OK... Two note, I had to re-instal Java in order to run Kapersky and I had to uninstal Avast anyway because its GUI broke after the first run of combo fix.
I can attach these instead if you would prefer.
Once again, thanks for your assistance.
Virustotal link:
http://www.virustotal.com/analisis/5787ad3...3259-1258460410
Combofix log:
ComboFix 09-11-17.01 - cswitch 11/17/2009 7:57.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2550.1970 [GMT -8:00]
Running from: c:\documents and settings\cswitch\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\cswitch\Desktop\bleepingcomputer_logs\CFScript.txt
AV: avast! antivirus 4.8.1356 [VPS 091117-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
file zipped: c:\documents and settings\cswitch\Application Data\Adobe\isdn.dll
file zipped: c:\documents and settings\cswitch\Application Data\Ahead\pup.exe
file zipped: c:\documents and settings\cswitch\Application Data\Corel Photo Album\ven32.exe
file zipped: c:\documents and settings\cswitch\Application Data\Google\kls.dll
file zipped: c:\documents and settings\cswitch\Application Data\Help\regs32.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\cswitch\Application Data\Adobe\isdn.dll
c:\documents and settings\cswitch\Application Data\Ahead\pup.exe
c:\documents and settings\cswitch\Application Data\Corel Photo Album\ven32.exe
c:\documents and settings\cswitch\Application Data\Google\kls.dll
c:\documents and settings\cswitch\Application Data\Help\regs32.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-17 to 2009-11-17 )))))))))))))))))))))))))))))))
.
2009-11-17 15:25 . 2009-11-17 15:25 -------- d-----w- c:\windows\LastGood
2009-11-16 15:30 . 2009-11-17 15:26 -------- d-----w- c:\windows\ie8updates
2009-11-16 02:57 . 2009-11-16 02:57 54624 ----a-w- c:\windows\system32\51334.sys
2009-11-15 17:37 . 2009-11-15 17:37 -------- d-----w- c:\program files\Java
2009-11-15 17:16 . 2009-11-15 17:16 -------- d-sh--w- c:\documents and settings\cswitch\PrivacIE
2009-11-15 17:07 . 2009-11-15 17:07 -------- d-sh--w- c:\documents and settings\cswitch\IETldCache
2009-11-15 11:22 . 2009-11-15 11:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-11-15 07:32 . 2009-08-29 08:08 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-11-15 07:31 . 2009-08-29 08:08 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-15 07:28 . 2009-11-15 07:30 -------- dc-h--w- c:\windows\ie8
2009-11-15 07:21 . 2009-11-15 07:21 -------- d-----w- c:\windows\system32\MpEngineStore
2009-11-12 18:56 . 2009-11-15 17:08 -------- d-----w- c:\windows\038A524F58DB438A83918F7F0CA14B9E.TMP
2009-11-09 22:55 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-09 22:55 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-09 22:55 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-09 22:54 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-09 22:54 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-09 22:54 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-09 22:54 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-09 22:54 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-09 22:53 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-09 22:53 . 2009-11-09 22:53 -------- d-----w- c:\program files\Alwil Software
2009-11-09 22:20 . 2009-11-15 17:37 152576 ----a-w- c:\documents and settings\cswitch\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-09 22:20 . 2009-11-09 22:20 79488 ----a-w- c:\documents and settings\cswitch\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-09 22:01 . 2009-11-09 22:01 -------- d-----w- c:\documents and settings\admin\Application Data\Spyware Terminator
2009-11-09 04:13 . 2009-11-09 04:13 -------- d-----w- c:\program files\Trend Micro
2009-11-08 17:18 . 2009-11-08 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2009-11-08 17:18 . 2009-11-08 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2009-11-08 17:18 . 2009-11-08 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2009-11-08 17:18 . 2009-11-17 05:48 -------- d-----w- c:\documents and settings\cswitch\Application Data\Spyware Terminator
2009-11-08 17:18 . 2009-11-17 15:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-11-08 17:18 . 2009-11-17 05:48 -------- d-----w- c:\program files\Spyware Terminator
2009-10-27 02:09 . 2009-10-27 02:09 -------- d-----w- c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2009-10-27 02:09 . 2009-10-27 02:09 -------- d-----w- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2009-10-23 22:25 . 2009-10-23 22:25 -------- d-----w- c:\documents and settings\cswitch\Local Settings\Application Data\Cooliris
