Yes my Norton was a licensed copy back in 2006, but I let it expire due to the fact that I can get the definition updates at work for free. So it no longer auto updates but I "usually" update it once a week, missed this last time as you saw on the log. Thinking of picking up a free Antivirus software, just not sure which option is better...the free software or manually updating Norton over and over. Any suggestions?
On to the logs now:
HJT found and I checked the two items you called out, and selected fix and HJT did its thing.
========Combo Fix Log===========
ComboFix 09-04-01.01 - Jenkins Admin 2009-04-03 18:32:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.344 [GMT -5:00]
Running from: c:\documents and settings\Jenkins Admin\Desktop\STUFF.exe
Command switches used :: c:\documents and settings\Jenkins Admin\Desktop\CFScript.txt
AV: Norton AntiVirus 2006 *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *enabled*
* Created a new restore point
FILE ::
c:\documents and settings\Jenkins Admin\Start Menu\Programs\Startup\iWin Desktop Alerts.lnk
C:\pv.exe
c:\windows\ASSE.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\iWin Games
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\res\btn_all.png
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\res\btn_dl.png
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\res\btn_next.png
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\res\btn_prev.png
c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\WebUpdater.exe
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{130FFF0F-0FFF-0FFF-FFF4-FFFF0F0FF9IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17034006-0492-0633-9781-30320F0FF5IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17035905-0646-0759-8562-97500F0FF5IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17036901-0895-0358-6232-98859F0FF6IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17037304-0278-0786-1382-79390F0FF1IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17037308-0979-0952-1072-88000F0FF1IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17037595-4900-0849-9653-08055F0FF2IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17137681-6503-0622-0103-65684F0FF3IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17237311-8601-0192-2862-89915F0FF4IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17237356-8003-0069-2062-86356F0FF8IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17237384-0277-0445-6133-63534F0FF1IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17333168-0110-0651-2782-64530F0FF4GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17333767-0055-0675-2553-26820F0FF0GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17333967-0521-0937-1263-42680F0FF2GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17334066-0492-0633-9782-30320F0FF4GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17334163-0854-0510-2342-03960F0FF5GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17334261-0800-0649-0302-45410F0FF6GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17334567-0421-0797-4422-65010F0FF9GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17334666-0588-0052-5203-50810F0FF0GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17334865-0702-0689-0673-56530F0FF2GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335260-0361-0925-5002-74620F0FF7GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335269-0886-0741-1952-41910F0FF7GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335269-0887-0142-7822-33770F0FF7GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335363-0276-0017-9752-40210F0FF8GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335461-0209-0318-4532-71870F0FF9GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335464-0088-0050-6642-06200F0FF9GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335468-0717-0884-2812-36080F0FF9GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335468-0718-0540-4192-24260F0FF9GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335569-0345-0789-3813-61170F0FF0GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335667-0867-0457-9123-56470F0FF1GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335761-0243-0113-1643-02620F0FF2GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335765-0793-0595-0283-27690F0FF2GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17335962-0790-0751-5273-39350F0FF4GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17336068-0159-0755-9632-24870F0FF6GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17336361-0235-0827-7032-53550F0FF9GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17336500-6629-0421-7582-50464F0FF5IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17336560-0468-0202-4883-78930F0FF1GS}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17337150-4574-0730-3342-96373F0FF7IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17337446-4192-0691-4382-29554F0FF9IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{17337747-3324-0810-8943-14097F0FF2IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\data\{2007FF0F-0FFF-0FFF-FFF3-FFFF0F0FF9IW}.dta
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_13_RiskSA.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1733181106512786453_tpsa.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1733770556752552682_tpsa.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1733975219371264268_StandOFood.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1734064926339783032_DreamDayWedding.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1734138545102340396_CradleOfRome.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1734218006490304541_fgt_nt.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1734574217974426501_NannyMania.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1734665880525205081_Chocolatier.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1734857026890675653_DreamDayHoneymoon.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735203619255007462_cafe_mahjongg.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735298867411954191_JanesHotel.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735298871427823377_Buildalot.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735332760179754021_mahjong_artifacts2.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735412093184537187_FifthGrader.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735440880506640620_game.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735487178842813608_BurgerShop.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735487185404192426_Diner Dash - Hometown Hero.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735593457893816117_FashionFits.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735678674579125647_farm.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735712431131640262_Christmasville.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735757935950282769_HomeSweetHome_EN.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735927907515273935__SeasonMatch.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1735956467598569750_PizzaChef.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1736081597559632487_Go Go Gourmet.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1736312358277035355_magic_farm.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1736504682024887893_CookingAcademy.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1736506294217585046_TravelAgency.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1736918953586239885_RanchRush.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737105747303349637_StandOFood2.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737316011922868991_CakeMania3.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737342774456136353_diner dash - seasonal snack pack.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737342787861387939_cookingdash.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737360030692068635_CinemaTycoon2MovieMania.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737389799521078800_PageantPrincess.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737461926914382955_Avatar - Path of Zuko.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737559008499650805_AliceGreenfingers2.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737615036220106568_Farm.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_1737773248108941409_Home Sweet Home Christmas Edition.ifn.stdat
c:\documents and settings\All Users\Application Data\iWin Games\drm\drm_207_GemShop.ifn.stdat
C:\pv.exe
c:\windows\ASSE.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IWINTRUSTED
-------\Service_iWinTrusted
((((((((((((((((((((((((( Files Created from 2009-03-03 to 2009-04-03 )))))))))))))))))))))))))))))))
.
