Another DDS log is attached.
Here is the other:
DDS (Ver_09-07-30.01) - NTFSx86
Run by Family at 19:13:31.12 on Thu 08/20/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.343 [GMT -5:00]
AV: Trend Micro PC-cillin Internet Security 2007 *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro PC-cillin Internet Security (Firewall) *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ATT-SST\McciTrayApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Siber Systems\GoodSync\GoodSync.exe
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Family\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [GoodSync] "c:\program files\siber systems\goodsync\GoodSync.exe" /min
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 2007\pccguide.exe"
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [ATT-SST_McciTrayApp] "c:\program files\att-sst\McciTrayApp.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
StartupFolder: c:\docume~1\family\startm~1\programs\startup\greeti~1.lnk - c:\program files\greetings workshop\GWREMIND.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: 0.0.0.0
Trusted Zone: motive.com\pattta.att
Trusted Zone: motive.com\patttbc.att
DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135} - hxxp://download.microsoft.com/download/3/B/E/3BE57995-8452-41F1-8297-DD75EF049853/VirtualEarth3D.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1220110606171
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\family\applic~1\mozilla\firefox\profiles\t2ils920.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bleedcubbieblue.com/
FF - prefs.js: keyword.URL - hxxp://ws.infospace.com/coolchaser/ws/redir?_iceUrl=true&user_id=17650705&tool_id=61057&qkw=
FF - component: c:\documents and settings\family\application data\mozilla\firefox\profiles\t2ils920.default\extensions\{a2880346-35bb-45bb-9190-eedb49c132c5}\components\Engine.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\family\application data\mozilla\firefox\profiles\t2ils920.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\trendm~1\intern~1\Tmntsrv.exe [2006-12-29 480784]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2006-12-29 943696]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-8-30 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\trendm~1\intern~1\tmproxy.exe [2006-12-29 566872]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-8-30 288848]
S2 kvqnv;kvqnv;c:\windows\system32\drivers\yakf.sys --> c:\windows\system32\drivers\yakf.sys [?]
S3 dump_wmimmc;dump_wmimmc;\??\c:\gamescampus\mlbdugoutheroes\gameguard\dump_wmimmc.sys --> c:\gamescampus\mlbdugoutheroes\gameguard\dump_wmimmc.sys [?]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-12-14 33752]
S3 naecd;naecd;\??\c:\docume~1\family\locals~1\temp\naecd.sys --> c:\docume~1\family\locals~1\temp\naecd.sys [?]
=============== Created Last 30 ================
2009-08-19 18:08 578,560 ac------ c:\windows\system32\dllcache\user32.dll
2009-08-19 18:02
2009-08-19 17:58
2009-08-19 17:19 0 a------- C:\backup.reg
2009-08-19 03:01 221,184 a------- c:\windows\system32\wmpns.dll
2009-08-18 20:55 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
2009-08-18 20:55 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-08-18 19:20
2009-08-18 10:56 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-18 10:56 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-18 10:56
2009-08-18 10:56
2009-08-14 21:01
2009-08-11 19:42 2,297,552 a------- c:\windows\system32\d3dx9_26.dll
2009-08-11 13:21
2009-08-10 13:15
2009-08-10 11:58
2009-08-09 15:11
2009-08-08 21:38
2009-08-06 13:13 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat
2009-08-06 03:10
2009-08-06 03:08 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 03:08 117,760 -------- c:\windows\system32\prntvpt.dll
2009-08-06 03:08 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 03:08 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 03:08 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-08-06 03:08 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 03:08 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-08-06 03:08
2009-08-05 04:01 204,800 -c------ c:\windows\system32\dllcache\mswebdvd.dll
2009-08-01 12:21
2009-08-01 12:20 306,688 a------- c:\windows\IsUninst.exe
2009-08-01 12:20 911 a------- c:\windows\STA2.ini
2009-07-27 08:28 73,728 a------- c:\windows\system32\javacpl.cpl
2009-07-27 08:15 410,984 a------- c:\windows\system32\deploytk.dll
==================== Find3M ====================
2009-08-05 04:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 14:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-12 12:21 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-07-05 03:01 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-05 03:01 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-06-26 11:50 666,624 a------- c:\windows\system32\wininet.dll
2009-06-26 11:50 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-25 03:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 03:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 03:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 03:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 03:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 03:25 54,272 a------- c:\windows\system32\wdigest.dll
2009-06-24 06:18 92,928 a------- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 09:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 09:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-12 07:31 80,896 a------- c:\windows\system32\tlntsess.exe
2009-06-12 07:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 09:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 01:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-03 14:09 1,291,264 a------- c:\windows\system32\quartz.dll
============= FINISH: 19:13:52.76 ===============
Also, here is my RootRepeal log:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/20 15:19
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAAC6F000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7B40000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA98D0000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: Volume C:\
Status: MBR Rootkit Detected!
