I think this is the VirScan.org portion that you needed:
VirSCAN of c:\windows\system32\chg.exe
VirSCAN.org Scanned Report :
Scanned time : 2008/10/02 18:38:49 (CDT)
Scanner results: All Scanners reported not find malware!
File Name : sgswpu.exe
File Size : 19456 byte
File Type : data
MD5 : d82d6a77ed67e5fa62e8cee9a2073e4b
SHA1 : 7d9fb08dfd4a1a6c52d54ad00a715e4bfef3e330
Online report :
http://virscan.org/report/95fd1bfcb475a0ac...c5c164dbc4.htmlScanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.14 2008.10.02 2008-10-02 1.42 -
AhnLab V3 2008.10.02.01 2008.10.02 2008-10-02 0.91 -
AntiVir 7.8.1.34 7.0.6.241 2008-10-02 2.34 -
Arcavir 1.0.5 200810021817 2008-10-02 1.20 -
Authentium 5.1.1 200810012118 2008-10-01 0.01 -
AVAST! 3.0.1 081002-0 2008-10-02 0.69 -
AVG 7.5.52.442 270.7.5/1703 2008-10-02 1.59 -
BitDefender 7.60825.1831294 7.21145 2008-10-03 3.10 -
CA (VET) 9.0.0.143 31.6.6125 2008-10-02 5.38 -
ClamAV 0.94 8372 2008-10-02 0.01 -
Comodo 2.11 2.0.0.664 2008-10-02 0.40 -
CP Secure 1.1.0.715 2008.10.02 2008-10-02 5.95 -
Dr.Web 4.44.0.9170 2008.10.02 2008-10-02 3.25 -
ewido 4.0.0.2 2008.10.02 2008-10-02 2.78 -
F-Prot 4.4.4.56 20081002 2008-10-02 1.01 -
F-Secure 5.51.6100 2008.10.03.01 2008-10-03 3.46 -
Fortinet 2.81-3.113 9.610 2008-10-02 0.15 -
ViRobot 20081002 2008.10.02 2008-10-02 0.40 -
Ikarus T3.1.01.34 2008.10.02.71570 2008-10-02 3.39 -
JiangMin 11.0.706 2008.10.02 2008-10-02 1.22 -
Kaspersky 5.5.10 2008.10.02 2008-10-02 0.02 -
KingSoft 2008.9.8.18 2008.10.2.18 2008-10-02 0.62 -
McAfee 5.3.00 5397 2008-10-02 1.99 -
Microsoft 1.4005 2008.10.02 2008-10-02 3.85 -
mks_vir 2.01 2008.10.03 2008-10-03 2.58 -
Norman 5.93.01 5.93.00 2008-10-02 5.03 -
Panda 9.05.01 2008.10.02 2008-10-02 2.14 -
Trend Micro 8.700-1004 5.576.11 2008-10-02 0.02 -
Quick Heal 9.50 2008.10.01 2008-10-01 1.79 -
Rising 20.0 20.63.62.00 2008-09-28 0.25 -
Sophos 2.79.0 4.34 2008-10-03 1.71 -
Sunbelt 3.1.1675.1 2261 2008-09-26 0.41 -
Symantec 1.3.0.24 20081002.004 2008-10-02 0.07 -
nProtect 2008-10-02.00 2194932 2008-10-02 4.14 -
The Hacker 6.3.1.0 v00099 2008-10-02 0.41 -
VBA32 3.12.8.6 20081001.2041 2008-10-01 1.22 -
VirusBuster 4.5.11.10 10.89.5/633834 2008-10-02 0.82 -
VirScan of c:\windows\is-QGESV.exe
VirSCAN.org Scanned Report :
Scanned time : 2008/11/26 13:51:28 (CST)
Scanner results: All Scanners reported not find malware!
File Name : is-LHFKP.exe
File Size : 775168 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 9bd0dc2d4c0ddda3d37733e3d45a3aaa
SHA1 : 7d81ae5fbf367b2592bb2d27bcdd6d9e7469f3be
Online report :
http://virscan.org/report/1a8ddcdb420714d1...93dbccf1f6.htmlScanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.26 20081126233104 2008-11-26 4.36 -
AhnLab V3 2008.11.26.03 2008.11.26 2008-11-26 1.09 -
AntiVir 7.9.0.35 7.1.0.143 2008-11-26 1.58 -
Antiy 2.0.18 20081126.1749264 2008-11-26 0.12 -
Arcavir 1.0.5 200811231052 2008-11-23 1.33 -
Authentium 5.1.1 200811260609 2008-11-26 1.18 -
AVAST! 3.0.1 081126-0 2008-11-26 0.07 -
AVG 7.5.52.442 270.9.10/1813 2008-11-26 1.78 -
BitDefender 7.81008.2265781 7.22104 2008-11-27 2.19 -
CA (VET) 9.0.0.143 31.6.6228 2008-11-25 5.87 -
ClamAV 0.94.1 8684 2008-11-26 0.21 -
Comodo 2.11 2.0.0.712 2008-11-20 0.50 -
CP Secure 1.1.0.715 2008.11.27 2008-11-27 6.61 -
Dr.Web 4.44.0.9170 2008.11.26 2008-11-26 3.87 -
ewido 4.0.0.2 2008.11.26 2008-11-26 4.08 -
F-Prot 4.4.4.56 20081125 2008-11-25 1.19 -
F-Secure 5.51.6100 2008.11.26.08 2008-11-26 0.09 -
Fortinet 2.81-3.117 9.747 2008-11-26 0.27 -
GData 19.1680/19.123 20081126 2008-11-26 2.78 -
ViRobot 20081126 2008.11.26 2008-11-26 0.42 -
Ikarus T3.1.01.45 2008.11.26.71916 2008-11-26 3.58 -
JiangMin 11.0.706 2008.11.26 2008-11-26 2.28 -
Kaspersky 5.5.10 2008.11.26 2008-11-26 0.06 -