2009-10-23 22:24 . 2009-10-20 20:33 545280 ----a-w- c:\documents and settings\cswitch\Application Data\Mozilla\Firefox\Profiles\kulz7fqu.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-10-23 22:24 . 2009-10-20 20:33 4716544 ----a-w- c:\documents and settings\cswitch\Application Data\Mozilla\Firefox\Profiles\kulz7fqu.default\extensions\piclens@cooliris.com\components\cooliris.dll
2009-10-23 22:24 . 2009-10-20 20:33 344064 ----a-w- c:\documents and settings\cswitch\Application Data\Mozilla\Firefox\Profiles\kulz7fqu.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-10-23 22:24 . 2009-10-20 20:33 153600 ----a-w- c:\documents and settings\cswitch\Application Data\Mozilla\Firefox\Profiles\kulz7fqu.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2009-10-23 22:24 . 2009-10-20 20:33 103424 ----a-w- c:\documents and settings\cswitch\Application Data\Mozilla\Firefox\Profiles\kulz7fqu.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-17 16:02 . 2009-08-01 01:22 -------- d-----w- c:\documents and settings\cswitch\Application Data\Ahead
2009-11-17 16:02 . 2009-07-17 20:08 -------- d-----w- c:\documents and settings\cswitch\Application Data\Corel Photo Album
2009-11-17 04:31 . 2009-09-19 19:22 -------- d-----w- c:\documents and settings\cswitch\Application Data\Skype
2009-11-15 17:37 . 2009-04-01 01:11 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-15 17:15 . 2006-04-04 14:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-10 00:05 . 2006-04-04 14:57 -------- d-----w- c:\program files\BAE
2009-11-08 20:53 . 2009-09-05 18:10 -------- d-----w- c:\program files\SoundSpectrum
2009-11-08 20:52 . 2009-09-05 18:16 -------- d-----w- c:\documents and settings\cswitch\Application Data\SoundSpectrum
2009-11-08 00:23 . 2009-04-02 00:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-08 00:22 . 2009-07-17 20:02 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-10-22 09:19 . 2009-11-16 23:02 5939712 ------w- c:\windows\system32\SET18.tmp
2009-10-10 00:40 . 2009-10-10 00:39 -------- d-----w- c:\program files\XEmacs
2009-10-01 22:18 . 2009-10-01 22:18 -------- d-----w- c:\program files\IrfanView
2009-09-20 17:18 . 2006-04-04 14:57 -------- d-----w- c:\program files\Sonic
2009-09-19 19:22 . 2009-09-19 19:22 -------- d-----r- c:\program files\Skype
2009-09-19 19:22 . 2009-09-19 19:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-09-11 14:18 . 2004-08-11 22:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 22:54 . 2009-04-02 00:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 22:53 . 2009-04-02 00:47 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2004-08-11 22:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-11 22:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-28 01:21 . 2009-04-29 21:42 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-28 01:21 . 2009-04-29 21:42 56 --sh--r- c:\windows\system32\F1048E2600.sys
2009-08-26 08:00 . 2004-08-11 22:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-21 16:48 . 2009-08-21 16:48 152576 ----a-w- c:\documents and settings\cswitch\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-17_05.30.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-17 15:26 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976749-IE8\spuninst\updspapi.dll
+ 2009-11-17 15:26 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976749-IE8\spuninst\spuninst.exe
+ 2006-05-19 15:06 . 2009-10-22 09:19 5939712 c:\windows\system32\dllcache\mshtml.dll
+ 2009-11-17 15:26 . 2009-08-29 08:08 5940224 c:\windows\ie8updates\KB976749-IE8\mshtml.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-07 149040]
"DellTransferAgent"="c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 135168]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
"PxDotNetLoader"="c:\program files\Fidelity Investments\Fidelity Active Trader\System\ATPStartupAssistant.exe" [2009-03-25 42336]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-03 25626408]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2009-11-08 3055616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-04-04 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-04 98304]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-04-04 169472]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-13 1117184]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-10-30 949376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"Ink Monitor"="c:\program files\EPSON\Ink Monitor\InkMonitor.exe" [2001-12-07 258118]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-11-08 2172416]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-15 149280]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2009-8-27 135680]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
Winter Fun Wallpaper Changer.lnk - c:\windows\Installer\{038A524F-58DB-438A-8391-8F7F0CA14B9E}\Icon038A524F.exe [2009-9-5 14336]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\InstantRails\\ruby\\bin\\ruby.exe"=
"c:\\InstantRails\\apache\\Apache.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11/9/2009 2:54 PM 114768]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [10/29/2007 5:04 PM 15424]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [11/8/2009 9:18 AM 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/9/2009 2:54 PM 20560]
R3 SNXPCARD;Sunix PCI Multi I/O Card Driver;c:\windows\system32\drivers\snxpcard.sys [6/15/2006 12:19 PM 23040]
R3 SNXPSERX;SNXPSERX;c:\windows\system32\drivers\snxpserx.sys [6/15/2006 12:31 PM 56320]
S3 51334;51334;c:\windows\system32\51334.sys [11/15/2009 6:57 PM 54624]
S3 EPUSBSTOR;EPSON USB Storage Driver;c:\windows\system32\drivers\epusbsto.sys [8/27/2009 4:52 PM 17976]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder
2006-04-28 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-11 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\cswitch\Application Data\Mozilla\Firefox\Profiles\kulz7fqu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\cswitch\Application Data\Mozilla\Firefox\Profiles\kulz7fqu.default\extensions\piclens@cooliris.com\components\cooliris.dll
FF - plugin: c:\documents and settings\cswitch\Application Data\Mozilla\Firefox\Profiles\kulz7fqu.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\cswitch\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\igfxdev.dll
.
Completion time: 2009-11-17 08:05
ComboFix-quarantined-files.txt 2009-11-17 16:04
ComboFix2.txt 2009-11-17 05:37
Pre-Run: 117,237,501,952 bytes free
Post-Run: 117,203,062,784 bytes free
- - End Of File - - 9D37B423FA824B55FA958E0EA471CC88
Upload was successful
Kapersky log:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, November 17, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, November 17, 2009 23:55:39
Records in database: 3230740
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Objects scanned: 139344
Threats found: 5
Infected objects found: 5
Suspicious objects found: 0
Scan duration: 02:04:33
File name / Threat / Threats count
C:\Program Files\Eset\cache\FND0.NFI Infected: Trojan.Win32.FraudPack.tbp 1
C:\Program Files\Eset\cache\FND1.NFI Infected: Packed.Win32.Zack.a 1
C:\Program Files\Eset\cache\FND2.NFI Infected: Trojan.Win32.FraudPack.stu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.TDSS.u 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP918\A0029138.dll Infected: Packed.Win32.TDSS.z 1
Selected area has been scanned.
DDS log:
DDS (Ver_09-10-26.01) - NTFSx86
Run by cswitch at 21:13:17.64 on Tue 11/17/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2550.1943 [GMT -8:00]
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
svchost.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\cswitch\Desktop\bleepingcomputer_logs\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [DellTransferAgent] "c:\documents and settings\all users\application data\dell\transferagent\TransferAgent.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [PxDotNetLoader] "c:\program files\fidelity investments\fidelity active trader\system\ATPStartupAssistant.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [SpywareTerminatorUpdate] "c:\program files\spyware terminator\SpywareTerminatorUpdate.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [Ink Monitor] c:\program files\epson\ink monitor\InkMonitor.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [SpywareTerminator] "c:\program files\spyware terminator\SpywareTerminatorShield.exe"
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsons~1.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winter~1.lnk - c:\windows\installer\{038a524f-58db-438a-8391-8f7f0ca14b9e}\Icon038A524F.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238549138022
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: x-atng - {7e8717b0-d862-11d5-8c9e-00010304f989} - c:\program files\fidelity investments\fidelity active trader\system\atngprot.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\cswitch\applic~1\mozilla\firefox\profiles\kulz7fqu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\cswitch\application data\mozilla\firefox\profiles\kulz7fqu.default\extensions\piclens@cooliris.com\components\cooliris.dll
FF - plugin: c:\documents and settings\cswitch\application data\mozilla\firefox\profiles\kulz7fqu.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\cswitch\local settings\application data\yahoo!\browserplus\2.4.17\plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-10-29 15424]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2009-11-8 142592]
R3 SNXPCARD;Sunix PCI Multi I/O Card Driver;c:\windows\system32\drivers\snxpcard.sys [2006-6-15 23040]
R3 SNXPSERX;SNXPSERX;c:\windows\system32\drivers\snxpserx.sys [2006-6-15 56320]
S3 51334;51334;c:\windows\system32\51334.sys [2009-11-15 54624]
S3 EPUSBSTOR;EPSON USB Storage Driver;c:\windows\system32\drivers\epusbsto.sys [2009-8-27 17976]
=============== Created Last 30 ================
2009-11-18 02:29:56 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-11-18 02:29:55 411368 ----a-w- c:\windows\system32\REN33.tmp
2009-11-17 15:55:55 0 d-----w- C:\ComboFix
2009-11-17 04:48:43 0 d-sha-r- C:\cmdcons
2009-11-17 04:41:50 98816 ----a-w- c:\windows\sed.exe
2009-11-17 04:41:50 77312 ----a-w- c:\windows\MBR.exe
2009-11-17 04:41:50 260608 ----a-w- c:\windows\PEV.exe
2009-11-17 04:41:50 161792 ----a-w- c:\windows\SWREG.exe
2009-11-16 15:30:12 0 d-----w- c:\windows\ie8updates
2009-11-16 02:57:26 54624 ----a-w- c:\windows\system32\51334.sys
2009-11-16 02:57:20 2335270 ----a-w- c:\windows\system32\aa633.mht
2009-11-15 17:16:38 0 d-sh--w- c:\documents and settings\cswitch\PrivacIE
2009-11-15 17:07:12 0 d-sh--w- c:\documents and settings\cswitch\IETldCache
2009-11-15 07:32:00 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-11-15 07:31:58 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-15 07:28:42 0 dc-h--w- c:\windows\ie8
2009-11-15 07:21:12 0 d-----w- c:\windows\system32\MpEngineStore
2009-11-12 18:56:35 0 d-----w- c:\windows\038A524F58DB438A83918F7F0CA14B9E.TMP
2009-11-09 22:55:27 372 ----a-w- c:\windows\system32\BIN_STRSBW.SPT
2009-11-09 04:13:56 0 d-----w- c:\program files\Trend Micro
2009-11-08 17:18:20 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2009-11-08 17:18:16 0 d-----w- c:\docume~1\cswitch\applic~1\Spyware Terminator
2009-11-08 17:18:07 0 d-----w- c:\program files\Spyware Terminator
2009-11-08 17:18:07 0 d-----w- c:\docume~1\alluse~1\applic~1\Spyware Terminator
2009-10-27 02:09:48 0 d-----w- c:\docume~1\alluse~1\applic~1\SSScanAppDataDir
2009-10-27 02:09:24 0 d-----w- c:\docume~1\alluse~1\applic~1\MSScanAppDataDir
==================== Find3M ====================
2009-11-15 17:37:47 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-22 09:19:04 5939712 ----a-w- c:\windows\system32\dllcache\mshtml.dll
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 21:03:36 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\dllcache\wininet.dll
2009-08-29 08:08:21 916480 ------w- c:\windows\system32\wininet.dll
2009-08-29 08:08:21 1208832 ----a-w- c:\windows\system32\dllcache\urlmon.dll
2009-08-29 08:08:20 206848 ----a-w- c:\windows\system32\dllcache\occache.dll
2009-08-29 08:08:18 594432 ----a-w- c:\windows\system32\dllcache\msfeeds.dll
2009-08-29 08:08:18 55296 ----a-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-08-29 08:08:18 25600 ----a-w- c:\windows\system32\dllcache\jsproxy.dll
2009-08-29 08:08:18 1985536 ----a-w- c:\windows\system32\dllcache\iertutil.dll
2009-08-29 08:08:17 184320 ----a-w- c:\windows\system32\dllcache\iepeers.dll
2009-08-29 08:08:16 11069440 ----a-w- c:\windows\system32\dllcache\ieframe.dll
2009-08-29 08:08:13 387584 ----a-w- c:\windows\system32\dllcache\iedkcs32.dll
2009-08-29 07:36:24 133120 ----a-w- c:\windows\system32\dllcache\extmgr.dll
2009-08-28 10:35:52 173056 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-08-28 10:28:59 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-08-28 01:21:33 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-26 08:00:21 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-04-01 00:07:56 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009033120090401\index.dat
============= FINISH: 21:13:29.81 ===============