Sorry, have been out of town but am back now...
HJT Log:Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:57 PM, on 1/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ICQ\ICQ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Orbitdownloader\orbitnet.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Trend Micro\HijackThis\something.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduserR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduserR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {3DD33E23-F028-41C7-A709-0BEF031B53F0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {AC2C2F57-DB21-4E01-A93A-7A389C26DFA8} - (no file)
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupd...b?1229134910687O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1229388167343O20 - AppInit_DLLs: dyvvxj.dll
O20 - Winlogon Notify: awtRlMCV - C:\WINDOWS\
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 11948 bytes
Combo Log:ComboFix 09-01-10.03 - HP_Administrator 2009-01-11 20:22:23.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3710.3038 [GMT -5:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated)
FW: Symantec Endpoint Protection *enabled*
* Created a new restore point
FILE ::
c:\windows\system32\crash
c:\windows\system32\easllsbq.ini
c:\windows\system32\olhlyucb.ini
c:\windows\system32\qtuflaqs.ini
c:\windows\system32\skmigrdn.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\crash
.
((((((((((((((((((((((((( Files Created from 2008-12-12 to 2009-01-12 )))))))))))))))))))))))))))))))
.
2008-12-30 21:34 . 2008-12-30 21:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-30 21:15 . 2008-12-30 21:15 <DIR> d-------- c:\program files\Apple Software Update
2008-12-30 21:14 . 2009-01-06 20:16 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-12-30 21:14 . 2008-12-30 21:34 <DIR> d-------- c:\program files\Common Files\Apple
2008-12-30 21:14 . 2008-12-30 21:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-12-30 21:14 . 2008-11-07 14:23 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys
2008-12-30 20:20 . 2008-12-30 20:48 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-29 18:03 . 2008-12-29 18:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avg8
2008-12-27 21:28 . 2008-04-13 19:12 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-12-27 21:28 . 2008-04-13 13:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-12-27 21:28 . 2008-04-13 13:45 15,104 --a------ c:\windows\system32\dllcache\usbscan.sys
2008-12-27 21:28 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-12-27 18:31 . 2008-12-27 18:31 <DIR> d-------- c:\program files\Trend Micro
2008-12-26 09:41 . 2008-12-29 15:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\_comodo_
2008-12-26 09:30 . 2008-12-26 09:30 120 --a------ c:\windows\CIS_Setup_3.5.57173.439_XP_Vista_x32.INI
2008-12-26 00:40 . 2008-12-26 00:40 <DIR> d-------- c:\program files\AVG
2008-12-26 00:05 . 2008-12-29 17:55 <DIR> d-------- c:\program files\COMODO
2008-12-23 22:57 . 2008-12-23 22:57 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Media Player Classic
2008-12-23 22:56 . 2008-12-23 22:56 <DIR> d-------- c:\program files\Combined Community Codec Pack
2008-12-21 17:36 . 2009-01-09 16:39 <DIR> d-------- C:\Downloads
2008-12-16 22:15 . 2008-12-29 23:31 69 --a------ c:\windows\NeroDigital.ini
2008-12-16 21:06 . 2008-12-16 21:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\LightScribe
2008-12-16 21:05 . 2008-12-16 21:08 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Nero
2008-12-16 20:47 . 2008-12-16 20:47 4,767 --a------ c:\windows\Irremote.ini
2008-12-16 20:44 . 2008-12-16 20:44 <DIR> d-------- c:\program files\Windows Sidebar
2008-12-16 20:30 . 2008-12-16 20:46 <DIR> d-------- c:\program files\Nero
2008-12-16 20:30 . 2008-12-16 21:02 <DIR> d-------- c:\program files\Common Files\Nero
2008-12-16 20:30 . 2008-12-16 20:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2008-12-16 20:07 . 2008-12-16 20:07 <DIR> d-------- c:\program files\Xvid
2008-12-16 20:07 . 2008-12-04 21:42 815,104 --a------ c:\windows\system32\xvidcore.dll
2008-12-16 20:07 . 2008-12-04 21:46 180,224 --a------ c:\windows\system32\xvidvfw.dll
2008-12-16 20:07 . 2008-12-04 19:00 110,592 --a------ c:\windows\system32\xvid.ax
2008-12-16 02:48 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-16 02:48 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-15 21:31 . 2008-12-15 21:33 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Filter Forge
2008-12-15 21:29 . 2008-12-15 21:29 <DIR> d-------- c:\program files\Filter Forge
2008-12-15 21:29 . 2006-11-10 19:41 1,030,144 --a------ c:\windows\system32\dbghelp-xfw.dll
2008-12-15 21:26 . 2008-12-19 23:08 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Alien Skin
2008-12-15 21:26 . 2008-12-15 21:26 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\AdobeUM
2008-12-15 21:21 . 2004-03-29 17:23 90,112 --a------ c:\windows\unvise32.exe
2008-12-15 21:19 . 2004-03-29 12:16 352,256 --a------ c:\windows\esellerateEngine.dll
2008-12-15 20:58 . 2008-12-15 21:25 754 --a------ c:\windows\WORDPAD.INI
2008-12-15 20:55 . 2008-12-15 20:55 <DIR> d-------- c:\program files\Alien Skin
2008-12-15 20:21 . 2008-12-15 20:21 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Sonic
2008-12-15 20:21 . 2008-12-15 20:21 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Leadertech
2008-12-15 20:15 . 2008-12-16 15:53 <DIR> d-------- c:\program files\Pismo File Mount Audit Package
2008-12-15 16:30 . 2008-12-15 16:30 <DIR> d-------- c:\program files\MSBuild
2008-12-15 16:26 . 2008-12-15 19:51 <DIR> d-------- c:\windows\system32\XPSViewer
2008-12-15 16:26 . 2008-12-15 16:26 <DIR> d-------- c:\program files\Reference Assemblies
2008-12-15 16:25 . 2006-06-29 13:07 14,048 --a------ c:\windows\system32\spmsg2.dll
2008-12-14 01:49 . 2008-12-14 01:49 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\ZoomBrowser EX
2008-12-14 01:38 . 2008-12-14 01:38 <DIR> d-------- c:\windows\Sun
2008-12-14 01:29 . 2008-12-14 01:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\ZoomBrowser
2008-12-14 01:28 . 2008-12-14 01:29 <DIR> d-------- c:\program files\Canon
2008-12-14 01:26 . 2008-12-14 01:26 <DIR> d-------- c:\program files\Common Files\Canon
2008-12-14 01:01 . 2008-12-14 01:02 <DIR> d-------- c:\program files\Winamp
2008-12-14 01:01 . 2008-12-14 01:01 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Winamp
2008-12-14 00:57 . 2008-12-14 00:57 <DIR> d-------- c:\program files\Orbitdownloader
2008-12-14 00:57 . 2009-01-11 20:30 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Orbit
2008-12-14 00:14 . 2008-12-14 00:14 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\OpenOffice.org
2008-12-14 00:12 . 2008-12-14 00:12 <DIR> d-------- c:\program files\OpenOffice.org 3
2008-12-14 00:12 . 2008-12-14 00:12 <DIR> d-------- c:\program files\JRE
2008-12-14 00:10 . 2008-12-14 00:10 <DIR> d-------- c:\program files\OpenOffice
2008-12-13 20:41 . 2008-12-13 20:41 <DIR> d-------- c:\windows\aod
2008-12-13 20:41 . 2008-12-29 18:53 <DIR> d-------- c:\program files\ICQ
2008-12-13 20:41 . 2008-12-13 20:41 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\ICQ
2008-12-13 19:22 . 2008-12-13 19:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2008-12-13 19:08 . 2008-12-30 21:17 <DIR> d-------- c:\program files\Bonjour
2008-12-13 18:57 . 2008-12-13 18:57 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-12-13 18:18 . 2008-12-15 20:07 <DIR> d-------- C:\BT
2008-12-13 18:10 . 2008-12-13 18:10 <DIR> d-------- c:\program files\Common Files\Vbox
2008-12-13 18:09 . 2009-01-11 20:28 <DIR> d-------- c:\program files\DNA
2008-12-13 18:09 . 2008-12-13 18:10 <DIR> d-------- c:\program files\Common Files\Macromedia
2008-12-13 18:09 . 2008-12-13 18:09 <DIR> d-------- c:\program files\BitTorrent
2008-12-13 18:09 . 2009-01-11 20:28 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\DNA
2008-12-13 18:09 . 2008-12-15 15:56 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\BitTorrent
2008-12-13 18:08 . 2008-12-13 19:19 <DIR> d-------- c:\program files\Macromedia
2008-12-13 18:04 . 2008-12-13 18:04 <DIR> d-------- c:\program files\Agent
2008-12-13 18:02 . 2008-12-13 18:02 <DIR> d-------- c:\program files\Digital Dutch
2008-12-13 18:00 . 2008-12-13 18:00 <DIR> d-------- c:\program files\Ahead
2008-12-13 18:00 . 2002-09-25 13:15 901,120 --------- c:\windows\Unnero.exe
2008-12-13 18:00 . 2002-09-11 18:00 532,480 --a------ c:\windows\system32\imagx5.dll
2008-12-13 18:00 . 2002-09-11 18:00 507,904 --a------ c:\windows\system32\imagr5.dll
2008-12-13 18:00 . 2002-09-11 18:00 275,312 --a------ c:\windows\system32\ImagXpr5.dll
2008-12-13 18:00 . 2002-09-11 18:01 155,648 --a------ c:\windows\system32\NeroCheck.exe
2008-12-13 18:00 . 2002-09-11 18:00 106,496 --a------ c:\windows\system32\TwnLib20.dll
2008-12-13 18:00 . 2002-09-11 18:07 68,516 --------- c:\windows\Unnero.cfg
2008-12-13 18:00 . 2002-09-11 18:01 49,152 --a------ c:\windows\system32\MultiSZ.dll
2008-12-13 18:00 . 2002-09-11 18:00 35,328 --a------ c:\windows\system32\picn20.dll
2008-12-13 17:56 . 2008-12-13 17:56 <DIR> d-------- c:\program files\WS_FTP Pro
2008-12-13 17:56 . 2008-12-13 17:56 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Ipswitch
2008-12-13 17:56 . 2008-12-13 17:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ipswitch
2008-12-13 17:56 . 2002-07-16 18:08 49,152 --a------ c:\windows\system32\FTPStubInstUtils.dll
2008-12-13 17:18 . 2008-12-13 17:18 623 --a------ c:\windows\WININI.QTW
2008-12-13 17:18 . 2008-12-13 17:19 269 --a------ c:\windows\QTW.INI
2008-12-13 17:18 . 2008-12-13 17:18 231 --a------ c:\windows\SYSINI.QTW
2008-12-13 16:36 . 2004-02-25 17:10 131,072 -ra------ c:\windows\system32\SCCD3X01.DLL
2008-12-13 16:36 . 2004-02-25 17:10 90,112 -ra------ c:\windows\system32\SCCD3X02.DLL
2008-12-13 15:06 . 2008-12-13 15:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-13 15:06 . 2008-12-13 15:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\AOL
2008-12-13 15:05 . 2008-12-13 15:08 375 --ah----- C:\IPH.PH
2008-12-13 01:33 . 2008-12-13 14:14 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-13 01:33 . 2008-12-13 14:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-13 01:30 . 2008-12-13 01:30 <DIR> d-------- c:\program files\Lavasoft
2008-12-13 01:30 . 2008-12-13 01:30 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-13 01:30 . 2008-12-13 01:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-13 00:18 . 2008-12-13 00:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Logitech
2008-12-13 00:12 . 2008-12-13 00:18 <DIR> d-------- c:\program files\Logitech
2008-12-13 00:05 . 2008-12-13 01:26 <DIR> d-------- c:\program files\Common Files\logishrd
2008-12-12 23:49 . 2008-12-13 01:26 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\acccore
2008-12-12 23:46 . 2008-12-13 15:06 <DIR> d-------- c:\program files\Viewpoint
2008-12-12 23:46 . 2008-12-12 23:46 <DIR> d-------- c:\program files\Common Files\AOL
2008-12-12 23:46 . 2008-12-13 15:08 <DIR> d-------- c:\program files\AIM6
2008-12-12 23:46 . 2008-12-12 23:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\AOL OCP
2008-12-12 23:46 . 2008-12-12 23:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\acccore
2008-12-12 23:27 . 2008-12-12 23:27 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\HPQ
2008-12-12 23:00 . 2009-01-11 20:30 183 --a------ c:\windows\system\hpsysdrv.DAT
2008-12-12 22:38 . 2008-12-12 22:38 <DIR> d-------- c:\windows\system32\Flash
2008-12-12 22:38 . 2008-12-12 22:38 <DIR> d-------- c:\program files\TechSmith
2008-12-12 22:38 . 2008-12-12 22:38 <DIR> d-------- c:\program files\Common Files\TechSmith Shared
2008-12-12 22:38 . 2008-12-12 22:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\TechSmith
2008-12-12 22:38 . 2008-07-10 14:56 107,864 --a------ c:\windows\system32\tsccvid.dll
2008-12-12 22:34 . 2008-12-12 21:10 <DIR> d-------- c:\windows\I386
2008-12-12 22:28 . 2008-12-13 19:24 <DIR> d-------- c:\program files\Mozilla Firefox old
2008-12-12 22:28 . 2008-12-12 22:28 0 --a------ c:\windows\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 01:16 --------- d-----w c:\program files\iTunes
2008-12-31 02:34 --------- d-----w c:\program files\iPod
2008-12-31 02:16 --------- d-----w c:\program files\QuickTime
2008-12-31 02:15 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-20 16:25 --------- d-----w c:\documents and settings\All Users\Application Data\QuickTime
2008-12-17 01:29 --------- d---a-w c:\program files\Common Files\LightScribe
2008-12-14 05:12 --------- d-----w c:\program files\Java
2008-12-14 00:08 --------- d-----w c:\program files\Common Files\Adobe
2008-12-13 23:15 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-13 04:35 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-13 03:02 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-13 03:01 --------- d-----w c:\program files\Symantec
2008-12-13 02:25 --------- d-----w c:\program files\Microsoft Works
2008-12-13 02:20 --------- d-----w c:\program files\GemMaster
2008-12-13 02:08 --------- d-----w c:\program files\Easy Internet signup
.
((((((((((((((((((((((((((((( snapshot@2008-12-29_18.55.34.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-07 01:16:42 102,400 ----a-r c:\windows\Installer\{318AB667-3230-41B5-A617-CB3BF748D371}\iTunesIco.exe
+ 2008-12-31 02:15:17 27,136 ----a-r c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2008-12-31 02:17:04 86,016 ----a-r c:\windows\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe
- 2008-12-27 14:09:41 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-03 18:57:37 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-27 14:09:41 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-03 18:57:37 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-02-28 17:41:34 61,440 ----a-w c:\windows\system32\dns-sd.exe
+ 2008-08-29 15:18:58 87,336 ----a-w c:\windows\system32\dns-sd.exe
- 2006-02-28 17:41:22 53,248 ----a-w c:\windows\system32\dnssd.dll
+ 2008-08-29 14:53:50 61,440 ----a-w c:\windows\system32\dnssd.dll
- 2005-03-08 01:52:48 14,408 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2008-04-17 18:12:54 15,464 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2008-04-17 18:12:54 107,368 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
+ 2008-04-17 18:12:54 15,464 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
+ 2008-11-07 19:23:30 32,000 -c--a-w c:\windows\system32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
- 2005-03-08 01:52:48 79,432 ----a-w c:\windows\system32\GEARAspi.dll
+ 2008-04-17 18:12:54 107,368 ----a-w c:\windows\system32\GEARAspi.dll
+ 2008-04-13 18:45:38 26,368 ----a-w c:\windows\system32\ReinstallBackups\
0019\DriverFiles\i386\USBSTOR.SYS
+ 2009-01-12 01:27:24 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_1ec.dat
+ 2009-01-12 01:28:54 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_f14.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-18 342848]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-10 61440]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-10 253952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-12 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-09-14 180269]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2002-09-11 155648]
"Mirabilis ICQ"="c:\progra~1\ICQ\ICQNet.exe" [2003-10-14 38984]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-08 c:\windows\RTHDCPL.EXE]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ATI CATALYST System Tray.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-08-10 61440]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2008-12-14 1690824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtRlMCV]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=dyvvxj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-12 99376]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-12-13 24652]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-01-12 23888]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2008-12-13 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2005-05-24 18:46]
.
- - - - ORPHANS REMOVED - - - -
BHO-{3DD33E23-F028-41C7-A709-0BEF031B53F0} - (no file)
BHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
BHO-{AC2C2F57-DB21-4E01-A93A-7A389C26DFA8} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fiw3cndm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-11 20:31:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3929598875-2078755853-2325519148-1008\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{644CA0C5-8EC5-BDE7-DA67-5DD59EC4D615}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"ianmnjkabiagobgile"=hex:6b,61,69,68,6f,6d,6e,67,67,6f,69,69,6a,65,69,68,62,6e,
67,62,63,62,00,00
"halmjgggkdffiipf"=hex:6b,61,69,68,6f,6d,6e,67,67,6f,69,69,6a,65,69,68,62,6e,
67,62,63,62,00,00
"hachkgpkooklhepg"=hex:64,63,67,6b,6e,68,67,6a,62,64,63,65,6f,6a,67,62,70,62,
6a,6f,70,6c,61,67,6d,6b,61,63,61,6a,64,69,6d,6f,68,6a,6e,66,61,6f,66,6b,63,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{644CA0C5-8EC5-BDE7-DA67-5DD59EC4D615}\InProcServer32*]
"japmifmhojaaphfjigeh"=hex:6b,61,69,68,6f,6d,6e,67,67,6f,69,69,6a,65,69,68,62,
6e,67,62,63,62,00,00
"iapmcgmgedconppnil"=hex:6b,61,69,68,6f,6d,6e,67,67,6f,69,69,6a,65,69,68,62,6e,
67,62,63,62,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1016)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\arservice.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
c:\hp\KBD\kbd.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Orbitdownloader\orbitnet.exe
c:\windows\system\hpsysdrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-11 20:35:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-12 01:35:30
ComboFix2.txt 2009-01-12 01:18:54
ComboFix3.txt 2008-12-29 23:56:07
Pre-Run: 586,008,936,448 bytes free
Post-Run: 585,978,814,464 bytes free
372 --- E O F --- 2008-12-13 03:15:50
KAS Log--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, January 12, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, January 12, 2009 01:05:58
Records in database: 1605088
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\
N:\
O:\
Scan statistics:
Files scanned: 535669
Threat name: 7
Infected objects: 9
Suspicious objects: 0
Duration of the scan: 11:19:59
File name / Threat name / Threats count
C:\Documents and Settings\HP_Administrator\My Documents\Downloads\photoshop plugins\HumanSoft.AutoDeNoise.v1.8.for.Adobe.Photoshop-FOSI\fo-adn18.zip Infected: not-a-virus:AdWare.Win32.Rabio.gm 1
C:\Program Files\Online Services\AOL\United States\AOL90\comps\toolbar\toolbr.EXE Infected: not-a-virus:AdWare.Win32.SearchIt.t 1
K:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine47C7258.zip Infected: Trojan-Downloader.Java.OpenStream.w 1
K:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17EA5272.exe Infected: Trojan-Dropper.Win32.Agent.qgq 1
K:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17F1266B.tmp Infected: Trojan-Dropper.Win32.Agent.qgq 1
K:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\36FE1085 Infected: Trojan-Downloader.Win32.Zlob.bke 1
K:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\370E6273.exe Infected: Trojan-Downloader.Win32.Zlob.bke 1
K:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\69095027.zip Infected: Exploit.Java.Gimsh.a 1
K:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79D61D36.tmp Infected: Exploit.Win32.Pidief.pw 1
The selected area was scanned.