Results 1 to 9 of 9

Thread: Virtumonde Infection

  1. #1
    Junior Member
    Join Date
    Mar 2009
    Posts
    16

    Default Virtumonde Infection

    I was asked by my mom to take a look at her computer because she was having problems with pop ups. When I scanned it I came across virtumonde. I haven't been able to remove it and I'm not confident to mess around with her comp due to certain important things she keeps stored on it.

    Here's a Hijackthis log that I did for her comp.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:19:50 PM, on 3/22/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\msa.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\keyhook.exe
    C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
    C:\Program Files\Arcade\PCMService.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\WINDOWS\system32\hphmon03.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\WINDOWS\svcho.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\PROGRA~1\MICROS~4\rapimgr.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\acer\eRecovery\Monitor.exe
    C:\Program Files\Common Files\AOL\1226720766\ee\AOLDesktop.exe
    C:\Program Files\Common Files\AOL\1226720766\ee\aolsoftware.exe
    C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
    C:\WINDOWS\system32\5DPtWNv3.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yco...search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
    R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll
    F2 - REG:system.ini: UserInit=Userinit.exe,
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: {b268a64f-841d-d95a-4af4-182f56053cf8} - {8fc35065-f281-4fa4-a59d-d148f46a862b} - C:\WINDOWS\system32\ayqjoh.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    O2 - BHO: (no name) - {b83d3af9-89f7-4876-bc8c-d7e18fa1f851} - C:\WINDOWS\system32\sodisogi.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\ribivome.dll",s
    O4 - HKLM\..\Run: [CPM313e2b3d] Rundll32.exe "c:\windows\system32\yupabeda.dll",a
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7467] command.com /c del "c:\windows\system32\yupabeda.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6304] cmd.exe /c del "c:\windows\system32\yupabeda.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun
    O4 - HKCU\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe
    O4 - HKUS\S-1-5-19\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\ribivome.dll",s (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\ribivome.dll",s (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx
    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn...taller_gmn.cab
    O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - http://o.aolcdn.com/pictures/ap/Reso...s.10.2.0.0.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1132986941937
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemp...ogin-devel.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/armhelper.ocx
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL C:\WINDOWS\system32\zafozene.dll c:\windows\system32\rilonowu.dll ayqjoh.dll c:\windows\system32\yupabeda.dll
    O21 - SSODL: flammei - {9d635a36-6b3c-4146-8625-f3aaf507bbf8} - (no file)
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yupabeda.dll (file missing)
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yupabeda.dll (file missing)
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 15411 bytes

  2. #2
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,067

    Default

    hi,

    we will get a download to use. Its called MBAM. Link and directons below.
    After you use MBAM rescan and post a new hjt log.

    Please download Malwarebytes' Anti-Malware (MBAM) to your desktop:

    http://www.malwarebytes.org/mbam.php

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform FULL SCAN, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click **Remove Selected.**
    *A restart may be required to finish the clean up process*
    * After the restart, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

    please post the MBAM log in reply
    How Can I Reduce My Risk?

  3. #3
    Junior Member
    Join Date
    Mar 2009
    Posts
    16

    Default

    Malwarebytes' Anti-Malware 1.34
    Database version: 1892
    Windows 5.1.2600 Service Pack 2

    3/24/2009 2:24:42 PM
    mbam-log-2009-03-24 (14-24-42).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 290704
    Time elapsed: 1 hour(s), 17 minute(s), 9 second(s)

    Memory Processes Infected: 1
    Memory Modules Infected: 8
    Registry Keys Infected: 17
    Registry Values Infected: 7
    Registry Data Items Infected: 11
    Folders Infected: 5
    Files Infected: 41

    Memory Processes Infected:
    C:\WINDOWS\svcho.exe (Trojan.Agent) -> Unloaded process successfully.

    Memory Modules Infected:
    C:\WINDOWS\system32\pinoteye.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\zafozene.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\sodisogi.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\ribivome.dll (Trojan.Vundo.H) -> Delete on reboot.
    c:\WINDOWS\system32\kiguhoba.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\pajuwojo.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\ptyiqv.dll (Trojan.Vundo.H) -> Delete on reboot.
    c:\WINDOWS\system32\witukezo.dll (Trojan.BHO) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{058620a5-4522-4ffc-9286-3060a16b1985} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{058620a5-4522-4ffc-9286-3060a16b1985} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b83d3af9-89f7-4876-bc8c-d7e18fa1f851} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{b83d3af9-89f7-4876-bc8c-d7e18fa1f851} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b83d3af9-89f7-4876-bc8c-d7e18fa1f851} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{058620a5-4522-4ffc-9286-3060a16b1985} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{60af7e75-d08e-fef7-4ae6-aab98e03212d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\PrivacyProtector Free (Rogue.Privacy.Protector) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\320d18a1 (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rirawapola (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm313e2b3d (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\svcho (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ms antispyware 2009 (Rogue.MSantispyware2009) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\zafozene.dll -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\zafozene.dll -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\zafozene.dll -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\kiguhoba.dll -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\kiguhoba.dll -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\witukezo.dll -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\witukezo.dll -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Spyware.Passwords) -> Data: mcenspc.dll -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Documents and Settings\Dave\Application Data\PrivacyProtector Free (Rogue.PrivacyProtector) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Dave\Application Data\PrivacyProtector Free\Logs (Rogue.PrivacyProtector) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Application Data\PrivacyProtector Free (Rogue.PrivacyProtector) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Application Data\PrivacyProtector Free\Logs (Rogue.PrivacyProtector) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Start Menu\A360 (Rogue.A360Antivirus) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\ptyiqv.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\hevinuku.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ukuniveh.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\parodupa.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\apudorap.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\pinoteye.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\eyetonip.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ribivome.dll (Trojan.Vundo.H) -> Delete on reboot.
    c:\WINDOWS\system32\kiguhoba.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\sodisogi.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\zafozene.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\pajuwojo.dll (Trojan.Vundo.H) -> Delete on reboot.
    c:\WINDOWS\system32\witukezo.dll (Trojan.BHO) -> Delete on reboot.
    C:\WINDOWS\msa.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ruweyego.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ayqjoh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Local Settings\Temp\e.exe (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Local Settings\Temp\18685.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Local Settings\Temporary Internet Files\Content.IE5\CPRNA145\promo[2].exe (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Local Settings\Temporary Internet Files\Content.IE5\NTDG7V4V\load[1].php (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Local Settings\Temporary Internet Files\Content.IE5\UUE9DMDS\bb[1].jpg (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP679\A0231359.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP663\A0220269.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP671\A0226378.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP671\A0226379.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP673\A0229187.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP673\A0230186.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP673\A0230209.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP674\A0230242.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP677\A0230294.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP677\A0230319.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Dave\Application Data\PrivacyProtector Free\Logs\update.log (Rogue.PrivacyProtector) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Application Data\PrivacyProtector Free\Logs\update.log (Rogue.PrivacyProtector) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Start Menu\A360\A360.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Start Menu\A360\Help.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Elaine\Start Menu\A360\Registration.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
    C:\WINDOWS\svcho.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\5DPtWNv3.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mcenspc.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
    C:\Program Files\Common Files\System\Uninstall\Uninstall A360.lnk (Rogue.av360) -> Quarantined and deleted successfully.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:38:43 PM, on 3/24/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\keyhook.exe
    C:\Program Files\Arcade\PCMService.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\WINDOWS\system32\hphmon03.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\PROGRA~1\MICROS~4\rapimgr.exe
    C:\Program Files\Common Files\AOL\1226720766\ee\AOLDesktop.exe
    C:\Program Files\Common Files\AOL\1226720766\ee\aolsoftware.exe
    C:\Program Files\acer\eRecovery\Monitor.exe
    C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yco...search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
    R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [CPM313e2b3d] Rundll32.exe "c:\windows\system32\medesewo.dll",a
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\ribivome.dll",s (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\ribivome.dll",s (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx
    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn...taller_gmn.cab
    O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - http://o.aolcdn.com/pictures/ap/Reso...s.10.2.0.0.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1132986941937
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemp...ogin-devel.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/armhelper.ocx
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL c:\windows\system32\rilonowu.dll c:\windows\system32\yupabeda.dll ptyiqv.dll c:\windows\system32\medesewo.dll,
    O21 - SSODL: flammei - {9d635a36-6b3c-4146-8625-f3aaf507bbf8} - (no file)
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\medesewo.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\medesewo.dll
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Update Service (gupdate1c9ac8bbac1dd8e) (gupdate1c9ac8bbac1dd8e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 14716 bytes

  4. #4
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,067

    Default

    hi,

    ok. we will get one more download to use. Its called combofix. there is a guide to read first. Read through the guide, download combofix to your desktop, disable AV and any antimalware thats running (like Windows defender) as mentioned in the guide. double click the combofix icon and follow the prompts.
    Post the combofix log.

    The guide:
    http://www.bleepingcomputer.com/comb...o-use-combofix
    How Can I Reduce My Risk?

  5. #5
    Junior Member
    Join Date
    Mar 2009
    Posts
    16

    Default

    ComboFix 09-03-23.01 - Elaine 2009-03-24 18:19:16.1 - FAT32x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.958.522 [GMT -4:00]
    Running from: c:\documents and settings\Elaine\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Dave\Application Data\install.dat
    c:\documents and settings\Dave\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyLocked 4.0.lnk
    c:\documents and settings\Dave\err.log
    c:\program files\Common Files\System\Uninstall
    c:\program files\USS
    c:\program files\USS\#agents\53\#startup
    c:\program files\USS\{5F608915-125D-404d-AC44-D78C760AE1A3}\AMPlugin.xml
    c:\program files\USS\{5F608915-125D-404d-AC44-D78C760AE1A3}\AsAgents.xml
    c:\program files\USS\{5F608915-125D-404d-AC44-D78C760AE1A3}\unins000.dat
    c:\program files\USS\unins000.dat
    c:\windows\syssvc.exe
    c:\windows\system32\ .txt
    c:\windows\system32\fsxjey.dll
    c:\windows\system32\fukiroki.dll
    c:\windows\system32\jevuwuwa.dll
    c:\windows\system32\medesewo.dll
    c:\windows\system32\pakiwega.dll
    c:\windows\system32\qxaikd.dll
    c:\windows\system32\ravumoru.dll
    c:\windows\system32\tadebava.dll
    c:\windows\system32\tesifeke.dll
    c:\windows\system32\uythgl.dll
    c:\windows\system32\zdpkcf.dll
    c:\windows\system32\ziluvora.dll

    .
    ((((((((((((((((((((((((( Files Created from 2009-02-24 to 2009-03-24 )))))))))))))))))))))))))))))))
    .

    2009-03-24 14:39 . 2009-03-24 14:39 268 --ah----- C:\sqmdata19.sqm
    2009-03-24 14:39 . 2009-03-24 14:39 244 --ah----- C:\sqmnoopt19.sqm
    2009-03-24 14:26 . 2009-03-24 14:26 268 --ah----- C:\sqmdata18.sqm
    2009-03-24 14:26 . 2009-03-24 14:26 244 --ah----- C:\sqmnoopt18.sqm
    2009-03-24 12:54 . 2009-03-24 12:54 <DIR> d-------- c:\documents and settings\Elaine\Application Data\Malwarebytes
    2009-03-24 12:53 . 2009-03-24 12:53 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
    2009-03-24 12:53 . 2009-03-24 12:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-24 12:53 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-24 12:53 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2009-03-24 12:26 . 2009-03-24 12:26 <DIR> d--hs---- C:\FOUND.017
    2009-03-24 11:22 . 2009-03-24 11:22 280 --ah----- C:\sqmdata17.sqm
    2009-03-24 11:22 . 2009-03-24 11:22 244 --ah----- C:\sqmnoopt17.sqm
    2009-03-24 10:25 . 2009-03-24 10:25 <DIR> d-------- c:\program files\Common Files\xing shared
    2009-03-23 23:07 . 2009-03-23 23:07 268 --ah----- C:\sqmdata16.sqm
    2009-03-23 23:07 . 2009-03-23 23:07 244 --ah----- C:\sqmnoopt16.sqm
    2009-03-23 10:56 . 2009-03-23 10:57 268 --ah----- C:\sqmdata15.sqm
    2009-03-23 10:56 . 2009-03-23 10:57 244 --ah----- C:\sqmnoopt15.sqm
    2009-03-22 22:17 . 2009-03-22 22:17 268 --ah----- C:\sqmdata14.sqm
    2009-03-22 22:17 . 2009-03-22 22:17 244 --ah----- C:\sqmnoopt14.sqm
    2009-03-22 15:19 . 2009-03-22 15:19 <DIR> d-------- c:\program files\Trend Micro
    2009-03-22 15:18 . 2009-03-22 15:18 <DIR> d-------- c:\program files\ERUNT
    2009-03-22 15:10 . 2009-03-22 15:10 244 --ah----- C:\sqmnoopt13.sqm
    2009-03-22 15:10 . 2009-03-22 15:10 232 --ah----- C:\sqmdata13.sqm
    2009-03-22 15:09 . 2009-03-22 15:09 244 --ah----- C:\sqmnoopt12.sqm
    2009-03-22 15:09 . 2009-03-22 15:09 232 --ah----- C:\sqmdata12.sqm
    2009-03-22 11:21 . 2009-03-22 11:21 <DIR> d--hs---- C:\FOUND.016
    2009-03-21 20:58 . 2009-03-21 20:58 268 --ah----- C:\sqmdata11.sqm
    2009-03-21 20:58 . 2009-03-21 20:58 244 --ah----- C:\sqmnoopt11.sqm
    2009-03-21 19:19 . 2009-03-21 19:19 268 --ah----- C:\sqmdata10.sqm
    2009-03-21 19:19 . 2009-03-21 19:19 244 --ah----- C:\sqmnoopt10.sqm
    2009-03-21 19:04 . 2009-03-21 19:04 244 --ah----- C:\sqmnoopt09.sqm
    2009-03-21 19:04 . 2009-03-21 19:04 232 --ah----- C:\sqmdata09.sqm
    2009-03-21 18:58 . 2009-03-21 18:58 268 --ah----- C:\sqmdata08.sqm
    2009-03-21 18:58 . 2009-03-21 18:58 244 --ah----- C:\sqmnoopt08.sqm
    2009-03-21 16:07 . 2009-03-24 14:28 11,168 --ah----- c:\windows\system32\pekebiji
    2009-03-21 00:20 . 2009-03-21 00:20 268 --ah----- C:\sqmdata07.sqm
    2009-03-21 00:20 . 2009-03-21 00:20 244 --ah----- C:\sqmnoopt07.sqm
    2009-03-20 16:53 . 2009-03-20 16:53 268 --ah----- C:\sqmdata06.sqm
    2009-03-20 16:53 . 2009-03-20 16:53 244 --ah----- C:\sqmnoopt06.sqm
    2009-03-19 23:05 . 2009-03-19 23:05 118 --a------ c:\windows\system32\MRT.INI
    2009-03-19 23:02 . 2009-03-19 23:02 268 --ah----- C:\sqmdata05.sqm
    2009-03-19 23:02 . 2009-03-19 23:02 244 --ah----- C:\sqmnoopt05.sqm
    2009-03-18 20:20 . 2009-03-18 20:20 268 --ah----- C:\sqmdata04.sqm
    2009-03-18 20:20 . 2009-03-18 20:20 244 --ah----- C:\sqmnoopt04.sqm
    2009-03-17 22:18 . 2009-03-17 22:18 244 --ah----- C:\sqmnoopt03.sqm
    2009-03-17 22:18 . 2009-03-17 22:18 232 --ah----- C:\sqmdata03.sqm
    2009-03-09 18:07 . 2009-03-09 18:07 244 --ah----- C:\sqmnoopt02.sqm
    2009-03-09 18:07 . 2009-03-09 18:07 232 --ah----- C:\sqmdata02.sqm
    2009-03-08 10:02 . 2009-03-08 10:02 244 --ah----- C:\sqmnoopt01.sqm
    2009-03-08 10:02 . 2009-03-08 10:02 232 --ah----- C:\sqmdata01.sqm
    2009-03-05 20:15 . 2009-03-05 20:15 <DIR> d--hs---- C:\FOUND.015
    2009-03-04 09:23 . 2009-03-21 17:20 76,288 --a------ c:\windows\system32\5DPtWNv3.exe
    2009-03-02 22:42 . 2009-03-02 22:42 268 --ah----- C:\sqmdata00.sqm
    2009-03-02 22:42 . 2009-03-02 22:42 244 --ah----- C:\sqmnoopt00.sqm
    2009-02-28 21:11 . 2009-02-28 21:11 <DIR> d-------- c:\program files\DivX
    2009-02-28 20:56 . 2009-02-28 20:56 <DIR> d--hs---- C:\FOUND.014
    2009-02-28 09:47 . 2009-02-28 09:47 <DIR> d-------- c:\program files\LogMeIn
    2009-02-28 09:47 . 2009-02-28 09:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\LogMeIn
    2009-02-28 09:47 . 2008-10-16 20:35 87,352 --a------ c:\windows\system32\LMIinit.dll
    2009-02-28 09:47 . 2008-10-16 20:35 83,288 --a------ c:\windows\system32\LMIRfsClientNP.dll
    2009-02-28 09:47 . 2008-07-24 18:46 47,640 --a------ c:\windows\system32\drivers\LMIRfsDriver.sys
    2009-02-28 09:47 . 2008-10-16 20:35 28,984 --a------ c:\windows\system32\LMIport.dll
    2009-02-28 09:47 . 2009-02-28 09:47 1,024 --a------ C:\.rnd
    2009-02-27 19:41 . 2009-03-22 15:00 1,123 --a------ c:\windows\wininit.ini
    2009-02-25 11:42 . 2009-02-25 11:42 <DIR> d-------- C:\BurnInTest test files
    2009-02-25 11:42 . 2006-09-28 16:05 2,414,360 --a------ c:\windows\system32\d3dx9_31.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-02-09 10:19 1,846,272 ----a-w c:\windows\system32\win32k.sys
    2009-02-09 10:19 1,846,272 ----a-w c:\windows\system32\dllcache\win32k.sys
    2009-01-17 01:35 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
    2007-05-18 18:46 10,878,344 ----a-w c:\program files\SpeedScan.setup.exe
    2007-05-18 18:25 10,878,344 ----a-w c:\program files\SpeedScan_setup.exe
    2008-02-08 03:38 131,584 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    2008-05-22 03:56 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052120080522\index.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-06 68856]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
    "H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 1200128]
    "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp"="Alaunch" [X]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
    "SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2005-03-04 32768]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "PCMService"="c:\program files\Arcade\PCMService.exe" [2005-03-09 49152]
    "LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2005-03-28 315392]
    "eRecoveryService"="c:\windows\System32\Check.exe" [2005-03-23 245760]
    "vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-04-26 90112]
    "DiskeeperSystray"="c:\program files\Executive Software\Diskeeper\DkIcon.exe" [2004-10-04 176216]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-07-31 98304]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-11-17 1168264]
    "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-13 196608]
    "HPHmon03"="c:\windows\system32\hphmon03.exe" [2006-01-13 311296]
    "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-24 198160]
    "SoundMan"="SOUNDMAN.EXE" [2005-02-23 c:\windows\SOUNDMAN.EXE]
    "AGRSMMSG"="AGRSMMSG.exe" [2004-10-07 c:\windows\AGRSMMSG.exe]
    "SiSPower"="SiSPower.dll" [2005-02-25 c:\windows\system32\SiSPower.dll]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

    c:\documents and settings\Elaine\Start Menu\Programs\Startup\
    AOL Desktop.lnk - c:\program files\Common Files\AOL\Launch\aollaunch.exe [2008-06-24 41824]
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
    2008-10-16 20:35 87352 c:\windows\system32\LMIinit.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "MSACM.CEGSM"= mobilev.acm
    "vidc.ffds"= c:\progra~1\COMBIN~1\Filters\ff_vfw.dll
    "vidc.wmv3"= c:\progra~1\COMBIN~1\Filters\wmv9vcm.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax 4.2.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\eFax 4.2.lnk
    backup=c:\windows\pss\eFax 4.2.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
    backup=c:\windows\pss\Google Updater.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
    backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 2000 Series.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk
    backup=c:\windows\pss\hp psc 2000 Series.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
    backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
    backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
    backup=c:\windows\pss\Kodak software updater.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
    backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
    backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
    backup=c:\windows\pss\Utility Tray.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
    backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Dave^Start Menu^Programs^Startup^AOL OpenRide.lnk]
    path=c:\documents and settings\Dave\Start Menu\Programs\Startup\AOL OpenRide.lnk
    backup=c:\windows\pss\AOL OpenRide.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Dave^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=c:\documents and settings\Dave\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=c:\windows\pss\LimeWire On Startup.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Dave^Start Menu^Programs^Startup^VZAccess Manager.lnk]
    path=c:\documents and settings\Dave\Start Menu\Programs\Startup\VZAccess Manager.lnk
    backup=c:\windows\pss\VZAccess Manager.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
    --a------ 2005-06-06 23:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
    -r------- 2006-10-23 07:50 71216 c:\program files\Common Files\AOL\ACS\AOLDial.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    --a------ 2008-02-07 23:38 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
    --a------ 2005-11-15 19:44 1200128 c:\program files\Microsoft ActiveSync\wcescomm.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    --a------ 2006-02-19 02:41 49152 c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --------- 2004-10-13 12:24 1694208 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    --a------ 2006-01-12 16:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Performance Center]
    --a------ 2007-04-26 18:00 3039232 c:\program files\Ascentive\Performance Center\ApcMain.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
    --a------ 2008-08-20 21:18 443968 c:\program files\Picasa2\PicasaMediaDetector.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
    --a------ 2009-03-24 10:24 214536 c:\program files\Real\RealPlayer\realplay.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-07-06 21:03 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "gusvc"=2 (0x2)
    "GoogleDesktopManager-093007-112848"=3 (0x3)
    "WMPNetworkSvc"=3 (0x3)
    "Viewpoint Manager Service"=2 (0x2)
    "SPTISRV"=3 (0x3)
    "sdCoreService"=2 (0x2)
    "sdAuxService"=2 (0x2)
    "MSCSPTISRV"=3 (0x3)
    "LightScribeService"=2 (0x2)
    "IDriverT"=3 (0x3)
    "Diskeeper"=2 (0x2)
    "AOL TopSpeedMonitor"=2 (0x2)
    "AOL ACS"=3 (0x3)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\UT2004Demo\\System\\UT2004.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
    "c:\\Program Files\\eSignal\\winros.exe"=
    "c:\\StubInstaller.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
    "c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
    "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
    "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
    "c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
    "c:\\WINDOWS\\System32\\mmc.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqtra08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqste08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpofxm08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposfx08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposid01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqscnvw.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqkygrp.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqCopy.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpfccopy.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpzwiz01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpoews01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqnrs08.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\REALPLAY.EXE"=
    "c:\\WINDOWS\\System32\\dpvsetup.exe"=
    "c:\\Program Files\\Common Files\\AOL\\1226720766\\ee\\aolsoftware.exe"=
    "c:\\Program Files\\Common Files\\AOL\\1226720766\\ee\\AOLDesktop.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R0 sonypvl3;sonypvl3;c:\windows\system32\drivers\sonypvl3.sys [2006-05-06 18110]
    R1 sonypvf3;sonypvf3;c:\windows\system32\drivers\sonypvf3.sys [2006-05-06 619390]
    R1 sonypvt3;sonypvt3;c:\windows\system32\drivers\sonypvt3.sys [2006-05-06 423454]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2008-07-24 12856]
    R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-02-28 47640]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
    S2 gupdate1c9ac8bbac1dd8e;Google Update Service (gupdate1c9ac8bbac1dd8e);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 133104]
    S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [2008-05-11 18864]
    S3 PLUsbbc2;USB 2.0 Networking/Data Transfer Cable;c:\windows\system32\drivers\usbbc2.sys [2008-10-18 8960]
    S3 PTDCWWAN;PANTECH PC Card WWAN Controller device driver;c:\windows\system32\drivers\PTDCWWAN.sys [2008-03-13 58240]
    S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [2008-07-24 29824]
    S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [2008-07-24 41344]
    S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [2008-07-24 39936]
    S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [2008-07-24 59776]
    S4 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2007-07-06 29744]
    S4 LMIRfsClientNP;LMIRfsClientNP; [x]
    S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-03-20 356920]
    S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-02-15 24652]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-24 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

    2008-06-13 c:\windows\Tasks\Norton Security Scan.job
    - c:\program files\Norton Security Scan\Nss.exe [2007-04-19 22:42]

    2009-03-21 c:\windows\Tasks\WebReg psc 2210.job
    - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2006-02-19 05:09]

    2009-03-24 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

    2009-03-04 c:\windows\Tasks\At1.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At2.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At3.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At4.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At5.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At6.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At7.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At8.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At9.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At10.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At11.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At12.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-22 c:\windows\Tasks\At13.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At14.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At15.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-22 c:\windows\Tasks\At16.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At17.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At18.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At19.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-23 c:\windows\Tasks\At20.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At21.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At22.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At23.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At24.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At25.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At26.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At27.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At28.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At29.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At30.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At31.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At32.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At33.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At34.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At35.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At36.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-22 c:\windows\Tasks\At37.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At38.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At39.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-22 c:\windows\Tasks\At40.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At41.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At42.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At43.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-23 c:\windows\Tasks\At44.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At45.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At46.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At47.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At48.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 10:18]

    2006-07-11 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1136700040.job
    - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 17:56]

    2009-03-22 c:\windows\Tasks\WebReg 20070323112304.job
    - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2006-02-19 05:09]
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-NWEReboot - (no file)
    MSConfigStartUp-AOL Fast Start - c:\program files\America Online 9.0\AOL.EXE
    MSConfigStartUp-eFax 4 - c:\program files\eFax Messenger 4.2\J2GDllCmd.exe
    MSConfigStartUp-HostManager - c:\program files\Common Files\AOL\1122856127\ee\AOLSoftware.exe
    MSConfigStartUp-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    MSConfigStartUp-PC ScanAndSweep - c:\program files\Ascentive\PC ScanAndSweep\PCScanAndSweep.exe
    MSConfigStartUp-PC SpeedScan Pro - c:\program files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe
    MSConfigStartUp-Pure Networks Port Magic - c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe
    MSConfigStartUp-spywarebot - c:\program files\SpywareBot\SpywareBot.exe
    MSConfigStartUp-uprpcw - c:\program files\PrivacyProtector Free\uprpcw.exe
    MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\YahooMessenger.exe


    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=yie7c
    mStart Page = hxxp://www.yahoo.com
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
    IE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Elaine\Application Data\Mozilla\Firefox\Profiles\jhxocqy7.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopie7&query=
    FF - prefs.js: browser.search.selectedEngine - AOL Search
    FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopab&query=
    FF - component: c:\documents and settings\Elaine\Application Data\Mozilla\Firefox\Profiles\jhxocqy7.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dll
    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
    FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
    FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
    FF - plugin: c:\program files\Picasa2\npPicasa2.dll
    FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true.

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-24 18:22:59
    Windows 5.1.2600 Service Pack 2 FAT NTAPI

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(688)
    c:\windows\system32\LMIinit.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\acer\EMANAGER\ANBMSERV.EXE
    c:\program files\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
    c:\program files\GOOGLE\COMMON\GOOGLE UPDATER\GOOGLEUPDATERSERVICE.EXE
    c:\program files\JAVA\JRE6\BIN\JQS.EXE
    c:\program files\LOGMEIN\X86\RAMAINT.EXE
    c:\program files\LOGMEIN\X86\LOGMEIN.EXE
    c:\program files\LOGMEIN\X86\LMIGUARDIAN.EXE
    c:\windows\SYSTEM32\WSCNTFY.EXE
    c:\windows\SYSTEM32\RUNDLL32.EXE
    c:\program files\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
    c:\program files\LOGMEIN\X86\LMIGUARDIAN.EXE
    c:\progra~1\MICROS~4\rapimgr.exe
    c:\program files\acer\eRecovery\Monitor.exe
    c:\program files\Common Files\AOL\1226720766\ee\AOLDesktop.exe
    c:\program files\Common Files\AOL\1226720766\ee\aolsoftware.exe
    c:\program files\Common Files\AOL\ACS\AOLacsd.exe
    .
    **************************************************************************
    .
    Completion time: 2009-03-24 18:28:28 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-03-24 22:28:26

    Pre-Run: 1,851,162,624 bytes free
    Post-Run: 5,730,861,056 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    504 --- E O F --- 2009-03-20 03:05:38

  6. #6
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,067

    Default

    ok good. we will use combofix.

    Click Start, then Run and type Notepad and click OK.
    Copy/paste the text in the code box below into notepad:

    Code:
    File:
    c:\windows\system32\5DPtWNv3.exe
    c:\windows\Tasks\At1.job
    c:\windows\Tasks\At2.job
    c:\windows\Tasks\At3.job
    c:\windows\Tasks\At4.job
    c:\windows\Tasks\At5.job
    c:\windows\Tasks\At6.job
    c:\windows\Tasks\At7.job
    c:\windows\Tasks\At8.job
    c:\windows\Tasks\At9.job
    c:\windows\Tasks\At10.jo
    c:\windows\Tasks\At11.job
    c:\windows\Tasks\At12.job
    c:\windows\Tasks\At13.job
    c:\windows\Tasks\At14.job
    c:\windows\Tasks\At15.job
    c:\windows\Tasks\At16.job
    c:\windows\Tasks\At17.job
    c:\windows\Tasks\At18.job
    c:\windows\Tasks\At19.job
    c:\windows\Tasks\At20.job
    c:\windows\Tasks\At21.job
    c:\windows\Tasks\At22.job
    c:\windows\Tasks\At23.job
    c:\windows\Tasks\At24.job
    c:\windows\Tasks\At25.job
    c:\windows\Tasks\At26.job
    c:\windows\Tasks\At27.job
    c:\windows\Tasks\At28.job
    c:\windows\Tasks\At29.job
    c:\windows\Tasks\At30.job
    c:\windows\Tasks\At31.job
    c:\windows\Tasks\At32.job
    c:\windows\Tasks\At33.job
    c:\windows\Tasks\At34.job
    c:\windows\Tasks\At35.job
    c:\windows\Tasks\At36.job
    c:\windows\Tasks\At37.job
    c:\windows\Tasks\At38.job
    c:\windows\Tasks\At39.job
    c:\windows\Tasks\At40.job
    c:\windows\Tasks\At41.job
    c:\windows\Tasks\At42.job
    c:\windows\Tasks\At43.job
    c:\windows\Tasks\At44.job
    c:\windows\Tasks\At45.job
    c:\windows\Tasks\At46.job
    c:\windows\Tasks\At47.job
    c:\windows\Tasks\At48.job
    Name the Notepad file CFScript.txt and Save it to your desktop.
    now locate the file you just saved and the combofix icon, both on your desktop
    using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log
    please post the new combofix log. Last: rescan and post a new hjt log also.
    How Can I Reduce My Risk?

  7. #7
    Junior Member
    Join Date
    Mar 2009
    Posts
    16

    Default

    ComboFix 09-03-25.03 - Elaine 2009-03-26 9:37:37.3 - FAT32x86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.958.537 [GMT -4:00]
    Running from: c:\documents and settings\Elaine\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Elaine\Desktop\CFScript.txt
    * Created a new restore point
    .

    ((((((((((((((((((((((((( Files Created from 2009-02-26 to 2009-03-26 )))))))))))))))))))))))))))))))
    .

    2009-03-24 14:39 . 2009-03-24 14:39 268 --ah----- C:\sqmdata19.sqm
    2009-03-24 14:39 . 2009-03-24 14:39 244 --ah----- C:\sqmnoopt19.sqm
    2009-03-24 14:26 . 2009-03-24 14:26 268 --ah----- C:\sqmdata18.sqm
    2009-03-24 14:26 . 2009-03-24 14:26 244 --ah----- C:\sqmnoopt18.sqm
    2009-03-24 12:54 . 2009-03-24 12:54 <DIR> d-------- c:\documents and settings\Elaine\Application Data\Malwarebytes
    2009-03-24 12:53 . 2009-03-24 12:53 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
    2009-03-24 12:53 . 2009-03-24 12:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-24 12:53 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-24 12:53 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2009-03-24 12:26 . 2009-03-24 12:26 <DIR> d--hs---- C:\FOUND.017
    2009-03-24 11:22 . 2009-03-24 11:22 280 --ah----- C:\sqmdata17.sqm
    2009-03-24 11:22 . 2009-03-24 11:22 244 --ah----- C:\sqmnoopt17.sqm
    2009-03-24 10:25 . 2009-03-24 10:25 <DIR> d-------- c:\program files\Common Files\xing shared
    2009-03-23 23:07 . 2009-03-23 23:07 268 --ah----- C:\sqmdata16.sqm
    2009-03-23 23:07 . 2009-03-23 23:07 244 --ah----- C:\sqmnoopt16.sqm
    2009-03-23 10:56 . 2009-03-23 10:57 268 --ah----- C:\sqmdata15.sqm
    2009-03-23 10:56 . 2009-03-23 10:57 244 --ah----- C:\sqmnoopt15.sqm
    2009-03-22 22:17 . 2009-03-22 22:17 268 --ah----- C:\sqmdata14.sqm
    2009-03-22 22:17 . 2009-03-22 22:17 244 --ah----- C:\sqmnoopt14.sqm
    2009-03-22 15:19 . 2009-03-22 15:19 <DIR> d-------- c:\program files\Trend Micro
    2009-03-22 15:18 . 2009-03-22 15:18 <DIR> d-------- c:\program files\ERUNT
    2009-03-22 15:10 . 2009-03-22 15:10 244 --ah----- C:\sqmnoopt13.sqm
    2009-03-22 15:10 . 2009-03-22 15:10 232 --ah----- C:\sqmdata13.sqm
    2009-03-22 15:09 . 2009-03-22 15:09 244 --ah----- C:\sqmnoopt12.sqm
    2009-03-22 15:09 . 2009-03-22 15:09 232 --ah----- C:\sqmdata12.sqm
    2009-03-22 11:21 . 2009-03-22 11:21 <DIR> d--hs---- C:\FOUND.016
    2009-03-21 20:58 . 2009-03-21 20:58 268 --ah----- C:\sqmdata11.sqm
    2009-03-21 20:58 . 2009-03-21 20:58 244 --ah----- C:\sqmnoopt11.sqm
    2009-03-21 19:19 . 2009-03-21 19:19 268 --ah----- C:\sqmdata10.sqm
    2009-03-21 19:19 . 2009-03-21 19:19 244 --ah----- C:\sqmnoopt10.sqm
    2009-03-21 19:04 . 2009-03-21 19:04 244 --ah----- C:\sqmnoopt09.sqm
    2009-03-21 19:04 . 2009-03-21 19:04 232 --ah----- C:\sqmdata09.sqm
    2009-03-21 18:58 . 2009-03-21 18:58 268 --ah----- C:\sqmdata08.sqm
    2009-03-21 18:58 . 2009-03-21 18:58 244 --ah----- C:\sqmnoopt08.sqm
    2009-03-21 16:07 . 2009-03-24 14:28 11,168 --ah----- c:\windows\system32\pekebiji
    2009-03-21 00:20 . 2009-03-21 00:20 268 --ah----- C:\sqmdata07.sqm
    2009-03-21 00:20 . 2009-03-21 00:20 244 --ah----- C:\sqmnoopt07.sqm
    2009-03-20 16:53 . 2009-03-20 16:53 268 --ah----- C:\sqmdata06.sqm
    2009-03-20 16:53 . 2009-03-20 16:53 244 --ah----- C:\sqmnoopt06.sqm
    2009-03-19 23:05 . 2009-03-19 23:05 118 --a------ c:\windows\system32\MRT.INI
    2009-03-19 23:02 . 2009-03-19 23:02 268 --ah----- C:\sqmdata05.sqm
    2009-03-19 23:02 . 2009-03-19 23:02 244 --ah----- C:\sqmnoopt05.sqm
    2009-03-18 20:20 . 2009-03-26 09:16 244 --ah----- C:\sqmnoopt04.sqm
    2009-03-18 20:20 . 2009-03-26 09:16 232 --ah----- C:\sqmdata04.sqm
    2009-03-17 22:18 . 2009-03-25 22:35 244 --ah----- C:\sqmnoopt03.sqm
    2009-03-17 22:18 . 2009-03-25 22:35 232 --ah----- C:\sqmdata03.sqm
    2009-03-09 18:07 . 2009-03-25 22:34 268 --ah----- C:\sqmdata02.sqm
    2009-03-09 18:07 . 2009-03-25 22:34 244 --ah----- C:\sqmnoopt02.sqm
    2009-03-08 10:02 . 2009-03-24 21:37 268 --ah----- C:\sqmdata01.sqm
    2009-03-08 10:02 . 2009-03-24 21:37 244 --ah----- C:\sqmnoopt01.sqm
    2009-03-05 20:15 . 2009-03-05 20:15 <DIR> d--hs---- C:\FOUND.015
    2009-03-04 09:23 . 2009-03-21 17:20 76,288 --a------ c:\windows\system32\5DPtWNv3.exe
    2009-03-02 22:42 . 2009-03-24 18:34 268 --ah----- C:\sqmdata00.sqm
    2009-03-02 22:42 . 2009-03-24 18:34 244 --ah----- C:\sqmnoopt00.sqm
    2009-02-28 21:11 . 2009-02-28 21:11 <DIR> d-------- c:\program files\DivX
    2009-02-28 20:56 . 2009-02-28 20:56 <DIR> d--hs---- C:\FOUND.014
    2009-02-28 09:47 . 2009-02-28 09:47 <DIR> d-------- c:\program files\LogMeIn
    2009-02-28 09:47 . 2009-02-28 09:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\LogMeIn
    2009-02-28 09:47 . 2008-10-16 20:35 87,352 --a------ c:\windows\system32\LMIinit.dll
    2009-02-28 09:47 . 2008-10-16 20:35 83,288 --a------ c:\windows\system32\LMIRfsClientNP.dll
    2009-02-28 09:47 . 2008-07-24 18:46 47,640 --a------ c:\windows\system32\drivers\LMIRfsDriver.sys
    2009-02-28 09:47 . 2008-10-16 20:35 28,984 --a------ c:\windows\system32\LMIport.dll
    2009-02-28 09:47 . 2009-02-28 09:47 1,024 --a------ C:\.rnd
    2009-02-27 19:41 . 2009-03-22 15:00 1,123 --a------ c:\windows\wininit.ini

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-02-09 10:19 1,846,272 ----a-w c:\windows\system32\win32k.sys
    2009-02-09 10:19 1,846,272 ----a-w c:\windows\system32\dllcache\win32k.sys
    2009-01-17 01:35 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
    2007-05-18 18:46 10,878,344 ----a-w c:\program files\SpeedScan.setup.exe
    2007-05-18 18:25 10,878,344 ----a-w c:\program files\SpeedScan_setup.exe
    2008-02-08 03:38 131,584 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    2008-05-22 03:56 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052120080522\index.dat
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-03-24_18.27.20.78 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2005-10-20 16:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-25-2009\ERDNT.EXE
    + 2009-03-25 22:39:40 5,746,688 ----a-w c:\windows\ERDNT\AutoBackup\3-25-2009\Users\00000001\ntuser.dat
    + 2009-03-25 22:39:40 303,104 ----a-w c:\windows\ERDNT\AutoBackup\3-25-2009\Users\00000002\UsrClass.dat
    + 2005-10-20 16:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\3-26-2009\ERDNT.EXE
    + 2009-03-26 12:25:54 5,746,688 ----a-w c:\windows\ERDNT\AutoBackup\3-26-2009\Users\00000001\ntuser.dat
    + 2009-03-26 12:25:54 303,104 ----a-w c:\windows\ERDNT\AutoBackup\3-26-2009\Users\00000002\UsrClass.dat
    + 2009-03-26 13:25:34 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_700.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-06 68856]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
    "H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 1200128]
    "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp"="Alaunch" [X]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
    "SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2005-03-04 32768]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
    "PCMService"="c:\program files\Arcade\PCMService.exe" [2005-03-09 49152]
    "LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2005-03-28 315392]
    "eRecoveryService"="c:\windows\System32\Check.exe" [2005-03-23 245760]
    "vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-04-26 90112]
    "DiskeeperSystray"="c:\program files\Executive Software\Diskeeper\DkIcon.exe" [2004-10-04 176216]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-07-31 98304]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-11-17 1168264]
    "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-13 196608]
    "HPHmon03"="c:\windows\system32\hphmon03.exe" [2006-01-13 311296]
    "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-24 198160]
    "SoundMan"="SOUNDMAN.EXE" [2005-02-23 c:\windows\SOUNDMAN.EXE]
    "AGRSMMSG"="AGRSMMSG.exe" [2004-10-07 c:\windows\AGRSMMSG.exe]
    "SiSPower"="SiSPower.dll" [2005-02-25 c:\windows\system32\SiSPower.dll]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

    c:\documents and settings\Elaine\Start Menu\Programs\Startup\
    AOL Desktop.lnk - c:\program files\Common Files\AOL\Launch\aollaunch.exe [2008-06-24 41824]
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
    2008-10-16 20:35 87352 c:\windows\system32\LMIinit.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "MSACM.CEGSM"= mobilev.acm
    "vidc.ffds"= c:\progra~1\COMBIN~1\Filters\ff_vfw.dll
    "vidc.wmv3"= c:\progra~1\COMBIN~1\Filters\wmv9vcm.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax 4.2.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\eFax 4.2.lnk
    backup=c:\windows\pss\eFax 4.2.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
    backup=c:\windows\pss\Google Updater.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
    backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 2000 Series.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk
    backup=c:\windows\pss\hp psc 2000 Series.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
    backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
    backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
    backup=c:\windows\pss\Kodak software updater.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
    backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
    backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
    backup=c:\windows\pss\Utility Tray.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
    backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Dave^Start Menu^Programs^Startup^AOL OpenRide.lnk]
    path=c:\documents and settings\Dave\Start Menu\Programs\Startup\AOL OpenRide.lnk
    backup=c:\windows\pss\AOL OpenRide.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Dave^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=c:\documents and settings\Dave\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=c:\windows\pss\LimeWire On Startup.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Dave^Start Menu^Programs^Startup^VZAccess Manager.lnk]
    path=c:\documents and settings\Dave\Start Menu\Programs\Startup\VZAccess Manager.lnk
    backup=c:\windows\pss\VZAccess Manager.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
    --a------ 2005-06-06 23:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
    -r------- 2006-10-23 07:50 71216 c:\program files\Common Files\AOL\ACS\AOLDial.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    --a------ 2008-02-07 23:38 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
    --a------ 2005-11-15 19:44 1200128 c:\program files\Microsoft ActiveSync\wcescomm.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    --a------ 2006-02-19 02:41 49152 c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --------- 2004-10-13 12:24 1694208 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    --a------ 2006-01-12 16:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Performance Center]
    --a------ 2007-04-26 18:00 3039232 c:\program files\Ascentive\Performance Center\ApcMain.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
    --a------ 2008-08-20 21:18 443968 c:\program files\Picasa2\PicasaMediaDetector.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
    --a------ 2009-03-24 10:24 214536 c:\program files\Real\RealPlayer\realplay.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-07-06 21:03 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "gusvc"=2 (0x2)
    "GoogleDesktopManager-093007-112848"=3 (0x3)
    "WMPNetworkSvc"=3 (0x3)
    "Viewpoint Manager Service"=2 (0x2)
    "SPTISRV"=3 (0x3)
    "sdCoreService"=2 (0x2)
    "sdAuxService"=2 (0x2)
    "MSCSPTISRV"=3 (0x3)
    "LightScribeService"=2 (0x2)
    "IDriverT"=3 (0x3)
    "Diskeeper"=2 (0x2)
    "AOL TopSpeedMonitor"=2 (0x2)
    "AOL ACS"=3 (0x3)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\UT2004Demo\\System\\UT2004.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
    "c:\\Program Files\\eSignal\\winros.exe"=
    "c:\\StubInstaller.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
    "c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
    "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
    "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
    "c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
    "c:\\WINDOWS\\System32\\mmc.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqtra08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqste08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpofxm08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposfx08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hposid01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqscnvw.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqkygrp.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqCopy.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpfccopy.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpzwiz01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpoews01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\BIN\\hpqnrs08.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\REALPLAY.EXE"=
    "c:\\WINDOWS\\System32\\dpvsetup.exe"=
    "c:\\Program Files\\Common Files\\AOL\\1226720766\\ee\\aolsoftware.exe"=
    "c:\\Program Files\\Common Files\\AOL\\1226720766\\ee\\AOLDesktop.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R0 sonypvl3;sonypvl3;c:\windows\system32\drivers\sonypvl3.sys [2006-05-06 18110]
    R1 sonypvf3;sonypvf3;c:\windows\system32\drivers\sonypvf3.sys [2006-05-06 619390]
    R1 sonypvt3;sonypvt3;c:\windows\system32\drivers\sonypvt3.sys [2006-05-06 423454]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2008-07-24 12856]
    R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-02-28 47640]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
    S2 gupdate1c9ac8bbac1dd8e;Google Update Service (gupdate1c9ac8bbac1dd8e);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 133104]
    S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [2008-05-11 18864]
    S3 PLUsbbc2;USB 2.0 Networking/Data Transfer Cable;c:\windows\system32\drivers\usbbc2.sys [2008-10-18 8960]
    S3 PTDCWWAN;PANTECH PC Card WWAN Controller device driver;c:\windows\system32\drivers\PTDCWWAN.sys [2008-03-13 58240]
    S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [2008-07-24 29824]
    S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [2008-07-24 41344]
    S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [2008-07-24 39936]
    S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [2008-07-24 59776]
    S4 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2007-07-06 29744]
    S4 LMIRfsClientNP;LMIRfsClientNP; [x]
    S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-03-20 356920]
    S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-02-15 24652]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-26 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

    2008-06-13 c:\windows\Tasks\Norton Security Scan.job
    - c:\program files\Norton Security Scan\Nss.exe [2007-04-19 22:42]

    2009-03-21 c:\windows\Tasks\WebReg psc 2210.job
    - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2006-02-19 05:09]

    2009-03-26 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

    2009-03-04 c:\windows\Tasks\At1.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At2.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At3.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At4.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At5.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At6.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At7.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At8.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-04 c:\windows\Tasks\At9.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\At10.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At11.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At12.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-22 c:\windows\Tasks\At13.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At14.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At15.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-22 c:\windows\Tasks\At16.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At17.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At18.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At19.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-25 c:\windows\Tasks\At20.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\At21.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\At22.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\At23.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At24.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At25.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At26.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At27.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At28.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At29.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At30.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At31.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At32.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At33.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\At34.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At35.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At36.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-22 c:\windows\Tasks\At37.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At38.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At39.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-22 c:\windows\Tasks\At40.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At41.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At42.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-21 c:\windows\Tasks\At43.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-25 c:\windows\Tasks\At44.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\At45.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\At46.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\At47.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-24 c:\windows\Tasks\At48.job
    - c:\windows\system32\5DPtWNv3.exe [2009-03-21 17:20]

    2009-03-26 c:\windows\Tasks\GoogleUpdateTaskMachine.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 10:18]

    2006-07-11 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1136700040.job
    - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 17:56]

    2009-03-26 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 20:38]

    2009-03-22 c:\windows\Tasks\WebReg 20070323112304.job
    - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2006-02-19 05:09]
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=yie7c
    mStart Page = hxxp://www.yahoo.com
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
    IE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Elaine\Application Data\Mozilla\Firefox\Profiles\jhxocqy7.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopie7&query=
    FF - prefs.js: browser.search.selectedEngine - AOL Search
    FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffaoldesktopab&query=
    FF - component: c:\documents and settings\Elaine\Application Data\Mozilla\Firefox\Profiles\jhxocqy7.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dll
    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
    FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
    FF - plugin: c:\program files\Picasa2\npPicasa2.dll
    FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true.

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-26 09:41:14
    Windows 5.1.2600 Service Pack 2 FAT NTAPI

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(688)
    c:\windows\system32\LMIinit.dll
    .
    Completion time: 2009-03-26 9:42:30
    ComboFix-quarantined-files.txt 2009-03-26 13:42:30
    ComboFix3.txt 2009-03-24 22:28:30
    ComboFix2.txt 2009-03-26 13:18:20

    Pre-Run: 5,327,880,192 bytes free
    Post-Run: 5,313,101,824 bytes free

    450 --- E O F --- 2009-03-24 22:30:10


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:49:53 AM, on 3/26/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\keyhook.exe
    C:\Program Files\Arcade\PCMService.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\WINDOWS\system32\hphmon03.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\PROGRA~1\MICROS~4\rapimgr.exe
    C:\Program Files\Common Files\AOL\1226720766\ee\AOLDesktop.exe
    C:\Program Files\Common Files\AOL\1226720766\ee\aolsoftware.exe
    C:\Program Files\acer\eRecovery\Monitor.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx
    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn...taller_gmn.cab
    O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - http://o.aolcdn.com/pictures/ap/Reso...s.10.2.0.0.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1132986941937
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/armhelper.ocx
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Update Service (gupdate1c9ac8bbac1dd8e) (gupdate1c9ac8bbac1dd8e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 13131 bytes

  8. #8
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,067

    Default

    looks like that script didnt work for some reason. try once more.
    like before: Click Start, then Run and type Notepad and click OK.
    Copy/paste the text in the code box below into notepad etc.

    You can also update MBAM and do a scan and post that log also.
    How Can I Reduce My Risk?

  9. #9
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,485

    Default

    This topic has been closed due to inactivity.

    As it has been five days or more since your last post, and your helper posted a response to which you did not reply, this topic has been archived and will not be reopened. If you still require help, please start a new topic and include a fresh HijackThis log and a link to this thread.

    Applies only to the original poster, anyone else with similar problems please start a new topic.

    Thank you shelf life.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •