I was able to update all the programs. couldn't run the ATF after download though..
below are the logs
kas.txt, dds, combofix
ComboFix 09-09-04.02 - Brian Y 05/09/2009 9:35.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.141 [GMT -6:00]
Running from: c:\documents and settings\Brian Y\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Brian Y\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"c:\windows\system32\ESQULzxspectrum"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Brian Y\Application Data\uTorrent
c:\documents and settings\Brian Y\Application Data\uTorrent\'mininova.org` Le Code Da Vinci [DVD-RIP].torrent
c:\documents and settings\Brian Y\Application Data\uTorrent\'mininova.org` Modern.Marvels._.More.Of.The.World__s.Biggest.Machines.Wendal._www.the_realworld.de_.avi.torrent
c:\documents and settings\Brian Y\Application Data\uTorrent\-(mininova.org)- Modern Marvels - Dangerous cargo.avi.torrent
c:\documents and settings\Brian Y\Application Data\uTorrent\-(mininova.org)- Modern.Marvels._.More.Of.The.World__s.Biggest.Machines.Wendal._www.the_realworld.de_.avi.torrent
[Eng] DVDSCR.AC3.NO.Logo&Timer.DivX-LTT.torrent
c:\documents and settings\Brian Y\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Brian Y\Application Data\uTorrent\utt1A.tmp
c:\documents and settings\Brian Y\Application Data\uTorrent\utt1B.tmp
c:\documents and settings\Brian Y\Application Data\uTorrent\utt27.tmp
c:\documents and settings\Brian Y\Application Data\uTorrent\utt37.tmp
c:\documents and settings\Brian Y\Application Data\uTorrent\You_Are_My_Solskjaer_-_Ole_Gunnar_Solskjaer-'s_Manchester_United_Goals_From_MUTV.avi.torrent
c:\program files\limewire
c:\program files\limewire\clink.jar
c:\program files\limewire\commons-httpclient.jar
c:\program files\limewire\commons-logging.jar
c:\program files\limewire\daap.jar
c:\program files\limewire\GenericWindowsUtils.dll
c:\program files\limewire\i18n.jar
c:\program files\limewire\icu4j.jar
c:\program files\limewire\id3v2.jar
c:\program files\limewire\jcraft.jar
c:\program files\limewire\jl011.jar
c:\program files\limewire\jmdns.jar
c:\program files\limewire\LimeWire.exe
c:\program files\limewire\LimeWire.jar
c:\program files\limewire\LimeWire20.dll
c:\program files\limewire\logicrypto.jar
c:\program files\limewire\looks.jar
c:\program files\limewire\MessagesBundles.jar
c:\program files\limewire\mp3sp14.jar
c:\program files\limewire\ProgressTabs.jar
c:\program files\limewire\themes.jar
c:\program files\limewire\tritonus.jar
c:\program files\limewire\vorbis.jar
c:\program files\limewire\WindowsV5PlusUtils.dll
c:\program files\limewire\xerces.jar
c:\program files\limewire\xml-apis.jar
c:\windows\system32\ESQULzxspectrum
.
((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 )))))))))))))))))))))))))))))))
.
2009-08-31 03:52 . 2008-06-19 23:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-08-31 03:51 . 2009-08-31 03:51 -------- d-----w- c:\program files\Panda Security
2009-08-31 00:01 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-08-30 22:44 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-30 22:44 . 2009-08-30 22:44 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-30 22:43 . 2009-08-30 22:43 -------- d-----w- c:\program files\Lavasoft
2009-08-30 22:43 . 2009-08-30 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-30 15:05 . 2009-08-30 15:05 -------- d-----w- c:\documents and settings\Brian Y\Application Data\WinPatrol
2009-08-30 15:04 . 2009-08-30 15:04 -------- d-----w- c:\program files\BillP Studios
2009-08-30 03:32 . 2009-08-30 03:32 -------- d-----w- c:\program files\Trend Micro
2009-08-30 03:23 . 2009-08-30 03:24 -------- d-----w- c:\program files\ERUNT
2009-08-30 02:48 . 2009-08-03 19:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-30 02:48 . 2009-08-03 19:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-30 00:33 . 2009-08-30 02:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-30 00:33 . 2009-08-30 00:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-29 23:53 . 2009-08-30 01:06 -------- d-----w- c:\program files\Anti-Virus&Spyware
2009-08-17 16:34 . 2009-08-17 19:50 -------- d--h--w- C:\$AVG8.VAULT$
2009-08-17 15:58 . 2009-08-17 15:58 -------- d-----w- c:\documents and settings\Brian Y\Local Settings\Application Data\AVG Security Toolbar
2009-08-17 15:50 . 2009-08-17 15:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-17 15:50 . 2009-08-17 15:50 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-17 15:50 . 2009-08-17 15:50 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-17 15:50 . 2009-08-17 15:50 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-17 15:49 . 2009-09-05 14:52 -------- d-----w- c:\windows\system32\drivers\Avg
2009-08-17 15:49 . 2009-08-19 14:23 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-17 15:49 . 2009-08-17 15:49 -------- d-----w- c:\program files\AVG
2009-08-17 15:49 . 2009-09-05 15:30 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-17 15:40 . 2009-08-17 15:40 -------- d-----w- c:\documents and settings\Brian Y\Application Data\AVG8
2009-08-17 14:13 . 2009-08-17 14:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-30 14:30 . 2006-07-21 04:11 -------- d-----w- c:\program files\Passware
2009-08-20 21:10 . 2007-05-28 22:20 -------- d-----w- c:\program files\Apple Software Update
2009-08-17 22:40 . 2008-01-06 19:24 -------- d-----w- c:\program files\PC Doc Pro
2009-08-17 14:10 . 2005-03-09 00:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-17 14:10 . 2005-03-09 00:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-25 18:09 . 2005-05-04 15:52 -------- d-----w- c:\documents and settings\Brian Y\Application Data\Skype
2005-11-18 01:18 . 2005-11-18 01:18 774144 -c--a-w- c:\program files\RngInterstitial.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-05_00.41.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-01-29 08:58 . 2008-10-23 10:06 62976 c:\windows\system32\tzchange.exe
- 2007-10-27 02:59 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
+ 2007-10-27 02:59 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 44544 c:\windows\system32\pngfilt.dll
+ 2006-11-08 04:03 . 2008-10-16 20:38 52224 c:\windows\system32\msfeedsbs.dll
- 2006-11-08 04:03 . 2008-08-26 07:24 52224 c:\windows\system32\msfeedsbs.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 27648 c:\windows\system32\jsproxy.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 27648 c:\windows\system32\jsproxy.dll
- 2006-11-07 10:26 . 2008-08-25 08:38 13824 c:\windows\system32\ieudinit.exe
+ 2006-11-07 10:26 . 2008-10-16 13:11 13824 c:\windows\system32\ieudinit.exe
- 2004-08-04 08:00 . 2008-08-26 07:24 44544 c:\windows\system32\iernonce.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 44544 c:\windows\system32\iernonce.dll
- 2004-08-04 08:00 . 2008-08-25 08:37 70656 c:\windows\system32\ie4uinit.exe
+ 2004-08-04 08:00 . 2008-10-16 13:11 70656 c:\windows\system32\ie4uinit.exe
+ 2006-10-17 18:58 . 2008-10-16 20:38 63488 c:\windows\system32\icardie.dll
- 2006-10-17 18:58 . 2008-08-26 07:24 63488 c:\windows\system32\icardie.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2006-05-10 05:23 . 2008-08-26 07:24 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2007-05-09 18:03 . 2008-08-26 07:24 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-05-09 18:03 . 2008-10-16 20:38 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2006-05-10 05:22 . 2008-08-26 07:24 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:22 . 2008-10-16 20:38 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2007-05-09 18:03 . 2008-10-16 13:11 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2007-05-09 18:03 . 2008-08-25 08:38 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2006-11-07 10:26 . 2008-08-26 07:24 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2006-11-07 10:26 . 2008-10-16 20:38 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2006-11-07 10:26 . 2008-10-16 13:11 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2006-11-07 10:26 . 2008-08-25 08:37 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-20 10:04 . 2008-10-16 20:38 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-08-20 10:04 . 2008-08-26 07:24 63488 c:\windows\system32\dllcache\icardie.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 44544 c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 52224 c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 27648 c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2009-09-05 02:13 . 2008-08-25 08:38 13824 c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2009-09-05 02:13 . 2008-08-26 07:24 44544 c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2009-09-05 02:13 . 2008-08-25 08:37 70656 c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2009-09-05 02:13 . 2008-08-26 07:24 63488 c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2004-08-04 08:00 . 2008-06-18 11:03 938496 c:\windows\system32\WMNetmgr.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 826368 c:\windows\system32\wininet.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 826368 c:\windows\system32\wininet.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 233472 c:\windows\system32\webcheck.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 233472 c:\windows\system32\webcheck.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 105984 c:\windows\system32\url.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 105984 c:\windows\system32\url.dll
+ 2004-08-04 08:00 . 2008-10-03 10:02 247326 c:\windows\system32\strmdll.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 102912 c:\windows\system32\occache.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 102912 c:\windows\system32\occache.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 671232 c:\windows\system32\mstime.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 671232 c:\windows\system32\mstime.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 193024 c:\windows\system32\msrating.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 193024 c:\windows\system32\msrating.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 477696 c:\windows\system32\mshtmled.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 477696 c:\windows\system32\mshtmled.dll
- 2006-11-08 04:03 . 2008-08-26 07:24 459264 c:\windows\system32\msfeeds.dll
+ 2006-11-08 04:03 . 2008-10-16 20:38 459264 c:\windows\system32\msfeeds.dll
- 2004-08-04 08:00 . 2006-10-19 02:03 100864 c:\windows\system32\logagent.exe
+ 2004-08-04 08:00 . 2008-06-18 07:09 100864 c:\windows\system32\logagent.exe
- 2006-10-17 18:57 . 2008-08-26 07:24 267776 c:\windows\system32\iertutil.dll
+ 2006-10-17 18:57 . 2008-10-16 20:38 267776 c:\windows\system32\iertutil.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 384512 c:\windows\system32\iedkcs32.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 384512 c:\windows\system32\iedkcs32.dll
+ 2006-10-17 18:27 . 2008-10-16 20:38 383488 c:\windows\system32\ieapfltr.dll
- 2006-10-17 18:27 . 2008-08-26 07:24 383488 c:\windows\system32\ieapfltr.dll
+ 2004-08-04 08:00 . 2008-10-15 07:04 161792 c:\windows\system32\ieakui.dll
- 2004-08-04 08:00 . 2008-08-23 05:54 161792 c:\windows\system32\ieakui.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 230400 c:\windows\system32\ieaksie.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 153088 c:\windows\system32\ieakeng.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-04 08:00 . 2008-10-23 12:36 286720 c:\windows\system32\gdi32.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 133120 c:\windows\system32\extmgr.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 133120 c:\windows\system32\extmgr.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 214528 c:\windows\system32\dxtrans.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 347136 c:\windows\system32\dxtmsft.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-04 08:00 . 2008-06-18 11:03 938496 c:\windows\system32\dllcache\WMNetmgr.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 826368 c:\windows\system32\dllcache\wininet.dll
- 2006-05-10 05:23 . 2008-08-26 07:24 826368 c:\windows\system32\dllcache\wininet.dll
- 2006-11-08 04:03 . 2008-08-26 07:24 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2006-11-08 04:03 . 2008-10-16 20:38 233472 c:\windows\system32\dllcache\webcheck.dll
- 2006-10-17 19:05 . 2008-08-26 07:24 105984 c:\windows\system32\dllcache\url.dll
+ 2006-10-17 19:05 . 2008-10-16 20:38 105984 c:\windows\system32\dllcache\url.dll
+ 2006-08-21 16:52 . 2008-10-03 10:02 247326 c:\windows\system32\dllcache\strmdll.dll
- 2006-10-17 19:04 . 2008-08-26 07:24 102912 c:\windows\system32\dllcache\occache.dll
+ 2006-10-17 19:04 . 2008-10-16 20:38 102912 c:\windows\system32\dllcache\occache.dll
- 2006-05-10 05:23 . 2008-08-26 07:24 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-05-10 05:23 . 2008-08-26 07:24 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-05-10 05:23 . 2008-08-26 07:24 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-05-09 18:03 . 2008-10-16 20:38 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2007-05-09 18:03 . 2008-08-26 07:24 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2004-08-04 08:00 . 2006-10-19 02:03 100864 c:\windows\system32\dllcache\logagent.exe
+ 2004-08-04 08:00 . 2008-06-18 07:09 100864 c:\windows\system32\dllcache\logagent.exe
+ 2006-10-17 19:04 . 2008-10-15 07:06 633632 c:\windows\system32\dllcache\iexplore.exe
+ 2007-05-09 18:03 . 2008-10-16 20:38 267776 c:\windows\system32\dllcache\iertutil.dll
- 2007-05-09 18:03 . 2008-08-26 07:24 267776 c:\windows\system32\dllcache\iertutil.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 384512 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 384512 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-05-09 18:03 . 2008-08-26 07:24 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-05-09 18:03 . 2008-10-16 20:38 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2006-11-07 10:25 . 2008-10-15 07:04 161792 c:\windows\system32\dllcache\ieakui.dll
- 2006-11-07 10:25 . 2008-08-23 05:54 161792 c:\windows\system32\dllcache\ieakui.dll
- 2006-11-07 10:27 . 2008-08-26 07:24 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-11-07 10:27 . 2008-10-16 20:38 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-11-07 10:26 . 2008-10-16 20:38 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2006-11-07 10:26 . 2008-08-26 07:24 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-23 12:36 . 2008-10-23 12:36 286720 c:\windows\system32\dllcache\gdi32.dll
- 2006-05-10 05:22 . 2008-08-26 07:24 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-05-10 05:22 . 2008-10-16 20:38 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-05-10 05:22 . 2008-10-16 20:38 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-05-10 05:22 . 2008-08-26 07:24 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-05-10 05:22 . 2008-10-16 20:38 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2006-05-10 05:22 . 2008-08-26 07:24 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-11-07 10:26 . 2008-10-16 20:38 124928 c:\windows\system32\dllcache\advpack.dll
- 2006-11-07 10:26 . 2008-08-26 07:24 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 124928 c:\windows\system32\advpack.dll
- 2004-08-04 08:00 . 2008-08-26 07:24 124928 c:\windows\system32\advpack.dll
+ 2009-09-05 02:08 . 2007-03-06 01:23 371424 c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
+ 2009-09-05 02:08 . 2007-03-06 01:22 213216 c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2009-09-05 02:13 . 2008-08-26 07:24 826368 c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 233472 c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 105984 c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2009-09-05 02:13 . 2007-03-06 01:23 371424 c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2009-09-05 02:13 . 2007-03-06 01:22 213216 c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2009-09-05 02:13 . 2008-08-26 07:24 102912 c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 671232 c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 193024 c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 477696 c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 459264 c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2009-09-05 02:13 . 2008-08-23 05:56 635848 c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2009-09-05 02:13 . 2008-08-26 07:24 267776 c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 384512 c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 383488 c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2009-09-05 02:13 . 2008-08-23 05:54 161792 c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 230400 c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 153088 c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 133120 c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 214528 c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 347136 c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 124928 c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2004-08-04 08:00 . 2008-06-18 11:03 2458112 c:\windows\system32\WMVCore.dll
+ 2004-08-04 08:00 . 2008-10-16 20:38 1160192 c:\windows\system32\urlmon.dll
+ 2004-08-04 08:00 . 2008-12-13 06:40 3593216 c:\windows\system32\mshtml.dll
- 2004-08-04 08:00 . 2008-08-27 08:24 3593216 c:\windows\system32\mshtml.dll
+ 2006-11-08 04:03 . 2008-10-16 20:38 6066176 c:\windows\system32\ieframe.dll
- 2006-11-08 04:03 . 2008-10-03 17:41 6066176 c:\windows\system32\ieframe.dll
+ 2004-08-04 08:00 . 2008-06-18 11:03 2458112 c:\windows\system32\dllcache\WMVCore.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-19 15:08 . 2008-12-13 06:40 3593216 c:\windows\system32\dllcache\mshtml.dll
- 2006-05-19 15:08 . 2008-08-27 08:24 3593216 c:\windows\system32\dllcache\mshtml.dll
+ 2007-05-09 18:03 . 2008-10-16 20:38 6066176 c:\windows\system32\dllcache\ieframe.dll
- 2007-05-09 18:03 . 2008-10-03 17:41 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2009-09-05 02:08 . 2008-08-27 08:24 3593216 c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2009-09-05 02:13 . 2008-08-26 07:24 1159680 c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2009-09-05 02:13 . 2008-10-03 17:41 6066176 c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2005-05-18 22:50 . 2008-12-09 23:24 17593280 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-26 68856]
"Google Update"="c:\documents and settings\Brian Y\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-15 133104]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-10-08 159744]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-03-01 200766]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-26 335872]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-08-19 290816]
"USB Storage Toolbox"="c:\program files\USBToolbox\Res.EXE" [2004-11-13 122880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-17 2007832]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-07-27 341312]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-08-24 88363]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672]
c:\documents and settings\Brian Y\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-9-25 25214]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-17 15:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"matlabserver"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\Brian Y\\My Documents\\My Documents1\\My Received Files\\Various files\\Install files\\utorrent.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Time Zone Clock V2.0\\Time Zone Clock.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Brian Y\\My Documents\\earth station\\ES5.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Brian Y\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\TightVNC\\WinVNC.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Documents and Settings\\Brian Y\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Brian Y\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2844:TCP"= 2844:TCP

pLive
"5609:UDP"= 5609:UDP

pLive
"5072:TCP"= 5072:TCP

pLive
"3461:UDP"= 3461:UDP

pLive
"4323:TCP"= 4323:TCP

pLive
"4262:UDP"= 4262:UDP

pLive
"5800:TCP"= 5800:TCP:VNC browser viewer
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [18/11/2004 10:42 PM 5632]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [30/08/2009 4:44 PM 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [30/08/2009 9:52 PM 28544]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [17/08/2009 9:50 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [17/08/2009 9:50 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [17/08/2009 9:49 AM 297752]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 8:49 AM 1029456]
S2 pciinfo;HP Pci Information;\??\c:\docume~1\BRIANY~1\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys --> c:\docume~1\BRIANY~1\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [?]
S3 MemStPCI;Sony Memory Stick controller (PCI);c:\windows\system32\drivers\memstpci.sys [15/06/2006 7:15 PM 26112]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2009-08-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2009-08-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 21:42]
2009-09-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3387010834-4065263752-808451065-1006Core.job
- c:\documents and settings\Brian Y\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-15 04:13]
2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3387010834-4065263752-808451065-1006UA.job
- c:\documents and settings\Brian Y\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-15 04:13]
.
.
------- Supplementary Scan -------
.
uStart Page =
https://www.google.com/accounts/Ser...mail/?ui=html&zy=l<mpl=default<mplcache=2
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} - hxxp://download.ppstream.com/bin/powerplayer.cab
FF - ProfilePath - c:\documents and settings\Brian Y\Application Data\Mozilla\Firefox\Profiles\4hi6cmi0.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fgmail.google.com%2Fgmail%3Fui%3Dhtml%26zy%3Dl&hl=en
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Brian Y\Application Data\Mozilla\Firefox\Profiles\4hi6cmi0.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\Brian Y\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Brian Y\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPinfotl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-05 09:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????2?6?3?7??`???? ???B???????????????B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(856)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-09-05 9:54
ComboFix-quarantined-files.txt 2009-09-05 15:53
ComboFix2.txt 2009-09-05 01:02
Pre-Run: 5,765,427,200 bytes free
Post-Run: 5,768,364,032 bytes free
527 --- E O F --- 2009-09-05 02:14
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, September 5, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, September 05, 2009 20:10:01
Records in database: 2750142
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Objects scanned: 67811
Threats found: 8
Infected objects found: 10
Suspicious objects found: 0
Scan duration: 02:46:45
File name / Threat / Threats count
C:\Documents and Settings\Brian Y\Desktop\tightvnc-1.3.9-setup.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1370 1
C:\Documents and Settings\Brian Y\My Documents\Downloads\Programs\p2ptvrecorderv1.63keygenexplosion.zip Infected: Trojan.Win32.Genome.psj 1
C:\Documents and Settings\Brian Y\My Documents\Downloads\rvnc2_cl.rar Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.427 1
C:\Documents and Settings\Brian Y\My Documents\My Documents1\My Received Files\Various files\Install files\Pwd restore tools\Relevation\Revelation.exe Infected: not-a-virus

SWTool.Win32.SnadBoy.2011 1
C:\Documents and Settings\Brian Y\My Documents\My Documents1\My Received Files\Various files\Install files\Pwd restore tools\Relevation\RevelationHelper.dll Infected: not-a-virus

SWTool.Win32.SnadBoy.2011 1
C:\Program Files\RealVNC\VNC4\vncclipboard.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.427 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ESQULqjxvkowxdkfyblrstjcfqxyirwhspiew.sys.vir Infected: Trojan.Win32.TDSS.aodp 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ESQULilasftlwhxvmpqxwnkoeptnboxqddkbu.dll.vir Infected: Trojan-Downloader.Win32.Agent.clvx 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ESQULlqbuvoyrgxguimpmeiilqqoddemserrr.dll.vir Infected: Trojan.Win32.Tdss.apoy 1
C:\WINDOWS\Downloaded Installations\{448A5AAF-26A0-4574-B76E-6C4166145AB1}\Recruit.msi Infected: not-a-virus:Client-IRC.Win32.mIRC.614 1
Selected area has been scanned.
DDS (Ver_09-07-30.01) - NTFSx86
Run by Brian Y at 19:05:10.23 on 04/09/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.104 [GMT -6:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\USBToolbox\Res.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Brian Y\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page =
https://www.google.com/accounts/Ser...mail/?ui=html&zy=l<mpl=default<mplcache=2
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
uRun: [googletalk] "c:\program files\google\google talk\googletalk.exe" /autostart
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Google Update] "c:\documents and settings\brian y\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\acrobat\AdobeUpdateManager.exe" AcPro7_0_9 -reboot 1
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [USB Storage Toolbox] c:\program files\usbtoolbox\Res.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
StartupFolder: c:\docume~1\briany~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL
DPF: McAfee Wi-FiScan - hxxp://download.mcafee.com/molbin/iss-loc/mwfs/3.1.0.0/WscWlanScannerCtrl.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} - hxxp://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} - hxxp://download.ppstream.com/bin/powerplayer.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5247/mcfscan.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\briany~1\applic~1\mozilla\firefox\profiles\4hi6cmi0.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fgmail.google.com%2Fgmail%3Fui%3Dhtml%26zy%3Dl&hl=en
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\brian y\application data\mozilla\firefox\profiles\4hi6cmi0.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\brian y\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\brian y\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPinfotl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2004-11-18 5632]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-30 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-8-30 28544]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-17 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-8-17 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-17 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-17 297752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
S2 pciinfo;HP Pci Information;\??\c:\docume~1\briany~1\locals~1\temp\hpispz\hpdom\pciinfo.sys --> c:\docume~1\briany~1\locals~1\temp\hpispz\hpdom\pciinfo.sys [?]
S3 MemStPCI;Sony Memory Stick controller (PCI);c:\windows\system32\drivers\memstpci.sys [2006-6-15 26112]
=============== Created Last 30 ================
2009-09-04 18:53 <DIR> --d----- c:\windows\system32\dllcache\cache
2009-09-04 18:00 <DIR> a-dshr-- C:\cmdcons
2009-09-04 17:57 230,912 a------- c:\windows\PEV.exe
2009-09-04 17:57 161,792 a------- c:\windows\SWREG.exe
2009-09-04 17:57 98,816 a------- c:\windows\sed.exe
2009-08-30 21:52 28,544 a------- c:\windows\system32\drivers\pavboot.sys
2009-08-30 21:51 <DIR> --d----- c:\program files\Panda Security
2009-08-30 18:01 15,688 a------- c:\windows\system32\lsdelete.exe
2009-08-30 16:44 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-08-30 16:44 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-30 16:43 <DIR> --d----- c:\program files\Lavasoft
2009-08-30 09:05 <DIR> --d----- c:\docume~1\briany~1\applic~1\WinPatrol
2009-08-30 09:04 <DIR> --d----- c:\program files\BillP Studios
2009-08-29 21:32 <DIR> --d----- c:\program files\Trend Micro
2009-08-29 20:48 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-29 20:48 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-29 18:33 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-29 18:33 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-29 17:53 <DIR> --d----- c:\program files\Anti-Virus&Spyware
2009-08-17 10:34 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-08-17 09:50 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-08-17 09:50 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-08-17 09:50 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
2009-08-17 09:49 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-08-17 09:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2009-08-17 09:49 <DIR> --d----- c:\program files\AVG
2009-08-17 09:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2009-08-17 09:40 <DIR> --d----- c:\docume~1\briany~1\applic~1\AVG8
2009-08-16 11:51 4 a------- c:\windows\system32\ESQULzxspectrum
==================== Find3M ====================
2006-03-14 14:31 21,376 a------- c:\windows\inf\hopperp.sys
2005-11-17 19:18 774,144 ac------ c:\program files\RngInterstitial.dll
============= FINISH: 19:06:43.15 ===============