Ran defogger, dds in safe mode networking
Also running gmer and waiting for log.
DDS (Ver_10-03-17.01) - NTFSx86 NETWORK
Run by user1 at 13:20:08.20 on Mon 04/05/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3583.3221 [GMT -7:00]
AV: AVG Anti-Virus Network Edition *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:WINDOWSsystem32svchost -k DcomLaunch
svchost.exe
C:WINDOWSsystem32svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:WINDOWSExplorer.EXE
C:Documents and Settingsuser1PCDesktopddkremote.exe
C:Program FilesXLAB ISL Client LightISLClient.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:WINDOWSsystem32ctfmon.exe
C:downloadsMalwareDefogger.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:downloadsMalwaredds.scr
============== Pseudo HJT Report ===============
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=92&bd=all&pf=cmdt
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:program
filesavgavg8toolbarIEToolbar.dll
uURLSearchHooks: H - No File
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:program
filesavgavg8toolbarIEToolbar.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:program filesyahoo!companioninstallscpnyt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon
filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:program filesskypetoolbarsinternet
explorerSkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:program filesavgavg8avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:program filesspybot - search &
destroySDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:program filesjavajre1.6.0_07binssv.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:program filesavgavg8toolbarIEToolbar.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:program filesask.comGenericAskToolbar.dll
BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:program filesstopzilla!SZIEBHO.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:program filesavgavg8toolbarIEToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:program filesyahoo!companioninstallscpnyt.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:program filesask.comGenericAskToolbar.dll
{555d4d79-4bd2-4094-a395-cfc534424a05}
uRun: [Skype] "c:program filesskypephoneSkype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
uRun: [SpybotSD TeaTimer] c:program filesspybot - search & destroyTeaTimer.exe
uRun: [DWQueuedReporting] "c:progra~1common~1micros~1dwdwtrig20.exe" -t
mRun: [SetRefresh] c:program filescompaqsetrefreshSetRefresh.exe
mRun: [Scheduler] c:windowssminstScheduler.exe
mRun: [RoxWatchTray] "c:program filescommon filesroxio shared9.0sharedcomRoxWatchTray9.exe"
mRun: [Reminder] c:windowscreatorRemind_XP.exe
mRun: [Recguard] c:windowssminstRecguard.exe
mRun: [HP Software Update] c:program fileshphp software updateHPWuSchd2.exe
mRun: [AVG8_TRAY] c:progra~1avgavg8avgtray.exe
mRun: [ATIPTA] "c:program filesati technologiesati control panelatiptaxx.exe"
mRun: [iTunesHelper] "c:program filesitunesiTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:program filesadobereader 9.0readerReader_sl.exe"
mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe"
dRun: [DWQueuedReporting] "c:progra~1common~1micros~1dwdwtrig20.exe" -t
StartupFolder: c:docume~1alluse~1startm~1programsstartupaudibl~1.lnk - c:program
filesaudiblebinAudibleDownloadHelper.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupdeskto~1.lnk - c:program filesresearch in
motionblackberryDesktopMgr.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartuphpdigi~1.lnk - c:program fileshpdigital
imagingbinhpqtra08.exe
IE: E&xport to Microsoft Excel - c:progra~1micros~2office12EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:program
filesjavajre1.6.0_07binssv.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:program
filesskypetoolbarsinternet explorerSkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:program
filesskypetoolbarsinternet explorerSkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} -
c:progra~1micros~2office12REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:program filesspybot - search &
destroySDHelper.dll
Trusted Zone: ddk.net
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxp://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -
hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1242069683046
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/RACtrl.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:program filesbelarcadvisorsystemBAVoilaX.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:program filesavgavg8avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:progra~1common~1skypeSKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: TPSvc - TPSvc.dll
============= SERVICES / DRIVERS ===============
R0 AvgRkx86;avgrkx86.sys;c:windowssystem32driversavgrkx86.sys [2009-5-11 12552]
R0 stcvsm;stcvsm;c:windowssystem32driversstcvsm.sys [2009-11-21 175776]
R0 szkg5;szkg5;c:windowssystem32driversSZKG.sys [2009-12-7 61328]
R0 szkgfs;szkgfs;c:windowssystem32driversSZKGFS.sys [2010-2-24 173328]
R1 AvgTdiX;AVG8 Network Redirector;c:windowssystem32driversavgtdix.sys [2009-5-11 108552]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:windowssystem32driverse1y5132.sys [2009-4-1 243856]
S0 is3srv;is3srv;c:windowssystem32driversis3srv.sys [2009-12-7 61328]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:windowssystem32driversavgldx86.sys [2009-5-11 335240]
S1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:windowssystem32driversavgmfx86.sys [2009-5-11 27784]
S1 FSLX;FSLX;c:windowssystem32driversfslx.sys [2008-7-11 191872]
S1 sbmount;StorageCraft Image Mount Driver;c:windowssystem32driverssbmount.sys [2009-11-21 101280]
S1 vcdrom;Virtual CD-ROM Device Driver;c:downloadsvirtalcdromVCdRom.sys [2001-12-19 8576]
S2 avg8wd;AVG8 WatchDog;c:progra~1avgavg8avgwdsvc.exe [2009-5-11 297752]
S2 PEVSystemStart;PEVSystemStart;c:combofixPEV.cfxxe [2010-4-1 261632]
S2 ShadowProtectSvc;ShadowProtect Service;c:program filesstoragecraftshadowprotectShadowProtectSvc.exe [2009-11-21
1497632]
S2 StorageCraft Image Manager;StorageCraft Image Manager;c:program filesstoragecraftimagemanagerImageManager.exe
[2009-9-10 102400]
S2 VSNAPVSS;StorageCraft Shadow Copy Provider;c:windowssystem32vsnapvss.exe [2009-11-21 67616]
S4 0263461241830440mcinstcleanup;McAfee Application Installer Cleanup
(0263461241830440);c:docume~1admini~1locals~1temp026346~1.exe c:progra~1common~1mcafeeinstal~1cleanup.ini -cleanup
-nolog -service --> c:docume~1admini~1locals~1temp026346~1.exe c:progra~1common~1mcafeeinstal~1cleanup.ini -cleanup
-nolog -service [?]
=============== Created Last 30 ================
2010-04-05 20:19:33 0 ----a-w- c:documents and settingsuser1pcdefogger_reenable
2010-04-01 03:25:19 0 d-----w- c:windowsLastGood.Tmp
2010-04-01 03:23:44 448 ----a-w- c:windowssystem32driverskgpfr2.cfg
2010-04-01 01:20:30 0 d-sha-r- C:cmdcons
2010-04-01 01:19:22 98816 ----a-w- c:windowssed.exe
2010-04-01 01:19:22 77312 ----a-w- c:windowsMBR.exe
2010-04-01 01:19:22 261632 ----a-w- c:windowsPEV.exe
2010-04-01 01:19:22 161792 ----a-w- c:windowsSWREG.exe
2010-04-01 01:17:45 0 d-----w- c:windowssystem32appmgmt
2010-04-01 01:00:28 23116 ------w- c:windowshpqins15.dat.temp
2010-04-01 00:57:58 0 d-----w- c:docume~1alluse~1applic~1SITEguard
2010-04-01 00:57:41 0 d-----w- c:program filesSTOPzilla!
2010-04-01 00:57:40 0 d-----w- c:program filescommon filesiS3
2010-04-01 00:57:40 0 d-----w- c:docume~1alluse~1applic~1STOPzilla!
2010-03-27 20:56:05 32 ----a-w- C:QDATACpy_20100327.QPH
2010-03-27 20:56:05 1731888 ----a-w- C:QDATACpy_20100327.QDF
2010-03-27 20:56:05 15360 ----a-w- C:QDATACpy_20100327.QEL
2010-03-27 20:56:05 117600 ----a-w- C:QDATACpy_20100327.IDX
2010-03-27 06:21:30 77380 ------w- c:windowshpqins05.dat.temp
2010-03-27 05:59:28 271704 ----a-w- c:windowssystem32hpzids01.dll
2010-03-27 05:58:34 2979 ------w- c:windowshpwmdl22.dat
2010-03-27 05:58:34 187946 ----a-w- c:windowshpwins22.dat
2010-03-26 23:17:11 0 d-----w- c:program filesSpybot - Search & Destroy
2010-03-26 23:17:11 0 d-----w- c:docume~1alluse~1applic~1Spybot - Search & Destroy
2010-03-26 23:07:54 3840 ----a-w- c:windowssystem32driversBANTExt.sys
2010-03-26 23:07:54 0 d-----w- c:program filesBelarc
2010-03-26 22:38:22 140 ----a-w- c:windowsODBC.INI
2010-03-24 18:24:57 32 ----a-w- C:QDATACpy_20100324.QPH
2010-03-24 18:24:57 1711368 ----a-w- C:QDATACpy_20100324.QDF
2010-03-24 18:24:57 15360 ----a-w- C:QDATACpy_20100324.QEL
2010-03-24 18:24:57 115560 ----a-w- C:QDATACpy_20100324.IDX
2010-03-14 09:10:33 32 ----a-w- C:QDATACpy_20100314.QPH
2010-03-14 09:10:33 1711368 ----a-w- C:QDATACpy_20100314.QDF
2010-03-14 09:10:33 15360 ----a-w- C:QDATACpy_20100314.QEL
2010-03-14 09:10:33 115560 ----a-w- C:QDATACpy_20100314.IDX
2010-03-11 03:35:47 3558912 ------w- c:windowssystem32dllcachemoviemk.exe
==================== Find3M ====================
2010-04-01 01:00:28 22766 ----a-w- c:windowshpqins15.dat
2010-03-27 06:26:58 77393 ----a-w- c:windowshpqins05.dat
2010-03-06 01:16:42 17408 ----a-r- c:windowssystem32SZIO5.dll
2010-03-06 01:14:16 442368 ----a-r- c:windowssystem32SZBase5.dll
2010-03-06 01:13:44 540672 ----a-r- c:windowssystem32SZComp5.dll
2010-02-25 18:54:36 11070976 ------w- c:windowssystem32dllcacheieframe.dll
2010-02-24 22:06:36 173328 ----a-r- c:windowssystem32driversSZKGFS.sys
2010-02-24 09:54:25 173056 ------w- c:windowssystem32dllcacheie4uinit.exe
============= FINISH: 13:20:28.82 ===============
ark.txt for gmer uploaded
After running all the tests seems ok now.
Just let me know if you find anything in the logs please
EDIT: Posts merged ~BP
Attached Files
Edited by Budapest, 05 April 2010 - 07:17 PM.