I've posted in another thread (in this forum) before I read the instructions, but now went ahead with all the requested scans and posting the logs here. Your help is greatly appreciated, thank you!!
Here is the link for the other thread post:
http://www.bleepingcomputer.com/forums/ind...amp;hl=cilxrhoj
DDS.txt log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Iris at 14:20:22.39 on Wed 09/15/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.155 [GMT -4:00]
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning enabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
============== Running Processes ===============
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost -k DcomLaunch
svchost.exe
C:WINDOWSSystem32svchost.exe -k netsvcs
C:WINDOWSsystem32svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:Program FilesLavasoftAd-AwareAAWService.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSehomeehtray.exe
C:Program FilesAnalog DevicesCoresmax4pnp.exe
C:Program FilesCreativeSBAudigy2ZSSurround MixerCTSysVol.exe
C:Program FilesCreativeSBAudigy2ZSDVDAudioCTDVDDET.EXE
C:WINDOWSsystem32CTHELPER.EXE
C:Program FilesGoogleGmail Notifiergnotify.exe
C:Program FilesAdobePhotoshop Elements 3.0PhotoshopElementsFileAgent.exe
C:Program FilesDell Photo AIO Printer 964memcard.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:Program FilesBabylonBabylon.exe
C:Program FilesCommon FilesJavaJava Updatejusched.exe
C:WINDOWSsystem32ctfmon.exe
C:Documents and SettingsIrisApplication DataSanDiskSansa UpdaterSansaDispatch.exe
C:WINDOWSsystem32CTsvcCDA.EXE
C:WINDOWSeHomeehRecvr.exe
C:WINDOWSeHomeehSched.exe
C:Documents and SettingsAll UsersApplication DataEPSONEPW!3 SSRPE_S40RP7.EXE
C:Program FilesIntelIntel Application Acceleratoriaantmon.exe
C:Program FilesAdobePhotoshop Elements 3.0PhotoshopElementsDeviceConnect.exe
C:WINDOWSsystem32svchost.exe -k imgsvc
C:WINDOWSsystem32dlcjcoms.exe
C:WINDOWSsystem32dllhost.exe
C:Program FilesLavasoftAd-AwareAAWTray.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
C:Program FilesLavasoftAd-AwareAd-Aware.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:WINDOWSsystem32rundll32.exe
C:Documents and SettingsIrisMy DocumentsDownloadsdds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:6092
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:documents and settingsall usersapplication datarealrealplayerbrowserrecordpluginierpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:program filescommon filesmicrosoft sharedwindows liveWindowsLiveLogin.dll
BHO: TBSB07286 Class: {c23d0d6a-8cba-4b33-9735-47d81f5b2b85} - c:program filesecobartbcore3.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll
TB: Ecobar: {10000000-1000-1000-1000-100000000000} - c:program filesecobartbcore3.dll
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
uRun: [SansaDispatch] c:documents and settingsirisapplication datasandisksansa updaterSansaDispatch.exe
uRun: [cilxrhoj£] c:documents and settingsiriscilxrhoj£.exe
uRun: [cilxrhoj»] c:documents and settingsiriscilxrhoj».exe
uRun: [cilxrhojø] c:documents and settingsiriscilxrhojø.exe
uRun: [cilxrhojª] c:documents and settingsiriscilxrhojª.exe
uRun: [cilxrhojÌ] c:documents and settingsiriscilxrhojÌ.exe
uRun: [cilxrhoj¾] c:documents and settingsiriscilxrhoj¾.exe
