Installed file from bleepingcomputer.com, d/l recovery console. dragged and dropped file, disabled spybot, spywareblaster and norton 360, ran combo fix , then ran hijackthis. Thanks for your time...
here's the hijackthis file:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:56:41 PM, on 8/8/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Linksys\WUSB600N\WUSB600N.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: MetaCrawl.WS Toolbar - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - C:\Program Files\IEToolbar\metacrawl.ws.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: Wireless Network Monitor.lnk = C:\Program Files\Linksys\WUSB600N\WUSB600N.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: xsspbqyw - C:\WINDOWS\SYSTEM32\xsspbqyw.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 6300 bytes
Heres the combofix file:
ComboFix 08-08-08.06 - 007 2008-08-08 18:42:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.179 [GMT -4:00]
Running from: C:\Documents and Settings\
007\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\
007\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\
007\Application Data\DriveCleaner Free
C:\Documents and Settings\
007\Application Data\DriveCleaner Free\Logs\update.log
C:\Documents and Settings\
007\Application Data\macromedia\Flash Player\#SharedObjects\FSFLFFY7\interclick.com
C:\Documents and Settings\
007\Application Data\macromedia\Flash Player\#SharedObjects\FSFLFFY7\interclick.com\ud.sol
C:\Documents and Settings\
007\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\
007\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\
007\err.log
C:\Documents and Settings\27\Application Data\searchtoolbarcorp
C:\Documents and Settings\27\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\27\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\Guest\Application Data\DriveCleaner Free
C:\Documents and Settings\Guest\Application Data\DriveCleaner Free\Logs\update.log
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\Guest\err.log
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\.lnk
C:\Documents and Settings\SCUBA\Application Data\MBOLS~1
C:\Documents and Settings\SCUBA\Application Data\MBOLS~1\??mbols\
C:\Documents and Settings\SCUBA\Application Data\searchtoolbarcorp
C:\Documents and Settings\SCUBA\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\SCUBA\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\SCUBA\My Documents\DOBE~1
C:\Program Files\IEToolbar
C:\Program Files\IEToolbar\basis.xml
C:\Program Files\IEToolbar\icons.bmp
C:\Program Files\IEToolbar\inst.bat
C:\Program Files\IEToolbar\metacrawl.ws.crc
C:\Program Files\IEToolbar\metacrawl.ws.dll
C:\Program Files\IEToolbar\metacrawl.ws.inf
C:\Program Files\IEToolbar\metacrawlit.bmp
C:\Program Files\IEToolbar\version.txt
C:\WINDOWS\BMb7cd7021.txt
C:\WINDOWS\BMb7cd7021.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\afoevogm.ini
C:\WINDOWS\system32\ajfljivl.ini
C:\WINDOWS\system32\apcclmvk.dll
C:\WINDOWS\system32\awairbgk.ini
C:\WINDOWS\system32\bjqigjyh.ini
C:\WINDOWS\system32\bkfckdvk.ini
C:\WINDOWS\system32\brbsvbiq.ini
C:\WINDOWS\system32\cbxuayvw.ini
C:\WINDOWS\system32\ccsrnxpj.ini
C:\WINDOWS\system32\ckuefjsx.ini
C:\WINDOWS\system32\cosjlmxw.ini
C:\WINDOWS\system32\cpgxipli.ini
C:\WINDOWS\system32\crjjdabs.ini
C:\WINDOWS\system32\crqrgccp.ini
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\cvarohdk.ini
C:\WINDOWS\system32\dekjoium.ini
C:\WINDOWS\system32\dhhnvedt.ini
C:\WINDOWS\system32\dsmgrcsf.ini
C:\WINDOWS\system32\dywstxgt.ini
C:\WINDOWS\system32\ekdhhlyl.ini
C:\WINDOWS\system32\elflhanc.ini
C:\WINDOWS\system32\emlcqbhv.ini
C:\WINDOWS\system32\entfhacv.ini
C:\WINDOWS\system32\erbxoowk.dll
C:\WINDOWS\system32\espcdcwh.ini
C:\WINDOWS\system32\esxmjjdo.ini
C:\WINDOWS\system32\fdbrujll.ini
C:\WINDOWS\system32\fdhtcway.dll
C:\WINDOWS\system32\fiyywggv.dll
C:\WINDOWS\system32\ftkaymjb.ini
C:\WINDOWS\system32\fvqhxdnh.ini
C:\WINDOWS\system32\gisxjhlu.ini
C:\WINDOWS\system32\gryjcqcy.ini
C:\WINDOWS\system32\gvegmgdf.ini
C:\WINDOWS\system32\gweaxxbt.ini
C:\WINDOWS\system32\gyyvlmnn.ini
C:\WINDOWS\system32\heejxwyr.ini
C:\WINDOWS\system32\hmvsslfb.ini
C:\WINDOWS\system32\hpyanbwf.ini
C:\WINDOWS\system32\igrnuphb.ini
C:\WINDOWS\system32\ioefeocq.ini
C:\WINDOWS\system32\iruufxya.ini
C:\WINDOWS\system32\jderssha.ini
C:\WINDOWS\system32\jenotwxw.ini
C:\WINDOWS\system32\jqrybrld.ini
C:\WINDOWS\system32\jttvvqls.ini
C:\WINDOWS\system32\jtvybxul.ini
C:\WINDOWS\system32\jumhfhxs.ini
C:\WINDOWS\system32\kerbfjwp.ini
C:\WINDOWS\system32\kgopnids.ini
C:\WINDOWS\system32\khsoixrd.ini
C:\WINDOWS\system32\kwicsvxf.ini
C:\WINDOWS\system32\kxfpkihd.ini
C:\WINDOWS\system32\lemfeomv.ini
C:\WINDOWS\system32\mauabxwb.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\motymmlj.ini
C:\WINDOWS\system32\mqkhjmqb.ini
C:\WINDOWS\system32\msmydjsm.ini
C:\WINDOWS\system32\nokuhrbh.ini
C:\WINDOWS\system32\npsmrfgs.ini
C:\WINDOWS\system32\nyqboluw.ini
C:\WINDOWS\system32\odtfhwfx.ini
C:\WINDOWS\system32\oebwffms.ini
C:\WINDOWS\system32\ofcdnbxn.dll
C:\WINDOWS\system32\oojhkivy.ini
C:\WINDOWS\system32\orksogwj.ini
C:\WINDOWS\system32\othqufwt.ini
C:\WINDOWS\system32\ovaaycsy.ini
C:\WINDOWS\system32\paqhxfid.ini
C:\WINDOWS\system32\pcfyrcld.ini
C:\WINDOWS\system32\pcmpufdt.ini
C:\WINDOWS\system32\pdeogmuf.ini
C:\WINDOWS\system32\pfpebnss.dll
C:\WINDOWS\system32\pjowlajf.dll
C:\WINDOWS\system32\pvjtpech.ini
C:\WINDOWS\system32\qibfutke.ini
C:\WINDOWS\system32\qkyfnqim.ini
C:\WINDOWS\system32\RCX2B.tmp
C:\WINDOWS\system32\RCX2C.tmp
C:\WINDOWS\system32\RCX2D.tmp
C:\WINDOWS\system32\RCX2E.tmp
C:\WINDOWS\system32\RCX2F.tmp
C:\WINDOWS\system32\RCX30.tmp
C:\WINDOWS\system32\RCX31.tmp
C:\WINDOWS\system32\RCX32.tmp
C:\WINDOWS\system32\RCX33.tmp
C:\WINDOWS\system32\RCX34.tmp
C:\WINDOWS\system32\RCX35.tmp
C:\WINDOWS\system32\RCX36.tmp
C:\WINDOWS\system32\RCX37.tmp
C:\WINDOWS\system32\RCX38.tmp
C:\WINDOWS\system32\RCX39.tmp
C:\WINDOWS\system32\RCX3A.tmp
C:\WINDOWS\system32\RCX3B.tmp
C:\WINDOWS\system32\RCX3C.tmp
C:\WINDOWS\system32\RCX3D.tmp
C:\WINDOWS\system32\RCX3E.tmp
C:\WINDOWS\system32\RCX3F.tmp
C:\WINDOWS\system32\RCX40.tmp
C:\WINDOWS\system32\RCX41.tmp
C:\WINDOWS\system32\RCX42.tmp
C:\WINDOWS\system32\RCX43.tmp
C:\WINDOWS\system32\RCX44.tmp
C:\WINDOWS\system32\RCX45.tmp
C:\WINDOWS\system32\RCX46.tmp
C:\WINDOWS\system32\RCX47.tmp
C:\WINDOWS\system32\RCX48.tmp
C:\WINDOWS\system32\RCX49.tmp
C:\WINDOWS\system32\RCX4A.tmp
C:\WINDOWS\system32\RCX4B.tmp
C:\WINDOWS\system32\RCX4C.tmp
C:\WINDOWS\system32\RCX4D.tmp
C:\WINDOWS\system32\RCX4E.tmp
C:\WINDOWS\system32\RCX4F.tmp
C:\WINDOWS\system32\RCX50.tmp
C:\WINDOWS\system32\RCX51.tmp
C:\WINDOWS\system32\RCX52.tmp
C:\WINDOWS\system32\RCX53.tmp
C:\WINDOWS\system32\RCX54.tmp
C:\WINDOWS\system32\RCX55.tmp
C:\WINDOWS\system32\RCX56.tmp
C:\WINDOWS\system32\RCX57.tmp
C:\WINDOWS\system32\RCX58.tmp
C:\WINDOWS\system32\RCX59.tmp
C:\WINDOWS\system32\RCX5A.tmp
C:\WINDOWS\system32\RCX5F.tmp
C:\WINDOWS\system32\RCX60.tmp
C:\WINDOWS\system32\RCX61.tmp
C:\WINDOWS\system32\RCX62.tmp
C:\WINDOWS\system32\RCX63.tmp
C:\WINDOWS\system32\RCX64.tmp
C:\WINDOWS\system32\RCX65.tmp
C:\WINDOWS\system32\RCX6D.tmp
C:\WINDOWS\system32\RCX75.tmp
C:\WINDOWS\system32\RCX82.tmp
C:\WINDOWS\system32\RCX8D.tmp
C:\WINDOWS\system32\RCX8E.tmp
C:\WINDOWS\system32\RCX90.tmp
C:\WINDOWS\system32\RCXAD.tmp
C:\WINDOWS\system32\RCXBA.tmp
C:\WINDOWS\system32\RCXBB.tmp
C:\WINDOWS\system32\RCXCF.tmp
C:\WINDOWS\system32\RCXE7.tmp
C:\WINDOWS\system32\RCXE8.tmp
C:\WINDOWS\system32\RCXFC.tmp
C:\WINDOWS\system32\reqkmxem.dll
C:\WINDOWS\system32\rfmhgdxk.ini
C:\WINDOWS\system32\rkkflesq.ini
C:\WINDOWS\system32\rqpweald.ini
C:\WINDOWS\system32\rqtss.ini
C:\WINDOWS\system32\rqtss.ini2
C:\WINDOWS\system32\setkljxt.ini
C:\WINDOWS\system32\sfgpvhwh.ini
C:\WINDOWS\system32\srbevkuj.ini
C:\WINDOWS\system32\sshmkkwp.ini
C:\WINDOWS\system32\sybwsbiv.ini
C:\WINDOWS\system32\tbqvclqg.ini
C:\WINDOWS\system32\tqulepwp.ini
C:\WINDOWS\system32\uirjntbj.ini
C:\WINDOWS\system32\ujdkylml.ini
C:\WINDOWS\system32\urxaywmi.ini
C:\WINDOWS\system32\uujujomm.ini
C:\WINDOWS\system32\vafevfjn.ini
C:\WINDOWS\system32\vevwblkg.ini
C:\WINDOWS\system32\vhnptybj.ini
C:\WINDOWS\system32\vjhpylha.ini
C:\WINDOWS\system32\vkemidii.ini
C:\WINDOWS\system32\vlmquvyf.dll
C:\WINDOWS\system32\vnbhvabt.ini
C:\WINDOWS\system32\vnbwhjle.ini
C:\WINDOWS\system32\vrmidawj.ini
C:\WINDOWS\system32\wadxqhxe.ini
C:\WINDOWS\system32\wdgieotk.ini
C:\WINDOWS\system32\wepywava.ini
C:\WINDOWS\system32\wnstssv.exe
C:\WINDOWS\system32\wsqkjeff.ini
C:\WINDOWS\system32\wtfdxkvo.ini
C:\WINDOWS\system32\wxhgggjw.dll
C:\WINDOWS\system32\xewosnhm.ini
C:\WINDOWS\system32\xfdwmfju.ini
C:\WINDOWS\system32\xklopupt.ini
C:\WINDOWS\system32\xmpcqdtf.ini
C:\WINDOWS\system32\xvgaeqry.ini
C:\WINDOWS\system32\xwtyurrx.ini
C:\WINDOWS\system32\yphrexuk.ini
C:\WINDOWS\system32\yqusbvnw.ini
C:\WINDOWS\system32\ytgytsfj.ini
C:\WINDOWS\system32\yxxrcoak.ini
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-08 to 2008-08-08 )))))))))))))))))))))))))))))))
.
2008-08-03 19:10 . 2008-08-03 19:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-03 12:08 . 2008-08-03 12:08 <DIR> d-------- C:\N360_BACKUP
2008-08-03 09:34 . 2008-08-03 09:34 <DIR> d-------- C:\Documents and Settings\
007\Application Data\Windows Search
2008-08-02 20:45 . 2008-08-02 20:45 <DIR> d-------- C:\Documents and Settings\
007\Application Data\Motive
2008-08-02 20:06 . 2008-08-02 20:06 <DIR> d-------- C:\Documents and Settings\
007\Application Data\Windows Desktop Search
2008-08-02 20:05 . 2008-08-02 20:05 <DIR> d-------- C:\WINDOWS\system32\GroupPolicy
2008-08-02 20:05 . 2008-08-02 20:05 <DIR> d-------- C:\Program Files\Windows Desktop Search
2008-08-02 20:03 . 2008-03-07 13:02 192,000 -----c--- C:\WINDOWS\system32\dllcache\offfilt.dll
2008-08-02 20:03 . 2008-03-07 13:02 98,304 -----c--- C:\WINDOWS\system32\dllcache\nlhtml.dll
2008-08-02 20:03 . 2008-03-07 13:02 29,696 -----c--- C:\WINDOWS\system32\dllcache\mimefilt.dll
2008-08-02 20:02 . 2008-08-02 20:02 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-08-02 20:00 . 2008-08-02 20:01 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-08-02 19:47 . 2008-08-06 19:32 <DIR> d-------- C:\Documents and Settings\
007\Application Data\U3
2008-08-02 18:59 . 2008-08-02 18:59 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-02 18:59 . 2008-08-02 18:59 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-02 18:59 . 2008-08-02 18:59 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-02 18:56 . 2008-08-02 19:00 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-02 18:49 . 2008-08-02 18:49 <DIR> d-------- C:\WINDOWS\EHome
2008-08-02 18:41 . 2008-04-13 20:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-08-02 18:40 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-08-02 17:14 . 2008-08-02 17:14 <DIR> d-------- C:\Program Files\Linksys
2008-08-02 17:14 . 2008-08-02 17:14 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-08-02 17:13 . 2008-08-02 17:13 <DIR> d-------- C:\WINDOWS\{7F7635FC-B887-49FA-8526-094724C01A6E}
2008-08-02 16:55 . 2008-08-02 16:55 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-08-02 16:55 . 2008-08-02 20:08 <DIR> d-------- C:\Program Files\Norton 360
2008-08-02 16:53 . 2008-08-02 17:46 <DIR> d-------- C:\Program Files\Symantec
2008-08-02 16:53 . 2008-08-04 17:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-02 16:53 . 2008-08-02 17:46 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-08-02 16:53 . 2008-08-02 17:46 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-02 16:53 . 2008-08-02 17:46 10,671 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-08-02 16:53 . 2008-08-02 17:46 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-08-02 16:34 . 2008-08-08 18:49 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-08-02 15:13 . 2008-08-02 15:13 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-02 15:13 . 2008-08-02 15:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-02 15:11 . 2008-08-03 18:37 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-08-02 15:11 . 2008-08-08 18:40 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-02 14:53 . 2006-12-04 18:25 385,443 --a------ C:\WINDOWS\hpdj5700.hi1
2008-08-02 14:53 . 2006-12-04 18:25 11,988 --a------ C:\WINDOWS\hpdj5700.bu1
2008-08-02 14:05 . 2008-08-02 14:05 2 --a------ C:\WINDOWS\msoffice.ini
2008-07-31 22:01 . 2008-04-23 00:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-07-31 22:01 . 2007-04-17 05:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-07-31 22:01 . 2007-03-08 01:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-07-31 22:01 . 2008-04-23 00:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-07-31 22:01 . 2008-04-23 00:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-07-31 22:01 . 2008-04-23 00:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-07-31 22:01 . 2008-04-23 00:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-07-31 22:01 . 2008-04-23 00:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-07-31 22:01 . 2008-04-22 03:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-07-31 21:51 . 2008-07-31 21:51 610 --a------ C:\WINDOWS\system32\MRT.INI
2008-07-31 21:33 . 2008-07-31 21:33 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-02 23:03 77,824 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\FDIWrapper.dll
2008-08-02 23:03 69,632 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\jsharpde\msxmlwrapper.dll
2008-08-02 23:03 49,152 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\PCHI18N.dll
2008-08-02 23:03 45,056 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\jsharpde\util.dll
2008-08-02 23:03 36,864 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\jsharpde\gnu.dll
2008-08-02 23:03 315,392 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\pchmsxml.dll
2008-08-02 23:03 307,200 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\pchealthplugin.dll
2008-08-02 23:03 28,672 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\InetWrap.dll
2008-08-02 23:03 26,572 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\jsharpde\INV16.dll
2008-08-02 23:03 155,877 ----a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHWWBF4Duet\plugin\bin\jsharpde\js.zip
2008-08-02 21:53 --------- d-----w C:\Documents and Settings\
007\Application Data\Symantec
2008-08-02 21:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-02 18:55 --------- d-----w C:\Program Files\HP
2008-08-02 18:55 --------- d-----w C:\Program Files\Hewlett-Packard
2008-08-02 18:11 --------- d-----w C:\Program Files\LimeWire
2008-08-02 18:05 --------- d-----w C:\Program Files\Common Files\AOL
2008-08-02 18:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-08-01 01:55 --------- d-----w C:\Program Files\iTunes
2008-08-01 01:54 --------- d-----w C:\Program Files\iPod
2008-08-01 01:51 --------- d-----w C:\Program Files\Easy Internet signup
2008-08-01 01:50 --------- d-----w C:\Program Files\QuickTime
2008-07-30 21:42 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-07-30 21:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-07-30 21:28 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-06-25 10:36 43,520 ----a-w C:\WINDOWS\system32\drivers\fetnd5bv.sys
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 18:14 31,280 ----a-w C:\WINDOWS\system32\drivers\SymIM.sys
2008-06-13 18:14 13,093 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2008-06-13 18:14 1,611 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2008-06-13 18:13 96,432 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2008-06-13 18:13 41,008 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2008-06-13 18:13 38,576 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2008-06-13 18:13 37,424 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2008-06-13 18:13 22,320 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2008-06-13 18:13 184,240 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2008-06-13 18:13 13,616 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-09 23:32 495,616 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe.tmp
2008-05-09 23:32 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
.
Code:
<pre>
----a-w 61,440 2008-08-01 01:33:31 C:\hp\KBD\KBD .EXE
----a-w 45,056 2008-08-01 01:33:42 C:\Program Files\ATI Technologies\ATI.ACE\cli .exe
----a-w 180,269 2008-08-01 01:33:32 C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w 241,664 2008-08-01 01:33:36 C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
----a-w 49,152 2008-04-27 18:24:03 C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 .exe
----a-w 256,576 2008-08-01 01:33:38 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 36,975 2008-08-01 01:33:27 C:\Program Files\Java\jre1.5.0_03\bin\jusched .exe
----a-w 282,624 2008-05-09 23:24:20 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-05-09 23:24:01 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-05-09 23:09:28 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-04-28 02:07:34 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-04-27 18:23:57 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-04-27 16:51:37 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-04-04 20:51:32 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-03-20 02:13:55 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-03-03 02:21:56 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-03-03 02:09:56 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-02-25 02:05:35 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-02-16 04:51:49 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-02-13 23:27:57 C:\Program Files\QuickTime\qttask .exe
----a-w 644,608 2008-02-11 02:51:57 C:\Program Files\QuickTime\qttask .exe
----a-w 158,208 2008-05-09 23:32:41 C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
----a-w 233,472 2008-08-01 01:33:33 C:\WINDOWS\SMINST\RECGUARD .EXE
----a-w 52,736 2008-08-01 01:33:31 C:\WINDOWS\system\hpsysdrv .exe
----a-w 15,360 2008-08-01 01:33:49 C:\WINDOWS\system32\ctfmon .exe
----a-w 659,456 2008-08-01 01:33:29 C:\WINDOWS\system32\hphmon06 .exe
----a-w 81,920 2008-08-01 01:33:33 C:\WINDOWS\system32\ps2 .exe
----a-w 527,872 2008-08-01 01:43:31 C:\WINDOWS\system32\spool\hpprintqueue .exe
----a-w 172,032 2008-08-01 01:33:37 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10 .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 04:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 04:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 04:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 20:12 169984]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 15:37 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 10:50 988512]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 88209 C:\WINDOWS\AGRSMMSG.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
C:\Documents and Settings\Clemson Tigers\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Documents and Settings\IronMan\My Documents\My Music\LimeWire\LimeWire.exe [2006-08-22 11:45:55 159744]
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
HP Organize.lnk - C:\Program Files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2004-08-07 17:29:30 36864]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 22:19:14 123904]
Wireless Network Monitor.lnk - C:\Program Files\Linksys\WUSB600N\WUSB600N.exe [2008-01-09 05:44:20 6922240]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 22:19 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xsspbqyw]
2006-09-09 19:59 188436 C:\WINDOWS\system32\xsspbqyw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b4fe43bd]
C:\WINDOWS\system32\tbxxaewg.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMb7cd7021]
C:\WINDOWS\system32\qmnpdodi.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2008-02-18 15:37 51048 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1135833712\ee\AOLSoftware.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAS_Check]
C:\Program Files\Common Files\DriveCleaner Free\udcpas .exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-09 19:24 282624 C:\Program Files\QuickTime\qttask .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDR6_Check]
C:\Program Files\Common Files\DriveCleaner Free\udcsdr .exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ccPwdSvc"=3 (0x3)
"DomainService"=2 (0x2)
"iPod Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R0 dajyqccz;dajyqccz;C:\WINDOWS\system32\drivers\tuhwliqz.dat []
R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-18 15:37]
R2 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2006-11-28 21:46]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2008-06-25 06:36]
R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;C:\WINDOWS\system32\DRIVERS\rt2870.sys [2007-12-14 18:04]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-07-30 17:42]
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2004-05-07 01:47]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a1fa7ac8-60cc-11dd-abcd-00112fab7212}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2008-08-05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 18:13]
.
- - - - ORPHANS REMOVED - - - -
Notify-hggdebc - hggdebc.dll
Notify-ypkhcwyo - ypkhcwyo.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-08 18:49:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dajyqccz]
"ImagePath"="system32\drivers\tuhwliqz.dat"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\searchindexer.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-08-08 18:55:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-08 22:54:59
Pre-Run: 127,451,815,936 bytes free
Post-Run: 127,644,844,032 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
504 --- E O F --- 2008-08-03 13:12:48