View Full Version : major malware problems
cinthetik
2009-04-11, 10:05
hello. like to start off by saying i've been using spybot for a long time and recommended it to alot of people. its a great program! ok so i've been sharing a computer with my roomate(it's her) and unfortunately ever time i go outta town she seems to get something new on the unit. this time it was pretty bad. i ran a scan with nod32, (because the f-secure we get from our isp totally missed everything) and it looks like these are the three main entries from that.
4/11/2009 1:36:19 AM Real-time file system protection file C:\WINDOWS\system32\arulasad.tmp Win32/Adware.Virtumonde.NEO application cleaned by deleting - quarantined KAHNS\Compaq_Administrator Event occurred on a new file created by the application: C:\WINDOWS\explorer.exe.
4/10/2009 4:55:35 PM Real-time file system protection file C:\WINDOWS\system32\lulihuni.exe probably a variant of Win32/TrojanDownloader.Small.EDB trojan cleaned by deleting - quarantined KAHNS\Compaq_Administrator Event occurred on a new file created by the application: C:\WINDOWS\explorer.exe.
4/9/2009 3:32:02 AM Real-time file system protection file C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP229\A0045476.exe probably unknown NewHeur_PE virus deleted - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\svchost.exe.
4/8/2009 4:13:39 PM Real-time file system protection file C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP229\A0045475.exe Win32/Adware.Toolbar.Dealio application cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\system32\svchost.exe.
i ran spybot s&d like he post befor thread instructed, and here is he HJT log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:59:14 AM, on 4/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {a660fb53-a7f4-447b-8c0e-39e990f5b9b9} - C:\WINDOWS\system32\duduhahi.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - (no file)
O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [nuzifijiya] Rundll32.exe "C:\WINDOWS\system32\kahufeto.dll",s
O4 - HKLM\..\Run: [CPMf3ac2887] Rundll32.exe "c:\windows\system32\holuyibi.dll",a
O4 - HKLM\..\Run: [f09f1b1b] rundll32.exe "C:\WINDOWS\system32\dasalura.dll",b
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [nuzifijiya] Rundll32.exe "C:\WINDOWS\system32\kahufeto.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [nuzifijiya] Rundll32.exe "C:\WINDOWS\system32\kahufeto.dll",s (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://charter.net/files/charter/securitysuite/fscax.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\bakovoti.dll c:\windows\system32\holuyibi.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\holuyibi.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\holuyibi.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 10139 bytes
Also note that, right befor i went outta town... i had used nod32 to get the new_heur pe off the system, and i thought it was gone... then the machine wanted to upgrade to service pack 3, so i did it... and then when i came back from outta town i noticed the new_heur pe again in the nod32 log.... i've read alittle about it, but im not exactly sure how to go about totally getting rid of it. any help would be awesome!
Hi there,
Download DDS and save it to your desktop from here (http://www.techsupportforum.com/sectools/sUBs/dds) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt
Save both reports to your desktop. Post them back to your topic.
cinthetik
2009-04-12, 21:33
Hey Blade81. Thanks for your reply. here's those two logs from dds.
DDS (Ver_09-03-16.01) - NTFSx86
Run by Compaq_Administrator at 13:25:11.25 on Sun 04/12/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.530 [GMT -5:00]
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Robz Shit\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: {a660fb53-a7f4-447b-8c0e-39e990f5b9b9} - c:\windows\system32\duduhahi.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {D0943516-5076-4020-A3B5-AEFAF26AB263} - No File
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRunOnce: [SpybotDeletingB8606] command.com /c del "c:\windows\system32\jujutoji.dll_old"
uRunOnce: [SpybotDeletingD3102] cmd.exe /c del "c:\windows\system32\jujutoji.dll_old"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [nuzifijiya] Rundll32.exe "c:\windows\system32\kahufeto.dll",s
mRun: [f09f1b1b] rundll32.exe "c:\windows\system32\kagobale.dll",b
mRun: [CPMf3ac2887] Rundll32.exe "c:\windows\system32\kafufigu.dll",a
mRunOnce: [SpybotDeletingA9073] command.com /c del "c:\windows\system32\jujutoji.dll_old"
mRunOnce: [SpybotDeletingC365] cmd.exe /c del "c:\windows\system32\jujutoji.dll_old"
mRunOnce: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck
StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\compaq~1.lnk - c:\program files\compaq connections\5577497\program\Compaq Connections.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: trymedia.com
DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://charter.net/files/charter/securitysuite/fscax.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: c:\windows\system32\bakovoti.dll c:\windows\system32\holuyibi.dll c:\windows\system32\kafufigu.dll
SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kafufigu.dll
STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\kafufigu.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Notification Packages = scecli c:\windows\system32\bakovoti.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\dehyd12c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.charter.net/index.php
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: c:\program files\mozilla firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\documents and settings\compaq_administrator\application data\mozilla\firefox\profiles\dehyd12c.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npImgCtl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npkimi.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
============= SERVICES / DRIVERS ===============
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-2-6 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-2-6 93336]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-2-6 727720]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-3-18 93696]
=============== Created Last 30 ================
2009-04-12 04:57 1,403,888 ---sh--- c:\windows\system32\elabogak.ini
2009-04-08 04:06 <DIR> --dsh--- c:\documents and settings\compaq_administrator\PrivacIE
2009-04-08 03:57 <DIR> --d----- c:\windows\system32\appmgmt
2009-04-08 03:52 <DIR> --dsh--- c:\documents and settings\compaq_administrator\IETldCache
2009-04-08 03:49 <DIR> --d----- c:\windows\ie8updates
2009-04-08 03:46 <DIR> -cd-h--- c:\windows\ie8
2009-04-08 03:44 105,984 -------- c:\windows\system32\dllcache\iecompat.dll
2009-04-07 23:21 272,128 -------- c:\windows\system32\dllcache\bthport.sys
2009-04-07 23:21 1,206,784 a------- c:\windows\system32\dllcache\urlmon.dll
2009-04-07 23:21 1,499,136 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-04-07 23:20 2,145,280 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-07 23:20 2,189,184 -------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-07 23:20 2,023,936 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-07 23:20 2,066,048 -------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-07 23:20 203,136 -------- c:\windows\system32\dllcache\rmcast.sys
2009-04-07 23:20 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-04-07 23:20 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-04-07 23:19 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-04-07 23:19 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\scripting
2009-04-07 23:09 <DIR> --d----- c:\windows\l2schemas
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\en
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\bits
2009-04-07 23:05 <DIR> --d----- c:\windows\ServicePackFiles
2009-04-07 22:47 <DIR> --d----- c:\windows\system32\NtmsData
2009-04-07 20:53 <DIR> --d----- c:\program files\ESET
2009-04-07 20:26 <DIR> --d----- c:\windows\pss
2009-04-07 17:40 664 a------- c:\windows\system32\d3d9caps.dat
2009-04-07 17:20 <DIR> --d----- c:\documents and settings\compaq_administrator\.housecall6.6
2009-03-30 09:57 268 ----h--- C:\sqmdata10.sqm
2009-03-30 09:57 244 ----h--- C:\sqmnoopt10.sqm
2009-03-28 02:03 601 a------- c:\windows\cdplayer.ini
2009-03-28 01:57 <DIR> --d----- c:\docume~1\alluse~1\applic~1\FreeRIP
2009-03-28 01:57 <DIR> --d----- c:\program files\FreeRIP3
2009-03-26 23:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\id Software
2009-03-24 03:06 <DIR> --d----- c:\program files\DVD Flick
2009-03-22 03:01 128,840 a------- c:\windows\system32\MSWINSCK.ocx
2009-03-22 03:01 <DIR> --d----- c:\program files\CamFrog
2009-03-18 18:35 0 a------- c:\windows\ativpsrm.bin
2009-03-18 18:26 <DIR> --d----- c:\program files\common files\ATI Technologies
2009-03-18 18:25 93,696 a----r-- c:\windows\system32\drivers\AtiHdmi.sys
2009-03-18 18:25 593,920 -------- c:\windows\system32\ati2sgag.exe
2009-03-18 18:25 13,848 a----r-- c:\windows\atiogl.xml
2009-03-18 18:24 413,696 a----r-- c:\windows\system32\ATIDEMGX.dll
2009-03-18 18:24 887,724 a----r-- c:\windows\system32\ativva6x.dat
2009-03-18 18:24 3,107,788 a----r-- c:\windows\system32\ativva5x.dat
2009-03-18 18:24 3,107,788 a----r-- c:\windows\system32\ativvaxx.dat
==================== Find3M ====================
2009-04-12 04:56 109,568 a--sh--- c:\windows\system32\kafufigu.dll
2009-04-12 04:56 62,976 a--sh--- c:\windows\system32\zotemiso.exe
2009-04-12 04:56 102,400 a--sh--- c:\windows\system32\kagobale.dll
2009-04-11 04:55 64,512 a--sh--- c:\windows\system32\pokarisu.exe
2009-04-10 04:55 70,144 a--sh--- c:\windows\system32\duweweba.dll
2009-04-10 04:55 108,544 a--sh--- c:\windows\system32\milodifu.dll
2009-04-10 04:55 63,488 a--sh--- c:\windows\system32\jirohowu.exe
2009-04-09 16:54 109,056 a--sh--- c:\windows\system32\datusesi.dll
2009-04-09 16:54 61,952 a--sh--- c:\windows\system32\yovedevi.exe
2009-04-09 16:54 101,376 -------- c:\windows\system32\lorotani.dll
2009-04-08 01:54 138,944 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-08 01:54 189,784 a------- c:\windows\system32\PnkBstrB.exe
2009-04-07 23:13 92,947 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-07 23:12 45,056 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\uninstallui\eHelpSetup.exe
2009-04-07 23:12 217,088 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
2009-04-07 23:12 61,440 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemutil.dll
2009-04-07 23:12 44,032 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\scripts\devcon.exe
2009-04-07 23:12 40,960 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\ScDmi.dll
2009-04-07 23:12 32,768 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\uploadHSC.dll
2009-04-07 23:12 32,768 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\Scom.dll
2009-04-07 23:12 341,048 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\HPBasicDetection3.dll
2009-04-07 23:12 163,840 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemcheck.dll
2009-03-27 00:00 22,328 a------- c:\docume~1\compaq~1\applic~1\PnkBstrK.sys
2009-03-27 00:00 2,246,144 a------- c:\windows\system32\pbsvc.exe
2009-03-12 00:13 75,064 a------- c:\windows\system32\PnkBstrA.exe
2009-03-08 14:09 638,816 -------- c:\windows\system32\dllcache\iexplore.exe
2009-03-08 14:09 391,536 -------- c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 04:41 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\dllcache\wininet.dll
2009-03-08 04:34 236,544 -------- c:\windows\system32\dllcache\webcheck.dll
2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 04:34 43,008 -------- c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 04:34 105,984 -------- c:\windows\system32\dllcache\url.dll
2009-03-08 04:34 193,536 -------- c:\windows\system32\dllcache\msrating.dll
2009-03-08 04:34 109,568 -------- c:\windows\system32\dllcache\occache.dll
2009-03-08 04:33 759,296 -------- c:\windows\system32\dllcache\VGX.dll
2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 04:33 18,944 -------- c:\windows\system32\dllcache\corpol.dll
2009-03-08 04:33 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 04:33 726,528 a------- c:\windows\system32\dllcache\jscript.dll
2009-03-08 04:33 229,376 -------- c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\dllcache\vbscript.dll
2009-03-08 04:33 125,952 -------- c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 04:32 72,704 -------- c:\windows\system32\dllcache\admparse.dll
2009-03-08 04:32 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 04:32 163,840 a------- c:\windows\system32\dllcache\ieakui.dll
2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 04:32 71,680 -------- c:\windows\system32\dllcache\iesetup.dll
2009-03-08 04:32 55,808 -------- c:\windows\system32\dllcache\iernonce.dll
2009-03-08 04:32 128,512 -------- c:\windows\system32\dllcache\advpack.dll
2009-03-08 04:32 94,720 -------- c:\windows\system32\dllcache\inseng.dll
2009-03-08 04:32 611,840 -------- c:\windows\system32\dllcache\mstime.dll
2009-03-08 04:31 183,808 -------- c:\windows\system32\dllcache\iepeers.dll
2009-03-08 04:31 348,160 -------- c:\windows\system32\dllcache\dxtmsft.dll
2009-03-08 04:31 34,816 a------- c:\windows\system32\imgutil.dll
2009-03-08 04:31 216,064 -------- c:\windows\system32\dllcache\dxtrans.dll
2009-03-08 04:31 34,816 -------- c:\windows\system32\dllcache\imgutil.dll
2009-03-08 04:31 46,592 -------- c:\windows\system32\dllcache\pngfilt.dll
2009-03-08 04:31 66,560 -------- c:\windows\system32\dllcache\mshtmled.dll
2009-03-08 04:31 48,128 a------- c:\windows\system32\mshtmler.dll
2009-03-08 04:31 48,128 -------- c:\windows\system32\dllcache\mshtmler.dll
2009-03-08 04:31 45,568 a------- c:\windows\system32\mshta.exe
2009-03-08 04:31 45,568 -------- c:\windows\system32\dllcache\mshta.exe
2009-03-08 04:24 68,608 -------- c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\dllcache\msls31.dll
2009-03-02 16:10 87,608 a------- c:\docume~1\compaq~1\applic~1\inst.exe
2009-03-02 16:10 47,360 a------- c:\docume~1\compaq~1\applic~1\pcouffin.sys
2009-02-26 15:32 157,219 a------- c:\windows\hphins26.dat
2009-02-22 02:47 127,034 -----r-- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-02-20 00:53 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-02-20 00:53 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-09 06:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-09 06:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2009-02-06 18:06 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-31 18:12 674 a------- c:\docume~1\compaq~1\applic~1\wklnhst.dat
2006-08-04 18:56 32 a--sh--- c:\windows\sminst\HPCD.SYS
2009-01-10 04:55 70,144 a--sh--- c:\windows\system32\bakovoti.dll
2009-01-10 04:55 70,144 a--sh--- c:\windows\system32\duduhahi.dll
2009-01-10 04:55 70,144 a--sh--- c:\windows\system32\kahufeto.dll
2008-09-29 16:32 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092920080930\index.dat
============= FINISH: 13:26:49.23 ===============
and here's the other
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-03-16.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 10/26/2008 1:13:07 AM
System Uptime: 4/11/2009 8:10:54 PM (17 hours ago)
Motherboard: ASUSTeK Computer INC. | | Altair
Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz | Socket 775 | 3066/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 178 GiB total, 68.58 GiB free.
