Page 1 of 3 123 LastLast
Results 1 to 10 of 24

Thread: Coupon Printer

  1. #1
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default Coupon Printer

    My wife recently installed coupon printer and while I'm not 100% sure that this caused the problem, the computer has stopped functioning correctly. Here are the symptoms. After restart a box comes up that says "Multimedia Card Reader" with the message "Resource is not enough". Then a message comes up from Catalyst (the ati graphics card program) saying that you do not have rights to modify these settings (I am not modifying any settings.) This dialog box comes up twice. Once everything is all booted, there are a few other problems. First the toolbar is gone from the bottom of the desktop, Second internet explorer will not run (the screen flashes and that is it), third the network profiles aren't loaded and the network connections service doesn't run. Also right clicking doesn't allow me to paste. The following is my log file.

    We are running Windows XP Home Edition Media Center. The computer was running fine until these problems. We don't normally use this computer for browsing although it is connected to the internet. Ok here is the log file.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:02:37 AM, on 1/24/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Mozy\mozybackup.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\zHotkey.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\PROGRA~1\Yahoo!\YOP\yop.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Mozy\mozystat.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    F:\Demos\officeFX\InstallOfficeFX.exe
    C:\Program Files\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: AMUST 1-Login IE Helper - {FFF1A4CB-472E-404a-9898-0B73B6B2E421} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
    O3 - Toolbar: AMUST 1-Login Toolbar - {F5BAA0B9-0DBF-4b42-BE9C-B2513ED71737} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [AMUST 1-Login AutoUpdate] rundll32.exe "C:\Program Files\Common Files\AMUST\Updater\amupdater.dll",AMUSTUpdate AMUST 1-Login ONLYLOCAL
    O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
    O4 - HKUS\S-1-5-21-3690015938-2637564805-925999644-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
    O4 - HKUS\S-1-5-21-3690015938-2637564805-925999644-1008\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem (User '?')
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
    O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\Mozy\mozystat.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} (WebInstaller Control) - http://concept.gamberjohnson.com/cor...bInstaller.ocx
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} (WebInstaller Control) - http://gamber.conceptconfigurator.co...bInstaller.ocx
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1156216832609
    O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://targetphoto.kodakgallery.com/...2/axofupld.cab
    O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
    O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photofinale.com/ImageUplo...eUploader4.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activ...v2.0.0.10.cab?
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O21 - SSODL: EPItZZQy - {2CEC6C2A-8646-C680-0D65-0E74600C38E7} - C:\WINDOWS\system32\vokz.dll (file missing)
    O23 - Service: IPv6 Helper Service (6to4) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Application Management (AppMgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Windows Audio (AudioSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Computer Browser (Browser) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Bluetooth Support Service (BthServ) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Cryptographic Services (CryptSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: DCOM Server Process Launcher (DcomLaunch) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: DHCP Client (Dhcp) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Logical Disk Manager (dmserver) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Error Reporting Service (ERSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: COM+ Event System (EventSystem) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Fast User Switching Compatibility (FastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Help and Support (helpsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: HID Input Service (HidServ) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
    O23 - Service: Server (lanmanserver) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Workstation (lanmanworkstation) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: TCP/IP NetBIOS Helper (LmHosts) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: MHN - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: MozyHome Backup Service (MozyBackup) - Unknown owner - C:\Program Files\Mozy\mozybackup.exe
    O23 - Service: Network Connections (Netman) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Network Location Awareness (NLA) (Nla) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: Remote Access Auto Connection Manager (RasAuto) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Remote Access Connection Manager (RasMan) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Remote Registry (RemoteRegistry) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Remote Procedure Call (RPC) (RpcSs) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Secondary Logon (seclogon) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: System Event Notification (SENS) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Shell Hardware Detection (ShellHWDetection) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)
    O23 - Service: System Restore Service (srservice) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: SSDP Discovery Service (SSDPSRV) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Windows Image Acquisition (WIA) (stisvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: Telephony (TapiSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Terminal Services (TermService) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Themes - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Distributed Link Tracking Client (TrkWks) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Universal Plug and Play Device Host (upnphost) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Windows Time (W32Time) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: WebClient - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Windows Management Instrumentation (winmgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Portable Media Serial Number Service (WmdmPmSN) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Windows Management Instrumentation Driver Extensions (Wmi) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Wireless Zero Configuration (WZCSVC) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Network Provisioning Service (xmlprov) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

    --
    End of file - 18393 bytes

  2. #2
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Manchester UK
    Posts
    3,425

    Default

    Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

    If you think you have similar problems, please post a log in the HJT forum and wait for help.

    Hello and welcome to the forums

    My name is Katana and I will be helping you to remove any infection(s) that you may have.

    Please observe these rules while we work:
    1. Please Read All Instructions Carefully
    2. If you don't understand something, stop and ask! Don't keep going on.
    3. Please do not run any other tools or scans whilst I am helping you
    4. Please continue to respond until I give you the "All Clear"
      (Just because you can't see a problem doesn't mean it isn't there)

    If you can do those few things, everything should go smoothly

    Please Note, your security programs may give warnings for some of the tools I will ask you to use.
    Be assured, any links I give are safe

    ----------------------------------------------------------------------------------------




    Download and Run ComboFix (by sUBs)
    Please visit this webpage for instructions for downloading and running ComboFix:

    Bleeping Computer ComboFix Tutorial

    • You must download it to and run it from your Desktop
    • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
    • Double click combofix.exe & follow the prompts.
    • When finished, it will produce a log. Please save that log to post in your next reply
    • Re-enable all the programs that were disabled during the running of ComboFix..



    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
    This tool is not a toy and not for everyday use.
    ComboFix SHOULD NOT be used unless requested by a forum helper
    Microsoft MVP Consumer Security 2009 -2010
    If we have helped, please consider a donation
    THESE INSTRUCTIONS ARE FOR THIS USER ONLY

  3. #3
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default Combo Fix Log

    Thanks for replying. Here is the combofix log.

    ComboFix 09-01-21.04 - chullz 2009-01-30 22:03:33.1 - NTFSx86
    Running from: K:\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .
    - REDUCED FUNCTIONALITY MODE -
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    D:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-31 )))))))))))))))))))))))))))))))
    .

    2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
    2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
    2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a--c--- c:\windows\system32\dllcache\explorer.exe
    2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a------ c:\windows\explorer.exe
    2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
    2009-01-14 03:04 . 2008-08-28 04:04 333,056 --a------ c:\windows\system32\drivers\srv.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-23 02:37 505,856 ----a-w c:\windows\system32\winlogon.exe
    2009-01-23 02:37 14,336 ----a-w c:\windows\system32\lsass.exe
    2009-01-23 02:37 110,080 ----a-w c:\windows\system32\services.exe
    2009-01-22 20:39 --------- d-----w c:\program files\Common Files\Symantec Shared
    2009-01-22 00:07 --------- d-----w c:\program files\Google
    2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
    2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
    2009-01-06 00:49 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
    2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
    2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
    2009-01-06 00:49 --------- d-----w c:\program files\Symantec
    2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll
    2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
    2008-10-16 20:13 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-10-16 20:06 268,648 ----a-w c:\windows\system32\mucltui.dll
    2008-10-16 20:06 208,744 ----a-w c:\windows\system32\muweb.dll
    2008-10-03 20:34 625,032 ----a-w c:\windows\system32\SymNeti.dll
    2008-10-03 20:34 242,056 ----a-w c:\windows\system32\SymRedir.dll
    2008-10-03 10:15 247,326 ----a-w c:\windows\system32\strmdll.dll
    2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
    .

    ------- Sigcheck -------

    2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
    2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
    2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
    2008-04-13 18:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
    2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\user32.dll
    2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\dllcache\user32.dll

    2008-04-13 18:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ws2_32.dll
    2004-08-10 13:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll

    2004-09-29 12:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
    2005-01-27 11:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
    2005-03-10 01:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
    2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
    2007-03-07 11:40 823296 b8f4db39ca7353752f245379d285c80e c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
    2007-04-25 03:08 823808 431defbb4a3d7b0dc062c1b064623a2f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
    2007-06-27 08:40 824320 d6ed5e042c5207553e7f5e842918137f c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
    2007-08-20 04:02 825344 357d54bf94fe9d6d8505a96b5c2a3bca c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
    2007-10-10 17:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
    2007-12-06 20:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
    2008-03-01 07:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
    2008-04-22 21:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
    2008-06-23 10:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
    2008-08-26 03:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
    2008-10-16 14:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
    2006-05-09 23:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB916281$\wininet.dll
    2005-03-10 02:02 656896 6f018d6319be4f96426ea829b79e05d5 c:\windows\$NtUninstallKB916281_0$\wininet.dll
    2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$NtUninstallKB918899$\wininet.dll
    2006-06-23 05:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$NtUninstallKB922760$\wininet.dll
    2006-09-14 02:31 664576 d207370287cf769aebebf03837784963 c:\windows\ie7\wininet.dll
    2006-11-07 21:03 818688 92995334f993e6e49c25c6d02ec04401 c:\windows\ie7updates\KB928090-IE7\wininet.dll
    2007-01-12 09:27 822784 be43d00d802c92f01c8cc952c6f483f8 c:\windows\ie7updates\KB931768-IE7\wininet.dll
    2007-03-07 11:45 822784 5b35dae6e4886f64d1da58c4e3e01eb9 c:\windows\ie7updates\KB933566-IE7\wininet.dll
    2007-04-25 02:41 822784 0586a7f0b2fdb94d624f399d4728e7c8 c:\windows\ie7updates\KB937143-IE7\wininet.dll
    2007-06-27 08:34 823808 8068cbb58fe60cc95aeb2cff70178208 c:\windows\ie7updates\KB939653-IE7\wininet.dll
    2007-08-20 04:04 824832 774435e499d8e9643ec961a6103c361f c:\windows\ie7updates\KB942615-IE7\wininet.dll
    2007-10-10 17:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll
    2007-12-06 20:21 824832 806d274c9a6c3aaea5eae8e4af841e04 c:\windows\ie7updates\KB947864-IE7\wininet.dll
    2008-03-01 07:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll
    2008-04-22 22:16 826368 f6589be784647cfdbc22ea51ccb1a57a c:\windows\ie7updates\KB953838-IE7\wininet.dll
    2008-06-23 10:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
    2008-08-26 01:24 826368 ef8eba98145bfa44e80d17a3b3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
    2008-04-13 18:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wininet.dll
    2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\wininet.dll
    2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\dllcache\wininet.dll

