Hello, thank you so much for helping me. I have done everything you asked.
Here are the logs.
Monica
New Hijack this Results:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:00 AM, on 11/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\QuickTime\bak\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\1189379618\ee\AOLSoftware.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {211FDA94-E4E7-4BDA-BBE3-0DB7757CDDB5} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {789C867A-F968-4826-A13F-A748A8D495F2} - (no file)
O2 - BHO: (no name) - {99611D24-B521-4F62-B2CA-664521665E74} - (no file)
O2 - BHO: (no name) - {A7460C74-475F-483E-8ECB-265D20950878} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\dpcrkqhi.dll
O2 - BHO: {6971927f-6a23-f3ab-0534-2bfab5f4a6bf} - {fb6a4f5b-afb2-4350-ba3f-32a6f7291796} - C:\WINDOWS\system32\npsbqepw.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\dpcrkqhi.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1189379618\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [407df185] rundll32.exe "C:\WINDOWS\system32\leebrosf.dll",b
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: dpcrkqhi - C:\WINDOWS\SYSTEM32\dpcrkqhi.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8896 bytes
ComboFix Results:
ComboFix 07-11-08.1 - Nikki 2007-11-13 11:28:43.1 - NTFSx86
Running from: C:\Documents and Settings\Nikki\Desktop\ComboFix.exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Nikki\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Nikki\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Nikki\Favorites\Online Security Guide.lnk
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\crap.1193189168.old
C:\Program Files\WinBudget\bin\crap.1193850125.old
C:\Program Files\WinBudget\bin\crap.1194493882.old
C:\Program Files\WinBudget\bin\matrix.dat
C:\Program Files\WinBudget\bin\matrix.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\dpcrkqhi.dllbox
C:\WINDOWS\SYSTEM32\ybadd.bak2
C:\WINDOWS\SYSTEM32\ybadd.ini
C:\WINDOWS\SYSTEM32\ybadd.ini2
C:\WINDOWS\SYSTEM32\ybadd.tmp
.
((((((((((((((((((((((((( Files Created from 2007-10-13 to 2007-11-13 )))))))))))))))))))))))))))))))
.
2007-11-13 11:24 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 21:14 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-12 21:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2007-11-12 21:04 <DIR> d-------- C:\Temp
2007-11-12 21:04 1,563,704 --a------ C:\Program Files\PREVXCSIFREE.EXE
2007-11-12 20:16 144,320 --a------ C:\WINDOWS\SYSTEM32\dpcrkqhi.dll
2007-11-12 20:15 144,320 --a------ C:\WINDOWS\SYSTEM32\atrtjnhv.dll
2007-11-12 15:33 89,664 --a------ C:\WINDOWS\SYSTEM32\leebrosf.dll
2007-11-12 15:30 81,472 --a------ C:\WINDOWS\SYSTEM32\npsbqepw.dll
2007-11-11 23:10 60,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Teefer.sys
2007-11-11 23:10 21,075 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wpsdrvnt.sys
2007-11-11 23:10 14,568 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wg6n.sys
2007-11-11 23:10 14,568 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wg5n.sys
2007-11-11 23:10 14,568 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wg4n.sys
2007-11-11 23:10 14,568 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wg3n.sys
2007-11-11 23:09 <DIR> d-------- C:\Program Files\Sygate
2007-11-11 23:09 83,096 --a------ C:\WINDOWS\SYSTEM32\SSSensor.dll
2007-11-11 21:46 1,953,799 --a------ C:\Program Files\stinger.exe
2007-11-11 21:41 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-11-11 17:46 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-11-11 16:28 7,467,056 --a------ C:\Program Files\spybotsd15.exe
2007-11-11 15:30 79,936 --a------ C:\WINDOWS\SYSTEM32\ndkpormo.dll
2007-11-11 15:24 88,128 --a------ C:\WINDOWS\SYSTEM32\bmpofqva.dll
2007-11-11 14:00 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-11 14:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-11 13:58 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-11 13:57 21,216,112 --a------ C:\Program Files\aaw2007.exe
2007-11-11 11:07 79,936 --a------ C:\WINDOWS\SYSTEM32\ebxsjepg.dll
2007-11-11 08:14 102,664 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
2007-11-10 22:37 <DIR> d-------- C:\Documents and Settings\Nikki\.housecall6.6
2007-11-10 11:06 81,472 --a------ C:\WINDOWS\SYSTEM32\ieaqlgay.dll
2007-11-09 23:08 81,472 --a------ C:\WINDOWS\SYSTEM32\quspqthq.dll
2007-11-09 18:25 77,888 --a------ C:\WINDOWS\SYSTEM32\llqxnsbf.dll
2007-11-09 18:22 88,128 --a------ C:\WINDOWS\SYSTEM32\yfpvoebn.dll
2007-11-09 15:17 <DIR> d-------- C:\Program Files\Windows Defender
2007-11-07 21:51 8,987,768 --a------ C:\Program Files\Windows-KB890830-x64-V1.34.exe
2007-11-07 20:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-03 17:44 <DIR> d-------- C:\Documents and Settings\Nikki\Application Data\PlayFirst
2007-11-03 17:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2007-11-03 17:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-11-03 17:40 <DIR> d-------- C:\Program Files\Yahoo! Games
2007-10-31 09:29 <DIR> d-------- C:\Program Files\AOL 9.0
2007-10-30 19:55 625,032 --a------ C:\WINDOWS\SYSTEM32\SymNeti.dll
2007-10-30 19:55 242,056 --a------ C:\WINDOWS\SYSTEM32\SymRedir.dll
2007-10-30 19:55 191,536 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symtdi.sys
2007-10-30 19:55 145,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symfw.sys
2007-10-30 19:55 39,856 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symids.sys
2007-10-30 19:55 37,936 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symndisv.sys
2007-10-30 19:55 35,120 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symndis.sys
2007-10-30 19:55 27,696 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symredrv.sys
2007-10-30 19:55 12,848 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symdns.sys
2007-10-25 10:26 53,248 --a------ C:\WINDOWS\bdoscandel.exe
2007-10-18 17:46 <DIR> d-------- C:\WINDOWS\SYSTEM32\bak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-13 19:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-13 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-13 04:27 17 ----a-w C:\Program Files\stinger.opt
2007-11-12 07:07 5,659,648 ----a-w C:\Program Files\spf.msi
2007-11-12 03:20 --------- d-----w C:\Program Files\Norton Internet Security
2007-11-11 21:50 --------- d-----w C:\Documents and Settings\Nikki\Application Data\Lavasoft
2007-11-11 18:56 --------- d-----w C:\Program Files\Morpheus
2007-11-09 23:15 5,154,304 ----a-w C:\Program Files\WindowsDefender.msi
2007-11-01 22:36 --------- d-----w C:\Documents and Settings\Robert\Application Data\AOL
2007-10-31 17:33 --------- d-----w C:\Program Files\Common Files\AOL
2007-10-31 17:33 --------- d-----w C:\Documents and Settings\Nikki\Application Data\AOL
2007-10-31 17:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-31 17:31 --------- d-----w C:\Program Files\Common Files\aolshare
2007-10-31 17:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-31 17:15 --------- d-----w C:\Program Files\America Online 9.0
2007-10-31 03:24 12,963 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2007-10-31 03:24 1,358 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2007-10-22 00:01 --------- d-----w C:\Program Files\QuickTime
2007-10-19 02:04 --------- d-----w C:\Program Files\iTunes
2007-10-13 04:03 --------- d-----w C:\Documents and Settings\Robert\Application Data\Lavasoft
2007-10-09 01:30 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-09 01:30 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-09 01:30 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-09 01:30 --------- d-----w C:\Program Files\Symantec
2007-09-29 19:46 --------- d-----w C:\Documents and Settings\Nikki\Application Data\Viewpoint
2007-09-26 22:04 --------- d-----w C:\Documents and Settings\Robert\Application Data\Viewpoint
2007-09-26 22:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-09-18 21:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 21:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 21:44 10,658 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 21:44 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 21:44 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 21:44 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 21:43 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 21:43 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 21:43 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-09-14 23:25 --------- d-----w C:\Documents and Settings\Nikki\Application Data\AdobeUM
2006-02-03 07:55 1,321,140 ----a-w C:\Program Files\iScrobblerWin_1_1_0.exe
2005-05-14 08:17 12,781,432 ----a-w C:\Program Files\LemonadeTycoon2Install.exe
2005-06-08 19:27:08 900 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 50,736 2006-09-26 00:52:48 C:\Program Files\Common Files\AOL\1189379618\ee\bak\AOLSoftware.exe
----a-w 50,736 2006-09-26 00:52:48 C:\Program Files\Common Files\AOL\1189379618\ee\AOLSoftware.exe
----a-w 180,269 2005-12-24 08:43:19 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 110,592 2003-08-19 06:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
----a-w 53,248 2004-04-11 16:43:44 C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe
----a-w 290,816 2004-04-12 01:15:14 C:\Program Files\Dell\Media Experience\bak\PCMService.exe
----a-w 221,184 2003-09-04 01:12:44 C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe
----a-w 278,528 2005-10-07 02:03:14 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 32,881 2003-11-19 22:48:14 C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe
----a-w 1,694,208 2004-10-13 16:24:37 C:\Program Files\Messenger\bak\msmsgs.exe
----a-w 11,776 2005-03-12 14:25:00 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mimboot.exe
----a-w 110,592 2005-03-12 14:25:00 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe
----a-w 155,648 2005-11-07 00:15:44 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 118,784 2004-02-10 16:51:30 C:\WINDOWS\SYSTEM32\bak\hkcmd.exe
----a-w 155,648 2004-02-10 16:55:32 C:\WINDOWS\SYSTEM32\bak\igfxtray.exe
----a-w 122,933 2004-03-15 06:04:00 C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{211FDA94-E4E7-4BDA-BBE3-0DB7757CDDB5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{789C867A-F968-4826-A13F-A748A8D495F2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{99611D24-B521-4F62-B2CA-664521665E74}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A7460C74-475F-483E-8ECB-265D20950878}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-12 20:16 144320 --a------ C:\WINDOWS\system32\dpcrkqhi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fb6a4f5b-afb2-4350-ba3f-32a6f7291796}]
2007-11-12 15:30 81472 --a------ C:\WINDOWS\system32\npsbqepw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\dpcrkqhi.dll [2007-11-12 20:16 144320]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\dpcrkqhi.dll [2007-11-12 20:16 144320]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\bak\qttask.exe" [2005-11-06 16:15]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 17:22]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30]
"HostManager"="C:\Program Files\Common Files\AOL\1189379618\ee\AOLSoftware.exe" [2006-09-25 16:52]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"407df185"="C:\WINDOWS\system32\leebrosf.dll" [2007-11-12 15:33]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="C:\Program Files\AOL 9.0\AOL.exe" [2007-04-17 22:49]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 00:17:18]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 00:06:58]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dpcrkqhi]
dpcrkqhi.dll 2007-11-12 20:16 144320 C:\WINDOWS\SYSTEM32\dpcrkqhi.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddaby.dll
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-10 06:30:20 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\SYSTEM32\CLEANMGR.EXE
"2005-04-17 06:44:05 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1098138235.job"
"2007-11-10 06:31:44 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Nikki.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-13 11:42:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-13 11:48:30 - machine was rebooted
.
