Hello there Balde81,
As requested I removed the pdfforge toolbar.
Ran Combofix and here are the two log files:
ComboFix.txt:ComboFix 09-06-04.06 - HP3PL 06/05/2009 10:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1578 [GMT 2:00]
Running from: c:\documents and settings\hp3pl\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-05 to 2009-06-05 )))))))))))))))))))))))))))))))
.
2009-06-04 22:28 . 2008-12-01 11:47 4244744 ----a-w- c:\windows\system32\qtp-mt334.dll
2009-06-04 22:28 . 2008-12-01 11:47 40368 ----a-w- c:\windows\system32\drivers\hotcore3.sys
2009-06-04 22:28 . 2008-12-01 11:46 247560 ----a-w- c:\windows\system32\prgiso.dll
2009-06-04 22:28 . 2008-12-01 11:47 13576 ----a-w- c:\windows\system32\wnaspi32.dll
2009-06-04 22:27 . 2009-06-04 22:27 -------- d-----w- c:\program files\Paragon Software
2009-06-04 09:56 . 2009-06-04 09:56 -------- d-----w- c:\documents and settings\hp3pl\Application Data\Uniblue
2009-06-03 19:28 . 2009-06-03 19:28 -------- d-----w- c:\program files\Trend Micro
2009-06-03 19:21 . 2009-06-03 18:19 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-03 18:19 . 2009-06-03 18:17 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-03 18:19 . 2009-06-03 18:19 -------- dc----w- c:\windows\system32\DRVSTORE
2009-06-03 18:19 . 2009-06-03 18:19 314200 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-03 18:19 . 2009-06-03 18:19 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-03 18:19 . 2009-06-03 18:19 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-03 18:19 . 2009-06-03 18:19 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-03 18:19 . 2009-06-03 18:19 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-03 18:19 . 2009-06-03 18:19 294240 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-03 18:19 . 2009-06-03 18:19 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-03 18:18 . 2009-06-03 18:18 1630048 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-03 18:17 . 2009-06-03 18:17 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-03 18:17 . 2009-06-03 18:17 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-03 18:17 . 2009-06-03 18:17 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-03 18:17 . 2009-06-03 18:17 640360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-03 18:17 . 2009-06-03 18:17 540536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-03 18:17 . 2009-06-03 18:17 559464 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-03 18:17 . 2009-06-03 18:17 2352456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-03 18:17 . 2009-06-03 18:17 627536 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-03 18:17 . 2009-06-03 18:17 518488 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-03 18:17 . 2009-06-03 18:17 1005904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-03 18:01 . 2009-06-03 18:01 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-03 18:01 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-03 18:01 . 2009-06-03 18:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-03 17:23 . 2009-06-03 17:24 -------- d-----w- c:\program files\ERUNT
2009-06-02 18:26 . 2009-06-02 18:26 -------- d-----w- c:\program files\SourceTec
2009-05-28 13:33 . 2009-05-28 13:41 -------- d-----w- c:\program files\AutoIt3
2009-05-28 12:32 . 2009-05-28 12:32 -------- d-----w- c:\program files\AutoHotkey
2009-05-13 18:11 . 2009-05-19 19:03 -------- d-----w- c:\program files\xampp
2009-05-10 09:27 . 2009-05-10 09:27 -------- d-----w- c:\program files\MSXML 4.0
2009-05-10 08:58 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2009-05-10 08:58 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-05-10 08:58 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-05-10 08:58 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
2009-05-10 08:58 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-05-10 08:58 . 2009-02-09 12:10 729088 ------w- c:\windows\system32\dllcache\lsasrv.dll
2009-05-10 08:58 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-05-10 08:58 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-10 08:58 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-05-10 08:56 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-05-10 08:56 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-05-10 08:15 . 2009-05-10 08:15 -------- d-----w- c:\windows\system32\scripting
2009-05-10 08:15 . 2009-05-10 08:15 -------- d-----w- c:\windows\l2schemas
2009-05-10 08:15 . 2009-05-10 08:15 -------- d-----w- c:\windows\system32\en
2009-05-10 01:02 . 2008-04-14 00:11 397312 ------w- c:\windows\system32\mmcex.dll
2009-05-08 20:52 . 2009-05-08 20:52 -------- d-----w- c:\program files\AVG
2009-05-08 11:11 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2009-05-08 11:11 . 2009-05-08 11:14 -------- d-----w- c:\program files\PDFCreator
2009-05-08 11:11 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2009-05-07 18:00 . 2009-05-07 18:00 -------- d-----w- c:\documents and settings\hp3pl\Local Settings\Application Data\oDesk
2009-05-07 17:59 . 2009-05-07 18:00 -------- d-----w- c:\program files\oDesk
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-04 22:27 . 2004-04-15 21:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-04 21:58 . 2009-04-08 19:40 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-06-04 15:13 . 2007-02-07 21:51 -------- d-----w- c:\program files\IrfanView
2009-06-03 18:01 . 2006-05-29 17:40 -------- d-----w- c:\program files\Lavasoft
2009-06-03 13:41 . 2008-05-05 10:30 -------- d-----w- c:\documents and settings\hp3pl\Application Data\Canon
2009-06-02 18:28 . 2009-02-09 20:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-26 07:40 . 2003-06-19 15:08 87944 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-05-17 14:55 . 2006-10-23 21:19 -------- d-----w- c:\program files\HighJackThis
2009-05-16 21:04 . 2008-04-16 19:19 -------- d-----w- c:\documents and settings\hp3pl\Application Data\FileZilla
2009-05-13 20:24 . 2006-01-31 12:45 -------- d-----w- c:\program files\QuickTime
2009-05-13 15:48 . 2008-06-27 22:55 -------- d-----w- c:\program files\Spybot
2009-05-07 12:44 . 2006-05-29 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-05 19:36 . 2009-05-05 19:36 -------- d-----w- c:\program files\Sothink DHTML Menu 9
2009-05-05 19:36 . 2009-05-05 19:36 -------- d-----w- c:\program files\Common Files\SourceTec
2009-04-29 22:38 . 2009-04-29 22:38 -------- d-----w- c:\program files\Rainlendar2
2009-04-26 20:34 . 2009-04-26 20:34 -------- d-----w- c:\program files\The Regex Coach
2009-04-24 23:54 . 2006-05-29 17:40 -------- d-----w- c:\documents and settings\hp3pl\Application Data\Lavasoft
2009-04-24 20:19 . 2008-10-12 18:17 -------- d-----w- c:\program files\Agent Ransack
2009-04-11 21:45 . 2009-04-11 21:45 -------- d-----w- c:\program files\The Guide
2009-04-09 20:01 . 2009-04-09 20:01 -------- d-----w- c:\program files\MP3 Converter
2009-04-08 19:40 . 2009-04-08 19:40 -------- d-----w- c:\documents and settings\hp3pl\Application Data\Thunderbird
2009-03-26 07:20 . 2009-05-05 19:36 82432 ----a-w- c:\windows\system32\msxml4r.dll
2009-03-26 07:20 . 2009-05-05 19:36 44544 ----a-w- c:\windows\system32\msxml4a.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-03-05 2260480]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-08-13 405504]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2009-02-21 4333568]
"Google Update"="c:\documents and settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-24 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-24 335872]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
"ChkAdmin"="c:\progra~1\Compaq\COMPAQ~1\CHKADMIN.EXE" [2003-05-12 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-01-10 180269]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-03 518488]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-05-30 88267]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-3-28 113664]
Wireless-G Notebook Adapter.lnk - c:\program files\Linksys\Wireless-G Notebook Adapter\Gcc.exe [2006-10-7 36864]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC654325-1273-C2A9-2B7C-45A29BCE2FBD}"= "c:\program files\Stardock\Fences\DesktopDock.dll" [2009-02-25 517480]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Irmon"=2 (0x2)
"DefWatch"=2 (0x2)
"btwdins"=2 (0x2)
"MDM"=2 (0x2)
"DfwWebAgent"=2 (0x2)
"CPQALERT"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\ScanSoft\\OmniPageSE\\EregEng\\NAVBrowser.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\xampp\\apache\\bin\\httpd.exe"=
"c:\\Program Files\\xampp\\mysql\\bin\\mysqld.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:*:Disabled:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:*:Disabled:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [6/5/2009 12:28 AM 40368]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/3/2009 8:19 PM 64160]
R1 ClntMgmt;HP Client Management Driver;c:\windows\system32\drivers\Clntmgmt.sys [6/3/2005 10:01 PM 55336]
R2 cpqWebDmi;Insight Web Agent;c:\progra~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe [6/3/2005 10:06 PM 24576]
R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [12/3/2006 5:37 PM 114944]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [4/16/2004 12:47 AM 182101]
R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [4/16/2004 12:47 AM 5689]
R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;c:\windows\system32\drivers\WPC54Gv3.SYS [11/30/2006 11:54 PM 610816]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 9:06 PM 1005904]
S2 RIOUSB;RioPort.Com Rio500 USB Driver;c:\windows\system32\drivers\RioUsb.sys [4/16/2007 11:42 PM 15152]
S3 Am772;AMD Alchemy Solutions Wireless 802.11 Adapter;c:\windows\system32\drivers\Am772.sys [7/26/2006 1:20 PM 174278]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [6/3/2005 9:40 PM 17408]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [5/21/2008 1:42 PM 64000]
S3 TIACXLN;22M WLAN Adapter;c:\windows\system32\DRIVERS\tiacxln.sys --> c:\windows\system32\DRIVERS\tiacxln.sys [?]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [2/25/2004 11:22 PM 322560]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - HOTCORE3
.
Contents of the 'Scheduled Tasks' folder
2009-06-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:17]
2009-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 16:13]
2009-06-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1980588459-256428701-3204507890-1006.job
- c:\documents and settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-24 15:20]
2009-06-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
HKLM-Run-QuickTime Task - c:\program files\QuickTime\qttask.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - c:\progra~1\VideoGet\Plugins\VIDEOG~1.DLL
Handler: schmap-help - {2CF664A0-5EA6-47B5-884C-433A60145F78} - c:\program files\Schmap\Schmap Player\schmapdoclib.dll
DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} - hxxps://www.p3.postbank.nl/sesam/CAX.cab
DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} - hxxps://gto.postbank.nl/GTO/PBGNX.cab
FF - ProfilePath - c:\documents and settings\hp3pl\Application Data\Mozilla\Firefox\Profiles\n3dc9n2k.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|http://reddit.com/|https://login.yahoo.com/config/mail?.intl=us
FF - plugin: c:\documents and settings\hp3pl\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-05 10:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(824)
c:\windows\system32\Ati2evxx.dll
c:\program files\Funk Software\Funk Client\odLogin.dll
- - - - - - - > 'explorer.exe'(3720)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Stardock\Fences\DesktopDock.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
.
Completion time: 2009-06-05 10:54
ComboFix-quarantined-files.txt 2009-06-05 08:53
Pre-Run: 4,159,889,408 bytes free
Post-Run: 4,288,339,968 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
231 --- E O F --- 2009-05-22 12:18
dds.txt:
DDS (Ver_09-05-14.01) - NTFSx86
Run by HP3PL at 10:59:36.72 on Fri 06/05/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1362 [GMT 2:00]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\ssoftsrv.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Documents and Settings\hp3pl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\hp3pl\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot\TeaTimer.exe
uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe"
uRun: [Rainlendar2] c:\program files\rainlendar2\Rainlendar2.exe
uRun: [Google Update] "c:\documents and settings\hp3pl\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [ChkAdmin] c:\progra~1\compaq\compaq~1\CHKADMIN.EXE
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wireless-g notebook adapter\Gcc.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - c:\progra~1\videoget\plugins\VIDEOG~1.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot\SDHelper.dll
DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} - hxxps://www.p3.postbank.nl/sesam/CAX.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {62789780-B744-11D0-986B-00609731A21D} -
ftp://ftp.giskit.com/pub/mapguide/mgaxctrl.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} - hxxps://gto.postbank.nl/GTO/PBGNX.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4795/mcfscan.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: schmap-help - {2CF664A0-5EA6-47B5-884C-433A60145F78} - c:\program files\schmap\schmap player\schmapdoclib.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: Fences: {ec654325-1273-c2a9-2b7c-45a29bce2fbd} - c:\program files\stardock\fences\DesktopDock.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\hp3pl\applic~1\mozilla\firefox\profiles\n3dc9n2k.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|http://reddit.com/|https://login.yahoo.com/config/mail?.intl=us
FF - plugin: c:\documents and settings\hp3pl\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll
============= SERVICES / DRIVERS ===============
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2009-6-5 40368]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-3 64160]
R1 ClntMgmt;HP Client Management Driver;c:\windows\system32\drivers\Clntmgmt.sys [2005-6-3 55336]
R2 cpqWebDmi;Insight Web Agent;c:\progra~1\compaq\compaq~1\cpqweb~1\WebDmi.exe [2005-6-3 24576]
R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [2006-12-3 114944]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [2004-4-16 182101]
R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [2004-4-16 5689]
R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;c:\windows\system32\drivers\WPC54Gv3.SYS [2006-11-30 610816]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904]
S2 RIOUSB;RioPort.Com Rio500 USB Driver;c:\windows\system32\drivers\RioUsb.sys [2007-4-16 15152]
S3 Am772;AMD Alchemy Solutions Wireless 802.11 Adapter;c:\windows\system32\drivers\Am772.sys [2006-7-26 174278]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [2005-6-3 17408]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
S3 TIACXLN;22M WLAN Adapter;c:\windows\system32\drivers\tiacxln.sys --> c:\windows\system32\drivers\tiacxln.sys [?]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [2004-2-25 322560]
=============== Created Last 30 ================
2009-06-05 10:46 <DIR> a-dshr-- C:\cmdcons
2009-06-05 10:39 161,792 a------- c:\windows\SWREG.exe
2009-06-05 10:39 154,624 a------- c:\windows\PEV.exe
2009-06-05 10:39 98,816 a------- c:\windows\sed.exe
2009-06-05 10:39 <DIR> --ds---- C:\ComboFix
2009-06-05 00:28 4,244,744 a------- c:\windows\system32\qtp-mt334.dll
2009-06-05 00:28 247,560 a------- c:\windows\system32\prgiso.dll
2009-06-05 00:28 40,368 a------- c:\windows\system32\drivers\hotcore3.sys
2009-06-05 00:28 13,576 a------- c:\windows\system32\wnaspi32.dll
2009-06-05 00:27 <DIR> --d----- c:\program files\Paragon Software
2009-06-04 11:56 <DIR> --d----- c:\docume~1\hp3pl\applic~1\Uniblue
2009-06-03 21:28 <DIR> --d----- c:\program files\Trend Micro
2009-06-03 21:21 15,688 a------- c:\windows\system32\lsdelete.exe
2009-06-03 20:19 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-06-03 20:01 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-02 20:26 17,542 a------- c:\windows\SothinkTree.ico
2009-06-02 20:26 <DIR> --d----- c:\program files\SourceTec
2009-05-28 15:33 <DIR> --d----- c:\program files\AutoIt3
2009-05-28 14:32 <DIR> --d----- c:\program files\AutoHotkey
2009-05-13 20:11 <DIR> --d----- c:\program files\xampp
2009-05-10 11:27 <DIR> --d----- c:\program files\MSXML 4.0
2009-05-10 10:58 284,160 -------- c:\windows\system32\dllcache\pdh.dll
2009-05-10 10:58 473,600 -------- c:\windows\system32\dllcache\fastprox.dll
2009-05-10 10:58 401,408 -------- c:\windows\system32\dllcache\rpcss.dll
2009-05-10 10:58 227,840 -------- c:\windows\system32\dllcache\wmiprvse.exe
2009-05-10 10:58 110,592 -------- c:\windows\system32\dllcache\services.exe
2009-05-10 10:58 729,088 -------- c:\windows\system32\dllcache\lsasrv.dll
2009-05-10 10:58 617,472 -------- c:\windows\system32\dllcache\advapi32.dll
2009-05-10 10:58 453,120 -------- c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-10 10:58 714,752 -------- c:\windows\system32\dllcache\ntdll.dll
2009-05-10 10:56 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-05-10 10:56 1,203,922 -------- c:\windows\system32\dllcache\sysmain.sdb
2009-05-10 10:56 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
2009-05-10 10:15 <DIR> --d----- c:\windows\system32\scripting
2009-05-10 10:15 <DIR> --d----- c:\windows\l2schemas
2009-05-10 10:15 <DIR> --d----- c:\windows\system32\en
2009-05-10 03:03 276,992 -------- c:\windows\system32\wmphoto.dll
2009-05-10 03:02 397,312 -------- c:\windows\system32\mmcex.dll
2009-05-08 22:52 <DIR> --d----- c:\program files\AVG
2009-05-08 13:11 137,000 a------- c:\windows\system32\MSMAPI32.OCX
2009-05-08 13:11 116,224 a------- c:\windows\system32\pdfcmnnt.dll
2009-05-08 13:11 23,552 a------- c:\windows\system32\MSMPIDE.DLL
2009-05-08 13:11 <DIR> --d----- c:\program files\PDFCreator
2009-05-07 19:59 <DIR> --d----- c:\program files\oDesk
==================== Find3M ====================
2009-05-26 09:40 87,944 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-03-26 09:20 82,432 a------- c:\windows\system32\msxml4r.dll
2009-03-26 09:20 44,544 a------- c:\windows\system32\msxml4a.dll
2009-03-21 16:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
2009-03-10 22:18 934,792 -------- c:\windows\system32\dllcache\WgaTray.exe
2009-03-10 22:18 239,496 -------- c:\windows\system32\dllcache\wgaLogon.dll
2008-07-15 22:58 21,336 a------- c:\docume~1\hp3pl\applic~1\GDIPFONTCACHEV1.DAT
============= FINISH: 10:59:56.69 ===============