uRun: [cilxrhojé] c:documents and settingsiriscilxrhojÉ.exe
uRun: [cilxrhojò] c:documents and settingsiriscilxrhojò.exe
uRun: [cilxrhoj³] c:documents and settingsiriscilxrhoj³.exe
uRun: [cilxrhoj] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhoj‰] c:documents and settingsiriscilxrhoj‰.exe
uRun: [cilxrhoj]] c:documents and settingsiriscilxrhoj].exe
uRun: [cilxrhoj¯] c:documents and settingsiriscilxrhoj¯.exe
uRun: [cilxrhoj‚] c:documents and settingsiriscilxrhoj‚.exe
uRun: [cilxrhoj’] c:documents and settingsiriscilxrhoj’.exe
uRun: [cilxrhoj÷] c:documents and settingsiriscilxrhoj÷.exe
uRun: [cilxrhoj=] c:documents and settingsiriscilxrhoj=.exe
uRun: [cilxrhoj5] c:documents and settingsiriscilxrhoj5.exe
uRun: [cilxrhoj[] c:documents and settingsiriscilxrhoj[.exe
uRun: [cilxrhojð] c:documents and settingsiriscilxrhojð.exe
uRun: [cilxrhoj²] c:documents and settingsiriscilxrhoj².exe
uRun: [cilxrhoj‡] c:documents and settingsiriscilxrhoj‡.exe
uRun: [cilxrhoj®] c:documents and settingsiriscilxrhoj®.exe
uRun: [cilxrhoj] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhoj´] c:documents and settingsiriscilxrhoj´.exe
uRun: [cilxrhojå] c:documents and settingsiriscilxrhojÅ.exe
uRun: [cilxrhojY] c:documents and settingsiriscilxrhojY.exe
uRun: [cilxrhojp] c:documents and settingsiriscilxrhojp.exe
uRun: [cilxrhoj0] c:documents and settingsiriscilxrhoj0.exe
uRun: [cilxrhoj…] c:documents and settingsiriscilxrhoj….exe
uRun: [cilxrhoj×] c:documents and settingsiriscilxrhoj×.exe
uRun: [cilxrhojŒ] c:documents and settingsiriscilxrhojŒ.exe
uRun: [cilxrhoj‹] c:documents and settingsiriscilxrhoj‹.exe
uRun: [cilxrhoj] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhojN] c:documents and settingsiriscilxrhojn.exe
uRun: [cilxrhojá] c:documents and settingsiriscilxrhojÁ.exe
uRun: [cilxrhojk] c:documents and settingsiriscilxrhojK.exe
uRun: [cilxrhoj] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhoj.] c:documents and settingsiriscilxrhoj..exe
uRun: [cilxrhojd] c:documents and settingsiriscilxrhojD.exe
uRun: [cilxrhojF] c:documents and settingsiriscilxrhojf.exe
uRun: [cilxrhojÚ] c:documents and settingsiriscilxrhojÚ.exe
uRun: [cilxrhojÑ] c:documents and settingsiriscilxrhojñ.exe
uRun: [cilxrhoj›] c:documents and settingsiriscilxrhoj›.exe
uRun: [cilxrhojÂ] c:documents and settingsiriscilxrhojÂ.exe
uRun: [cilxrhojb] c:documents and settingsiriscilxrhojB.exe
uRun: [cilxrhojê] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhojÍ] c:documents and settingsiriscilxrhojí.exe
uRun: [cilxrhojÏ] c:documents and settingsiriscilxrhojï.exe
uRun: [cilxrhojÈ] c:documents and settingsiriscilxrhojÈ.exe
uRun: [cilxrhojj] c:documents and settingsiriscilxrhojj.exe
uRun: [cilxrhoj«] c:documents and settingsiriscilxrhoj«.exe
uRun: [cilxrhojÝ] c:documents and settingsiriscilxrhojý.exe
uRun: [cilxrhoj ] c:documents and settingsiriscilxrhoj .exe
uRun: [cilxrhoj¢] c:documents and settingsiriscilxrhoj¢.exe
uRun: [cilxrhoj4] c:documents and settingsiriscilxrhoj4.exe
uRun: [cilxrhojÞ] c:documents and settingsiriscilxrhojþ.exe
uRun: [cilxrhojô] c:documents and settingsiriscilxrhojÔ.exe
uRun: [cilxrhoj“] c:documents and settingsiriscilxrhoj“.exe
uRun: [cilxrhoj¶] c:documents and settingsiriscilxrhoj¶.exe
uRun: [cilxrhoji] c:documents and settingsiriscilxrhojI.exe
uRun: [cilxrhoj¦] c:documents and settingsiriscilxrhoj¦.exe
uRun: [cilxrhojÇ] c:documents and settingsiriscilxrhojç.exe
uRun: [cilxrhojÎ] c:documents and settingsiriscilxrhojî.exe
uRun: [cilxrhojE] c:documents and settingsiriscilxrhoje.exe
uRun: [cilxrhojc] c:documents and settingsiriscilxrhojC.exe
uRun: [cilxrhojó] c:documents and settingsiriscilxrhojó.exe
uRun: [cilxrhoj„] c:documents and settingsiriscilxrhoj„.exe
uRun: [cilxrhoj2] c:documents and settingsiriscilxrhoj2.exe
uRun: [cilxrhojl] c:documents and settingsiriscilxrhojL.exe
uRun: [cilxrhoj&] c:documents and settingsiriscilxrhoj&.exe
uRun: [cilxrhoj9] c:documents and settingsiriscilxrhoj9.exe
uRun: [cilxrhoj`] c:documents and settingsiriscilxrhoj`.exe
uRun: [cilxrhojž] c:documents and settingsiriscilxrhojž.exe
uRun: [cilxrhoj%] c:documents and settingsiriscilxrhoj%.exe
uRun: [cilxrhoj@] c:documents and settingsiriscilxrhoj@.exe
uRun: [cilxrhoj°] c:documents and settingsiriscilxrhoj°.exe
uRun: [cilxrhoj,] c:documents and settingsiriscilxrhoj,.exe
uRun: [cilxrhoj•] c:documents and settingsiriscilxrhoj•.exe
uRun: [cilxrhojÃ] c:documents and settingsiriscilxrhojã.exe
uRun: [cilxrhoj©] c:documents and settingsiriscilxrhoj©.exe
uRun: [cilxrhojÜ] c:documents and settingsiriscilxrhojü.exe
uRun: [cilxrhoj·] c:documents and settingsiriscilxrhoj·.exe
uRun: [cilxrhoj˜] c:documents and settingsiriscilxrhoj˜.exe
uRun: [cilxrhoj#] c:documents and settingsiriscilxrhoj#.exe
uRun: [cilxrhoj$] c:documents and settingsiriscilxrhoj$.exe
uRun: [cilxrhojˆ] c:documents and settingsiriscilxrhojˆ.exe
uRun: [cilxrhojÛ] c:documents and settingsiriscilxrhojÛ.exe
uRun: [cilxrhojV] c:documents and settingsiriscilxrhojv.exe
uRun: [cilxrhoj¤] c:documents and settingsiriscilxrhoj¤.exe
uRun: [cilxrhoj¹] c:documents and settingsiriscilxrhoj¹.exe
uRun: [cilxrhoj–] c:documents and settingsiriscilxrhoj–.exe
uRun: [cilxrhoj1] c:documents and settingsiriscilxrhoj1.exe
uRun: [cilxrhojß] c:documents and settingsiriscilxrhojß.exe
uRun: [cilxrhoj”] c:documents and settingsiriscilxrhoj”.exe
uRun: [cilxrhoj'] c:documents and settingsiriscilxrhoj'.exe
uRun: [cilxrhoj}] c:documents and settingsiriscilxrhoj}.exe
uRun: [cilxrhoj)] c:documents and settingsiriscilxrhoj).exe
uRun: [cilxrhoj¿] c:documents and settingsiriscilxrhoj¿.exe
uRun: [cilxrhojƒ] c:documents and settingsiriscilxrhojƒ.exe
uRun: [cilxrhoj!] c:documents and settingsiriscilxrhoj!.exe
uRun: [cilxrhoj] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhojº] c:documents and settingsiriscilxrhojº.exe
uRun: [cilxrhoj—] c:documents and settingsiriscilxrhoj—.exe
uRun: [cilxrhoj8] c:documents and settingsiriscilxrhoj8.exe
uRun: [cilxrhoj^] c:documents and settingsiriscilxrhoj^.exe
uRun: [cilxrhoj~] c:documents and settingsiriscilxrhoj~.exe
uRun: [cilxrhoj¨] c:documents and settingsiriscilxrhoj¨.exe
uRun: [cilxrhojA] c:documents and settingsiriscilxrhojA.exe
uRun: [cilxrhoj½] c:documents and settingsiriscilxrhoj½.exe
uRun: [cilxrhojX] c:documents and settingsiriscilxrhojX.exe
uRun: [cilxrhoj] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhoj+] c:documents and settingsiriscilxrhoj+.exe
uRun: [cilxrhoj] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhojà] c:documents and settingsiriscilxrhojÀ.exe
uRun: [cilxrhoj§] c:documents and settingsiriscilxrhoj§.exe
uRun: [cilxrhoj™] c:documents and settingsiriscilxrhoj™.exe
uRun: [cilxrhoj¸] c:documents and settingsiriscilxrhoj¸.exe
