Computer seems to work ok. Combo fix gave me a rootkit.zeroaccess error. Oddly enough the log says AVG anti virus still running???? I thought I uninstalled all of it completely.
here is the log
ComboFix 12-07-31.05 - HP_Administrator 08/02/2012 23:22:05.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2947 [GMT -7:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\erdnt\cache\userinit.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-07-03 to 2012-08-03 )))))))))))))))))))))))))))))))
.
.
2012-08-03 05:00 . 2012-08-03 05:00 -------- d-----w- c:\program files\VS Revo Group
2012-07-31 23:09 . 2012-07-31 23:09 -------- d-----w- c:\program files\ESET
2012-07-31 18:28 . 2012-07-31 19:01 116189 ----a-w- c:\windows\system32\drivers\klin.dat
2012-07-31 18:28 . 2012-07-31 19:01 98168 ----a-w- c:\windows\system32\drivers\klick.dat
2012-07-31 18:27 . 2012-08-03 06:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2012-07-31 18:27 . 2012-07-31 18:27 -------- d-----w- c:\program files\Kaspersky Lab
2012-07-31 08:30 . 2012-07-31 08:30 -------- d-----w- C:\TDSSKiller_Quarantine
2012-07-31 05:39 . 2012-05-31 19:25 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-07-30 21:19 . 2012-07-30 21:19 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-07-30 20:51 . 2012-07-30 20:51 -------- d-----w- c:\program files\PlotSoft
2012-07-30 20:51 . 2012-07-30 20:51 -------- d-----w- c:\documents and settings\All Users\Application Data\PlotSoft
2012-07-29 09:48 . 2012-07-29 09:48 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-29 09:48 . 2012-07-29 09:48 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-23 01:48 . 2012-07-23 01:48 -------- d-----w- c:\program files\Google
2012-07-23 01:44 . 2012-07-23 01:44 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Foxit Software
2012-07-19 09:26 . 2011-06-26 00:56 28256 ----a-w- c:\windows\system32\drivers\appliand.sys
2012-07-19 09:26 . 2012-07-19 09:27 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Replay Media Catcher 4
2012-07-19 09:21 . 2012-07-31 07:08 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Media Player Classic
2012-07-19 09:20 . 2012-07-19 09:20 -------- d-----w- c:\program files\Essentials Codec Pack
2012-07-19 09:11 . 2012-07-19 09:11 -------- d-----w- c:\program files\WinPcap
2012-07-19 09:07 . 2012-07-19 09:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Freemake
2012-07-19 09:07 . 2012-07-19 09:07 -------- d-----w- c:\program files\Freemake
2012-07-13 09:19 . 2012-07-13 09:19 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Identities
2012-07-11 10:07 . 2012-07-16 22:16 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Mathematica
2012-07-11 10:07 . 2012-07-11 10:09 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Mathematica
2012-07-11 10:07 . 2012-07-11 10:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Mathematica
2012-07-11 10:06 . 2008-11-11 04:53 333096 ----a-w- c:\windows\system32\mltcpip32.mlp
2012-07-11 10:06 . 2008-11-11 04:53 107816 ----a-w- c:\windows\system32\mltcp32.mlp
2012-07-11 10:06 . 2008-11-11 04:53 103720 ----a-w- c:\windows\system32\mlshm32.mlp
2012-07-11 10:06 . 2008-11-11 04:53 95528 ----a-w- c:\windows\system32\mlmap32.mlp
2012-07-11 10:06 . 2008-11-11 04:53 185640 ----a-w- c:\windows\system32\mlmodule32.dll
2012-07-11 10:06 . 2008-11-11 04:53 378152 ----a-w- c:\windows\system32\ml32i3.dll
2012-07-11 10:06 . 2008-11-11 04:53 267560 ----a-w- c:\windows\system32\ml32i2.dll
2012-07-11 10:06 . 2008-11-11 04:53 255272 ----a-w- c:\windows\system32\ml32i1.dll
2012-07-11 10:04 . 2012-07-11 10:07 -------- d-----w- c:\program files\Wolfram Research
2012-07-11 09:58 . 2012-07-11 09:58 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\MathWorks
2012-07-11 09:56 . 2004-03-02 06:05 407104 ----a-w- c:\windows\system32\MSHFLXGD.OCX
2012-07-11 09:56 . 2004-02-11 22:37 203976 ----a-w- c:\windows\system32\RICHTX32.OCX
2012-07-11 09:56 . 2002-02-14 18:26 647872 ----a-w- c:\windows\system32\mscomct2.ocx
2012-07-11 09:43 . 2012-07-11 09:43 -------- d-----w- c:\program files\Matlab
2012-07-11 08:02 . 2012-07-11 08:02 -------- d-----w- c:\documents and settings\All Users\Application Data\FNP
2012-07-11 07:56 . 2012-07-11 08:23 -------- d-----w- c:\program files\ANSYS Inc
2012-07-11 04:12 . 2012-07-11 08:44 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Ansys
2012-07-10 12:29 . 2012-07-11 08:33 -------- d-----w- c:\program files\Foxit Software
2012-07-09 14:28 . 2012-07-27 17:29 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\SendSpace Wizard
2012-07-09 14:28 . 2012-07-09 14:28 -------- d-----w- c:\program files\SendSpace
2012-07-08 10:32 . 2012-07-23 03:34 -------- d-----w- c:\documents and settings\LogMeInRemoteUser
2012-07-08 07:19 . 2009-09-05 00:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2012-07-08 07:19 . 2006-09-28 23:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2012-07-08 07:18 . 2012-07-08 07:18 -------- d-----w- c:\program files\Microsoft Silverlight
2012-07-08 07:18 . 2012-07-08 07:18 -------- d-----w- c:\program files\Winamp Detect
2012-07-08 07:18 . 2011-03-04 19:44 133616 ------w- c:\windows\system32\pxafs.dll
2012-07-08 07:18 . 2012-08-01 21:55 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Winamp
2012-07-08 07:18 . 2012-07-08 07:20 -------- d-----w- c:\program files\Winamp
2012-07-08 06:59 . 2012-07-08 06:59 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Boilsoft
2012-07-08 06:59 . 2012-07-08 06:59 -------- d-----w- c:\program files\Boilsoft
2012-07-08 06:56 . 2012-07-08 06:56 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\MicroVision Applications
2012-07-08 06:56 . 2012-07-08 06:56 -------- d-----w- c:\program files\SureThing CD Labeler 5
2012-07-08 06:49 . 2012-07-08 06:49 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Publish Providers
2012-07-08 06:48 . 2012-07-08 06:48 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Sony
2012-07-08 06:46 . 2012-07-08 06:46 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Sony
2012-07-08 06:44 . 2012-07-08 06:44 -------- d-----w- c:\program files\Vstplugins
2012-07-08 06:44 . 2012-07-08 06:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony
2012-07-08 06:42 . 2012-07-08 06:45 -------- d-----w- c:\program files\Sony Setup
2012-07-08 05:54 . 2012-07-08 05:54 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Sony Corporation
2012-07-08 03:14 . 2007-07-20 01:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2012-07-08 03:13 . 2012-07-11 05:58 -------- d-----w- c:\windows\Logs
2012-07-08 03:13 . 2012-07-08 06:45 -------- d-----w- c:\program files\Sony
2012-07-08 03:13 . 2012-07-08 03:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Corporation
2012-07-08 03:11 . 2008-05-02 13:25 465920 ------w- c:\windows\system32\imapi2fs.dll
2012-07-08 03:11 . 2008-05-02 13:25 465920 ------w- c:\windows\system32\dllcache\imapi2fs.dll
2012-07-08 03:11 . 2008-05-02 13:25 317952 ------w- c:\windows\system32\imapi2.dll
2012-07-08 03:11 . 2008-05-02 13:25 317952 ------w- c:\windows\system32\dllcache\imapi2.dll
2012-07-08 03:11 . 2008-05-02 10:49 62976 ------w- c:\windows\system32\dllcache\cdrom.sys
2012-07-07 07:12 . 2012-07-07 07:12 -------- d-----w- c:\program files\Dropbox
2012-07-07 07:11 . 2012-08-03 06:34 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Dropbox
2012-07-07 01:11 . 2012-07-07 01:11 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Sonic
2012-07-07 01:11 . 2012-07-07 01:11 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Leadertech
2012-07-04 08:28 . 2012-07-04 08:28 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\LogMeIn
2012-07-04 08:28 . 2012-07-12 23:57 83392 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-07-04 08:28 . 2012-07-12 23:57 52128 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-07-04 08:28 . 2012-07-12 23:57 30624 ----a-w- c:\windows\system32\LMIport.dll
2012-07-04 08:28 . 2012-04-02 19:17 47640 ----a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2012-07-04 08:28 . 2012-04-02 19:17 10144 ----a-w- c:\windows\system32\drivers\lmimirr.sys
2012-07-04 08:28 . 2012-07-12 23:57 87456 ----a-w- c:\windows\system32\LMIinit.dll
2012-07-04 08:28 . 2012-08-02 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\LogMeIn
2012-07-04 08:28 . 2012-07-12 23:57 -------- d-----w- c:\program files\LogMeIn
2012-07-04 08:08 . 2012-07-04 08:25 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\PhotoScape
2012-07-04 08:07 . 2012-07-04 08:08 -------- d-----w- c:\program files\PhotoScape
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-31 08:31 . 2004-08-10 04:00 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2012-06-28 19:00 . 2012-06-28 19:00 208896 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
2012-06-28 05:37 . 2012-06-28 05:37 341048 ------w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2012-06-28 05:37 . 2012-06-28 05:37 32768 ------w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2012-06-13 13:19 . 2004-08-10 04:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2012-06-28 05:35 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2004-08-10 04:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-05 00:35 . 2004-08-10 04:00 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-05 00:35 . 2012-06-05 00:35 222448 ----a-w- c:\windows\system32\muweb.dll
2012-06-04 04:32 . 2004-08-10 04:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 22:19 . 2012-06-02 22:19 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 22:19 . 2012-06-02 22:19 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 22:19 . 2004-08-10 04:00 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 22:19 . 2004-08-10 04:00 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 22:19 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-02 22:19 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 22:19 . 2004-08-10 04:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 22:19 . 2004-08-10 04:00 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2004-08-10 04:00 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-02 22:19 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 22:19 . 2004-08-10 04:00 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2004-08-10 04:00 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:18 . 2012-06-29 02:43 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 22:18 . 2012-06-29 02:43 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2004-08-10 04:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2004-08-10 04:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2004-08-10 04:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2004-08-10 04:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2004-08-10 04:00 385024 ----a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-31_22.23.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-02 19:53 . 2012-08-02 19:53 78848 c:\windows\Installer\9c3cabf.msi
+ 2012-08-02 04:36 . 2012-08-02 04:36 371272 c:\windows\Installer\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}\SkypeIcon.exe
- 2012-07-31 19:43 . 2012-07-31 19:43 371272 c:\windows\Installer\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}\SkypeIcon.exe
+ 2012-08-02 04:36 . 2012-08-02 04:36 1648640 c:\windows\Installer\67c4852.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-07-20 22:17 556376 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-07-20 22:17 556376 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-07-20 22:17 556376 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-07-20 22:17 556376 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-07-20 12218904]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 16239616]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-21 7622656]
"nwiz"="nwiz.exe" [2006-06-21 1519616]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-09-29 180269]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2012-04-19 421888]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2012-04-02 63048]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-25 202296]
.