    2005-03-13 19:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
    2006-04-20 06:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
    2007-10-30 10:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
    2008-06-20 04:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
    2008-06-20 05:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
    2008-06-20 05:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
    2005-03-13 18:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 c:\windows\$NtUninstallKB917953$\tcpip.sys
    2006-04-20 05:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
    2007-10-30 11:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
    2008-04-13 13:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\tcpip.sys
    2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
    2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys

    2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
    2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe

    2008-04-13 13:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ndis.sys
    2004-08-10 13:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys

    2008-04-13 12:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
    2004-08-10 13:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys

    2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
    2006-12-19 10:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
    2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
    2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
    2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
    2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
    2005-03-01 18:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
    2006-12-19 06:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
    2007-02-28 02:38 2057600 515d30e2c90a3665a2739309334c9283 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\Driver Cache\i386\ntkrnlpa.exe
    2008-04-13 12:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\dllcache\ntkrnlpa.exe
    2004-08-10 13:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntkrnlpa.exe

    2005-03-01 19:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
    2006-12-19 10:51 2182016 cef243f6defd20be4adde26c7ecacb54 c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
    2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
    2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
    2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
    2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
    2005-03-01 18:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\$NtUninstallKB929338$\ntoskrnl.exe
    2006-12-19 08:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
    2007-02-28 03:10 2180352 582a8dbaa58c3b1f176eb2817daee77c c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\Driver Cache\i386\ntoskrnl.exe
    2008-04-13 13:27 2188928 0c89243c7c3ee199b96fcc16990e0679 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\dllcache\ntoskrnl.exe
    2004-08-10 13:00 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntoskrnl.exe

    2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
    2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
    2004-08-10 13:00 1032192 a0732187050030ae399b241436565e64 c:\windows\$NtUninstallKB938828$\explorer.exe
    2008-04-13 18:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
    2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\system32\dllcache\explorer.exe

    2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
    2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe

    2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
    2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe

    2008-04-13 18:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
    2004-08-10 13:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe

    2008-04-13 18:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
    2004-08-10 13:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe

    2004-08-10 13:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
    2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\termsrv.dll
    2005-03-10 01:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll

    2006-07-05 04:57 985088 0fdd84928a5dde2510761b7ec76ccec9 c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
    2007-04-16 10:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
    2004-08-10 13:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB917422$\kernel32.dll
    2006-07-05 04:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 c:\windows\$NtUninstallKB935839$\kernel32.dll
    2008-04-13 18:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\kernel32.dll
    2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\kernel32.dll
    2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\dllcache\kernel32.dll

    2008-04-13 18:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\powrprof.dll
    2004-08-10 13:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
    @="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
    [HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
    2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
    @="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
    [HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
    2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
    "AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
    "type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
    "AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
    "YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
    "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
    "osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
    "CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
    "SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=G

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8891:TCP"= 8891:TCP:Pitbull
    "50706:TCP"= 50706:TCP:PORT_50706
    "41136:TCP"= 41136:TCP:PORT_41136
    "58843:TCP"= 58843:TCP:PORT_58843
    "45453:TCP"= 45453:TCP:PORT_45453
    "46608:TCP"= 46608:TCP:PORT_46608
    "24395:TCP"= 24395:TCP:PORT_24395
    "58380:TCP"= 58380:TCP:PORT_58380
    "12476:TCP"= 12476:TCP:PORT_12476
    "44022:TCP"= 44022:TCP:PORT_44022
    "23014:TCP"= 23014:TCP:PORT_23014
    "61930:TCP"= 61930:TCP:PORT_61930
    "46327:TCP"= 46327:TCP:PORT_46327
    "34724:TCP"= 34724:TCP:PORT_34724
    "19950:TCP"= 19950:TCP:PORT_19950
    "49203:TCP"= 49203:TCP:PORT_49203
    "23848:TCP"= 23848:TCP:PORT_23848
    "48998:TCP"= 48998:TCP:PORT_48998
    "53375:TCP"= 53375:TCP:PORT_53375
    "40458:TCP"= 40458:TCP:PORT_40458
    "6428:TCP"= 6428:TCP:PORT_6428
    "37706:TCP"= 37706:TCP:PORT_37706
    "47531:TCP"= 47531:TCP:PORT_47531
    "46532:TCP"= 46532:TCP:PORT_46532
    "32902:TCP"= 32902:TCP:PORT_32902
    "17347:TCP"= 17347:TCP:PORT_17347
    "17586:TCP"= 17586:TCP:PORT_17586
    "26291:TCP"= 26291:TCP:PORT_26291
    "55534:TCP"= 55534:TCP:PORT_55534
    "41891:TCP"= 41891:TCP:PORT_41891
    "48462:TCP"= 48462:TCP:PORT_48462
    "18050:TCP"= 18050:TCP:PORT_18050
    "31483:TCP"= 31483:TCP:PORT_31483
    "33700:TCP"= 33700:TCP:PORT_33700
    "31203:TCP"= 31203:TCP:PORT_31203
    "43418:TCP"= 43418:TCP:PORT_43418
    "24985:TCP"= 24985:TCP:PORT_24985
    "19001:TCP"= 19001:TCP:PORT_19001
    "42324:TCP"= 42324:TCP:PORT_42324
    "10141:TCP"= 10141:TCP:PORT_10141
    "15865:TCP"= 15865:TCP:PORT_15865
    "36942:TCP"= 36942:TCP:PORT_36942
    "30525:TCP"= 30525:TCP:PORT_30525
    "41668:TCP"= 41668:TCP:PORT_41668
    "46918:TCP"= 46918:TCP:PORT_46918
    "34969:TCP"= 34969:TCP:PORT_34969
    "31365:TCP"= 31365:TCP:PORT_31365
    "46969:TCP"= 46969:TCP:PORT_46969
    "24597:TCP"= 24597:TCP:PORT_24597
    "20994:TCP"= 20994:TCP:PORT_20994
    "41178:TCP"= 41178:TCP:PORT_41178
    "28301:TCP"= 28301:TCP:PORT_28301
    "59290:TCP"= 59290:TCP:PORT_59290
    "24121:TCP"= 24121:TCP:PORT_24121
    "57424:TCP"= 57424:TCP:PORT_57424
    "44981:TCP"= 44981:TCP:PORT_44981
    "58917:TCP"= 58917:TCP:PORT_58917
    "19762:TCP"= 19762:TCP:PORT_19762
    "13600:TCP"= 13600:TCP:PORT_13600
    "50879:TCP"= 50879:TCP:PORT_50879
    "25703:TCP"= 25703:TCP:PORT_25703
    "25665:TCP"= 25665:TCP:PORT_25665
    "61900:TCP"= 61900:TCP:PORT_61900
    "39500:TCP"= 39500:TCP:PORT_39500
    "20341:TCP"= 20341:TCP:PORT_20341
    "19297:TCP"= 19297:TCP:PORT_19297
    "38391:TCP"= 38391:TCP:PORT_38391
    "49316:TCP"= 49316:TCP:PORT_49316
    "59874:TCP"= 59874:TCP:PORT_59874
    "37001:TCP"= 37001:TCP:PORT_37001
    "53583:TCP"= 53583:TCP:PORT_53583
    "16237:TCP"= 16237:TCP:PORT_16237
    "64731:TCP"= 64731:TCP:PORT_64731
    "20478:TCP"= 20478:TCP:PORT_20478
    "9205:TCP"= 9205:TCP:PORT_9205
    "21048:TCP"= 21048:TCP:PORT_21048
    "13985:TCP"= 13985:TCP:PORT_13985
    "17569:TCP"= 17569:TCP:PORT_17569
    "39416:TCP"= 39416:TCP:PORT_39416
    "64321:TCP"= 64321:TCP:PORT_64321
    "5541:TCP"= 5541:TCP:PORT_5541
    "11962:TCP"= 11962:TCP:PORT_11962
    "17814:TCP"= 17814:TCP:PORT_17814
    "23703:TCP"= 23703:TCP:PORT_23703
    "30958:TCP"= 30958:TCP:PORT_30958
    "56113:TCP"= 56113:TCP:PORT_56113
    "57434:TCP"= 57434:TCP:PORT_57434
    "6168:TCP"= 6168:TCP:PORT_6168
    "46504:TCP"= 46504:TCP:PORT_46504
    "33384:TCP"= 33384:TCP:PORT_33384
    "56375:TCP"= 56375:TCP:PORT_56375
    "51170:TCP"= 51170:TCP:PORT_51170
    "19586:TCP"= 19586:TCP:PORT_19586
    "25575:TCP"= 25575:TCP:PORT_25575
    "42489:TCP"= 42489:TCP:PORT_42489
    "48396:TCP"= 48396:TCP:PORT_48396
    "31465:TCP"= 31465:TCP:PORT_31465
    "10617:TCP"= 10617:TCP:PORT_10617
    "65508:TCP"= 65508:TCP:PORT_65508
    "33536:TCP"= 33536:TCP:PORT_33536
    "38457:TCP"= 38457:TCP:PORT_38457
    "10028:TCP"= 10028:TCP:PORT_10028
    "36496:TCP"= 36496:TCP:PORT_36496
    "7458:TCP"= 7458:TCP:PORT_7458
    "37384:TCP"= 37384:TCP:PORT_37384
    "10590:TCP"= 10590:TCP:PORT_10590
    "45703:TCP"= 45703:TCP:PORT_45703
    "36131:TCP"= 36131:TCP:PORT_36131
    "22055:TCP"= 22055:TCP:PORT_22055
    "22102:TCP"= 22102:TCP:PORT_22102
    "21263:TCP"= 21263:TCP:PORT_21263
    "57395:TCP"= 57395:TCP:PORT_57395
    "48141:TCP"= 48141:TCP:PORT_48141
    "54043:TCP"= 54043:TCP:PORT_54043
    "47551:TCP"= 47551:TCP:PORT_47551
    "20518:TCP"= 20518:TCP:PORT_20518
    "28583:TCP"= 28583:TCP:PORT_28583
    "25268:TCP"= 25268:TCP:PORT_25268
    "40777:TCP"= 40777:TCP:PORT_40777
    "26878:TCP"= 26878:TCP:PORT_26878
    "40930:TCP"= 40930:TCP:PORT_40930
    "22729:TCP"= 22729:TCP:PORT_22729
    "23165:TCP"= 23165:TCP:PORT_23165
    "14616:TCP"= 14616:TCP:PORT_14616
    "12196:TCP"= 12196:TCP:PORT_12196
    "29415:TCP"= 29415:TCP:PORT_29415
    "28376:TCP"= 28376:TCP:PORT_28376
    "23958:TCP"= 23958:TCP:PORT_23958
    "8479:TCP"= 8479:TCP:PORT_8479
    "7010:TCP"= 7010:TCP:PORT_7010
    "28177:TCP"= 28177:TCP:PORT_28177
    "17291:TCP"= 17291:TCP:PORT_17291
    "55072:TCP"= 55072:TCP:PORT_55072
    "17438:TCP"= 17438:TCP:PORT_17438
    "12604:TCP"= 12604:TCP:PORT_12604
    "25643:TCP"= 25643:TCP:PORT_25643
    "56825:TCP"= 56825:TCP:PORT_56825
    "49451:TCP"= 49451:TCP:PORT_49451
    "42493:TCP"= 42493:TCP:PORT_42493
    "11581:TCP"= 11581:TCP:PORT_11581
    "62951:TCP"= 62951:TCP:PORT_62951
    "53295:TCP"= 53295:TCP:PORT_53295
    "9788:TCP"= 9788:TCP:PORT_9788
    "59565:TCP"= 59565:TCP:PORT_59565
    "40583:TCP"= 40583:TCP:PORT_40583
    "14298:TCP"= 14298:TCP:PORT_14298
    "47022:TCP"= 47022:TCP:PORT_47022
    "61853:TCP"= 61853:TCP:PORT_61853
    "56114:TCP"= 56114:TCP:PORT_56114

