alyoob
Member
ComboFix 08-02.03.1 - HP_Owner 2008-02-03 19:25:04.2 - NTFSx86
Running from: C:\Documents and Settings\HP_Owner.YOUR-03667082DE\My Documents\Alfred stuff\Software Installer\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\inst.exe
C:\temp\tn3
C:\WINDOWS\ORUN32.EXE
C:\WINDOWS\system32\CMMGR32.EXE
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
hxxp:/
.
((((((((((((((((((((((((( Files Created from 2008-01-04 to 2008-02-04 )))))))))))))))))))))))))))))))
.
2008-02-03 19:31 . 2008-02-03 19:31 <DIR> d-------- C:\temp\tn3
2008-02-03 12:26 . 2008-02-03 12:26 167,545 --a--c--- C:\WINDOWS\system32\drivers\core.cache.dsk
2008-02-03 12:26 . 2008-02-03 12:26 86,144 --a--c--- C:\WINDOWS\system32\drivers\wmilibb.sys
2008-02-03 11:27 . 2008-02-03 15:31 <DIR> d----c--- C:\Downloads
2008-02-03 09:01 . 2008-02-03 09:01 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Nero
2008-02-01 18:19 . 2008-02-03 11:38 54,156 --ah-c--- C:\WINDOWS\QTFont.qfn
2008-02-01 18:19 . 2008-02-01 18:19 1,409 --a--c--- C:\WINDOWS\QTFont.for
2008-01-28 20:39 . 2008-01-28 20:39 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-01-28 20:36 . 2008-01-28 20:36 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-01-27 18:37 . 2008-01-27 18:38 <DIR> d-------- C:\Program Files\Java
2008-01-27 10:49 . 1995-12-14 02:10 1,682,688 -ra--c--- C:\WINDOWS\QTINSTAL.EXE
2008-01-27 10:49 . 1995-12-14 02:10 92,384 -ra--c--- C:\WINDOWS\QTW16DEL.EXE
2008-01-27 10:49 . 2006-02-11 20:51 191 --a--c--- C:\WINDOWS\QTW.INI
2008-01-27 10:49 . 2002-10-03 13:42 34 --a--c--- C:\WINDOWS\Q3version.ini
2008-01-24 09:16 . 2004-12-14 08:07 708,608 -ra--c--- C:\WINDOWS\system32\hpotiop.dll
2008-01-24 09:16 . 2004-12-14 08:07 278,528 -ra--c--- C:\WINDOWS\system32\hpgwiamd.dll
2008-01-24 09:16 . 2004-12-14 08:07 229,376 -ra--c--- C:\WINDOWS\system32\hpovst08.dll
2008-01-24 09:09 . 2008-01-24 09:37 68,964 --a--c--- C:\WINDOWS\hpoins05.dat
2008-01-24 09:09 . 2004-12-14 08:07 19,696 -----c--- C:\WINDOWS\hpomdl05.dat
2008-01-21 16:22 . 2008-01-21 16:22 12,518,948 -----c--- C:\avg7qt.dat
2008-01-21 16:09 . 2008-02-03 18:33 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\AVG7
2008-01-21 16:08 . 2008-01-21 16:08 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-21 16:08 . 2008-02-03 12:34 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-20 21:26 . 2008-01-28 20:43 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-20 19:53 . 2008-01-20 19:53 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\ICAClient
2008-01-19 09:16 . 2008-01-27 08:40 <DIR> d-------- C:\Program Files\DivX
2008-01-19 07:27 . 2008-01-27 09:10 5,632 --ahsc--- C:\WINDOWS\system32\Thumbs.db
2008-01-18 21:08 . 2008-01-18 21:08 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\IObit
2008-01-14 21:20 . 2008-01-14 21:21 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Vso
2008-01-14 21:20 . 2008-01-14 21:20 47,360 --a--c--- C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-14 21:20 . 2008-01-14 21:21 47,360 --a--c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\pcouffin.sys
2008-01-12 18:42 . 2008-01-12 18:42 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\snap
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\STATES
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\SHOTS
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\ROMDATA