D: is FIXED (FAT32) - 8 GiB total, 0.857 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 932 GiB total, 622.041 GiB free.
K: is FIXED (NTFS) - 298 GiB total, 20.178 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP129: 1/11/2009 10:50:01 PM - Installed CuteFTP 8 Professional
RP130: 1/12/2009 11:49:36 PM - System Checkpoint
RP131: 1/14/2009 12:50:44 AM - System Checkpoint
RP132: 1/14/2009 1:27:15 AM - Installed Quake Live Mozilla Plugin
RP133: 1/14/2009 3:00:31 AM - Software Distribution Service 3.0
RP134: 1/15/2009 3:00:26 AM - Software Distribution Service 3.0
RP135: 1/17/2009 2:21:09 AM - System Checkpoint
RP136: 1/18/2009 10:53:31 AM - System Checkpoint
RP137: 1/19/2009 4:47:36 PM - Installed Steam
RP138: 1/20/2009 5:54:15 PM - System Checkpoint
RP139: 1/21/2009 7:48:54 PM - System Checkpoint
RP140: 1/22/2009 8:02:05 PM - System Checkpoint
RP141: 1/23/2009 1:37:53 AM - Installed Quake Live Mozilla Plugin
RP142: 1/24/2009 5:14:15 AM - System Checkpoint
RP143: 1/25/2009 11:02:03 AM - System Checkpoint
RP144: 1/25/2009 2:39:24 PM - Installed Ventrilo Client
RP145: 1/26/2009 4:20:19 PM - System Checkpoint
RP146: 1/27/2009 5:51:30 PM - Installed Windows Live Messenger
RP147: 1/28/2009 6:48:24 PM - System Checkpoint
RP148: 1/29/2009 7:29:34 PM - System Checkpoint
RP149: 1/30/2009 7:56:44 PM - System Checkpoint
RP150: 1/31/2009 3:24:00 PM - Installed Quake Live Mozilla Plugin
RP151: 2/1/2009 5:36:08 PM - System Checkpoint
RP152: 2/2/2009 7:53:53 PM - System Checkpoint
RP153: 2/3/2009 8:09:37 PM - System Checkpoint
RP154: 2/5/2009 11:51:05 AM - System Checkpoint
RP155: 2/6/2009 5:06:17 PM - Installed Java(TM) 6 Update 11
RP156: 2/8/2009 6:26:39 AM - System Checkpoint
RP157: 2/9/2009 2:39:43 PM - System Checkpoint
RP158: 2/10/2009 6:05:50 PM - System Checkpoint
RP159: 2/11/2009 3:00:19 AM - Software Distribution Service 3.0
RP160: 2/12/2009 5:36:21 AM - System Checkpoint
RP161: 2/13/2009 12:00:58 AM - Installed Quake Live Mozilla Plugin
RP162: 2/14/2009 12:59:12 AM - System Checkpoint
RP163: 2/15/2009 9:06:36 PM - System Checkpoint
RP164: 2/17/2009 9:10:38 AM - System Checkpoint
RP165: 2/18/2009 9:54:00 AM - System Checkpoint
RP166: 2/19/2009 10:31:09 AM - System Checkpoint
RP167: 2/19/2009 11:51:57 PM - Logitech SetPoint Mouse and Keyboard Device Drivers
RP168: 2/21/2009 9:42:41 PM - System Checkpoint
RP169: 2/21/2009 11:54:12 PM - Installed Quake Live Mozilla Plugin
RP170: 2/22/2009 1:35:13 AM - Removed Logitech Desktop Messenger
RP171: 2/22/2009 1:43:31 AM - Logitech SetPoint Mouse and Keyboard Device Drivers
RP172: 2/24/2009 12:56:00 AM - System Checkpoint
RP173: 2/25/2009 6:19:56 AM - System Checkpoint
RP174: 2/25/2009 11:38:31 AM - Installed MP3 Player Utilities 4.15
RP175: 2/25/2009 11:39:26 AM - Installed MP3 Player Utilities 1.47
RP176: 2/26/2009 3:00:44 AM - Software Distribution Service 3.0
RP177: 2/26/2009 1:29:29 PM - Removed WebReg
RP178: 2/26/2009 1:30:11 PM - Removed BufferChm
RP179: 2/26/2009 1:31:35 PM - Removed HPProductAssistant
RP180: 2/26/2009 1:32:54 PM - Removed SolutionCenter
RP181: 2/26/2009 1:34:38 PM - Removed TrayApp
RP182: 2/26/2009 1:35:37 PM - Removed Status
RP183: 2/26/2009 1:38:02 PM - Removed HPSU306Stub
RP184: 2/26/2009 1:38:09 PM - Removed HP Software Update
RP185: 2/26/2009 5:16:41 PM - Installed Greeting Card Factory Photo Card Maker.
RP186: 2/27/2009 6:36:37 PM - System Checkpoint
RP187: 3/2/2009 3:13:55 AM - System Checkpoint
RP188: 3/2/2009 2:28:43 PM - 3-2-09
RP189: 3/3/2009 8:16:39 PM - System Checkpoint
RP190: 3/4/2009 8:32:10 PM - System Checkpoint
RP191: 3/5/2009 9:12:42 PM - System Checkpoint
RP192: 3/7/2009 3:31:49 AM - System Checkpoint
RP193: 3/8/2009 4:40:54 AM - System Checkpoint
RP194: 3/9/2009 4:42:27 AM - System Checkpoint
RP195: 3/10/2009 8:22:48 PM - Software Distribution Service 3.0
RP196: 3/11/2009 9:28:53 PM - System Checkpoint
RP197: 3/11/2009 11:07:00 PM - Installed Quake Live Mozilla Plugin
RP198: 3/13/2009 5:23:57 AM - System Checkpoint
RP199: 3/14/2009 12:14:40 PM - System Checkpoint
RP200: 3/15/2009 2:08:59 PM - System Checkpoint
RP201: 3/16/2009 7:47:45 PM - System Checkpoint
RP202: 3/18/2009 8:42:51 AM - System Checkpoint
RP203: 3/18/2009 6:26:44 PM - Installed ATI AVIVO Codecs
RP204: 3/18/2009 6:28:41 PM - Installed ATI Catalyst Control Center
RP205: 3/18/2009 6:32:59 PM - Installed ATI Parental Control & Encoder
RP206: 3/18/2009 6:33:59 PM - Installed ATI Problem Report Wizard
RP207: 3/19/2009 6:34:46 PM - System Checkpoint
RP208: 3/21/2009 3:57:40 AM - System Checkpoint
RP209: 3/22/2009 12:52:51 AM - 3-22-09
RP210: 3/23/2009 3:47:03 AM - System Checkpoint
RP211: 3/24/2009 9:43:27 AM - System Checkpoint
RP212: 3/25/2009 12:50:38 PM - System Checkpoint
RP213: 3/25/2009 8:39:03 PM - 3-25-09
RP214: 3/25/2009 8:40:27 PM - Installed Windows Defender
RP215: 3/25/2009 8:41:20 PM - Software Distribution Service 3.0
RP216: 3/26/2009 12:21:27 PM - Software Distribution Service 3.0
RP217: 3/26/2009 11:59:01 PM - Installed Quake Live Mozilla Plugin
RP218: 3/28/2009 12:22:52 AM - System Checkpoint
RP219: 3/29/2009 1:00:12 AM - System Checkpoint
RP220: 3/30/2009 2:13:41 AM - System Checkpoint
RP221: 3/30/2009 10:10:33 PM - Software Distribution Service 3.0
RP222: 4/1/2009 9:47:02 AM - System Checkpoint
RP223: 4/2/2009 12:18:40 PM - Software Distribution Service 3.0
RP224: 4/4/2009 6:07:24 AM - System Checkpoint
RP225: 4/5/2009 2:28:02 AM - Windows Defender Checkpoint
RP226: 4/6/2009 4:17:22 AM - System Checkpoint
RP227: 4/6/2009 9:42:42 AM - Software Distribution Service 3.0
RP228: 4/7/2009 2:36:30 AM - Windows Defender Checkpoint
RP229: 4/7/2009 8:53:09 PM - Installed ESET NOD32 Antivirus
RP230: 4/7/2009 10:45:09 PM - Software Distribution Service 3.0
RP231: 4/7/2009 10:47:10 PM - Software Distribution Service 3.0
RP232: 4/7/2009 10:49:20 PM - 04-07-09
RP233: 4/7/2009 11:00:22 PM - Installed Windows XP Service Pack 3.
RP234: 4/7/2009 11:15:52 PM - Installed Windows XP KB938464.
RP235: 4/7/2009 11:16:49 PM - Installed Windows XP KB946648.
RP236: 4/7/2009 11:17:46 PM - Installed Windows XP KB950759.
RP237: 4/7/2009 11:21:32 PM - Software Distribution Service 3.0
RP238: 4/8/2009 3:00:19 AM - Software Distribution Service 3.0
RP239: 4/8/2009 3:47:27 AM - Installed Windows Internet Explorer 8.
RP240: 4/8/2009 3:48:40 AM - Software Distribution Service 3.0
RP241: 4/8/2009 3:56:44 AM - Removed Steam
RP242: 4/8/2009 4:04:29 AM - Removed MP3 Player Utilities 1.47
RP243: 4/8/2009 4:04:49 AM - Removed MP3 Player Utilities 4.15
RP244: 4/8/2009 4:05:23 AM - Removed Cisco Network Magic
RP245: 4/8/2009 4:06:05 AM - Removed Pure Networks Platform
RP246: 4/8/2009 4:10:51 AM - Removed Quicken 2006
RP247: 4/8/2009 4:12:06 AM - Removed Sonic Express Labeler
RP248: 4/8/2009 4:12:49 AM - Removed Sonic MyDVD Plus
RP249: 4/8/2009 4:13:35 AM - Removed Sonic RecordNow Audio
RP250: 4/8/2009 4:13:49 AM - Removed Sonic RecordNow Copy
RP251: 4/8/2009 4:14:06 AM - Removed Sonic RecordNow Data
RP252: 4/8/2009 4:14:35 AM - Removed Sonic Update Manager
RP253: 4/9/2009 5:05:57 AM - System Checkpoint
RP254: 4/10/2009 6:59:29 AM - System Checkpoint
RP255: 4/11/2009 12:58:13 AM - 04-11-09
RP256: 4/11/2009 2:31:27 AM - 4-11-2009
==== Installed Programs ======================
µTorrent
Adobe Flash Player 10 ActiveX
Adobe Reader 7.0.5
Adobe Shockwave Player
Advanced SystemCare 3
AIM 6
ATI - Software Uninstall Utility
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Control Panel
ATI Display Driver
ATI MCE Transcode
ATI Parental Control & Encoder
ATI Problem Report Wizard
BufferChm
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Spanish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help English
CCC Help French
CCC Help German
CCC Help Spanish
CDDRV_Installer
Compaq Connections (remove only)
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Customer Experience Enhancement
CustomerResearchQFolder
CuteFTP 8 Professional
D1500
D1500_Help
Data Fax SoftModem with SmartCP
Destinations
DeviceDiscovery
DeviceFunctionQFolder
DeviceManagementQFolder
DISCover
DJ_SF_03_D1500_ProductContext
DJ_SF_03_D1500_Software
DJ_SF_03_D1500_Software_Min
DVD Flick 1.3.0.6
Enhanced Multimedia Keyboard Solution
ERUNT 1.1j
ESET NOD32 Antivirus
FreeRIP v3.1
FullDPAppQFolder
GPBaseService
Greeting Card Factory Photo Card Maker
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB952287)
HP Boot Optimizer
HP Customer Participation Program 10.0
HP Deskjet 3900 series
HP Deskjet D1500 Printer Driver Software 10.0 Rel .3
HP DVD Play 2.1
HP Game Console
HP Imaging Device Functions 10.0
HP Photosmart Essential 2.5
HP Photosmart Premier Software 6.5
HP Rhapsody
HP Smart Web Printing
HP Solution Center 10.0
HP Support Overview
HP Update
HP Web Helper
HPDeskjet3900Series
HPPhotoSmartExpress
HPProductAssistant
HpSdpAppCoreApp
HPSSupply
ImagXpress
InstantShareDevices
J2SE Runtime Environment 5.0 Update 5
Java(TM) 6 Update 11
K-Lite Codec Pack 4.3.8 (Full) BETA
KhalInstallWrapper
LightScribe System Software 1.14.17.1
Logitech Desktop Messenger
Logitech Registration
Logitech SetPoint
MarketResearch
Mega Manager
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Away Mode
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Money 2006
Microsoft Office 2003 Edition 60 Days Trial Welcome Tour
Microsoft Office Standard Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MilkDrop for Winamp 2x (remove only)
mIRC
Mozilla Firefox (3.0.8)
MSN
MSXML 4.0 SP2 (KB954430)
neroxml
OptionalContentQFolder
Otto
PC-Doctor 5 for Windows
PhotoGallery
PSSWCORE
PunkBuster Services
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
Quake Live Mozilla Plugin
RAdmin
RandMap
Realtek High Definition Audio Driver
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Shop for HP Supplies
Skins
SkinsHP1
SlideShow
SlideShowMusic
SmartWebPrintingOC
SolutionCenter
Sonic_PrimoSDK
Spybot - Search & Destroy
Status
Toolbox
TrayApp
TVUPlayer 2.4.1.0
Unload
UnloadSupport
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 2 for Windows XP Media Center Edition 2005
Ventrilo Client
Veoh Web Player Beta
VideoToolkit01
VLC media player 0.9.4
WebFldrs XP
WebReg
Windows Defender
Windows Internet Explorer 8
Windows Live Messenger
Windows Media Format Runtime
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB912067
Windows XP Service Pack 3
WinRAR archiver
Yahoo! Messenger
==== Event Viewer Messages From Past Week ========
4/8/2009 3:54:15 AM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
4/7/2009 8:29:35 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
4/7/2009 5:39:29 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: F-Secure HIPS Fips intelppm
4/6/2009 9:42:11 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
4/9/2009 5:14:20 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
==== End Of File ===========================
I'm also curious if you can tell by these logs if the infections have spread to my external drives, and if i'm going to need to reformat them after ridding the pc of the malware. I would just reformat the whole thing, but this is my sister in-laws pc, and she lost the discs that came with it. Thanks for your help!!!
IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.
µTorrent
I'd like you to read this thread (http://forums.spybot.info/showthread.php?t=282).
Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).
After that:
If you suspect your external drives have become infected please have them attached in during the process.
There're some Norton leftovers there. Please download & run this (http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039) removal tool.
Please visit this webpage for download links, and instructions for running ComboFix tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please ensure you read this guide carefully and install the Recovery Console first.
The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
Once installed, you should see a blue screen prompt that says:
The Recovery Console was successfully installed.
Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.
Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
New dds.txt log.
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
cinthetik
2009-04-13, 03:31
ok. i followed your instructions, read that post, got rid of utorrent and printed the rest of the insructions. however when using the combofix it never asked me if i wanted to install the windows recovery consol. i dont remember having that already... but i mist cause it went straight from clicking yes on the disclaimer, straight to scanning. heres the combofix log.
ComboFix 09-04-13.07 - Compaq_Administrator 2009-04-12 18:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.552 [GMT -5:00]
Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Compaq_Administrator\Application Data\inst.exe
c:\program files\SelectRebates
c:\program files\SelectRebates\SelectRebates.ini
c:\program files\SelectRebates\SelectRebatesDownload.exe
c:\windows\IE4 Error Log.txt
c:\windows\msvrc20.dll
c:\windows\system32\bakovoti.dll
c:\windows\system32\datusesi.dll
c:\windows\system32\duduhahi.dll
c:\windows\system32\duweweba.dll
c:\windows\system32\elabogak.ini
c:\windows\system32\kafufigu.dll
c:\windows\system32\kagobale.dll
c:\windows\system32\kahufeto.dll
c:\windows\system32\kidodize.dll
c:\windows\system32\lorotani.dll
c:\windows\system32\milodifu.dll
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://82.98.235.205
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_R_SERVER
((((((((((((((((((((((((( Files Created from 2009-03-13 to 2009-04-13 )))))))))))))))))))))))))))))))
.
2009-04-12 22:45 . 2009-04-12 22:45 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-04-12 22:37 . 2009-04-12 22:37 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-04-09 16:55 . 2009-04-09 16:55 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\HP
2009-04-08 09:06 . 2009-04-08 09:06 -------- d-sh--w c:\documents and settings\Compaq_Administrator\PrivacIE
2009-04-08 08:54 . 2009-04-08 08:54 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-04-08 08:52 . 2009-04-08 08:52 -------- d-sh--w c:\documents and settings\Compaq_Administrator\IETldCache
2009-04-08 08:49 . 2009-04-08 08:49 -------- d-----w c:\windows\ie8updates
2009-04-08 08:46 . 2009-04-08 08:47 -------- dc-h--w c:\windows\ie8
2009-04-08 08:44 . 2009-02-28 04:55 105984 ------w c:\windows\system32\dllcache\iecompat.dll
2009-04-08 08:13 . 2009-04-08 08:13 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-04-08 04:21 . 2008-06-13 11:05 272128 ------w c:\windows\system32\dllcache\bthport.sys
2009-04-08 04:21 . 2009-03-08 09:34 1206784 ----a-w c:\windows\system32\dllcache\urlmon.dll
2009-04-08 04:21 . 2008-10-16 01:00 1499136 ------w c:\windows\system32\dllcache\shdocvw.dll
2009-04-08 04:20 . 2008-08-14 10:09 2145280 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-08 04:20 . 2008-08-14 10:11 2189184 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-08 04:20 . 2008-08-14 09:33 2023936 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-08 04:20 . 2008-08-14 09:33 2066048 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-08 04:20 . 2008-05-08 14:02 203136 ------w c:\windows\system32\dllcache\rmcast.sys
2009-04-08 04:20 . 2008-10-24 11:21 455296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-08 04:20 . 2008-12-11 10:57 333952 ------w c:\windows\system32\dllcache\srv.sys
2009-04-08 04:19 . 2008-04-11 19:04 691712 ------w c:\windows\system32\dllcache\inetcomm.dll
2009-04-08 04:19 . 2008-10-15 16:34 337408 ------w c:\windows\system32\dllcache\netapi32.dll
2009-04-08 04:09 . 2009-04-08 04:09 -------- d-----w c:\windows\system32\scripting
2009-04-08 04:09 . 2009-04-08 04:09 -------- d-----w c:\windows\l2schemas
2009-04-08 04:09 . 2009-04-08 04:09 -------- d-----w c:\windows\system32\en
2009-04-08 04:09 . 2009-04-08 04:09 -------- d-----w c:\windows\system32\bits
2009-04-08 04:05 . 2009-04-08 04:09 -------- d-----w c:\windows\ServicePackFiles
2009-04-08 04:00 . 2009-04-08 08:48 1355 ----a-w c:\windows\imsins.BAK
2009-04-08 03:47 . 2009-04-08 03:55 -------- d-----w c:\windows\system32\NtmsData
2009-04-08 01:57 . 2009-04-08 01:57 -------- d-----w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\ESET
2009-04-08 01:53 . 2009-04-08 01:53 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-04-07 22:40 . 2009-04-08 01:20 -------- d-----w c:\documents and settings\Administrator\.housecall6.6
2009-04-07 22:40 . 2009-04-07 22:40 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-04-07 22:20 . 2009-04-07 22:21 -------- d-----w c:\documents and settings\Compaq_Administrator\.housecall6.6
2009-03-30 14:57 . 2009-03-30 14:57 268 ---h--w C:\sqmdata10.sqm
2009-03-30 14:57 . 2009-03-30 14:57 244 ---h--w C:\sqmnoopt10.sqm
2009-03-28 07:03 . 2009-03-28 08:29 601 ----a-w c:\windows\cdplayer.ini
2009-03-28 06:57 . 2009-03-28 06:57 -------- d-----w c:\documents and settings\All Users\Application Data\FreeRIP
2009-03-27 04:59 . 2009-03-27 04:59 -------- d-----w c:\documents and settings\All Users\Application Data\id Software
2009-03-22 08:01 . 2008-10-10 18:36 128840 ----a-w c:\windows\system32\MSWINSCK.ocx
2009-03-18 23:36 . 2009-03-18 23:36 -------- d-----w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\ATI
2009-03-18 23:36 . 2009-03-18 23:36 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\ATI
2009-03-18 23:36 . 2009-03-18 23:36 -------- d-----w c:\documents and settings\All Users\Application Data\ATI
2009-03-18 23:35 . 2009-03-18 23:35 0 ----a-w c:\windows\ativpsrm.bin
2009-03-18 23:25 . 2008-05-20 23:53 93696 ----a-r c:\windows\system32\drivers\AtiHdmi.sys
2009-03-18 23:25 . 2008-06-03 02:05 593920 ------w c:\windows\system32\ati2sgag.exe
2009-03-18 23:25 . 2008-05-22 18:46 13848 ----a-r c:\windows\atiogl.xml
2009-03-18 23:24 . 2008-06-03 03:22 413696 ----a-r c:\windows\system32\ATIDEMGX.dll
2009-03-18 23:24 . 2008-06-03 02:47 887724 ----a-r c:\windows\system32\ativva6x.dat
2009-03-18 23:24 . 2008-06-03 02:47 3107788 ----a-r c:\windows\system32\ativva5x.dat
2009-03-18 23:24 . 2008-06-03 02:47 3107788 ----a-r c:\windows\system32\ativvaxx.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-12 22:40 . 2006-06-22 22:04 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-12 22:34 . 2008-05-16 02:38 -------- d-----w c:\program files\uTorrent
2009-04-12 22:18 . 2008-06-20 18:03 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\mIRC
2009-04-12 21:56 . 2009-01-12 21:56 64000 --sha-w c:\windows\system32\gebunefi.exe
2009-04-12 09:56 . 2009-01-12 09:56 62976 --sha-w c:\windows\system32\zotemiso.exe
2009-04-12 06:49 . 2008-05-13 03:31 -------- d-----w c:\program files\mIRC
2009-04-11 09:55 . 2009-01-11 09:55 64512 --sha-w c:\windows\system32\pokarisu.exe
2009-04-11 06:48 . 2009-04-11 06:47 -------- d-----w c:\program files\ERUNT
2009-04-11 06:01 . 2008-05-14 16:05 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-11 05:56 . 2008-05-14 16:05 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-11 04:31 . 2008-06-20 20:41 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\uTorrent
2009-04-10 09:55 . 2009-01-10 09:55 63488 --sha-w c:\windows\system32\jirohowu.exe
2009-04-09 21:57 . 2008-12-17 01:31 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\DVD Flick
2009-04-09 21:54 . 2009-01-09 21:54 61952 --sha-w c:\windows\system32\yovedevi.exe
2009-04-09 20:11 . 2008-09-28 17:35 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\dvdcss
2009-04-08 20:47 . 2008-08-13 15:14 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\Move Networks
2009-04-08 19:50 . 2006-06-22 21:33 72880 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-08 09:15 . 2008-06-21 04:22 -------- d-----w c:\program files\Yahoo!