    R2 713xTVCard;SAA7133 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2005-03-15 277504]
    R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-08 29744]
    S1 MozyFilter;MozyFilter;c:\windows\system32\DRIVERS\mozy.sys [2008-10-06 53752]
    S3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
    S3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
    S3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
    S3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
    S3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
    S3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\DRIVERS\atinewp2.sys [2005-06-01 485760]
    S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]


    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - COMHOST
    *Deregistered* - abp480n5
    *Deregistered* - adpu160m
    *Deregistered* - AegisP
    *Deregistered* - AFD
    *Deregistered* - agp440
    *Deregistered* - agpCPQ
    *Deregistered* - Aha154x
    *Deregistered* - aic78u2
    *Deregistered* - aic78xx
    *Deregistered* - AliIde
    *Deregistered* - alim1541
    *Deregistered* - amdagp
    *Deregistered* - amsint
    *Deregistered* - Arp1394
    *Deregistered* - asc
    *Deregistered* - asc3350p
    *Deregistered* - asc3550
    *Deregistered* - Ati HotKey Poller
    *Deregistered* - ATI Smart
    *Deregistered* - audstub
    *Deregistered* - Beep
    *Deregistered* - cbidf
    *Deregistered* - cd20xrnt
    *Deregistered* - Cdfs
    *Deregistered* - CLTNetCnService
    *Deregistered* - CmdIde
    *Deregistered* - comHost
    *Deregistered* - Cpqarray
    *Deregistered* - dac2w2k
    *Deregistered* - dac960nt
    *Deregistered* - dmio
    *Deregistered* - dmload
    *Deregistered* - dpti2o
    *Deregistered* - eeCtrl
    *Deregistered* - EraserUtilRebootDrv
    *Deregistered* - Fastfat
    *Deregistered* - Fips
    *Deregistered* - FltMgr
    *Deregistered* - Ftdisk
    *Deregistered* - Gpc
    *Deregistered* - GTNDIS5
    *Deregistered* - hpn
    *Deregistered* - HTTP
    *Deregistered* - i2omgmt
    *Deregistered* - i2omp
    *Deregistered* - ini910u
    *Deregistered* - IntelIde
    *Deregistered* - Ip6Fw
    *Deregistered* - IpNat
    *Deregistered* - IPSec
    *Deregistered* - KSecDD
    *Deregistered* - LiveUpdate Notice Ex
    *Deregistered* - LiveUpdate Notice Service
    *Deregistered* - mnmdd
    *Deregistered* - MountMgr
    *Deregistered* - MozyBackup
    *Deregistered* - MozyFilter
    *Deregistered* - mraid35x
    *Deregistered* - MRxDAV
    *Deregistered* - MRxSmb
    *Deregistered* - Msfs
    *Deregistered* - mssmbios
    *Deregistered* - Mup
    *Deregistered* - NAVENG
    *Deregistered* - NAVEX15
    *Deregistered* - NDIS
    *Deregistered* - Ndisuio
    *Deregistered* - NdisWan
    *Deregistered* - NDProxy
    *Deregistered* - NetBIOS
    *Deregistered* - NetBT
    *Deregistered* - Npfs
    *Deregistered* - Ntfs
    *Deregistered* - Null
    *Deregistered* - NwlnkIpx
    *Deregistered* - NwlnkNb
    *Deregistered* - NwlnkSpx
    *Deregistered* - PartMgr
    *Deregistered* - perc2
    *Deregistered* - perc2hib
    *Deregistered* - PptpMiniport
    *Deregistered* - PrismXL
    *Deregistered* - PSched
    *Deregistered* - ql1080
    *Deregistered* - Ql10wnt
    *Deregistered* - ql12160
    *Deregistered* - ql1240
    *Deregistered* - ql1280
    *Deregistered* - RasAcd
    *Deregistered* - Rasl2tp
    *Deregistered* - RasPppoe
    *Deregistered* - Raspti
    *Deregistered* - Rdbss
    *Deregistered* - RDPCDD
    *Deregistered* - rdpdr
    *Deregistered* - sisagp
    *Deregistered* - Sparrow
    *Deregistered* - sr
    *Deregistered* - SRTSP
    *Deregistered* - SRTSPX
    *Deregistered* - swenum
    *Deregistered* - sym_hi
    *Deregistered* - sym_u3
    *Deregistered* - symc810
    *Deregistered* - symc8xx
    *Deregistered* - SYMDNS
    *Deregistered* - SymEvent
    *Deregistered* - SYMFW
    *Deregistered* - SYMIDS
    *Deregistered* - SYMIDSCO
    *Deregistered* - SYMNDIS
    *Deregistered* - SYMREDRV
    *Deregistered* - SYMTDI
    *Deregistered* - Tcpip
    *Deregistered* - Tcpip6
    *Deregistered* - TermDD
    *Deregistered* - TosIde
    *Deregistered* - tunmp
    *Deregistered* - ultra
    *Deregistered* - Update
    *Deregistered* - VgaSave
    *Deregistered* - viaagp
    *Deregistered* - ViaIde
    *Deregistered* - VolSnap
    *Deregistered* - Wanarp
    *Deregistered* - WMP54Gv4SVC

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
    \Shell\AutoRun\command - K:\smartAP.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
    \Shell\AutoRun\command - E:\run.bat
    .
    Contents of the 'Scheduled Tasks' folder

    2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
    - c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
    .
    - - - - ORPHANS REMOVED - - - -

    WebBrowser-{8B9F574C-32E6-4004-AF4D-6993481C790F} - (no file)
    SSODL-EPItZZQy-{2CEC6C2A-8646-C680-0D65-0E74600C38E7} - c:\windows\system32\vokz.dll


    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.yahoo.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
    DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-30 22:08:43
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,26,b8,5e,26,00,
    e0,e8,d1,e2,63,26,f1,3f,c8,ff,68,90,3b,26,5c,ae,6e,84,c4,e2,63,26,f1,3f,c8,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,03,46,b9,b8,
    a6,76,67,6a,9c,d6,61,af,45,84,18,94,5f,6f,37,d7,a1,a9,29,6a,9c,d6,61,af,45,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,3d,3c,71,b7,9f,
    dc,e9,1b,ff,7c,85,e0,43,d4,0e,fe,b5,a7,b9,1d,20,35,11,86,ff,7c,85,e0,43,d4,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,12,07,dd,0d,7f,
    21,d3,4c,86,8c,21,01,be,91,eb,e7,e9,5f,c9,fe,bc,ad,42,2a,86,8c,21,01,be,91,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,01,ad,dc,b1,
    bd,5b,fd,f5,1d,4d,73,a8,13,5c,05,81,15,3b,6a,17,dc,fe,4e,f5,1d,4d,73,a8,13,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,22,6d,67,b6,
    56,19,8a,df,20,58,62,78,6b,cf,c8,fd,57,42,60,5d,81,ab,f8,df,20,58,62,78,6b,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,71,e6,3b,c1,c4,
    3e,24,3e,fb,a7,78,e6,12,2f,9a,ea,a3,8d,75,0a,b5,04,8f,49,fb,a7,78,e6,12,2f,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,fb,ef,0e,e5,32,
    23,0d,a5,01,3a,48,fc,e8,04,4a,f1,90,cd,67,e4,36,b1,32,7a,01,3a,48,fc,e8,04,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c3,e7,d0,db,cc,
    15,36,e5,f6,0f,4e,58,98,5b,89,c9,8b,cd,ea,1c,db,2c,57,9e,f6,0f,4e,58,98,5b,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,f7,7c,3e,f9,01,
    9a,61,88,3d,ce,ea,26,2d,45,aa,78,db,8a,97,10,b0,21,48,0e,3d,ce,ea,26,2d,45,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,98,19,c0,41,43,
    f4,2b,a7,2a,b7,cc,b5,b9,7f,41,e7,2c,b4,f2,d2,fd,82,d7,82,2a,b7,cc,b5,b9,7f,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,fe,e6,69,6f,c3,
    9c,ba,71,6c,43,2d,1e,aa,22,2f,9c,08,f7,13,a7,0a,48,8d,4d,6c,43,2d,1e,aa,22,\
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(664)
    c:\windows\system32\Ati2evxx.dll
    c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
    c:\program files\common files\logitech\bluetooth\LBTServ.dll
    .
    Completion time: 2009-01-30 22:11:49
    ComboFix-quarantined-files.txt 2009-01-31 04:11:39

    Pre-Run: 140,171,087,872 bytes free
    Post-Run: 150,529,556,480 bytes free

    632 --- E O F --- 2009-01-14 09:04:25

  4. #4
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Manchester UK
    Posts
    3,425

    Default

    There looks to be a lot of problems on that machine, services not running and a lot of ports open to the internet ?
    The quickest option would be to use System Restore to get to a point before Coupon Printer was installed.
    If the machine functions properly when that is done, then you should update to SP3.

    Please post a fresh Combofix log when you have done the above.
    Microsoft MVP Consumer Security 2009 -2010
    If we have helped, please consider a donation
    THESE INSTRUCTIONS ARE FOR THIS USER ONLY

  5. #5
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default System restore

    It will not let me run system restore. It keeps saying restart and try again. I tried to do this with a normal restart and also with a restart to safe mode. Neither one would work.

  6. #6
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Manchester UK
    Posts
    3,425

    Default

    Hmmm....

    Delete the copy of Combofix that you have, and download a fresh copy from HERE

    Run it as you did last time.
    Microsoft MVP Consumer Security 2009 -2010
    If we have helped, please consider a donation
    THESE INSTRUCTIONS ARE FOR THIS USER ONLY

  7. #7
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default Results

    ComboFix 09-01-21.04 - chullz 2009-01-31 10:35:31.2 - NTFSx86
    Running from: K:\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .
    - REDUCED FUNCTIONALITY MODE -
    .

    ((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-31 )))))))))))))))))))))))))))))))
    .

    2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
    2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
    2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a--c--- c:\windows\system32\dllcache\explorer.exe
    2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a------ c:\windows\explorer.exe
    2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
    2009-01-14 03:04 . 2008-08-28 04:04 333,056 --a------ c:\windows\system32\drivers\srv.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-22 20:39 --------- d-----w c:\program files\Common Files\Symantec Shared
    2009-01-22 00:07 --------- d-----w c:\program files\Google
    2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
    2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
    2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
    2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
    2009-01-06 00:49 --------- d-----w c:\program files\Symantec
    2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
    .

    ------- Sigcheck -------

    2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
    2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
    2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
    2008-04-13 18:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
    2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\user32.dll
    2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\dllcache\user32.dll

    2008-04-13 18:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ws2_32.dll
    2004-08-10 13:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll

    2004-09-29 12:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
    2005-01-27 11:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
    2005-03-10 01:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
    2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
    2007-03-07 11:40 823296 b8f4db39ca7353752f245379d285c80e c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
    2007-04-25 03:08 823808 431defbb4a3d7b0dc062c1b064623a2f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
    2007-06-27 08:40 824320 d6ed5e042c5207553e7f5e842918137f c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
    2007-08-20 04:02 825344 357d54bf94fe9d6d8505a96b5c2a3bca c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
    2007-10-10 17:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
    2007-12-06 20:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
    2008-03-01 07:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
    2008-04-22 21:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
    2008-06-23 10:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
    2008-08-26 03:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
    2008-10-16 14:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
    2006-05-09 23:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB916281$\wininet.dll
    2005-03-10 02:02 656896 6f018d6319be4f96426ea829b79e05d5 c:\windows\$NtUninstallKB916281_0$\wininet.dll
    2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$NtUninstallKB918899$\wininet.dll
    2006-06-23 05:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$NtUninstallKB922760$\wininet.dll
    2006-09-14 02:31 664576 d207370287cf769aebebf03837784963 c:\windows\ie7\wininet.dll
    2006-11-07 21:03 818688 92995334f993e6e49c25c6d02ec04401 c:\windows\ie7updates\KB928090-IE7\wininet.dll
    2007-01-12 09:27 822784 be43d00d802c92f01c8cc952c6f483f8 c:\windows\ie7updates\KB931768-IE7\wininet.dll
    2007-03-07 11:45 822784 5b35dae6e4886f64d1da58c4e3e01eb9 c:\windows\ie7updates\KB933566-IE7\wininet.dll
    2007-04-25 02:41 822784 0586a7f0b2fdb94d624f399d4728e7c8 c:\windows\ie7updates\KB937143-IE7\wininet.dll
    2007-06-27 08:34 823808 8068cbb58fe60cc95aeb2cff70178208 c:\windows\ie7updates\KB939653-IE7\wininet.dll
    2007-08-20 04:04 824832 774435e499d8e9643ec961a6103c361f c:\windows\ie7updates\KB942615-IE7\wininet.dll
    2007-10-10 17:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll
    2007-12-06 20:21 824832 806d274c9a6c3aaea5eae8e4af841e04 c:\windows\ie7updates\KB947864-IE7\wininet.dll
    2008-03-01 07:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll
    2008-04-22 22:16 826368 f6589be784647cfdbc22ea51ccb1a57a c:\windows\ie7updates\KB953838-IE7\wininet.dll
    2008-06-23 10:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
    2008-08-26 01:24 826368 ef8eba98145bfa44e80d17a3b3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
    2008-04-13 18:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wininet.dll
    2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\wininet.dll
    2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\dllcache\wininet.dll

    2005-03-13 19:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
    2006-04-20 06:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
    2007-10-30 10:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
    2008-06-20 04:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
    2008-06-20 05:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
    2008-06-20 05:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
    2005-03-13 18:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 c:\windows\$NtUninstallKB917953$\tcpip.sys
    2006-04-20 05:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
    2007-10-30 11:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
    2008-04-13 13:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\tcpip.sys
    2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
    2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys

    2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
    2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe

    2008-04-13 13:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ndis.sys
    2004-08-10 13:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys

    2008-04-13 12:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
    2004-08-10 13:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys

    2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
    2006-12-19 10:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
    2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
    2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
    2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
    2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
    2005-03-01 18:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
    2006-12-19 06:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
    2007-02-28 02:38 2057600 515d30e2c90a3665a2739309334c9283 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\Driver Cache\i386\ntkrnlpa.exe
    2008-04-13 12:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\dllcache\ntkrnlpa.exe
    2004-08-10 13:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntkrnlpa.exe

    2005-03-01 19:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
    2006-12-19 10:51 2182016 cef243f6defd20be4adde26c7ecacb54 c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
    2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
    2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
    2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
    2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
    2005-03-01 18:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\$NtUninstallKB929338$\ntoskrnl.exe
    2006-12-19 08:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
    2007-02-28 03:10 2180352 582a8dbaa58c3b1f176eb2817daee77c c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\Driver Cache\i386\ntoskrnl.exe
    2008-04-13 13:27 2188928 0c89243c7c3ee199b96fcc16990e0679 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\dllcache\ntoskrnl.exe
    2004-08-10 13:00 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntoskrnl.exe

    2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
    2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
    2004-08-10 13:00 1032192 a0732187050030ae399b241436565e64 c:\windows\$NtUninstallKB938828$\explorer.exe
    2008-04-13 18:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
    2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\system32\dllcache\explorer.exe

    2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
    2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe

    2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
    2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe

    2008-04-13 18:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
    2004-08-10 13:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe

    2008-04-13 18:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
    2004-08-10 13:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe

    2004-08-10 13:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
    2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\termsrv.dll
    2005-03-10 01:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll

    2006-07-05 04:57 985088 0fdd84928a5dde2510761b7ec76ccec9 c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
    2007-04-16 10:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
    2004-08-10 13:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB917422$\kernel32.dll
    2006-07-05 04:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 c:\windows\$NtUninstallKB935839$\kernel32.dll
    2008-04-13 18:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\kernel32.dll
    2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\kernel32.dll
    2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\dllcache\kernel32.dll

    2008-04-13 18:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\powrprof.dll
    2004-08-10 13:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
    @="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
    [HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
    2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
    @="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
    [HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
    2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
    "AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
    "type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
    "AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
    "YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
    "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
    "osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
    "CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
    "SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=G