KingSoft 2008.9.8.18 2008.11.26.20 2008-11-26 0.70 -
McAfee 5.3.00 5446 2008-11-26 2.63 -
Microsoft 1.4104 2008.11.26 2008-11-26 4.42 -
mks_vir 2.01 2008.11.17 2008-11-17 2.72 -
Norman 5.93.01 5.93.00 2008-11-26 5.48 -
Panda 9.05.01 2008.11.25 2008-11-25 3.39 -
Trend Micro 8.700-1004 5.678.07 2008-11-26 0.03 -
Quick Heal 10.00 2008.11.26 2008-11-26 1.03 -
Rising 20.0 21.05.22.00 2008-11-26 2.14 -
Sophos 2.80.0 4.35 2008-11-27 2.12 -
Sunbelt 4474 4474 2008-11-04 1.76 -
Symantec 1.3.0.24 20081126.003 2008-11-26 0.23 -
nProtect 2008-11-26.00 2629064 2008-11-26 3.25 -
The Hacker 6.3.1.1 v00163 2008-11-25 0.57 -
VBA32 3.12.8.9 20081126.1036 2008-11-26 1.79 -
VirusBuster 4.5.11.10 10.94.7/729311 2008-11-26 1.65 -
VirScan of c:\windows\is-QGESV.msg
VirSCAN.org Scanned Report :
Scanned time : 2008/12/01 12:16:28 (CST)
Scanner results: All Scanners reported not find malware!
File Name : is-QGESV.msg
File Size : 10194 byte
File Type : data
MD5 : d2813196d9e8a3a41d20a3a2fdd84859
SHA1 : 5c4d2930585407ccbd6abe506f10495a87882c5e
Online report :
http://virscan.org/report/9256cd07dacc23e7...372dd8ab50.htmlScanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.27 20081202013306 2008-12-02 3.15 -
AhnLab V3 2008.12.02.00 2008.12.02 2008-12-02 1.07 -
AntiVir 7.9.0.36 7.1.0.169 2008-12-01 1.58 -
Antiy 2.0.18 20081201.1772504 2008-12-01 0.12 -
Arcavir 1.0.5 200811291125 2008-11-29 1.21 -
Authentium 5.1.1 200812011629 2008-12-01 1.02 -
AVAST! 3.0.1 081130-0 2008-11-30 0.74 -
AVG 7.5.52.442 270.9.12/1822 2008-12-01 1.73 -
BitDefender 7.81008.2312248 7.22224 2008-12-02 2.13 -
CA (VET) 9.0.0.143 31.6.6234 2008-11-28 2.32 -
ClamAV 0.94.1 8704 2008-12-02 0.00 -
Comodo 2.11 2.0.0.712 2008-11-20 1.62 -
CP Secure 1.1.0.715 2008.12.01 2008-12-01 5.92 -
Dr.Web 4.44.0.9170 2008.12.01 2008-12-01 3.62 -
ewido 4.0.0.2 2008.12.01 2008-12-01 3.39 -
F-Prot 4.4.4.56 20081201 2008-12-01 1.04 -
F-Secure 5.51.6100 2008.12.01.03 2008-12-01 0.03 -
Fortinet 2.81-3.117 9.765 2008-12-01 0.18 -
GData 19.1760/19.130 20081201 2008-12-01 2.79 -
ViRobot 20081129 2008.11.29 2008-11-29 0.41 -
Ikarus T3.1.01.45 2008.12.01.71941 2008-12-01 3.70 -
JiangMin 11.0.706 2008.12.01 2008-12-01 2.06 -
Kaspersky 5.5.10 2008.12.01 2008-12-01 0.03 -
KingSoft 2008.9.8.18 2008.12.1.20 2008-12-01 1.41 -
McAfee 5.3.00 5451 2008-12-01 2.51 -
Microsoft 1.4104 2008.12.01 2008-12-01 4.14 -
mks_vir 2.01 2008.12.01 2008-12-01 2.62 -
Norman 5.93.01 5.93.00 2008-12-01 5.81 -
Panda 9.05.01 2008.11.30 2008-11-30 3.64 -
Trend Micro 8.700-1004 5.684.09 2008-12-01 0.02 -
Quick Heal 10.00 2008.12.01 2008-12-01 0.91 -
Rising 20.0 21.06.02.00 2008-12-01 0.65 -
Sophos 2.81.2 4.36 2008-12-02 1.92 -
Sunbelt 4674 4674 2008-11-04 0.51 -
Symantec 1.3.0.24 20081201.006 2008-12-01 0.20 -
nProtect 2008-12-01.00 2632093 2008-12-01 4.82 -
The Hacker 6.3.1.1 v00169 2008-11-29 0.43 -
VBA32 3.12.8.9 20081201.0945 2008-12-01 1.36 -
VirusBuster 4.5.11.10 10.94.12/729518 2008-12-01 0.92 -
Here is the Combofix.txt
ComboFix 08-11-30.02 - Sederstrom 2008-12-01 12:43:31.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1270 [GMT -6:00]
Running from: c:\documents and settings\Sederstrom\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sederstrom\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
c:\windows\system32\drivers\updatee.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Viewpoint
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Viewpoint\Common\VistaBoot.sdll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VETScriptInterpreter.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_UPDATEE
-------\Legacy_VIEWPOINT_MANAGER_SERVICE
-------\Service_updatee
-------\Service_Viewpoint Manager Service
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.