2009-04-02 05:47 . 2009-04-02 05:47 <DIR> d-------- c:\documents and settings\Jenkins Admin\Application Data\preetlfx
2009-04-01 20:02 . 2009-04-01 20:02 54,156 --ah----- c:\windows\QTFont.qfn
2009-04-01 20:02 . 2009-04-01 20:02 1,409 --a------ c:\windows\QTFont.for
2009-03-31 22:33 . 2009-03-31 22:33 20,159 --a------ c:\windows\system32\AAWService_2009_03_31_22_33_11.dmp
2009-03-31 21:58 . 2009-03-31 21:58 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-03-31 20:41 . 2009-03-09 14:06 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-03-31 20:35 . 2009-03-09 14:06 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-03-31 20:33 . 2009-03-31 20:33 <DIR> d-------- c:\program files\Lavasoft
2009-03-31 19:07 . 2009-03-31 19:07 110 --a------ c:\documents and settings\All Users\Application Data\MostFunGameId.bin
2009-03-31 18:53 . 2009-03-31 20:33 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-31 17:30 . 2009-03-31 17:30 22,058 --a------ c:\windows\system32\AAWService_2009_03_31_17_30_45.dmp
2009-03-30 22:38 . 2009-03-30 22:38 22,581 --a------ c:\windows\system32\AAWService_2009_03_30_22_38_17.dmp
2009-03-30 22:27 . 2009-03-30 22:27 20,636 --a------ c:\windows\system32\AAWService_2009_03_30_22_27_01.dmp
2009-03-30 20:25 . 2009-03-30 20:25 22,485 --a------ c:\windows\system32\AAWService_2009_03_30_20_25_49.dmp
2009-03-29 14:43 . 2009-03-29 14:43 22,276 --a------ c:\windows\system32\AAWService_2009_03_29_14_43_22.dmp
2009-03-29 14:14 . 2009-03-29 14:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-22 12:19 . 2009-03-22 12:19 917,504 --a------ c:\windows\system32\FLASH.OCX
2009-03-22 12:04 . 2009-03-22 12:04 <DIR> d-------- c:\documents and settings\Jenkins Admin\Application Data\InstallShield
2009-03-22 12:03 . 2009-03-31 20:35 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-03-22 12:03 . 2009-03-22 12:03 <DIR> d-------- c:\program files\epson
2009-03-22 12:03 . 2009-03-22 12:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\EPSON
2009-03-22 12:02 . 2009-03-22 12:02 52 --a------ c:\windows\EPSNX200.ini
2009-03-22 12:01 . 2007-07-13 00:00 71,680 --a------ c:\windows\system32\escwiad.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-03 00:20 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-01 23:07 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2009-04-01 00:07 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-29 18:11 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-22 17:24 --------- d-----w c:\program files\Google
2009-03-22 17:18 --------- d-----w c:\program files\Yahoo!
2009-03-22 17:11 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-07 03:52 --------- d-----w c:\documents and settings\Jenkins Admin\Application Data\HP
2009-01-17 04:34 47,360 ----a-w c:\documents and settings\Jenkins Admin\Application Data\pcouffin.sys
2008-08-13 22:54 1,276 ----a-w c:\documents and settings\Jenkins Admin\Application Data\wklnhst.dat
2006-11-28 23:55 756 ----a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2006-01-30 00:21 774,144 ----a-w c:\program files\RngInterstitial.dll
2008-11-13 00:31 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008111220081113\index.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\Jenkins Admin\Application Data\preetlfx ----
2009-04-02 05:48 65536 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\cert8.db
2009-04-02 05:48 2048 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\cookies.sqlite
2009-04-02 05:48 0 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\places.sqlite-journal
2009-04-02 05:47 9736 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\pluginreg.dat
2009-04-02 05:47 96173 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\xpti.dat
2009-04-02 05:47 569 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\localstore.rdf
2009-04-02 05:47 4096 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\formhistory.sqlite
2009-04-02 05:47 367 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\prefs.js
2009-04-02 05:47 207 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\compatibility.ini
2009-04-02 05:47 2048 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\webappsstore.sqlite
2009-04-02 05:47 2048 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\permissions.sqlite
2009-04-02 05:47 16384 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\secmod.db
2009-04-02 05:47 16384 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\key3.db
2009-04-02 05:47 131072 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\places.sqlite
2009-04-02 05:47 127820 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\Profiles\z0j9z49r.default\compreg.dat
2009-04-02 05:47 111 --a------ c:\documents and settings\Jenkins Admin\Application Data\preetlfx\profiles.ini
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\progra~1\MESSEN~1\Msmsgs.exe" [2005-08-31 1658592]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"EPSON Stylus NX200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIEFA.EXE" [2007-12-13 188928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 52840]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-11-10 180269]
"InstantAccess"="c:\program files\TextBridge Pro Millennium\Bin\InstantAccess.exe" [2001-10-04 49152]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022]
"LogitechGalleryRepair"="c:\program files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 155648]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-11-16 282624]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 517768]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2004-08-23 35528]
c:\documents and settings\Jenkins Admin\Start Menu\Programs\Startup\
MostFun.lnk - c:\program files\MostFun\Bin\MostFun.exe [2007-08-28 147456]
Yahoo! Widget Engine.lnk - c:\program files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe [2007-07-20 2913584]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-07 00:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StxTrayMenu]
--a------ 2007-01-18 14:20 190008 c:\program files\Seagate\SystemTray\StxMenuMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"<NO NAME>"=
"LogitechImageStudioTray"=c:\program files\Logitech\ImageStudio\LogiTray.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\Msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Battlefront II PS2 Server\\BattlefrontII.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Battlefront PS2 Server\\battlefront.exe"=
"c:\\Program Files\\MostFun\\Bin\\MostFun.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-31 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
R2 Seagate Sync Service;Seagate Sync Service;c:\program files\Seagate\Sync\SeaSyncServices.exe [2007-01-18 24120]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-19 101936]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fd1d5186-77a7-11dd-bd18-0015f26ad17d}]
\Shell\AutoRun\command - J:\Autorun.exe /run
\Shell\Shell00\Command - J:\Autorun.exe /run
\Shell\Shell01\Command - J:\Autorun.exe /action
\Shell\Shell02\Command - J:\Autorun.exe /uninstall
.
Contents of the 'Scheduled Tasks' folder
2009-04-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 14:06]
2009-04-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2009-03-27 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - HP_Administrator.job
- c:\progra~1\NORTON~2\Navw32.exe [2007-05-23 12:13]
2007-01-29 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 15:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: {FD163A9A-A3D8-4F7D-8224-32F81AC29EDA} - hxxp://video.vividas.com/CDN1/5029_paramount/en/web/player/vivid_ocx.jpeg
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-03 18:40:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(588)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\arservice.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Norton AntiVirus\IWP\NPFMNTOR.EXE
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
c:\windows\ALCXMNTR.EXE
c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2009-04-03 18:48:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-03 23:48:51
ComboFix2.txt 2009-04-03 00:05:07
Pre-Run: 34,945,073,152 bytes free
Post-Run: 34,935,132,160 bytes free
327 --- E O F --- 2009-04-02 18:30:15
==========HJT Log=============
Logfile of HijackThis v1.99.1
Scan saved at 10:53:15 PM, on 4/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Seagate\Sync\SeaSyncServices.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TextBridge Pro Millennium\Bin\InstantAccess.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\MESSEN~1\Msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MostFun\Bin\MostFun.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [InstantAccess] C:\Program Files\TextBridge Pro Millennium\Bin\InstantAccess.exe /h
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\Msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [EPSON Stylus NX200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFA.EXE /FU "C:\WINDOWS\TEMP\E_S22A1.tmp" /EF "HKCU"
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) -
https://install.charter.com/diskless/bin/ssctlsma.dllO16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akamai.net/7/1540/52/200610...ex/qtplugin.cabO16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CABO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/download/ipixx.cabO16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Text%20Express%202/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) -
http://www.gamehouse.com/ghdlctl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1138490921968O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cabO16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) -
http://chat.yahoo.com/cab/yuplapp.cabO16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) -
http://www.vzwpix.com/activex/VerizonWirel...loadControl.cabO16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) -
http://eu.download.games.yahoo.com/zylom/a...zylomloader.cabO16 - DPF: {FD163A9A-A3D8-4F7D-8224-32F81AC29EDA} (VPlayer Control) -
http://video.vividas.com/CDN1/5029_paramou.../vivid_ocx.jpegO20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Seagate Sync Service - Seagate Technology LLC - C:\Program Files\Seagate\Sync\SeaSyncServices.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe
=================Kaspersky Report (man that was a long one, just short of 3 hrs.)============
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, April 3, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, April 04, 2009 01:02:43
Records in database: 2007642
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
Scan statistics:
Files scanned: 212799
Threat name: 19
Infected objects: 35
Suspicious objects: 0
Duration of the scan: 02:58:39
File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine1EB1DF8.zip Infected: Exploit.Java.ByteVerify 2
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine1EB1DF8.zip Infected: Trojan-Downloader.Java.OpenConnection.aa 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12EF6CA8.htm Infected: Trojan-Downloader.VBS.Mscount.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1E6575C6.tmp Infected: Trojan.Java.ClassLoader.ao 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29D874E6.tmp Infected: Trojan.Java.ClassLoader.ao 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39143028.tmp Infected: Trojan.Java.ClassLoader.ao 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39185A24.tmp Infected: Trojan.Java.ClassLoader.ao 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39E70481.htm Infected: Exploit.JS.Agent.fd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A773BE2.htm Infected: Exploit.JS.Agent.fd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A9B09BB.htm Infected: Exploit.JS.Agent.fd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3AA15DB4.htm Infected: Exploit.JS.Agent.fd 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3E087005.exe Infected: Trojan-Spy.Win32.SCKeyLog.cs 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\47631177.tmp Infected: Trojan.Java.ClassLoader.ao 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\57E07FED.dll Infected: not-a-virus:FraudTool.Win32.WorldSecurityOnline.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\58D31B58.mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\58DD194D.mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5C06303B.tmp Infected: Trojan.Java.ClassLoader.ao 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5C095A38.tmp Infected: Trojan.Java.ClassLoader.ao 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5CA126AC.tmp Infected: Trojan.Java.ClassLoader.ao 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB540F9.htm Infected: Exploit.JS.Agent.fd 1
C:\Documents and Settings\Jenkins Admin\Desktop\fp2006-final-3.00-setup.zip Infected: Hoax.JS.BadJoke.RJump 1
C:\Documents and Settings\Jenkins Admin\My Documents\My Music3 Track 3.wma Infected: Trojan-Downloader.WMA.Wimad.k 1
C:\Documents and Settings\Jenkins Admin\My Documents\My Music\Top of Charts - 2003 (song).wma Infected: Trojan-Downloader.WMA.Wimad.k 1
C:\Documents and Settings\Jenkins Admin\My Documents\My Music\TOTALLY HIP TRACK.wma Infected: Trojan-Downloader.WMA.Wimad.k 1
C:\Program Files\Evrsoft First Page 2006\Iscripts\Page Details\crazy-window.izs Infected: Hoax.JS.BadJoke.RJump 1
C:\Program Files\iWin.com\Cinema Tycoon 2\GLWorker.exe Infected: Trojan-Spy.Win32.SCKeyLog.hh 1
C:\Program Files\iWin.com\Dream Day Honeymoon\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.bc 1
C:\Program Files\iWin.com\Heroes of Hellas\GLWorker.exe Infected: Trojan-Spy.Win32.SCKeyLog.fo 1
C:\Program Files\iWin.com\Nanny Mania\GameLauncher.exe Infected: Trojan-Dropper.Win32.Irsd.ai 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACahxlrgmd.dll.vir Infected: Trojan.Win32.TDSS.vsz 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACfxgkidtb.dll.vir Infected: Packed.Win32.Tdss.f 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UAClqqqnmie.dll.vir Infected: Trojan.Win32.Tdss.ror 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACulnssncg.dll.vir Infected: Trojan.Win32.TDSS.vta 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwgrxadqo.dll.vir Infected: Trojan.Win32.Tdss.why 1
The selected area was scanned.