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\INPUT
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\EEPROM
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\CONFIG
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\CHEATS
2008-01-12 18:27 . 2008-01-12 18:38 25 --a--c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\RomInfo.dat
2008-01-12 18:27 . 2008-01-12 18:39 0 --a--c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\FAVORITES.DAT
2008-01-12 07:03 . 2008-01-12 07:09 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a--c--- C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a--c--- C:\WINDOWS\system32\QuickTime.qts
2008-01-06 19:56 . 2007-01-18 04:00 3,968 --a--c--- C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-05 14:42 . 2008-01-05 14:42 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Comodo
2008-01-05 14:42 . 2008-01-05 14:42 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Comodo
2008-01-05 14:40 . 2008-01-04 16:15 281 --a--c--- C:\boot.ini.comodofirewall
2008-01-04 12:55 . 2007-09-24 23:31 69,632 --a--c--- C:\WINDOWS\system32\javacpl.cpl
2008-01-04 09:11 . 2008-01-04 09:11 917,504 --a--c--- C:\WINDOWS\system32\FLASH.OCX
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-03 17:15 --------- d-----w C:\Program Files\iTunes
2008-02-03 17:15 --------- d-----w C:\Program Files\iPod
2008-02-03 17:14 --------- d-----w C:\Program Files\QuickTime
2008-02-02 14:22 --------- d-----w C:\Program Files\Blubster
2008-01-29 04:41 --------- d-----w C:\Program Files\MSBuild
2008-01-29 04:41 --------- d-----w C:\Program Files\Microsoft Works
2008-01-27 19:35 --------- dc----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-27 17:18 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-27 16:47 15,582 -c--a-w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\wklnhst.dat
2008-01-24 17:34 --------- d-----w C:\Program Files\Common Files\HP
2008-01-24 17:32 --------- d-----w C:\Program Files\HP
2008-01-24 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-01-24 16:57 --------- d-----w C:\Program Files\Hewlett-Packard
2008-01-24 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-22 00:08 --------- dc----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-21 22:18 --------- d-----w C:\Program Files\InterVideo
2008-01-20 01:08 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-01-20 01:08 --------- d-----w C:\Program Files\Spyware Terminator
2008-01-19 22:19 --------- d-----w C:\Program Files\WinClamAVShield
2008-01-19 05:06 --------- d-----w C:\Program Files\IObit
2008-01-12 15:03 --------- d-----w C:\Program Files\Common Files\Scanner
2008-01-10 23:21 --------- d-----w C:\Program Files\SpywareGuard
2008-01-07 04:30 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Apple Computer
2008-01-05 19:14 --------- d-----w C:\Program Files\EsetOnlineScanner
2008-01-04 16:24 --------- d-----w C:\Program Files\IntelliMover Data Transfer Demo
2008-01-04 16:09 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Spyware Terminator
2008-01-02 21:40 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-02 21:30 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Sereniti
2008-01-02 21:26 --------- d-----w C:\Program Files\Common Files\AOL
2008-01-02 21:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-31 06:29 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Yahoo!
2007-12-31 06:28 --------- dc----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-30 22:27 --------- d-----w C:\Program Files\Common Files\xing shared
2007-12-30 22:26 --------- d-----w C:\Program Files\Common Files\Real
2007-12-30 17:48 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Motive
2007-12-30 17:23 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\SUPERAntiSpyware.com
2007-12-30 01:05 --------- d-----w C:\Program Files\WindSolutions
2007-12-29 16:44 --------- d-----w C:\Program Files\interMute
2007-12-29 03:53 138,752 -c--a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-12-27 20:38 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\AdobeUM
2007-12-27 04:39 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\CopyTransPhoto
2007-12-27 03:53 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\CopyTrans
2007-12-27 03:21 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\SyncGuardian
2007-12-27 03:21 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\iLibs
2007-12-27 03:21 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\iCloner
2007-12-27 02:18 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Talkback
2007-12-27 01:24 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Template
2007-12-27 01:19 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Viewpoint
2007-12-27 01:18 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\AOL
2007-12-27 01:14 1,865 -csha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM503_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M384_J160_7AMD_8Athlon 64_92.41_#060605_N10390900_Z11C1048C_G10396330.MRK
2007-12-27 01:06 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2007-12-27 01:05 --------- d-----w C:\Program Files\SiS VGA Utilities V3.63
2007-12-26 17:23 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\SiteAdvisor
2007-12-26 17:06 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\PC Suite
2007-12-26 17:06 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\Nokia
2007-12-26 17:06 --------- dc----w C:\Documents and Settings\All Users\Application Data\PC Suite
2007-12-26 17:05 --------- d-----w C:\Program Files\DIFX
2007-12-26 17:04 --------- d-----w C:\Program Files\PC Connectivity Solution
2007-12-26 17:02 --------- dc----w C:\Documents and Settings\All Users\Application Data\Installations
2007-12-25 05:56 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\FileVOoM
2007-12-25 05:56 --------- d-----w C:\Program Files\iPod Download
2007-12-20 22:22 --------- d-----w C:\Program Files\Premium Booster
2007-12-20 22:16 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\iolo
2007-12-20 22:16 --------- dc----w C:\Documents and Settings\All Users\Application Data\iolo
2007-12-19 02:45 16,750 -c--a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2007-12-17 15:47 572 -c--a-w C:\Documents and Settings\HP_Owner\RomInfo.dat
2007-12-15 19:41 --------- d-----w C:\Program Files\Google
2007-12-14 23:00 --------- d-----w C:\Program Files\Norton Security Scan
2007-12-12 03:15 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-12 00:20 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\AVG7
2007-12-10 18:34 1,824 -c--a-w C:\reg_AppID_CLSID.reg,.reg
2007-12-10 17:57 --------- d-----w C:\Program Files\Windows Installer Clean Up
2007-12-10 17:57 --------- d-----w C:\Program Files\MSECACHE
2007-12-09 21:04 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-03-05 00:29 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 19:02 61440]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 19:43 233472]
"SiSPower"="SiSPower.dll" [2004-09-24 08:49 49152 C:\WINDOWS\system32\SiSPower.dll]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 16:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 15:57 81920]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"SmartRAM"="C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe" [2007-10-29 16:43 662016]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 04:00 158208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-21 16:18 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a--c--- 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a--c--- 2005-07-12 05:17 50776 C:\Program Files\America Online 9.0\AOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoTBar]
c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2008-01-21 16:18 579072 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_Run]
--a------ 2008-01-21 16:18 219136 C:\PROGRA~1\Grisoft\AVG7\avgw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2007-04-12 13:23 42032 C:\Program Files\Common Files\AOL\1199309204\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 15:49 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon06]
--a--c--- 2004-06-07 17:42 659456 C:\WINDOWS\system32\hphmon06.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
--a------ 2004-06-07 17:53 49152 c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 1998-05-07 15:04 52736 c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a--c--- 2004-08-20 21:55 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a--c--- 2004-04-17 12:41 196608 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
--a------ 2004-10-14 20:54 253952 c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
--a------ 2003-12-17 23:31 118784 C:\Windows\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 16:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
--a--c--- 2007-11-04 12:21 2832384 C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a--c--- 2006-10-18 11:36 1294336 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-12-30 14:26 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 07:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a--c--- 2006-11-03 18:20 866584 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVG Anti-Spyware Guard"=2 (0x2)
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2007-12-28 19:53]
R1 wmilibb;wmilibb;C:\WINDOWS\system32\drivers\wmilibb.sys [2008-02-03 12:26]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 02:55:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-04 03:34:47 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-04 23:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 19:32:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\America Online 9.0\shellmon.exe
.
**************************************************************************
.
Completion time: 2008-02-03 19:38:34 - machine was rebooted [HP_Owner]
ComboFix-quarantined-files.txt 2008-02-04 03:38:30
.
2007-12-27 05:09:38 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:48 PM, on 2/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn6\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn6\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn6\yt.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SmartRAM] C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe /m
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E704581-CCAE-46D2-9C64-20D724B3624E} (UnagiAx Class) - http://radaol-prod-web-rr.streamops.aol.com/mediaplugin/3.0.84.2/win32/unagi3.0.84.2.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 7165 bytes
Running from: C:\Documents and Settings\HP_Owner.YOUR-03667082DE\My Documents\Alfred stuff\Software Installer\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\inst.exe
C:\temp\tn3
C:\WINDOWS\ORUN32.EXE
C:\WINDOWS\system32\CMMGR32.EXE
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
hxxp:/
.
((((((((((((((((((((((((( Files Created from 2008-01-04 to 2008-02-04 )))))))))))))))))))))))))))))))
.
2008-02-03 19:31 . 2008-02-03 19:31 <DIR> d-------- C:\temp\tn3
2008-02-03 12:26 . 2008-02-03 12:26 167,545 --a--c--- C:\WINDOWS\system32\drivers\core.cache.dsk
2008-02-03 12:26 . 2008-02-03 12:26 86,144 --a--c--- C:\WINDOWS\system32\drivers\wmilibb.sys
2008-02-03 11:27 . 2008-02-03 15:31 <DIR> d----c--- C:\Downloads
2008-02-03 09:01 . 2008-02-03 09:01 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Nero
2008-02-01 18:19 . 2008-02-03 11:38 54,156 --ah-c--- C:\WINDOWS\QTFont.qfn
2008-02-01 18:19 . 2008-02-01 18:19 1,409 --a--c--- C:\WINDOWS\QTFont.for
2008-01-28 20:39 . 2008-01-28 20:39 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-01-28 20:36 . 2008-01-28 20:36 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-01-27 18:37 . 2008-01-27 18:38 <DIR> d-------- C:\Program Files\Java
2008-01-27 10:49 . 1995-12-14 02:10 1,682,688 -ra--c--- C:\WINDOWS\QTINSTAL.EXE
2008-01-27 10:49 . 1995-12-14 02:10 92,384 -ra--c--- C:\WINDOWS\QTW16DEL.EXE
2008-01-27 10:49 . 2006-02-11 20:51 191 --a--c--- C:\WINDOWS\QTW.INI
2008-01-27 10:49 . 2002-10-03 13:42 34 --a--c--- C:\WINDOWS\Q3version.ini
2008-01-24 09:16 . 2004-12-14 08:07 708,608 -ra--c--- C:\WINDOWS\system32\hpotiop.dll
2008-01-24 09:16 . 2004-12-14 08:07 278,528 -ra--c--- C:\WINDOWS\system32\hpgwiamd.dll
2008-01-24 09:16 . 2004-12-14 08:07 229,376 -ra--c--- C:\WINDOWS\system32\hpovst08.dll
2008-01-24 09:09 . 2008-01-24 09:37 68,964 --a--c--- C:\WINDOWS\hpoins05.dat
2008-01-24 09:09 . 2004-12-14 08:07 19,696 -----c--- C:\WINDOWS\hpomdl05.dat
2008-01-21 16:22 . 2008-01-21 16:22 12,518,948 -----c--- C:\avg7qt.dat
2008-01-21 16:09 . 2008-02-03 18:33 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\AVG7
2008-01-21 16:08 . 2008-01-21 16:08 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-21 16:08 . 2008-02-03 12:34 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-20 21:26 . 2008-01-28 20:43 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-20 19:53 . 2008-01-20 19:53 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\ICAClient
2008-01-19 09:16 . 2008-01-27 08:40 <DIR> d-------- C:\Program Files\DivX
2008-01-19 07:27 . 2008-01-27 09:10 5,632 --ahsc--- C:\WINDOWS\system32\Thumbs.db
2008-01-18 21:08 . 2008-01-18 21:08 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\IObit
2008-01-14 21:20 . 2008-01-14 21:21 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Vso
2008-01-14 21:20 . 2008-01-14 21:20 47,360 --a--c--- C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-14 21:20 . 2008-01-14 21:21 47,360 --a--c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\pcouffin.sys
2008-01-12 18:42 . 2008-01-12 18:42 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\snap
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\STATES
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\SHOTS
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\ROMDATA
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\INPUT
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\EEPROM
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\CONFIG
2008-01-12 18:27 . 2008-01-12 18:27 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\CHEATS
2008-01-12 18:27 . 2008-01-12 18:38 25 --a--c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\RomInfo.dat
2008-01-12 18:27 . 2008-01-12 18:39 0 --a--c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\FAVORITES.DAT
2008-01-12 07:03 . 2008-01-12 07:09 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a--c--- C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a--c--- C:\WINDOWS\system32\QuickTime.qts
2008-01-06 19:56 . 2007-01-18 04:00 3,968 --a--c--- C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-05 14:42 . 2008-01-05 14:42 <DIR> d----c--- C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Comodo
2008-01-05 14:42 . 2008-01-05 14:42 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Comodo
2008-01-05 14:40 . 2008-01-04 16:15 281 --a--c--- C:\boot.ini.comodofirewall
2008-01-04 12:55 . 2007-09-24 23:31 69,632 --a--c--- C:\WINDOWS\system32\javacpl.cpl
2008-01-04 09:11 . 2008-01-04 09:11 917,504 --a--c--- C:\WINDOWS\system32\FLASH.OCX
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-03 17:15 --------- d-----w C:\Program Files\iTunes
2008-02-03 17:15 --------- d-----w C:\Program Files\iPod
2008-02-03 17:14 --------- d-----w C:\Program Files\QuickTime
2008-02-02 14:22 --------- d-----w C:\Program Files\Blubster
2008-01-29 04:41 --------- d-----w C:\Program Files\MSBuild
2008-01-29 04:41 --------- d-----w C:\Program Files\Microsoft Works
2008-01-27 19:35 --------- dc----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-27 17:18 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-27 16:47 15,582 -c--a-w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\wklnhst.dat
2008-01-24 17:34 --------- d-----w C:\Program Files\Common Files\HP
2008-01-24 17:32 --------- d-----w C:\Program Files\HP
2008-01-24 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-01-24 16:57 --------- d-----w C:\Program Files\Hewlett-Packard
2008-01-24 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-22 00:08 --------- dc----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-21 22:18 --------- d-----w C:\Program Files\InterVideo
2008-01-20 01:08 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-01-20 01:08 --------- d-----w C:\Program Files\Spyware Terminator
2008-01-19 22:19 --------- d-----w C:\Program Files\WinClamAVShield
2008-01-19 05:06 --------- d-----w C:\Program Files\IObit
2008-01-12 15:03 --------- d-----w C:\Program Files\Common Files\Scanner
2008-01-10 23:21 --------- d-----w C:\Program Files\SpywareGuard
2008-01-07 04:30 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Apple Computer
2008-01-05 19:14 --------- d-----w C:\Program Files\EsetOnlineScanner
2008-01-04 16:24 --------- d-----w C:\Program Files\IntelliMover Data Transfer Demo
2008-01-04 16:09 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Spyware Terminator
2008-01-02 21:40 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-02 21:30 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Sereniti
2008-01-02 21:26 --------- d-----w C:\Program Files\Common Files\AOL
2008-01-02 21:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-31 06:29 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Yahoo!
2007-12-31 06:28 --------- dc----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-30 22:27 --------- d-----w C:\Program Files\Common Files\xing shared
2007-12-30 22:26 --------- d-----w C:\Program Files\Common Files\Real
2007-12-30 17:48 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Motive
2007-12-30 17:23 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\SUPERAntiSpyware.com
2007-12-30 01:05 --------- d-----w C:\Program Files\WindSolutions
2007-12-29 16:44 --------- d-----w C:\Program Files\interMute
2007-12-29 03:53 138,752 -c--a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-12-27 20:38 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\AdobeUM
2007-12-27 04:39 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\CopyTransPhoto
2007-12-27 03:53 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\CopyTrans
2007-12-27 03:21 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\SyncGuardian
2007-12-27 03:21 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\iLibs
2007-12-27 03:21 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\iCloner
2007-12-27 02:18 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Talkback
2007-12-27 01:24 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Template
2007-12-27 01:19 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Viewpoint
2007-12-27 01:18 --------- dc----w C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\AOL
2007-12-27 01:14 1,865 -csha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_PP164AA-ABA a810n_YC_0Pavi_QMXM503_E51NAheBLU3_47_ISalmon_SASUSTek Computer INC._V1.04_B3.04_T041029_WXH2_L409_M384_J160_7AMD_8Athlon 64_92.41_#060605_N10390900_Z11C1048C_G10396330.MRK
2007-12-27 01:06 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2007-12-27 01:05 --------- d-----w C:\Program Files\SiS VGA Utilities V3.63
2007-12-26 17:23 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\SiteAdvisor
2007-12-26 17:06 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\PC Suite
2007-12-26 17:06 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\Nokia
2007-12-26 17:06 --------- dc----w C:\Documents and Settings\All Users\Application Data\PC Suite
2007-12-26 17:05 --------- d-----w C:\Program Files\DIFX
2007-12-26 17:04 --------- d-----w C:\Program Files\PC Connectivity Solution
2007-12-26 17:02 --------- dc----w C:\Documents and Settings\All Users\Application Data\Installations
2007-12-25 05:56 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\FileVOoM
2007-12-25 05:56 --------- d-----w C:\Program Files\iPod Download
2007-12-20 22:22 --------- d-----w C:\Program Files\Premium Booster
2007-12-20 22:16 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\iolo
2007-12-20 22:16 --------- dc----w C:\Documents and Settings\All Users\Application Data\iolo
2007-12-19 02:45 16,750 -c--a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2007-12-17 15:47 572 -c--a-w C:\Documents and Settings\HP_Owner\RomInfo.dat
2007-12-15 19:41 --------- d-----w C:\Program Files\Google
2007-12-14 23:00 --------- d-----w C:\Program Files\Norton Security Scan
2007-12-12 03:15 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-12 00:20 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\AVG7
2007-12-10 18:34 1,824 -c--a-w C:\reg_AppID_CLSID.reg,.reg
2007-12-10 17:57 --------- d-----w C:\Program Files\Windows Installer Clean Up
2007-12-10 17:57 --------- d-----w C:\Program Files\MSECACHE
2007-12-09 21:04 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-03-05 00:29 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 19:02 61440]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 19:43 233472]
"SiSPower"="SiSPower.dll" [2004-09-24 08:49 49152 C:\WINDOWS\system32\SiSPower.dll]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 16:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 15:57 81920]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"SmartRAM"="C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe" [2007-10-29 16:43 662016]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 04:00 158208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-21 16:18 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a--c--- 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a--c--- 2005-07-12 05:17 50776 C:\Program Files\America Online 9.0\AOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoTBar]
c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2008-01-21 16:18 579072 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_Run]
--a------ 2008-01-21 16:18 219136 C:\PROGRA~1\Grisoft\AVG7\avgw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2007-04-12 13:23 42032 C:\Program Files\Common Files\AOL\1199309204\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 15:49 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon06]
--a--c--- 2004-06-07 17:42 659456 C:\WINDOWS\system32\hphmon06.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
--a------ 2004-06-07 17:53 49152 c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 1998-05-07 15:04 52736 c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a--c--- 2004-08-20 21:55 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a--c--- 2004-04-17 12:41 196608 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
--a------ 2004-10-14 20:54 253952 c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
--a------ 2003-12-17 23:31 118784 C:\Windows\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 16:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
--a--c--- 2007-11-04 12:21 2832384 C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a--c--- 2006-10-18 11:36 1294336 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-12-30 14:26 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 07:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a--c--- 2006-11-03 18:20 866584 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVG Anti-Spyware Guard"=2 (0x2)
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2007-12-28 19:53]
R1 wmilibb;wmilibb;C:\WINDOWS\system32\drivers\wmilibb.sys [2008-02-03 12:26]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 02:55:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-04 03:34:47 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-04 23:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 19:32:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\America Online 9.0\shellmon.exe
.
**************************************************************************
.
Completion time: 2008-02-03 19:38:34 - machine was rebooted [HP_Owner]
ComboFix-quarantined-files.txt 2008-02-04 03:38:30
.
2007-12-27 05:09:38 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:48 PM, on 2/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn6\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn6\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn6\yt.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SmartRAM] C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe /m
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E704581-CCAE-46D2-9C64-20D724B3624E} (UnagiAx Class) - http://radaol-prod-web-rr.streamops.aol.com/mediaplugin/3.0.84.2/win32/unagi3.0.84.2.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 7165 bytes
Last edited: