I ran this in safe mode
.
DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL
Internet Explorer: 6.0.2900.5512
Run by OEM at 17:31:35 on 2011-12-28
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1782 [GMT 13:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
============== Running Processes ===============
.
C:\WINDOWS\3872222862:1905340953.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uURLSearchHooks: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - c:\program files\adawaretb\adawareDx.dll
uWinlogon: Shell=c:\documents and settings\oem\local settings\application data\8e6ecde6\X
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Groove Folder Synchronization: {4da6114d-3366-1228-057d-509775e46fd4} - c:\windows\system32\Audiio3D.dll
BHO: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - c:\program files\adawaretb\adawareDx.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - c:\program files\adawaretb\adawareDx.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [SiSUSBRG] c:\windows\SiSUSBrg.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Ad-Aware Browsing Protection] "c:\documents and settings\all users\application data\ad-aware browsing protection\adawarebp.exe"
mRun: [SpyHunter Security Suite] c:\program files\enigma software group\spyhunter\SpyHunter4.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ADSL_A2] A2Installed
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\oem\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adsldi~1.lnk - c:\windows\system32\mapiicon.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1267652763921
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-12-12 64512]
S2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [2009-1-28 59776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-9-19 20328]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-3 135664]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-12-2 2152152]
S2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\enigma~1\spyhun~1\SH4SER~1.EXE [2011-10-10 736672]
S2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;c:\windows\system32\drivers\wf2ktunr.sys [2009-1-28 19456]
S2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;c:\windows\system32\drivers\wf2kXbar.sys [2009-1-28 9600]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2011-3-31 23456]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-3 135664]
S3 HVWINDR.SYS;HVWINDR.SYS;c:\documents and settings\oem\desktop\hvc alpha 2\hvwindr.sys [2009-8-1 205220]
S3 itexadsla2;ITeX ADSL PCI NIC Service;c:\windows\system32\drivers\TBCIwana.sys [2001-10-5 432640]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-12-2 15232]
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [2009-9-17 24416]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-12-28 02:33:26 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-28 02:00:42 48016 --sha-w- c:\windows\system32\c_23141.nl_
2011-12-28 01:52:59 82035 -c--a-w- c:\windows\system32\dllcache\fp4anscp.dll
2011-12-28 01:52:59 49210 -c--a-w- c:\windows\system32\dllcache\fp4areg.dll
2011-12-28 01:52:59 147513 -c--a-w- c:\windows\system32\dllcache\fp4apws.dll
2011-12-28 01:52:58 184435 -c--a-w- c:\windows\system32\dllcache\fp4amsft.dll
2011-12-28 01:52:57 46592 -c--a-w- c:\windows\system32\dllcache\coadmin.dll
2011-12-28 01:52:56 188480 -c--a-w- c:\windows\system32\dllcache\cfgwiz.exe
2011-12-28 01:52:55 20540 -c--a-w- c:\windows\system32\dllcache\author.dll
2011-12-28 01:52:55 16439 -c--a-w- c:\windows\system32\dllcache\author.exe
2011-12-28 01:52:54 43520 -c--a-w- c:\windows\system32\dllcache\admwprox.dll
2011-12-28 01:52:54 290816 -c--a-w- c:\windows\system32\dllcache\adsiis51.dll
2011-12-28 01:52:53 16439 -c--a-w- c:\windows\system32\dllcache\admin.exe
2011-12-28 01:52:51 20540 -c--a-w- c:\windows\system32\dllcache\admin.dll
2011-12-28 01:50:13 16384 ----a-w- c:\program files\internet explorer\connection wizard\isignup.exe
2011-12-28 01:35:56 13312 ----a-w- c:\windows\system32\irclass.dll
2011-12-28 01:35:55 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-12-28 01:35:31 16535 ----a-r- c:\windows\SETC3.tmp
2011-12-28 01:35:24 1088840 ----a-r- c:\windows\SETB7.tmp
2011-12-28 01:35:21 1296669 ----a-r- c:\windows\SETB4.tmp
2011-12-27 14:49:46 -------- d-----w- C:\_OTL
2011-12-18 01:23:48 110080 ----a-r- c:\documents and settings\oem\application data\microsoft\installer\{1c7cc8e2-cfcf-41e6-a863-7c7a45ce8a78}\IconD7F16134.exe
2011-12-18 01:23:48 110080 ----a-r- c:\documents and settings\oem\application data\microsoft\installer\{1c7cc8e2-cfcf-41e6-a863-7c7a45ce8a78}\IconCF33A0CE.exe
2011-12-18 01:23:47 110080 ----a-r- c:\documents and settings\oem\application data\microsoft\installer\{1c7cc8e2-cfcf-41e6-a863-7c7a45ce8a78}\IconF7A21AF7.exe
2011-12-18 01:23:31 -------- d-----w- C:\sh4ldr
2011-12-18 01:23:31 -------- d-----w- c:\program files\Enigma Software Group
2011-12-18 01:21:18 -------- d-----w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
2011-12-18 01:21:05 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2011-12-17 19:31:16 -------- d-----w- c:\documents and settings\oem\application data\MediaWmplay
2011-12-11 22:08:53 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-11 22:08:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-11 21:22:18 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-12-11 20:55:13 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-12-11 17:55:09 -------- d-----w- c:\documents and settings\oem\local settings\application data\adaware
2011-12-11 17:55:06 -------- d-----w- c:\documents and settings\all users\application data\Ad-Aware Browsing Protection
2011-12-11 17:55:04 -------- d-----w- c:\program files\Toolbar Cleaner
2011-12-11 17:55:01 -------- d-----w- c:\documents and settings\oem\application data\adawaretb
2011-12-11 17:54:59 -------- d-----w- c:\program files\adawaretb
2011-12-11 17:54:52 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-12-11 17:54:42 -------- d-----w- c:\program files\Lavasoft
.
