Thank you for the reply...
=====================================
=====================================
DDS
=====================================
=====================================
DDS (Ver_09-12-01.01) - NTFSx86
Run by Compaq_Owner at 8:06:11.51 on Mon 12/21/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.446.141 [GMT -8:00]
AV: Norton Internet Security 2006 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security 2006 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
svchost.exe C:\WINDOWS\TEMP\VRT2.tmp
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\svchust.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\wmdtc.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\FastNetSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\lsm32.sys
C:\Documents and Settings\Compaq_Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: CNavExtBho Class: {a8f38d8d-e480-4d52-b7a2-731bb6995fdd} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Norton AntiVirus: {c4069e3a-68f1-403e-b40e-20066696354b} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mRun: [notepad] rundll32.exe c:\windows\system32\notepad.dll,_IWMPEvents@0
mRun: [jiqmkjgm] c:\windows\system32\config\systemprofile\local settings\application data\djvvfk\xkufsysguard.exe
mRun: [wmpaonpf] c:\windows\system32\config\systemprofile\local settings\application data\didfqd\xvrnsysguard.exe
dRun: [notepad] rundll32.exe c:\docume~1\networ~1\ntload.dll,_IWMPEvents@0
dRun: [jiqmkjgm] c:\windows\system32\config\systemprofile\local settings\application data\djvvfk\xkufsysguard.exe
dRun: [wmpaonpf] c:\windows\system32\config\systemprofile\local settings\application data\didfqd\xvrnsysguard.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_05\bin\npjpi150_05.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {24E794CE-267F-4083-B81B-19BDE10D0D5B} = 192.168.1.1,192.168.1.2
============= SERVICES / DRIVERS ===============
R2 BtwSrv;BtwSrv;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-9-16 192112]
R2 ccProxy;Symantec Network Proxy;c:\program files\common files\symantec shared\ccProxy.exe [2005-9-16 202352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-9-16 169584]
R2 fastnetsrv;fastnetsrv Service;c:\windows\system32\FastNetSrv.exe [2004-8-4 60928]
R2 Ias;Windows Device Access;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
R2 Iprip;Network Security;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
R2 navapsvc;Norton AntiVirus Auto-Protect Service;c:\program files\norton internet security\norton antivirus\navapsvc.exe [2005-10-6 133744]
R2 Net_Login;Net_Login;c:\windows\svchust.exe [2009-12-13 766465]
R2 NetLogin;Net Login;c:\windows\svchost.exe [2009-12-8 1169408]
R2 SAVRTPEL;SAVRTPEL;c:\program files\norton internet security\norton antivirus\Savrtpel.sys [2005-8-26 53896]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20060104.006\NAVENG.Sys [2006-2-22 77864]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20060104.006\NavEx15.Sys [2006-2-22 750952]