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8891:TCP"= 8891:TCP:Pitbull
    "50706:TCP"= 50706:TCP:PORT_50706
    "41136:TCP"= 41136:TCP:PORT_41136
    "58843:TCP"= 58843:TCP:PORT_58843
    "45453:TCP"= 45453:TCP:PORT_45453
    "46608:TCP"= 46608:TCP:PORT_46608
    "24395:TCP"= 24395:TCP:PORT_24395
    "58380:TCP"= 58380:TCP:PORT_58380
    "12476:TCP"= 12476:TCP:PORT_12476
    "44022:TCP"= 44022:TCP:PORT_44022
    "23014:TCP"= 23014:TCP:PORT_23014
    "61930:TCP"= 61930:TCP:PORT_61930
    "46327:TCP"= 46327:TCP:PORT_46327
    "34724:TCP"= 34724:TCP:PORT_34724
    "19950:TCP"= 19950:TCP:PORT_19950
    "49203:TCP"= 49203:TCP:PORT_49203
    "23848:TCP"= 23848:TCP:PORT_23848
    "48998:TCP"= 48998:TCP:PORT_48998
    "53375:TCP"= 53375:TCP:PORT_53375
    "40458:TCP"= 40458:TCP:PORT_40458
    "6428:TCP"= 6428:TCP:PORT_6428
    "37706:TCP"= 37706:TCP:PORT_37706
    "47531:TCP"= 47531:TCP:PORT_47531
    "46532:TCP"= 46532:TCP:PORT_46532
    "32902:TCP"= 32902:TCP:PORT_32902
    "17347:TCP"= 17347:TCP:PORT_17347
    "17586:TCP"= 17586:TCP:PORT_17586
    "26291:TCP"= 26291:TCP:PORT_26291
    "55534:TCP"= 55534:TCP:PORT_55534
    "41891:TCP"= 41891:TCP:PORT_41891
    "48462:TCP"= 48462:TCP:PORT_48462
    "18050:TCP"= 18050:TCP:PORT_18050
    "31483:TCP"= 31483:TCP:PORT_31483
    "33700:TCP"= 33700:TCP:PORT_33700
    "31203:TCP"= 31203:TCP:PORT_31203
    "43418:TCP"= 43418:TCP:PORT_43418
    "24985:TCP"= 24985:TCP:PORT_24985
    "19001:TCP"= 19001:TCP:PORT_19001
    "42324:TCP"= 42324:TCP:PORT_42324
    "10141:TCP"= 10141:TCP:PORT_10141
    "15865:TCP"= 15865:TCP:PORT_15865
    "36942:TCP"= 36942:TCP:PORT_36942
    "30525:TCP"= 30525:TCP:PORT_30525
    "41668:TCP"= 41668:TCP:PORT_41668
    "46918:TCP"= 46918:TCP:PORT_46918
    "34969:TCP"= 34969:TCP:PORT_34969
    "31365:TCP"= 31365:TCP:PORT_31365
    "46969:TCP"= 46969:TCP:PORT_46969
    "24597:TCP"= 24597:TCP:PORT_24597
    "20994:TCP"= 20994:TCP:PORT_20994
    "41178:TCP"= 41178:TCP:PORT_41178
    "28301:TCP"= 28301:TCP:PORT_28301
    "59290:TCP"= 59290:TCP:PORT_59290
    "24121:TCP"= 24121:TCP:PORT_24121
    "57424:TCP"= 57424:TCP:PORT_57424
    "44981:TCP"= 44981:TCP:PORT_44981
    "58917:TCP"= 58917:TCP:PORT_58917
    "19762:TCP"= 19762:TCP:PORT_19762
    "13600:TCP"= 13600:TCP:PORT_13600
    "50879:TCP"= 50879:TCP:PORT_50879
    "25703:TCP"= 25703:TCP:PORT_25703
    "25665:TCP"= 25665:TCP:PORT_25665
    "61900:TCP"= 61900:TCP:PORT_61900
    "39500:TCP"= 39500:TCP:PORT_39500
    "20341:TCP"= 20341:TCP:PORT_20341
    "19297:TCP"= 19297:TCP:PORT_19297
    "38391:TCP"= 38391:TCP:PORT_38391
    "49316:TCP"= 49316:TCP:PORT_49316
    "59874:TCP"= 59874:TCP:PORT_59874
    "37001:TCP"= 37001:TCP:PORT_37001
    "53583:TCP"= 53583:TCP:PORT_53583
    "16237:TCP"= 16237:TCP:PORT_16237
    "64731:TCP"= 64731:TCP:PORT_64731
    "20478:TCP"= 20478:TCP:PORT_20478
    "9205:TCP"= 9205:TCP:PORT_9205
    "21048:TCP"= 21048:TCP:PORT_21048
    "13985:TCP"= 13985:TCP:PORT_13985
    "17569:TCP"= 17569:TCP:PORT_17569
    "39416:TCP"= 39416:TCP:PORT_39416
    "64321:TCP"= 64321:TCP:PORT_64321
    "5541:TCP"= 5541:TCP:PORT_5541
    "11962:TCP"= 11962:TCP:PORT_11962
    "17814:TCP"= 17814:TCP:PORT_17814
    "23703:TCP"= 23703:TCP:PORT_23703
    "30958:TCP"= 30958:TCP:PORT_30958
    "56113:TCP"= 56113:TCP:PORT_56113
    "57434:TCP"= 57434:TCP:PORT_57434
    "6168:TCP"= 6168:TCP:PORT_6168
    "46504:TCP"= 46504:TCP:PORT_46504
    "33384:TCP"= 33384:TCP:PORT_33384
    "56375:TCP"= 56375:TCP:PORT_56375
    "51170:TCP"= 51170:TCP:PORT_51170
    "19586:TCP"= 19586:TCP:PORT_19586
    "25575:TCP"= 25575:TCP:PORT_25575
    "42489:TCP"= 42489:TCP:PORT_42489
    "48396:TCP"= 48396:TCP:PORT_48396
    "31465:TCP"= 31465:TCP:PORT_31465
    "10617:TCP"= 10617:TCP:PORT_10617
    "65508:TCP"= 65508:TCP:PORT_65508
    "33536:TCP"= 33536:TCP:PORT_33536
    "38457:TCP"= 38457:TCP:PORT_38457
    "10028:TCP"= 10028:TCP:PORT_10028
    "36496:TCP"= 36496:TCP:PORT_36496
    "7458:TCP"= 7458:TCP:PORT_7458
    "37384:TCP"= 37384:TCP:PORT_37384
    "10590:TCP"= 10590:TCP:PORT_10590
    "45703:TCP"= 45703:TCP:PORT_45703
    "36131:TCP"= 36131:TCP:PORT_36131
    "22055:TCP"= 22055:TCP:PORT_22055
    "22102:TCP"= 22102:TCP:PORT_22102
    "21263:TCP"= 21263:TCP:PORT_21263
    "57395:TCP"= 57395:TCP:PORT_57395
    "48141:TCP"= 48141:TCP:PORT_48141
    "54043:TCP"= 54043:TCP:PORT_54043
    "47551:TCP"= 47551:TCP:PORT_47551
    "20518:TCP"= 20518:TCP:PORT_20518
    "28583:TCP"= 28583:TCP:PORT_28583
    "25268:TCP"= 25268:TCP:PORT_25268
    "40777:TCP"= 40777:TCP:PORT_40777
    "26878:TCP"= 26878:TCP:PORT_26878
    "40930:TCP"= 40930:TCP:PORT_40930
    "22729:TCP"= 22729:TCP:PORT_22729
    "23165:TCP"= 23165:TCP:PORT_23165
    "14616:TCP"= 14616:TCP:PORT_14616
    "12196:TCP"= 12196:TCP:PORT_12196
    "29415:TCP"= 29415:TCP:PORT_29415
    "28376:TCP"= 28376:TCP:PORT_28376
    "23958:TCP"= 23958:TCP:PORT_23958
    "8479:TCP"= 8479:TCP:PORT_8479
    "7010:TCP"= 7010:TCP:PORT_7010
    "28177:TCP"= 28177:TCP:PORT_28177
    "17291:TCP"= 17291:TCP:PORT_17291
    "55072:TCP"= 55072:TCP:PORT_55072
    "17438:TCP"= 17438:TCP:PORT_17438
    "12604:TCP"= 12604:TCP:PORT_12604
    "25643:TCP"= 25643:TCP:PORT_25643
    "56825:TCP"= 56825:TCP:PORT_56825
    "49451:TCP"= 49451:TCP:PORT_49451
    "42493:TCP"= 42493:TCP:PORT_42493
    "11581:TCP"= 11581:TCP:PORT_11581
    "62951:TCP"= 62951:TCP:PORT_62951
    "53295:TCP"= 53295:TCP:PORT_53295
    "9788:TCP"= 9788:TCP:PORT_9788
    "59565:TCP"= 59565:TCP:PORT_59565
    "40583:TCP"= 40583:TCP:PORT_40583
    "14298:TCP"= 14298:TCP:PORT_14298
    "47022:TCP"= 47022:TCP:PORT_47022
    "61853:TCP"= 61853:TCP:PORT_61853
    "56114:TCP"= 56114:TCP:PORT_56114

    R2 713xTVCard;SAA7133 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2005-03-15 277504]
    R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-08 29744]
    S1 MozyFilter;MozyFilter;c:\windows\system32\DRIVERS\mozy.sys [2008-10-06 53752]
    S3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
    S3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
    S3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
    S3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
    S3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
    S3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\DRIVERS\atinewp2.sys [2005-06-01 485760]
    S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]


    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - COMHOST
    *Deregistered* - abp480n5
    *Deregistered* - adpu160m
    *Deregistered* - AegisP
    *Deregistered* - AFD
    *Deregistered* - agp440
    *Deregistered* - agpCPQ
    *Deregistered* - Aha154x
    *Deregistered* - aic78u2
    *Deregistered* - aic78xx
    *Deregistered* - AliIde
    *Deregistered* - alim1541
    *Deregistered* - amdagp
    *Deregistered* - amsint
    *Deregistered* - Arp1394
    *Deregistered* - asc
    *Deregistered* - asc3350p
    *Deregistered* - asc3550
    *Deregistered* - Ati HotKey Poller
    *Deregistered* - ATI Smart
    *Deregistered* - audstub
    *Deregistered* - Beep
    *Deregistered* - cbidf
    *Deregistered* - cd20xrnt
    *Deregistered* - Cdfs
    *Deregistered* - CLTNetCnService
    *Deregistered* - CmdIde
    *Deregistered* - comHost
    *Deregistered* - Cpqarray
    *Deregistered* - dac2w2k
    *Deregistered* - dac960nt
    *Deregistered* - dmio
    *Deregistered* - dmload
    *Deregistered* - dpti2o
    *Deregistered* - eeCtrl
    *Deregistered* - EraserUtilRebootDrv
    *Deregistered* - Fastfat
    *Deregistered* - Fips
    *Deregistered* - FltMgr
    *Deregistered* - Ftdisk
    *Deregistered* - Gpc
    *Deregistered* - GTNDIS5
    *Deregistered* - hpn
    *Deregistered* - HTTP
    *Deregistered* - i2omgmt
    *Deregistered* - i2omp
    *Deregistered* - ini910u
    *Deregistered* - IntelIde
    *Deregistered* - Ip6Fw
    *Deregistered* - IpNat
    *Deregistered* - IPSec
    *Deregistered* - KSecDD
    *Deregistered* - LiveUpdate Notice Ex
    *Deregistered* - LiveUpdate Notice Service
    *Deregistered* - mnmdd
    *Deregistered* - MountMgr
    *Deregistered* - MozyBackup
    *Deregistered* - MozyFilter
    *Deregistered* - mraid35x
    *Deregistered* - MRxDAV
    *Deregistered* - MRxSmb
    *Deregistered* - Msfs
    *Deregistered* - mssmbios
    *Deregistered* - Mup
    *Deregistered* - NAVENG
    *Deregistered* - NAVEX15
    *Deregistered* - NDIS
    *Deregistered* - Ndisuio
    *Deregistered* - NdisWan
    *Deregistered* - NDProxy
    *Deregistered* - NetBIOS
    *Deregistered* - NetBT
    *Deregistered* - Npfs
    *Deregistered* - Ntfs
    *Deregistered* - Null
    *Deregistered* - NwlnkIpx
    *Deregistered* - NwlnkNb
    *Deregistered* - NwlnkSpx
    *Deregistered* - PartMgr
    *Deregistered* - perc2
    *Deregistered* - perc2hib
    *Deregistered* - PptpMiniport
    *Deregistered* - PrismXL
    *Deregistered* - PSched
    *Deregistered* - ql1080
    *Deregistered* - Ql10wnt
    *Deregistered* - ql12160
    *Deregistered* - ql1240
    *Deregistered* - ql1280
    *Deregistered* - RasAcd
    *Deregistered* - Rasl2tp
    *Deregistered* - RasPppoe
    *Deregistered* - Raspti
    *Deregistered* - Rdbss
    *Deregistered* - RDPCDD
    *Deregistered* - rdpdr
    *Deregistered* - sisagp
    *Deregistered* - Sparrow
    *Deregistered* - sr
    *Deregistered* - SRTSP
    *Deregistered* - SRTSPX
    *Deregistered* - swenum
    *Deregistered* - sym_hi
    *Deregistered* - sym_u3
    *Deregistered* - symc810
    *Deregistered* - symc8xx
    *Deregistered* - SYMDNS
    *Deregistered* - SymEvent
    *Deregistered* - SYMFW
    *Deregistered* - SYMIDS
    *Deregistered* - SYMIDSCO
    *Deregistered* - SYMNDIS
    *Deregistered* - SYMREDRV
    *Deregistered* - SYMTDI
    *Deregistered* - Tcpip
    *Deregistered* - Tcpip6
    *Deregistered* - TermDD
    *Deregistered* - TosIde
    *Deregistered* - tunmp
    *Deregistered* - ultra
    *Deregistered* - Update
    *Deregistered* - VgaSave
    *Deregistered* - viaagp
    *Deregistered* - ViaIde
    *Deregistered* - VolSnap
    *Deregistered* - Wanarp
    *Deregistered* - WMP54Gv4SVC

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
    \Shell\AutoRun\command - K:\smartAP.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
    \Shell\AutoRun\command - E:\run.bat
    .
    Contents of the 'Scheduled Tasks' folder

