Hi, per your request, attached is the results of the scans:
DDS (Ver_09-12-01.01) - NTFSx86
Run by Adam Soccorsi at 12:28:48.53 on Tue 03/16/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2558.2008 [GMT -4:00]
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Kodak\AiO\center\KodakSvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\ehome\RMSvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\1.2.183.17\GoogleCrashHandler.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Adam Soccorsi\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page =
hxxp://www.google.comuSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/iemStart Page =
hxxp://www.google.commDefault_Search_URL =
hxxp://www.google.com/iemSearch Page =
hxxp://www.google.comuInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.commSearchAssistant =
hxxp://www.google.commURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
uWinlogon: Shell=c:\documents and settings\adam soccorsi\application data\privacy center\ccmain.exe
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: Ask Toolbar: {fe063db9-4ec0-403e-8dd8-394c54984b2c} - c:\program files\asktbar\bar\1.bin\ASKTBAR.DLL
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [DeathAdder] c:\program files\razer\deathadder\razerhid.exe
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [ripohirev] Rundll32.exe "c:\windows\system32\sofodowi.dll",a
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
LSP: c:\windows\system32\imon.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cabDPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
hxxp://fpdownload.macromedia.com/get/fl ... rashim.cabDPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cabAppInit_DLLs: nusayuta.dll c:\windows\system32\sofodowi.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: zejateded - {255efa85-7439-45d6-9333-187f32d8e3b5} - c:\windows\system32\sofodowi.dll
STS: mujuzedij: {255efa85-7439-45d6-9333-187f32d8e3b5} - c:\windows\system32\sofodowi.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli pimimoso.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\adamso~1\applic~1\mozilla\firefox\profiles\b0ygk3a8.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/firefoxFF - prefs.js: keyword.URL -
hxxp://slirsredirect.search.aol.com/sli ... 706&query=FF - plugin: c:\documents and settings\adam soccorsi\application data\mozilla\firefox\profiles\b0ygk3a8.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1691.8062\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-9-27 15424]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\aio\center\KodakSvc.exe [2008-12-1 28672]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\McrdSvc.exe [2005-10-20 96256]
R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2008-9-27 552064]
R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2008-1-17 10880]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\EKDiscovery.exe [2008-10-10 274432]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-11-23 25832]
S4 gupdate1ca25f239b5547e;Google Update Service (gupdate1ca25f239b5547e);c:\program files\google\update\GoogleUpdate.exe [2009-8-25 133104]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-8-1 24652]
=============== Created Last 30 ================
2010-03-16 16:24:51 20 ----a-w- c:\documents and settings\adam soccorsi\defogger_reenable
2010-03-16 05:39:23 1 --sh--w- c:\windows\system32\kavumefe.dll
2010-03-15 05:39:13 1 --sh--w- c:\windows\system32\dukareyo.dll
2010-03-14 17:37:23 1 --sh--w- c:\windows\system32\kofipulo.dll
2010-02-22 04:15:52 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-02-22 04:15:52 34688 ----a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-02-22 04:15:51 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-02-22 04:15:51 8192 ----a-w- c:\windows\system32\dllcache\changer.sys
2010-02-22 04:15:14 0 d-----w- c:\docume~1\alluse~1\applic~1\94383633
2010-02-22 04:15:07 24 ----a-w- c:\docume~1\adamso~1\applic~1\cqfyto.dat
2010-02-22 04:15:02 4 ----a-w- c:\docume~1\adamso~1\applic~1\avdrn.dat
==================== Find3M ====================
2009-12-31 15:33:06 70656 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ------w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ------w- c:\windows\system32\dllcache\ieakui.dll
2009-08-22 23:14:14 19403 ----a-w- c:\program files\common files\esobika.sys
2009-08-22 23:11:29 16323 ----a-w- c:\program files\common files\zolula.inf
2009-08-22 23:11:29 13876 ----a-w- c:\program files\common files\telofim.dat
2009-08-22 23:11:29 10957 ----a-w- c:\program files\common files\lulokumi.bat
1601-01-01 00:03:28 69632 --sha-w- c:\windows\system32\divosewo.dll
1601-01-01 00:03:28 46080 --sha-w- c:\windows\system32\jajulaze.dll
1601-01-01 00:03:28 46080 --sha-w- c:\windows\system32\jinuwayi.dll
1601-01-01 00:03:28 47104 --sha-w- c:\windows\system32\keminazo.dll
1601-01-01 00:03:28 69632 --sha-w- c:\windows\system32\kuwovogi.dll
1601-01-01 00:03:28 100864 --sha-w- c:\windows\system32\lipegamu.dll
1601-01-01 00:03:28 97280 --sha-w- c:\windows\system32\lozaguje.dll
1601-01-01 00:03:52 60928 --sha-w- c:\windows\system32\nusayuta.dll
1601-01-01 00:03:52 60928 --sha-w- c:\windows\system32\pimimoso.dll
1601-01-01 00:03:28 70656 --sha-w- c:\windows\system32\royetuki.dll
1601-01-01 00:03:28 100864 --sha-w- c:\windows\system32\sarepelo.dll
1601-01-01 00:03:28 47104 --sha-w- c:\windows\system32\semasema.dll
1601-01-01 00:03:28 100352 --sha-w- c:\windows\system32\sofodowi.dll
1601-01-01 00:03:52 60928 --sha-w- c:\windows\system32\vetahadu.dll
1601-01-01 00:03:28 43008 --sha-w- c:\windows\system32\yejedotu.dll
1601-01-01 00:03:28 60928 --sha-w- c:\windows\system32\yirumuno.dll
1601-01-01 00:03:28 97280 --sha-w- c:\windows\system32\yizimife.dll
1601-01-01 00:03:28 44032 --sha-w- c:\windows\system32\yotewari.dll
2008-09-22 01:55:56 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092120080922\index.dat
============= FINISH: 12:29:44.31 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 12/22/2006 9:36:39 PM
System Uptime: 3/16/2010 12:25:45 PM (0 hours ago)
Motherboard: Dell Inc. | | 0WG855
Processor: Intel(R) Core(TM)2 CPU 6400 @ 2.13GHz | Microprocessor | 2128/1066mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 228 GiB total, 70.402 GiB free.
D: is CDROM ()
E: is FIXED (FAT32) - 931 GiB total, 923.394 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Hamachi Network Interface
Device ID: ROOT\NET\0000
Manufacturer: LogMeIn, Inc.
Name: Hamachi Network Interface
PNP Device ID: ROOT\NET\0000
Service: hamachi
==== System Restore Points ===================
RP1211: 12/17/2009 3:00:25 AM - Software Distribution Service 3.0
RP1212: 12/20/2009 7:05:18 PM - Software Distribution Service 3.0
RP1213: 12/20/2009 7:24:04 PM - Software Distribution Service 3.0
RP1214: 12/21/2009 3:00:14 AM - Software Distribution Service 3.0
RP1215: 12/22/2009 3:00:16 AM - Software Distribution Service 3.0
RP1216: 12/23/2009 3:00:18 AM - Software Distribution Service 3.0
RP1217: 12/24/2009 3:00:18 AM - Software Distribution Service 3.0
RP1218: 12/25/2009 3:00:16 AM - Software Distribution Service 3.0
RP1219: 12/25/2009 1:14:47 PM - Installed iTunes
RP1220: 12/25/2009 1:55:05 PM - Software Distribution Service 3.0
RP1221: 12/25/2009 1:59:38 PM - Software Distribution Service 3.0
RP1222: 12/26/2009 3:00:16 AM - Software Distribution Service 3.0
RP1223: 12/27/2009 3:00:16 AM - Software Distribution Service 3.0
RP1224: 12/28/2009 3:00:13 AM - Software Distribution Service 3.0
RP1225: 12/28/2009 8:27:57 PM - Software Distribution Service 3.0
RP1226: 12/29/2009 8:38:59 PM - System Checkpoint
RP1227: 12/30/2009 8:40:21 PM - System Checkpoint
RP1228: 12/31/2009 9:40:22 PM - System Checkpoint
RP1229: 1/1/2010 9:53:58 PM - System Checkpoint
RP1230: 1/2/2010 10:04:30 PM - System Checkpoint
RP1231: 1/3/2010 6:08:45 AM - Software Distribution Service 3.0
RP1232: 1/4/2010 6:47:47 AM - System Checkpoint
RP1233: 1/5/2010 7:47:43 AM - System Checkpoint
RP1234: 1/6/2010 7:48:49 AM - System Checkpoint
RP1235: 1/7/2010 8:47:54 AM - System Checkpoint
RP1236: 1/8/2010 8:55:15 AM - System Checkpoint
RP1237: 1/9/2010 9:47:56 AM - System Checkpoint
RP1238: 1/10/2010 10:47:50 AM - System Checkpoint
RP1239: 1/11/2010 11:47:54 AM - System Checkpoint
RP1240: 1/11/2010 10:08:35 PM - Installed DirectX
RP1241: 1/13/2010 12:15:15 AM - System Checkpoint
RP1242: 1/13/2010 11:05:34 PM - Software Distribution Service 3.0
RP1243: 1/14/2010 2:12:33 PM - Software Distribution Service 3.0
RP1244: 1/14/2010 11:12:38 PM - Software Distribution Service 3.0
RP1245: 1/15/2010 11:17:20 PM - System Checkpoint
RP1246: 1/16/2010 11:19:23 PM - System Checkpoint
RP1247: 1/18/2010 12:14:18 AM - System Checkpoint
RP1248: 1/19/2010 12:26:24 AM - System Checkpoint
RP1249: 1/20/2010 1:17:24 AM - System Checkpoint
RP1250: 1/21/2010 2:18:35 AM - System Checkpoint
RP1251: 1/21/2010 7:11:02 PM - Software Distribution Service 3.0
RP1252: 1/22/2010 7:17:52 PM - System Checkpoint
RP1253: 1/22/2010 7:24:50 PM - Installed DirectX
RP1254: 1/24/2010 2:34:30 AM - Software Distribution Service 3.0
RP1255: 1/25/2010 12:32:16 AM - Software Distribution Service 3.0
RP1256: 1/25/2010 7:43:41 PM - Software Distribution Service 3.0
RP1257: 1/26/2010 10:50:23 PM - System Checkpoint
RP1258: 1/28/2010 12:01:48 AM - System Checkpoint
RP1259: 1/29/2010 1:12:08 AM - System Checkpoint
RP1260: 1/29/2010 8:01:43 AM - Software Distribution Service 3.0
RP1261: 1/31/2010 5:47:51 PM - Installed DirectX
RP1262: 1/31/2010 5:48:55 PM - Removed Microsoft Visual C++ 2005 Redistributable
RP1263: 1/31/2010 5:49:45 PM - Removed Microsoft Visual C++ 2005 Redistributable
RP1264: 1/31/2010 5:50:18 PM - Installed Microsoft Visual C++ 2005 Redistributable
RP1265: 2/2/2010 12:43:28 AM - System Checkpoint
RP1266: 2/3/2010 12:45:23 AM - System Checkpoint
RP1267: 2/4/2010 1:20:55 AM - System Checkpoint
RP1268: 2/5/2010 1:44:22 AM - System Checkpoint
RP1269: 2/5/2010 6:25:09 PM - Installed DirectX
RP1270: 2/6/2010 6:27:57 PM - System Checkpoint
RP1271: 2/7/2010 6:44:28 PM - System Checkpoint
RP1272: 2/8/2010 8:00:50 PM - System Checkpoint
RP1273: 2/9/2010 8:14:04 PM - System Checkpoint
RP1274: 2/10/2010 2:48:29 PM - Installed DirectX
RP1275: 2/10/2010 2:50:09 PM - Installed DirectX
RP1276: 2/11/2010 2:53:52 PM - System Checkpoint
RP1277: 2/12/2010 6:12:21 PM - System Checkpoint
RP1278: 2/13/2010 2:03:26 PM - Installed DirectX
RP1279: 2/14/2010 10:27:46 PM - System Checkpoint
RP1280: 2/16/2010 12:14:19 AM - System Checkpoint
RP1281: 2/17/2010 12:53:54 AM - System Checkpoint
RP1282: 2/18/2010 1:54:03 AM - System Checkpoint
RP1283: 2/19/2010 2:53:58 AM - System Checkpoint
RP1284: 2/20/2010 3:54:00 AM - System Checkpoint
RP1285: 2/20/2010 2:08:05 PM - Installed DirectX
RP1286: 2/21/2010 7:13:27 PM - System Checkpoint
RP1287: 2/22/2010 9:01:19 PM - System Checkpoint
RP1288: 2/23/2010 10:28:15 PM - System Checkpoint
RP1289: 2/24/2010 3:33:29 PM - Removed Netflix Movie Viewer
RP1290: 2/25/2010 3:56:28 PM - System Checkpoint
RP1291: 2/26/2010 4:10:14 PM - System Checkpoint
RP1292: 2/27/2010 5:04:14 PM - System Checkpoint
RP1293: 2/28/2010 7:19:33 PM - System Checkpoint
RP1294: 3/1/2010 7:03:59 PM - Installed BioShock 2
RP1295: 3/2/2010 11:26:20 PM - System Checkpoint
RP1296: 3/4/2010 12:21:45 AM - System Checkpoint
RP1297: 3/5/2010 1:10:18 AM - System Checkpoint
RP1298: 3/6/2010 1:35:59 AM - System Checkpoint
RP1299: 3/7/2010 2:16:20 AM - System Checkpoint
RP1300: 3/7/2010 11:53:28 PM - Software Distribution Service 3.0
RP1301: 3/9/2010 12:05:52 AM - System Checkpoint
RP1302: 3/10/2010 12:46:30 AM - System Checkpoint
RP1303: 3/11/2010 1:23:38 AM - System Checkpoint
RP1304: 3/12/2010 1:57:28 AM - System Checkpoint
RP1305: 3/13/2010 3:14:07 AM - System Checkpoint
RP1306: 3/14/2010 1:25:52 PM - System Checkpoint
RP1307: 3/15/2010 2:21:36 PM - System Checkpoint
==== Installed Programs ======================
µTorrent
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.9
Adobe Shockwave Player
AIM Toolbar
aiofw
aioprnt
aioscnnr
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Audacity 1.2.6
AusLogics Disk Defrag
AutoUpdate
Azureus Vuze
Banctec Service Agreement
BioShock 2
Bonjour
Bonjour Core for Windows
BufferChm
Call of Duty(R) - World at War(TM) 1.1 Patch
CCleaner
center
Copy
Counter-Strike: Source
Critical Update for Windows Media Player 11 (KB959772)
Data Lifeguard Diagnostic for Windows
Dell CinePlayer
Dell Driver Reset Tool
Dell Support 3.2.1
Dell System Restore
Destination Component
DeviceDiscovery
Digital Content Portal
DivX Codec
DivX Converter
DivX Player
DivX Web Player
DJ_AIO_ProductContext
Documentation & Support Launcher
Dragon Age: Origins
F4100_Help
Free M4a to MP3 Converter 6.0
GCH Guitar academy
Google Earth
Google Update Helper
Google Updater
Goombah Partner COM Server
GTK+ 2.10.6-1 runtime environment
Hamachi 1.0.3.0
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB938759)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
HP Imaging Device Functions 9.0
HP Photosmart Essential
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Solution Center 9.0
HP Update
HPProductAssistant
HPSSupply
Impulse
Intel(R) Matrix Storage Manager
Intel(R) PRO Network Connections
Intel(R) Quick Resume Technology Drivers
Intel® Viiv™ Software
iTunes
J2SE Runtime Environment 5.0 Update 6
KODAK All-in-One Printer Software
ksDIP
Left 4 Dead
Logitech GamePanel Software 2.00
Magic DVD Copier Version 4.9 build 3
MagicDisc 2.7.105
Malwarebytes' Anti-Malware
Mass Effect
Mass Effect 2
MCU
Media Center Extender
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Project 2007 Service Pack 2 (SP2)
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business 2007
Microsoft Office Visio 2007 Service Pack 2 (SP2)
Microsoft Office Visio MUI (English) 2007
Microsoft Office Visio Professional 2007
Microsoft Office Word MUI (English) 2007
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft redistributable runtime DLLs VS2005(x86)
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual J# .NET Redistributable Package 1.1
Mozilla Firefox (3.0.2)
Mozilla Firefox (3.6)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
neroxml
NOD32 Antivirus System
NVIDIA Drivers
NVIDIA PhysX
PowerISO
PreReq
Privacy Center
PSSWCORE
QuickTime
Razer DeathAdder(TM) Mouse
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978262)
Sid Meier's Civilization 4
Sins of a Solar Empire
Sins of a Solar Empire - Entrenchment
Skype 3.0
Skype Plugin Manager
SolutionCenter
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
SoundTaxi 2.5.9
Star Wars Empire at War
Status
Steam
System Requirements Lab
System Shock2
The GIMP 2.2.13
The Lord of the Rings Online™: Shadows of Angmar™ v01.05.00.811
TrayApp
UnloadSupport
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Outlook 2007 Junk Email Filter (kb977719)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
Ventrilo Client
VideoLAN VLC media player 0.8.6e
VideoToolkit01
Viewpoint Media Player
Warhammer 40,000: Dawn of War II
WebFldrs XP
West Point Bridge Designer 2007
Winamp
Winamp Remote
Windows 7 Upgrade Advisor
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Presentation Foundation
Windows XP Media Center Edition 2005 KB905589
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
==== Event Viewer Messages From Past Week ========
3/15/2010 8:58:24 PM, error: Service Control Manager [7031] - The COM+ System Application service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
3/15/2010 7:25:31 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
3/15/2010 7:25:26 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/15/2010 7:25:20 PM, error: Service Control Manager [7034] - The Kodak AiO Device Service service terminated unexpectedly. It has done this 1 time(s).
3/15/2010 7:25:12 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
3/14/2010 12:26:02 PM, error: Service Control Manager [7001] - The Kodak AiO Network Discovery Service service depends on the Bonjour Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
3/14/2010 1:38:32 AM, error: Service Control Manager [7031] - The Media Center Extender Resource Monitor service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
3/14/2010 1:38:21 AM, error: Service Control Manager [7031] - The Media Center Extender Resource Monitor service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
3/14/2010 1:38:14 AM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s).
3/14/2010 1:38:07 AM, error: Service Control Manager [7031] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
3/14/2010 1:38:02 AM, error: Service Control Manager [7031] - The Media Center Extender Resource Monitor service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
3/14/2010 1:37:58 AM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
==== End Of File ===========================
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-03-16 15:13:21
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\ADAMSO~1\LOCALS~1\Temp\pxtoapow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs amon.sys (Amon monitor/Eset )
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 Elkbd.sys (Intel Corporation)
AttachedDevice \FileSystem\Fastfat \Fat amon.sys (Amon monitor/Eset )
---- Threads - GMER 1.0.15 ----
Thread System [4:204] 89C68298
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x85 0x60 0x8A 0x7C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xED 0xF2 0x8D 0x72 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x1F 0x67 0xE2 0x87 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBC 0xB2 0xB8 0x33 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x73 0x27 0x56 0x38 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x85 0x60 0x8A 0x7C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xED 0xF2 0x8D 0x72 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x1F 0x67 0xE2 0x87 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBC 0xB2 0xB8 0x33 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x73 0x27 0x56 0x38 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x30 0xFE 0x74 0x85 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xED 0xF2 0x8D 0x72 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x77 0x9D 0x39 0xBA ...
---- EOF - GMER 1.0.15 ----
Thanks for all your help.
-Adam-