2008-11-30 22:59 . 2008-11-30 22:59 <DIR> d-------- c:\windows\ERUNT
2008-11-30 22:49 . 2008-11-30 23:59 <DIR> d-------- C:\SDFix
2008-11-21 12:09 . 2008-11-21 12:09 <DIR> d-------- c:\program files\Trend Micro
2008-11-20 17:39 . 2008-11-20 17:40 127 --a------ c:\windows\system32\MRT.INI
2008-11-20 17:34 . 2008-10-24 05:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-20 17:33 . 2008-09-04 11:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-20 17:30 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2008-11-20 14:52 . 2008-11-20 14:52 850 --a------ c:\windows\system32\ProductTweaks.xml
2008-11-20 14:52 . 2008-11-20 14:52 385 --a------ c:\windows\system32\user_gensett.xml
2008-11-20 14:46 . 2008-11-20 14:46 <DIR> d-------- c:\windows\system32\logs
2008-11-20 14:43 . 2008-11-20 14:43 <DIR> d-------- c:\documents and settings\Sederstrom\Application Data\BitDefender
2008-11-20 14:41 . 2008-11-20 14:42 <DIR> d-------- c:\program files\BitDefender
2008-11-20 14:41 . 2008-11-20 14:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\BitDefender
2008-11-20 14:39 . 2008-11-20 14:42 <DIR> d-------- c:\program files\Common Files\BitDefender
2008-11-20 02:29 . 2008-11-20 02:29 <DIR> d-------- C:\VundoFix Backups
2008-11-20 01:36 . 2008-11-30 23:50 <DIR> d-------- c:\program files\SpyZooka
2008-11-20 01:35 . 2008-11-20 01:35 <DIR> d-------- c:\program files\Common Files\Download Manager
2008-11-20 00:31 . 2008-11-20 00:31 <DIR> d-------- c:\program files\Lavasoft
2008-11-20 00:31 . 2008-11-20 00:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-20 00:29 . 2008-11-20 00:29 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-19 22:15 . 2008-11-19 22:15 775,168 --a------ c:\windows\is-QGESV.exe
2008-11-19 22:15 . 2008-11-19 22:15 10,194 --a------ c:\windows\is-QGESV.msg
2008-11-19 22:15 . 2008-11-19 22:15 277 --a------ c:\windows\is-QGESV.lst
2008-11-19 20:03 . 2008-11-19 20:04 <DIR> d-------- c:\program files\Google
2008-11-18 12:54 . 2008-11-18 12:54 <DIR> d-------- c:\program files\Microsoft Baseline Security Analyzer 2
2008-11-18 12:54 . 2008-11-18 12:56 <DIR> d-------- c:\documents and settings\Sederstrom\SecurityScans
2008-11-18 12:51 . 2008-11-18 12:51 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-11-18 12:49 . 2008-11-18 12:50 <DIR> d-------- c:\program files\Common Files\Adobe
2008-11-18 12:46 . 2008-11-19 19:32 <DIR> d-------- c:\program files\NOS
2008-11-18 12:46 . 2008-11-19 19:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2008-11-09 19:06 . 2008-11-09 19:06 <DIR> d-------- c:\program files\Webroot
2008-11-09 19:06 . 2008-11-09 19:06 <DIR> d-------- c:\documents and settings\Sederstrom\Application Data\Webroot
2008-11-09 19:06 . 2008-11-09 19:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Webroot
2008-11-09 19:06 . 2008-11-20 14:43 <DIR> d-------- C:\Binaries
2008-11-09 19:06 . 2008-11-13 17:11 1,553,272 --a------ c:\windows\WRSetup.dll
2008-11-09 15:41 . 2008-11-09 16:34 227 --a------ c:\windows\wininit.ini
2008-11-09 15:33 . 2008-11-19 22:10 164 --a------ C:\install.dat
2008-11-09 10:59 . 2008-11-18 12:33 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-09 10:59 . 2008-11-18 12:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-09 10:50 . 2008-11-09 10:50 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Wyzo
2008-11-09 10:50 . 2008-11-09 10:50 <DIR> d-------- c:\documents and settings\LocalService\Application Data\.wyzo
2008-11-09 10:46 . 2008-11-09 22:35 <DIR> d--hs---- c:\windows\U2VkZXJzdHJvbQ
2008-11-09 10:46 . 2008-11-20 13:28 <DIR> d-------- c:\windows\system32\sX3i02
2008-11-09 10:46 . 2008-11-09 10:46 <DIR> d-------- c:\windows\system32\prt
2008-11-09 10:46 . 2008-11-09 10:46 <DIR> d-------- c:\windows\system32\db
2008-11-09 10:46 . 2008-11-09 22:35 <DIR> d-------- c:\windows\system32\AX5
2008-11-09 10:46 . 2008-11-09 10:46 <DIR> d-------- c:\temp\PRE45
2008-11-09 10:46 . 2008-11-30 23:10 <DIR> d-------- C:\Temp
2008-11-09 10:35 . 2008-11-09 10:35 <DIR> d-------- c:\documents and settings\Sederstrom\Application Data\.wyzo
2008-11-09 10:25 . 2008-11-24 22:30 <DIR> d-------- c:\documents and settings\Sederstrom\Application Data\LimeWire
2008-11-09 10:24 . 2008-11-09 10:24 <DIR> d-------- c:\windows\Sun
2008-11-09 10:24 . 2008-11-09 10:24 <DIR> d-------- c:\program files\Sun
2008-11-09 10:24 . 2008-11-09 10:24 <DIR> d-------- c:\program files\Java
2008-11-09 10:24 . 2008-11-09 10:24 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-09 10:24 . 2008-11-09 10:24 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-09 10:21 . 2008-11-09 10:22 <DIR> d-------- c:\program files\LimeWire
2008-11-09 09:17 . 2008-11-09 09:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\AVS4YOU
2008-11-09 09:16 . 2008-11-09 10:16 <DIR> d-------- c:\program files\Common Files\AVSMedia
2008-11-09 09:16 . 2008-11-09 10:16 <DIR> d-------- c:\program files\AVS4YOU
2008-11-09 09:16 . 2007-09-27 15:22 524,288 --a------ c:\windows\system32\xvidcore.dll
2008-11-09 09:16 . 2007-09-27 15:22 261,632 --a------ c:\windows\system32\mcdvd_32.dll
2008-11-09 09:16 . 2003-05-22 00:50 156,910 --a------ c:\windows\WMSysPr8.prx
2008-11-09 09:16 . 2007-09-27 15:22 139,264 --a------ c:\windows\system32\xvidvfw.dll
2008-11-09 09:16 . 2003-05-22 00:50 82,944 --a------ c:\windows\system32\vct3216.acm
2008-11-09 09:16 . 2004-02-04 22:11 81,920 --a------ c:\windows\system32\AC3ACM.acm
2008-11-09 09:16 . 2004-09-06 17:06 53,248 --a------ c:\windows\system32\xvid.ax
2008-11-09 09:16 . 2003-05-22 00:50 38,912 --a------ c:\windows\system32\alf2cd.acm
2008-11-09 09:16 . 2003-05-21 13:50 24,576 --a------ c:\windows\system32\msxml3a.dll
2008-11-09 09:16 . 2000-03-14 21:55 13,239 --a------ c:\windows\system32\Scg726.acm
2008-11-08 22:53 . 2008-11-08 22:53 <DIR> d-------- C:\DECCHECK
2008-11-08 22:46 . 2008-11-08 22:46 <DIR> d-------- c:\documents and settings\Sederstrom\Application Data\Apple Computer
2008-11-08 22:45 . 2008-11-08 22:45 <DIR> d-------- c:\program files\iTunes
2008-11-08 22:45 . 2008-11-08 22:45 <DIR> d-------- c:\program files\iPod
2008-11-08 22:45 . 2008-11-08 22:45 <DIR> d-------- c:\program files\Bonjour
2008-11-08 22:45 . 2008-11-08 22:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-08 22:45 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-11-08 22:45 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-11-08 22:44 . 2008-11-08 22:45 <DIR> d-------- c:\program files\QuickTime
2008-11-08 22:44 . 2008-11-08 22:44 <DIR> d-------- c:\program files\Apple Software Update
2008-11-08 22:44 . 2008-11-08 22:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-08 22:43 . 2008-11-08 22:43 <DIR> d-------- c:\program files\Common Files\Apple
2008-11-08 22:43 . 2008-11-08 22:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-11-08 19:32 . 2008-11-08 19:32 <DIR> d-------- c:\documents and settings\Sederstrom\Application Data\DivX
2008-11-08 19:30 . 2008-11-08 19:31 <DIR> d-------- c:\program files\DivX
2008-11-07 22:46 . 2008-11-07 22:46 376 --a------ c:\windows\ODBC.INI
2008-11-07 22:45 . 2008-11-07 22:46 <DIR> d-------- c:\windows\ShellNew
2008-11-05 21:51 . 2008-10-20 00:48 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Intel
2008-11-05 21:51 . 2008-11-09 14:20 <DIR> d-------- c:\documents and settings\Administrator
2008-11-05 21:38 . 2008-11-05 21:38 <DIR> d-------- c:\program files\Windows Mobile Device Handbook
2008-11-05 21:38 . 2008-11-07 22:46 <DIR> d-------- c:\program files\Microsoft ActiveSync
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-12 22:02 29,808 ----a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 22:02 23,152 ----a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 22:02 170,608 ----a-w c:\windows\system32\drivers\ssidrv.sys
2008-10-30 05:35 --------- d-----w c:\documents and settings\Sederstrom\Application Data\acccore
2008-10-30 05:35 --------- d-----w c:\documents and settings\All Users\Application Data\AOL OCP
2008-10-30 05:34 --------- d-----w c:\program files\Common Files\AOL
2008-10-30 05:34 --------- d-----w c:\program files\AIM6
2008-10-30 05:34 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-10-30 05:34 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-10-30 05:34 --------- d-----w c:\documents and settings\All Users\Application Data\acccore
2008-10-29 05:10 --------- d-----w c:\documents and settings\Sederstrom\Application Data\Windows Search
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-10-28 22:35 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-10-28 22:35 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\DivX.dll
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-20 17:48 --------- d-----w c:\documents and settings\Sederstrom\Application Data\Windows Desktop Search
2008-10-20 17:47 --------- d-----w c:\program files\Windows Desktop Search
2008-10-20 17:44 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-20 17:09 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-20 16:53 --------- d-----w c:\program files\MSXML 4.0
2008-10-20 06:50 --------- d-----w c:\program files\Synaptics
2008-10-20 06:50 --------- d-----w c:\program files\HPQ
2008-10-20 06:48 21,361 ----a-w c:\windows\system32\drivers\AegisP.sys
2008-10-20 06:48 21,361 ----a-w c:\windows\AegisP.sys
2008-10-20 06:48 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\Intel
2008-10-20 06:48 --------- d-----w c:\program files\Intel
2008-10-20 06:48 --------- d-----w c:\documents and settings\Sederstrom\Application Data\Intel
2008-10-20 06:48 --------- d-----w c:\documents and settings\NetworkService\Application Data\Intel
2008-10-20 06:48 --------- d-----w c:\documents and settings\LocalService\Application Data\Intel
2008-10-20 06:48 --------- d-----w c:\documents and settings\All Users\Application Data\Intel
2008-10-20 06:47 --------- d-----w c:\program files\Hewlett-Packard
2008-10-20 06:44 --------- d-----w c:\documents and settings\All Users\Application Data\ATI
2008-10-20 06:40 155,136 ----a-w c:\windows\system32\imapihp.exe
2008-10-20 06:39 753,664 ----a-w c:\windows\system32\bcm1xsup.dll
2008-10-20 06:39 724,992 ----a-w c:\windows\system32\BCMLogon.dll
2008-10-20 06:39 69,632 ----a-w c:\windows\system32\bcmwlpkt.dll
2008-10-20 06:39 65,536 ----a-w c:\windows\system32\wltrynt.dll
2008-10-20 06:39 33,664 ----a-w c:\windows\system32\drivers\BCMWLNPF.SYS
2008-10-20 06:39 24,064 ----a-w c:\windows\system32\WLTRYSVC.EXE
2008-10-20 06:39 2,682,880 ----a-w c:\windows\system32\vcredist_x86.exe
2008-10-20 06:39 2,670,592 ----a-w c:\windows\system32\WLBCGCBPRO731.DLL
2008-10-20 06:39 196,608 ----a-w c:\windows\system32\bcmwlu00.exe
2008-10-20 06:39 139,264 ----a-w c:\windows\system32\preflib.dll
2008-10-20 06:39 1,839,104 ----a-w c:\windows\system32\WLTRAY.EXE
2008-10-20 06:39 1,576,960 ----a-w c:\windows\system32\BCMWLTRY.EXE
2008-10-20 06:38 --------- d-----w c:\program files\ATI Technologies
