January 6th, 2011 16:00

I am a CPU Noob and need help

Everytime I search something and they try to go to that page I get redirected. First why do people do this? Is it funny? I think not more like childish... Any way her is the log I have. if any one could help that would be awesome...


January 8th, 2011 04:00

Welcome. Thank you for using Dell Community Forums.

I am reviewing your log. In the meantime, you can help me by addressing the following:

* Have you posted this issue on another forum? If so, please provide a link to the topic.

* If you have disabled System Restore in an attempt to begin cleaning malware, please enable it now. We will flush System Restore when we are finished cleaning and we are sure that everything is running smoothly.

* If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software HERE.

* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.  The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list HERE.    

* If this computer belongs to someone else, do you have authority to apply the fixes we will use?

* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures. Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using. Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate. It is understood by the trained analysts that once a helper replies to a log, he continues working with you until the issue is resolved.

* During the course of our cleanup please do not do any additional online work or surfing until we have verified that your system is clean.

* We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case. Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them. *Please note also that not all of our tools work on 64-bit systems, so we may be limited in our procedures.

* The presence of windows error codes may indicate hardware problems and could limit the success of infection removal.

(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
  • Install ERUNT by following the prompts
(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
  • Start ERUNT
(either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
  • Choose a location for the backup
(the default location is C:\WINDOWS\ERDNT which is acceptable).
  • Make sure that at least the first two check boxes are ticked
  • Press OK
  • Press YES to create the folder.

If there is a problem after making changes to the system,  to restore your registry, go to the folder and start ERUNT.exe

Let me know after you have installed ERUNT.

No Reply within 3 days will result in this topic being closed, and I will remove it from my subscriptions. If you require more time, please let me know.

Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a log at the top of this board to start a new forum topic.

January 8th, 2011 10:00

Ok I have installed ERUNT

January 8th, 2011 11:00

We need to see some additional information about what is happening in your machine.

  • Please download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.
  • Click Yes at the prompt for Optional Scan.
  • When done, DDS will open two (2) logs

1. DDS.txt
2. Attach.txt

  • Save both reports to your desktop.
  • Copy/paste both logs to your reply on the forum. Do not attach them.
  • Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE.

Also  please run the following scan and include its log with the two DDS logs:

Download Security Check by screen317 and save it to your Desktop: here or here

  • Run Security Check
  • Follow the onscreen instructions inside of the command window.
  • A Notepad document should open automatically called checkup.txt; close Notepad. As mentioned above, we will need this log, too, so remember where you've saved it!

If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.

January 8th, 2011 16:00

ok so here is that stuff

DDS First

DDS (Ver_10-12-12.02) - NTFSx86 
Run by User at 18:57:10.34 on Sat 01/08/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1014.206 [GMT -5:00]

AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kodak\AiO\center\KodakSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\Program Files\Zune\ZuneBusEnum.exe
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\User\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://
uWindow Title = Windows Internet Explorer provided by MySpace
uSearch Bar =
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [WavXMgr] c:\program files\wave systems corp\services manager\docmgr\bin\WavXDocMgr.exe
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [SecureUpgrade] c:\program files\wave systems corp\SecureUpgrade.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [KADxMain] c:\windows\system32\KADxMain.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\downlo~1.lnk - c:\program files\yamaha corporation\digital music notebook\common\download centre\Download Centre.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone:\ttlc
Notify: gemsafe - c:\program files\gemplus\gemsafe libraries\bin\WLEventNotify.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 wvauth
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\jed6bdxq.default\
FF - prefs.js: browser.startup.homepage -
FF - plugin: c:\documents and settings\user\application data\move networks\plugins\npqmp071500000347.dll
FF - plugin: c:\documents and settings\user\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\user\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\user\application data\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\documents and settings\user\application data\move networks\plugins\npqmp071706000001.dll
FF - plugin: c:\documents and settings\user\application data\mozilla\firefox\profiles\jed6bdxq.default\extensions\\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Battlefield Heroes Updater: - %profile%\extensions\
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Move Media Player: - c:\documents and settings\user\application data\Move Networks

FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2006-12-19 79432]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632]
R2 FAD;FAD;c:\program files\broadcom\bacs\FADXP32.sys [2007-1-14 16352]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\aio\center\KodakSvc.exe [2009-1-19 38296]
R2 NMPortMapper;NMPortMapper;c:\objectmanager\migra\etc\bin\nt\pmapsvc.exe [2008-7-25 13312]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-9-27 1813232]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [2004-8-11 5120]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [2006-11-2 97536]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-8-6 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110107.003\naveng.sys [2011-1-7 86008]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110107.003\navex15.sys [2011-1-7 1360760]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\EKDiscovery.exe [2009-1-19 279960]
S3 cpuz134;cpuz134;\??\c:\docume~1\user\locals~1\temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\user\locals~1\temp\cpuz134\cpuz134_x32.sys [?]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-9-27 116464]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\zune\WMZuneComm.exe [2010-11-11 268528]

=============== Created Last 30 ================

2011-01-08 23:56:25    --------    d--h--w-    c:\windows\PIF
2011-01-04 17:18:08    --------    d-sh--w-    c:\documents and settings\user\PrivacIE
2011-01-03 17:41:18    388096    ----a-r-    c:\docume~1\user\applic~1\microsoft\installer\{0761c9a8-8f3a-4216-b4a7-b7afbf24a24a}\HiJackThis.exe
2011-01-03 17:41:16    --------    d-----w-    c:\program files\TrendMicro
2010-12-29 17:44:58    --------    d-sh--w-    c:\documents and settings\user\IETldCache
2010-12-28 23:31:47    --------    d-----w-    c:\windows\ie8updates
2010-12-28 23:25:31    --------    dc-h--w-    c:\windows\ie8
2010-12-28 23:24:09    7680    ------w-    c:\windows\system32\dllcache\iecompat.dll
2010-12-28 23:23:40    12800    ------w-    c:\windows\system32\dllcache\xpshims.dll
2010-12-28 23:23:38    743424    ------w-    c:\windows\system32\dllcache\iedvtool.dll
2010-12-28 23:23:37    247808    ------w-    c:\windows\system32\dllcache\ieproxy.dll
2010-12-28 23:22:46    --------    d-----w-    C:\d150c3849615d151bd4e
2010-12-25 19:39:18    16928    ------w-    c:\windows\system32\spmsgXP_2k3.dll
2010-12-25 19:34:37    62976    ------w-    c:\windows\system32\dllcache\cdrom.sys
2010-12-25 19:34:37    465920    ------w-    c:\windows\system32\imapi2fs.dll
2010-12-25 19:34:37    465920    ------w-    c:\windows\system32\dllcache\imapi2fs.dll
2010-12-25 19:34:36    317952    ------w-    c:\windows\system32\imapi2.dll
2010-12-25 19:34:36    317952    ------w-    c:\windows\system32\dllcache\imapi2.dll
2010-12-25 19:12:49    --------    d-----w-    c:\windows\system32\wbem\repository\FS
2010-12-25 19:12:49    --------    d-----w-    c:\windows\system32\wbem\Repository
2010-12-25 17:30:02    --------    d-----w-    c:\windows\system32\pt-PT
2010-12-25 17:25:30    --------    d-----w-    c:\windows\system32\drivers\umdf\pt-BR
2010-12-25 17:25:28    --------    d-----w-    c:\windows\system32\drivers\umdf\pt-PT
2010-12-25 17:25:26    --------    d-----w-    c:\windows\system32\drivers\umdf\nl-NL
2010-12-25 17:25:23    --------    d-----w-    c:\windows\system32\drivers\umdf\it-IT
2010-12-25 17:25:20    --------    d-----w-    c:\windows\system32\drivers\umdf\de-DE
2010-12-25 17:25:18    --------    d-----w-    c:\windows\system32\drivers\umdf\fr-FR
2010-12-25 17:25:15    --------    d-----w-    c:\windows\system32\drivers\umdf\es-ES
2010-12-25 17:23:08    --------    d-----w-    c:\windows\system32\drivers\umdf\en-US
2010-12-15 23:06:30    40960    ------w-    c:\windows\system32\dllcache\ndproxy.sys
2010-12-15 23:05:36    45568    ------w-    c:\windows\system32\dllcache\wab.exe

==================== Find3M  ====================

2010-12-06 00:15:12    226816    ----a-w-    c:\windows\system32\sshnas21.dll
2010-12-05 01:58:45    54784    --sha-r-    c:\windows\system32\wuauclt10.dll
2010-11-18 18:12:44    81920    ----a-w-    c:\windows\system32\isign32.dll
2010-11-06 00:26:58    916480    ----a-w-    c:\windows\system32\wininet.dll
2010-11-06 00:26:58    43520    ------w-    c:\windows\system32\licmgr10.dll
2010-11-06 00:26:58    1469440    ------w-    c:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54    385024    ------w-    c:\windows\system32\html.iec
2010-10-28 13:13:22    290048    ----a-w-    c:\windows\system32\atmfd.dll
2010-10-26 13:25:00    1853312    ----a-w-    c:\windows\system32\win32k.sys

============= FINISH: 18:59:14.81 ===============


And the Attach


DDS (Ver_10-12-12.02)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 7/9/2008 11:48:42 AM
System Uptime: 1/8/2011 1:36:18 PM (5 hours ago)

Motherboard: Dell Inc. |  | 0KU184
Processor: Intel(R) Core(TM)2 Duo CPU     T7250  @ 2.00GHz | Microprocessor | 778/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 74 GiB total, 38.548 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 12/5/2010 11:10:27 AM - System Checkpoint
RP2: 12/6/2010 10:30:37 AM - Software Distribution Service 3.0
RP3: 12/6/2010 5:05:21 PM - Removed ABBYY FineReader 6.0 Sprint
RP4: 12/6/2010 5:06:32 PM - Removed Bonjour
RP5: 12/6/2010 5:08:33 PM - Configured EMBASSY Trust Suite by Wave Systems
RP6: 12/6/2010 7:41:08 PM - Installed Broadcom Gigabit Integrated Controller.
RP7: 12/7/2010 7:43:09 PM - System Checkpoint
RP8: 12/7/2010 9:48:21 PM - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
RP9: 12/8/2010 11:24:27 AM - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
RP10: 12/9/2010 11:49:34 AM - System Checkpoint
RP11: 12/10/2010 1:40:49 PM - Installed Java(TM) 6 Update 22
RP12: 12/14/2010 10:19:34 AM - System Checkpoint
RP13: 12/15/2010 7:22:26 PM - Software Distribution Service 3.0
RP14: 12/18/2010 8:12:52 PM - System Checkpoint
RP15: 12/25/2010 12:18:48 PM - Software Distribution Service 3.0
RP16: 12/25/2010 12:20:58 PM - Installed Zune 4.7
RP17: 12/25/2010 12:30:22 PM - Installed Windows XP Wudf01009.
RP18: 12/25/2010 12:32:36 PM - Installed Windows XP winusb0100.
RP19: 12/25/2010 2:06:05 PM - Restore Operation
RP20: 12/25/2010 2:34:26 PM - Software Distribution Service 3.0
RP21: 12/25/2010 2:36:27 PM - Installed Zune 4.7
RP22: 12/25/2010 2:51:43 PM - Installed Windows XP Wudf01009.
RP23: 12/25/2010 2:55:34 PM - Installed Windows XP winusb0100.
RP24: 12/25/2010 4:57:11 PM - Software Distribution Service 3.0
RP25: 12/28/2010 10:08:16 AM - System Checkpoint
RP26: 12/28/2010 5:36:36 PM - Software Distribution Service 3.0
RP27: 12/28/2010 6:28:03 PM - Installed Windows Internet Explorer 8.
RP28: 12/28/2010 6:30:10 PM - Software Distribution Service 3.0
RP29: 12/30/2010 4:34:11 PM - Software Distribution Service 3.0
RP30: 1/3/2011 12:41:14 PM - Installed HiJackThis
RP31: 1/4/2011 6:57:31 PM - System Checkpoint
RP32: 1/7/2011 7:37:56 AM - System Checkpoint
RP33: 1/8/2011 12:55:09 PM - System Checkpoint

==== Event Viewer Messages From Past Week ========

1/7/2011 9:38:21 AM, error: Dhcp [1002]  - The IP address lease for the Network Card with network address 001644E19E32 has been denied by the DHCP server (The DHCP Server sent a DHCPNACK message).
1/7/2011 7:47:18 AM, error: Dhcp [1002]  - The IP address lease for the Network Card with network address 001644E19E32 has been denied by the DHCP server (The DHCP Server sent a DHCPNACK message).
1/7/2011 7:23:59 AM, error: Dhcp [1002]  - The IP address lease for the Network Card with network address 001644E19E32 has been denied by the DHCP server (The DHCP Server sent a DHCPNACK message).
1/7/2011 10:12:12 AM, error: Dhcp [1002]  - The IP address lease for the Network Card with network address 001644E19E32 has been denied by the DHCP server (The DHCP Server sent a DHCPNACK message).
1/4/2011 6:35:02 PM, error: Dhcp [1002]  - The IP address lease for the Network Card with network address 001644E19E32 has been denied by the DHCP server (The DHCP Server sent a DHCPNACK message).
1/4/2011 11:58:32 AM, error: Service Control Manager [7034]  - The Zune Bus Enumerator service terminated unexpectedly.  It has done this 3 time(s).
1/4/2011 11:58:04 AM, error: Service Control Manager [7034]  - The SSDP Discovery Service service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:58:03 AM, error: Service Control Manager [7034]  - The TCP/IP NetBIOS Helper service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:58:03 AM, error: Service Control Manager [7031]  - The Remote Registry service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service.
1/4/2011 11:58:00 AM, error: Service Control Manager [7034]  - The NTRU TSS v1.2.1.25 TCS service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:57:56 AM, error: Service Control Manager [7034]  - The Wave UCSPlus service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:57:52 AM, error: Service Control Manager [7034]  - The Windows Image Acquisition (WIA) service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:57:47 AM, error: Service Control Manager [7034]  - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:57:31 AM, error: Service Control Manager [7034]  - The NMPortMapper service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:57:21 AM, error: Service Control Manager [7034]  - The Distributed Transaction Coordinator service terminated unexpectedly.  It has done this 2 time(s).
1/4/2011 11:56:38 AM, error: Service Control Manager [7031]  - The COM+ System Application service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service.
1/4/2011 11:56:34 AM, error: Service Control Manager [7034]  - The Distributed Transaction Coordinator service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:54:27 AM, error: Service Control Manager [7031]  - The Zune Bus Enumerator service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
1/4/2011 11:52:04 AM, error: Service Control Manager [7034]  - The Kodak AiO Device Service service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:51:56 AM, error: Service Control Manager [7034]  - The TdmService service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:51:24 AM, error: Service Control Manager [7034]  - The Application Layer Gateway Service service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:51:00 AM, error: Service Control Manager [7031]  - The Apple Mobile Device service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/4/2011 11:50:49 AM, error: Service Control Manager [7034]  - The Broadcom ASF IP and SMBIOS Mailbox Monitor service terminated unexpectedly.  It has done this 1 time(s).
1/4/2011 11:48:29 AM, error: Service Control Manager [7003]  - The Kodak AiO Network Discovery Service service depends on the following nonexistent service: Bonjour Service
1/4/2011 1:25:58 PM, error: Service Control Manager [7011]  - Timeout (30000 milliseconds) waiting for a transaction response from the KodakSvc service.

==== End Of File ===========================

Now the Checkup

 Results of screen317's Security Check version 0.99.8 
 Windows XP Service Pack 3 
 Internet Explorer 8 
Antivirus/Firewall Check:

 Windows Security Center service is not running! This report may not be accurate!
 Windows Firewall Enabled! 
 Symantec AntiVirus    
 Antivirus up to date! (On Access scanning disabled!)
Anti-malware/Other Utilities Check:

 Java(TM) 6 Update 22 
 Java(TM) 6 Update 5 
 Java(TM) 6 Update 7 
 Out of date Java installed!
 Adobe Flash Player 
Adobe Reader 9.4.1
Out of date Adobe Reader installed!
 Mozilla Firefox (3.6.13)
Process Check: 
objlist.exe by Laurent

 Symantec AntiVirus DefWatch.exe  
 Symantec AntiVirus Rtvscan.exe  
 Symantec AntiVirus VPC32.exe  
``````````End of Log````````````


I sure hope this is legit


January 8th, 2011 16:00

Here is the Security Check again wiht the A/V disabled ...


 Results of screen317's Security Check version 0.99.8 
 Windows XP Service Pack 3 
 Internet Explorer 8 
Antivirus/Firewall Check:

 Windows Security Center service is not running! This report may not be accurate!
 Windows Firewall Enabled! 
 Symantec AntiVirus    
 Antivirus up to date! (On Access scanning disabled!)
Anti-malware/Other Utilities Check:

 Java(TM) 6 Update 22 
 Java(TM) 6 Update 5 
 Java(TM) 6 Update 7 
 Out of date Java installed!
 Adobe Flash Player 
Adobe Reader 9.4.1
Out of date Adobe Reader installed!
 Mozilla Firefox (3.6.13)
Process Check: 
objlist.exe by Laurent

 Symantec AntiVirus DefWatch.exe  
 Symantec AntiVirus Rtvscan.exe  
``````````End of Log````````````

January 8th, 2011 17:00

Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

  • If an infected file is detected, the default action will be Cure Make sure that is selected. Click on Continue.

  • If a suspicious file is detected, the default action will be Skip, click on Continue.

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.___log.txt". Please copy and paste the contents of that file here.


January 8th, 2011 17:00

Here it is...

January 8th, 2011 18:00

So far, so good.

Please run a scan with MBAM. * If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use the update link mentioned below to manually update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "lookinhere.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the files to the infected computer. Install the "lookinhere.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link

  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.

MBAM will automatically start and you will be asked to update the program before performing a scan.

  • If an update is found, the program will automatically update itself.
  • Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates,
manually download them from here
and just double-click on mbam-rules.exe to install.
Alternatively, you can update through MBAM's interface from a clean computer,
copy the definitions (rules.ref) located in
C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.

On the Scanner tab:

  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top.
It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully.
Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.

Back at the main Scanner screen:

  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report into your next reply and exit MBAM.

Note:-- If MBAM encounters a file that is difficult to remove,
you may be asked to reboot your computer so it can proceed with the disinfection process.
Regardless if prompted to restart the computer or not, please do so immediately.
Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

-- MBAM may make changes to your registry as part of its disinfection routine.
If you're using other security programs that detect registry changes (like Spybot's Teatimer),
they may interfere with the fix or alert you after scanning with MBAM.
Please disable such programs until disinfection is complete or permit them to allow the changes.


**If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from HERE


January 8th, 2011 19:00

so am I good now?
How is it running? Any symptoms of malware?

You still have some outdated programs that are making you vulnerable to malware.

If not ill have to pick it up tomorrow
You had not only a rootkit but other malware as well. These things often take several days to clean. Do you want to continue tomorrow?

January 8th, 2011 19:00

Ok here is this one



Malwarebytes' Anti-Malware

Database version: 5485

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/8/2011 10:20:53 PM
mbam-log-2011-01-08 (22-20-53).txt

Scan type: Quick scan
Objects scanned: 156313
Time elapsed: 11 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEAC7DC8-E106-4C6A-931E-5A42E7362883} (Adware.GameVance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\JP595IR86O (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\OW1T3CYG7T (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QuickyPlaeyrSoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\gxvxc (Rootkit.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\documents and settings\User\start menu\Programs\quickyplaeyr (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Files Infected:
c:\documents and settings\User\my documents\downloads\firefox-update(2).exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\sshnas21.dll (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{62c40aa6-4406-467a-a5a5-dfdf1b559b7a}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.


so am I good now?

If not ill have to pick it up tomorrow

Thanks for all your help

January 9th, 2011 19:00

You can go ahead and delete TDSS Killer and its log. Also delete DDs and its two logs. Your HijackThis is outdated, so please delete that old beta version.

Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java SE Runtime Environment (JRE) 6 Update 23  to your Desktop.
  • You will find it here:
  • Click the "Download" button. Make sure you do not by accident download any of the other programs advertised on that page.
  • Do not install it yet.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each of the Java versions.
    Close Add/Remove.

* In Windows Explorer, navigate to C:\Program Files\Java =this folder. Delete any subfolders.
* Do NOT delete C:\Program Files\ JavaVM =this folder, if found!
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u23-windows-i586.exe to install the newest version. NOTE: As always during installations, beware of any pre-checked option to install a toolbar. If you do not want it, UNcheck it.

Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.

To disable the JQS service if you don't want to use it:

* Go to Start-->Control Panel-->Java-->Advanced-->Miscellaneous and uncheck the box for Java Quick Starter.

* Click Ok and reboot your computer.

Open your Adobe Reader.  Go to Help > Check for Updates and download/install the latest version. Just follow the prompts.

Please let me know how things are running after that.

January 10th, 2011 16:00

Everything seems OK. It seems faster to. So I thank you for your help. Ill be back if I have more trouble.

January 10th, 2011 17:00

That's good news. You can delete Security Check and its log now.

After something like this it is a good idea to purge the Restore Points and start fresh.
If everything is running well....
To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)
Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.

Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.

Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.

If you have used Malwarebytes' Anti-Malware as part of your cleaning procedures, keep it updated and use it to scan every so often for malware, or upgrade to the paid version for realtime scanning and auto updating.

The following suggestions are general prevention and are not customized for your computer. You may have already taken some of these steps, and depending on your current security, you may not need to implement all of these:

1. Visit Microsoft Update: Make sure that you have all the Critical Updates recommended for your operating system, Office, and IE. The first defense against infection is a properly patched OS from Microsoft Update at More info HERE.

2. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.. Run a complete system scan with your anti-virus at least once a week...preferably in Safe mode.
If your anti-virus program is a paid/licensed version that is about to expire, you can consider removing it and using a free one such as:
Microsoft Security Essentials
AntiVir Personal Edition Classic
Avast! Home Edition

If you prefer not to use the Windows Firewall, there are several of the freeware Firewalls available on the public domain.

Please see this list for anti-virus, firewalls, and other FREE SECURITY SOFTWARE.

3. Using an alternate browser can reduce your chance of certain infections installing themselves. You might consider installing Mozilla / Firefox.

4. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.

5. Keep your software updated...make it easier on yourself and install the free security tool Secunia PSI .

6. If you have not already done so, you might want to install CCleaner and run it in each user's profile: ** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.

7. Web Of Trust , uses colored alerts to warn about risky websites warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:

  • Red for Warning = STOP
  • Yellow for Use Caution
  • Green for Safe
  • Grey for Unknown

There is a Web Of Trust version for Firefox as well.

8. If you still wish to use Internet Explorer, please make sure you install SpywareBlaster:
It will:
Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.
Block spyware/tracking cookies in Internet Explorer and Mozilla Firefox.
Restrict the actions of potentially unwanted sites in Internet Explorer.
Tutorial here:
Periodically check for updates.

9. You might want to install Winpatrol. Winpatrol is heuristic protection program, meaning it looks for patterns in codes that work like malware. It also takes a snapshot of your system's critical resources and alerts you to any changes that may occur without you knowing. You can read more about Winpatrol's features here.  You can download a free copy of Winpatrol or use the Plus version for more features.
You can read Winpatrol's FAQ if you run into problems.

10. Many of us in the online security community have tried and tested programs to determine their abilities. Please remember that there is no guarantee regarding computer security. However, the available software, combined with the rest of these recommendations will contribute to helping your system running safely.

Here are some helpful articles:
How did I get infected?  HERE

  I'm not pulling your leg, honest?
by Sandi Hardmeier  HERE

11. If you use Social Media (Facebook, Twitter, etc.) you can stay informed at SpywareHammer's Forum for Social Media Security

12. Check to be sure that you are not one of those people who is using a dangerously easy-to-guess password at websites requiring passwords. There is a good how-to video HERE.

Let us know if we have not resolved your problem. Otherwise, you are good to go.
Happy and Safe Surfing!


