Seem to have contracted a virus. Can't do anything related to the interenet including email.
Ran combofix before I found this website and it mentioned something about rootkit sero access, but didnt seem to correct the problems. Thanks for any help you cn provide.
Here are the logs.
Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org
Database version: v2012.12.03.01
Windows XP Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.18702
dolsen :: TEST1 [administrator]
12/9/2012 1:13:25 PM
mbam-log-2012-12-09 (13-13-25).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 322336
Time elapsed: 7 minute(s), 7 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 5/4/2007 4:12:11 PM
System Uptime: 12/9/2012 12:29:52 PM (1 hours ago)
.
Motherboard: Dell Inc. | | 0FT292
Processor: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz | Microprocessor | 981/166mhz
Processor: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz | Microprocessor | 981/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 74 GiB total, 37.737 GiB free.
D: is CDROM ()
E: is CDROM (CDFS)
F: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Broadcom NetXtreme 57xx Gigabit Controller
Device ID: PCI\VEN_14E4&DEV_1600&SUBSYS_01C21028&REV_02\4&378EDFA4&0&00E2
Manufacturer: Broadcom
Name: Broadcom NetXtreme 57xx Gigabit Controller
PNP Device ID: PCI\VEN_14E4&DEV_1600&SUBSYS_01C21028&REV_02\4&378EDFA4&0&00E2
Service: b57w2k
.
==== System Restore Points ===================
.
RP274: 9/10/2012 6:58:02 AM - System Checkpoint
RP275: 9/11/2012 4:28:10 PM - System Checkpoint
RP276: 9/13/2012 7:23:26 AM - System Checkpoint
RP277: 9/14/2012 10:13:41 PM - System Checkpoint
RP278: 9/15/2012 10:35:48 PM - System Checkpoint
RP279: 9/17/2012 8:12:34 AM - System Checkpoint
RP280: 9/18/2012 8:59:12 AM - System Checkpoint
RP281: 9/19/2012 4:44:14 PM - System Checkpoint
RP282: 9/20/2012 4:53:02 PM - System Checkpoint
RP283: 9/22/2012 8:05:05 AM - System Checkpoint
RP284: 9/23/2012 9:24:34 AM - System Checkpoint
RP285: 9/23/2012 10:36:33 PM - Installed Secop CapSel
RP286: 9/25/2012 12:34:20 AM - System Checkpoint
RP287: 9/26/2012 6:09:17 AM - System Checkpoint
RP288: 9/27/2012 12:10:20 PM - System Checkpoint
RP289: 9/28/2012 7:54:12 AM - Restore Operation
RP290: 9/29/2012 9:04:36 AM - System Checkpoint
RP291: 9/30/2012 10:05:33 AM - System Checkpoint
RP292: 10/1/2012 11:09:26 AM - Installed SolidWorks eDrawings 2012.
RP293: 10/2/2012 7:36:47 PM - System Checkpoint
RP294: 10/2/2012 8:33:07 PM - Logitech Webcam Software v12.10.1110
RP295: 10/3/2012 7:02:20 AM - Restore Operation
RP296: 10/3/2012 7:17:36 AM - Restore Operation
RP297: 10/4/2012 6:28:09 PM - System Checkpoint
RP298: 10/6/2012 9:23:53 AM - System Checkpoint
RP299: 10/7/2012 2:51:11 PM - System Checkpoint
RP300: 10/8/2012 5:26:06 PM - System Checkpoint
RP301: 10/9/2012 10:05:34 PM - System Checkpoint
RP302: 10/11/2012 3:33:46 AM - System Checkpoint
RP303: 10/12/2012 2:10:08 PM - System Checkpoint
RP304: 10/13/2012 4:18:40 PM - System Checkpoint
RP305: 10/16/2012 6:28:24 PM - System Checkpoint
RP306: 10/18/2012 6:27:42 PM - System Checkpoint
RP307: 10/19/2012 7:28:16 PM - System Checkpoint
RP308: 10/20/2012 8:28:00 PM - System Checkpoint
RP309: 10/22/2012 8:07:28 AM - System Checkpoint
RP310: 10/23/2012 8:48:39 AM - System Checkpoint
RP311: 10/24/2012 9:03:17 AM - System Checkpoint
RP312: 10/28/2012 11:28:45 AM - System Checkpoint
RP313: 10/29/2012 11:31:23 AM - System Checkpoint
RP314: 11/2/2012 6:56:24 PM - System Checkpoint
RP315: 11/4/2012 11:43:08 AM - System Checkpoint
RP316: 11/5/2012 4:48:41 PM - System Checkpoint
RP317: 11/7/2012 2:30:48 AM - System Checkpoint
RP318: 11/8/2012 8:00:41 AM - Restore Operation
RP319: 11/10/2012 6:40:02 AM - System Checkpoint
RP320: 11/10/2012 8:14:51 AM - System Checkpoint
RP321: 11/11/2012 9:00:52 PM - System Checkpoint
RP322: 11/13/2012 7:56:40 AM - System Checkpoint
RP323: 11/14/2012 10:43:39 PM - System Checkpoint
RP324: 11/16/2012 5:11:03 PM - System Checkpoint
RP325: 11/18/2012 1:47:59 PM - System Checkpoint
RP326: 11/19/2012 5:21:18 PM - System Checkpoint
RP327: 11/20/2012 5:44:36 PM - System Checkpoint
RP328: 11/22/2012 2:48:58 PM - System Checkpoint
RP329: 11/23/2012 6:37:15 PM - System Checkpoint
RP330: 11/24/2012 7:25:33 PM - System Checkpoint
RP331: 11/25/2012 10:55:28 PM - System Checkpoint
RP332: 11/27/2012 7:46:20 AM - System Checkpoint
RP333: 11/28/2012 12:36:04 PM - System Checkpoint
RP334: 11/29/2012 6:36:06 PM - System Checkpoint
RP335: 12/1/2012 2:21:10 AM - System Checkpoint
RP336: 12/3/2012 8:24:07 AM - System Checkpoint
RP337: 12/4/2012 8:52:03 AM - System Checkpoint
RP338: 12/5/2012 11:01:23 AM - System Checkpoint
RP339: 12/5/2012 2:49:49 PM - Installed SolidWorks eDrawings 2013.
RP340: 12/7/2012 6:41:59 PM - System Checkpoint
RP341: 12/8/2012 11:23:19 PM - System Checkpoint
RP342: 12/9/2012 7:58:39 AM - Restore Operation
RP343: 12/9/2012 8:11:39 AM - Restore Operation
RP344: 12/9/2012 8:21:53 AM - Restore Operation
RP345: 12/9/2012 8:53:47 AM - Restore Operation
RP346: 12/9/2012 9:06:09 AM - Restore Operation
RP347: 12/9/2012 9:12:19 AM - Restore Operation
RP348: 12/9/2012 10:43:07 AM - Restore Operation
.
==== Installed Programs ======================
.
Add/Remove Pro (Freeware)
Adobe Acrobat 9 Standard
Adobe Acrobat 9.3.4 - CPSID_83708
Adobe Flash Player 11 ActiveX
Adobe Reader 9.3.1
AESPcLink
ALPS Touch Pad Driver
American Greetings CreataCard Select 6
AnswerWorks Runtime
AOL Uninstaller (Choose which Products to Remove)
Apple Application Support
Apple Software Update
AutoCAD LT 2002
Bonjour
Broadcom Gigabit Integrated Controller
Broadcom TPM Driver Installer
Canon CanoScan Toolbox 4.1
Cartwheel Shopping
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Creative Live! Cam Center
Creative Live! Cam Video Chat or Video IM Driver (1.02.01.00)
Creative Software AutoUpdate
Creative System Information
Dell Support 3.2.1
Dell Wireless WLAN Card
Digital Line Detect
EMBASSY Trust Suite by Wave Systems
ESET Online Scanner v3
ETS Launch Pad
Final Media Player 2010
FreePriceAlerts 2.3.5
Google Chrome
Google Talk (remove only)
Google Toolbar for Internet Explorer
Google Update Helper
H&R Block Deluxe + Efile + State 2011
H&R Block Massachusetts 2011
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB908673)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB971276-v3)
Intel(R) Graphics Media Accelerator Driver
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 30
LibUSB-Win32-0.1.10.1
LiveUpdate 2.0 (Symantec Corporation)
Logitech High Quality Video
Logitech Webcam Software
Logitech Webcam Software Driver Package
LWS Launcher
LWS Motion Detection
LWS Video Mask Maker
LWS VideoEffects
LWS Webcam Software
Malwarebytes Anti-Malware version 1.65.1.1000
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 ??? Language Pack
Microsoft .NET Framework 2.0 Language Pack - DEU
Microsoft .NET Framework 2.0 Language Pack - FRA
Microsoft .NET Framework 2.0 Language Pack - JPN
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Standard 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Edition 2003
Microsoft Office Visio Viewer 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Web Publishing Wizard 1.52
Modem Helper
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA
MPLAB Tools v8.46
MSXML 6.0 Parser (KB933579)
NetWaiting
NTRU Hybrid TSS v2.0.25
PowerDVD 5.7
QuickSet
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Roxio DLA
Roxio Express Labeler
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
SearchAssist
Secure Update
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929969)
SolidWorks eDrawings 2010
SolidWorks eDrawings 2011
SolidWorks eDrawings 2013
Sonic Update Manager
StarCraft II
Symantec AntiVirus
TurboTax 2010
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wrapper
Tweak UI
Uninstall AOL Emergency Connect Utility 1.0
Update for Windows XP (KB912945)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
URL Assistant
Viewpoint Media Player
Volo View Express
WebFldrs XP
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB891781
WinRAR archiver
WinZip Driver Updater
XPS Essentials Pack
XPS Essentials Pack 1.0
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
.
==== Event Viewer Messages From Past Week ========
.
12/9/2012 9:38:20 AM, error: Service Control Manager [7022] - The Yahoo! Updater service hung on starting.
12/9/2012 9:28:51 AM, error: Service Control Manager [7034] - The NTRU Hybrid TSS v2.0.25 TCS service terminated unexpectedly. It has done this 1 time(s).
12/9/2012 9:28:51 AM, error: Service Control Manager [7034] - The Dell Wireless WLAN Tray Service service terminated unexpectedly. It has done this 1 time(s).
12/9/2012 9:20:29 AM, error: Service Control Manager [7034] - The DefaultTabUpdate service terminated unexpectedly. It has done this 1 time(s).
12/9/2012 1:28:19 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the libusbd service.
12/8/2012 8:14:51 AM, error: System Error [1003] - Error code 00000019, parameter1 00000020, parameter2 86f78948, parameter3 86f78988, parameter4 0a080018.
12/6/2012 2:14:07 PM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 00197D995577 has been denied by the DHCP server 1.1.1.1 (The DHCP Server sent a DHCPNACK message).
12/5/2012 8:47:30 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
12/4/2012 9:04:31 PM, error: System Error [1003] - Error code 1000000a, parameter1 00004ff0, parameter2 00000002, parameter3 00000000, parameter4 804e30ca.
12/3/2012 8:05:22 AM, error: Dhcp [1002] - The IP address lease 192.168.1.166 for the Network Card with network address 00197D995577 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
12/3/2012 6:03:22 PM, error: Service Control Manager [7001] - The SSDP Discovery Service service depends on the HTTP service which failed to start because of the following error: Not enough storage is available to process this command.
12/3/2012 6:03:22 PM, error: Service Control Manager [7000] - The HTTP service failed to start due to the following error: Not enough storage is available to process this command.
12/3/2012 6:02:04 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SBRE
12/3/2012 6:02:04 PM, error: Service Control Manager [7023] - The Symantec AntiVirus service terminated with the following error: The environment is incorrect.
12/3/2012 6:02:04 PM, error: Service Control Manager [7000] - The Microchip MPLAB PM3 Firmware Client Driver (PM3W2K.SYS) service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
12/3/2012 6:02:04 PM, error: Service Control Manager [7000] - The Microchip MPLAB ICD 2 Firmware Client Driver (ICD2W2K.SYS) service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
12/3/2012 6:02:04 PM, error: Service Control Manager [7000] - The DataSvr2 service failed to start due to the following error: The system cannot find the file specified.
12/3/2012 6:01:37 PM, error: NETLOGON [5719] - No Domain Controller is available for domain ASPENTHERMAL due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
12/3/2012 5:50:41 PM, error: Srv [2020] - The server was unable to allocate from the system paged pool because the pool was empty.
12/3/2012 5:35:10 PM, error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{42B39CB8-08E9-402D-AABB-D369E8FDC8C8} because another computer on the network has the same name. The server could not start.
12/3/2012 5:35:10 PM, error: Server [2505] - The server could not bind to the transport \Device\NetbiosSmb because another computer on the network has the same name. The server could not start.
12/3/2012 3:38:28 PM, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.1.101 with the system having network hardware address D0:23B:0E:56E. Network operations on this system may be disrupted as a result.
12/2/2012 6:36:36 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SAVRT SBRE
12/2/2012 6:34:37 PM, error: SAVRT [20] - Unable to initialize the virus scanning engine database files.
12/2/2012 11:49:17 AM, error: Dhcp [1002] - The IP address lease 192.168.1.6 for the Network Card with network address 00197D995577 has been denied by the DHCP server 192.168.208.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by dolsen at 13:29:34 on 2012-12-09
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.567 [GMT -5:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.weather.com/weather/right-now/USMA0273
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070424
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: YTNavAssistPlugin Class: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: DriveLetterAccess: {5CA3D70E-1895-11CF-8E15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: Cartwheel: {B50DF051-E1D4-439C-B94E-F4DE82B56542} - c:\documents and settings\dolsen\application data\cartwheel\Cartwheel.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178310621687
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} - file:///C:/Program%20Files/AutoCAD%20LT%202002/InstBanr.ocx
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202002/InstFred.ocx
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202002/AcPreview.ocx
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{42B39CB8-08E9-402D-AABB-D369E8FDC8C8} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{528D6902-83EA-4BF9-BE9E-6330E3C55526} : DHCPNameServer = 192.168.2.12
TCP: Interfaces\{C8FB8631-14EB-4BD0-9EBA-74664FE3AF1E} : DHCPNameServer = 192.168.2.12 192.168.2.11
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
.
============= SERVICES / DRIVERS ===============
.
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2004-2-9 301200]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [2012-5-6 332248]
R1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [2012-5-6 212568]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2004-3-12 169192]
R2 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2004-2-9 37008]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2011-7-24 33792]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100823.002\naveng.sys [2010-8-24 85424]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100823.002\navex15.sys [2010-8-24 1362608]
R3 SBFWIMCLMP;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [2012-5-6 69208]
S0 mtjjs;mtjjs;c:\windows\system32\drivers\mvoxailg.sys --> c:\windows\system32\drivers\mvoxailg.sys [?]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S2 MCUSBICD2;Microchip MPLAB ICD 2 Firmware Client Driver (ICD2W2K.SYS);c:\windows\system32\drivers\icd2w2k.sys [2004-3-22 12427]
S2 MCUSBPM3;Microchip MPLAB PM3 Firmware Client Driver (PM3W2K.SYS);c:\windows\system32\drivers\PM3w2k.sys [2004-3-22 12447]
S2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2004-3-12 1221864]
S3 NCBULK;MPLAB HS USB client driver;c:\windows\system32\drivers\RealICEBulk.SYS [2010-11-23 12160]
S3 nicsrkw;nicsrkw;c:\windows\system32\drivers\nicsrkw.sys --> c:\windows\system32\drivers\nicsrkw.sys [?]
S3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Service;c:\windows\system32\drivers\SbFwIm.sys [2012-5-6 69208]
S3 sbhips;sbhips;c:\windows\system32\drivers\sbhips.sys [2012-5-6 94040]
S3 VF0350Afx;VF0350 Audio FX;c:\windows\system32\drivers\V0350Afx.sys [2010-3-31 142656]
S3 VF0350Vfx;VF0350 Video FX;c:\windows\system32\drivers\V0350Vfx.sys [2010-3-31 7424]
S3 VF0350Vid;Live! Cam Video IM (VF0350);c:\windows\system32\drivers\V0350Vid.sys [2010-3-31 170368]
S4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2004-2-29 255096]
S4 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2004-2-29 87160]
S4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2004-2-29 242808]
.
=============== Created Last 30 ================
.
2012-12-09 13:19:26 -------- d-----w- c:\documents and settings\all users\application data\PC Optimizer Pro
2012-12-08 19:36:18 -------- d-----w- c:\documents and settings\dolsen\application data\DefaultTab
2012-12-08 19:35:51 -------- d-----w- c:\documents and settings\dolsen\application data\Cartwheel
2012-12-05 19:49:53 -------- d-----w- c:\program files\common files\eDrawings2013
2012-12-05 11:41:16 -------- d-----w- c:\documents and settings\dolsen\application data\Paltalk
2012-12-02 18:45:04 -------- d-----w- c:\documents and settings\dolsen\application data\FreePriceAlerts
2012-12-02 18:40:46 -------- d-----w- c:\program files\common files\xing shared
2012-12-02 18:39:47 -------- d-----w- c:\program files\FreePriceAlerts
2012-12-02 18:39:46 -------- d-----w- c:\documents and settings\all users\application data\InstallMate
.
==================== Find3M ====================
.
2012-11-09 16:59:50 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-09 16:59:50 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-30 00:54:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-14 16:55:40 368128 ----a-w- c:\program files\EModelViewer.exe
2010-06-14 16:55:14 97280 ----a-w- c:\program files\EModelEx
2010-06-14 16:55:12 27648 ----a-w- c:\program files\edrwthumbnailprovider.dll
2010-06-14 16:54:20 1149952 ----a-w- c:\program files\eDrawingOfficeAutomator.exe
2010-06-14 16:53:54 835584 ----a-w- c:\program files\EModelSWDisplayLists.dll
2010-06-14 16:52:50 91136 ----a-w- c:\program files\EModelExport.dll
2010-06-14 16:52:28 143360 ----a-w- c:\program files\EModelMDReader.dll
2010-06-14 16:52:08 8760832 ----a-w- c:\program files\EModelXlator.dll
2010-06-14 16:51:16 72192 ----a-w- c:\program files\EModelEventLog.dll
2010-06-14 16:49:52 868352 ----a-w- c:\program files\EModelReviewer.dll
2010-06-14 16:46:36 4797952 ----a-w- c:\program files\EModelView.dll
2010-06-14 16:38:48 61440 ----a-w- c:\program files\EModelUtilsVista.dll
2010-06-14 16:38:38 216576 ----a-w- c:\program files\EModelUtils.dll
2010-06-14 16:38:06 3385344 ----a-w- c:\program files\EModelAddIn_libFNP.dll
2010-06-14 16:38:04 2938383 ----a-w- c:\program files\EModelAddIn.dll
2010-06-14 16:37:50 53248 ----a-w- c:\program files\eDrawingsGraphicsCardClient.dll
2010-06-14 16:37:42 4483584 ----a-w- c:\program files\HoopsManager.dll
2010-06-14 15:52:34 299288 ----a-w- c:\program files\solidworkslicenseservice.dll
2010-06-14 15:52:34 263464 ----a-w- c:\program files\swlicservinst.exe
2010-06-14 15:50:52 17920 ----a-w- c:\program files\IMPLODE.DLL
.
============= FINISH: 13:30:19.32 ===============
Ran combofix before I found this website and it mentioned something about rootkit sero access, but didnt seem to correct the problems. Thanks for any help you cn provide.
Here are the logs.
Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org
Database version: v2012.12.03.01
Windows XP Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.18702
dolsen :: TEST1 [administrator]
12/9/2012 1:13:25 PM
mbam-log-2012-12-09 (13-13-25).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 322336
Time elapsed: 7 minute(s), 7 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 5/4/2007 4:12:11 PM
System Uptime: 12/9/2012 12:29:52 PM (1 hours ago)
.
Motherboard: Dell Inc. | | 0FT292
Processor: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz | Microprocessor | 981/166mhz
Processor: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz | Microprocessor | 981/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 74 GiB total, 37.737 GiB free.
D: is CDROM ()
E: is CDROM (CDFS)
F: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Broadcom NetXtreme 57xx Gigabit Controller
Device ID: PCI\VEN_14E4&DEV_1600&SUBSYS_01C21028&REV_02\4&378EDFA4&0&00E2
Manufacturer: Broadcom
Name: Broadcom NetXtreme 57xx Gigabit Controller
PNP Device ID: PCI\VEN_14E4&DEV_1600&SUBSYS_01C21028&REV_02\4&378EDFA4&0&00E2
Service: b57w2k
.
==== System Restore Points ===================
.
RP274: 9/10/2012 6:58:02 AM - System Checkpoint
RP275: 9/11/2012 4:28:10 PM - System Checkpoint
RP276: 9/13/2012 7:23:26 AM - System Checkpoint
RP277: 9/14/2012 10:13:41 PM - System Checkpoint
RP278: 9/15/2012 10:35:48 PM - System Checkpoint
RP279: 9/17/2012 8:12:34 AM - System Checkpoint
RP280: 9/18/2012 8:59:12 AM - System Checkpoint
RP281: 9/19/2012 4:44:14 PM - System Checkpoint
RP282: 9/20/2012 4:53:02 PM - System Checkpoint
RP283: 9/22/2012 8:05:05 AM - System Checkpoint
RP284: 9/23/2012 9:24:34 AM - System Checkpoint
RP285: 9/23/2012 10:36:33 PM - Installed Secop CapSel
RP286: 9/25/2012 12:34:20 AM - System Checkpoint
RP287: 9/26/2012 6:09:17 AM - System Checkpoint
RP288: 9/27/2012 12:10:20 PM - System Checkpoint
RP289: 9/28/2012 7:54:12 AM - Restore Operation
RP290: 9/29/2012 9:04:36 AM - System Checkpoint
RP291: 9/30/2012 10:05:33 AM - System Checkpoint
RP292: 10/1/2012 11:09:26 AM - Installed SolidWorks eDrawings 2012.
RP293: 10/2/2012 7:36:47 PM - System Checkpoint
RP294: 10/2/2012 8:33:07 PM - Logitech Webcam Software v12.10.1110
RP295: 10/3/2012 7:02:20 AM - Restore Operation
RP296: 10/3/2012 7:17:36 AM - Restore Operation
RP297: 10/4/2012 6:28:09 PM - System Checkpoint
RP298: 10/6/2012 9:23:53 AM - System Checkpoint
RP299: 10/7/2012 2:51:11 PM - System Checkpoint
RP300: 10/8/2012 5:26:06 PM - System Checkpoint
RP301: 10/9/2012 10:05:34 PM - System Checkpoint
RP302: 10/11/2012 3:33:46 AM - System Checkpoint
RP303: 10/12/2012 2:10:08 PM - System Checkpoint
RP304: 10/13/2012 4:18:40 PM - System Checkpoint
RP305: 10/16/2012 6:28:24 PM - System Checkpoint
RP306: 10/18/2012 6:27:42 PM - System Checkpoint
RP307: 10/19/2012 7:28:16 PM - System Checkpoint
RP308: 10/20/2012 8:28:00 PM - System Checkpoint
RP309: 10/22/2012 8:07:28 AM - System Checkpoint
RP310: 10/23/2012 8:48:39 AM - System Checkpoint
RP311: 10/24/2012 9:03:17 AM - System Checkpoint
RP312: 10/28/2012 11:28:45 AM - System Checkpoint
RP313: 10/29/2012 11:31:23 AM - System Checkpoint
RP314: 11/2/2012 6:56:24 PM - System Checkpoint
RP315: 11/4/2012 11:43:08 AM - System Checkpoint
RP316: 11/5/2012 4:48:41 PM - System Checkpoint
RP317: 11/7/2012 2:30:48 AM - System Checkpoint
RP318: 11/8/2012 8:00:41 AM - Restore Operation
RP319: 11/10/2012 6:40:02 AM - System Checkpoint
RP320: 11/10/2012 8:14:51 AM - System Checkpoint
RP321: 11/11/2012 9:00:52 PM - System Checkpoint
RP322: 11/13/2012 7:56:40 AM - System Checkpoint
RP323: 11/14/2012 10:43:39 PM - System Checkpoint
RP324: 11/16/2012 5:11:03 PM - System Checkpoint
RP325: 11/18/2012 1:47:59 PM - System Checkpoint
RP326: 11/19/2012 5:21:18 PM - System Checkpoint
RP327: 11/20/2012 5:44:36 PM - System Checkpoint
RP328: 11/22/2012 2:48:58 PM - System Checkpoint
RP329: 11/23/2012 6:37:15 PM - System Checkpoint
RP330: 11/24/2012 7:25:33 PM - System Checkpoint
RP331: 11/25/2012 10:55:28 PM - System Checkpoint
RP332: 11/27/2012 7:46:20 AM - System Checkpoint
RP333: 11/28/2012 12:36:04 PM - System Checkpoint
RP334: 11/29/2012 6:36:06 PM - System Checkpoint
RP335: 12/1/2012 2:21:10 AM - System Checkpoint
RP336: 12/3/2012 8:24:07 AM - System Checkpoint
RP337: 12/4/2012 8:52:03 AM - System Checkpoint
RP338: 12/5/2012 11:01:23 AM - System Checkpoint
RP339: 12/5/2012 2:49:49 PM - Installed SolidWorks eDrawings 2013.
RP340: 12/7/2012 6:41:59 PM - System Checkpoint
RP341: 12/8/2012 11:23:19 PM - System Checkpoint
RP342: 12/9/2012 7:58:39 AM - Restore Operation
RP343: 12/9/2012 8:11:39 AM - Restore Operation
RP344: 12/9/2012 8:21:53 AM - Restore Operation
RP345: 12/9/2012 8:53:47 AM - Restore Operation
RP346: 12/9/2012 9:06:09 AM - Restore Operation
RP347: 12/9/2012 9:12:19 AM - Restore Operation
RP348: 12/9/2012 10:43:07 AM - Restore Operation
.
==== Installed Programs ======================
.
Add/Remove Pro (Freeware)
Adobe Acrobat 9 Standard
Adobe Acrobat 9.3.4 - CPSID_83708
Adobe Flash Player 11 ActiveX
Adobe Reader 9.3.1
AESPcLink
ALPS Touch Pad Driver
American Greetings CreataCard Select 6
AnswerWorks Runtime
AOL Uninstaller (Choose which Products to Remove)
Apple Application Support
Apple Software Update
AutoCAD LT 2002
Bonjour
Broadcom Gigabit Integrated Controller
Broadcom TPM Driver Installer
Canon CanoScan Toolbox 4.1
Cartwheel Shopping
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Creative Live! Cam Center
Creative Live! Cam Video Chat or Video IM Driver (1.02.01.00)
Creative Software AutoUpdate
Creative System Information
Dell Support 3.2.1
Dell Wireless WLAN Card
Digital Line Detect
EMBASSY Trust Suite by Wave Systems
ESET Online Scanner v3
ETS Launch Pad
Final Media Player 2010
FreePriceAlerts 2.3.5
Google Chrome
Google Talk (remove only)
Google Toolbar for Internet Explorer
Google Update Helper
H&R Block Deluxe + Efile + State 2011
H&R Block Massachusetts 2011
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB908673)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB971276-v3)
Intel(R) Graphics Media Accelerator Driver
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 30
LibUSB-Win32-0.1.10.1
LiveUpdate 2.0 (Symantec Corporation)
Logitech High Quality Video
Logitech Webcam Software
Logitech Webcam Software Driver Package
LWS Launcher
LWS Motion Detection
LWS Video Mask Maker
LWS VideoEffects
LWS Webcam Software
Malwarebytes Anti-Malware version 1.65.1.1000
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 ??? Language Pack
Microsoft .NET Framework 2.0 Language Pack - DEU
Microsoft .NET Framework 2.0 Language Pack - FRA
Microsoft .NET Framework 2.0 Language Pack - JPN
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Standard 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Edition 2003
Microsoft Office Visio Viewer 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Web Publishing Wizard 1.52
Modem Helper
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA
MPLAB Tools v8.46
MSXML 6.0 Parser (KB933579)
NetWaiting
NTRU Hybrid TSS v2.0.25
PowerDVD 5.7
QuickSet
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Roxio DLA
Roxio Express Labeler
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
SearchAssist
Secure Update
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929969)
SolidWorks eDrawings 2010
SolidWorks eDrawings 2011
SolidWorks eDrawings 2013
Sonic Update Manager
StarCraft II
Symantec AntiVirus
TurboTax 2010
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wrapper
Tweak UI
Uninstall AOL Emergency Connect Utility 1.0
Update for Windows XP (KB912945)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
URL Assistant
Viewpoint Media Player
Volo View Express
WebFldrs XP
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB891781
WinRAR archiver
WinZip Driver Updater
XPS Essentials Pack
XPS Essentials Pack 1.0
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
.
==== Event Viewer Messages From Past Week ========
.
12/9/2012 9:38:20 AM, error: Service Control Manager [7022] - The Yahoo! Updater service hung on starting.
12/9/2012 9:28:51 AM, error: Service Control Manager [7034] - The NTRU Hybrid TSS v2.0.25 TCS service terminated unexpectedly. It has done this 1 time(s).
12/9/2012 9:28:51 AM, error: Service Control Manager [7034] - The Dell Wireless WLAN Tray Service service terminated unexpectedly. It has done this 1 time(s).
12/9/2012 9:20:29 AM, error: Service Control Manager [7034] - The DefaultTabUpdate service terminated unexpectedly. It has done this 1 time(s).
12/9/2012 1:28:19 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the libusbd service.
12/8/2012 8:14:51 AM, error: System Error [1003] - Error code 00000019, parameter1 00000020, parameter2 86f78948, parameter3 86f78988, parameter4 0a080018.
12/6/2012 2:14:07 PM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 00197D995577 has been denied by the DHCP server 1.1.1.1 (The DHCP Server sent a DHCPNACK message).
12/5/2012 8:47:30 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
12/4/2012 9:04:31 PM, error: System Error [1003] - Error code 1000000a, parameter1 00004ff0, parameter2 00000002, parameter3 00000000, parameter4 804e30ca.
12/3/2012 8:05:22 AM, error: Dhcp [1002] - The IP address lease 192.168.1.166 for the Network Card with network address 00197D995577 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
12/3/2012 6:03:22 PM, error: Service Control Manager [7001] - The SSDP Discovery Service service depends on the HTTP service which failed to start because of the following error: Not enough storage is available to process this command.
12/3/2012 6:03:22 PM, error: Service Control Manager [7000] - The HTTP service failed to start due to the following error: Not enough storage is available to process this command.
12/3/2012 6:02:04 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SBRE
12/3/2012 6:02:04 PM, error: Service Control Manager [7023] - The Symantec AntiVirus service terminated with the following error: The environment is incorrect.
12/3/2012 6:02:04 PM, error: Service Control Manager [7000] - The Microchip MPLAB PM3 Firmware Client Driver (PM3W2K.SYS) service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
12/3/2012 6:02:04 PM, error: Service Control Manager [7000] - The Microchip MPLAB ICD 2 Firmware Client Driver (ICD2W2K.SYS) service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
12/3/2012 6:02:04 PM, error: Service Control Manager [7000] - The DataSvr2 service failed to start due to the following error: The system cannot find the file specified.
12/3/2012 6:01:37 PM, error: NETLOGON [5719] - No Domain Controller is available for domain ASPENTHERMAL due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
12/3/2012 5:50:41 PM, error: Srv [2020] - The server was unable to allocate from the system paged pool because the pool was empty.
12/3/2012 5:35:10 PM, error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{42B39CB8-08E9-402D-AABB-D369E8FDC8C8} because another computer on the network has the same name. The server could not start.
12/3/2012 5:35:10 PM, error: Server [2505] - The server could not bind to the transport \Device\NetbiosSmb because another computer on the network has the same name. The server could not start.
12/3/2012 3:38:28 PM, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.1.101 with the system having network hardware address D0:23B:0E:56E. Network operations on this system may be disrupted as a result.
12/2/2012 6:36:36 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SAVRT SBRE
12/2/2012 6:34:37 PM, error: SAVRT [20] - Unable to initialize the virus scanning engine database files.
12/2/2012 11:49:17 AM, error: Dhcp [1002] - The IP address lease 192.168.1.6 for the Network Card with network address 00197D995577 has been denied by the DHCP server 192.168.208.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by dolsen at 13:29:34 on 2012-12-09
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.567 [GMT -5:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.weather.com/weather/right-now/USMA0273
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070424
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: YTNavAssistPlugin Class: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: DriveLetterAccess: {5CA3D70E-1895-11CF-8E15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: Cartwheel: {B50DF051-E1D4-439C-B94E-F4DE82B56542} - c:\documents and settings\dolsen\application data\cartwheel\Cartwheel.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178310621687
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} - file:///C:/Program%20Files/AutoCAD%20LT%202002/InstBanr.ocx
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202002/InstFred.ocx
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file:///C:/Program%20Files/AutoCAD%20LT%202002/AcPreview.ocx
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{42B39CB8-08E9-402D-AABB-D369E8FDC8C8} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{528D6902-83EA-4BF9-BE9E-6330E3C55526} : DHCPNameServer = 192.168.2.12
TCP: Interfaces\{C8FB8631-14EB-4BD0-9EBA-74664FE3AF1E} : DHCPNameServer = 192.168.2.12 192.168.2.11
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
.
============= SERVICES / DRIVERS ===============
.
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2004-2-9 301200]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [2012-5-6 332248]
R1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [2012-5-6 212568]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2004-3-12 169192]
R2 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2004-2-9 37008]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2011-7-24 33792]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100823.002\naveng.sys [2010-8-24 85424]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100823.002\navex15.sys [2010-8-24 1362608]
R3 SBFWIMCLMP;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [2012-5-6 69208]
S0 mtjjs;mtjjs;c:\windows\system32\drivers\mvoxailg.sys --> c:\windows\system32\drivers\mvoxailg.sys [?]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S2 MCUSBICD2;Microchip MPLAB ICD 2 Firmware Client Driver (ICD2W2K.SYS);c:\windows\system32\drivers\icd2w2k.sys [2004-3-22 12427]
S2 MCUSBPM3;Microchip MPLAB PM3 Firmware Client Driver (PM3W2K.SYS);c:\windows\system32\drivers\PM3w2k.sys [2004-3-22 12447]
S2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2004-3-12 1221864]
S3 NCBULK;MPLAB HS USB client driver;c:\windows\system32\drivers\RealICEBulk.SYS [2010-11-23 12160]
S3 nicsrkw;nicsrkw;c:\windows\system32\drivers\nicsrkw.sys --> c:\windows\system32\drivers\nicsrkw.sys [?]
S3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Service;c:\windows\system32\drivers\SbFwIm.sys [2012-5-6 69208]
S3 sbhips;sbhips;c:\windows\system32\drivers\sbhips.sys [2012-5-6 94040]
S3 VF0350Afx;VF0350 Audio FX;c:\windows\system32\drivers\V0350Afx.sys [2010-3-31 142656]
S3 VF0350Vfx;VF0350 Video FX;c:\windows\system32\drivers\V0350Vfx.sys [2010-3-31 7424]
S3 VF0350Vid;Live! Cam Video IM (VF0350);c:\windows\system32\drivers\V0350Vid.sys [2010-3-31 170368]
S4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2004-2-29 255096]
S4 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2004-2-29 87160]
S4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2004-2-29 242808]
.
=============== Created Last 30 ================
.
2012-12-09 13:19:26 -------- d-----w- c:\documents and settings\all users\application data\PC Optimizer Pro
2012-12-08 19:36:18 -------- d-----w- c:\documents and settings\dolsen\application data\DefaultTab
2012-12-08 19:35:51 -------- d-----w- c:\documents and settings\dolsen\application data\Cartwheel
2012-12-05 19:49:53 -------- d-----w- c:\program files\common files\eDrawings2013
2012-12-05 11:41:16 -------- d-----w- c:\documents and settings\dolsen\application data\Paltalk
2012-12-02 18:45:04 -------- d-----w- c:\documents and settings\dolsen\application data\FreePriceAlerts
2012-12-02 18:40:46 -------- d-----w- c:\program files\common files\xing shared
2012-12-02 18:39:47 -------- d-----w- c:\program files\FreePriceAlerts
2012-12-02 18:39:46 -------- d-----w- c:\documents and settings\all users\application data\InstallMate
.
==================== Find3M ====================
.
2012-11-09 16:59:50 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-09 16:59:50 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-30 00:54:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-14 16:55:40 368128 ----a-w- c:\program files\EModelViewer.exe
2010-06-14 16:55:14 97280 ----a-w- c:\program files\EModelEx
2010-06-14 16:55:12 27648 ----a-w- c:\program files\edrwthumbnailprovider.dll
2010-06-14 16:54:20 1149952 ----a-w- c:\program files\eDrawingOfficeAutomator.exe
2010-06-14 16:53:54 835584 ----a-w- c:\program files\EModelSWDisplayLists.dll
2010-06-14 16:52:50 91136 ----a-w- c:\program files\EModelExport.dll
2010-06-14 16:52:28 143360 ----a-w- c:\program files\EModelMDReader.dll
2010-06-14 16:52:08 8760832 ----a-w- c:\program files\EModelXlator.dll
2010-06-14 16:51:16 72192 ----a-w- c:\program files\EModelEventLog.dll
2010-06-14 16:49:52 868352 ----a-w- c:\program files\EModelReviewer.dll
2010-06-14 16:46:36 4797952 ----a-w- c:\program files\EModelView.dll
2010-06-14 16:38:48 61440 ----a-w- c:\program files\EModelUtilsVista.dll
2010-06-14 16:38:38 216576 ----a-w- c:\program files\EModelUtils.dll
2010-06-14 16:38:06 3385344 ----a-w- c:\program files\EModelAddIn_libFNP.dll
2010-06-14 16:38:04 2938383 ----a-w- c:\program files\EModelAddIn.dll
2010-06-14 16:37:50 53248 ----a-w- c:\program files\eDrawingsGraphicsCardClient.dll
2010-06-14 16:37:42 4483584 ----a-w- c:\program files\HoopsManager.dll
2010-06-14 15:52:34 299288 ----a-w- c:\program files\solidworkslicenseservice.dll
2010-06-14 15:52:34 263464 ----a-w- c:\program files\swlicservinst.exe
2010-06-14 15:50:52 17920 ----a-w- c:\program files\IMPLODE.DLL
.
============= FINISH: 13:30:19.32 ===============