Path: Volume C:\, Sector 1
Status: Sector mismatch
Path: Volume C:\, Sector 2
Status: Sector mismatch
Path: Volume C:\, Sector 3
Status: Sector mismatch
Path: Volume C:\, Sector 4
Status: Sector mismatch
Path: Volume C:\, Sector 5
Status: Sector mismatch
Path: Volume C:\, Sector 6
Status: Sector mismatch
Path: Volume C:\, Sector 7
Status: Sector mismatch
Path: Volume C:\, Sector 8
Status: Sector mismatch
Path: Volume C:\, Sector 9
Status: Sector mismatch
Path: Volume C:\, Sector 10
Status: Sector mismatch
Path: Volume C:\, Sector 11
Status: Sector mismatch
Path: Volume C:\, Sector 12
Status: Sector mismatch
Path: Volume C:\, Sector 13
Status: Sector mismatch
Path: Volume C:\, Sector 14
Status: Sector mismatch
Path: Volume C:\, Sector 15
Status: Sector mismatch
Path: Volume C:\, Sector 16
Status: Sector mismatch
Path: Volume C:\, Sector 17
Status: Sector mismatch
Path: Volume C:\, Sector 18
Status: Sector mismatch
Path: Volume C:\, Sector 19
Status: Sector mismatch
Path: Volume C:\, Sector 20
Status: Sector mismatch
Path: Volume C:\, Sector 21
Status: Sector mismatch
Path: Volume C:\, Sector 22
Status: Sector mismatch
Path: Volume C:\, Sector 23
Status: Sector mismatch
Path: Volume C:\, Sector 24
Status: Sector mismatch
Path: Volume C:\, Sector 25
Status: Sector mismatch
Path: Volume C:\, Sector 26
Status: Sector mismatch
Path: Volume C:\, Sector 27
Status: Sector mismatch
Path: Volume C:\, Sector 28
Status: Sector mismatch
Path: Volume C:\, Sector 29
Status: Sector mismatch
Path: Volume C:\, Sector 30
Status: Sector mismatch
Path: Volume C:\, Sector 31
Status: Sector mismatch
Path: Volume C:\, Sector 32
Status: Sector mismatch
Path: Volume C:\, Sector 33
Status: Sector mismatch
Path: Volume C:\, Sector 34
Status: Sector mismatch
Path: Volume C:\, Sector 35
Status: Sector mismatch
Path: Volume C:\, Sector 36
Status: Sector mismatch
Path: Volume C:\, Sector 37
Status: Sector mismatch
Path: Volume C:\, Sector 38
Status: Sector mismatch
Path: Volume C:\, Sector 39
Status: Sector mismatch
Path: Volume C:\, Sector 40
Status: Sector mismatch
Path: Volume C:\, Sector 41
Status: Sector mismatch
Path: Volume C:\, Sector 42
Status: Sector mismatch
Path: Volume C:\, Sector 43
Status: Sector mismatch
Path: Volume C:\, Sector 44
Status: Sector mismatch
Path: Volume C:\, Sector 45
Status: Sector mismatch
Path: Volume C:\, Sector 46
Status: Sector mismatch
Path: Volume C:\, Sector 47
Status: Sector mismatch
Path: Volume C:\, Sector 48
Status: Sector mismatch
Path: Volume C:\, Sector 49
Status: Sector mismatch
Path: Volume C:\, Sector 50
Status: Sector mismatch
Path: Volume C:\, Sector 51
Status: Sector mismatch
Path: Volume C:\, Sector 52
Status: Sector mismatch
Path: Volume C:\, Sector 53
Status: Sector mismatch
Path: Volume C:\, Sector 54
Status: Sector mismatch
Path: Volume C:\, Sector 55
Status: Sector mismatch
Path: Volume C:\, Sector 56
Status: Sector mismatch
Path: Volume C:\, Sector 57
Status: Sector mismatch
Path: Volume C:\, Sector 58
Status: Sector mismatch
Path: Volume C:\, Sector 59
Status: Sector mismatch
Path: Volume C:\, Sector 60
Status: Sector mismatch
Path: Volume C:\, Sector 61
Status: Sector mismatch
Path: Volume C:\, Sector 62
Status: Sector mismatch
Path: C:\WINDOWS\system32\ESQULnntuikalqpmupxdlechwiwqtoqyxomac.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\ESQULtwbcmkagwkkyubgrsnkndovkretuvesm.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\ESQULzxspectrum
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\drivers\ESQULwswtxjiflkharusxwpnbidprqpslhrrv.sys
Status: Invisible to the Windows API!
Stealth Objects
-------------------
Object: Hidden Module [Name: ESQULtwbcmkagwkkyubgrsnkndovkretuvesm.dll]
Process: svchost.exe (PID: 1224) Address: 0x10000000 Size: 32768
Hidden Services
-------------------
Service Name: ESQULserv.sys
Image Path: C:\WINDOWS\system32\drivers\ESQULwswtxjiflkharusxwpnbidprqpslhrrv.sys
==EOF==
Attached Files
Edited by Orange Blossom, 21 August 2009 - 12:26 AM.