Below are the results from the second run of scanning and hijackthis log.
<Begin TrendMicro Sysclean log>
/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
|
http://www.trendmicro.com |
\--------------------------------------------------------------/
2005-07-06, 22:52:20, Auto-clean mode specified.
2005-07-06, 22:52:20, Running scanner "C:\Documents and Settings\Todd\Desktop\TrendMicro\TSC.BIN"...
2005-07-06, 22:53:14, Scanner "C:\Documents and Settings\Todd\Desktop\TrendMicro\TSC.BIN" has finished running.
2005-07-06, 22:53:14, TSC Log:
2005-07-06, 22:53:31, Could not set file for reading on "C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp": Access is denied.
2005-07-06, 23:07:12, An error occurred while scanning file "C:\Documents and Settings\Todd\NTUSER.DAT": Access is denied.
2005-07-06, 23:07:12, An error occurred while scanning file "C:\Documents and Settings\Todd\ntuser.dat.LOG": Access is denied.
2005-07-06, 23:07:36, An error occurred while scanning file "C:\Documents and Settings\Todd\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Access is denied.
2005-07-06, 23:07:36, An error occurred while scanning file "C:\Documents and Settings\Todd\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Access is denied.
2005-07-06, 23:44:53, Could not set file for reading on "C:\WINDOWS\MEMORY.DMP": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB824141$\user32.dll": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB824141$\win32k.sys": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\html32.cnv": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\msconv97.dll": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe": Access is denied.
2005-07-06, 23:45:19, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\ole32.dll": Access is denied.
2005-07-06, 23:45:20, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll": Access is denied.
2005-07-06, 23:45:20, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll": Access is denied.
2005-07-06, 23:45:20, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\shell32.dll": Access is denied.
2005-07-06, 23:45:20, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\srv.sys": Access is denied.
2005-07-06, 23:45:20, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll": Access is denied.
2005-07-06, 23:45:20, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll": Access is denied.
2005-07-06, 23:45:31, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx": Access is denied.
2005-07-06, 23:45:31, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ828026$\wmp.dll": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\ACTIVATION.EXE-1E1C168C.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\ATI2MDXX.EXE-2A5FBD2A.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\ATIPTAXX.EXE-362CCF09.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\AUPATCH.DAT-16438FFC.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\AUPDATE.EXE-223E3682.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\AUTORUN.EXE-055703AF.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\AUUNZIP.DAT-2DB1FDF1.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\AUUPDATE.DAT-25C4984F.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\CCAPP.EXE-10E11A7C.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\CCPWDSVC.EXE-27405C8C.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\CCREGVFY.EXE-32D048B2.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\CHCP.COM-17EDBDC9.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-034B0549.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DADAPP.EXE-3517EEA8.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DADTRAY.EXE-1C249507.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-2858C7E2.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-38C3807C.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DIRECTCD.EXE-0582AB76.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DLG.EXE-332F77D1.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DSENTRY.EXE-28A3C4CF.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DUMPREP.EXE-0AF2BF67.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\DWWIN.EXE-2C373FB7.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\FTP.EXE-06C55CF9.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPSVC.EXE-1C192440.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-37930709.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\IES.EXE-2114FB03.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\IMAPI.EXE-201490BB.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\INSUTILS.EXE-1679A95C.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGON.SCR-24ADF392.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-312BE1BF.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\LUALL.EXE-288D30C1.pf": Access is denied.
2005-07-06, 23:50:56, Could not set file for reading on "C:\WINDOWS\Prefetch\LUCOMS~1.EXE-1DF6F3E9.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIEXEC.EXE-330626DC.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\MSMSGS.EXE-0620E8B3.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\NAVSTUB.EXE-0146EB7A.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\NAVW32.EXE-21393D56.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\NAVW32.EXE-21E86A90.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\NDETECT.EXE-2DABC14D.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\NMAIN.EXE-3A3D97F1.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\NOTEPAD.EXE-2F2D61E1.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\OSA.EXE-28494AD2.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\OUTLOOK.EXE-2D46ED9D.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\PATCH.EXE-1F0BC711.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\PDMJV.EXE-05B90F9E.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\PROPELAC.EXE-1A4A8696.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\PSPA.EXE-0610C6DF.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\QCONSOLE.EXE-1BC342DB.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\RASAUTOU.EXE-10B4F92F.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\REGEDIT.EXE-2AE3423E.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\ROOTKITREVEALER.EXE-320D9762.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-3DA75B89.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-4FF9832D.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-614D7FD5.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-67E85A51.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-6E8D4657.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\SNDMON.EXE-1C89C7E1.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\SSPIPES.SCR-111D20AE.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\SYNTPENH.EXE-2B70B91C.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\SYNTPLPR.EXE-0340D8DF.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSMON32.EXE-1040E1AD.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\TASKMGR.EXE-06144C13.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\TRAYCTL.EXE-30A5783A.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\TSC.EXE-009ED701.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\UPD.EXE-1912787E.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\URLMAP.EXE-2A71A1E4.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\USERINIT.EXE-0743FDA9.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\USRPRMPT.EXE-3B41CCA8.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\UZSHL.EXE-32580D30.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\WINWORD.EXE-0614BEA2.pf": Access is denied.
2005-07-06, 23:50:57, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-0D449B4F.pf": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\SAM": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\SECURITY": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM": Access is denied.
2005-07-06, 23:54:35, An error occurred while scanning file "C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG": Access is denied.
2005-07-06, 23:57:27, Running scanner "C:\Documents and Settings\Todd\Desktop\TrendMicro\VSCANTM.BIN"...
2005-07-07, 00:34:53, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 7/6/2005 23:57:28
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 715 (104247 Patterns) (2005/07/04) (271500)
Command Line: C:\Documents and Settings\Todd\Desktop\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Todd\Desktop\TrendMicro
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP124\A0034268.sys [TROJ_ROOTKIT.H]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP124\A0035267.sys [TROJ_ROOTKIT.H]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP124\A0036260.sys [TROJ_ROOTKIT.H]
C:\WINDOWS\SYSTEM32\msdirectx.sys [TROJ_ROOTKIT.H]
C:\WINDOWS\SYSTEM32\sysmon32.exe [WORM_RBOT.BPU]
48461 files have been read.
48461 files have been checked.
34400 files have been scanned.
46452 files have been scanned. (including files in archived)
5 files containing viruses.
Found 5 viruses totally.
Maybe 0 viruses totally.
Stop At : 7/7/2005 00:34:53
---------*---------*---------*---------*---------*---------*---------*---------*
2005-07-07, 00:34:53, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 7/6/2005 23:57:28
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 715 (104247 Patterns) (2005/07/04) (271500)
Command Line: C:\Documents and Settings\Todd\Desktop\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Todd\Desktop\TrendMicro
Success Clean [ TROJ_ROOTKIT.H]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP124\A0034268.sys
Success Clean [ TROJ_ROOTKIT.H]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP124\A0035267.sys
Success Clean [ TROJ_ROOTKIT.H]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP124\A0036260.sys
Success Clean [ TROJ_ROOTKIT.H]( 1) from C:\WINDOWS\SYSTEM32\msdirectx.sys
48461 files have been read.
48461 files have been checked.
34400 files have been scanned.
46452 files have been scanned. (including files in archived)
5 files containing viruses.
Found 5 viruses totally.
Maybe 0 viruses totally.
Stop At : 7/7/2005 00:34:53 37 minutes 18 seconds (2238.25 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-07-07, 00:34:53, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 7/6/2005 23:57:28
VSAPI Engine Version : 7.510-1002
VSCANTM Version : 1.1-1001
Virus Pattern Version : 715 (104247 Patterns) (2005/07/04) (271500)
Command Line: C:\Documents and Settings\Todd\Desktop\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\Todd\Desktop\TrendMicro
48461 files have been read.
48461 files have been checked.
34400 files have been scanned.
46452 files have been scanned. (including files in archived)
5 files containing viruses.
Found 5 viruses totally.
Maybe 0 viruses totally.
Stop At : 7/7/2005 00:34:53 37 minutes 18 seconds (2238.25 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2005-07-07, 00:34:53, Scanner "C:\Documents and Settings\Todd\Desktop\TrendMicro\VSCANTM.BIN" has finished running.
<End TrendMicro sysclean log>
<Begin result of Norton Antivirus system scan>
One Virus found: Hacktool.Rootkit
Source: C:\WINDOWS\System32\msdirectx.sys
Repair failed, access to file denied. Note that I still get this warning from Norton AV autoprotect.
<End result of Norton Antivirus system scan>
<Begin result of RootkitRevealer>
No discrepancies were found
<Begin result of RootkitRevealer>
<Begin result of hijackthis post-run log>
Logfile of HijackThis v1.99.1
Scan saved at 7:28:12 AM, on 7/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\LocalNet Express 2.0\PropelAC.exe
C:\Program Files\CASIO\PC Connect for CASSIOPEIA\pclstart.exe
C:\Program Files\UltimateZip 2.7\uzqkst.exe
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.earthlink.net/partner/mor...on/search.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.dellnet.com/
F2 - REG:system.ini: Shell=Explorer.exe sysmon32.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\LocalNet Express 2.0\prpl_IePopupBlocker.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\LocalNet Express 2.0\trayctl.exe" /STARTUPLAUNCH
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: UltimateZip Quick Start.lnk = C:\Program Files\UltimateZip 2.7\uzqkst.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PC Connect for CASSIOPEIA starter.lnk = ?
O8 - Extra context menu item: Allow pop-ups from this site - C:\Program Files\LocalNet Express 2.0\pac-addwl.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\LocalNet Express 2.0\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\LocalNet Express 2.0\pac-image.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: CWQJWON - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\Todd\LOCALS~1\Temp\CWQJWON.exe
O23 - Service: EWXUXYXFY - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\Todd\LOCALS~1\Temp\EWXUXYXFY.exe
O23 - Service: IAFP - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\Todd\LOCALS~1\Temp\IAFP.exe
O23 - Service: IES - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\Todd\LOCALS~1\Temp\IES.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LGVUPEI - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\Todd\LOCALS~1\Temp\LGVUPEI.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: PCM - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\Todd\LOCALS~1\Temp\PCM.exe
O23 - Service: PDMJV - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\Todd\LOCALS~1\Temp\PDMJV.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: XXXEQZVOW - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\Todd\LOCALS~1\Temp\XXXEQZVOW.exe
<End result of hijackthis post-run log>
Thanks again for your help! I'm going to bring this computer into work today so that I can work through this issue more quickly.
Todd