    2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
    - c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.yahoo.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
    DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-31 10:37:43
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,26,b8,5e,26,00,
    e0,e8,d1,e2,63,26,f1,3f,c8,ff,68,90,3b,26,5c,ae,6e,84,c4,e2,63,26,f1,3f,c8,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,03,46,b9,b8,
    a6,76,67,6a,9c,d6,61,af,45,84,18,94,5f,6f,37,d7,a1,a9,29,6a,9c,d6,61,af,45,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,3d,3c,71,b7,9f,
    dc,e9,1b,ff,7c,85,e0,43,d4,0e,fe,b5,a7,b9,1d,20,35,11,86,ff,7c,85,e0,43,d4,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,12,07,dd,0d,7f,
    21,d3,4c,86,8c,21,01,be,91,eb,e7,e9,5f,c9,fe,bc,ad,42,2a,86,8c,21,01,be,91,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,01,ad,dc,b1,
    bd,5b,fd,f5,1d,4d,73,a8,13,5c,05,81,15,3b,6a,17,dc,fe,4e,f5,1d,4d,73,a8,13,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,22,6d,67,b6,
    56,19,8a,df,20,58,62,78,6b,cf,c8,fd,57,42,60,5d,81,ab,f8,df,20,58,62,78,6b,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,71,e6,3b,c1,c4,
    3e,24,3e,fb,a7,78,e6,12,2f,9a,ea,a3,8d,75,0a,b5,04,8f,49,fb,a7,78,e6,12,2f,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,fb,ef,0e,e5,32,
    23,0d,a5,01,3a,48,fc,e8,04,4a,f1,90,cd,67,e4,36,b1,32,7a,01,3a,48,fc,e8,04,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c3,e7,d0,db,cc,
    15,36,e5,f6,0f,4e,58,98,5b,89,c9,8b,cd,ea,1c,db,2c,57,9e,f6,0f,4e,58,98,5b,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,f7,7c,3e,f9,01,
    9a,61,88,3d,ce,ea,26,2d,45,aa,78,db,8a,97,10,b0,21,48,0e,3d,ce,ea,26,2d,45,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,98,19,c0,41,43,
    f4,2b,a7,2a,b7,cc,b5,b9,7f,41,e7,2c,b4,f2,d2,fd,82,d7,82,2a,b7,cc,b5,b9,7f,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,fe,e6,69,6f,c3,
    9c,ba,71,6c,43,2d,1e,aa,22,2f,9c,08,f7,13,a7,0a,48,8d,4d,6c,43,2d,1e,aa,22,\
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(648)
    c:\windows\system32\Ati2evxx.dll
    c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
    c:\program files\common files\logitech\bluetooth\LBTServ.dll
    .
    Completion time: 2009-01-31 10:41:11
    ComboFix-quarantined-files.txt 2009-01-31 16:41:02
    ComboFix2.txt 2009-01-31 04:11:51

    Pre-Run: 150,614,978,560 bytes free
    Post-Run: 150,597,599,232 bytes free

    605 --- E O F --- 2009-01-14 09:04:25

  8. #8
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Manchester UK
    Posts
    3,425

    Default

    Something went wrong there, please do the following

    • Click START then RUN
    • Now type Combofix /u in the runbox and click OK. Note the space between the X and the /U, it needs to be there.




    Download and Run ComboFix
    • ComboFix.exe 1
      ComboFix.exe 2
      ComboFix.exe 3
    • You must download it to and run it from your Desktop
    • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
    • Double click combofix.exe & follow the prompts.
    • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
    • Re-enable all the programs that were disabled during the running of ComboFix..


    Note:
    Do not mouse-click combofix's window while it is running. That may cause it to stall.

    CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
    ComboFix SHOULD NOT be used unless requested by a forum helper
    Microsoft MVP Consumer Security 2009 -2010
    If we have helped, please consider a donation
    THESE INSTRUCTIONS ARE FOR THIS USER ONLY

  9. #9
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default Results

    Ok. I was having a challenge getting cf to the desktop, but I finally was successful. Here are the results. (Thanks for your patience.)

    ComboFix 09-02-01.01 - chullz 2009-02-01 14:56:32.3 - NTFSx86
    Running from: c:\documents and settings\chullz\Desktop\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((( Files Created from 2009-01-01 to 2009-02-01 )))))))))))))))))))))))))))))))
    .

    2009-02-01 14:46 . 2009-02-01 13:43 3,307,596 --a------ C:\ComboFix.exe
    2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
    2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
    2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a--c--- c:\windows\system32\dllcache\explorer.exe
    2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a------ c:\windows\explorer.exe
    2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
    2009-01-14 03:04 . 2008-08-28 04:04 333,056 --a------ c:\windows\system32\drivers\srv.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-22 20:39 --------- d-----w c:\program files\Common Files\Symantec Shared
    2009-01-22 00:07 --------- d-----w c:\program files\Google
    2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
    2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
    2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
    2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
    2009-01-06 00:49 --------- d-----w c:\program files\Symantec
    2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
    .

    ------- Sigcheck -------

    2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
    2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
    2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
    2008-04-13 18:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
    2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\user32.dll
    2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\dllcache\user32.dll

    2008-04-13 18:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ws2_32.dll
    2004-08-10 13:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll

    2004-09-29 12:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
    2005-01-27 11:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
    2005-03-10 01:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
    2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
    2007-03-07 11:40 823296 b8f4db39ca7353752f245379d285c80e c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
    2007-04-25 03:08 823808 431defbb4a3d7b0dc062c1b064623a2f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
    2007-06-27 08:40 824320 d6ed5e042c5207553e7f5e842918137f c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
    2007-08-20 04:02 825344 357d54bf94fe9d6d8505a96b5c2a3bca c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
    2007-10-10 17:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
    2007-12-06 20:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
    2008-03-01 07:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
    2008-04-22 21:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
    2008-06-23 10:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
    2008-08-26 03:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
    2008-10-16 14:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
    2006-05-09 23:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB916281$\wininet.dll
    2005-03-10 02:02 656896 6f018d6319be4f96426ea829b79e05d5 c:\windows\$NtUninstallKB916281_0$\wininet.dll
    2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$NtUninstallKB918899$\wininet.dll
    2006-06-23 05:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$NtUninstallKB922760$\wininet.dll
    2006-09-14 02:31 664576 d207370287cf769aebebf03837784963 c:\windows\ie7\wininet.dll
    2006-11-07 21:03 818688 92995334f993e6e49c25c6d02ec04401 c:\windows\ie7updates\KB928090-IE7\wininet.dll
    2007-01-12 09:27 822784 be43d00d802c92f01c8cc952c6f483f8 c:\windows\ie7updates\KB931768-IE7\wininet.dll
    2007-03-07 11:45 822784 5b35dae6e4886f64d1da58c4e3e01eb9 c:\windows\ie7updates\KB933566-IE7\wininet.dll
    2007-04-25 02:41 822784 0586a7f0b2fdb94d624f399d4728e7c8 c:\windows\ie7updates\KB937143-IE7\wininet.dll
    2007-06-27 08:34 823808 8068cbb58fe60cc95aeb2cff70178208 c:\windows\ie7updates\KB939653-IE7\wininet.dll
    2007-08-20 04:04 824832 774435e499d8e9643ec961a6103c361f c:\windows\ie7updates\KB942615-IE7\wininet.dll
    2007-10-10 17:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll
    2007-12-06 20:21 824832 806d274c9a6c3aaea5eae8e4af841e04 c:\windows\ie7updates\KB947864-IE7\wininet.dll
    2008-03-01 07:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll
    2008-04-22 22:16 826368 f6589be784647cfdbc22ea51ccb1a57a c:\windows\ie7updates\KB953838-IE7\wininet.dll
    2008-06-23 10:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
    2008-08-26 01:24 826368 ef8eba98145bfa44e80d17a3b3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
    2008-04-13 18:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wininet.dll
    2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\wininet.dll
    2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\dllcache\wininet.dll

    2005-03-13 19:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
    2006-04-20 06:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
    2007-10-30 10:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
    2008-06-20 04:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
    2008-06-20 05:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
    2008-06-20 05:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
    2005-03-13 18:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 c:\windows\$NtUninstallKB917953$\tcpip.sys
    2006-04-20 05:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
    2007-10-30 11:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
    2008-04-13 13:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\tcpip.sys
    2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
    2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys

    2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
    2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe

    2008-04-13 13:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ndis.sys
    2004-08-10 13:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys

    2008-04-13 12:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
    2004-08-10 13:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys

    2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
    2006-12-19 10:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
    2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
    2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
    2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
    2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
    2005-03-01 18:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
    2006-12-19 06:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
    2007-02-28 02:38 2057600 515d30e2c90a3665a2739309334c9283 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\Driver Cache\i386\ntkrnlpa.exe
    2008-04-13 12:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\ntkrnlpa.exe
    2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\dllcache\ntkrnlpa.exe
    2004-08-10 13:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntkrnlpa.exe

    2005-03-01 19:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
    2006-12-19 10:51 2182016 cef243f6defd20be4adde26c7ecacb54 c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
    2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
    2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
    2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
    2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
    2005-03-01 18:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\$NtUninstallKB929338$\ntoskrnl.exe
    2006-12-19 08:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
    2007-02-28 03:10 2180352 582a8dbaa58c3b1f176eb2817daee77c c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\Driver Cache\i386\ntoskrnl.exe
    2008-04-13 13:27 2188928 0c89243c7c3ee199b96fcc16990e0679 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\ntoskrnl.exe
    2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\dllcache\ntoskrnl.exe
    2004-08-10 13:00 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntoskrnl.exe

    2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
    2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
    2004-08-10 13:00 1032192 a0732187050030ae399b241436565e64 c:\windows\$NtUninstallKB938828$\explorer.exe
    2008-04-13 18:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
    2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\system32\dllcache\explorer.exe

    2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
    2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe

    2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
    2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe

    2008-04-13 18:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
    2004-08-10 13:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe

    2008-04-13 18:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
    2004-08-10 13:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe

    2004-08-10 13:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
    2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\termsrv.dll
    2005-03-10 01:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll

    2006-07-05 04:57 985088 0fdd84928a5dde2510761b7ec76ccec9 c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
    2007-04-16 10:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
    2004-08-10 13:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB917422$\kernel32.dll
    2006-07-05 04:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 c:\windows\$NtUninstallKB935839$\kernel32.dll
    2008-04-13 18:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\kernel32.dll
    2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\kernel32.dll
    2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\dllcache\kernel32.dll

    2008-04-13 18:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\powrprof.dll
    2004-08-10 13:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
    @="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
    [HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
    2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
    @="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
    [HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
    2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
    "AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
    "type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
    "AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
    "YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
    "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
    "osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
    "CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
    "SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8891:TCP"= 8891:TCP:Pitbull
    "50706:TCP"= 50706:TCP:PORT_50706
    "41136:TCP"= 41136:TCP:PORT_41136
    "58843:TCP"= 58843:TCP:PORT_58843
    "45453:TCP"= 45453:TCP:PORT_45453
    "46608:TCP"= 46608:TCP:PORT_46608
    "24395:TCP"= 24395:TCP:PORT_24395
    "58380:TCP"= 58380:TCP:PORT_58380
    "12476:TCP"= 12476:TCP:PORT_12476
    "44022:TCP"= 44022:TCP:PORT_44022
    "23014:TCP"= 23014:TCP:PORT_23014
    "61930:TCP"= 61930:TCP:PORT_61930
    "46327:TCP"= 46327:TCP:PORT_46327
    "34724:TCP"= 34724:TCP:PORT_34724
    "19950:TCP"= 19950:TCP:PORT_19950
    "49203:TCP"= 49203:TCP:PORT_49203
    "23848:TCP"= 23848:TCP:PORT_23848
    "48998:TCP"= 48998:TCP:PORT_48998
    "53375:TCP"= 53375:TCP:PORT_53375
    "40458:TCP"= 40458:TCP:PORT_40458
    "6428:TCP"= 6428:TCP:PORT_6428
    "37706:TCP"= 37706:TCP:PORT_37706
    "47531:TCP"= 47531:TCP:PORT_47531
    "46532:TCP"= 46532:TCP:PORT_46532
    "32902:TCP"= 32902:TCP:PORT_32902
    "17347:TCP"= 17347:TCP:PORT_17347
    "17586:TCP"= 17586:TCP:PORT_17586
    "26291:TCP"= 26291:TCP:PORT_26291
    "55534:TCP"= 55534:TCP:PORT_55534
    "41891:TCP"= 41891:TCP:PORT_41891
    "48462:TCP"= 48462:TCP:PORT_48462
    "18050:TCP"= 18050:TCP:PORT_18050
    "31483:TCP"= 31483:TCP:PORT_31483
    "33700:TCP"= 33700:TCP:PORT_33700
    "31203:TCP"= 31203:TCP:PORT_31203
    "43418:TCP"= 43418:TCP:PORT_43418
    "24985:TCP"= 24985:TCP:PORT_24985
    "19001:TCP"= 19001:TCP:PORT_19001
    "42324:TCP"= 42324:TCP:PORT_42324
    "10141:TCP"= 10141:TCP:PORT_10141
    "15865:TCP"= 15865:TCP:PORT_15865
    "36942:TCP"= 36942:TCP:PORT_36942
    "30525:TCP"= 30525:TCP:PORT_30525
    "41668:TCP"= 41668:TCP:PORT_41668
    "46918:TCP"= 46918:TCP:PORT_46918
    "34969:TCP"= 34969:TCP:PORT_34969
    "31365:TCP"= 31365:TCP:PORT_31365
    "46969:TCP"= 46969:TCP:PORT_46969
    "24597:TCP"= 24597:TCP:PORT_24597
    "20994:TCP"= 20994:TCP:PORT_20994
    "41178:TCP"= 41178:TCP:PORT_41178
    "28301:TCP"= 28301:TCP:PORT_28301
    "59290:TCP"= 59290:TCP:PORT_59290
    "24121:TCP"= 24121:TCP:PORT_24121
    "57424:TCP"= 57424:TCP:PORT_57424
    "44981:TCP"= 44981:TCP:PORT_44981
    "58917:TCP"= 58917:TCP:PORT_58917
    "19762:TCP"= 19762:TCP:PORT_19762
    "13600:TCP"= 13600:TCP:PORT_13600
    "50879:TCP"= 50879:TCP:PORT_50879
    "25703:TCP"= 25703:TCP:PORT_25703
    "25665:TCP"= 25665:TCP:PORT_25665
    "61900:TCP"= 61900:TCP:PORT_61900
    "39500:TCP"= 39500:TCP:PORT_39500
    "20341:TCP"= 20341:TCP:PORT_20341
    "19297:TCP"= 19297:TCP:PORT_19297
    "38391:TCP"= 38391:TCP:PORT_38391
    "49316:TCP"= 49316:TCP:PORT_49316
    "59874:TCP"= 59874:TCP:PORT_59874
    "37001:TCP"= 37001:TCP:PORT_37001
    "53583:TCP"= 53583:TCP:PORT_53583
    "16237:TCP"= 16237:TCP:PORT_16237
    "64731:TCP"= 64731:TCP:PORT_64731
    "20478:TCP"= 20478:TCP:PORT_20478
    "9205:TCP"= 9205:TCP:PORT_9205
    "21048:TCP"= 21048:TCP:PORT_21048
    "13985:TCP"= 13985:TCP:PORT_13985
    "17569:TCP"= 17569:TCP:PORT_17569
    "39416:TCP"= 39416:TCP:PORT_39416
    "64321:TCP"= 64321:TCP:PORT_64321
    "5541:TCP"= 5541:TCP:PORT_5541
    "11962:TCP"= 11962:TCP:PORT_11962
    "17814:TCP"= 17814:TCP:PORT_17814
    "23703:TCP"= 23703:TCP:PORT_23703
    "30958:TCP"= 30958:TCP:PORT_30958
    "56113:TCP"= 56113:TCP:PORT_56113
    "57434:TCP"= 57434:TCP:PORT_57434
    "6168:TCP"= 6168:TCP:PORT_6168
    "46504:TCP"= 46504:TCP:PORT_46504
    "33384:TCP"= 33384:TCP:PORT_33384
    "56375:TCP"= 56375:TCP:PORT_56375
    "51170:TCP"= 51170:TCP:PORT_51170
    "19586:TCP"= 19586:TCP:PORT_19586
    "25575:TCP"= 25575:TCP:PORT_25575
    "42489:TCP"= 42489:TCP:PORT_42489
    "48396:TCP"= 48396:TCP:PORT_48396
    "31465:TCP"= 31465:TCP:PORT_31465
    "10617:TCP"= 10617:TCP:PORT_10617
    "65508:TCP"= 65508:TCP:PORT_65508
    "33536:TCP"= 33536:TCP:PORT_33536
    "38457:TCP"= 38457:TCP:PORT_38457
    "10028:TCP"= 10028:TCP:PORT_10028
    "36496:TCP"= 36496:TCP:PORT_36496
    "7458:TCP"= 7458:TCP:PORT_7458
    "37384:TCP"= 37384:TCP:PORT_37384
    "10590:TCP"= 10590:TCP:PORT_10590
    "45703:TCP"= 45703:TCP:PORT_45703
    "36131:TCP"= 36131:TCP:PORT_36131
    "22055:TCP"= 22055:TCP:PORT_22055
    "22102:TCP"= 22102:TCP:PORT_22102
    "21263:TCP"= 21263:TCP:PORT_21263
    "57395:TCP"= 57395:TCP:PORT_57395
    "48141:TCP"= 48141:TCP:PORT_48141
    "54043:TCP"= 54043:TCP:PORT_54043
    "47551:TCP"= 47551:TCP:PORT_47551
    "20518:TCP"= 20518:TCP:PORT_20518
    "28583:TCP"= 28583:TCP:PORT_28583
    "25268:TCP"= 25268:TCP:PORT_25268
    "40777:TCP"= 40777:TCP:PORT_40777
    "26878:TCP"= 26878:TCP:PORT_26878
    "40930:TCP"= 40930:TCP:PORT_40930
    "22729:TCP"= 22729:TCP:PORT_22729
    "23165:TCP"= 23165:TCP:PORT_23165
    "14616:TCP"= 14616:TCP:PORT_14616
    "12196:TCP"= 12196:TCP:PORT_12196
    "29415:TCP"= 29415:TCP:PORT_29415
    "28376:TCP"= 28376:TCP:PORT_28376
    "23958:TCP"= 23958:TCP:PORT_23958
    "8479:TCP"= 8479:TCP:PORT_8479
    "7010:TCP"= 7010:TCP:PORT_7010
    "28177:TCP"= 28177:TCP:PORT_28177
    "17291:TCP"= 17291:TCP:PORT_17291
    "55072:TCP"= 55072:TCP:PORT_55072
    "17438:TCP"= 17438:TCP:PORT_17438
    "12604:TCP"= 12604:TCP:PORT_12604
    "25643:TCP"= 25643:TCP:PORT_25643
    "56825:TCP"= 56825:TCP:PORT_56825
    "49451:TCP"= 49451:TCP:PORT_49451
    "42493:TCP"= 42493:TCP:PORT_42493
    "11581:TCP"= 11581:TCP:PORT_11581
    "62951:TCP"= 62951:TCP:PORT_62951
    "53295:TCP"= 53295:TCP:PORT_53295
    "9788:TCP"= 9788:TCP:PORT_9788
    "59565:TCP"= 59565:TCP:PORT_59565
    "40583:TCP"= 40583:TCP:PORT_40583
    "14298:TCP"= 14298:TCP:PORT_14298
    "47022:TCP"= 47022:TCP:PORT_47022
    "61853:TCP"= 61853:TCP:PORT_61853
    "56114:TCP"= 56114:TCP:PORT_56114

    R2 713xTVCard;SAA7133 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2005-03-15 277504]
    R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-08 29744]
    S1 MozyFilter;MozyFilter;c:\windows\system32\DRIVERS\mozy.sys [2008-10-06 53752]
    S3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
    S3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
    S3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
    S3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
    S3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
    S3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\DRIVERS\atinewp2.sys [2005-06-01 485760]
    S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]