--- E O F ---
AWF Results:
Find AWF report by noahdfear ©2006
Version 1.40
The current date is: Tue 11/13/2007
The current time is: 11:53:47.71
bak folders found
~~~~~~~~~~~
Directory of C:\PROGRA~1\ITUNES\BAK
10/06/2005 06:03 PM 278,528 iTunesHelper.exe
1 File(s) 278,528 bytes
Directory of C:\PROGRA~1\MESSEN~1\BAK
10/13/2004 08:24 AM 1,694,208 msmsgs.exe
1 File(s) 1,694,208 bytes
Directory of C:\PROGRA~1\QUICKT~1\BAK
11/06/2005 04:15 PM 155,648 qttask.exe
1 File(s) 155,648 bytes
Directory of C:\WINDOWS\SYSTEM32\BAK
02/10/2004 08:51 AM 118,784 hkcmd.exe
02/10/2004 08:55 AM 155,648 igfxtray.exe
2 File(s) 274,432 bytes
Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\CYBERL~1\POWERDVD\BAK
04/11/2004 08:43 AM 53,248 DVDLauncher.exe
1 File(s) 53,248 bytes
Directory of C:\PROGRA~1\DELL\MEDIAE~1\BAK
04/11/2004 05:15 PM 290,816 PCMService.exe
1 File(s) 290,816 bytes
Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK
09/03/2003 05:12 PM 221,184 IntelMEM.exe
1 File(s) 221,184 bytes
Directory of C:\PROGRA~1\MUSICM~1\MUSICM~2\BAK
03/12/2005 06:25 AM 11,776 mimboot.exe
03/12/2005 06:25 AM 110,592 mm_tray.exe
2 File(s) 122,368 bytes
Directory of C:\WINDOWS\SYSTEM32\DLA\BAK
03/14/2004 10:04 PM 122,933 tfswctrl.exe
1 File(s) 122,933 bytes
Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK
12/24/2005 12:43 AM 180,269 realsched.exe
1 File(s) 180,269 bytes
Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK
08/18/2003 10:01 PM 110,592 sgtray.exe
1 File(s) 110,592 bytes
Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK
11/19/2003 02:48 PM 32,881 jusched.exe
1 File(s) 32,881 bytes
Directory of C:\PROGRA~1\COMMON~1\AOL\118937~1\EE\BAK
09/25/2006 04:52 PM 50,736 AOLSoftware.exe
1 File(s) 50,736 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
278528 Oct 6 2005 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
1667584 Aug 3 2004 "C:\WINDOWS\$NtUninstallKB887472$\msmsgs.exe"
1694208 Oct 13 2004 "C:\Program Files\Messenger\bak\msmsgs.exe"
1694208 Oct 13 2004 "C:\WINDOWS\$hf_mig$\KB887472\SP2QFE\msmsgs.exe"
155648 Nov 6 2005 "C:\Program Files\QuickTime\bak\qttask.exe"
118784 Feb 10 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE"
118784 Feb 10 2004 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
118784 Feb 10 2004 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\hkcmd.exe"
155648 Feb 10 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE"
155648 Feb 10 2004 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
155648 Feb 10 2004 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxtray.exe"
53248 Apr 11 2004 "C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe"
290816 Apr 11 2004 "C:\Program Files\Dell\Media Experience\bak\PCMService.exe"
221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe"
11776 Apr 5 2005 "C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\mimboot.exe"
11776 Mar 12 2005 "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mimboot.exe"
110592 Apr 5 2005 "C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\mm_tray.exe"
110592 Mar 12 2005 "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe"
122933 Mar 14 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe"
122933 Mar 14 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe"
180269 Dec 24 2005 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
110592 Aug 18 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe"
50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1189379618\ee\AOLSoftware.exe"
50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1189379618\ee\bak\AOLSoftware.exe"
end of report