2009-04-08 09:14 . 2008-05-14 18:01 -------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-04-08 09:14 . 2006-06-22 21:25 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-08 09:14 . 2006-06-22 21:30 -------- d-----w c:\program files\Common Files\Sonic Shared
2009-04-08 09:13 . 2006-06-22 21:35 -------- d-----w c:\program files\Sonic
2009-04-08 09:11 . 2006-06-22 21:48 -------- d-----w c:\program files\Quicken
2009-04-08 09:10 . 2006-06-22 21:36 -------- d-----w c:\program files\HP Games
2009-04-08 09:06 . 2008-09-22 17:12 -------- d-----w c:\program files\Common Files\Pure Networks Shared
2009-04-08 09:00 . 2008-09-26 15:09 -------- d-----w c:\program files\iWin.com
2009-04-08 08:44 . 2009-03-02 20:29 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\HPAppData
2009-04-08 06:54 . 2009-01-14 07:27 138944 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-08 06:54 . 2009-01-14 07:27 189784 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-08 04:33 . 2009-01-27 23:51 -------- d-----w c:\program files\MSN Messenger
2009-04-08 04:13 . 2005-08-31 04:01 92947 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-08 04:12 . 2009-04-08 04:12 45056 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2009-04-08 04:12 . 2009-04-08 04:12 44032 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2009-04-08 04:12 . 2009-04-08 04:12 40960 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2009-04-08 04:12 . 2009-04-08 04:12 32768 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2009-04-08 04:12 . 2009-04-08 04:12 32768 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2009-04-08 04:12 . 2009-04-08 04:12 217088 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
2009-04-08 04:12 . 2009-04-08 04:12 61440 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2009-04-08 04:12 . 2009-04-08 04:12 341048 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2009-04-08 04:12 . 2009-04-08 04:12 163840 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2009-04-08 04:01 . 2004-08-10 11:00 250048 --sh--r C:\ntldr
2009-04-08 02:26 . 2008-06-02 22:56 -------- d-----w c:\program files\Search Settings
2009-04-08 01:53 . 2009-04-08 01:53 -------- d-----w c:\program files\ESET
2009-04-08 01:43 . 2008-10-28 20:49 -------- d-----w c:\program files\Charter High-Speed Security Suite
2009-04-08 01:40 . 2008-05-13 02:28 -------- d-----w c:\documents and settings\All Users\Application Data\F-Secure
2009-03-28 06:58 . 2009-03-28 06:57 -------- d-----w c:\program files\FreeRIP3
2009-03-27 05:00 . 2009-01-14 07:27 22328 ----a-w c:\documents and settings\Compaq_Administrator\Application Data\PnkBstrK.sys
2009-03-27 05:00 . 2009-01-14 07:27 2246144 ----a-w c:\windows\system32\pbsvc.exe
2009-03-26 01:40 . 2009-03-26 01:40 -------- d-----w c:\program files\Windows Defender
2009-03-24 18:51 . 2008-08-04 20:57 -------- d-----w c:\program files\DVDMagic
2009-03-24 08:06 . 2009-03-24 08:06 -------- d-----w c:\program files\DVD Flick
2009-03-23 03:36 . 2008-05-14 16:32 -------- d-----w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-03-23 03:36 . 2008-05-14 16:32 -------- d-----w c:\program files\Security Task Manager
2009-03-22 08:03 . 2009-03-22 08:01 -------- d-----w c:\program files\CamFrog
2009-03-18 23:34 . 2009-03-18 23:26 -------- d-----w c:\program files\Common Files\ATI Technologies
2009-03-18 23:33 . 2006-06-22 21:25 -------- d-----w c:\program files\ATI Technologies
2009-03-18 23:28 . 2006-06-22 21:25 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-12 05:13 . 2009-01-14 07:27 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-03-08 19:09 . 2009-03-08 19:09 638816 ------w c:\windows\system32\dllcache\iexplore.exe
2009-03-08 19:09 . 2009-03-08 19:09 391536 ------w c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 09:41 . 2008-04-21 06:44 5937152 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-03-08 09:34 . 2008-04-21 06:44 914944 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-03-08 09:34 . 2004-08-10 04:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2009-03-08 09:34 236544 ------w c:\windows\system32\dllcache\webcheck.dll
2009-03-08 09:34 . 2009-03-08 09:34 43008 ------w c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 09:34 . 2004-08-10 04:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 09:34 . 2009-03-08 09:34 105984 ------w c:\windows\system32\dllcache\url.dll
2009-03-08 09:34 . 2009-03-08 09:34 193536 ------w c:\windows\system32\dllcache\msrating.dll
2009-03-08 09:34 . 2009-03-08 09:34 109568 ------w c:\windows\system32\dllcache\occache.dll
2009-03-08 09:33 . 2009-03-08 09:33 759296 ------w c:\windows\system32\dllcache\VGX.dll
2009-03-08 09:33 . 2009-03-08 09:33 18944 ------w c:\windows\system32\dllcache\corpol.dll
2009-03-08 09:33 . 2004-08-10 04:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2009-03-08 09:33 25600 ------w c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 09:33 . 2008-05-09 10:53 726528 ----a-w c:\windows\system32\dllcache\jscript.dll
2009-03-08 09:33 . 2009-03-08 09:33 229376 ------w c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 09:33 . 2008-05-09 10:53 420352 ----a-w c:\windows\system32\dllcache\vbscript.dll
2009-03-08 09:33 . 2004-08-10 04:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 09:33 . 2009-03-08 09:33 125952 ------w c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 09:32 . 2009-03-08 09:32 72704 ------w c:\windows\system32\dllcache\admparse.dll
2009-03-08 09:32 . 2004-08-10 04:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2009-03-08 09:32 173056 ------w c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 09:32 . 2004-08-10 04:00 163840 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-03-08 09:32 . 2009-03-08 09:32 71680 ------w c:\windows\system32\dllcache\iesetup.dll
2009-03-08 09:32 . 2009-03-08 09:32 55808 ------w c:\windows\system32\dllcache\iernonce.dll
2009-03-08 09:32 . 2004-08-10 04:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 09:32 . 2009-03-08 09:32 128512 ------w c:\windows\system32\dllcache\advpack.dll
2009-03-08 09:32 . 2009-03-08 09:32 94720 ------w c:\windows\system32\dllcache\inseng.dll
2009-03-08 09:32 . 2009-03-08 09:32 611840 ------w c:\windows\system32\dllcache\mstime.dll
2009-03-08 09:31 . 2009-03-08 09:31 183808 ------w c:\windows\system32\dllcache\iepeers.dll
2009-03-08 09:31 . 2009-03-08 09:31 348160 ------w c:\windows\system32\dllcache\dxtmsft.dll
2009-03-08 09:31 . 2009-03-08 09:31 34816 ------w c:\windows\system32\dllcache\imgutil.dll
2009-03-08 09:31 . 2009-03-08 09:31 216064 ------w c:\windows\system32\dllcache\dxtrans.dll
2009-03-08 09:31 . 2004-08-10 04:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2009-03-08 09:31 46592 ------w c:\windows\system32\dllcache\pngfilt.dll
2009-03-08 09:31 . 2009-03-08 09:31 66560 ------w c:\windows\system32\dllcache\mshtmled.dll
2009-03-08 09:31 . 2009-03-08 09:31 48128 ------w c:\windows\system32\dllcache\mshtmler.dll
2009-03-08 09:31 . 2004-08-10 04:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2009-03-08 09:31 45568 ------w c:\windows\system32\dllcache\mshta.exe
2009-03-08 09:31 . 2004-08-10 04:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 09:24 . 2009-03-08 09:24 68608 ------w c:\windows\system32\dllcache\hmmapi.dll
2008-08-14 00:2008-08-26 01:06 02:10 . c:\program files\mozilla firefox\components\FFComm.dll
2009-04-12 21:56 . 2009-01-12 21:56 64000 --sha-w c:\windows\system32\gebunefi.exe
2009-04-10 09:55 . 2009-01-10 09:55 63488 --sha-w c:\windows\system32\jirohowu.exe
2009-04-11 09:55 . 2009-01-11 09:55 64512 --sha-w c:\windows\system32\pokarisu.exe
2009-04-09 21:54 . 2009-01-09 21:54 61952 --sha-w c:\windows\system32\yovedevi.exe
2009-04-12 09:56 . 2009-01-12 09:56 62976 --sha-w c:\windows\system32\zotemiso.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2008-11-26 2235920]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 c:\windows\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 c:\windows\KHALMNPR.Exe]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-06-22 27136]
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Compaq Connections.lnk - c:\program files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-06-22 36903]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-02-22 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-02-22 692224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-05-20 93696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9d908a47-2217-11de-94c4-001731b9c969}]
\Shell\AutoRun\command - L:\rcaeasyrip_setup.exe
\Shell\install\command - L:\rcaeasyrip_setup.exe
\Shell\usermanualEnglish\command - L:\rcaeasyrip_setup.exe /pdf_English
\Shell\usermanualFrench\command - L:\rcaeasyrip_setup.exe /pdf_French
\Shell\usermanualSpanish\command - L:\rcaeasyrip_setup.exe /pdf_Spanish
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf25a923-e659-11dd-948b-001731b9c969}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f96ae82b-a61b-11dd-945f-001731b9c969}]
\Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-04-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -
BHO-{a660fb53-a7f4-447b-8c0e-39e990f5b9b9} - c:\windows\system32\duduhahi.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: trymedia.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\dehyd12c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.charter.net/index.php
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\dehyd12c.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npImgCtl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-13 18:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3376)
c:\docume~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\arservice.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Logitech\KhalShared\KHALMNPR.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-13 18:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-13 23:13
Pre-Run: 73,518,718,976 bytes free
Post-Run: 77,741,850,624 bytes free
357 --- E O F --- 2009-04-08 08:03
and heres the new dds log.
DDS (Ver_09-03-16.01) - NTFSx86
Run by Compaq_Administrator at 19:23:21.00 on Mon 04/13/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.370 [GMT -5:00]
AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Robz Shit\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {D0943516-5076-4020-A3B5-AEFAF26AB263} - No File
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\compaq~1.lnk - c:\program files\compaq connections\5577497\program\Compaq Connections.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: trymedia.com
DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://charter.net/files/charter/securitysuite/fscax.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\dehyd12c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.charter.net/index.php
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: c:\program files\mozilla firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\documents and settings\compaq_administrator\application data\mozilla\firefox\profiles\dehyd12c.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npImgCtl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npkimi.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
============= SERVICES / DRIVERS ===============
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-2-6 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-2-6 93336]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-2-6 727720]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-3-18 93696]
=============== Created Last 30 ================
2009-04-12 17:59 161,792 a------- c:\windows\SWREG.exe
2009-04-12 17:59 98,816 a------- c:\windows\sed.exe
2009-04-12 17:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-04-08 04:06 <DIR> --dsh--- c:\documents and settings\compaq_administrator\PrivacIE
2009-04-08 03:57 <DIR> --d----- c:\windows\system32\appmgmt
2009-04-08 03:52 <DIR> --dsh--- c:\documents and settings\compaq_administrator\IETldCache
2009-04-08 03:49 <DIR> --d----- c:\windows\ie8updates
2009-04-08 03:46 <DIR> -cd-h--- c:\windows\ie8
2009-04-08 03:44 105,984 -------- c:\windows\system32\dllcache\iecompat.dll
2009-04-07 23:21 272,128 -------- c:\windows\system32\dllcache\bthport.sys
2009-04-07 23:21 1,206,784 a------- c:\windows\system32\dllcache\urlmon.dll
2009-04-07 23:21 1,499,136 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-04-07 23:20 2,145,280 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-07 23:20 2,189,184 -------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-07 23:20 2,023,936 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-07 23:20 2,066,048 -------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-07 23:20 203,136 -------- c:\windows\system32\dllcache\rmcast.sys
2009-04-07 23:20 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-04-07 23:20 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-04-07 23:19 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-04-07 23:19 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\scripting
2009-04-07 23:09 <DIR> --d----- c:\windows\l2schemas
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\en
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\bits
2009-04-07 23:05 <DIR> --d----- c:\windows\ServicePackFiles
2009-04-07 22:47 <DIR> --d----- c:\windows\system32\NtmsData
2009-04-07 20:53 <DIR> --d----- c:\program files\ESET
2009-04-07 20:26 <DIR> --d----- c:\windows\pss
2009-04-07 17:40 664 a------- c:\windows\system32\d3d9caps.dat
2009-04-07 17:20 <DIR> --d----- c:\documents and settings\compaq_administrator\.housecall6.6
2009-03-30 09:57 268 ----h--- C:\sqmdata10.sqm
2009-03-30 09:57 244 ----h--- C:\sqmnoopt10.sqm
2009-03-28 02:03 601 a------- c:\windows\cdplayer.ini
2009-03-28 01:57 <DIR> --d----- c:\docume~1\alluse~1\applic~1\FreeRIP
2009-03-28 01:57 <DIR> --d----- c:\program files\FreeRIP3
2009-03-26 23:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\id Software
2009-03-24 03:06 <DIR> --d----- c:\program files\DVD Flick
2009-03-22 03:01 128,840 a------- c:\windows\system32\MSWINSCK.ocx
2009-03-22 03:01 <DIR> --d----- c:\program files\CamFrog
2009-03-18 18:35 0 a------- c:\windows\ativpsrm.bin
2009-03-18 18:26 <DIR> --d----- c:\program files\common files\ATI Technologies
2009-03-18 18:25 93,696 a----r-- c:\windows\system32\drivers\AtiHdmi.sys
2009-03-18 18:25 593,920 -------- c:\windows\system32\ati2sgag.exe
2009-03-18 18:25 13,848 a----r-- c:\windows\atiogl.xml
2009-03-18 18:24 413,696 a----r-- c:\windows\system32\ATIDEMGX.dll
2009-03-18 18:24 887,724 a----r-- c:\windows\system32\ativva6x.dat
2009-03-18 18:24 3,107,788 a----r-- c:\windows\system32\ativva5x.dat
2009-03-18 18:24 3,107,788 a----r-- c:\windows\system32\ativvaxx.dat
==================== Find3M ====================
2009-04-12 16:56 64,000 a--sh--- c:\windows\system32\gebunefi.exe
2009-04-12 04:56 62,976 a--sh--- c:\windows\system32\zotemiso.exe
2009-04-11 04:55 64,512 a--sh--- c:\windows\system32\pokarisu.exe
2009-04-10 04:55 63,488 a--sh--- c:\windows\system32\jirohowu.exe
2009-04-09 16:54 61,952 a--sh--- c:\windows\system32\yovedevi.exe
2009-04-08 01:54 138,944 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-08 01:54 189,784 a------- c:\windows\system32\PnkBstrB.exe
2009-04-07 23:13 92,947 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-07 23:12 45,056 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\uninstallui\eHelpSetup.exe
2009-04-07 23:12 217,088 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
2009-04-07 23:12 61,440 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemutil.dll
2009-04-07 23:12 44,032 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\scripts\devcon.exe
2009-04-07 23:12 40,960 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\ScDmi.dll
2009-04-07 23:12 32,768 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\uploadHSC.dll
2009-04-07 23:12 32,768 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\Scom.dll
2009-04-07 23:12 341,048 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\HPBasicDetection3.dll
2009-04-07 23:12 163,840 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemcheck.dll
2009-03-27 00:00 22,328 a------- c:\docume~1\compaq~1\applic~1\PnkBstrK.sys
2009-03-27 00:00 2,246,144 a------- c:\windows\system32\pbsvc.exe
2009-03-12 00:13 75,064 a------- c:\windows\system32\PnkBstrA.exe
2009-03-08 14:09 638,816 -------- c:\windows\system32\dllcache\iexplore.exe
2009-03-08 14:09 391,536 -------- c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 04:41 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\dllcache\wininet.dll
2009-03-08 04:34 236,544 -------- c:\windows\system32\dllcache\webcheck.dll
2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 04:34 43,008 -------- c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 04:34 105,984 -------- c:\windows\system32\dllcache\url.dll
2009-03-08 04:34 193,536 -------- c:\windows\system32\dllcache\msrating.dll
2009-03-08 04:34 109,568 -------- c:\windows\system32\dllcache\occache.dll
2009-03-08 04:33 759,296 -------- c:\windows\system32\dllcache\VGX.dll
2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 04:33 18,944 -------- c:\windows\system32\dllcache\corpol.dll
2009-03-08 04:33 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 04:33 726,528 a------- c:\windows\system32\dllcache\jscript.dll
2009-03-08 04:33 229,376 -------- c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\dllcache\vbscript.dll
2009-03-08 04:33 125,952 -------- c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 04:32 72,704 -------- c:\windows\system32\dllcache\admparse.dll
2009-03-08 04:32 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 04:32 163,840 a------- c:\windows\system32\dllcache\ieakui.dll
2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 04:32 71,680 -------- c:\windows\system32\dllcache\iesetup.dll
2009-03-08 04:32 55,808 -------- c:\windows\system32\dllcache\iernonce.dll
2009-03-08 04:32 128,512 -------- c:\windows\system32\dllcache\advpack.dll
2009-03-08 04:32 94,720 -------- c:\windows\system32\dllcache\inseng.dll
2009-03-08 04:32 611,840 -------- c:\windows\system32\dllcache\mstime.dll
2009-03-08 04:31 183,808 -------- c:\windows\system32\dllcache\iepeers.dll
2009-03-08 04:31 348,160 -------- c:\windows\system32\dllcache\dxtmsft.dll
2009-03-08 04:31 34,816 a------- c:\windows\system32\imgutil.dll
2009-03-08 04:31 216,064 -------- c:\windows\system32\dllcache\dxtrans.dll
2009-03-08 04:31 34,816 -------- c:\windows\system32\dllcache\imgutil.dll
2009-03-08 04:31 46,592 -------- c:\windows\system32\dllcache\pngfilt.dll
2009-03-08 04:31 66,560 -------- c:\windows\system32\dllcache\mshtmled.dll
2009-03-08 04:31 48,128 a------- c:\windows\system32\mshtmler.dll
2009-03-08 04:31 48,128 -------- c:\windows\system32\dllcache\mshtmler.dll
2009-03-08 04:31 45,568 a------- c:\windows\system32\mshta.exe
2009-03-08 04:31 45,568 -------- c:\windows\system32\dllcache\mshta.exe
2009-03-08 04:24 68,608 -------- c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\dllcache\msls31.dll
2009-03-02 16:10 47,360 a------- c:\docume~1\compaq~1\applic~1\pcouffin.sys
2009-02-26 15:32 157,219 a------- c:\windows\hphins26.dat
2009-02-22 02:47 127,034 -----r-- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-02-20 00:53 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-02-20 00:53 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-09 06:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-09 06:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2009-02-06 18:06 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-31 18:12 674 a------- c:\docume~1\compaq~1\applic~1\wklnhst.dat
2006-08-04 18:56 32 a--sh--- c:\windows\sminst\HPCD.SYS
2008-09-29 16:32 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092920080930\index.dat
============= FINISH: 19:24:20.93 ===============
Hi
It's possible that recovery console was already installed. At least log didn't list it as missing.
There are still some signs of Norton there. Please run removal tool found here (http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039).
Open notepad and copy/paste the text in the quotebox below into it:
File::
c:\windows\system32\gebunefi.exe
c:\windows\system32\zotemiso.exe
c:\windows\system32\pokarisu.exe
c:\windows\system32\jirohowu.exe
c:\windows\system32\yovedevi.exe
c:\windows\system32\gebunefi.exe
Folder::
c:\program files\uTorrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent
c:\program files\iWin.com
c:\program files\Search Settings
DDS::
TB: {D0943516-5076-4020-A3B5-AEFAF26AB263} - No File
Trusted Zone: trymedia.com
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=-
"UpdatesDisableNotify"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=-
Save this as
CFScript
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Close all browsers and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.
Uninstall old Adobe Reader versions and get the latest one here (http://www.filehippo.com/download_adobe_reader/) or get Foxit Reader here (http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm). Make sure you don't install toolbar if choose Foxit Reader!
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...
Updating Java:
Download the latest version of Java Runtime Environment (JRE) 6 Update 13 (http://java.sun.com/javase/downloads/index.jsp).
Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version. Uncheck MSN toolbar if it's offered there.
Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.
Double-click ATF Cleaner.exe to open it
Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.
If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Click Exit on the Main menu to close the program.
Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/virusscanner) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).
Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
cinthetik
2009-04-14, 02:56
Thanks again blade. i'm not positive but it seems like you got all the malware gone. my game runs alot smoother now, as well as the whole box. thanks alot man! heres the logs you asked for
Kaspersky online scanner
Scan statistics
Files scanned 146727
Threat names 0
Infected objects 0
Suspicious objects 0
Duration of the scan 03:56:41
New ComboFix Log
ComboFix 09-04-13.07 - Compaq_Administrator 2009-04-14 12:49.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.594 [GMT -5:00]
Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Administrator\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\system32\gebunefi.exe
c:\windows\system32\jirohowu.exe
c:\windows\system32\pokarisu.exe
c:\windows\system32\yovedevi.exe
c:\windows\system32\zotemiso.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\(TPB) Haystak MP3 Collection.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\~Saliva.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\10,000 BC.[2008].DVDRIP.XVID.[Eng]-DUQA.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\2 Live Crew Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\3 Melancholy Gypsys - The Penguins EP.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\3 Melancholy Gypsys.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\30 Seconds To Mars - Complete Discography [320KBPS].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\8Ball & 8 Ways Ent - Light Up The Bomb (2006) - Rap By FEFE2003.rar.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\8ball & MJG - Comin Out Hard and On Top Of The World.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\8Ball & MJG - We Are The South (Greatest Hits).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\8Ball_&_MJG-Tennessee_Pimpin-(DJ Wally Sparks)-2006.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\911 mysteries demolition.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\9th wonder.1.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\A Guide To Recognizing Your Saints.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Affliction.Day.of.Reckoning.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Alabama - For the Record (1998) [V0].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Alice Cooper.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\America's.Most.Wanted.Secret.Recipes-c00L.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\America's_Most_Wanted_Secret_Recipes-Uploaded By MARZone.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\As Daylight Dies [Special Edition].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Atmosphere - When Life Gives You Lemons, You Paint That Shit Gold.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Atmosphere Airlines Vol 2.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Atmosphere.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Atreyu.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Australia[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Avenged Sevenfold.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Babylon.A.D.[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Bad Boys II (2003) [DVDRip][1337x][Wolphie].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Bangkok Dangerous[2008]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Barbie and the Diamond Castle.[2008].DVDRIP.XVID.[Eng]-DUQA.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Barney's Colourful World,Live! - DvdRip.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Barney - The Land Of Make Believe - DvdRip.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Beastie Boys Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Beastie Boys.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Bedtime Stories[2008]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Beer For My Horses 2008 DvDrip[Eng]-greenbud1969.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Best Of Country Songs.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Beyond - Comparison.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Blindness 2008 DVDScr H264 AAC-SecretMyth (Kingdom-Release).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Body of Lies[2008]DVDrip[AC-3(5.1)ENG][UKB-RG Xvid]-keltz.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Bolt[2008]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Bone.Thugs-N-Harmony-Midwest.Warriors-(Bootleg)-2008-[NoFS].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Bones Season 3.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\BORN LIKE THIS. (5 Track Promo Sampler).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Brad Paisley - Fifth Gear.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Brad Paisley - Mud On The Tires.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Brad Paisley - Play (V0).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Brad Paisley - Time Well Wasted - FLAC.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Brad Paisley - Time Well Wasted.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Brother Ali & Plain Ole Bill - Where'd You Get That Funk From.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Brother Bear 2 [2006] Eng [DVDRiP] -=Flint=-.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Bullet for my Valentine Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Burn.After.Reading[2008][ENG]DVDRip.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\C-Dub-Special_Music_The_Mixtape-(Bootleg)-2006-RAGEMP3.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Cadillac Records 2008 DVDRip[A Release-Lounge H.264 by Titan].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Chamillionaire - Mixtape Messiah 5-2008-MIXFIEND.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Changeling.2008.DvDRip-FxM.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\City.Of.Ember[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Crank [2006-HDDVDRip-H.264]-NewArtRiot.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Crucial Conflict - Good Side Bad Side (1998).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Crucial Conflict - The Final Tic (1996).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Crucial_Conflict-Planet_Crucon-2008-RAGEMP3.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Death.Race.R5.LiNE.JARKO3333.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Death.Race[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\DEATH.THE.ULTIMATE.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Dessa-Doomtree_False Hopes.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Devildriver.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\dht.dat
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Do Or Die.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Dollhouse.S01E01.HDTV.XviD-LOL.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eagle Eye 2008 DVDRip H264-KingBen (Kingdom-Release).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eagle Eye[2008]DVDrip[AC-3(5.1)ENG][a UKB-RG Xvid by]- keltz.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eagle.Eye.DVDSCR.XviD-HEFTY(no rars).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eagle.Eye[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eligh.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Elmo in Grouchland.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eyedea -The Many Faces of Oliver Hart.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eyedea & Abilities-E&A.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eyedea & Abilities - First Born.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Eyedea & Abilities_Road Mix.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Face_Candy-This_Is_Where_We_Were-2006-C4.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\False Hopes Mega!.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Finch.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Five Finger Death Punch -Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Flash.Of.Genius[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Foo Fighters.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Framing Hanley - Lollipop (Lil Wayne Cover) Tagged [[JohnPiracy]].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Frozen River (2008) DVDR XviD DivXNL-Team(dutch subs NL).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Gandalf's Beat Machine.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Garth Brooks - The Collection.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Gas Dream.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\George Strait - 50 Number Ones.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\George Strait - It Just Comes Natural.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\George Strait - Latest Greatest Straitest Hits (V0).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\George Strait - Troubadour.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Ghost Whisperer Season 01.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Ghost Whisperer Season 2.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Ghost Whisperer Season 3.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Godmack - 5 Albums 1998-2006.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Gone in 60 seconds (1974).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Grouch.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Hancock[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Haystak Albums.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\HBO.Boxing.De.La.Hoya.vs.Pacquiao.MAIN.EVENT.HDTV.XviD-aAF.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Hollywood Undead.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Hoobastank Discography -Muffins.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Igor[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\ill niño Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Incendiary.2008.LIMITED.DVDRip.XviD-AMIABLE.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Insane Clown Posse.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Iraq.for.Sale.The.War.Profiteers.2006.DivX.AC3.pb.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Iron Man 2008.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Iron.Man[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\John Cena & The Trademarc - You Can't See Me.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Joy Ride 2 - Dead Ahead 2008 DVDRip XviD AC3-FLAWL3SS.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Kama Sutra ebooks etext Lovers Guide to Sexual Positions.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Kanye West - 808s and Heartbreak (V0 VBR).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Katt.Williams.Internet.Dating.2008.DVDRip.XviD-ARiGOLD.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\King of New York.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\KING OF NEWYORK[DVDRIP][ENG]-JOCKTHERIPPER.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Kiss Kiss Bang Bang [2005-HDDVDRip-H.264]-NewArtRiot.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Lab.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Lakeview Terrace (2008) DVDR DivXNL-Team.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Legendary Music Volume 1.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Legendary.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Lil_Young-Juvenile_Delinquent-(Bootleg).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Limp Bizkit - Complete discography 9 Albums.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Linkin Park.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Lion King Collection.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Living Legends - Four Track Avengers Vol. 1.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Living Legends.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Lost.Boys.2.The.Tribe.DVDR-GRiM-REPACK.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Ludacris_-_Theater_Of_The_Mind-2008-YSP.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Lyfe Jennings - Lyfe Change.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Lyfe_Jennings-Lyfe_268-192_Special_Edition-2005-MTD.rar.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\MADAGASCAR-2005[DVDRIP][ENG]-KIDZCORNER&J.T.R.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Madagascar-Escape.2.Africa((2008))DVDrip.Bigbro.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Make.It.Happen[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Mama Mia (2008) HLS DVDRip KvCD hoopsbhoy (TLS Release).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Manny Pacquiao vs Oscar De La Hoya MGM Grand, Las Vegas, Nevada 06.12.2008.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Marley & Me[2008]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Max.Payne[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Metallica - Discography 1983-2008 (19 Albums, 23 CDs).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\MF DOOM - MM.. Food V0.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\MF Doom.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Milk (2008) [DvdRip] [Xvid] {1337x}-Noir.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Milk.DVDRip.XviD-DiAMOND[SpaEstrenos].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Miracle.At.St.Anna[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Mirrors (2008) R5 Line Occor.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Monsters, Inc.[2001]DvDrip[Eng]-Stealthmaster.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\MOVIES - BOLT divx.total by globe@.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Mr. Lucci - 100 Percent Real (2007).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\MUDVAYNE - DISCOGRAPHY.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\MURS.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Musab - Respect The Life.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\My Best Friends Girl R5 LINE XviD-COALiTiON.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\My Chemical Romance.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\my will.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\N.W.A.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Nappy_Roots-Wooden_Leather-(Explicit_Retail)-2003-RNS.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Never Back Down Soundtrack.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Nine Inch Nails Discography (Kingdom-music by KloWn).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Open.Season.2[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Oregon Trail II.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\oregondlx.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Otep discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\P.O.S. - Audition (V0).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\P.O.S. - Ipecac Neat (V0).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\P.O.S. - Never Better.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Pantera.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Passengers ((2008)) DVDrip(divx)BigbrO.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Personal Effects (2009) [DvdRip] [Xvid] {1337x}-Noir.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Pineapple.Express[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Playa Jay Tee.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\POD Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Pride.And.Glory[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Prince.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\PURE_COUNTRY[1992]DvDrip[ENG 16x9]-Osuald.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Q-Tip_-_The_Renaissance-2008-YSP.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Quantum.Of.Solace[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Quarantine.[2008].RETAIL.DVDRIP.XVID.[Eng]-DUQA.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Questlove & Black Thought 2009-03-07 FLAC16.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Rambo[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Randy Travis - Around The Bend.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Red Hot Chili Peppers - Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\resume.dat
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Rich Boy - Rich Boy - 2007.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Righteous.Kill[2008]-(thismoviesonme.com).avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Righteous.Kill[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Rock And Roll Jesus.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\RocknRolla[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Role.Models[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\rss.dat
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Sad Clown Bad Summer Number 9.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Sage Francis - A Healthy Distrust (2005).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Saw V Unrated[2008]DVDrip[AC-3(5.1)ENG][a UKB-RG Xvid by]- keltz.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Scarface.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Seether - Complete Discography (2000-2007 6 Albums).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\settings.dat
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Seven.Pounds[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Sex.Drive[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Shadow.Company.2006.FESTIVAL.DOC.DVDRip.XviD-SAPHiRE.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Shrek 2.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Sidewaydaze.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Silverchair.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Slayer 1.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Slipknot.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Slug & MURS.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Slumdog Millionaire[2008]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\SpongeBob.Vs.The.Big.One.DVDRip.XviD-DEViSE.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Step.Brothers[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\STUDIO ALBUMS.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Sugarland- Twice the Speed of Life (V0).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Sugarland - 2008 - Love On The Inside (Deluxe Fan Edition).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Sugarland - Enjoy the Ride (2006) [FLAC].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Swishahouse-Salute_2_Tha_Hood-(Bootleg)-2009-GT4.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\T.I.-Paper_Trail-(Proper)-2008-C4.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Taylor Swift - Beautiful Eyes.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Taylor Swift - Fearless.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Taylor Swift - Taylor Swift [V0].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Tela.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The 911 Report.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Alphabet Killer[2008]DvDrip[Eng]-FXG.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Brothers Grime.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\THE CURIOUS CASE of BENJAMIN BUTTON (2008) PROPER DVDRIP - SUPER EXCELLENT VIDEO and AUDIO.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Fixtape Vol. 1 - Smoke On This.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Illuminati (2005).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Incredible Hulk(2008)Xvid(DVDRip)- keltz.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Judds - Number 1 Hits.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Offspring.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Righteous Brothers Project.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\the roots.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Strangers Unrated[2008]DvDrip[Eng]-NikonXp.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Tale of Despereaux (2008) [DvdRip] [Xvid] {1337x}-Noir.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Ultimate Fighter 8.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Ultimate Fighter Season 1.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Ultimate Fighter Season 4 (complete).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The White Stripes Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The Wizard In The Mountain.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The.Boy.In.The.Striped.Pyjamas[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The.Chronicles.Of.Narnia-Prince.Caspian[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The.Dark.Knight[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The.Day.The.Earth.Stood.Still[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The.Gene.Generation.2007.LIMITED.DVDSCR.XviD-COALiTiON.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The.Mummy-Tomb.Of.The.Dragon.Emperor[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The.Spirit.PROPER.DVDRip.XViD-PUKKA.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\The.Way.Of.War.2008.LiMiTED.DVDRip.XViD-iMMORTALs.[www.torrentfive.com].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\THEORY OF A DEADMAN.1.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Theory of a Deadman.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\This Is Where We Were (V0).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Three Days Grace - Discography.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\TinkerBell_DvdRip_2008[jars].avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Toby Keith - 35 Biggest Hits.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Toby Keith - That Don't Make Me A Bad Guy (V0).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Traitor - DVDRip - 2008 - Drama-Thriller.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Transporter.3[2008]DvDrip-786.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Trapt.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Tropic Thunder Unrated 2008 DVDRip H264 5.1 ch-SecretMyth (Kingdom-Release).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\TUF Se.9.Ep.1.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Twilight.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Twilight[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Tyler.Perrys.The.Family.That.Preys.DVDRip.XviD-Larceny.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC 94 - St.Pierre vs Penn II (Full).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.1-20.Collection.Xvid-TSD.PACK.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.21-40.Collection.Xvid-TSD.PACK.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.41-60.Collection.Xvid-TSD.PACK.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.61-82.Collection.Xvid-TSD.PACK.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.85.Bedlam.PPV.HDTV.XviD-aAF.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.87.Seek.And.Destroy.PPV.HDTV.XviD-aAF.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.88.Liddell.vs.Evans.PPV.HDTV.XviD-aAF.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.89.Bisping.vs.Leban.HDTV.XviD-aAF.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.90.Silva.vs.Cote.PPV.HDTV.XviD-aAF.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.92.The.Ultimate aAF.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.92.The.Ultimate.2008.DSR.XviD-XWT.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.93.Franklin.vs.Henderson.DSR.XviD-XWT.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.95.Sanchez.vs.Stevenson.DSR.XviD-XWT.avi.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.96.Rampage.vs.Jardine.DSR.XviD-XWT.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.Fight.For.The.Troops.2008.DSRip.XviD-aAF.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UFC.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\UHB I.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\uhb.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Underworld.Rise.Of.The.Lycans.R5.XViD-COALiTiON.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\VA - Everlasting God [2008].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Velvet Revolver Discography (LOSSLESS).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Wall-E[2008]DvDrip-aXXo.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Walt Disney - Brother Bear.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Wanted[2008]DvDrip-Xhora.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\What Dreams May Come (H-264 By Foxy).torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Who Needs Pictures-V2.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Win XP Pro SP3 PT-BR_WOMB.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\XIII The Conspiracy2008[TabsmanRip][H33T][Release].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Yes.Man.2008.DvDRip-FxM.torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Zack and Miri Make a Porno (2008) [djfred].torrent
c:\documents and settings\Compaq_Administrator\Application Data\uTorrent\Zeitgeist.Final.Edition.DVDRip.XviD.torrent
c:\program files\iWin.com
c:\program files\Search Settings
c:\program files\Search Settings\kb127\SearchSettings.dll
c:\program files\Search Settings\kb127\SearchSettingsRes409.dll
c:\program files\uTorrent
c:\program files\uTorrent\12639-utorrent.b329.dmp
c:\windows\system32\gebunefi.exe
c:\windows\system32\jirohowu.exe
c:\windows\system32\pokarisu.exe
c:\windows\system32\zotemiso.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-14 to 2009-04-14 )))))))))))))))))))))))))))))))
.
2009-04-12 22:45 . 2009-04-12 22:45 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-04-12 22:37 . 2009-04-12 22:37 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-04-09 16:55 . 2009-04-09 16:55 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\HP
2009-04-08 09:06 . 2009-04-08 09:06 -------- d-sh--w c:\documents and settings\Compaq_Administrator\PrivacIE
2009-04-08 08:54 . 2009-04-08 08:54 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-04-08 08:52 . 2009-04-08 08:52 -------- d-sh--w c:\documents and settings\Compaq_Administrator\IETldCache
2009-04-08 08:49 . 2009-04-08 08:49 -------- d-----w c:\windows\ie8updates
2009-04-08 08:46 . 2009-04-08 08:47 -------- dc-h--w c:\windows\ie8
2009-04-08 08:44 . 2009-02-28 04:55 105984 ------w c:\windows\system32\dllcache\iecompat.dll
2009-04-08 08:13 . 2009-04-08 08:13 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-04-08 04:21 . 2008-06-13 11:05 272128 ------w c:\windows\system32\dllcache\bthport.sys
2009-04-08 04:21 . 2009-03-08 09:34 1206784 ----a-w c:\windows\system32\dllcache\urlmon.dll
2009-04-08 04:21 . 2008-10-16 01:00 1499136 ------w c:\windows\system32\dllcache\shdocvw.dll
2009-04-08 04:20 . 2008-08-14 10:09 2145280 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-08 04:20 . 2008-08-14 10:11 2189184 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-08 04:20 . 2008-08-14 09:33 2023936 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-08 04:20 . 2008-08-14 09:33 2066048 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-08 04:20 . 2008-05-08 14:02 203136 ------w c:\windows\system32\dllcache\rmcast.sys
2009-04-08 04:20 . 2008-10-24 11:21 455296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-08 04:20 . 2008-12-11 10:57 333952 ------w c:\windows\system32\dllcache\srv.sys
2009-04-08 04:19 . 2008-04-11 19:04 691712 ------w c:\windows\system32\dllcache\inetcomm.dll
2009-04-08 04:19 . 2008-10-15 16:34 337408 ------w c:\windows\system32\dllcache\netapi32.dll
2009-04-08 04:09 . 2009-04-08 04:09 -------- d-----w c:\windows\system32\scripting
2009-04-08 04:09 . 2009-04-08 04:09 -------- d-----w c:\windows\l2schemas
2009-04-08 04:09 . 2009-04-08 04:09 -------- d-----w c:\windows\system32\en
2009-04-08 04:09 . 2009-04-08 04:09 -------- d-----w c:\windows\system32\bits
2009-04-08 04:05 . 2009-04-08 04:09 -------- d-----w c:\windows\ServicePackFiles
2009-04-08 04:00 . 2009-04-08 08:48 1355 ----a-w c:\windows\imsins.BAK
2009-04-08 03:47 . 2009-04-08 03:55 -------- d-----w c:\windows\system32\NtmsData
2009-04-08 01:57 . 2009-04-08 01:57 -------- d-----w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\ESET
2009-04-08 01:53 . 2009-04-08 01:53 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-04-07 22:40 . 2009-04-08 01:20 -------- d-----w c:\documents and settings\Administrator\.housecall6.6
2009-04-07 22:40 . 2009-04-07 22:40 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-04-07 22:20 . 2009-04-07 22:21 -------- d-----w c:\documents and settings\Compaq_Administrator\.housecall6.6
2009-03-30 14:57 . 2009-03-30 14:57 268 ---h--w C:\sqmdata10.sqm
2009-03-30 14:57 . 2009-03-30 14:57 244 ---h--w C:\sqmnoopt10.sqm
2009-03-28 07:03 . 2009-03-28 08:29 601 ----a-w c:\windows\cdplayer.ini
2009-03-28 06:57 . 2009-03-28 06:57 -------- d-----w c:\documents and settings\All Users\Application Data\FreeRIP
2009-03-27 04:59 . 2009-03-27 04:59 -------- d-----w c:\documents and settings\All Users\Application Data\id Software
2009-03-22 08:01 . 2008-10-10 18:36 128840 ----a-w c:\windows\system32\MSWINSCK.ocx
2009-03-18 23:36 . 2009-03-18 23:36 -------- d-----w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\ATI
2009-03-18 23:36 . 2009-03-18 23:36 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\ATI
2009-03-18 23:36 . 2009-03-18 23:36 -------- d-----w c:\documents and settings\All Users\Application Data\ATI
2009-03-18 23:35 . 2009-03-18 23:35 0 ----a-w c:\windows\ativpsrm.bin
2009-03-18 23:25 . 2008-05-20 23:53 93696 ----a-r c:\windows\system32\drivers\AtiHdmi.sys
2009-03-18 23:25 . 2008-06-03 02:05 593920 ------w c:\windows\system32\ati2sgag.exe
2009-03-18 23:25 . 2008-05-22 18:46 13848 ----a-r c:\windows\atiogl.xml
2009-03-18 23:24 . 2008-06-03 03:22 413696 ----a-r c:\windows\system32\ATIDEMGX.dll
2009-03-18 23:24 . 2008-06-03 02:47 887724 ----a-r c:\windows\system32\ativva6x.dat
2009-03-18 23:24 . 2008-06-03 02:47 3107788 ----a-r c:\windows\system32\ativva5x.dat
2009-03-18 23:24 . 2008-06-03 02:47 3107788 ----a-r c:\windows\system32\ativvaxx.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-14 17:46 . 2008-06-20 18:03 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\mIRC
2009-04-14 07:41 . 2009-01-14 07:27 138944 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-14 07:41 . 2009-01-14 07:27 189784 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-14 00:43 . 2008-05-13 03:31 -------- d-----w c:\program files\mIRC
2009-04-12 22:40 . 2006-06-22 22:04 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-11 06:48 . 2009-04-11 06:47 -------- d-----w c:\program files\ERUNT
2009-04-11 06:01 . 2008-05-14 16:05 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-11 05:56 . 2008-05-14 16:05 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-09 21:57 . 2008-12-17 01:31 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\DVD Flick
2009-04-09 20:11 . 2008-09-28 17:35 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\dvdcss
2009-04-08 20:47 . 2008-08-13 15:14 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\Move Networks
2009-04-08 19:50 . 2006-06-22 21:33 72880 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-08 09:15 . 2008-06-21 04:22 -------- d-----w c:\program files\Yahoo!
2009-04-08 09:14 . 2008-05-14 18:01 -------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-04-08 09:14 . 2006-06-22 21:25 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-08 09:14 . 2006-06-22 21:30 -------- d-----w c:\program files\Common Files\Sonic Shared
2009-04-08 09:13 . 2006-06-22 21:35 -------- d-----w c:\program files\Sonic
2009-04-08 09:11 . 2006-06-22 21:48 -------- d-----w c:\program files\Quicken
2009-04-08 09:10 . 2006-06-22 21:36 -------- d-----w c:\program files\HP Games
2009-04-08 09:06 . 2008-09-22 17:12 -------- d-----w c:\program files\Common Files\Pure Networks Shared
2009-04-08 08:44 . 2009-03-02 20:29 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\HPAppData
2009-04-08 04:33 . 2009-01-27 23:51 -------- d-----w c:\program files\MSN Messenger
2009-04-08 04:13 . 2005-08-31 04:01 92947 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-08 04:12 . 2009-04-08 04:12 45056 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2009-04-08 04:12 . 2009-04-08 04:12 44032 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2009-04-08 04:12 . 2009-04-08 04:12 40960 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2009-04-08 04:12 . 2009-04-08 04:12 32768 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2009-04-08 04:12 . 2009-04-08 04:12 32768 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2009-04-08 04:12 . 2009-04-08 04:12 217088 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
2009-04-08 04:12 . 2009-04-08 04:12 61440 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2009-04-08 04:12 . 2009-04-08 04:12 341048 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2009-04-08 04:12 . 2009-04-08 04:12 163840 ----a-w c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2009-04-08 04:01 . 2004-08-10 11:00 250048 --sh--r C:\ntldr
2009-04-08 01:53 . 2009-04-08 01:53 -------- d-----w c:\program files\ESET
2009-04-08 01:43 . 2008-10-28 20:49 -------- d-----w c:\program files\Charter High-Speed Security Suite
2009-04-08 01:40 . 2008-05-13 02:28 -------- d-----w c:\documents and settings\All Users\Application Data\F-Secure
2009-03-28 06:58 . 2009-03-28 06:57 -------- d-----w c:\program files\FreeRIP3
2009-03-27 05:00 . 2009-01-14 07:27 22328 ----a-w c:\documents and settings\Compaq_Administrator\Application Data\PnkBstrK.sys
2009-03-27 05:00 . 2009-01-14 07:27 2246144 ----a-w c:\windows\system32\pbsvc.exe
2009-03-26 01:40 . 2009-03-26 01:40 -------- d-----w c:\program files\Windows Defender
2009-03-24 18:51 . 2008-08-04 20:57 -------- d-----w c:\program files\DVDMagic
2009-03-24 08:06 . 2009-03-24 08:06 -------- d-----w c:\program files\DVD Flick
2009-03-23 03:36 . 2008-05-14 16:32 -------- d-----w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-03-23 03:36 . 2008-05-14 16:32 -------- d-----w c:\program files\Security Task Manager
2009-03-22 08:03 . 2009-03-22 08:01 -------- d-----w c:\program files\CamFrog
2009-03-18 23:34 . 2009-03-18 23:26 -------- d-----w c:\program files\Common Files\ATI Technologies
2009-03-18 23:33 . 2006-06-22 21:25 -------- d-----w c:\program files\ATI Technologies
2009-03-18 23:28 . 2006-06-22 21:25 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-12 05:13 . 2009-01-14 07:27 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-03-08 19:09 . 2009-03-08 19:09 638816 ------w c:\windows\system32\dllcache\iexplore.exe
2009-03-08 19:09 . 2009-03-08 19:09 391536 ------w c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 09:41 . 2008-04-21 06:44 5937152 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-03-08 09:34 . 2008-04-21 06:44 914944 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-03-08 09:34 . 2004-08-10 04:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2009-03-08 09:34 236544 ------w c:\windows\system32\dllcache\webcheck.dll
2009-03-08 09:34 . 2009-03-08 09:34 43008 ------w c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 09:34 . 2004-08-10 04:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 09:34 . 2009-03-08 09:34 105984 ------w c:\windows\system32\dllcache\url.dll
2009-03-08 09:34 . 2009-03-08 09:34 193536 ------w c:\windows\system32\dllcache\msrating.dll
2009-03-08 09:34 . 2009-03-08 09:34 109568 ------w c:\windows\system32\dllcache\occache.dll
2009-03-08 09:33 . 2009-03-08 09:33 759296 ------w c:\windows\system32\dllcache\VGX.dll
2009-03-08 09:33 . 2009-03-08 09:33 18944 ------w c:\windows\system32\dllcache\corpol.dll
2009-03-08 09:33 . 2004-08-10 04:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2009-03-08 09:33 25600 ------w c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 09:33 . 2008-05-09 10:53 726528 ----a-w c:\windows\system32\dllcache\jscript.dll
2009-03-08 09:33 . 2009-03-08 09:33 229376 ------w c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 09:33 . 2008-05-09 10:53 420352 ----a-w c:\windows\system32\dllcache\vbscript.dll
2009-03-08 09:33 . 2004-08-10 04:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 09:33 . 2009-03-08 09:33 125952 ------w c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 09:32 . 2009-03-08 09:32 72704 ------w c:\windows\system32\dllcache\admparse.dll
2009-03-08 09:32 . 2004-08-10 04:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2009-03-08 09:32 173056 ------w c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 09:32 . 2004-08-10 04:00 163840 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-03-08 09:32 . 2009-03-08 09:32 71680 ------w c:\windows\system32\dllcache\iesetup.dll
2009-03-08 09:32 . 2009-03-08 09:32 55808 ------w c:\windows\system32\dllcache\iernonce.dll
2009-03-08 09:32 . 2004-08-10 04:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 09:32 . 2009-03-08 09:32 128512 ------w c:\windows\system32\dllcache\advpack.dll
2009-03-08 09:32 . 2009-03-08 09:32 94720 ------w c:\windows\system32\dllcache\inseng.dll
2009-03-08 09:32 . 2009-03-08 09:32 611840 ------w c:\windows\system32\dllcache\mstime.dll
2009-03-08 09:31 . 2009-03-08 09:31 183808 ------w c:\windows\system32\dllcache\iepeers.dll
2009-03-08 09:31 . 2009-03-08 09:31 348160 ------w c:\windows\system32\dllcache\dxtmsft.dll
2009-03-08 09:31 . 2009-03-08 09:31 34816 ------w c:\windows\system32\dllcache\imgutil.dll
2009-03-08 09:31 . 2009-03-08 09:31 216064 ------w c:\windows\system32\dllcache\dxtrans.dll
2009-03-08 09:31 . 2004-08-10 04:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2009-03-08 09:31 46592 ------w c:\windows\system32\dllcache\pngfilt.dll
2009-03-08 09:31 . 2009-03-08 09:31 66560 ------w c:\windows\system32\dllcache\mshtmled.dll
2009-03-08 09:31 . 2009-03-08 09:31 48128 ------w c:\windows\system32\dllcache\mshtmler.dll
2009-03-08 09:31 . 2004-08-10 04:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2009-03-08 09:31 45568 ------w c:\windows\system32\dllcache\mshta.exe
2009-03-08 09:31 . 2004-08-10 04:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 09:24 . 2009-03-08 09:24 68608 ------w c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 09:22 . 2004-08-10 04:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-08 09:22 . 2004-08-10 04:00 156160 ----a-w c:\windows\system32\dllcache\msls31.dll
2009-03-02 21:19 . 2006-06-22 21:34 -------- d-----w c:\program files\Common Files\Real
2009-03-02 21:11 . 2006-06-22 22:01 -------- d-----w c:\program files\Google
2009-03-02 21:11 . 2006-06-22 21:05 -------- d-----w c:\program files\GemMaster
2009-03-02 21:10 . 2008-12-17 01:16 -------- d-----w c:\documents and settings\Compaq_Administrator\Application Data\Vso
2009-03-02 21:10 . 2008-12-17 01:16 47360 ----a-w c:\documents and settings\Compaq_Administrator\Application Data\pcouffin.sys
2009-03-02 20:00 . 2008-05-14 17:59 -------- d-----w c:\program files\PokerStars
2009-03-02 01:18 . 2009-03-02 01:18 268 ---h--w C:\sqmdata09.sqm
2008-08-14 00:2008-08-26 01:06 02:10 . c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-13_18.11.45.85 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-14 07:27 . 2009-04-14 07:41 189784 c:\windows\system32\PnkBstrB.exe
- 2009-01-14 07:27 . 2009-04-08 06:54 189784 c:\windows\system32\PnkBstrB.exe
+ 2009-01-14 07:27 . 2009-04-14 07:41 138944 c:\windows\system32\drivers\PnkBstrK.sys
- 2009-01-14 07:27 . 2009-04-08 06:54 138944 c:\windows\system32\drivers\PnkBstrK.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2008-11-26 2235920]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 c:\windows\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 c:\windows\KHALMNPR.Exe]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-06-22 27136]
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Compaq Connections.lnk - c:\program files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-06-22 36903]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-02-22 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-02-22 692224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-05-20 93696]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PNKBSTRB
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9d908a47-2217-11de-94c4-001731b9c969}]
\Shell\AutoRun\command - L:\rcaeasyrip_setup.exe
\Shell\install\command - L:\rcaeasyrip_setup.exe
\Shell\usermanualEnglish\command - L:\rcaeasyrip_setup.exe /pdf_English
\Shell\usermanualFrench\command - L:\rcaeasyrip_setup.exe /pdf_French
\Shell\usermanualSpanish\command - L:\rcaeasyrip_setup.exe /pdf_Spanish
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf25a923-e659-11dd-948b-001731b9c969}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f96ae82b-a61b-11dd-945f-001731b9c969}]
\Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-04-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\dehyd12c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.charter.net/index.php
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\dehyd12c.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npImgCtl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-14 12:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-04-14 12:57
ComboFix-quarantined-files.txt 2009-04-14 17:57
ComboFix2.txt 2009-04-13 23:13
Pre-Run: 78,265,552,896 bytes free
Post-Run: 78,287,355,904 bytes free
617 --- E O F --- 2009-04-14 17:56
cinthetik
2009-04-14, 02:57
and new dds log
DDS (Ver_09-03-16.01) - NTFSx86
Run by Compaq_Administrator at 18:49:44.18 on Tue 04/14/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.568 [GMT -5:00]
AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Robz Shit\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\compaq~1.lnk - c:\program files\compaq connections\5577497\program\Compaq Connections.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://charter.net/files/charter/securitysuite/fscax.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\dehyd12c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.charter.net/index.php
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: c:\program files\mozilla firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npImgCtl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npkimi.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
============= SERVICES / DRIVERS ===============
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-2-6 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-2-6 93336]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-2-6 727720]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-3-18 93696]
=============== Created Last 30 ================
2009-04-14 14:24 268 a---h--- C:\sqmdata12.sqm
2009-04-14 14:24 244 a---h--- C:\sqmnoopt12.sqm
2009-04-14 13:32 268 a---h--- C:\sqmdata11.sqm
2009-04-14 13:32 244 a---h--- C:\sqmnoopt11.sqm
2009-04-14 13:24 73,728 a------- c:\windows\system32\javacpl.cpl
2009-04-14 13:21 <DIR> --d----- c:\documents and settings\compaq_administrator\.SunDownloadManager
2009-04-12 17:59 161,792 a------- c:\windows\SWREG.exe
2009-04-12 17:59 98,816 a------- c:\windows\sed.exe
2009-04-12 17:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-04-08 04:06 <DIR> --dsh--- c:\documents and settings\compaq_administrator\PrivacIE
2009-04-08 03:57 <DIR> --d----- c:\windows\system32\appmgmt
2009-04-08 03:52 <DIR> --dsh--- c:\documents and settings\compaq_administrator\IETldCache
2009-04-08 03:49 <DIR> --d----- c:\windows\ie8updates
2009-04-08 03:46 <DIR> -cd-h--- c:\windows\ie8
2009-04-08 03:44 105,984 -------- c:\windows\system32\dllcache\iecompat.dll
2009-04-07 23:21 272,128 -------- c:\windows\system32\dllcache\bthport.sys
2009-04-07 23:21 1,206,784 a------- c:\windows\system32\dllcache\urlmon.dll
2009-04-07 23:21 1,499,136 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-04-07 23:20 2,145,280 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-07 23:20 2,189,184 -------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-07 23:20 2,023,936 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-07 23:20 2,066,048 -------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-07 23:20 203,136 -------- c:\windows\system32\dllcache\rmcast.sys
2009-04-07 23:20 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-04-07 23:20 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-04-07 23:19 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-04-07 23:19 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\scripting
2009-04-07 23:09 <DIR> --d----- c:\windows\l2schemas
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\en
2009-04-07 23:09 <DIR> --d----- c:\windows\system32\bits
2009-04-07 23:05 <DIR> --d----- c:\windows\ServicePackFiles
2009-04-07 22:47 <DIR> --d----- c:\windows\system32\NtmsData
2009-04-07 20:53 <DIR> --d----- c:\program files\ESET
2009-04-07 20:26 <DIR> --d----- c:\windows\pss
2009-04-07 17:40 664 a------- c:\windows\system32\d3d9caps.dat
2009-04-07 17:20 <DIR> --d----- c:\documents and settings\compaq_administrator\.housecall6.6
2009-03-30 09:57 268 ----h--- C:\sqmdata10.sqm
2009-03-30 09:57 244 ----h--- C:\sqmnoopt10.sqm
2009-03-28 02:03 601 a------- c:\windows\cdplayer.ini
2009-03-28 01:57 <DIR> --d----- c:\docume~1\alluse~1\applic~1\FreeRIP
2009-03-28 01:57 <DIR> --d----- c:\program files\FreeRIP3
2009-03-26 23:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\id Software
2009-03-24 03:06 <DIR> --d----- c:\program files\DVD Flick
2009-03-22 03:01 128,840 a------- c:\windows\system32\MSWINSCK.ocx
2009-03-22 03:01 <DIR> --d----- c:\program files\CamFrog
2009-03-18 18:35 0 a------- c:\windows\ativpsrm.bin
2009-03-18 18:26 <DIR> --d----- c:\program files\common files\ATI Technologies
2009-03-18 18:25 93,696 a----r-- c:\windows\system32\drivers\AtiHdmi.sys
2009-03-18 18:25 593,920 -------- c:\windows\system32\ati2sgag.exe
2009-03-18 18:25 13,848 a----r-- c:\windows\atiogl.xml
2009-03-18 18:24 413,696 a----r-- c:\windows\system32\ATIDEMGX.dll
2009-03-18 18:24 887,724 a----r-- c:\windows\system32\ativva6x.dat
2009-03-18 18:24 3,107,788 a----r-- c:\windows\system32\ativva5x.dat
2009-03-18 18:24 3,107,788 a----r-- c:\windows\system32\ativvaxx.dat
==================== Find3M ====================
2009-04-14 13:23 410,984 a------- c:\windows\system32\deploytk.dll
2009-04-14 02:41 138,944 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-14 02:41 189,784 a------- c:\windows\system32\PnkBstrB.exe
2009-04-07 23:13 92,947 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-07 23:12 45,056 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\uninstallui\eHelpSetup.exe
2009-04-07 23:12 217,088 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
2009-04-07 23:12 61,440 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemutil.dll
2009-04-07 23:12 44,032 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\scripts\devcon.exe
2009-04-07 23:12 40,960 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\ScDmi.dll
2009-04-07 23:12 32,768 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\uploadHSC.dll
2009-04-07 23:12 32,768 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\Scom.dll
2009-04-07 23:12 341,048 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\HPBasicDetection3.dll
2009-04-07 23:12 163,840 a------- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemcheck.dll
2009-03-27 00:00 22,328 a------- c:\docume~1\compaq~1\applic~1\PnkBstrK.sys
2009-03-27 00:00 2,246,144 a------- c:\windows\system32\pbsvc.exe
2009-03-12 00:13 75,064 a------- c:\windows\system32\PnkBstrA.exe
2009-03-08 14:09 638,816 -------- c:\windows\system32\dllcache\iexplore.exe
2009-03-08 14:09 391,536 -------- c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 04:41 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\dllcache\wininet.dll
2009-03-08 04:34 236,544 -------- c:\windows\system32\dllcache\webcheck.dll
2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 04:34 43,008 -------- c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 04:34 105,984 -------- c:\windows\system32\dllcache\url.dll
2009-03-08 04:34 193,536 -------- c:\windows\system32\dllcache\msrating.dll
2009-03-08 04:34 109,568 -------- c:\windows\system32\dllcache\occache.dll
2009-03-08 04:33 759,296 -------- c:\windows\system32\dllcache\VGX.dll
2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 04:33 18,944 -------- c:\windows\system32\dllcache\corpol.dll
2009-03-08 04:33 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 04:33 726,528 a------- c:\windows\system32\dllcache\jscript.dll
2009-03-08 04:33 229,376 -------- c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\dllcache\vbscript.dll
2009-03-08 04:33 125,952 -------- c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 04:32 72,704 -------- c:\windows\system32\dllcache\admparse.dll
2009-03-08 04:32 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 04:32 163,840 a------- c:\windows\system32\dllcache\ieakui.dll
2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 04:32 71,680 -------- c:\windows\system32\dllcache\iesetup.dll
2009-03-08 04:32 55,808 -------- c:\windows\system32\dllcache\iernonce.dll
2009-03-08 04:32 128,512 -------- c:\windows\system32\dllcache\advpack.dll
2009-03-08 04:32 94,720 -------- c:\windows\system32\dllcache\inseng.dll
2009-03-08 04:32 611,840 -------- c:\windows\system32\dllcache\mstime.dll
2009-03-08 04:31 183,808 -------- c:\windows\system32\dllcache\iepeers.dll
2009-03-08 04:31 348,160 -------- c:\windows\system32\dllcache\dxtmsft.dll
2009-03-08 04:31 34,816 a------- c:\windows\system32\imgutil.dll
2009-03-08 04:31 216,064 -------- c:\windows\system32\dllcache\dxtrans.dll
2009-03-08 04:31 34,816 -------- c:\windows\system32\dllcache\imgutil.dll
2009-03-08 04:31 46,592 -------- c:\windows\system32\dllcache\pngfilt.dll
2009-03-08 04:31 66,560 -------- c:\windows\system32\dllcache\mshtmled.dll
2009-03-08 04:31 48,128 a------- c:\windows\system32\mshtmler.dll
2009-03-08 04:31 48,128 -------- c:\windows\system32\dllcache\mshtmler.dll
2009-03-08 04:31 45,568 a------- c:\windows\system32\mshta.exe
2009-03-08 04:31 45,568 -------- c:\windows\system32\dllcache\mshta.exe
2009-03-08 04:24 68,608 -------- c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\dllcache\msls31.dll
2009-03-02 16:10 47,360 a------- c:\docume~1\compaq~1\applic~1\pcouffin.sys
2009-02-26 15:32 157,219 a------- c:\windows\hphins26.dat
2009-02-22 02:47 127,034 -----r-- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-02-20 00:53 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-02-20 00:53 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-09 06:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-09 06:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2008-12-31 18:12 674 a------- c:\docume~1\compaq~1\applic~1\wklnhst.dat
2006-08-04 18:56 32 a--sh--- c:\windows\sminst\HPCD.SYS
2008-09-29 16:32 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092920080930\index.dat
============= FINISH: 18:50:50.51 ===============
lemme know how it looks but i think you did a great job! thanks again blade!
Hi
Please uninstall J2SE Runtime Environment 5.0 Update 5.
Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.
THESE STEPS ARE VERY IMPORTANT
Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
2. Reboot.
3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis
Now lets uninstall ComboFix:
Click START then RUN
Now type "c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe" /u in the runbox and click OK
Delete dds.com file and related logs.
UPDATING WINDOWS AND INTERNET EXPLORER
IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.
If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.
Make your Internet Explorer more secure
This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.
hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this (http://www.bleepingcomputer.com/forums/tutorial60.html) webpage out.
If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free (http://www.tallemu.com/free-firewall-protection-software.html) or Comodo Firewall Pro (http://www.personalfirewall.comodo.com/download_firewall.html#fw3.0) (If you choose Comodo: Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and install firewall ONLY!).
Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Once again, please post and tell me how things are going with your system... problems etc.
Have a great day,
Blade :cool:
cinthetik
2009-04-16, 03:40
hey blade. im trying to install all these security updates for windows, but when i goto that windows update page but i keep getting this message.
Thank you for your interest in obtaining updates from our site.
To use this site, you must be running Microsoft Internet Explorer 5 or later.
To upgrade to the latest version of the browser, go to the Internet Explorer Downloads website.
If you prefer to use a different web browser, you can obtain updates from the Microsoft Download Center or you can stay up to date with the latest critical and security updates by using Automatic Updates. To turn on Automatic Updates:
Click Start, and then click Control Panel.
Depending on which Control Panel view you use, Classic or Category, do one of the following:
Click System, and then click the Automatic Updates tab.
Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
Click the option that you want. Make sure Automatic Updates is not turned off.
-------
well i downloaded and installed internet explorer 8 twice, and for whatever reason it didn't work. it uninstalls the previous version, then asks for reboot, then installed IE 8 on the start up. i do everything, appears to install fine, but when i goto use IE i get this error. Internet explorer has encountered a problem and needs to close. we are sorry for the inconvenience. i hit debug it doesn't work. i hit close. it says this tab has been recovered. and then goto the link for the windows update installer, and it says i need IE 5 or later. kinda stumped it seems like the installing of IE 8 is going fun, but obviously isn't. any ideas??
Hi
Did you install any firewall there yet? Sometimes firewall, if not configured properly, may block the site from working correctly.
If that's not the case, have you tried compatibility view (http://www.microsoft.com/windows/internet-explorer/features/enhanced-navigation.aspx) to browse the site?
Also, I'd like to know did you modify IE security settings.
cinthetik
2009-04-19, 11:27
yeah i don't see that button on my IE. so i'm pretty sure that the install of IE8 isn't working. it seems to go fine during the install... get no prompts of it messing up. however its still not on 8 and getting errors when trying to use it.
Hi
Please uninstall Internet Explorer 8. You should end up with older browser. Then try access the update site with that. Let me know how it goes :)
Due to inactivity, this thread will now be closed.
Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.
If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.