    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - COMHOST
    *Deregistered* - abp480n5
    *Deregistered* - adpu160m
    *Deregistered* - AegisP
    *Deregistered* - AFD
    *Deregistered* - agp440
    *Deregistered* - agpCPQ
    *Deregistered* - Aha154x
    *Deregistered* - aic78u2
    *Deregistered* - aic78xx
    *Deregistered* - AliIde
    *Deregistered* - alim1541
    *Deregistered* - amdagp
    *Deregistered* - amsint
    *Deregistered* - Arp1394
    *Deregistered* - asc
    *Deregistered* - asc3350p
    *Deregistered* - asc3550
    *Deregistered* - Ati HotKey Poller
    *Deregistered* - ATI Smart
    *Deregistered* - audstub
    *Deregistered* - Beep
    *Deregistered* - cbidf
    *Deregistered* - cd20xrnt
    *Deregistered* - Cdfs
    *Deregistered* - CLTNetCnService
    *Deregistered* - CmdIde
    *Deregistered* - comHost
    *Deregistered* - Cpqarray
    *Deregistered* - dac2w2k
    *Deregistered* - dac960nt
    *Deregistered* - dmio
    *Deregistered* - dmload
    *Deregistered* - dpti2o
    *Deregistered* - eeCtrl
    *Deregistered* - EraserUtilRebootDrv
    *Deregistered* - Fastfat
    *Deregistered* - Fips
    *Deregistered* - FltMgr
    *Deregistered* - Ftdisk
    *Deregistered* - Gpc
    *Deregistered* - GTNDIS5
    *Deregistered* - hpn
    *Deregistered* - HTTP
    *Deregistered* - i2omgmt
    *Deregistered* - i2omp
    *Deregistered* - ini910u
    *Deregistered* - IntelIde
    *Deregistered* - Ip6Fw
    *Deregistered* - IpNat
    *Deregistered* - IPSec
    *Deregistered* - KSecDD
    *Deregistered* - LiveUpdate Notice Ex
    *Deregistered* - LiveUpdate Notice Service
    *Deregistered* - mnmdd
    *Deregistered* - MountMgr
    *Deregistered* - MozyBackup
    *Deregistered* - MozyFilter
    *Deregistered* - mraid35x
    *Deregistered* - MRxDAV
    *Deregistered* - MRxSmb
    *Deregistered* - Msfs
    *Deregistered* - mssmbios
    *Deregistered* - Mup
    *Deregistered* - NAVENG
    *Deregistered* - NAVEX15
    *Deregistered* - NDIS
    *Deregistered* - Ndisuio
    *Deregistered* - NdisWan
    *Deregistered* - NDProxy
    *Deregistered* - NetBIOS
    *Deregistered* - NetBT
    *Deregistered* - Npfs
    *Deregistered* - Ntfs
    *Deregistered* - Null
    *Deregistered* - NwlnkIpx
    *Deregistered* - NwlnkNb
    *Deregistered* - NwlnkSpx
    *Deregistered* - PartMgr
    *Deregistered* - perc2
    *Deregistered* - perc2hib
    *Deregistered* - PptpMiniport
    *Deregistered* - PrismXL
    *Deregistered* - PSched
    *Deregistered* - ql1080
    *Deregistered* - Ql10wnt
    *Deregistered* - ql12160
    *Deregistered* - ql1240
    *Deregistered* - ql1280
    *Deregistered* - RasAcd
    *Deregistered* - Rasl2tp
    *Deregistered* - RasPppoe
    *Deregistered* - Raspti
    *Deregistered* - Rdbss
    *Deregistered* - RDPCDD
    *Deregistered* - rdpdr
    *Deregistered* - sisagp
    *Deregistered* - Sparrow
    *Deregistered* - sr
    *Deregistered* - SRTSP
    *Deregistered* - SRTSPX
    *Deregistered* - swenum
    *Deregistered* - sym_hi
    *Deregistered* - sym_u3
    *Deregistered* - symc810
    *Deregistered* - symc8xx
    *Deregistered* - SYMDNS
    *Deregistered* - SymEvent
    *Deregistered* - SYMFW
    *Deregistered* - SYMIDS
    *Deregistered* - SYMIDSCO
    *Deregistered* - SYMNDIS
    *Deregistered* - SYMREDRV
    *Deregistered* - SYMTDI
    *Deregistered* - Tcpip
    *Deregistered* - Tcpip6
    *Deregistered* - TermDD
    *Deregistered* - TosIde
    *Deregistered* - tunmp
    *Deregistered* - ultra
    *Deregistered* - Update
    *Deregistered* - VgaSave
    *Deregistered* - viaagp
    *Deregistered* - ViaIde
    *Deregistered* - VolSnap
    *Deregistered* - Wanarp
    *Deregistered* - WMP54Gv4SVC

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
    \Shell\AutoRun\command - K:\smartAP.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
    \Shell\AutoRun\command - E:\run.bat
    .
    Contents of the 'Scheduled Tasks' folder

    2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
    - c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.yahoo.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
    DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-02-01 15:03:48
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,26,b8,5e,26,00,
    e0,e8,d1,e2,63,26,f1,3f,c8,ff,68,90,3b,26,5c,ae,6e,84,c4,e2,63,26,f1,3f,c8,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,03,46,b9,b8,
    a6,76,67,6a,9c,d6,61,af,45,84,18,94,5f,6f,37,d7,a1,a9,29,6a,9c,d6,61,af,45,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,3d,3c,71,b7,9f,
    dc,e9,1b,ff,7c,85,e0,43,d4,0e,fe,b5,a7,b9,1d,20,35,11,86,ff,7c,85,e0,43,d4,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,12,07,dd,0d,7f,
    21,d3,4c,86,8c,21,01,be,91,eb,e7,e9,5f,c9,fe,bc,ad,42,2a,86,8c,21,01,be,91,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,01,ad,dc,b1,
    bd,5b,fd,f5,1d,4d,73,a8,13,5c,05,81,15,3b,6a,17,dc,fe,4e,f5,1d,4d,73,a8,13,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,22,6d,67,b6,
    56,19,8a,df,20,58,62,78,6b,cf,c8,fd,57,42,60,5d,81,ab,f8,df,20,58,62,78,6b,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,71,e6,3b,c1,c4,
    3e,24,3e,fb,a7,78,e6,12,2f,9a,ea,a3,8d,75,0a,b5,04,8f,49,fb,a7,78,e6,12,2f,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,fb,ef,0e,e5,32,
    23,0d,a5,01,3a,48,fc,e8,04,4a,f1,90,cd,67,e4,36,b1,32,7a,01,3a,48,fc,e8,04,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c3,e7,d0,db,cc,
    15,36,e5,f6,0f,4e,58,98,5b,89,c9,8b,cd,ea,1c,db,2c,57,9e,f6,0f,4e,58,98,5b,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,f7,7c,3e,f9,01,
    9a,61,88,3d,ce,ea,26,2d,45,aa,78,db,8a,97,10,b0,21,48,0e,3d,ce,ea,26,2d,45,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,98,19,c0,41,43,
    f4,2b,a7,2a,b7,cc,b5,b9,7f,41,e7,2c,b4,f2,d2,fd,82,d7,82,2a,b7,cc,b5,b9,7f,\

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
    "ThreadingModel"="Apartment"
    @="c:\\WINDOWS\\system32\\OLE32.DLL"
    "8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,fe,e6,69,6f,c3,
    9c,ba,71,6c,43,2d,1e,aa,22,2f,9c,08,f7,13,a7,0a,48,8d,4d,6c,43,2d,1e,aa,22,\
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(664)
    c:\windows\system32\Ati2evxx.dll
    c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
    c:\program files\common files\logitech\bluetooth\LBTServ.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\ati2evxx.exe
    c:\windows\system32\ati2evxx.exe
    c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
    c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
    c:\program files\Mozy\mozybackup.exe
    c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    c:\program files\Logitech\SetPoint\SetPoint.exe
    c:\program files\Mozy\mozystat.exe
    c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
    .
    **************************************************************************
    .
    Completion time: 2009-02-01 15:12:55 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-02-01 21:12:52
    ComboFix2.txt 2009-01-31 16:41:12

    Pre-Run: 150,602,010,624 bytes free
    Post-Run: 150,504,599,552 bytes free

    620 --- E O F --- 2009-01-14 09:04:25

  10. #10
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default new hijack log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:30:40 PM, on 2/1/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Mozy\mozybackup.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\zHotkey.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\PROGRA~1\Yahoo!\YOP\yop.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Mozy\mozystat.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\WINDOWS\explorer.exe
    K:\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: AMUST 1-Login IE Helper - {FFF1A4CB-472E-404a-9898-0B73B6B2E421} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
    O3 - Toolbar: AMUST 1-Login Toolbar - {F5BAA0B9-0DBF-4b42-BE9C-B2513ED71737} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [AMUST 1-Login AutoUpdate] rundll32.exe "C:\Program Files\Common Files\AMUST\Updater\amupdater.dll",AMUSTUpdate AMUST 1-Login ONLYLOCAL
    O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
    O4 - HKUS\S-1-5-21-3690015938-2637564805-925999644-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
    O4 - HKUS\S-1-5-21-3690015938-2637564805-925999644-1008\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem (User '?')
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
    O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\Mozy\mozystat.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} (WebInstaller Control) - http://concept.gamberjohnson.com/cor...bInstaller.ocx
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} (WebInstaller Control) - http://gamber.conceptconfigurator.co...bInstaller.ocx
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1156216832609
    O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://targetphoto.kodakgallery.com/...2/axofupld.cab
    O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
    O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photofinale.com/ImageUplo...eUploader4.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activ...v2.0.0.10.cab?
    O23 - Service: IPv6 Helper Service (6to4) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Application Management (AppMgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Windows Audio (AudioSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Computer Browser (Browser) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Bluetooth Support Service (BthServ) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Cryptographic Services (CryptSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: DCOM Server Process Launcher (DcomLaunch) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: DHCP Client (Dhcp) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Logical Disk Manager (dmserver) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Error Reporting Service (ERSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: COM+ Event System (EventSystem) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Fast User Switching Compatibility (FastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Help and Support (helpsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: HID Input Service (HidServ) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
    O23 - Service: Server (lanmanserver) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Workstation (lanmanworkstation) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: TCP/IP NetBIOS Helper (LmHosts) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: MHN - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: MozyHome Backup Service (MozyBackup) - Unknown owner - C:\Program Files\Mozy\mozybackup.exe
    O23 - Service: Network Connections (Netman) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Network Location Awareness (NLA) (Nla) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: Remote Access Auto Connection Manager (RasAuto) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Remote Access Connection Manager (RasMan) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Remote Registry (RemoteRegistry) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Remote Procedure Call (RPC) (RpcSs) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Secondary Logon (seclogon) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: System Event Notification (SENS) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Shell Hardware Detection (ShellHWDetection) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)
    O23 - Service: System Restore Service (srservice) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: SSDP Discovery Service (SSDPSRV) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Windows Image Acquisition (WIA) (stisvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: Telephony (TapiSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Terminal Services (TermService) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Themes - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Distributed Link Tracking Client (TrkWks) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Universal Plug and Play Device Host (upnphost) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Windows Time (W32Time) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: WebClient - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Windows Management Instrumentation (winmgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Portable Media Serial Number Service (WmdmPmSN) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Windows Management Instrumentation Driver Extensions (Wmi) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    O23 - Service: Security Center (wscsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
    O23 - Service: Wireless Zero Configuration (WZCSVC) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: Network Provisioning Service (xmlprov) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

    --
    End of file - 18318 bytes

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •