"Compaq_Administrator" - 07-02-02 20:22:32 Service Pack 2
ComboFix 07.01.31 - Running from: "C:\Documents and Settings\Compaq_Administrator\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2007-01-02 to 2007-02-02 ))))))))))))))))))))))))))))))))))
2007-02-02 15:45 45,568 --a------ C:\Program Files\Common Files\quha691.dll
2007-02-02 08:02 45,568 --a------ C:\Program Files\Common Files\quha.dll
2007-02-01 17:29 <DIR> d-------- C:\!KillBox
2007-01-31 16:47 93,564 --a------ C:\WINDOWS\TTC.exe
2007-01-30 22:19 <DIR> d-------- C:\Avenger
2007-01-28 10:15 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\Application Data\Viewpoint
2007-01-27 18:21 <DIR> d-------- C:\Program Files\Entriq
2007-01-15 19:02 <DIR> d-------- C:\Spyware
2007-01-12 08:01 <DIR> d-------- C:\Program Files\Viewpoint
2007-01-12 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Viewpoint
2007-01-12 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\AOL OCP
2007-01-12 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\AOL
2007-01-12 07:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\AOL Downloads
2007-01-09 17:00 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\Application Data\System Restore
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-02 19:06 379 --a------ C:\Program Files\Common Files\quha691
2007-02-02 15:45 -------- d-------- C:\Program Files\messenger
2007-02-02 15:45 -------- d-------- C:\DOCUME~1\COMPAQ~1\Application Data\adobeum
2007-01-28 22:28 -------- d-------- C:\Program Files\bodog poker
2007-01-23 21:06 12308 --a------ C:\DOCUME~1\COMPAQ~1\Application Data\wklnhst.dat
2007-01-12 08:00 -------- d-------- C:\DOCUME~1\COMPAQ~1\Application Data\mozilla
2007-01-12 07:55 -------- d---s---- C:\DOCUME~1\COMPAQ~1\Application Data\microsoft
2007-01-04 06:50 -------- d-------- C:\DOCUME~1\COMPAQ~1\Application Data\adobe
2007-01-02 16:22 -------- d-------- C:\Program Files\java
2006-12-28 20:25 -------- d-------- C:\Program Files\Common Files\symantec shared
2006-12-28 17:04 -------- d-------- C:\Program Files\Common Files\blizzard entertainment
2006-12-28 16:41 -------- d-------- C:\Program Files\lavasoft
2006-12-28 16:41 -------- d-------- C:\DOCUME~1\COMPAQ~1\Application Data\lavasoft
2006-12-06 22:14 2330624 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-12-02 15:21 142 --a------ C:\Program Files\Common Files\rteqe.html
2006-11-07 23:06 679424 --------- C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe"
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe AcRdB7_0_0"
"PID41IER.exe "="C:\\WINDOWS\\system32\\PID41IER.exe "
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"DiscUpdateManager"="C:\\Program Files\\DISC\\DiscUpdateMgr.exe"
"DMAScheduler"="c:\\Program Files\\Sonic\\DigitalMedia Plus\\DigitalMedia Archive\\DMAScheduler.exe"
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
@=""
"PCDrProfiler"=""
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"EntriqMediaTray"="\"C:\\Program Files\\Entriq\\MediaSphere\\EntriqMediaTray.exe\""
"nokomola"="C:\\WINDOWS\\$NtUninstallKB893756$\\nokomola.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ C:\Program Files\Common Files\rteqe.html
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{720e29cd-d9f7-11da-877f-0015f2f10a83}]
Shell\AutoRun\command J:\setupSNK.exe
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070202-080555-539
O2 - BHO: (no name) - {CDA3F57D-B88E-4928-92AD-0341AE776394} - C:\Program Files\Messenger\mevobuli.dll
backup-20070202-080555-411
O2 - BHO: (no name) - {EC3ED3B1-AAA8-4027-B42C-4460BD7BB7AB} - C:\Program Files\Messenger\mevobuli.dll
backup-20070202-080555-657
O2 - BHO: (no name) - {E8DF1257-E558-4302-A220-72FE761CDB9E} - C:\Program Files\Messenger\mevobuli.dll
backup-20070202-080554-470
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
backup-20070202-080554-847
O2 - BHO: (no name) - {8238EDBC-17BF-44F7-8BF6-EE9E28176C78} - C:\Program Files\Messenger\mevobuli.dll
backup-20070202-080554-271
O2 - BHO: (no name) - {9CD629F7-B73A-4719-862C-6C1002108B5A} - C:\Program Files\Messenger\mevobuli.dll
backup-20070202-080554-367
O2 - BHO: (no name) - {89FAC2C8-02A6-4F5D-BB50-4B29E26068D9} - C:\Program Files\Messenger\mevobuli.dll
backup-20070202-080554-181
O2 - BHO: (no name) - {8CC77AE9-6B94-45C6-89DD-1110FB663EBF} - C:\Program Files\Messenger\mevobuli.dll
backup-20070202-080554-943
O2 - BHO: (no name) - {81B2CFBC-BDF6-4E03-9F54-AED5819A74A4} - C:\Program Files\Messenger\mevobuli.dll
backup-20070201-172844-879
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} -
http://drivecleaner.com/.freeware/installdrivecleanerstart.cab
backup-20070201-172844-273
O2 - BHO: 0 - {B2025671-3F42-4C11-CF8E-9AAC63E7180E} - C:\Program Files\Common Files\quha.dll
backup-20070115-184619-453
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
backup-20070112-175953-964
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
backup-20070112-175953-723
O15 - Trusted Zone:
http://*.trymedia.com (HKLM)
backup-20070112-175831-173
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
backup-20070112-175831-751
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
backup-20070112-175831-697
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
backup-20070112-175831-682
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
backup-20070112-175831-436
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
backup-20070112-175831-946
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
backup-20070112-175649-484
O2 - BHO: 0 - {0463234D-D25E-4FA0-C186-5421DF169C54} - C:\Program Files\Common Files\quha.dll
backup-20070112-175629-938
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
backup-20070112-175629-927
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
backup-20070112-175629-718
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
backup-20070112-175629-113
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
backup-20070109-210827-611
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} -
http://apps.deskwizz.com/ax/adwerkz.cab
backup-20070109-210827-937
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} -
http://drivecleaner.com/.freeware/installdrivecleanerstart.cab
backup-20070109-210723-251
O4 - HKCU\..\Run: [PID41IER.exe ] C:\WINDOWS\system32\PID41IER.exe
backup-20070109-210723-333
O4 - HKLM\..\Run: [wasa] C:\WINDOWS\$NtUninstallKB898461$\wasa.exe
Completion time: 07-02-02 20:24:14