I'm cleaning up my girlfriend's computer. She picked up a virus that totally disabled it. I could click her account name at the Windows splash screen, it would flash her desktop, then immediately log her off. Using the recovery console of the Windows XP CD I was able to repair some files and get some things working. I ran ran the DDS scanner and that log is below. The Attach.txt and RootRepeal log files are attached.
Here's the problem, or at least one of the problems. The computer has internet connectivity but many programs are broken. I can't run IE; when I try, it says "iexplore.exe Entry Point Not Found. The procedure entry point SetDllDirectoryW could not be located in the dynamic link library KERNEL32.dll." iTunes, AVG Antivirus, etc. don't work either. All these programs give variations of the error "(Program) requires Windows XP SP2 or later." I can't run Windows Update to upgrade to SP3 because IE doesn't work. I was able to install Firefox, which works fine.
Thanks in advance for your help.
DDS.txt
DDS (Ver_09-12-01.01) - NTFSx86
Run by jenn at 13:35:35.08 on Sun 01/03/2010
Internet Explorer: 6.0.2600.0000
============== Running Processes ===============
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uWindow Title = Windows Internet Explorer provided by Comcast
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [<NO NAME>]
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [ddoctorv2] "c:\program files\comcast\desktop doctor\bin\sprtcmd.exe" /P ddoctorv2
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SoundMan] SOUNDMAN.EXE
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\procexp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\utilit~1.lnk - c:\windows\system32\sistray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193007011129
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - hxxp://www.live365.com/players/play365.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {FCBABDA2-801E-4F51-B6E8-0122032FB16B} - No File
LSA: Authentication Packages = msv1_0 c:\windows\system32\byXQIBSJ
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jenn\applic~1\mozilla\firefox\profiles\olrczaf5.default\
FF - plugin: c:\documents and settings\jenn\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\download manager\npfpdlm.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-12-24 01:24:34 0 d-----w- c:\docume~1\jenn\applic~1\Malwarebytes
2009-12-24 01:24:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-24 01:24:28 18520 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 01:24:28 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-24 01:24:28 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-23 05:34:58 79872 -c--a-w- c:\windows\system32\dllcache\rwia330.dll
2009-12-23 05:33:56 10129408 -c--a-w- c:\windows\system32\dllcache\hwxkor.dll
2009-12-23 05:32:59 94208 -c--a-w- c:\windows\system32\dllcache\fpcount.exe
2009-12-23 05:26:01 488 ---ha-r- c:\windows\system32\logonui.exe.manifest
2009-12-23 05:24:59 57344 -c--a-w- c:\windows\system32\dllcache\msadcf.dll
2009-12-23 05:24:59 53248 -c--a-w- c:\windows\system32\dllcache\msadcs.dll
2009-12-23 05:24:59 20480 -c--a-w- c:\windows\system32\dllcache\msadcer.dll
2009-12-23 05:24:59 16384 -c--a-w- c:\windows\system32\dllcache\msadcor.dll
2009-12-23 05:24:59 16384 -c--a-w- c:\windows\system32\dllcache\msadcfr.dll
2009-12-23 05:24:59 147456 -c--a-w- c:\windows\system32\dllcache\msadds.dll
2009-12-23 05:24:59 131072 -c--a-w- c:\windows\system32\dllcache\msadco.dll
2009-12-23 05:21:25 50048 ----a-w- c:\windows\system32\drivers\DMusic.sys
2009-12-23 05:21:21 5632 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-12-23 05:20:26 55808 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-12-23 05:19:49 23070 ----a-w- c:\windows\system32\drivers\RTL8139.sys
2009-12-23 05:19:27 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-12-23 05:19:27 117248 ----a-w- c:\windows\system32\ksproxy.ax
2009-12-23 05:19:04 37896 ----a-w- c:\windows\system32\drivers\termdd.sys
2009-12-23 05:19:02 181632 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2009-12-18 07:43:26 0 d-----w- c:\program files\iPod
2009-12-18 07:43:22 0 d-----w- c:\program files\iTunes
2009-12-18 07:43:22 0 d-----w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-09 05:11:45 0 d-----w- c:\documents and settings\jenn\Tracing
2009-12-09 05:08:31 0 d-----w- c:\program files\Microsoft Office Outlook Connector
2009-12-09 05:07:49 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-12-09 05:06:20 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-12-09 05:06:15 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-09 05:04:31 0 d-----w- c:\program files\Microsoft
2009-12-09 05:04:16 0 d-----w- c:\program files\Windows Live SkyDrive
2009-12-09 04:55:17 0 d-----w- c:\program files\common files\Windows Live
==================== Find3M ====================
2009-12-23 05:24:17 23348 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-29 07:46:52 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
============= FINISH: 13:36:07.42 ===============