Virtumode infection

PKalico

New member
Here is my Hijack this log. I ran the Kaspersky but the log was too long to post. Before I created an account to post I looked over other posts and ran the combofix first so I don't know how this has affected the problem I was having. After logging in and reading the "Before You Post" thread I did everything it recommended which has gotten me to this point. I haven't noticed anymore pop-ups opening on me since I did everything but I just want to make sure I am clean of this stupid thing. Looking forward to your help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:34 AM, on 1/21/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Peggle/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-trial-mind-medley/gamehouseplayer.cab
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {C9D7D239-B502-48B3-BA25-9DF8C7264073} (CCAWebLogin Control) - https://199.5.206.34/auth/CCALogin.CAB
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Peggle/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 13920 bytes
 
Hi

You shouldn't have run Combofix until we asked you to, but as you have, then that is the log we need to see.

Also the Kaspersky log will have a header like this :-

Scan Statistics:
Total number of scanned objects: 60605
Number of viruses found: 7
Number of infected objects: 33
Number of suspicious objects: 0

If you search the log for all instances of the word infected then just post those lines, that's all we need to see,

Your hijackthis log is clean

steam
 
The logs are from before I ran the HJT. I am posting the results that I received. If you would you like new ones let me know.

ComboFix 08-01-20.1 - odcustomer 2008-01-20 20:29:03.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.998 [GMT -5:00]
Running from: C:\Users\odcustomer\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\system32\ddccbbc.dll
C:\Windows\system32\fvcpbmei.dll
C:\Windows\system32\gebbbcc.dll
C:\Windows\System32\iembpcvf.ini
C:\Windows\system32\qomno.dll
C:\Windows\System32\ruvut.ini
C:\Windows\System32\ruvut.ini2
C:\Windows\system32\tuvur.dll
C:\Windows\system32\x64
H:\Autorun.inf

----- Unknown downloads made by BITS: ----
http://epg.tvdownload.microsoft.com
.
((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-20 20:23 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-20 20:07 . 2008-01-20 20:07 88 --a------ C:\Windows\wininit.ini
2008-01-20 17:25 . 2008-01-20 20:02 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-20 17:25 . 2008-01-20 20:02 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-01-19 21:39 . 2008-01-19 21:39 <DIR> d-------- C:\Users\All Users\Yahoo! Companion
2008-01-19 21:39 . 2008-01-19 21:39 <DIR> d-------- C:\ProgramData\Yahoo! Companion
2008-01-19 12:39 . 2008-01-19 12:39 23,040 --a------ C:\Windows\System32\winnzy32.dll
2008-01-19 12:37 . 2008-01-19 12:37 <DIR> d-------- C:\Users\All Users\Macrovision
2008-01-19 12:37 . 2008-01-19 12:37 <DIR> d-------- C:\ProgramData\Macrovision
2008-01-19 12:36 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
2008-01-19 12:36 . 2003-07-30 18:28 974,848 --a------ C:\Windows\System32\mfc70.dll
2008-01-19 12:36 . 2003-07-30 18:28 487,424 --a------ C:\Windows\System32\msvcp70.dll
2008-01-19 12:36 . 2003-07-30 18:28 344,064 --a------ C:\Windows\System32\msvcr70.dll
2008-01-19 12:35 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-01-19 12:32 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Macromedia
2008-01-19 12:05 . 2008-01-20 08:26 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\LimeWire
2008-01-19 12:03 . 2008-01-19 12:03 <DIR> d-------- C:\Program Files\LimeWire
2008-01-13 16:26 . 2008-01-13 16:26 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-13 16:26 . 2008-01-13 16:26 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-13 16:26 . 2008-01-13 16:26 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-13 16:26 . 2008-01-13 16:26 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-13 16:26 . 2008-01-13 16:26 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-13 16:26 . 2008-01-13 16:26 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-13 16:26 . 2008-01-13 16:26 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-13 16:26 . 2008-01-13 16:26 25,656 --a------ C:\Windows\System32\drivers\msahci.sys
2008-01-13 16:26 . 2008-01-13 16:26 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-13 16:26 . 2008-01-13 16:26 17,464 --a------ C:\Windows\System32\drivers\intelide.sys
2008-01-09 03:02 . 2008-01-09 03:02 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-09 03:02 . 2008-01-09 03:02 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-09 03:02 . 2008-01-09 03:02 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-09 03:02 . 2008-01-09 03:02 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-09 03:02 . 2008-01-09 03:02 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-09 03:01 . 2008-01-09 03:01 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-01-01 22:59 . 2008-01-01 22:59 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\MechCAD
2008-01-01 22:59 . 2008-01-01 23:16 <DIR> d-------- C:\Program Files\AceMoney
2007-12-31 10:33 . 2007-12-31 10:33 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\.purple
2007-12-31 10:31 . 2008-01-01 09:50 <DIR> d-------- C:\Program Files\Pidgin
2007-12-31 10:30 . 2007-12-31 10:30 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-12-30 15:54 . 2007-12-30 16:04 <DIR> d-------- C:\Program Files\BearFlix Applications
2007-12-30 15:53 . 2007-12-30 16:04 <DIR> d-------- C:\Program Files\BearFlix
2007-12-30 14:07 . 2007-10-18 08:51 172,032 --a------ C:\Windows\System32\igfxres.dll
2007-12-27 10:13 . 2008-01-20 20:40 373,392,862 --a------ C:\Windows\MEMORY.DMP
2007-12-26 23:10 . 2007-12-26 23:10 364,544 --a------ C:\Windows\System32\WDBtnMgr.exe
2007-12-26 23:08 . 2007-12-26 23:08 <DIR> d-------- C:\Program Files\Western Digital Technologies
2007-12-26 22:49 . 2008-01-19 12:44 <DIR> d-------- C:\Program Files\StorageSync
2007-12-22 11:23 . 2007-12-22 11:23 <DIR> d-------- C:\Users\All Users\LightScribe
2007-12-22 11:23 . 2007-12-22 11:23 <DIR> d-------- C:\ProgramData\LightScribe
2007-12-22 11:07 . 2007-12-22 11:09 <DIR> d--h----- C:\Windows\msdownld.tmp
2007-12-22 11:05 . 2007-12-22 11:05 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2007-12-22 10:58 . 2007-12-31 10:40 <DIR> d-------- C:\Program Files\Free WMA to MP3 Converter
2007-12-22 10:32 . 2007-12-22 10:33 <DIR> d-------- C:\Users\Ryan\AppData\Roaming\Roxio

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 01:29 --------- d-----w C:\Program Files\MSN Messenger
2008-01-20 23:58 --------- d-----w C:\ProgramData\Symantec
2008-01-20 15:58 --------- d-----w C:\ProgramData\Google Updater
2008-01-20 02:40 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Yahoo!
2008-01-20 02:36 --------- d-----w C:\ProgramData\Yahoo!
2008-01-20 02:36 --------- d-----w C:\Program Files\Yahoo!
2008-01-19 23:00 --------- d-----w C:\ProgramData\Roxio
2008-01-19 23:00 --------- d-----w C:\Program Files\Roxio
2008-01-19 22:59 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-01-19 22:53 --------- d-----w C:\ProgramData\Lavasoft
2008-01-19 17:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-19 17:24 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-13 22:29 --------- d-----w C:\Program Files\Windows Mail
2008-01-13 21:26 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-13 21:26 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-13 21:26 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-13 21:26 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-09 08:01 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-06 14:53 --------- d-----w C:\Users\Ryan\AppData\Roaming\HP
2007-12-31 15:34 206 ----a-w C:\Users\odcustomer\AppData\Roaming\wklnhst.dat
2007-12-31 15:33 --------- d-----w C:\Users\odcustomer\AppData\Roaming\.purple
2007-12-29 16:45 --------- d-----w C:\Program Files\Windows Defender
2007-12-29 16:45 --------- d-----w C:\Program Files\Windows Calendar
2007-12-29 16:14 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-12-29 16:14 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-12-29 16:14 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-12-29 16:14 2,923,520 ----a-w C:\Windows\explorer.exe
2007-12-29 16:14 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-12-29 16:14 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys
2007-12-22 23:40 --------- d-----w C:\Program Files\Norton Internet Security
2007-12-16 04:07 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Template
2007-12-16 04:01 --------- d-----w C:\Users\odcustomer\AppData\Roaming\InstallShield
2007-12-14 22:12 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-14 21:59 --------- d-----w C:\Program Files\Common Files\LightScribe
2007-12-14 21:52 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Hewlett-Packard
2007-12-14 21:42 0 --sha-r C:\Windows\system32\drivers\103C_HP_cNB_Pavilion dv6000 (GA378UA#ABA)_Y5335KV_0U_QCNF72858F5_E447502-001_4A_I30BB_SQuanta_V66.40_F.29_T071113_WV3-0_L409_M2038_J160_7Intel_86EC_92.00_#070809_N80861092;80864222_(GA378UA#ABA)_XMOBILE_CN10_Z.MRK
2007-12-14 02:42 --------- d-----w C:\Users\Ryan\AppData\Roaming\Symantec
2007-12-14 02:42 --------- d-----w C:\Users\Ryan\AppData\Roaming\MySpace
2007-12-12 21:40 174 --sha-w C:\Program Files\desktop.ini
2007-12-12 03:01 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2007-12-12 03:01 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2007-12-12 03:01 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2007-12-12 03:01 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2007-12-12 03:01 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2007-12-12 02:53 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-12-12 02:53 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-12-12 02:53 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-12-12 02:53 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2007-12-12 02:53 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-12-12 02:53 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-12-12 02:53 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-12 02:51 82,432 ----a-w C:\Windows\system32\drivers\sdbus.sys
2007-12-12 02:45 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 02:44 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2007-12-12 02:36 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-12 02:36 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-12 02:36 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-12 02:36 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 02:33 --------- d-----w C:\Program Files\CONEXANT
2007-12-08 19:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-08 14:43 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2007-12-08 14:43 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2007-12-08 14:43 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2007-12-08 14:43 --------- d-----w C:\Program Files\Symantec
2007-12-01 04:57 43,696 ----a-w C:\Windows\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 ----a-w C:\Windows\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 ----a-w C:\Windows\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 ----a-w C:\Windows\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 ----a-w C:\Windows\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 ----a-w C:\Windows\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 ----a-w C:\Windows\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 ----a-w C:\Windows\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 ----a-w C:\Windows\system32\drivers\srtsp.inf
2007-11-28 04:53 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Symantec
2007-11-27 01:44 --------- d-----w C:\ProgramData\GameHouse
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 22:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2007-11-27 23:50 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 22:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 03:01 1232896]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [ ]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-29 11:14 1006264]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [ ]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 13:38 159744]
"HP Health Check Scheduler"="[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [ ]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 15:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 18:12 317128]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [ ]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [ ]
"StrgSync.exe"="C:\Program Files\StorageSync\StrgSync.exe" [ ]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [ ]
"Persistence"="C:\Windows\system32\igfxpers.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]

C:\Users\odcustomer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-01-10 13:08:24 147456]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-10-01 07:58:15 126136]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-02 20:40:10 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080116.003\IDSvix86.sys [2007-11-06 11:07]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 06:27]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-10-18 09:05]
R3 moufiltr;Mouse Filter;C:\Windows\system32\DRIVERS\moufiltr.sys [2007-01-09 09:22]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-21 11:51]
R3 SymIMMP;SymIMMP;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-08-13 15:50]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 02:30]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2007-02-07 16:15]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11d59101-760d-11dc-a300-001b246ad1bd}]
\shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 22:10:05 C:\Windows\Tasks\HPCeeScheduleForodcustomer.job"
- C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe
"2008-01-16 01:12:03 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - odcustomer.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-21 01:45:35 C:\Windows\Tasks\User_Feed_Synchronization-{2C866FF7-7A81-4853-8801-7A62DBA88F61}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 20:41:51
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 20:47:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-21 01:47:52
.
2008-01-13 21:27:43 --- E O F ---


----Kaspersky Scan--------------------------------------
Scan Statistics:
Total number of scanned objects: 166525
Number of viruses found: 3
Number of infected objects: 5
Number of suspicious objects: 0
Duration of the scan process: 02:05:10
C:\QooBox\Quarantine\C\Windows\System32\ddccbbc.dll.vir Infected: Trojan-Downloader.Win32.Small.htk skipped
C:\QooBox\Quarantine\C\Windows\System32\gebbbcc.dll.vir Infected: Trojan-Downloader.Win32.Small.htk skipped
C:\Windows\System32\winnzy32.dll Infected: Trojan.Win32.Dialer.yz skipped
H:\Heathers Documents\My Music\Rare Recording (jenna).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
H:\Heathers Documents\My Music\TOTALLY HIP TRACK (jenna).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
 
Sorry about jumping the gun. The logs are from before I ran the HJT. I am posting the results that I received. If you would you like new ones let me know.

ComboFix 08-01-20.1 - odcustomer 2008-01-20 20:29:03.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.998 [GMT -5:00]
Running from: C:\Users\odcustomer\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\system32\ddccbbc.dll
C:\Windows\system32\fvcpbmei.dll
C:\Windows\system32\gebbbcc.dll
C:\Windows\System32\iembpcvf.ini
C:\Windows\system32\qomno.dll
C:\Windows\System32\ruvut.ini
C:\Windows\System32\ruvut.ini2
C:\Windows\system32\tuvur.dll
C:\Windows\system32\x64
H:\Autorun.inf

----- Unknown downloads made by BITS: ----
http://epg.tvdownload.microsoft.com
.
((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-20 20:23 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-20 20:07 . 2008-01-20 20:07 88 --a------ C:\Windows\wininit.ini
2008-01-20 17:25 . 2008-01-20 20:02 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-20 17:25 . 2008-01-20 20:02 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-01-19 21:39 . 2008-01-19 21:39 <DIR> d-------- C:\Users\All Users\Yahoo! Companion
2008-01-19 21:39 . 2008-01-19 21:39 <DIR> d-------- C:\ProgramData\Yahoo! Companion
2008-01-19 12:39 . 2008-01-19 12:39 23,040 --a------ C:\Windows\System32\winnzy32.dll
2008-01-19 12:37 . 2008-01-19 12:37 <DIR> d-------- C:\Users\All Users\Macrovision
2008-01-19 12:37 . 2008-01-19 12:37 <DIR> d-------- C:\ProgramData\Macrovision
2008-01-19 12:36 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
2008-01-19 12:36 . 2003-07-30 18:28 974,848 --a------ C:\Windows\System32\mfc70.dll
2008-01-19 12:36 . 2003-07-30 18:28 487,424 --a------ C:\Windows\System32\msvcp70.dll
2008-01-19 12:36 . 2003-07-30 18:28 344,064 --a------ C:\Windows\System32\msvcr70.dll
2008-01-19 12:35 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-01-19 12:32 . 2008-01-19 12:36 <DIR> d-------- C:\Program Files\Macromedia
2008-01-19 12:05 . 2008-01-20 08:26 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\LimeWire
2008-01-19 12:03 . 2008-01-19 12:03 <DIR> d-------- C:\Program Files\LimeWire
2008-01-13 16:26 . 2008-01-13 16:26 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-13 16:26 . 2008-01-13 16:26 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-13 16:26 . 2008-01-13 16:26 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-13 16:26 . 2008-01-13 16:26 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-13 16:26 . 2008-01-13 16:26 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-13 16:26 . 2008-01-13 16:26 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-13 16:26 . 2008-01-13 16:26 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-13 16:26 . 2008-01-13 16:26 25,656 --a------ C:\Windows\System32\drivers\msahci.sys
2008-01-13 16:26 . 2008-01-13 16:26 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-13 16:26 . 2008-01-13 16:26 17,464 --a------ C:\Windows\System32\drivers\intelide.sys
2008-01-09 03:02 . 2008-01-09 03:02 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-09 03:02 . 2008-01-09 03:02 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-09 03:02 . 2008-01-09 03:02 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-09 03:02 . 2008-01-09 03:02 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-09 03:02 . 2008-01-09 03:02 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-09 03:01 . 2008-01-09 03:01 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-01-01 22:59 . 2008-01-01 22:59 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\MechCAD
2008-01-01 22:59 . 2008-01-01 23:16 <DIR> d-------- C:\Program Files\AceMoney
2007-12-31 10:33 . 2007-12-31 10:33 <DIR> d-------- C:\Users\odcustomer\AppData\Roaming\.purple
2007-12-31 10:31 . 2008-01-01 09:50 <DIR> d-------- C:\Program Files\Pidgin
2007-12-31 10:30 . 2007-12-31 10:30 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-12-30 15:54 . 2007-12-30 16:04 <DIR> d-------- C:\Program Files\BearFlix Applications
2007-12-30 15:53 . 2007-12-30 16:04 <DIR> d-------- C:\Program Files\BearFlix
2007-12-30 14:07 . 2007-10-18 08:51 172,032 --a------ C:\Windows\System32\igfxres.dll
2007-12-27 10:13 . 2008-01-20 20:40 373,392,862 --a------ C:\Windows\MEMORY.DMP
2007-12-26 23:10 . 2007-12-26 23:10 364,544 --a------ C:\Windows\System32\WDBtnMgr.exe
2007-12-26 23:08 . 2007-12-26 23:08 <DIR> d-------- C:\Program Files\Western Digital Technologies
2007-12-26 22:49 . 2008-01-19 12:44 <DIR> d-------- C:\Program Files\StorageSync
2007-12-22 11:23 . 2007-12-22 11:23 <DIR> d-------- C:\Users\All Users\LightScribe
2007-12-22 11:23 . 2007-12-22 11:23 <DIR> d-------- C:\ProgramData\LightScribe
2007-12-22 11:07 . 2007-12-22 11:09 <DIR> d--h----- C:\Windows\msdownld.tmp
2007-12-22 11:05 . 2007-12-22 11:05 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2007-12-22 10:58 . 2007-12-31 10:40 <DIR> d-------- C:\Program Files\Free WMA to MP3 Converter
2007-12-22 10:32 . 2007-12-22 10:33 <DIR> d-------- C:\Users\Ryan\AppData\Roaming\Roxio

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 01:29 --------- d-----w C:\Program Files\MSN Messenger
2008-01-20 23:58 --------- d-----w C:\ProgramData\Symantec
2008-01-20 15:58 --------- d-----w C:\ProgramData\Google Updater
2008-01-20 02:40 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Yahoo!
2008-01-20 02:36 --------- d-----w C:\ProgramData\Yahoo!
2008-01-20 02:36 --------- d-----w C:\Program Files\Yahoo!
2008-01-19 23:00 --------- d-----w C:\ProgramData\Roxio
2008-01-19 23:00 --------- d-----w C:\Program Files\Roxio
2008-01-19 22:59 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-01-19 22:53 --------- d-----w C:\ProgramData\Lavasoft
2008-01-19 17:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-19 17:24 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-13 22:29 --------- d-----w C:\Program Files\Windows Mail
2008-01-13 21:26 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-13 21:26 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-13 21:26 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-13 21:26 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-09 08:01 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-06 14:53 --------- d-----w C:\Users\Ryan\AppData\Roaming\HP
2007-12-31 15:34 206 ----a-w C:\Users\odcustomer\AppData\Roaming\wklnhst.dat
2007-12-31 15:33 --------- d-----w C:\Users\odcustomer\AppData\Roaming\.purple
2007-12-29 16:45 --------- d-----w C:\Program Files\Windows Defender
2007-12-29 16:45 --------- d-----w C:\Program Files\Windows Calendar
2007-12-29 16:14 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-12-29 16:14 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-12-29 16:14 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-12-29 16:14 2,923,520 ----a-w C:\Windows\explorer.exe
2007-12-29 16:14 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-12-29 16:14 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys
2007-12-22 23:40 --------- d-----w C:\Program Files\Norton Internet Security
2007-12-16 04:07 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Template
2007-12-16 04:01 --------- d-----w C:\Users\odcustomer\AppData\Roaming\InstallShield
2007-12-14 22:12 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-14 21:59 --------- d-----w C:\Program Files\Common Files\LightScribe
2007-12-14 21:52 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Hewlett-Packard
2007-12-14 21:42 0 --sha-r C:\Windows\system32\drivers\103C_HP_cNB_Pavilion dv6000 (GA378UA#ABA)_Y5335KV_0U_QCNF72858F5_E447502-001_4A_I30BB_SQuanta_V66.40_F.29_T071113_WV3-0_L409_M2038_J160_7Intel_86EC_92.00_#070809_N80861092;80864222_(GA378UA#ABA)_XMOBILE_CN10_Z.MRK
2007-12-14 02:42 --------- d-----w C:\Users\Ryan\AppData\Roaming\Symantec
2007-12-14 02:42 --------- d-----w C:\Users\Ryan\AppData\Roaming\MySpace
2007-12-12 21:40 174 --sha-w C:\Program Files\desktop.ini
2007-12-12 03:01 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2007-12-12 03:01 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2007-12-12 03:01 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2007-12-12 03:01 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2007-12-12 03:01 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2007-12-12 02:53 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-12-12 02:53 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-12-12 02:53 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-12-12 02:53 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2007-12-12 02:53 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-12-12 02:53 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-12-12 02:53 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-12 02:51 82,432 ----a-w C:\Windows\system32\drivers\sdbus.sys
2007-12-12 02:45 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 02:44 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2007-12-12 02:36 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-12 02:36 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-12 02:36 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-12 02:36 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 02:33 --------- d-----w C:\Program Files\CONEXANT
2007-12-08 19:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-08 14:43 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2007-12-08 14:43 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2007-12-08 14:43 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2007-12-08 14:43 --------- d-----w C:\Program Files\Symantec
2007-12-01 04:57 43,696 ----a-w C:\Windows\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 ----a-w C:\Windows\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 ----a-w C:\Windows\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 ----a-w C:\Windows\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 ----a-w C:\Windows\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 ----a-w C:\Windows\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 ----a-w C:\Windows\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 ----a-w C:\Windows\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 ----a-w C:\Windows\system32\drivers\srtsp.inf
2007-11-28 04:53 --------- d-----w C:\Users\odcustomer\AppData\Roaming\Symantec
2007-11-27 01:44 --------- d-----w C:\ProgramData\GameHouse
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 22:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2007-11-27 23:50 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 22:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 03:01 1232896]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [ ]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-29 11:14 1006264]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [ ]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [ ]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 13:38 159744]
"HP Health Check Scheduler"="[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [ ]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 15:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 18:12 317128]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [ ]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [ ]
"StrgSync.exe"="C:\Program Files\StorageSync\StrgSync.exe" [ ]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [ ]
"Persistence"="C:\Windows\system32\igfxpers.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]

C:\Users\odcustomer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-01-10 13:08:24 147456]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-10-01 07:58:15 126136]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-02 20:40:10 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080116.003\IDSvix86.sys [2007-11-06 11:07]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 06:27]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-10-18 09:05]
R3 moufiltr;Mouse Filter;C:\Windows\system32\DRIVERS\moufiltr.sys [2007-01-09 09:22]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-21 11:51]
R3 SymIMMP;SymIMMP;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-08-13 15:50]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 02:30]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2007-02-07 16:15]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11d59101-760d-11dc-a300-001b246ad1bd}]
\shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 22:10:05 C:\Windows\Tasks\HPCeeScheduleForodcustomer.job"
- C:\Program Files\Hewlett-Packard\SDP\Ceement\HPCEE.exe
"2008-01-16 01:12:03 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - odcustomer.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-21 01:45:35 C:\Windows\Tasks\User_Feed_Synchronization-{2C866FF7-7A81-4853-8801-7A62DBA88F61}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 20:41:51
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-20 20:47:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-21 01:47:52
.
2008-01-13 21:27:43 --- E O F ---


----Kaspersky Scan--------------------------------------
Scan Statistics:
Total number of scanned objects: 166525
Number of viruses found: 3
Number of infected objects: 5
Number of suspicious objects: 0
Duration of the scan process: 02:05:10
C:\QooBox\Quarantine\C\Windows\System32\ddccbbc.dll.vir Infected: Trojan-Downloader.Win32.Small.htk skipped
C:\QooBox\Quarantine\C\Windows\System32\gebbbcc.dll.vir Infected: Trojan-Downloader.Win32.Small.htk skipped
C:\Windows\System32\winnzy32.dll Infected: Trojan.Win32.Dialer.yz skipped
H:\Heathers Documents\My Music\Rare Recording (jenna).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
H:\Heathers Documents\My Music\TOTALLY HIP TRACK (jenna).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
 
Hi

Please delete the following :-

C:\QooBox ... folder

C:\Windows\System32\winnzy32.dll ... file

H:\Heathers Documents\My Music\Rare Recording (jenna).wma ... file

H:\Heathers Documents\My Music\TOTALLY HIP TRACK (jenna).wma ... file

Then your logs are clean...

steam
 
Back
Top