DDS.txt, Attach.txt, and HiJackThis_logfile.txt attached.
---------------
Update: I just ran TFC and now after rebooting, computer freezes after a minute (presumably, a startup service lost one of it's file in the TFC cleanup). Also, safe mode is still unavailable as mentioned before -- it stops here:
STOP: 0x0000007E (Oxc0000005, 0x8673cc21, 0x8673cc21, 0xF7c45c44, 0xF7c45940)
---------------
DDS (Ver_09-11-29.01) - NTFSx86
Run by David Norris at 14:36:06.51 on Sun 11/29/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.632 [GMT -8:00]
AV: System Defender *On-access scanning enabled* (Updated) {202B08C2-1131-4F93-B4DF-3184684295C0}
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: System Defender *enabled* {27F57D55-D1E9-405E-A0DB-4A0001FF50DF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Documents and Settings\David Norris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David Norris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David Norris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\David Norris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David Norris\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223262157000
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
AppInit_DLLs: c:\windows\system32\miposaho.dll c:\windows\system32\pabewisa.dll worusego.dll c:\windows\system32\hibunevo.dll hutijezu.dll
SSODL: bavujolot - {e1c0920d-ba72-49e0-a4d2-de3495c817ea} - No File
SSODL: zadosuhih - {e78c16bc-327d-44b7-8ffe-47c796e504fd} - No File
SSODL: tetotezol - {0390ad1a-268f-4970-91a0-9b5c6402edc5} - No File
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: neluparut - {f6c3c148-ea4d-4cad-a8f7-b899384250e5} - No File
STS: {e1c0920d-ba72-49e0-a4d2-de3495c817ea} - No File
STS: {e78c16bc-327d-44b7-8ffe-47c796e504fd} - No File
STS: {0390ad1a-268f-4970-91a0-9b5c6402edc5} - No File
STS: {f6c3c148-ea4d-4cad-a8f7-b899384250e5} - No File
LSA: Notification Packages = scecli zukuyepu.dll yiyobuye.dll
IFEO: image file execution options - svchost.exe
IFEO: brastk.exe - svchost.exe
Hosts: 74.125.45.100 4-open-davinci.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 getantivirusplusnow.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-11-16 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-11-16 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-11-16 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-11-16 55656]
S2 cexpvfrcermqas;cexpvfrcermqas;\??\c:\windows\system32\drivers\yyfjbzywzljfir.sys --> c:\windows\system32\drivers\yyfjbzywzljfir.sys [?]
=============== Created Last 30 ================
2009-11-29 19:49:46 0 d-----w- c:\program files\Trend Micro
2009-11-29 19:47:03 161296 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-29 19:47:03 0 d-----w- c:\documents and settings\david norris\log
2009-11-28 06:30:30 0 d-sh--w- c:\documents and settings\david norris\PrivacIE
2009-11-28 06:25:21 0 d-sh--w- c:\documents and settings\david norris\IETldCache
2009-11-28 06:21:36 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-11-28 06:21:14 0 d-----w- c:\windows\ie8updates
2009-11-28 06:20:59 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-28 06:20:59 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-11-28 06:18:48 0 dc-h--w- c:\windows\ie8
2009-11-28 04:24:43 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-28 04:24:40 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-28 04:24:40 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-22 03:13:40 0 d-----w- c:\program files\Windows Media Connect 2
2009-11-22 03:11:50 0 d-----w- c:\windows\system32\LogFiles
2009-11-21 01:29:05 1962544 ----a-w- c:\windows\system32\install_flash_player_ax.exe
2009-11-21 01:14:49 1962544 ----a-w- c:\windows\install_flash_player_ax.exe
2009-11-21 01:10:23 1962544 ----a-w- c:\program files\install_flash_player_ax.exe
2009-11-17 00:53:37 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-17 00:53:34 0 d-----w- c:\program files\Avira
2009-11-17 00:53:34 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2009-11-17 00:43:45 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-11-16 15:02:01 0 d-sh--w- c:\docume~1\alluse~1\applic~1\3282c
2009-11-16 14:26:24 0 d-sh--w- c:\documents and settings\all users\76cb400
2009-11-16 04:51:32 0 d-----w- c:\docume~1\davidn~1\applic~1\Malwarebytes
2009-11-16 04:51:11 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-11-16 04:51:10 0 d-----w- c:\program files\M-ware_bytes
2009-11-16 04:28:57 0 d-----w- c:\program files\CCleaner
2009-11-16 04:11:23 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-11-16 04:11:23 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-11-16 04:08:57 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-11-16 04:08:57 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-11-13 03:48:06 148 ----a-w- c:\documents and settings\david norris\Video .lnk
2009-11-13 03:48:06 148 ----a-w- c:\documents and settings\david norris\Pictures .lnk
2009-11-13 03:48:06 148 ----a-w- c:\documents and settings\david norris\Passwords .lnk
2009-11-13 03:48:06 148 ----a-w- c:\documents and settings\david norris\New Folder .lnk
2009-11-13 03:48:06 148 ----a-w- c:\documents and settings\david norris\Music .lnk
2009-11-13 03:48:06 148 ----a-w- c:\documents and settings\david norris\Documents .lnk
2009-11-13 03:47:54 124 --sh--r- c:\documents and settings\david norris\autorun.inf
2009-11-12 06:55:16 468 ----a-w- c:\windows\system32\5834009.exe
2009-11-12 06:19:50 221 ----a-w- c:\documents and settings\david norris\SrdoBO.bat
==================== Find3M ====================
2009-11-12 07:51:14 31396352 ----a-w- c:\program files\eav_nt32_enu.msi
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-08 22:56:28 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-04-28 01:43:50 43083040 ----a-w- c:\program files\AdbeRdr910_en_US_Std.exe
2009-04-25 07:08:41 1047072 ----a-w- c:\program files\MoveMediaPlayer_071303000006.exe
2009-04-24 04:20:26 74302760 ----a-w- c:\program files\iTunesSetup.exe
============= FINISH: 14:37:47.93 ===============
Attached Files
Edited by guglyman, 29 November 2009 - 07:45 PM.