R3 SAVRT;SAVRT;c:\program files\norton internet security\norton antivirus\savrt.sys [2005-8-26 334984]
S3 SAVScan;Symantec AVScan;c:\program files\norton internet security\norton antivirus\SAVScan.exe [2005-8-26 198368]
S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-2-22 1119888]
S3 winsts;winsts;c:\windows\system32\winsts.sys [2004-8-4 2304]
=============== Created Last 30 ================
2009-12-28 06:55:49 7525 ----a-w- c:\windows\4d69steal1z549.ocx
2009-12-25 01:19:11 12737 ----a-w- c:\windows\5536sp9rse8z.dll
2009-12-24 07:58:36 6489 ----a-w- c:\windows\56792vi9uz736.dll
2009-12-23 11:25:54 9961 ----a-w- c:\windows\17z95viru559b.bin
2009-12-22 19:42:26 14992 ----a-w- c:\windows\599dbaczdoor2353.dll
2009-12-21 00:50:01 88576 ----a-w- c:\windows\system32\5.tmp
2009-12-21 00:50:00 88 ----a-w- c:\windows\system32\4.tmp
2009-12-20 01:40:44 88576 ----a-w- c:\windows\system32\24.tmp
2009-12-20 01:40:40 88 ----a-w- c:\windows\system32\23.tmp
2009-12-19 15:25:53 12555 ----a-w- c:\windows\z9253hack9ool655.cpl
2009-12-19 08:18:06 88576 ----a-w- c:\windows\system32\3.tmp
2009-12-19 08:18:05 88 ----a-w- c:\windows\system32\2.tmp
2009-12-19 07:00:19 0 d-sh--r- C:\cmdcons
2009-12-18 23:18:20 13305 ----a-w- c:\windows\759ds9zal869.cpl
2009-12-17 02:53:59 6169 ----a-w- c:\windows\4z27vi59543.ocx
2009-12-16 20:48:25 16177 ----a-w- c:\windows\7201spy5arz689.ocx
2009-12-14 07:00:43 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-12-14 07:00:32 1855 --sha-r- c:\windows\system32\drivers\103C_HP_CPC_ER919AA-ABA SR1820NX NA620_YC_0Pres_QCNH610_E62NAheREA2_48_INAGAMI_SASUSTek Computer INC._V1.01_B3.01_T060209_WXH2_L409_M447_J160_7AMD_8Athlon 64_92.2_#080117_N_Z11C10620_G10DE0241_O_DHWP2647.MRK
2009-12-14 06:58:53 0 d-----w- c:\docume~1\compaq~1\applic~1\Symantec
2009-12-14 06:58:53 0 d-----w- c:\docume~1\compaq~1\applic~1\Intuit
2009-12-14 06:50:57 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-12-14 06:50:40 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-12-14 05:29:31 102401 ----a-w- c:\windows\sv2.exe
2009-12-14 05:02:10 0 d-sh--r- c:\windows\system32\dllcache
2009-12-14 00:03:28 766465 ----a-w- c:\windows\svchust.exe
2009-12-14 00:00:11 0 d-sh--w- C:\found.000
2009-12-13 04:26:39 0 d-----w- c:\program files\InternetSecurity2010
2009-12-13 03:29:27 46 ----a-w- C:\p2hhr.bat
2009-12-13 03:22:44 168 ----a-w- C:\fyjrshntjm108.bat
2009-12-13 02:55:29 0 d-----w- c:\program files\SopCast
2009-12-13 02:55:15 0 d-----w- c:\program files\Ask.com
2009-12-12 03:54:28 100958 ----a-w- C:\dror.exe
2009-12-12 03:54:26 76515 ----a-w- C:\pdvwd.exe
2009-12-12 03:54:26 180224 ----a-w- C:\nymeu.exe
2009-12-12 03:54:25 44032 ----a-w- C:\tdndhuv.exe
2009-12-12 03:54:13 337920 ----a-w- C:\CYQS.exe
2009-12-11 03:41:55 301056 ----a-w- C:\ccu.exe
2009-12-11 02:30:41 287744 ----a-w- C:\ycvz.exe
2009-12-10 11:37:20 287744 ----a-w- C:\pfL.exe
2009-12-09 19:51:18 18207 ----a-w- c:\windows\1ddabackdoo519z.bin
2009-12-09 03:59:38 112520 ----a-w- C:\ryiasu.exe
2009-12-09 03:59:37 74752 ----a-w- C:\eauxx.exe
2009-12-09 01:03:28 0 d-----w- C:\800cc9a67a25cb3093
2009-12-08 15:25:43 56 ----a-w- c:\windows\Micorsoft.bat
2009-12-08 12:09:10 1239 ----a-w- C:\shellfix.zip
2009-12-08 11:35:28 1169408 ----a-w- c:\windows\svchost.exe
2009-12-08 11:35:08 441857 ----a-w- c:\windows\isvchost.exe
2009-12-08 10:32:59 280576 ----a-w- c:\windows\PEV.exe
2009-12-08 10:32:59 182272 ----a-w- c:\windows\SWREG.exe
2009-12-08 10:32:59 118784 ----a-w- c:\windows\sed.exe
2009-12-08 10:32:59 100864 ----a-w- c:\windows\MBR.exe
2009-12-08 10:32:55 0 d-----w- C:\ComboFix
2009-12-08 02:33:34 382 ----a-w- c:\windows\explorer.RPT
2009-12-07 03:55:49 0 d-----w- c:\program files\MSSOAP
2009-12-07 03:55:07 1563008 ----a-w- c:\windows\WRSetup.dll
2009-12-07 03:55:06 0 d-----w- c:\program files\Webroot
2009-12-07 03:55:06 0 d-----w- c:\docume~1\compaq~1\applic~1\Webroot
2009-12-07 03:55:06 0 d-----w- c:\docume~1\alluse~1\applic~1\Webroot
2009-12-07 03:52:38 164 ----a-w- c:\windows\install.dat
2009-12-07 03:42:31 0 d-----w- c:\program files\a-squared Anti-Malware
2009-12-07 03:21:55 0 d-----w- c:\program files\a-squared Free
2009-12-04 19:42:48 0 d-----w- c:\program files\Input Director
2009-12-04 15:25:31 0 d-----w- C:\$AVG
2009-12-04 15:23:43 0 d-----w- c:\program files\AVG
2009-12-04 15:23:40 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2009-12-04 14:58:24 622 ----a-w- c:\windows\RegGenie.ini
2009-12-04 14:32:10 161816 ----a-w- c:\windows\RegGenieOnUninstall.exe
2009-12-04 14:30:45 0 d-----w- c:\docume~1\alluse~1\applic~1\ParetoLogic
2009-12-04 14:30:44 0 d-----w- c:\program files\common files\ParetoLogic
2009-12-04 14:30:43 0 d-----w- c:\program files\common files\XoftSpySE
2009-12-04 14:30:41 0 d-----w- c:\docume~1\alluse~1\applic~1\XoftSpySE
2009-12-03 07:05:29 7813 ----a-w- c:\windows\61c6thiz917355.cpl
2009-12-03 03:32:12 11819 ----a-w- c:\windows\6796backd5or68z.cpl
2009-11-28 05:11:36 14369 ----a-w- c:\windows\2c74d5wnloader19z1.ocx
2009-11-25 23:06:55 3216 ----a-w- c:\windows\951zdownloade5703.bin
2009-11-24 14:53:38 3939 ----a-w- c:\windows\5f9dvzr1859.cpl
2009-11-23 16:50:43 11198 ----a-w- c:\windows\16555virus995z.dll
==================== Find3M ====================
2009-11-12 12:33:17 15370 ----a-w- c:\windows\z5692w5rm79c.exe
2009-11-07 18:05:14 34816 ----a-r- c:\windows\Setup_ck.exe
2009-11-07 18:04:43 18944 ----a-w- c:\windows\Ckrfresh.exe
2009-11-07 18:04:43 173056 ----a-w- c:\windows\Ckconfig.exe
2009-11-07 03:32:02 32768 ----a-w- C:\yeoumtkh.exe
2009-11-07 03:32:01 66048 ----a-w- C:\sadcadwm.exe
2009-11-07 03:32:00 90624 ----a-w- C:\sacbnjm.exe
2009-11-07 03:31:57 66048 ----a-w- C:\fabbw.exe
2009-11-07 03:31:55 296448 ----a-w- C:\gvU9.exe
2009-11-07 03:31:49 97792 ----a-w- C:\juvau.exe
2009-11-07 03:31:49 39936 ----a-w- C:\jjxaejk.exe
2009-11-05 21:56:06 75264 ----a-w- C:\ktpubj.exe
2009-11-05 21:52:01 75264 ----a-w- C:\ltafa.exe
2009-11-04 21:22:08 6059 ----a-w- c:\windows\1645vir9z3.bin
2009-10-29 03:45:54 262144 ----a-w- C:\rfkykhaf.exe
2009-10-27 08:57:56 135367 ----a-w- c:\windows\zAdBHO.dll
2009-10-23 08:57:46 9538 ----a-w- c:\windows\35a1s9yw5ze1359.exe
2009-10-22 04:47:51 18074 ----a-w- c:\windows\7740addw9re1z55.dll
2009-10-15 08:34:11 13068 ----a-w- c:\windows\3afbbackdooz2599.dll
2009-10-10 23:43:34 11259 ----a-w- c:\windows\3205azd5are1969.bin
2009-10-08 15:31:46 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-10-08 15:31:44 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-10-08 15:31:44 1636304 ----a-w- c:\windows\PCTBDCore.dll
2009-10-08 15:31:14 767952 ----a-w- c:\windows\BDTSupport.dll
2009-10-06 06:57:15 15725 ----a-w- c:\windows\24180not-a-viruz59e.exe
2009-10-04 03:59:08 15316 ----a-w- c:\windows\6915spyz1f.bin
2009-10-02 18:19:04 1152470 ----a-w- c:\windows\UDB.zip
2009-10-01 04:30:48 9547 ----a-w- c:\windows\9409worz5b9.bin
2009-09-23 03:21:36 90112 ----a-w- c:\windows\DUMP4362.tmp
2009-09-23 02:53:18 90112 ----a-w- c:\windows\DUMP4527.tmp
2009-09-23 02:49:11 90112 ----a-w- c:\windows\DUMP494d.tmp
2009-09-23 02:47:49 90112 ----a-w- c:\windows\DUMP4517.tmp
2009-09-23 02:41:03 90112 ----a-w- c:\windows\DUMP49e9.tmp
2009-09-23 02:39:41 90112 ----a-w- c:\windows\DUMP4e00.tmp
2009-09-23 01:51:47 90112 ----a-w- c:\windows\DUMP5062.tmp
2009-09-23 01:29:09 90112 ----a-w- c:\windows\DUMP442d.tmp
2009-09-23 01:03:04 90112 ----a-w- c:\windows\DUMP4778.tmp
2009-09-23 00:55:46 90112 ----a-w- c:\windows\DUMP4f69.tmp
2009-09-23 00:53:31 90112 ----a-w- c:\windows\DUMP4f68.tmp
2009-09-23 00:49:39 90112 ----a-w- c:\windows\DUMP4853.tmp
2009-09-23 00:48:17 90112 ----a-w- c:\windows\DUMP49f9.tmp
2009-09-23 00:44:35 90112 ----a-w- c:\windows\DUMP44c9.tmp
2009-09-23 00:31:55 90112 ----a-w- c:\windows\DUMP4342.tmp
2004-08-04 11:00:00 29696 --sha-w- c:\windows\system32\notepad.dll
2004-08-04 11:00:00 29696 --sha-w- c:\windows\system32\config\systemprofile\ntload.dll
2004-08-04 11:00:00 29696 --sha-w- c:\windows\system32\config\systemprofile\start menu\programs\startup\scandisk.dll
============= FINISH: 8:07:32.25 ===============
=====================================
=====================================
Attach
=====================================
=====================================
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 12/13/2009 10:58:28 PM
System Uptime: 12/20/2009 3:32:12 AM (29 hours ago)
Motherboard: ASUSTek Computer INC. | | NAGAMI
Processor: AMD Athlon 64 Processor 3400+ | Socket 939 | 2204/199mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 142 GiB total, 2.71 GiB free.
D: is FIXED (FAT32) - 7 GiB total, 0.339 GiB free.
E: is Removable
F: is Removable
G: is Removable
H: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 12/13/2009 11:50:05 PM - System Checkpoint
RP2: 12/19/2009 5:58:53 PM - System Checkpoint
RP3: 12/20/2009 6:52:24 PM - System Checkpoint
==== Installed Programs ======================
5 Card Slingo from Compaq (remove only)
Adobe Reader 7.0
Agere Systems PCI-SV92PP Soft Modem
AstroPop Deluxe from Compaq (remove only)
Barnyard Invasion from Compaq (remove only)
Bejeweled 2 Deluxe from Compaq (remove only)
Blackhawk Striker 2 from Compaq (remove only)
Blasterball 2 from Compaq (remove only)
Blasterball 2 Remix from Compaq (remove only)
Boggle Supreme from Compaq (remove only)
Bookworm Deluxe from Compaq (remove only)
Bounce Symphony from Compaq (remove only)
BufferChm
CC_ccProxyExt
ccCommon
ccPxyCore
Chuzzle Deluxe from Compaq (remove only)
Compaq Connections (remove only)
Compaq Organize
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
Crystal Maze from Compaq (remove only)
CueTour
Customer Experience Enhancement
Destinations
DeviceManagementQFolder
Easy Internet Sign-up
Family Feud
FATE from Compaq (remove only)
FullDPAppQFolder
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB888111
Hotfix for Windows XP (KB893357)
Hotfix for Windows XP (KB906569)
HP Boot Optimizer
HP DVD Play 1.0
HP Game Console and games
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Rhapsody
HP Software Update
HP Support Overview
HP Web Helper
HpSdpAppCoreApp
Insaniquarium Deluxe from Compaq (remove only)
InstantShareDevices
J2SE Runtime Environment 5.0 Update 5
Lemonade Tycoon 2 from Compaq (remove only)
Lexibox Deluxe from Compaq (remove only)
LightScribe 1.4.62.1
LiveUpdate 2.7 (Symantec Corporation)
Mah Jong Quest from Compaq (remove only)
Microsoft .NET Framework 1.1
Microsoft Money 2006
Microsoft Office 2003 Edition 60 Days Trial Welcome Tour
Microsoft Office Standard Edition 2003
Microsoft Works
MSRedist
Netscape Browser (remove only)
Norton AntiSpam
Norton AntiVirus 2006
Norton Internet Security
Norton Internet Security 2006 (Symantec Corporation)
Norton Protection Center
Norton WMI Update
NVIDIA Drivers
OptionalContentQFolder
PC-Doctor 5 for Windows
PhotoGallery
Polar Bowler from Compaq (remove only)
Polar Golfer from Compaq (remove only)
Puzzle Express from Compaq (remove only)
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
Quicken 2006
RandMap
RealPlayer
Realtek High Definition Audio Driver
Remove WeatherBug Installer
Ricochet Lost Worlds from Compaq (remove only)
SCRABBLE from Compaq (remove only)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB912919)
Shooting Stars Pool from Compaq (remove only)
Shrek 2 Ogre Bowler from Compaq (remove only)
SkinsHP1
Slingo Deluxe from Compaq (remove only)
Snowboard SuperJam from Compaq (remove only)
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sonic_PrimoSDK
SPBBC
Super Granny from Compaq (remove only)
SymNet
Tradewinds from Compaq (remove only)
Unload
WebFldrs XP
WildTangent Web Driver
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892050
Windows XP Hotfix - KB893066
WinRAR archiver
Zuma Deluxe from Compaq (remove only)
==== Event Viewer Messages From Past Week ========
12/20/2009 5:22:54 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.CRT. Reference error message: The referenced assembly is not installed on your system. .
12/20/2009 5:22:54 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Documents and Settings\Compaq_Owner\Application Data\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll. Reference error message: The operation completed successfully. .
12/20/2009 5:22:54 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
12/18/2009 11:37:41 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
12/18/2009 11:37:15 PM, error: Service Control Manager [7034] - The Windows Audio service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:37:15 PM, error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:37:15 PM, error: Service Control Manager [7034] - The Fast User Switching Compatibility service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:37:15 PM, error: Service Control Manager [7034] - The Error Reporting Service service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:37:15 PM, error: Service Control Manager [7034] - The DHCP Client service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:37:15 PM, error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:37:15 PM, error: Service Control Manager [7034] - The COM+ Event System service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:37:15 PM, error: Service Control Manager [7031] - The Help and Support service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
12/18/2009 11:36:17 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:36:13 PM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:36:04 PM, error: Service Control Manager [7034] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:36:02 PM, error: Service Control Manager [7034] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:36:01 PM, error: Service Control Manager [7034] - The Symantec Network Proxy service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Workstation service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Wireless Zero Configuration service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Windows Time service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The System Restore Service service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The System Event Notification service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Secondary Logon service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Norton AntiVirus Auto-Protect Service service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Network Location Awareness (NLA) service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7034] - The Automatic Updates service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:26:30 PM, error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/18/2009 11:26:30 PM, error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/18/2009 11:26:30 PM, error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 6000 milliseconds: Restart the service.
12/18/2009 11:21:57 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Installer service to connect.
12/18/2009 11:21:57 PM, error: Service Control Manager [7000] - The Windows Installer service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/18/2009 11:20:06 PM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s).
12/18/2009 11:19:58 PM, error: Service Control Manager [7034] - The Symantec Network Drivers Service service terminated unexpectedly. It has done this 1 time(s).
==== End Of File ===========================
=====================================
=====================================
HijackThis
=====================================
=====================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:08:30 AM, on 12/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\svchust.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\wmdtc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\FastNetSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\lsm32.sys
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [notepad] rundll32.exe C:\WINDOWS\system32\notepad.dll,_IWMPEvents@0
O4 - HKLM\..\Run: [jiqmkjgm] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\djvvfk\xkufsysguard.exe
O4 - HKLM\..\Run: [wmpaonpf] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\didfqd\xvrnsysguard.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [notepad] rundll32.exe C:\DOCUME~1\NETWOR~1\ntload.dll,_IWMPEvents@0 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [jiqmkjgm] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\djvvfk\xkufsysguard.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [wmpaonpf] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\didfqd\xvrnsysguard.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [notepad] rundll32.exe C:\DOCUME~1\NETWOR~1\ntload.dll,_IWMPEvents@0 (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{24E794CE-267F-4083-B81B-19BDE10D0D5B}: NameServer = 192.168.1.1,192.168.1.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{24E794CE-267F-4083-B81B-19BDE10D0D5B}: NameServer = 192.168.1.1,192.168.1.2
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: fastnetsrv Service (fastnetsrv) - Netopsystems A - C:\WINDOWS\system32\FastNetSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Net Login (NetLogin) - Unknown owner - C:\WINDOWS\svchost.exe
O23 - Service: Net_Login - Unknown owner - C:\WINDOWS\svchust.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 9329 bytes
=====================================
=====================================
Symptoms
=====================================
=====================================
I've done a lot of different things within the 15 days of the original post. I have run a bunch of various anti-spyware/anti-malware/anti-virus services/programs. A lot of stuff was picked up and fixed. However, a lot of stuff is lingering and continues to come back. My major symptom seems to be jsut random errors popping up. On startup, I get the logouni.exe error (something along those lines). After continuously Xing and canceling out the error.. eventually the basic login window shows up. I click OK and windows starts up. Explorer.exe does not show up. I then ctl+alt+delete and I get an error for taskmngr.exe. I can only get to the task manager by doing ctl+alt+delete again while the error is still up. I then run explorer.exe from the task manager. Once in a while the same thing happens where I get an error for explorer.exe and I have to run the task again while the error is up to get the explorer to work. Along with those errors, I get a lot or random errors popping up at random times. It doesn't seem to happen as much anymore after running a bunch of tests, but they are still there. My firefox homepage seems to be stuck on "http://www.webweb123.com/". That seems to be about it for now. I will edit this post with other symptoms as they pop up or if I remeber a couple I left out..as well as exact error messages.
EDIT: Once in a while when I start up the machine, it boots up and gets to a certain point on startup and shuts down. I have probably restored windows around 10 times with the past month and a half.
Thanks for the help.