PDA

View Full Version : Virtumode infection



PKalico
2008-01-21, 22:59
Here is my Hijack this log. I ran the Kaspersky but the log was too long to post. Before I created an account to post I looked over other posts and ran the combofix first so I don't know how this has affected the problem I was having. After logging in and reading the "Before You Post" thread I did everything it recommended which has gotten me to this point. I haven't noticed anymore pop-ups opening on me since I did everything but I just want to make sure I am clean of this stupid thing. Looking forward to your help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:34 AM, on 1/21/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Peggle/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-trial-mind-medley/gamehouseplayer.cab
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {C9D7D239-B502-48B3-BA25-9DF8C7264073} (CCAWebLogin Control) - https://199.5.206.34/auth/CCALogin.CAB
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Peggle/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 13920 bytes

steamwiz
2008-01-22, 00:13
Hi

You shouldn't have run Combofix until we asked you to, but as you have, then that is the log we need to see.

Also the Kaspersky log will have a header like this :-

Scan Statistics:
Total number of scanned objects: 60605
Number of viruses found: 7
Number of infected objects: 33
Number of suspicious objects: 0

If you search the log for all instances of the word infected then just post those lines, that's all we need to see,

Your hijackthis log is clean

steam

PKalico
2008-01-22, 00:34
The logs are from before I ran the HJT. I am posting the results that I received. If you would you like new ones let me know.

ComboFix 08-01-20.1 - odcustomer 2008-01-20 20:29:03.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.998 [GMT -5:00]
Running from: C:\Users\odcustomer\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\system32\ddccbbc.dll
C:\Windows\system32\fvcpbmei.dll
C:\Windows\system32\gebbbcc.dll
C:\Windows\System32\iembpcvf.ini
C:\Windows\system32\qomno.dll
C:\Windows\System32\ruvut.ini
C:\Windows\System32\ruvut.ini2
C:\Windows\system32\tuvur.dll
C:\Windows\system32\x64
H:\Autorun.inf

----- Unknown downloads made by BITS: ----
http://epg.tvdownload.microsoft.com
.
((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-20 20:23 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-20 20:07 . 2008-01-20 20:07 88 --a------ C:\Windows\wininit.ini
2008-01-20 17:25 . 2008-01-20 20:02 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-20 17:25 . 2008-01-20 20:02 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-01-19 21:39 . 2008-01-19 21:39 <DIR> d-------- C:\Users\All Users\Yahoo! Companion
2008-01-19 21:39 . 2008-01-19 21:39 <DIR> d-------- C:\ProgramData\Yahoo! Companion
2008-01-19 12:39 . 2008-01-19 12:39 23,040 --a------ C:\Windows\System32\winnzy32.dll
2008-01-19 12:37 . 2008-01-19 12:37 <DIR> d-------- C:\Users\All Users\Macrovision
2008-01-19 12:37 . 2008-01-19 12:37 <DIR> d-------- C:\ProgramData\Macrovision
2008-01-19 12:36 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
2008-01-19 12:36 . 2003-07-30 18:28 974,848 --a------ C:\Windows\System32\mfc70.dll
2008-01-19 12:36 . 2003-07-30 18:28 487,424 --a------ C:\Windows\System32\msvcp70.dll
2008-01-19 12:36 . 2003-07-30 18:28 344,064 --a------ C:\Windows\System32\msvcr70.dll
2008-01-19 12:35 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-01-19 12:32 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Macromedia
2008-01-19 12:05 . 2008-01-20 08:26 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\LimeWire
2008-01-19 12:03 . 2008-01-19 12:03 <DIR> d-------- C:\Program Files\LimeWire
2008-01-13 16:26 . 2008-01-13 16:26 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-13 16:26 . 2008-01-13 16:26 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-13 16:26 . 2008-01-13 16:26 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-13 16:26 . 2008-01-13 16:26 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-13 16:26 . 2008-01-13 16:26 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-13 16:26 . 2008-01-13 16:26 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-13 16:26 . 2008-01-13 16:26 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-13 16:26 . 2008-01-13 16:26 25,656 --a------ C:\Windows\System32\drivers\msahci.sys
2008-01-13 16:26 . 2008-01-13 16:26 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-13 16:26 . 2008-01-13 16:26 17,464 --a------ C:\Windows\System32\drivers\intelide.sys
2008-01-09 03:02 . 2008-01-09 03:02 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-09 03:02 . 2008-01-09 03:02 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-09 03:02 . 2008-01-09 03:02 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-09 03:02 . 2008-01-09 03:02 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-09 03:02 . 2008-01-09 03:02 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-09 03:01 . 2008-01-09 03:01 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-01-01 22:59 . 2008-01-01 22:59 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\MechCAD
2008-01-01 22:59 . 2008-01-01 23:16 <DIR> d-------- C:\Program Files\AceMoney
2007-12-31 10:33 . 2007-12-31 10:33 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\.purple
2007-12-31 10:31 . 2008-01-01 09:50 <DIR> d-------- C:\Program Files\Pidgin
2007-12-31 10:30 . 2007-12-31 10:30 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-12-30 15:54 . 2007-12-30 16:04 <DIR> d-------- C:\Program Files\BearFlix Applications
2007-12-30 15:53 . 2007-12-30 16:04 <DIR> d-------- C:\Program Files\BearFlix
2007-12-30 14:07 . 2007-10-18 08:51 172,032 --a------ C:\Windows\System32\igfxres.dll
2007-12-27 10:13 . 2008-01-20 20:40 373,392,862 --a------ C:\Windows\MEMORY.DMP
2007-12-26 23:10 . 2007-12-26 23:10 364,544 --a------ C:\Windows\System32\WDBtnMgr.exe
2007-12-26 23:08 . 2007-12-26 23:08 <DIR> d-------- C:\Program Files\Western Digital Technologies
2007-12-26 22:49 . 2008-01-19 12:44 <DIR> d-------- C:\Program Files\StorageSync
2007-12-22 11:23 . 2007-12-22 11:23 <DIR> d-------- C:\Users\All Users\LightScribe
2007-12-22 11:23 . 2007-12-22 11:23 <DIR> d-------- C:\ProgramData\LightScribe
2007-12-22 11:07 . 2007-12-22 11:09 <DIR> d--h----- C:\Windows\msdownld.tmp
2007-12-22 11:05 . 2007-12-22 11:05 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2007-12-22 10:58 . 2007-12-31 10:40 <DIR> d-------- C:\Program Files\Free WMA to MP3 Converter
2007-12-22 10:32 . 2007-12-22 10:33 <DIR> d-------- C:\Users\Ryan\AppData\Roaming\Roxio

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 01:29 --------- d-----w C:\Program Files\MSN Messenger
2008-01-20 23:58 --------- d-----w C:\ProgramData\Symantec
2008-01-20 15:58 --------- d-----w C:\ProgramData\Google Updater
2008-01-20 02:40 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Yahoo!
2008-01-20 02:36 --------- d-----w C:\ProgramData\Yahoo!
2008-01-20 02:36 --------- d-----w C:\Program Files\Yahoo!
2008-01-19 23:00 --------- d-----w C:\ProgramData\Roxio
2008-01-19 23:00 --------- d-----w C:\Program Files\Roxio
2008-01-19 22:59 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-01-19 22:53 --------- d-----w C:\ProgramData\Lavasoft
2008-01-19 17:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-19 17:24 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-13 22:29 --------- d-----w C:\Program Files\Windows Mail
2008-01-13 21:26 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-13 21:26 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-13 21:26 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-13 21:26 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-09 08:01 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-06 14:53 --------- d-----w C:\Users\Ryan\AppData\Roaming\HP
2007-12-31 15:34 206 ----a-w C:\Users\odcustomer\AppData\Roaming\wklnhst.dat
2007-12-31 15:33 --------- d-----w C:\Users\odcustomer\AppData\Roaming\.purple
2007-12-29 16:45 --------- d-----w C:\Program Files\Windows Defender
2007-12-29 16:45 --------- d-----w C:\Program Files\Windows Calendar
2007-12-29 16:14 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-12-29 16:14 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-12-29 16:14 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-12-29 16:14 2,923,520 ----a-w C:\Windows\explorer.exe
2007-12-29 16:14 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-12-29 16:14 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys
2007-12-22 23:40 --------- d-----w C:\Program Files\Norton Internet Security
2007-12-16 04:07 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Template
2007-12-16 04:01 --------- d-----w C:\Users\odcustomer\AppData\Roaming\InstallShield
2007-12-14 22:12 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-14 21:59 --------- d-----w C:\Program Files\Common Files\LightScribe
2007-12-14 21:52 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Hewlett-Packard
2007-12-14 21:42 0 --sha-r C:\Windows\system32\drivers\103C_HP_cNB_Pavilion dv6000 (GA378UA#ABA)_Y5335KV_0U_QCNF72858F5_E447502-001_4A_I30BB_SQuanta_V66.40_F.29_T071113_WV3-0_L409_M2038_J160_7Intel_86EC_92.00_#070809_N80861092;80864222_(GA378UA#ABA)_XMOBILE_CN10_Z.MRK
2007-12-14 02:42 --------- d-----w C:\Users\Ryan\AppData\Roaming\Symantec
2007-12-14 02:42 --------- d-----w C:\Users\Ryan\AppData\Roaming\MySpace
2007-12-12 21:40 174 --sha-w C:\Program Files\desktop.ini
2007-12-12 03:01 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2007-12-12 03:01 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2007-12-12 03:01 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2007-12-12 03:01 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2007-12-12 03:01 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2007-12-12 02:53 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-12-12 02:53 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-12-12 02:53 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-12-12 02:53 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2007-12-12 02:53 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-12-12 02:53 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-12-12 02:53 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-12 02:51 82,432 ----a-w C:\Windows\system32\drivers\sdbus.sys
2007-12-12 02:45 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 02:44 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2007-12-12 02:36 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-12 02:36 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-12 02:36 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-12 02:36 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 02:33 --------- d-----w C:\Program Files\CONEXANT
2007-12-08 19:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-08 14:43 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2007-12-08 14:43 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2007-12-08 14:43 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2007-12-08 14:43 --------- d-----w C:\Program Files\Symantec
2007-12-01 04:57 43,696 ----a-w C:\Windows\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 ----a-w C:\Windows\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 ----a-w C:\Windows\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 ----a-w C:\Windows\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 ----a-w C:\Windows\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 ----a-w C:\Windows\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 ----a-w C:\Windows\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 ----a-w C:\Windows\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 ----a-w C:\Windows\system32\drivers\srtsp.inf
2007-11-28 04:53 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Symantec
2007-11-27 01:44 --------- d-----w C:\ProgramData\GameHouse
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 22:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2007-11-27 23:50 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 22:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 03:01 1232896]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [ ]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-29 11:14 1006264]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [ ]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 13:38 159744]
"HP Health Check Scheduler"="[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [ ]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 15:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 18:12 317128]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [ ]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [ ]
"StrgSync.exe"="C:\Program Files\StorageSync\StrgSync.exe" [ ]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [ ]
"Persistence"="C:\Windows\system32\igfxpers.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]

C:\Users\odcustomer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-01-10 13:08:24 147456]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-10-01 07:58:15 126136]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-02 20:40:10 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080116.003\IDSvix86.sys [2007-11-06 11:07]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 06:27]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-10-18 09:05]
R3 moufiltr;Mouse Filter;C:\Windows\system32\DRIVERS\moufiltr.sys [2007-01-09 09:22]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-21 11:51]
R3 SymIMMP;SymIMMP;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-08-13 15:50]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 02:30]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2007-02-07 16:15]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11d59101-760d-11dc-a300-001b246ad1bd}]
\shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 22:10:05 C:\Windows\Tasks\HPCeeScheduleForodcustomer.job"
- C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe
"2008-01-16 01:12:03 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - odcustomer.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-21 01:45:35 C:\Windows\Tasks\User_Feed_Synchronization-{2C866FF7-7A81-4853-8801-7A62DBA88F61}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 20:41:51
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 20:47:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-21 01:47:52
.
2008-01-13 21:27:43 --- E O F ---


----Kaspersky Scan--------------------------------------
Scan Statistics:
Total number of scanned objects: 166525
Number of viruses found: 3
Number of infected objects: 5
Number of suspicious objects: 0
Duration of the scan process: 02:05:10
C:\QooBox\Quarantine\C\Windows\System32\ddccbbc.dll.vir Infected: Trojan-Downloader.Win32.Small.htk skipped
C:\QooBox\Quarantine\C\Windows\System32\gebbbcc.dll.vir Infected: Trojan-Downloader.Win32.Small.htk skipped
C:\Windows\System32\winnzy32.dll Infected: Trojan.Win32.Dialer.yz skipped
H:\Heathers Documents\My Music\Rare Recording (jenna).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
H:\Heathers Documents\My Music\TOTALLY HIP TRACK (jenna).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped

PKalico
2008-01-22, 00:36
Sorry about jumping the gun. The logs are from before I ran the HJT. I am posting the results that I received. If you would you like new ones let me know.

ComboFix 08-01-20.1 - odcustomer 2008-01-20 20:29:03.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.998 [GMT -5:00]
Running from: C:\Users\odcustomer\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\system32\ddccbbc.dll
C:\Windows\system32\fvcpbmei.dll
C:\Windows\system32\gebbbcc.dll
C:\Windows\System32\iembpcvf.ini
C:\Windows\system32\qomno.dll
C:\Windows\System32\ruvut.ini
C:\Windows\System32\ruvut.ini2
C:\Windows\system32\tuvur.dll
C:\Windows\system32\x64
H:\Autorun.inf

----- Unknown downloads made by BITS: ----
http://epg.tvdownload.microsoft.com
.
((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-20 20:23 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-20 20:07 . 2008-01-20 20:07 88 --a------ C:\Windows\wininit.ini
2008-01-20 17:25 . 2008-01-20 20:02 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-20 17:25 . 2008-01-20 20:02 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-01-19 21:39 . 2008-01-19 21:39 <DIR> d-------- C:\Users\All Users\Yahoo! Companion
2008-01-19 21:39 . 2008-01-19 21:39 <DIR> d-------- C:\ProgramData\Yahoo! Companion
2008-01-19 12:39 . 2008-01-19 12:39 23,040 --a------ C:\Windows\System32\winnzy32.dll
2008-01-19 12:37 . 2008-01-19 12:37 <DIR> d-------- C:\Users\All Users\Macrovision
2008-01-19 12:37 . 2008-01-19 12:37 <DIR> d-------- C:\ProgramData\Macrovision
2008-01-19 12:36 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
2008-01-19 12:36 . 2003-07-30 18:28 974,848 --a------ C:\Windows\System32\mfc70.dll
2008-01-19 12:36 . 2003-07-30 18:28 487,424 --a------ C:\Windows\System32\msvcp70.dll
2008-01-19 12:36 . 2003-07-30 18:28 344,064 --a------ C:\Windows\System32\msvcr70.dll
2008-01-19 12:35 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-01-19 12:32 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Macromedia
2008-01-19 12:05 . 2008-01-20 08:26 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\LimeWire
2008-01-19 12:03 . 2008-01-19 12:03 <DIR> d-------- C:\Program Files\LimeWire
2008-01-13 16:26 . 2008-01-13 16:26 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-13 16:26 . 2008-01-13 16:26 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-13 16:26 . 2008-01-13 16:26 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-13 16:26 . 2008-01-13 16:26 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-13 16:26 . 2008-01-13 16:26 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-13 16:26 . 2008-01-13 16:26 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-13 16:26 . 2008-01-13 16:26 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-13 16:26 . 2008-01-13 16:26 25,656 --a------ C:\Windows\System32\drivers\msahci.sys
2008-01-13 16:26 . 2008-01-13 16:26 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-13 16:26 . 2008-01-13 16:26 17,464 --a------ C:\Windows\System32\drivers\intelide.sys
2008-01-09 03:02 . 2008-01-09 03:02 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-09 03:02 . 2008-01-09 03:02 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-09 03:02 . 2008-01-09 03:02 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-09 03:02 . 2008-01-09 03:02 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-09 03:02 . 2008-01-09 03:02 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-09 03:01 . 2008-01-09 03:01 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-01-01 22:59 . 2008-01-01 22:59 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\MechCAD
2008-01-01 22:59 . 2008-01-01 23:16 <DIR> d-------- C:\Program Files\AceMoney
2007-12-31 10:33 . 2007-12-31 10:33 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\.purple
2007-12-31 10:31 . 2008-01-01 09:50 <DIR> d-------- C:\Program Files\Pidgin
2007-12-31 10:30 . 2007-12-31 10:30 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-12-30 15:54 . 2007-12-30 16:04 <DIR> d-------- C:\Program Files\BearFlix Applications
2007-12-30 15:53 . 2007-12-30 16:04 <DIR> d-------- C:\Program Files\BearFlix
2007-12-30 14:07 . 2007-10-18 08:51 172,032 --a------ C:\Windows\System32\igfxres.dll
2007-12-27 10:13 . 2008-01-20 20:40 373,392,862 --a------ C:\Windows\MEMORY.DMP
2007-12-26 23:10 . 2007-12-26 23:10 364,544 --a------ C:\Windows\System32\WDBtnMgr.exe
2007-12-26 23:08 . 2007-12-26 23:08 <DIR> d-------- C:\Program Files\Western Digital Technologies
2007-12-26 22:49 . 2008-01-19 12:44 <DIR> d-------- C:\Program Files\StorageSync
2007-12-22 11:23 . 2007-12-22 11:23 <DIR> d-------- C:\Users\All Users\LightScribe
2007-12-22 11:23 . 2007-12-22 11:23 <DIR> d-------- C:\ProgramData\LightScribe
2007-12-22 11:07 . 2007-12-22 11:09 <DIR> d--h----- C:\Windows\msdownld.tmp
2007-12-22 11:05 . 2007-12-22 11:05 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2007-12-22 10:58 . 2007-12-31 10:40 <DIR> d-------- C:\Program Files\Free WMA to MP3 Converter
2007-12-22 10:32 . 2007-12-22 10:33 <DIR> d-------- C:\Users\Ryan\AppData\Roaming\Roxio

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 01:29 --------- d-----w C:\Program Files\MSN Messenger
2008-01-20 23:58 --------- d-----w C:\ProgramData\Symantec
2008-01-20 15:58 --------- d-----w C:\ProgramData\Google Updater
2008-01-20 02:40 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Yahoo!
2008-01-20 02:36 --------- d-----w C:\ProgramData\Yahoo!
2008-01-20 02:36 --------- d-----w C:\Program Files\Yahoo!
2008-01-19 23:00 --------- d-----w C:\ProgramData\Roxio
2008-01-19 23:00 --------- d-----w C:\Program Files\Roxio
2008-01-19 22:59 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-01-19 22:53 --------- d-----w C:\ProgramData\Lavasoft
2008-01-19 17:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-19 17:24 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-13 22:29 --------- d-----w C:\Program Files\Windows Mail
2008-01-13 21:26 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-13 21:26 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-13 21:26 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-13 21:26 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-09 08:01 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-06 14:53 --------- d-----w C:\Users\Ryan\AppData\Roaming\HP
2007-12-31 15:34 206 ----a-w C:\Users\odcustomer\AppData\Roaming\wklnhst.dat
2007-12-31 15:33 --------- d-----w C:\Users\odcustomer\AppData\Roaming\.purple
2007-12-29 16:45 --------- d-----w C:\Program Files\Windows Defender
2007-12-29 16:45 --------- d-----w C:\Program Files\Windows Calendar
2007-12-29 16:14 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-12-29 16:14 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-12-29 16:14 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-12-29 16:14 2,923,520 ----a-w C:\Windows\explorer.exe
2007-12-29 16:14 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-12-29 16:14 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys
2007-12-22 23:40 --------- d-----w C:\Program Files\Norton Internet Security
2007-12-16 04:07 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Template
2007-12-16 04:01 --------- d-----w C:\Users\odcustomer\AppData\Roaming\InstallShield
2007-12-14 22:12 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-14 21:59 --------- d-----w C:\Program Files\Common Files\LightScribe
2007-12-14 21:52 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Hewlett-Packard
2007-12-14 21:42 0 --sha-r C:\Windows\system32\drivers\103C_HP_cNB_Pavilion dv6000 (GA378UA#ABA)_Y5335KV_0U_QCNF72858F5_E447502-001_4A_I30BB_SQuanta_V66.40_F.29_T071113_WV3-0_L409_M2038_J160_7Intel_86EC_92.00_#070809_N80861092;80864222_(GA378UA#ABA)_XMOBILE_CN10_Z.MRK
2007-12-14 02:42 --------- d-----w C:\Users\Ryan\AppData\Roaming\Symantec
2007-12-14 02:42 --------- d-----w C:\Users\Ryan\AppData\Roaming\MySpace
2007-12-12 21:40 174 --sha-w C:\Program Files\desktop.ini
2007-12-12 03:01 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2007-12-12 03:01 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2007-12-12 03:01 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2007-12-12 03:01 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2007-12-12 03:01 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2007-12-12 02:53 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-12-12 02:53 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-12-12 02:53 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-12-12 02:53 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2007-12-12 02:53 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-12-12 02:53 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-12-12 02:53 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-12 02:51 82,432 ----a-w C:\Windows\system32\drivers\sdbus.sys
2007-12-12 02:45 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 02:44 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2007-12-12 02:36 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-12 02:36 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-12 02:36 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-12 02:36 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 02:33 --------- d-----w C:\Program Files\CONEXANT
2007-12-08 19:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-08 14:43 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2007-12-08 14:43 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2007-12-08 14:43 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2007-12-08 14:43 --------- d-----w C:\Program Files\Symantec
2007-12-01 04:57 43,696 ----a-w C:\Windows\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 ----a-w C:\Windows\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 ----a-w C:\Windows\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 ----a-w C:\Windows\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 ----a-w C:\Windows\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 ----a-w C:\Windows\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 ----a-w C:\Windows\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 ----a-w C:\Windows\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 ----a-w C:\Windows\system32\drivers\srtsp.inf
2007-11-28 04:53 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Symantec
2007-11-27 01:44 --------- d-----w C:\ProgramData\GameHouse
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 22:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2007-11-27 23:50 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 22:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 03:01 1232896]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [ ]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-29 11:14 1006264]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [ ]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 13:38 159744]
"HP Health Check Scheduler"="[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [ ]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 15:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 18:12 317128]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [ ]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [ ]
"StrgSync.exe"="C:\Program Files\StorageSync\StrgSync.exe" [ ]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [ ]
"Persistence"="C:\Windows\system32\igfxpers.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]

C:\Users\odcustomer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-01-10 13:08:24 147456]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-10-01 07:58:15 126136]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-02 20:40:10 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080116.003\IDSvix86.sys [2007-11-06 11:07]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 06:27]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-10-18 09:05]
R3 moufiltr;Mouse Filter;C:\Windows\system32\DRIVERS\moufiltr.sys [2007-01-09 09:22]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-21 11:51]
R3 SymIMMP;SymIMMP;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-08-13 15:50]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 02:30]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2007-02-07 16:15]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11d59101-760d-11dc-a300-001b246ad1bd}]
\shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 22:10:05 C:\Windows\Tasks\HPCeeScheduleForodcustomer.job"
- C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe
"2008-01-16 01:12:03 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - odcustomer.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-21 01:45:35 C:\Windows\Tasks\User_Feed_Synchronization-{2C866FF7-7A81-4853-8801-7A62DBA88F61}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 20:41:51
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 20:47:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-21 01:47:52
.
2008-01-13 21:27:43 --- E O F ---


----Kaspersky Scan--------------------------------------
Scan Statistics:
Total number of scanned objects: 166525
Number of viruses found: 3
Number of infected objects: 5
Number of suspicious objects: 0
Duration of the scan process: 02:05:10
C:\QooBox\Quarantine\C\Windows\System32\ddccbbc.dll.vir Infected: Trojan-Downloader.Win32.Small.htk skipped
C:\QooBox\Quarantine\C\Windows\System32\gebbbcc.dll.vir Infected: Trojan-Downloader.Win32.Small.htk skipped
C:\Windows\System32\winnzy32.dll Infected: Trojan.Win32.Dialer.yz skipped
H:\Heathers Documents\My Music\Rare Recording (jenna).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
H:\Heathers Documents\My Music\TOTALLY HIP TRACK (jenna).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped

steamwiz
2008-01-22, 01:36
Hi

Please delete the following :-

C:\QooBox ... folder

C:\Windows\System32\winnzy32.dll ... file

H:\Heathers Documents\My Music\Rare Recording (jenna).wma ... file

H:\Heathers Documents\My Music\TOTALLY HIP TRACK (jenna).wma ... file

Then your logs are clean...

steam

PKalico
2008-01-22, 01:50
Thank you for your help.

steamwiz
2008-01-22, 02:45
You're welcome :)

Happy surfing

steam