uRun: [cilxrhoj6] c:documents and settingsiriscilxrhoj6.exe
uRun: [cilxrhoj] c:documents and settingsiriscilxrhoj.exe
uRun: [cilxrhoj;] c:documents and settingsiriscilxrhoj;.exe
uRun: [cilxrhoj(] c:documents and settingsiriscilxrhoj(.exe
uRun: [cilxrhoj±] c:documents and settingsiriscilxrhoj±.exe
mRun: [ehTray] c:windowsehomeehtray.exe
mRun: [SoundMAXPnP] c:program filesanalog devicescoresmax4pnp.exe
mRun: [IAAnotif] c:program filesintelintel application acceleratoriaanotif.exe
mRun: [ATIPTA] c:program filesati technologiesati control panelatiptaxx.exe
mRun: [CTSysVol] c:program filescreativesbaudigy2zssurround mixerCTSysVol.exe /r
mRun: [CTDVDDET] "c:program filescreativesbaudigy2zsdvdaudioCTDVDDET.EXE"
mRun: [CTHelper] CTHELPER.EXE
mRun: [UpdReg] c:windowsUpdReg.EXE
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:program filesgooglegmail notifiergnotify.exe
mRun: [Adobe Reader Speed Launcher] "c:program filesadobereader 9.0readerReader_sl.exe"
mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe"
mRun: [DLCJCATS] rundll32 c:windowssystem32spooldriversw32x863DLCJtime.dll,_RunDLLEntry@16
mRun: [dlcjmon.exe] "c:program filesdell photo aio printer 964dlcjmon.exe"
mRun: [MemoryCardManager] "c:program filesdell photo aio printer 964memcard.exe"
mRun: [TkBellExe] "c:program filescommon filesrealupdate_obrealsched.exe" -osboot
mRun: [Babylon Client] c:program filesbabylonBabylon.exe -AutoStart
mRun: [cilxrhoj£] c:windowssystem32cilxrhoj£.exe
mRun: [Yhijetohekafom] rundll32.exe "c:windowsuzeqepijo.dll",Startup
mRun: [cilxrhojª] c:windowssystem32cilxrhojª.exe
mRun: [cilxrhojò] c:windowssystem32cilxrhojò.exe
mRun: [cilxrhoj³] c:windowssystem32cilxrhoj³.exe
mRun: [cilxrhoj] c:windowssystem32cilxrhoj.exe
mRun: [cilxrhoj]] c:windowssystem32cilxrhoj].exe
mRun: [cilxrhoj¯] c:windowssystem32cilxrhoj¯.exe
mRun: [cilxrhoj’] c:windowssystem32cilxrhoj’.exe
mRun: [cilxrhoj÷] c:windowssystem32cilxrhoj÷.exe
mRun: [cilxrhoj=] c:windowssystem32cilxrhoj=.exe
mRun: [cilxrhoj[] c:windowssystem32cilxrhoj[.exe
mRun: [cilxrhoj‡] c:windowssystem32cilxrhoj‡.exe
mRun: [cilxrhoj®] c:windowssystem32cilxrhoj®.exe
mRun: [cilxrhoj] c:windowssystem32cilxrhoj.exe
mRun: [cilxrhoj´] c:windowssystem32cilxrhoj´.exe
mRun: [cilxrhojå] c:windowssystem32cilxrhojÅ.exe
mRun: [cilxrhojY] c:windowssystem32cilxrhojY.exe
mRun: [cilxrhojp] c:windowssystem32cilxrhojp.exe
mRun: [cilxrhoj0] c:windowssystem32cilxrhoj0.exe
mRun: [cilxrhoj…] c:windowssystem32cilxrhoj….exe
mRun: [cilxrhoj×] c:windowssystem32cilxrhoj×.exe
mRun: [cilxrhojŒ] c:windowssystem32cilxrhojŒ.exe
mRun: [cilxrhoj‹] c:windowssystem32cilxrhoj‹.exe
mRun: [cilxrhoj] c:windowssystem32cilxrhoj.exe
mRun: [cilxrhojá] c:windowssystem32cilxrhojÁ.exe
mRun: [cilxrhoj] c:windowssystem32cilxrhoj.exe
mRun: [cilxrhoj.] c:windowssystem32cilxrhoj..exe
mRun: [cilxrhojF] c:windowssystem32cilxrhojf.exe
mRun: [cilxrhojÚ] c:windowssystem32cilxrhojú.exe
mRun: [cilxrhojÂ] c:windowssystem32cilxrhojÂ.exe
mRun: [cilxrhojb] c:windowssystem32cilxrhojB.exe
mRun: [cilxrhojê] c:windowssystem32cilxrhoj.exe
mRun: [cilxrhojÏ] c:windowssystem32cilxrhojï.exe
mRun: [cilxrhojj] c:windowssystem32cilxrhojj.exe
mRun: [cilxrhoj«] c:windowssystem32cilxrhoj«.exe
mRun: [cilxrhoj ] c:windowssystem32cilxrhoj .exe
mRun: [cilxrhoj¢] c:windowssystem32cilxrhoj¢.exe
mRun: [cilxrhoj4] c:windowssystem32cilxrhoj4.exe
mRun: [cilxrhojÞ] c:windowssystem32cilxrhojþ.exe
mRun: [cilxrhoj¶] c:windowssystem32cilxrhoj¶.exe
mRun: [cilxrhoji] c:windowssystem32cilxrhojI.exe
mRun: [cilxrhoj¦] c:windowssystem32cilxrhoj¦.exe
mRun: [cilxrhojÎ] c:windowssystem32cilxrhojî.exe
mRun: [cilxrhojE] c:windowssystem32cilxrhoje.exe
mRun: [cilxrhojc] c:windowssystem32cilxrhojC.exe
mRun: [cilxrhoj2] c:windowssystem32cilxrhoj2.exe
mRun: [cilxrhojl] c:windowssystem32cilxrhojL.exe
mRun: [cilxrhoj&] c:windowssystem32cilxrhoj&.exe
mRun: [cilxrhoj9] c:windowssystem32cilxrhoj9.exe
mRun: [cilxrhoj`] c:windowssystem32cilxrhoj`.exe
mRun: [cilxrhojž] c:windowssystem32cilxrhojž.exe
mRun: [cilxrhoj%] c:windowssystem32cilxrhoj%.exe
mRun: [cilxrhoj°] c:windowssystem32cilxrhoj°.exe
mRun: [cilxrhoj,] c:windowssystem32cilxrhoj,.exe
mRun: [cilxrhoj•] c:windowssystem32cilxrhoj•.exe
mRun: [cilxrhojÃ] c:windowssystem32cilxrhojã.exe
mRun: [cilxrhoj©] c:windowssystem32cilxrhoj©.exe
mRun: [cilxrhojÜ] c:windowssystem32cilxrhojü.exe
mRun: [cilxrhoj·] c:windowssystem32cilxrhoj·.exe
mRun: [cilxrhoj˜] c:windowssystem32cilxrhoj˜.exe
mRun: [cilxrhoj#] c:windowssystem32cilxrhoj#.exe
mRun: [cilxrhoj¤] c:windowssystem32cilxrhoj¤.exe
mRun: [cilxrhoj¹] c:windowssystem32cilxrhoj¹.exe
mRun: [cilxrhoj–] c:windowssystem32cilxrhoj–.exe
mRun: [cilxrhojS] c:windowssystem32cilxrhojs.exe
mRun: [cilxrhoj1] c:windowssystem32cilxrhoj1.exe
mRun: [cilxrhojß] c:windowssystem32cilxrhojß.exe
mRun: [cilxrhoj'] c:windowssystem32cilxrhoj'.exe
mRun: [cilxrhoj}] c:windowssystem32cilxrhoj}.exe
mRun: [cilxrhoj¿] c:windowssystem32cilxrhoj¿.exe
mRun: [cilxrhoj!] c:windowssystem32cilxrhoj!.exe
mRun: [cilxrhoj—] c:windowssystem32cilxrhoj—.exe
mRun: [cilxrhoj8] c:windowssystem32cilxrhoj8.exe
mRun: [cilxrhoj^] c:windowssystem32cilxrhoj^.exe
mRun: [cilxrhoj~] c:windowssystem32cilxrhoj~.exe
mRun: [cilxrhojA] c:windowssystem32cilxrhojA.exe
mRun: [cilxrhojX] c:windowssystem32cilxrhojX.exe
mRun: [cilxrhoj] c:windowssystem32cilxrhoj.exe
mRun: [cilxrhoj+] c:windowssystem32cilxrhoj+.exe
mRun: [cilxrhoj] c:windowssystem32cilxrhoj.exe
mRun: [cilxrhojà] c:windowssystem32cilxrhojÀ.exe
mRun: [cilxrhoj™] c:windowssystem32cilxrhoj™.exe
mRun: [cilxrhoj¸] c:windowssystem32cilxrhoj¸.exe
mRun: [cilxrhoj6] c:windowssystem32cilxrhoj6.exe
mRun: [cilxrhoj] c:windowssystem32cilxrhoj.exe
mRun: [cilxrhoj;] c:windowssystem32cilxrhoj;.exe
mRun: [cilxrhoj(] c:windowssystem32cilxrhoj(.exe
mRun: [cilxrhoj7] c:windowssystem32cilxrhoj7.exe
mRun: [SunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe"
StartupFolder: c:docume~1alluse~1startm~1programsstartupadobeg~1.lnk - c:program filescommon filesadobecalibrationAdobe Gamma Loader.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
IE: E&xport to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC} - c:program filesjavajre6binjp2iexp.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~2office11REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:docume~1irisapplic~1mozillafirefoxprofilesorl4g2on.default
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=55555
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=adbartrp&AF=55555&q=
FF - component: c:documents and settingsirisapplication datamozillafirefoxprofilesorl4g2on.defaultextensions{e001c731-5e37-4538-a5cb-8168736a2360}componentsqscanff.dll
FF - plugin: c:documents and settingsall usersapplication datarealrealplayerbrowserrecordpluginmozillapluginsnprphtml5videoshim.dll
FF - plugin: c:documents and settingsirisapplication datamozillafirefoxprofilesorl4g2on.defaultextensions{e001c731-5e37-4538-a5cb-8168736a2360}pluginsnpqscan.dll
FF - plugin: c:program filesgoogleupdate1.2.183.13npGoogleOneClick8.dll
FF - plugin: c:program filesjavajre6binnpdeployJava1.dll
FF - plugin: c:program filesjavajre6binnpjpi160_21.dll
FF - HiddenExtension: XULRunner: {53AB71CE-B9FA-404F-8118-B68194A9397F} - c:documents and settingsirislocal settingsapplication data{53AB71CE-B9FA-404F-8118-B68194A9397F}
FF - HiddenExtension: Java Console: No Registry Reference - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:program filesmozilla firefoxgreprefsall.js - pref("ui.use_native_colors", true);
c:program filesmozilla firefoxgreprefsall.js - pref("ui.use_native_popup_windows", false);
c:program filesmozilla firefoxgreprefsall.js - pref("browser.enable_click_image_resizing", true);
c:program filesmozilla firefoxgreprefsall.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:program filesmozilla firefoxgreprefsall.js - pref("javascript.options.mem.high_water_mark", 32);
c:program filesmozilla firefoxgreprefsall.js - pref("javascript.options.mem.gc_frequency", 1600);
c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.lu", true);
c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.nu", true);
c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.nz", true);
c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.tel", true);
c:program filesmozilla firefoxgreprefsall.js - pref("network.auth.force-generic-ntlm", false);
c:program filesmozilla firefoxgreprefsall.js - pref("network.proxy.type", 5);
c:program filesmozilla firefoxgreprefsall.js - pref("network.buffer.cache.count", 24);
c:program filesmozilla firefoxgreprefsall.js - pref("network.buffer.cache.size", 4096);
c:program filesmozilla firefoxgreprefsall.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:program filesmozilla firefoxgreprefsall.js - pref("svg.smil.enabled", false);
c:program filesmozilla firefoxgreprefsall.js - pref("ui.trackpoint_hack.enabled", -1);
c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.debug", false);
c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.agedWeight", 2);
c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.bucketSize", 1);
c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.maxTimeGroupings", 25);
c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.timeGroupingSize", 604800);
c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.boundaryWeight", 25);
c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.prefixWeight", 5);
c:program filesmozilla firefoxgreprefsall.js - pref("accelerometer.enabled", true);
c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:program filesmozilla firefoxdefaultspreffirefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:program filesmozilla firefoxdefaultspreffirefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:program filesmozilla firefoxdefaultspreffirefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("lightweightThemes.update.enabled", true);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("browser.allTabs.previews", false);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("plugins.update.notifyUser", false);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("toolbar.customization.usesheet", false);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled", false);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("browser.taskbar.previews.enable", false);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("browser.taskbar.previews.max", 20);
c:program filesmozilla firefoxdefaultspreffirefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:windowssystem32driversLbd.sys [2010-9-14 64288]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:program filesadobephotoshop elements 3.0PhotoshopElementsFileAgent.exe [2004-10-20 98304]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:program fileslavasoftad-awareAAWService.exe [2010-8-12 1355928]
R2 McrdSvc;Media Center Extender Service;c:windowsehomemcrdsvc.exe [2005-8-5 99328]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:program filesadobephotoshop elements 3.0PhotoshopElementsDeviceConnect.exe [2004-10-20 118784]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:program fileslavasoftad-awarekernexplorer.sys [2010-8-12 15008]
S2 gupdate;Google Update Service (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2010-9-14 135664]
=============== Created Last 30 ================
2010-09-15 18:15:31 0 ----a-w- c:documents and settingsirisdefogger_reenable
2010-09-15 17:36:47 0 d-----w- c:program filesTrend Micro
2010-09-15 15:06:57 41600 -c--a-w- c:windowssystem32dllcacheweitekp9.dll
2010-09-15 15:05:58 38912 -c--a-w- c:windowssystem32dllcacheEXCH_ntfsdrv.dll
2010-09-15 15:04:59 36864 -c--a-w- c:windowssystem32dllcachehanjadic.dll
2010-09-15 15:03:59 76800 -c--a-w- c:windowssystem32dllcachelogui.ocx
2010-09-15 15:00:10 488 ---ha-r- c:windowssystem32logonui.exe.manifest
2010-09-15 15:00:05 749 ---ha-r- c:windowsWindowsShell.Manifest
2010-09-15 15:00:05 749 ---ha-r- c:windowssystem32wuaucpl.cpl.manifest
2010-09-15 15:00:05 749 ---ha-r- c:windowssystem32sapi.cpl.manifest
2010-09-15 15:00:05 749 ---ha-r- c:windowssystem32nwc.cpl.manifest
2010-09-15 15:00:05 749 ---ha-r- c:windowssystem32ncpa.cpl.manifest
2010-09-15 14:59:45 16384 -c--a-w- c:windowssystem32dllcacheisignup.exe
2010-09-15 14:05:42 0 d-----w- c:program filesBroadcom
2010-09-15 04:16:32 127 ----a-w- c:windowssystem32MRT.INI
2010-09-15 04:16:32 0 d-----w- c:windowssystem32MpEngineStore
2010-09-15 01:13:11 423656 ----a-w- c:windowssystem32deployJava1.dll
2010-09-15 01:13:11 0 ----a-w- c:windowssystem32REN10C.tmp
2010-09-15 01:13:11 0 ----a-w- c:windowssystem32REN10B.tmp
2010-09-15 01:13:11 0 ----a-w- c:windowssystem32REN10A.tmp
2010-09-14 19:54:41 15880 ----a-w- c:windowssystem32lsdelete.exe
2010-09-14 18:31:29 210959 ----a-w- c:windowssetupapi.old
2010-09-14 18:31:22 64288 ----a-w- c:windowssystem32driversLbd.sys
2010-09-14 18:31:17 95024 ----a-w- c:windowssystem32driversSBREDrv.sys
2010-09-14 18:22:11 0 dc-h--w- c:docume~1alluse~1applic~1{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-14 18:21:31 0 d-----w- c:program filesLavasoft
2010-09-14 17:52:23 0 d-----w- c:docume~1irisapplic~1QuickScan
2010-09-09 13:57:10 0 ----a-w- c:windowssystem32cilxrhoj
2010-09-09 13:57:10 0 ----a-w- c:documents and settingsiriscilxrhoj
2010-09-09 05:56:52 274288 ----a-w- c:windowssystem32mucltui.dll
2010-09-09 05:56:52 215920 ----a-w- c:windowssystem32muweb.dll
2010-09-09 05:56:52 16736 ----a-w- c:windowssystem32mucltui.dll.mui
2010-09-08 13:55:46 0 d-----w- c:documents and settingsirisTracing
2010-09-08 13:53:57 0 d-----w- c:program filesMicrosoft
2010-09-08 13:53:43 0 d-----w- c:program filesWindows Live SkyDrive
2010-09-08 13:51:13 0 d-----w- c:program filescommon filesWindows Live
2010-09-05 00:06:07 0 d-----w- c:docume~1irisapplic~1Malwarebytes
2010-09-05 00:05:58 38224 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2010-09-05 00:05:57 20952 ----a-w- c:windowssystem32driversmbam.sys
2010-09-05 00:05:57 0 d-----w- c:program filesMalwarebytes' Anti-Malware
2010-09-05 00:05:57 0 d-----w- c:docume~1alluse~1applic~1Malwarebytes
2010-09-04 23:58:12 0 d-----w- c:program filesCCleaner
2010-09-04 21:39:11 0 d-----w- c:windowssystem32appmgmt
2010-09-04 21:11:14 120 ----a-w- c:windowsRdegoxiredoxir.dat
2010-09-04 21:11:14 0 ----a-w- c:windowsOtumogovitogol.bin
2010-09-04 21:09:29 0 d-----w- c:docume~1irisapplic~1Toolbar4
2010-09-04 20:55:57 73728 ----a-w- c:windowssystem32javacpl.cpl
2010-08-24 21:50:54 5632 ----a-w- c:windowssystem32ptpusb.dll
2010-08-24 21:50:53 15104 ----a-w- c:windowssystem32driversusbscan.sys
2010-08-24 21:50:52 159232 ----a-w- c:windowssystem32ptpusd.dll
2010-08-17 14:21:42 0 d-----w- c:docume~1alluse~1applic~1Babylon
2010-08-17 14:19:15 0 d-----w- c:docume~1irisapplic~1Babylon
==================== Find3M ====================
2010-09-15 14:57:27 34284 ----a-w- c:windowssystem32emptyregdb.dat
2010-08-15 19:07:24 499712 ----a-w- c:windowssystem32msvcp71.dll
2010-08-15 19:07:24 348160 ----a-w- c:windowssystem32msvcr71.dll
2010-08-02 05:28:41 0 ---ha-w- c:windowssystem32driversMsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-08-02 05:28:41 0 ---ha-w- c:windowssystem32driversMsft_Kernel_NuidFltr_01005.Wdf
2010-07-22 05:57:20 5120 ----a-w- c:windowssystem32xpsp4res.dll
============= FINISH: 14:20:49.28 ===============
Other two files are attached.
Thank you so much for your help!
Iris
here's another strange thing i've noticed: this re-direct search phenomenon happens only on one windows user account, which is the administrator account. I've opened another account (non-administrator) and transferred my browser profile (FF) to the new account, including all the bookmarks and add ons, but surprisingly the search works fine here. yet when i go back to the other account it's still there.
I am adding another event that happened today (not trying to bump, just informing of the developments) - today at some point there was a small window informing me of a security update/fix for FireFox browser. I clicked install and then restart, and only afterward realized I may have authorized another virus! before FF went back on another window opened asking me do I want to install this program on another user account - which program???!!! I didn't mean to authorize any program, only an update to the browser!
However, so far I don't see any strange behavior. Maybe in the morning. But I'm not running any additional scans because I'm waiting for a reply here, and read the administrators request not to run any additional scans until a reply is received.
EDIT: Posts merged ~BP
Attached Files
Edited by Budapest, 19 September 2010 - 01:22 AM.