053: 3/19/2009 9:08:09 AM - System Checkpoint
    RP1054: 3/20/2009 10:20:10 AM - System Checkpoint
    RP1055: 3/21/2009 10:32:26 AM - Installed Windows Internet Explorer 8.
    RP1056: 3/21/2009 10:35:40 AM - Software Distribution Service 3.0
    RP1057: 3/21/2009 12:13:00 PM - Software Distribution Service 3.0
    RP1058: 3/21/2009 1:07:34 PM - Software Distribution Service 3.0
    RP1059: 3/22/2009 7:37:35 AM - Software Distribution Service 3.0
    RP1060: 3/22/2009 1:48:04 PM - Removed QuickTime
    RP1061: 3/22/2009 2:52:19 PM - Installed QuickTime
    RP1062: 3/23/2009 3:32:49 PM - System Checkpoint
    RP1063: 3/24/2009 4:11:11 PM - System Checkpoint
    RP1064: 3/25/2009 5:11:10 PM - System Checkpoint
    RP1065: 3/26/2009 7:24:41 PM - System Checkpoint

    ==== Installed Programs ======================

    Adobe Bridge 1.0
    Adobe Common File Installer
    Adobe Flash Player 10 ActiveX
    Adobe Help Center 1.0
    Adobe Photoshop CS2
    Adobe Reader 7.1.0
    Adobe Stock Photos 1.0
    AIM 6
    AOL Instant Messenger
    Apple Mobile Device Support
    Apple Software Update
    ATI Control Panel
    ATI Display Driver
    Baseball Almanac
    Bonjour
    BufferChm
    CA Yahoo! Anti-Spy (remove only)
    Choice Guard
    Compatibility Pack for the 2007 Office system
    CP_AtenaShokunin1Config
    CP_CalendarTemplates1
    cp_LightScribeConfig
    cp_OnlineProjectsConfig
    CP_Package_Basic1
    CP_Package_Variety1
    CP_Package_Variety2
    CP_Package_Variety3
    CP_Panorama1Config
    cp_PosterPrintConfig
    cp_UpdateProjectsConfig
    Critical Update for Windows Media Player 11 (KB959772)
    CueTour
    Customer Experience Enhancement
    Data Fax SoftModem with SmartCP
    Destinations
    DeviceManagementQFolder
    Diamond Mind Baseball version 9
    DMB Encyclopedia 9a patch
    DMB Encyclopedia 9b patch
    DMB Encyclopedia version 9
    DMB version 9a patch
    DMB version 9b patch
    DMB version 9c patch
    eMusic Download Manager 3.0
    ESPN Java Check
    Form Fill (Windows Live Toolbar)
    FullDPAppQFolder
    High Definition Audio Driver Package - KB888111
    HOT ALBUM MYBOX
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Format SDK (KB902344)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    HP Boot Optimizer
    HP DVD Play 2.1
    HP Imaging Device Functions 7.0
    HP Photo and Imaging 2.0 - All-in-One
    HP Photo and Imaging 2.0 - All-in-One Drivers
    HP Photo and Imaging 2.0 - hp psc 2100 series
    HP Photosmart Premier Software 6.5
    hp psc 2100 series
    HP Rhapsody
    HP Support Overview
    HP Update
    HP Web Helper
    HPPhotoSmartExpress
    HpSdpAppCoreApp
    iMusic Tools
    InstantShareDevices
    iPod for Windows 2006-01-10
    iTunes
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    LightScribe 1.4.84.1
    LiveUpdate (Symantec Corporation)
    LiveUpdate Notice (Symantec Corporation)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Professional
    Microsoft Search Enhancement Pack
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    MLB.com Shuffle (remove only)
    MobileMe Control Panel
    Move Networks Media Player for Internet Explorer
    MSVCRT
    MSXML 4.0 SP2 (KB925672)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    Multiple Season Box Scores
    Netscape Browser (remove only)
    New_York_Yankees Toolbar
    Norton Spyware Scan
    Norton Spyware Scan provided by Yahoo!
    OneCare Advisor (Windows Live Toolbar)
    OptionalContentQFolder
    PC-Doctor 5 for Windows
    Photo Viewer 2.3
    PhotoGallery
    QuickTime
    RandMap
    Readiris 7.5
    RealPlayer
    Realtek High Definition Audio Driver
    Rhapsody
    Rhapsody Player Engine
    Security Update for CAPICOM (KB931906)
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Segoe UI
    SkinsHP1
    SlideShow
    SlideShowMusic
    Smart Menus (Windows Live Toolbar)
    Sonic Express Labeler
    Sonic MyDVD Plus
    Sonic RecordNow Audio
    Sonic RecordNow Copy
    Sonic RecordNow Data
    Sonic Update Manager
    Sonic_PrimoSDK
    Sony Picture Utility
    Sony USB Driver
    Symantec KB-DocID:2003093015493306
    Tabbed Browsing (Windows Live Toolbar)
    Total Recorder 6.0
    Trilogy 3.1 for DMB
    Unload
    Update for Windows Internet Explorer 8 (KB968220)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Verizon Broadband Toolbar
    Verizon Media Manager
    Verizon Servicepoint 1.3.21
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    Wal-Mart Music Downloads Store
    WebFldrs XP
    WildTangent Web Driver
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Outlook Toolbar (Windows Live Toolbar)
    Windows Live Sign-in Assistant
    Windows Live Toolbar
    Windows Live Toolbar Extension (Windows Live Toolbar)
    Windows Live Toolbar Feed Detector (Windows Live Toolbar)
    Windows Live Upload Tool
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    Yahoo! Search Protection
    Yahoo! Software Update
    Yahoo! Toolbar

    ==== Event Viewer Messages From Past Week ========

    3/21/2009 10:43:22 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ftsata2
    3/22/2009 7:20:26 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ftsata2 IDSxpx86
    3/22/2009 7:20:28 AM, error: RemoteAccess [20151] - The Control Protocol IPCP in the Point to Point Protocol module (unknown) returned an error while initializing. A device attached to the system is not functioning.
    3/25/2009 10:06:55 PM, error: Dhcp [1002] - The IP address lease 169.254.12.76 for the Network Card with network address 001731C10066 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
    3/26/2009 8:25:14 PM, error: Print [19] - Sharing printer failed + 1722, Printer Microsoft XPS Document Writer share name Printer.
    3/26/2009 8:29:14 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000369' while processing the file 'desktop.ini' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
    3/26/2009 9:25:25 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000369' while processing the file 'Autorun.inf' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
    3/27/2009 6:50:47 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Kaspersky Internet Security service to connect.
    3/27/2009 6:50:47 AM, error: Service Control Manager [7000] - The Kaspersky Internet Security service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

    ==== End Of File ===========================
     
  2. 2009/04/04
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi dawgyjay
    Welcome to WindowsBBS.
    Sorry for the wait.

    Do you have access to another computer where you can download and transfer a tool to the infected one to run it?

    Thanks
    Geri
     
    Geri,
    #2

  3. to hide this advert.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.