2008-10-20 06:31 --------- d-----w c:\program files\Analog Devices
2008-10-20 06:29 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\Infineon
2008-10-20 06:25 --------- d-----w c:\program files\CONEXANT
2008-10-20 06:22 --------- d-----w c:\program files\TIVistadriver
2008-10-20 06:21 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-20 06:21 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2008-10-20 06:20 --------- d-----w c:\documents and settings\Sederstrom\Application Data\InstallShield
2008-10-20 06:16 --------- d-----w c:\program files\ActivIdentity
2008-10-20 06:14 --------- d-----w c:\program files\ProtectTools
2008-10-20 06:14 --------- d-----w c:\documents and settings\Sederstrom\Application Data\Infineon
2008-10-20 06:14 --------- d-----w c:\documents and settings\All Users\Application Data\Infineon
2008-10-20 06:13 --------- d-----w c:\documents and settings\Sederstrom\Application Data\hpqLog
2008-10-20 06:09 --------- d-----w c:\program files\Fingerprint Sensor
2008-10-20 06:07 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-20 06:03 --------- d-----w c:\documents and settings\Sederstrom\Application Data\SampleView
2008-10-20 05:55 --------- d-----w c:\documents and settings\Sederstrom\Application Data\ATI
2008-10-20 05:38 --------- d-----w c:\program files\Broadcom
2008-10-20 04:31 --------- d-----w c:\program files\Microsoft Broadband Networking
2008-10-20 03:49 --------- d-----w c:\program files\microsoft frontpage
2008-10-17 20:01 104,328 ----a-w c:\windows\system32\drivers\bdfndisf.sys
2008-10-16 20:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-09 21:31 192,512 ----a-w c:\windows\system32\txmlutil.dll
2008-09-30 22:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-25 08:03 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-09-25 08:03 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-09-25 08:03 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
2008-09-25 08:03 524,288 ----a-w c:\windows\system32\DivXsm.exe
2008-09-25 08:03 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-09-25 08:03 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-09-25 08:03 294,912 ----a-w c:\windows\system32\dpu10.dll
2008-09-25 08:03 196,608 ----a-w c:\windows\system32\dtu100.dll
2008-09-25 08:03 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-19 21:57 129,784 ----a-w c:\windows\system32\pxafs.dll
2008-09-19 21:57 120,056 ----a-w c:\windows\system32\pxcpyi64.exe
2008-09-19 21:57 118,520 ----a-w c:\windows\system32\pxinsi64.exe
2008-09-19 21:55 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-19 21:55 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-19 21:54 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\LocalService\Application Data\.wyzo ----
---- Directory of c:\documents and settings\LocalService\Application Data\Wyzo ----
2008-11-09 16:29 0 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\permissions.sqlite
2008-11-09 10:51 120 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\btdht.dat
2008-11-09 10:50 92842 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\xpti.dat
2008-11-09 10:50 8111 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\pluginreg.dat
2008-11-09 10:50 65536 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\cert8.db
2008-11-09 10:50 634 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\history.dat
2008-11-09 10:50 424 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\Settings.ini
2008-11-09 10:50 3567 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\extensions.rdf
2008-11-09 10:50 319 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\cookies.txt
2008-11-09 10:50 282 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\extensions.cache
2008-11-09 10:50 249 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\extensions.ini
2008-11-09 10:50 2048 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\search.sqlite
2008-11-09 10:50 16384 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\secmod.db
2008-11-09 10:50 16384 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\key3.db
2008-11-09 10:50 147531 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\compreg.dat
2008-11-09 10:50 146432 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\urlclassifier2.sqlite
2008-11-09 10:50 1324 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\prefs.js
2008-11-09 10:50 128 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\compatibility.ini
2008-11-09 10:50 11635 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\bookmarks.html
2008-11-09 10:50 11635 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\bookmarks.bak
2008-11-09 10:50 111 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\profiles.ini
2008-11-09 10:50 1022 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\localstore.rdf
2008-10-28 18:29 11489 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\bookmarkbackups\bookmarks-2008-11-09.html
2005-02-01 11:36 3287 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\search.rdf
2004-11-30 15:26 663 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\chrome\userContent-example.css
2004-11-30 15:26 356 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\mimeTypes.rdf
2004-11-30 15:26 1078 --a------ c:\documents and settings\LocalService\Application Data\Wyzo\Data\Profiles\k0y8fn65.default\chrome\userChrome-example.css
---- Directory of c:\documents and settings\Sederstrom\Application Data\.wyzo ----
---- Directory of c:\temp\PRE45 ----
2008-11-09 10:46 1858 --a------ c:\temp\PRE45\pG8.log
---- Directory of c:\windows\system32\AX5 ----
---- Directory of c:\windows\system32\db ----
---- Directory of c:\windows\system32\prt ----
2008-11-08 21:21 190424 --a------ c:\windows\system32\prt\PDLWI40.exe
---- Directory of c:\windows\system32\sX3i02 ----
---- Directory of c:\windows\U2VkZXJzdHJvbQ ----
((((((((((((((((((((((((((((( snapshot@2008-11-30_23.52.31.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-01 05:07:03 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-01 05:46:29 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-01 05:07:03 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-01 05:46:29 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-01 18:49:18 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_928.dat
- 2008-12-01 05:49:11 3,652 ----a-w c:\windows\Temp\wrstemp\S-1-5-18.dat
+ 2008-12-01 18:49:52 3,652 ----a-w c:\windows\Temp\wrstemp\S-1-5-18.dat
- 2008-12-01 05:49:11 4,182 ----a-w c:\windows\Temp\wrstemp\S-1-5-19.dat
+ 2008-12-01 18:49:52 4,182 ----a-w c:\windows\Temp\wrstemp\S-1-5-19.dat
- 2008-12-01 05:49:11 4,250 ----a-w c:\windows\Temp\wrstemp\S-1-5-20.dat
+ 2008-12-01 18:49:52 4,250 ----a-w c:\windows\Temp\wrstemp\S-1-5-20.dat
- 2008-12-01 05:51:02 5,040 ----a-w c:\windows\Temp\wrstemp\S-1-5-21-1957994488-1682526488-839522115-1003.dat
+ 2008-12-01 18:49:52 5,040 ----a-w c:\windows\Temp\wrstemp\S-1-5-21-1957994488-1682526488-839522115-1003.dat
- 2008-12-01 05:49:11 4,216 ----a-w c:\windows\Temp\wrstemp\S-1-5-21-1957994488-1682526488-839522115-500.dat
+ 2008-12-01 18:49:52 4,216 ----a-w c:\windows\Temp\wrstemp\S-1-5-21-1957994488-1682526488-839522115-500.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\CHCP.bat
2008-12-01 12:40 16 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000132.bat
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_9013\avxdisk.dll
2008-09-25 16:48 53248 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000117.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_9013\avxs.dll
2002-01-14 13:49 10240 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000118.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_9013\avxt.dll
2002-01-14 13:49 27136 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000119.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_9013\bdc.exe
2006-10-28 22:06 92160 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000120.exe
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_9013\bdcore.dll
2008-09-25 16:49 102400 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000116.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_9013\bdupd.dll
2005-09-03 10:28 77824 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000122.dll
c:\program files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_9013\libfn.dll
2007-06-13 00:02 178176 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000123.dll
c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
2007-02-07 00:30 74240 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000019.dll
2008-10-30 17:34 39424 c:\program files\Mozilla Firefox\components\FFComm.dll
2008-10-30 17:34 39424 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000052.dll
2008-10-30 17:34 39424 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000217.dll
c:\program files\Viewpoint\Common\ViewpointService.exe
2007-01-04 15:38 24652 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000166.exe
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
2008-02-06 18:58 262214 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000167.dll
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr.dll
2007-03-13 09:25 217158 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000169.dll
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
2008-02-06 18:57 114688 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000171.exe
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AOLUserShell.dll
2006-10-11 13:22 413766 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000172.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
2006-10-11 13:19 36864 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000173.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\JpegReader.dll
2006-10-11 13:10 122948 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000174.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Mts3Reader.dll
2006-10-11 13:10 204868 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000175.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SceneComponent.dll
2007-03-13 09:25 1282120 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000176.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SreeDMMX.dll
2006-10-11 13:15 774210 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000177.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SWFView.dll
2006-10-11 13:18 725057 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000178.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VETScriptInterpreter.dll
2006-10-11 13:16 725070 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000179.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPSpeech.dll
2006-10-11 13:22 249923 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000180.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPVideo2.dll
2006-10-11 13:21 770115 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000181.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
2007-04-16 11:07 180293 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000182.dll
c:\windows\system32\bincaz.dll
2008-11-20 13:46 120832 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000034.dll
c:\windows\system32\chg.exe
2008-11-30 23:07 114688 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000051.exe
2008-11-30 23:46 114688 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP3\A0000211.exe
c:\windows\system32\gptica.dll
2008-11-19 13:40 120832 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000036.dll
c:\windows\system32\gxeexdgd.dll
2008-11-20 13:40 75776 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000037.dll
c:\windows\system32\kcjxjlwv.dll
2008-11-20 13:46 120832 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000038.dll
c:\windows\system32\mpg4c32.dll
2007-09-27 15:22 413760 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000039.dll
c:\windows\system32\winpfz33.sys
2008-11-09 10:46 859 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000015.sys
c:\windows\system32\wvfdkcdk.dll
2008-11-19 13:40 120832 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000042.dll
c:\windows\system32\xrsoitsu.dll
2008-11-19 13:43 75776 {EC06A898-65D2-45C3-84EC-6482941135D9}\RP2\A0000043.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 --a------ c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"Google Update"="c:\documents and settings\Sederstrom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-19 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-19 39408]
"SpyZooka"="c:\program files\SpyZooka\SpyZookaLdr.exe" [2007-04-06 39656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"Recguard"="c:\windows\Sminst\Recguard.exe" [2005-12-20 1187840]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-03-09 806912]
"Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-10-09 697976]
"PTHOSTTR"="c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2007-01-09 145184]
"CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2003-12-22 17920]
"accrdsub"="c:\program files\ActivIdentity\ActivClient Mini\accrdsub.exe" [2006-04-20 176128]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-10-19 177456]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-10-20 1839104]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"AccelerometerSysTrayApplet"="c:\windows\system32\AccelerometerSt.exe" [2006-01-16 53248]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-11-01 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-11-01 1101824]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-10-27 241726]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-14 102400]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-09 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2008-10-30 741376]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 69632]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]
c:\documents and settings\Sederstrom\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-07-17 49152]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Broadband Networking.lnk - c:\windows\Installer\{06B2B442-19FE-4398-BD4B-F5C00928DD8E}\_18be6784.exe [2008-10-19 25214]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
"{D468BCE5-D18E-49A4-8EA7-34BD583659D5}"= "c:\progra~1\SpyZooka\spyguard.dll" [2005-05-07 173568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2006-04-27 14:43 98304 c:\program files\ActivIdentity\ActivClient Mini\ackpbsc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2006-04-14 14:55 94208 c:\program files\ActivIdentity\ActivClient Mini\acunlock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2007-04-30 07:19 49152 c:\windows\system32\DeviceNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-03 14:08 434176 c:\windows\system32\IfxWlxEN.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
Notification Packages REG_MULTI_SZ scecli ASWLNPkg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SMINST\\Scheduler.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-10-02 29808]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2005-11-29 36768]
R2 acachsrv;ActivClient Authentication Service;"c:\program files\ActivIdentity\ActivClient Mini\acachsrv.exe" [2006-04-12 81920]
R2 accoca;ActivClient Middleware Service;"c:\program files\ActivIdentity\ActivClient Mini\accoca.exe" [2006-05-02 135168]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [2006-02-28 14336]
R2 BDVEDISK;BDVEDISK;\??\c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-09-04 82440]
R2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" [2008-11-09 1086840]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2008-10-17 104328]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\DRIVERS\gtipci21.sys [2008-10-20 88192]
R3 IFXTPM;IFXTPM;c:\windows\system32\DRIVERS\IFXTPM.SYS [2005-10-21 36352]
S2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [2006-02-28 14336]
S3 Arrakis3;BitDefender Arrakis Server;"c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe" [2008-07-17 118784]
S3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv.sys [2007-04-23 30008]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [2007-04-30 172131]
S3 tcpip_patcher;tcpip_patcher;\??\c:\progra~1\wyzo\extensions\firetorrent@wyzo.com\components\tcpip_patcher.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd6c6ac0-9e5d-11dd-a8ad-ed90c954bd9c}]
\Shell\AutoRun\command - F:\PortableVault.exe
.
Contents of the 'Scheduled Tasks' folder
2008-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-12-01 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Sederstrom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-19 20:00]
2008-11-28 c:\windows\Tasks\wrSpySweeper_L1B68ECA27F834E2893E6FB0B9CB85CE4.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]
2008-11-28 c:\windows\Tasks\wrSpySweeper_L1B68ECA27F834E2893E6FB0B9CB85CE4.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]
2008-11-28 c:\windows\Tasks\wrSpySweeper_L1B68ECA27F834E2893E6FB0B9CB85CE4.job
- c:\","d:\" []
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-01 12:49:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1364)
c:\program files\Hewlett-Packard\IAM\bin\ocgina.dll
c:\program files\Hewlett-Packard\IAM\bin\ItMsg.dll
c:\program files\Hewlett-Packard\IAM\bin\HPBrand.dll
c:\program files\Hewlett-Packard\IAM\bin\ItTal.dll
c:\program files\Hewlett-Packard\IAM\bin\ItReports.DLL
c:\program files\ActivIdentity\ActivClient Mini\ackpbsc.dll
c:\windows\system32\ACLIBEAY.dll
c:\windows\system32\aclog.dll
c:\windows\system32\acevtsub.dll
c:\windows\system32\asphat32.dll
c:\windows\system32\acauth.dll
c:\windows\system32\acerrmes.dll
c:\windows\system32\aspcom.dll
c:\program files\ActivIdentity\ActivClient Mini\Resources\acerrmrc.dll
c:\program files\ActivIdentity\ActivClient Mini\Resources\asphatrc.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\Hewlett-Packard\IAM\Bin\BioAuth.dll
c:\program files\Hewlett-Packard\IAM\Bin\AuthWiz.dll
c:\program files\Hewlett-Packard\IAM\Bin\TpmAuth.dll
c:\program files\Hewlett-Packard\IAM\Bin\TokenAuth.dll
c:\program files\Hewlett-Packard\IAM\Bin\ittalsnap.DLL
c:\program files\Hewlett-Packard\IAM\Bin\ItVCard.dll
c:\program files\Hewlett-Packard\IAM\Bin\ASChnl.dll
c:\program files\Hewlett-Packard\IAM\Bin\ItDAC.dll
c:\program files\Hewlett-Packard\IAM\Bin\ItAuth.dll
c:\program files\Hewlett-Packard\IAM\Bin\ItVCClient.dll
c:\program files\Hewlett-Packard\IAM\Bin\TrayIcon.dll
c:\program files\Hewlett-Packard\IAM\Bin\STEngine.dll
c:\program files\Hewlett-Packard\IAM\Bin\ASBIoAT.dll
c:\windows\system32\xenroll.dll
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\ActivIdentity\ActivClient Mini\acunlock.dll
c:\windows\system32\aipingui.dll
c:\program files\ActivIdentity\ActivClient Mini\Resources\acunlockrc.dll
c:\windows\system32\DeviceNP.dll
c:\windows\system32\IfxWlxEN.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
c:\program files\BitDefender\BitDefender 2009\vsserv.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\ActivIdentity\ActivClient Mini\acevents.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\scardsvr.exe
c:\program files\Hewlett-Packard\IAM\Bin\asghost.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\windows\system32\IFXSPMGT.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\windows\system32\searchindexer.exe
c:\program files\ActivIdentity\ActivClient Mini\acevents.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\ProtectTools\Embedded Security Software\PSDrt.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\windows\system32\searchprotocolhost.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\program files\Microsoft Broadband Networking\MSBNTray.exe
c:\program files\BitDefender\BitDefender 2009\seccenter.exe
c:\windows\system32\searchfilterhost.exe
c:\program files\Webroot\WebrootSecurity\SSU.exe
.
**************************************************************************
.
Completion time: 2008-12-01 12:55:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 18:55:27
ComboFix2.txt 2008-12-01 05:53:35
Pre-Run: 87,896,907,776 bytes free
Post-Run: 87,877,017,600 bytes free
571 --- E O F --- 2008-10-30 05:32:54
And here is a new HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:58:47 PM, on 12/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hewlett-Packard\IAM\bin\asghost.exe
C:\Program Files\ActivIdentity\ActivClient Mini\acachsrv.exe
C:\Program Files\ActivIdentity\ActivClient Mini\accoca.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\Program Files\ActivIdentity\ActivClient Mini\accrdsub.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\AccelerometerSt.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ActivIdentity\ActivClient Mini\acevents.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\ProtectTools\Embedded Security Software\PSDrt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Documents and Settings\Sederstrom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe"
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\Sminst\Recguard.exe"
O4 - HKLM\..\Run: [Reminder] "C:\WINDOWS\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [Scheduler] "C:\WINDOWS\SMINST\Scheduler.exe"
O4 - HKLM\..\Run: [PTHOSTTR] "C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" /Start
O4 - HKLM\..\Run: [CognizanceTS] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient Mini\accrdsub.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] "C:\WINDOWS\system32\WLTRAY.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] "C:\WINDOWS\system32\AccelerometerSt.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Cpqset] "C:\Program Files\HPQ\Default Settings\cpqset.exe"
O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Sederstrom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpyZooka] "C:\Program Files\SpyZooka\SpyZookaLdr.exe"
O4 - S-1-5-18 Startup: CCC.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: CCC.lnk = ? (User 'Default user')
O4 - Startup: CCC.lnk = ?
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jdk...ows-i586-jc.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO20 - Winlogon Notify: ackpbsc - C:\Program Files\ActivIdentity\ActivClient Mini\ackpbsc.dll
O20 - Winlogon Notify: acunlock - C:\Program Files\ActivIdentity\ActivClient Mini\acunlock.dll
O20 - Winlogon Notify: DeviceNP - C:\WINDOWS\SYSTEM32\DeviceNP.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ActivClient Authentication Service (acachsrv) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient Mini\acachsrv.exe
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient Mini\accoca.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L.
http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\WINDOWS\system32\flcdlock.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
--
End of file - 13223 bytes
Thanks again. Let me know if I did anything wrong and I'll try it again. I think I followed all of the instructions.