Hello
I have removed some programs and it is booting up a little faster, but I'm still suspicious.
Here are my dds files, defogger and gmer files.
DDS (Ver_10-10-10.03) - NTFSx86
Run by HP_Administrator at 18:43:21.80 on Thu 10/14/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2558.1678 [GMT -5:00]
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\AnalogX\MaxMem\maxmem.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\HP_Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - No File
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\maxmem.lnk - c:\program files\analogx\maxmem\maxmem.exe
mPolicies-explorer: NoResolveTrack = 1 (0x1)
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: junomsg - {C4D10830-379D-11d4-9B2D-00C04F1579A5} - c:\program files\juno\bin\jmsgpph.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\hp_adm~1\applic~1\mozilla\firefox\profiles\cpxqlop7.default\
FF - prefs.js: browser.search.selectedEngine - Ixquick
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\hp_administrator\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\hp_administrator\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\hp_administrator\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-3-25 64288]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 151216]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-6-23 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 66632]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1357464]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R3 AV88BASE;Cx2388x Base Driver;c:\windows\system32\drivers\av88base.sys [2009-12-7 425472]
S1 czfiaplx;czfiaplx;\??\c:\windows\system32\drivers\czfiaplx.sys --> c:\windows\system32\drivers\czfiaplx.sys [?]
S1 dnmwzuyv;dnmwzuyv;\??\c:\windows\system32\drivers\dnmwzuyv.sys --> c:\windows\system32\drivers\dnmwzuyv.sys [?]
S1 hxswzipm;hxswzipm;\??\c:\windows\system32\drivers\hxswzipm.sys --> c:\windows\system32\drivers\hxswzipm.sys [?]
S1 mifhzhyw;mifhzhyw;\??\c:\windows\system32\drivers\mifhzhyw.sys --> c:\windows\system32\drivers\mifhzhyw.sys [?]
S1 pumkiecg;pumkiecg;\??\c:\windows\system32\drivers\pumkiecg.sys --> c:\windows\system32\drivers\pumkiecg.sys [?]
S1 rqbscmyh;rqbscmyh;\??\c:\windows\system32\drivers\rqbscmyh.sys --> c:\windows\system32\drivers\rqbscmyh.sys [?]
S1 szutpasl;szutpasl;\??\c:\windows\system32\drivers\szutpasl.sys --> c:\windows\system32\drivers\szutpasl.sys [?]
S1 wdxsjdmv;wdxsjdmv;\??\c:\windows\system32\drivers\wdxsjdmv.sys --> c:\windows\system32\drivers\wdxsjdmv.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2009-6-17 12672]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\35.tmp --> c:\windows\system32\35.tmp [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 12872]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-10 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 getPlus® Installer;getPlus® Installer;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-8-12 59552]
=============== Created Last 30 ================
2072-07-31 23:44:42 375808 ----a-w- c:\program files\microsoft games\halo\binkw32.dll
2010-10-14 21:34:32 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-14 21:34:30 974848 ------w- c:\windows\system32\dllcache\mfc42.dll
2010-10-14 21:34:09 6084944 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{5947732e-1503-4231-9ff1-6aa078b6838d}\mpengine.dll
2010-10-14 21:33:42 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2010-10-08 17:41:57 -------- dc-h--w- c:\docume~1\alluse~1\applic~1\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-10-05 20:07:51 -------- d-----w- c:\documents and settings\hp_administrator\New Folder
2010-10-05 19:15:54 -------- d-----w- c:\program files\Speccy
2010-10-05 15:52:05 61440 ----a-w- c:\windows\_detmp.2
2010-10-05 00:39:01 -------- d-----w- C:\~$PVRTmp0$
2010-09-26 18:05:47 -------- d-----w- c:\program files\NetLibrary
2010-09-26 12:51:54 -------- d-----w- c:\program files\OverDrive Media Console
2010-09-25 20:51:44 -------- d-----w- c:\windows\system32\windows media
2010-09-25 20:51:22 -------- d--h--w- c:\windows\msdownld.tmp
2010-09-25 20:51:20 -------- d-----w- c:\program files\Windows Media Components
2010-09-22 23:10:52 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2010-09-22 23:10:52 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2010-09-18 17:23:26 974848 ------w- c:\windows\system32\dllcache\mfc42u.dll
2010-09-18 15:58:45 -------- d-----w- c:\docume~1\hp_adm~1\applic~1\Ashampoo
2010-09-18 15:58:33 -------- d-----w- c:\docume~1\hp_adm~1\locals~1\applic~1\ashampoo
2010-09-18 15:58:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\ashampoo
2010-09-17 23:46:56 -------- d-----w- c:\program files\Ashampoo
2010-09-15 03:43:56 -------- d-----w- c:\program files\MSECache
==================== Find3M ====================
2010-09-18 17:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ------w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-01 23:52:37 232968 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-09-01 23:52:37 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-09-01 23:52:29 232968 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 17:33:14 1728512 ----a-w- c:\program files\LC.exe
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-25 15:09:35 159843 ----a-w- c:\windows\ScanWiz Uninstaller.exe
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-12 12:15:20 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-08-12 04:07:46 133616 ------w- c:\windows\system32\pxafs.dll
2010-08-12 04:07:46 126448 ------w- c:\windows\system32\pxinsi64.exe
============= FINISH: 18:43:49.75 ===============
GMER 1.0.15.15315 -
http://www.gmer.netRootkit quick scan 2010-10-14 18:49:48
Windows 5.1.2600 Service Pack 3
Running: npdet4nb.exe; Driver: C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\axldypob.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
---- EOF - GMER 1.0.15 ----
Thanks for the help.