==================== Find3M ====================
.
2011-11-11 19:57:32 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
============= FINISH: 17:34:36.53 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/28/2011 2:55:22 PM
System Uptime: 12/28/2011 5:16:11 PM (0 hours ago)
.
Motherboard: | | SiS-661
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Socket 478 | 3006/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 37 GiB total, 1.147 GiB free.
D: is FIXED (NTFS) - 37 GiB total, 0.564 GiB free.
E: is FIXED (NTFS) - 37 GiB total, 0.408 GiB free.
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: SiS 900-Based PCI Fast Ethernet Adapter
Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_0C56105B&REV_91\3&61AAA01&0&20
Manufacturer: SiS
Name: SiS 900-Based PCI Fast Ethernet Adapter
PNP Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_0C56105B&REV_91\3&61AAA01&0&20
Service: SISNIC
.
==== System Restore Points ===================
.
RP1: 12/28/2011 3:03:29 PM - System Checkpoint
.
==== Installed Programs ======================
.
7-Zip 9.16 beta
Ad-Aware
Ad-Aware Security Toolbar
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 11 ActiveX
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.2
Adobe Stock Photos 1.0
ATI - Software Uninstall Utility
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Display Driver
ATI HYDRAVISION
ATI Parental Control & Encoder
ATI Problem Report Wizard
Brother HL-2040
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center Localization All
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CPUID CPU-Z 1.55
DriverAgent by eSupport.com
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
IsoBuster 2.5
ITeX ADSL Software
MailWasher Pro
Malwarebytes' Anti-Malware version 1.51.2.1300
METAbolt
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft XML Parser
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MWSnap 3
Nero 6 Enterprise Edition
neroxml
Phoenix Viewer 1.5.2.1102
Realtek AC'97 Audio
SecondLife (remove only)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Side By Side Fix
Skins
Skype™ 4.0
SpyHunter
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
VCRedistSetup
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
WinFast Multimedia Driver Installation
WinRAR archiver
WinZip
Yahoo! Messenger
.
==== Event Viewer Messages From Past Week ========
.
12/28/2011 5:19:36 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Lavasoft Ad-Aware Service service to connect.
12/28/2011 5:19:36 PM, error: Service Control Manager [7000] - The Lavasoft Ad-Aware Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/28/2011 5:19:01 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
12/28/2011 5:18:40 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/28/2011 2:59:27 PM, error: Setup [60055] - Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information.
12/28/2011 2:51:46 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service SENS with arguments "" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
12/26/2011 9:16:22 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
12/26/2011 9:16:22 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
12/26/2011 9:16:22 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/26/2011 9:16:22 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/26/2011 9:16:22 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
12/26/2011 8:46:28 AM, error: Service Control Manager [7024] - The Background Intelligent Transfer Service service terminated with service-specific error 2147952450 (0x80072742).
12/26/2011 8:44:59 AM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: A socket operation encountered a dead network.
12/26/2011 8:44:59 AM, error: Service Control Manager [7023] - The IPSEC Services service terminated with the following error: A socket operation encountered a dead network.
12/26/2011 8:44:59 AM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: %%2147952450
12/26/2011 8:44:59 AM, error: Service Control Manager [7000] - The WinFast TV2000 XP WDM Video Capture service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
12/26/2011 8:44:59 AM, error: Service Control Manager [7000] - The WinFast TV2000 XP WDM TVTuner service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
12/26/2011 8:44:59 AM, error: Service Control Manager [7000] - The WinFast TV2000 XP WDM Crossbar service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.
==== End Of File ===========================