c:\documents and settings\LogMeInRemoteUser\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-9-29 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-9-29 27136]
.
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\HP_Administrator\Application Data\Dropbox\bin\Dropbox.exe [2012-7-2 26868192]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-9-29 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-9-29 27136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-07-12 23:57 87456 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2012-05-25 11:25 6595928 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMBVolumeWatcher]
2010-03-24 22:42 599328 ----a-w- c:\program files\Sony\PMB\PMBVolumeWatcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 20:33 17418928 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2012-06-28 15:40 74752 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Documents and Settings\\HP_Administrator\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [3/4/2011 1:23 PM 11352]
R2 ANSYS, Inc. License Manager;ANSYS, Inc. License Manager;c:\program files\ANSYS Inc\Shared Files\Licensing\win32\ansysli_server.exe [7/11/2012 1:00 AM 3326976]
R2 ANSYS;ANSYS;c:\program files\ANSYS Inc\Shared Files\Licensing\win32\lmgrd.exe [7/11/2012 1:00 AM 1334096]
R2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files\Freemake\CaptureLib\CaptureLibService.exe [7/19/2012 2:07 AM 8704]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [5/11/2012 10:40 AM 374184]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [4/2/2012 12:17 PM 12856]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2/11/2011 2:23 PM 35088]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [10/24/2009 3:18 AM 360224]
R3 appliandMP;appliandMP;c:\windows\system32\drivers\appliand.sys [7/19/2012 2:26 AM 28256]
R3 CXFALCON;Conexant Falcon II NTSC Video Capture;c:\windows\system32\drivers\cxfalcon.sys [9/29/2006 11:13 AM 82048]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [3/10/2011 6:34 PM 34608]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [11/2/2009 8:27 PM 19472]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;c:\windows\system32\drivers\wn5301.sys [9/29/2006 11:13 AM 468768]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/22/2012 6:48 PM 116648]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [6/7/2012 7:12 PM 160944]
S3 appliand;Applian Network Service;c:\windows\system32\drivers\appliand.sys [7/19/2012 2:26 AM 28256]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/22/2012 6:48 PM 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [6/12/2011 11:15 AM 31125880]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S3 SureThing Labelflash service;SureThing Labelflash service;c:\program files\Common Files\SureThing Shared\stllssvr.exe [7/7/2012 11:56 PM 74384]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/6/2008 4:06 PM 11520]
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-07-23 11:51]
.
2012-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-07-23 11:51]
.
2012-08-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201676905-1722714622-782747575-1007Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-06-28 04:46]
.
2012-08-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201676905-1722714622-782747575-1007UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-06-28 04:46]
.
2012-08-03 c:\windows\Tasks\User_Feed_Synchronization-{387926FE-DE24-4D05-BD14-182F45C4A27A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
2012-08-03 c:\windows\Tasks\Windows Codec Update Service.job
- c:\program files\Essentials Codec Pack\WECPUpdate.exe [2012-02-03 09:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
Trusted Zone: trymedia.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-02 23:34
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1916)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(2112)
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\documents and settings\HP_Administrator\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\program files\Google\Drive\googledrivesync32.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~4\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\program files\ANSYS Inc\Shared Files\Licensing\win32\ansyslmd.exe
c:\windows\eHome\ehRecvr.exe
c:\program files\ANSYS Inc\Shared Files\Licensing\win32\ansysli_monitor.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-08-02 23:38:06 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-03 06:38
ComboFix2.txt 2012-07-31 22:29
.
Pre-Run: 123,659,300,864 bytes free
Post-Run: 123,823,136,768 bytes free
.
- - End Of File - - 4C018820EA487095782C711E93F564F8