Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected By Nasty Malware & Viruses


  • This topic is locked This topic is locked
14 replies to this topic

#1 yoori

yoori

  • Members
  • 149 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:In Your Dreams
  • Local time:05:56 AM

Posted 21 July 2008 - 07:03 AM

Hi,
my computer had been infected by more than a few malware and viruses,
I was told to go here for further investigation because I had nasty malwares
when I posted up my SDFix log in the other thread. Thread located here: http://www.bleepingcomputer.com/forums/t/156283/still-infected-with-antivirus-2008/ ~ OB

these are the ones are the stubborn ones that I had hard time getting rid of:

Antivirus XP 2008 (file name: rhcgdrj0elce)
freeware sysinternals/bluescreen screen saver (file name: lphcldrj0elce)
outerinfo
speed moniter
internet security suite (This is the one that stills comes back when the internet is turned on)

I had the hardest time getting out Antivirus XP 2008 and Freeware sysinternal-Bluescreen saver
Even if my computer was put into safemode the Freeware Sysinternal would keep making my moniter screen
go black for a sec and then come back on. Even if I had them removed it would always come back if the internet
was turned on. I think I removed the two most frustrating ones, though they might still be in there. So far the
only one that comes back is the "internet security suite". I also would like to know how to take off the unwanted files
from my start up under my msconfig.

Thank you for your time and help, I appreciate it alot. ^____^

Here is my SDFix & HJT logs:

--------------------------------------------

SDFix: Version 1.203
Run by HP_Administrator on Wed 07/09/2008 at 02:19 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Name :
MsSecurity1.209.4

Path :
c:\winself.exe service

MsSecurity1.209.4 - Deleted



Restoring Default Security Values
Restoring Default Hosts File
Restoring Default IE Search Pages
Restoring Default Desktop Wallpaper
Restoring Default ScreenSaver value

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\lphcldrj0elce.exe - Deleted
C:\WINDOWS\SYSTEM32\PHCLDR~1.BMP - Deleted
C:\WINDOWS\SYSTEM32\BLPHCL~1.SCR - Deleted
C:\WINDOWS\trlrokgq\1.png - Deleted
C:\WINDOWS\trlrokgq\2.png - Deleted
C:\WINDOWS\trlrokgq\3.png - Deleted
C:\WINDOWS\trlrokgq\4.png - Deleted
C:\WINDOWS\trlrokgq\5.png - Deleted
C:\WINDOWS\trlrokgq\6.png - Deleted
C:\WINDOWS\trlrokgq\7.png - Deleted
C:\WINDOWS\trlrokgq\8.png - Deleted
C:\WINDOWS\trlrokgq\9.png - Deleted
C:\WINDOWS\trlrokgq\bottom-rc.gif - Deleted
C:\WINDOWS\trlrokgq\config.png - Deleted
C:\WINDOWS\trlrokgq\content.png - Deleted
C:\WINDOWS\trlrokgq\download.gif - Deleted
C:\WINDOWS\trlrokgq\frame-bg.gif - Deleted
C:\WINDOWS\trlrokgq\frame-bottom-left.gif - Deleted
C:\WINDOWS\trlrokgq\frame-h1bg.gif - Deleted
C:\WINDOWS\trlrokgq\head.png - Deleted
C:\WINDOWS\trlrokgq\icon.png - Deleted
C:\WINDOWS\trlrokgq\indexwp.html - Deleted
C:\WINDOWS\trlrokgq\main.css - Deleted
C:\WINDOWS\trlrokgq\memory-prots.png - Deleted
C:\WINDOWS\trlrokgq\net.png - Deleted
C:\WINDOWS\trlrokgq\pc.gif - Deleted
C:\WINDOWS\trlrokgq\pc-mag.gif - Deleted
C:\WINDOWS\trlrokgq\poloska1.png - Deleted
C:\WINDOWS\trlrokgq\poloska2.png - Deleted
C:\WINDOWS\trlrokgq\poloska3.png - Deleted
C:\WINDOWS\trlrokgq\promowp1.html - Deleted
C:\WINDOWS\trlrokgq\promowp2.html - Deleted
C:\WINDOWS\trlrokgq\promowp3.html - Deleted
C:\WINDOWS\trlrokgq\promowp4.html - Deleted
C:\WINDOWS\trlrokgq\promowp5.html - Deleted
C:\WINDOWS\trlrokgq\reg.png - Deleted
C:\WINDOWS\trlrokgq\repair.png - Deleted
C:\WINDOWS\trlrokgq\scr-1.png - Deleted
C:\WINDOWS\trlrokgq\scr-2.png - Deleted
C:\WINDOWS\trlrokgq\start.png - Deleted
C:\WINDOWS\trlrokgq\styles.css - Deleted
C:\WINDOWS\trlrokgq\top-rc.gif - Deleted
C:\WINDOWS\trlrokgq\vline.gif - Deleted
C:\WINDOWS\trlrokgq\wp.png - Deleted
C:\Temp\1cb\syscheck.log - Deleted
C:\Temp\vtmp2\ktnv33.log - Deleted
C:\WINDOWS\system32\iTmp\dutdtx2.exe - Deleted
C:\WINDOWS\system32\netrax06\netrax061083.exe - Deleted
C:\WINDOWS\system32\vntiho06\vntiho061083.exe - Deleted
C:\Program Files\Sysmnt\Ssmgr.exe - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt10.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt11.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt15.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt16.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt184.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt1A2.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt2.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt21D.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt255.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt3.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt4.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt5.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt6.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt7.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.ttD9.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.ttDA.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.ttDC.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.ttDF.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.ttE.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.ttE2.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.ttE3.tmp - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt16.tmp.vbs - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt2.tmp.vbs - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.tt3.tmp.vbs - Deleted
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\.ttE.tmp.vbs - Deleted
C:\WINDOWS\system32\000070.exe - Deleted
C:\WINDOWS\system32\000080.exe - Deleted
C:\Program Files\stc\csv5p070.exe - Deleted
C:\winself.exe - Deleted
C:\WINDOWS\123messenger.per - Deleted
C:\WINDOWS\apphelp32.dll - Deleted
C:\WINDOWS\asferror32.dll - Deleted
C:\WINDOWS\asycfilt32.dll - Deleted
C:\WINDOWS\athprxy32.dll - Deleted
C:\WINDOWS\ati2dvaa32.dll - Deleted
C:\WINDOWS\ati2dvag32.dll - Deleted
C:\WINDOWS\audiosrv32.dll - Deleted
C:\WINDOWS\autodisc32.dll - Deleted
C:\WINDOWS\avifile32.dll - Deleted
C:\WINDOWS\avisynthex32.dll - Deleted
C:\WINDOWS\aviwrap32.dll - Deleted
C:\WINDOWS\browserad.dll - Deleted
C:\WINDOWS\changeurl_30.dll - Deleted
C:\WINDOWS\default.htm - Deleted
C:\WINDOWS\didduid.ini - Deleted
C:\WINDOWS\licencia.txt - Deleted
C:\WINDOWS\megavid.cdt - Deleted
C:\WINDOWS\msa64chk.dll - Deleted
C:\WINDOWS\msapasrc.dll - Deleted
C:\WINDOWS\mspphe.dll - Deleted
C:\WINDOWS\muotr.so - Deleted
C:\WINDOWS\ntnut.exe - Deleted
C:\WINDOWS\saiemod.dll - Deleted
C:\WINDOWS\salm.exe - Deleted
C:\WINDOWS\shdocpe.dll - Deleted
C:\WINDOWS\shdocpl.dll - Deleted
C:\WINDOWS\system32\441465\441465.dll - Deleted
C:\WINDOWS\system32\hljwugsf.bin - Deleted
C:\WINDOWS\system32\iftuyszv.exe - Deleted
C:\WINDOWS\system32\MSIXU.DLL - Deleted
C:\WINDOWS\system32\MSNSA32.dll - Deleted
C:\WINDOWS\system32\ntnut32.exe - Deleted
C:\WINDOWS\system32\pac.txt - Deleted
C:\WINDOWS\system32\shdocpe.dll - Deleted
C:\WINDOWS\system32\SIPSPI32.dll - Deleted
C:\WINDOWS\system32\WER8274.DLL - Deleted
C:\WINDOWS\telefonos.txt - Deleted
C:\WINDOWS\textos.txt - Deleted
C:\WINDOWS\updatetc.exe - Deleted
C:\WINDOWS\voiceip.dll - Deleted
C:\WINDOWS\winsb.dll - Deleted
C:\WINDOWS\system32\clbdll.dll - Deleted
C:\WINDOWS\system32\drivers\clbdriver.sys - Deleted



Folder C:\Program Files\stc - Removed
Folder C:\Program Files\Sysmnt - Removed
Folder C:\Temp\1cb - Removed
Folder C:\Temp\vtmp2 - Removed
Folder C:\WINDOWS\FLEOK - Removed
Folder C:\WINDOWS\system32\441465 - Removed
Folder C:\WINDOWS\system32\iTmp - Removed
Folder C:\WINDOWS\system32\netrax06 - Removed
Folder C:\WINDOWS\system32\vntiho06 - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-09 02:41:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_8852CD8ACA0D0B86C1B0F9109EDB6CAB]
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_8852CD8ACA0D0B86C1B0F9109EDB6CAB\0000]
"Service"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\8852cd8aca0d0b86c1b0f9109edb6cab]
"c"="&registry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\8852cd8aca0d0b86c1b0f9109edb6cab&primary_ip=586742989&secondary_ip=586742989&primary_port=7000&secondary_port=7000&download_period=432000&first_download_delay=300&version=1&current_ip=0&name=8852cd8aca0d0b86c1b0f9109edb6cab&path=system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys&wmid=Dti002&idate=2008-07-03 10:21:10:531&last_download_time=2008-7-8 14:55:32.62"
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000000
"Tag"=dword:00000005
"ImagePath"=str(2):"system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys"
"DisplayName"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Group"="System Bus Extender"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\8852cd8aca0d0b86c1b0f9109edb6cab\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_8852CD8ACA0D0B86C1B0F9109EDB6CAB]
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_8852CD8ACA0D0B86C1B0F9109EDB6CAB\0000]
"Service"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\8852cd8aca0d0b86c1b0f9109edb6cab]
"c"="&registry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\8852cd8aca0d0b86c1b0f9109edb6cab&primary_ip=586742989&secondary_ip=586742989&primary_port=7000&secondary_port=7000&download_period=432000&first_download_delay=300&version=1&current_ip=0&name=8852cd8aca0d0b86c1b0f9109edb6cab&path=system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys&wmid=Dti002&idate=2008-07-03 10:21:10:531&last_download_time=2008-7-8 14:55:32.62"
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000000
"Tag"=dword:00000005
"ImagePath"=str(2):"system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys"
"DisplayName"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Group"="System Bus Extender"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\8852cd8aca0d0b86c1b0f9109edb6cab\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"\xac8?\xb3 ?(?T?r?u?e?T?y?p?e?)?"="Mgonsm.TTF"
"\xb1\xbf\xb6 ?\xbf\xbb\xbc2? ?(?T?r?u?e?T?y?p?e?)?"="KZSESB2.ttf"
"\xb1\xbf\xb6 ?\xbe\xbb\xbc ?(?T?r?u?e?T?y?p?e?)?"="KZSESB.TTF"
"\xb1\xb4\xa9\xb8\xae\xbc ?(?T?r?u?e?T?y?p?e?)?"="gumchef.ttf"
"\300\x00ae1?0? ?(?T?r?u?e?T?y?p?e?)?"="sugi10.ttf"
"\xbb\xbc ?(?T?r?u?e?T?y?p?e?)?"="Pretty Variation.TTF"
"\25\b\x00ac9? ?(?T?r?u?e?T?y?p?e?)?"="jungal9.ttf"
"\b\xb4L? ?(?T?r?u?e?T?y?p?e?)?"="ChoDeungL.TTF"

scanning hidden files ...

C:\WINDOWS\system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys 36864 bytes executable

scan completed successfully
hidden processes: 0
hidden services: 1
hidden files: 1


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\WINDOWS\\system32\\fscagent.exe"="C:\\WINDOWS\\system32\\fscagent.exe:*:Enabled:???? ???? ??"
"C:\\WINDOWS\\system32\\clubbox.exe"="C:\\WINDOWS\\system32\\clubbox.exe:*:Enabled:'1 ,r"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\WINDOWS\\system32\\pdrtvsvr.exe"="C:\\WINDOWS\\system32\\pdrtvsvr.exe:*:Enabled:PandoraTV VoD Control"
"C:\\Program Files\\Gizmo Project for LJ Talk\\mDNSResponder.exe"="C:\\Program Files\\Gizmo Project for LJ Talk\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Gizmo Project for LJ Talk\\Gizmo-LJ.exe"="C:\\Program Files\\Gizmo Project for LJ Talk\\Gizmo-LJ.exe:*:Enabled:Gizmo Project for LJ Talk"
"C:\\WINDOWS\\system32\\grdmgr.exe"="C:\\WINDOWS\\system32\\grdmgr.exe:*:Enabled:CDN ???? ??"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\WINDOWS\\kdx\\KHost.exe"="C:\\WINDOWS\\kdx\\KHost.exe:*:Enabled:Delivery Manager"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\system32\\P3MxSvr.exe"="C:\\WINDOWS\\system32\\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control"
"C:\\WINDOWS\\system32\\p3mxvsvr.exe"="C:\\WINDOWS\\system32\\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control"
"C:\\WINDOWS\\system32\\muzmvsvr.exe"="C:\\WINDOWS\\system32\\muzmvsvr.exe:*:Enabled:MUZ VOD Control"
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"="C:\\Program Files\\Orbitdownloader\\orbitdm.exe:*:Enabled:Orbit"
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"="C:\\Program Files\\Orbitdownloader\\orbitnet.exe:*:Enabled:Orbit"
"C:\\WINDOWS\\system32\\BugsSvr.exe"="C:\\WINDOWS\\system32\\BugsSvr.exe:*:Enabled:Bugs Music Player Control"
"C:\\WINDOWS\\system32\\p3bvsvr.exe"="C:\\WINDOWS\\system32\\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control"
"C:\\WINDOWS\\system32\\skcbgm.exe"="C:\\WINDOWS\\system32\\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player"
"C:\\Program Files\\DISC\\DISCover.exe"="C:\\Program Files\\DISC\\DISCover.exe:*:Enabled:DISCover Drop & Play System"
"C:\\Program Files\\DISC\\DiscStreamHub.exe"="C:\\Program Files\\DISC\\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub"
"C:\\Program Files\\DISC\\myFTP.exe"="C:\\Program Files\\DISC\\myFTP.exe:*:Enabled:DISCover FTP"
"C:\\Program Files\\pandora.tv\\minilite\\MiniStream.exe"="C:\\Program Files\\pandora.tv\\minilite\\MiniStream.exe:*:Enabled:MiniStream.exe"
"C:\\WINDOWS\\system32\\mnetasvr.exe"="C:\\WINDOWS\\system32\\mnetasvr.exe:*:Enabled:MNet AoD Server"
"C:\\WINDOWS\\system32\\mnetvsvr.exe"="C:\\WINDOWS\\system32\\mnetvsvr.exe:*:Enabled:MNet VoD Server"
"C:\\Program Files\\pandora.tv\\minilite\\MiniLite.exe"="C:\\Program Files\\pandora.tv\\minilite\\MiniLite.exe:*:Enabled:MiniLite.exe"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:Torrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 1 Mar 2006 211 A.SHR --- "C:\BOOT.BAK"
Wed 6 Feb 2008 217,073 A.SHR --- "C:\WINDOWS\meta4.exe"
Thu 14 Jul 2005 27,648 A.SHR --- "C:\WINDOWS\system32\AVSredirect.dll"
Sun 26 Jun 2005 616,448 A.SHR --- "C:\WINDOWS\system32\cygwin1.dll"
Tue 21 Jun 2005 45,568 A.SHR --- "C:\WINDOWS\system32\cygz.dll"
Wed 3 May 2006 163,328 ..SHR --- "C:\WINDOWS\system32\flvDX.dll"
Sun 25 Jan 2004 70,656 A.SHR --- "C:\WINDOWS\system32\i420vfw.dll"
Wed 21 Feb 2007 31,232 ..SHR --- "C:\WINDOWS\system32\msfDX.dll"
Mon 17 Dec 2007 27,648 ..SH. --- "C:\WINDOWS\system32\Smab0.dll"
Mon 4 Feb 2008 151,040 ..SH. --- "C:\WINDOWS\system32\VistaUltm.dll"
Mon 28 Feb 2005 240,128 A.SHR --- "C:\WINDOWS\system32\x.264.exe"
Sun 25 Jan 2004 70,656 A.SHR --- "C:\WINDOWS\system32\yv12vfw.dll"
Thu 29 May 2008 230,400 ..SHR --- "C:\WINDOWS\s?stem\m?config.exe"
Sat 5 Jul 2008 89,088 ..SHR --- "C:\Program Files\Common Files\?icrosoft.NET\services.exe"
Sun 26 Jun 2005 616,448 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygwin1.dll"
Tue 21 Jun 2005 45,568 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygz.dll"
Wed 6 Feb 2008 72,704 ..SHR --- "C:\Program Files\eRightSoft\SUPER\Setup.exe"
Sun 25 Mar 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 6 Mar 2006 1,302 A..H. --- "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK"
Mon 3 Jun 2002 84,992 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
Mon 3 Jun 2002 44,032 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
Mon 9 Dec 2002 73,766 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
Mon 9 Dec 2002 65,575 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
Sun 9 Jun 2002 36,864 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll"
Mon 3 Jun 2002 20,480 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
Mon 9 Dec 2002 102,437 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll"
Mon 9 Dec 2002 176,165 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
Mon 9 Dec 2002 208,935 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
Mon 9 Dec 2002 217,127 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
Sun 9 Jun 2002 40,448 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll"
Sat 3 Nov 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
Tue 10 Apr 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
Fri 20 Feb 2004 232,960 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
Sun 9 Jun 2002 525,824 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll"
Mon 9 Dec 2002 245,805 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll"
Mon 9 Dec 2002 45,093 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll"
Mon 9 Dec 2002 98,341 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll"
Mon 9 Dec 2002 94,247 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll"
Mon 9 Dec 2002 90,151 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll"
Mon 9 Dec 2002 102,439 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
Sun 9 Jun 2002 49,152 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll"
Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT2F.tmp"
Mon 12 Jun 2006 11,116 A.SH. --- "C:\Documents and Settings\HP_Administrator\My Documents\My Music\License Backup\drmv2key.bak"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\HP_Administrator\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\HP_Administrator\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"

Finished!

--------------------------------------------------------------


SDFix: Version 1.203
Run by HP_Administrator on Sat 07/12/2008 at 05:12 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File
Restoring Default Desktop Wallpaper

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\SYSTEM32\PHCLDR~1.BMP - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-12 17:28:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_8852CD8ACA0D0B86C1B0F9109EDB6CAB]
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_8852CD8ACA0D0B86C1B0F9109EDB6CAB\0000]
"Service"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\8852cd8aca0d0b86c1b0f9109edb6cab]
"c"="&registry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\8852cd8aca0d0b86c1b0f9109edb6cab&primary_ip=586742989&secondary_ip=586742989&primary_port=7000&secondary_port=7000&download_period=432000&first_download_delay=300&version=1&current_ip=0&name=8852cd8aca0d0b86c1b0f9109edb6cab&path=system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys&wmid=Dti002&idate=2008-07-03 10:21:10:531&last_download_time=2008-7-8 14:55:32.62"
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000000
"Tag"=dword:00000005
"ImagePath"=str(2):"system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys"
"DisplayName"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Group"="System Bus Extender"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\8852cd8aca0d0b86c1b0f9109edb6cab\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_8852CD8ACA0D0B86C1B0F9109EDB6CAB]
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_8852CD8ACA0D0B86C1B0F9109EDB6CAB\0000]
"Service"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\8852cd8aca0d0b86c1b0f9109edb6cab]
"c"="&registry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\8852cd8aca0d0b86c1b0f9109edb6cab&primary_ip=586742989&secondary_ip=586742989&primary_port=7000&secondary_port=7000&download_period=432000&first_download_delay=300&version=1&current_ip=0&name=8852cd8aca0d0b86c1b0f9109edb6cab&path=system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys&wmid=Dti002&idate=2008-07-03 10:21:10:531&last_download_time=2008-7-8 14:55:32.62"
"Type"=dword:00000001
"Start"=dword:00000000
"ErrorControl"=dword:00000000
"Tag"=dword:00000005
"ImagePath"=str(2):"system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys"
"DisplayName"="8852cd8aca0d0b86c1b0f9109edb6cab"
"Group"="System Bus Extender"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\8852cd8aca0d0b86c1b0f9109edb6cab\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts]
"\xac8?\xb3 ?(?T?r?u?e?T?y?p?e?)?"="Mgonsm.TTF"
"\xb1\xbf\xb6 ?\xbf\xbb\xbc2? ?(?T?r?u?e?T?y?p?e?)?"="KZSESB2.ttf"
"\xb1\xbf\xb6 ?\xbe\xbb\xbc ?(?T?r?u?e?T?y?p?e?)?"="KZSESB.TTF"
"\xb1\xb4\xa9\xb8\xae\xbc ?(?T?r?u?e?T?y?p?e?)?"="gumchef.ttf"
"\300\x00ae1?0? ?(?T?r?u?e?T?y?p?e?)?"="sugi10.ttf"
"\xbb\xbc ?(?T?r?u?e?T?y?p?e?)?"="Pretty Variation.TTF"
"\25\b\x00ac9? ?(?T?r?u?e?T?y?p?e?)?"="jungal9.ttf"
"\b\xb4L? ?(?T?r?u?e?T?y?p?e?)?"="ChoDeungL.TTF"

scanning hidden files ...

C:\WINDOWS\system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys 36864 bytes executable

scan completed successfully
hidden processes: 0
hidden services: 1
hidden files: 1


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\WINDOWS\\system32\\fscagent.exe"="C:\\WINDOWS\\system32\\fscagent.exe:*:Enabled:???? ???? ??"
"C:\\WINDOWS\\system32\\clubbox.exe"="C:\\WINDOWS\\system32\\clubbox.exe:*:Enabled:'1 ,r"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\WINDOWS\\system32\\pdrtvsvr.exe"="C:\\WINDOWS\\system32\\pdrtvsvr.exe:*:Enabled:PandoraTV VoD Control"
"C:\\Program Files\\Gizmo Project for LJ Talk\\mDNSResponder.exe"="C:\\Program Files\\Gizmo Project for LJ Talk\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Gizmo Project for LJ Talk\\Gizmo-LJ.exe"="C:\\Program Files\\Gizmo Project for LJ Talk\\Gizmo-LJ.exe:*:Enabled:Gizmo Project for LJ Talk"
"C:\\WINDOWS\\system32\\grdmgr.exe"="C:\\WINDOWS\\system32\\grdmgr.exe:*:Enabled:CDN ???? ??"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\WINDOWS\\kdx\\KHost.exe"="C:\\WINDOWS\\kdx\\KHost.exe:*:Enabled:Delivery Manager"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\system32\\P3MxSvr.exe"="C:\\WINDOWS\\system32\\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control"
"C:\\WINDOWS\\system32\\p3mxvsvr.exe"="C:\\WINDOWS\\system32\\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control"
"C:\\WINDOWS\\system32\\muzmvsvr.exe"="C:\\WINDOWS\\system32\\muzmvsvr.exe:*:Enabled:MUZ VOD Control"
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"="C:\\Program Files\\Orbitdownloader\\orbitdm.exe:*:Enabled:Orbit"
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"="C:\\Program Files\\Orbitdownloader\\orbitnet.exe:*:Enabled:Orbit"
"C:\\WINDOWS\\system32\\BugsSvr.exe"="C:\\WINDOWS\\system32\\BugsSvr.exe:*:Enabled:Bugs Music Player Control"
"C:\\WINDOWS\\system32\\p3bvsvr.exe"="C:\\WINDOWS\\system32\\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control"
"C:\\WINDOWS\\system32\\skcbgm.exe"="C:\\WINDOWS\\system32\\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player"
"C:\\Program Files\\DISC\\DISCover.exe"="C:\\Program Files\\DISC\\DISCover.exe:*:Enabled:DISCover Drop & Play System"
"C:\\Program Files\\DISC\\DiscStreamHub.exe"="C:\\Program Files\\DISC\\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub"
"C:\\Program Files\\DISC\\myFTP.exe"="C:\\Program Files\\DISC\\myFTP.exe:*:Enabled:DISCover FTP"
"C:\\Program Files\\pandora.tv\\minilite\\MiniStream.exe"="C:\\Program Files\\pandora.tv\\minilite\\MiniStream.exe:*:Enabled:MiniStream.exe"
"C:\\WINDOWS\\system32\\mnetasvr.exe"="C:\\WINDOWS\\system32\\mnetasvr.exe:*:Enabled:MNet AoD Server"
"C:\\WINDOWS\\system32\\mnetvsvr.exe"="C:\\WINDOWS\\system32\\mnetvsvr.exe:*:Enabled:MNet VoD Server"
"C:\\Program Files\\pandora.tv\\minilite\\MiniLite.exe"="C:\\Program Files\\pandora.tv\\minilite\\MiniLite.exe:*:Enabled:MiniLite.exe"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:Torrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 1 Mar 2006 211 A.SHR --- "C:\BOOT.BAK"
Wed 6 Feb 2008 217,073 A.SHR --- "C:\WINDOWS\meta4.exe"
Thu 14 Jul 2005 27,648 A.SHR --- "C:\WINDOWS\system32\AVSredirect.dll"
Sun 26 Jun 2005 616,448 A.SHR --- "C:\WINDOWS\system32\cygwin1.dll"
Tue 21 Jun 2005 45,568 A.SHR --- "C:\WINDOWS\system32\cygz.dll"
Wed 3 May 2006 163,328 ..SHR --- "C:\WINDOWS\system32\flvDX.dll"
Sun 25 Jan 2004 70,656 A.SHR --- "C:\WINDOWS\system32\i420vfw.dll"
Wed 21 Feb 2007 31,232 ..SHR --- "C:\WINDOWS\system32\msfDX.dll"
Mon 17 Dec 2007 27,648 ..SH. --- "C:\WINDOWS\system32\Smab0.dll"
Mon 4 Feb 2008 151,040 ..SH. --- "C:\WINDOWS\system32\VistaUltm.dll"
Mon 28 Feb 2005 240,128 A.SHR --- "C:\WINDOWS\system32\x.264.exe"
Sun 25 Jan 2004 70,656 A.SHR --- "C:\WINDOWS\system32\yv12vfw.dll"
Thu 29 May 2008 230,400 ..SHR --- "C:\WINDOWS\s?stem\m?config.exe"
Sat 5 Jul 2008 89,088 ..SHR --- "C:\Program Files\Common Files\?icrosoft.NET\services.exe"
Sun 26 Jun 2005 616,448 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygwin1.dll"
Tue 21 Jun 2005 45,568 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygz.dll"
Wed 6 Feb 2008 72,704 ..SHR --- "C:\Program Files\eRightSoft\SUPER\Setup.exe"
Sun 25 Mar 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 6 Mar 2006 1,302 A..H. --- "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK"
Mon 3 Jun 2002 84,992 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
Mon 3 Jun 2002 44,032 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
Mon 9 Dec 2002 73,766 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
Mon 9 Dec 2002 65,575 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
Sun 9 Jun 2002 36,864 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll"
Mon 3 Jun 2002 20,480 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
Mon 9 Dec 2002 102,437 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll"
Mon 9 Dec 2002 176,165 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
Mon 9 Dec 2002 208,935 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
Mon 9 Dec 2002 217,127 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
Sun 9 Jun 2002 40,448 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll"
Sat 3 Nov 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
Tue 10 Apr 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
Fri 20 Feb 2004 232,960 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
Sun 9 Jun 2002 525,824 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll"
Mon 9 Dec 2002 245,805 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll"
Mon 9 Dec 2002 45,093 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll"
Mon 9 Dec 2002 98,341 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll"
Mon 9 Dec 2002 94,247 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll"
Mon 9 Dec 2002 90,151 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll"
Mon 9 Dec 2002 102,439 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
Sun 9 Jun 2002 49,152 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll"
Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT2F.tmp"
Mon 12 Jun 2006 11,116 A.SH. --- "C:\Documents and Settings\HP_Administrator\My Documents\My Music\License Backup\drmv2key.bak"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\HP_Administrator\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 19 Nov 2007 8 A..H. --- "C:\Documents and Settings\HP_Administrator\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"

Finished!

-------------------------------------------------------------
Deckard's System Scanner v20071014.68
Run by HP_Administrator on 2008-07-20 18:14:16
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
9: 2008-07-21 04:14:21 UTC - RP37 - Deckard's System Scanner Restore Point
8: 2008-07-21 03:38:36 UTC - RP36 - System Checkpoint
7: 2008-07-18 11:38:33 UTC - RP35 - System Checkpoint
6: 2008-07-17 01:23:26 UTC - RP34 - System Checkpoint
5: 2008-07-15 05:40:30 UTC - RP33 - System Checkpoint


-- First Restore Point --
1: 2008-07-11 03:31:57 UTC - RP29 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

System Drive C: has 10.48 GiB (less than 15%) free.


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-07-20 18:16:52
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Grisoft\AVG Free\avgamsvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Program Files\Grisoft\AVG Free\avgupsvc.exe
C:\Program Files\Grisoft\AVG Free\avgemc.exe
C:\Program Files\Common Files\AOL\1141644703\ee\aolsoftware.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\?icrosoft.NET\services.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11822.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\s?stem\m?config.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11822.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\portsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\hp\KBD\kbd.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Documents and Settings\HP_Administrator\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daum.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2A704A86-579B-4979-BC9A-D06625ADE606} - C:\Program Files\MSN\metocolovC:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\CEMG555077.exe.dll (file missing)
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll
O2 - BHO: PPOob - {51E30BDC-0E41-4AED-8FBE-7813CB42497B} - C:\WINDOWS\system32\ppobo.dll
O2 - BHO: targetedbanner browser optimizer - {651f6428-3394-5721-1c3a-ece197d3a6c2} - C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NXIECatcher Class - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: XBTB05340 - {94F8F350-B1A4-4488-A55A-1FEE8494004F} - C:\Program Files\Search Toolbar\search.dll
O2 - BHO: (no name) - {A13E6D04-17B3-40FC-B69A-C47914BA377E} - C:\PROGRA~1\CashOn\bin\NCHO12~1.DLL (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\Jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar5.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: (no name) - {D4139E6D-2AAB-0F58-F935-7FA2979C1EE7} - C:\WINDOWS\system32\qrtblr.dll
O2 - BHO: ShopPoint Class - {DA18CDFC-11E1-48e4-BFEE-775890B9AE44} - C:\Program Files\ShopPoint\ShopPoint.dll (file missing)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll (file missing)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar5.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Search Toolbar - {D9CECB1C-55D7-4DF4-BC51-08D15C95DE5E} - C:\Program Files\Search Toolbar\search.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [pgo.exe] C:\Program Files\pointgo\pgo.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141644703\ee\AOLSoftware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [internet_webplayer] C:\Program Files\internet_webplayer\internet_webplayer.exe /WS
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [ǵTV̴] C:\Program Files\PandoraTVMini\MiniUpdate.exe
O4 - HKCU\..\Run: [confile] C:\Program Files\confile\confile.exe
O4 - HKCU\..\Run: [ShopPoint] C:\Program Files\ShopPoint\ShopPoint.exe /WS
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [upfilemans] C:\WINDOWS\upfilemans.exe
O4 - HKCU\..\Run: [choifile.exe] C:\WINDOWS\system32\choifile.exe
O4 - HKCU\..\Run: [inupdaters.exe] C:\WINDOWS\inupdaters.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Scbu] "C:\PROGRA~1\COMMON~1\ICROSO~1.NET\services.exe" -vt yazb
O4 - HKCU\..\Run: [Microsoft Windows Installer] C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11822.exe
O4 - HKCU\..\Run: [Llx] C:\WINDOWS\s?stem\m?config.exe
O4 - HKCU\..\Run: [ncevlkqd] C:\WINDOWS\system32\bepyxwvk.exe
O4 - HKCU\..\Run: [myddslyn] C:\WINDOWS\system32\fevehkty.exe
O4 - HKCU\..\Run: [nfvzuerq] C:\WINDOWS\system32\enslihod.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Download All by FlashGet - C:\Documents and Settings\HP_Administrator\Favorites\FlashGet\jc_all.htm
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: Download using FlashGet - C:\Documents and Settings\HP_Administrator\Favorites\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\nwprovau.dll
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - http://help.rr.com/Foundrysdccommon/download/tgctlar.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} (Street Technologies ActiveX Control Object) - http://www2.stlu.com/plugins/Plugin5.0.021...eetnoagent7.cab
O16 - DPF: {21FDDE58-51A6-402A-8040-39DA033DC196} (Pull0PlayerX Control) - http://image.pullbbang.com/newTop/Pull0Control.ocx
O16 - DPF: {2FDAF918-389E-4402-9DA1-F5348615BC30} (axMROpen Control) - http://www.dosirak.com/Commons/Activex/MROpen.cab
O16 - DPF: {3270EED1-B285-4828-A0A7-F55913A9B724} (S2PlayerPan Class) - http://listen.daum.net/52st/52street/S2MusicPlayer.dll
O16 - DPF: {36F46B1E-11B7-4221-B4F7-F1FC9687E7F7} (YBox Control) - http://kr.music.yahoo.com/Components/YMusicPack.cab
O16 - DPF: {3942BD43-B5CE-465F-9AC3-16BA93994273} (DosirakControl Control) - http://www.dosirak.com/Commons/Activex/DosirakControl.ocx
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc...OnlineGames.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {40A217E1-BDDA-44DE-9BBC-D678C7B48603} (EspressoAgent Control) - http://www.bluemountainsoft.com/agent/EspressoAgent.ocx
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://imgcdn.pandora.tv/pan_img/liveupdate/SVPorsche.cab
O16 - DPF: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} (DaumBGMCtrl Class) - http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1143507627125
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) - http://app.gomtv.com/gom/GomWeb.cab
O16 - DPF: {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} (MnetHelper Control) - http://www.mnet.com/Ver2/App/totalApp/maxh...r/maxhelper.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab
O16 - DPF: {913BF18F-672D-4676-9855-F9A192A88886} (IMBCContents Control) - http://touch.imbc.com/ocx/Online.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
O16 - DPF: {9B75502C-BBED-4BBD-8FE2-822E5E0AD32C} (MagicLockOCX Control) - http://www.diodeo.com/DioDeoPlayer.cab
O16 - DPF: {A0E7D0C1-9854-497E-8645-38C19AA00724} (IssacWebSE Class) - http://www.teenkorean.net/Penta/KoreanSecurity.cab
O16 - DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} (PandoraTVSet Class) - http://imgcdn.pandora.tv/pan_img/p3player/...ge/pdrtvset.cab
O16 - DPF: {B8C4B31D-6DCE-4DF0-BF73-44686849F67D} (PDRInst1 Class) - http://imgcdn.pandora.tv/pan_img/p3player/...age/pdrinst.cab
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/xman.cab?ver=1,2,3,3
O16 - DPF: {BBFD2D10-EC6E-4259-91D1-1E38C826E5E2} (Launcher Class) - http://app.gomtv.com/gomtv/gomtvx.cab
O16 - DPF: {BCA935CA-7E41-4F73-BA9C-FAB4393DBAC0} (MADanalCtrl Control) - http://www.csafer.net/ActiveX/MAStreamCtrl.cab
O16 - DPF: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} (BugsInstallEx Control) - http://install.bugs.co.kr/install/BugsInstallerEx.cab
O16 - DPF: {BD6BB450-7C69-43B8-96F3-689CAE57AB51} (SBSWebPlayer Class) - http://netv.sbs.co.kr/object/player/SBSWebPlayer.cab
O16 - DPF: {BD6F8792-B90E-4431-B0AB-08CF414E9D35} (DamoimBGMPlayerX Control) - http://bgm.iple.com/Cab/SMMusicPlayerX.cab
O16 - DPF: {C394A9A2-C51D-4C26-BB2C-6DEB30A890F4} (ActiveDiodeoPlayer Control) - http://www.diodeo.com/ActiveDiodeoPlayer.cab
O16 - DPF: {CEE326E8-7571-4086-B347-3C0ACA9A9DE8} (PcubeSet Class) - http://player.muz.co.kr/package/installer2...02/p3Instal.cab
O16 - DPF: {CF362BDB-4EA2-11D5-AB47-000102913414} (SetGlb Control) - http://touch.imbc.com/ocx/SetGlb.cab
O16 - DPF: {CFCBEE6F-BE54-4682-84F6-0E3FCDFAE3E2} (NowCAFE Control) - http://www.clubbox.co.kr/neo.fld/NowCAFE.cab
O16 - DPF: {D1160D6F-214B-4B4E-A361-977817ACC516} (websafe_player Control) - http://www.websafe.co.kr/websafe_player.cab
O16 - DPF: {D26A941D-7E89-4098-B583-43291FC14218} (Pull0PlayerX Control) - http://image.pullbbang.com/images/Pull0Control.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F4A1D5E2-AF49-47A7-A945-23038106F3A4} (Pandora_SetUp Control) - http://imgcdn.pandora.tv/pan_img/launcher/...ora_SetUpAX.cab
O16 - DPF: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} (MultiUpload Control) - http://www.clubbox.co.kr/neo.fld/MultiUpload.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: dabdbdcccffed - C:\WINDOWS\system32\dabdbdcccffed.dll
O21 - SSODL: gdqlexyz - {88fe03e6-19ba-4610-9d40-3ff9ccca9b91} - C:\Documents and Settings\All Users\Application Data\gdqlexyz.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG Free\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG Free\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG Free\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O24 - Desktop Component 0: - http://img.kbs.co.kr/cms/drama/honggildong...1152_864.jpgO24 - Desktop Component 1: - http://www.gtv.com.tw/Program/S05142005100...24768-03.jpgO24 - Desktop Component 2: - http://img.imbc.com/imbc/afieldfile/2006/0..._01_1280.jpgO24 - Desktop Component 3: - http://img.kbs.co.kr/cms/drama/honggildong...1024_768.jpgO24 - Desktop Component 4: - http://img.imbc.com/imbc/afieldfile/2006/0...all_01_1024.jpg

--
End of file - 21465 bytes

-- File Associations -----------------------------------------------------------

.scr - scrfile - shell\open\command - "%1" %*


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys

S3 catchme - c:\docume~1\hp_adm~1\locals~1\temp\catchme.sys (file missing)
S3 NOWMEMDF - c:\windows\system32\nowmemdf.sys
S3 SASENUM - c:\program files\superantispyware\sasenum.sys
S4 intelppm (Intel Processor Driver) - c:\windows\system32\drivers\intelppm.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 PlugPlayRPC (Plug and Play (RPC)) - c:\windows\portsv.exe service

S0 Pml Driver HPZ12 - \systemroot\c:\windows\system32\hpzipm12.exe (file missing)


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Wireless LAN PCI 802.11 b/g adapter WN5301A
Device ID: PCI\VEN_168C&DEV_001B&SUBSYS_500111AD&REV_01\4&1C88B56&0&50A4
Manufacturer: Liteon
Name: Wireless LAN PCI 802.11 b/g adapter WN5301A
PNP Device ID: PCI\VEN_168C&DEV_001B&SUBSYS_500111AD&REV_01\4&1C88B56&0&50A4
Service: WN5301


-- Scheduled Tasks -------------------------------------------------------------

2008-07-20 17:37:01 256 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
2008-06-01 08:01:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2006-04-30 21:00:00 480 --a------ C:\WINDOWS\Tasks\Easy Internet Sign-up.job


-- Files created between 2008-06-20 and 2008-07-20 -----------------------------

2008-07-20 16:14:46 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\uTorrent
2008-07-11 01:27:35 0 d-------- C:\Program Files\SPoint
2008-07-09 02:08:53 0 d-------- C:\WINDOWS\ERUNT
2008-07-08 16:18:56 109056 --a------ C:\WINDOWS\system32\ojevepwl.exe
2008-07-06 20:24:50 0 d-------- C:\Program Files\uTorrent
2008-07-05 14:06:30 0 d-------- C:\WINDOWS\system32\olixds06
2008-07-05 14:06:01 0 d-------- C:\Documents and Settings\All Users\Application Data\fgfwxovs
2008-07-05 14:05:51 0 d-------- C:\WINDOWS\s?stem
2008-07-05 14:05:50 60928 --a------ C:\WINDOWS\system32\qrtblr.dll
2008-07-05 14:05:37 0 d-------- C:\Program Files\Common Files\?icrosoft.NET
2008-07-05 09:07:53 94208 --a------ C:\WINDOWS\system32\pphcldrj0elce.exe
2008-07-05 09:07:34 0 d-------- C:\Documents and Settings\All Users\Application Data\pyvszqzu
2008-07-01 23:34:22 158208 --a------ C:\WINDOWS\system32\drvokevwqsuoqmfp.dll
2008-06-25 00:14:42 64317 --a------ C:\WINDOWS\system32\lzhlvjexgdlfth.exe
2008-06-25 00:11:13 0 d-------- C:\WINDOWS\system32\1804
2008-06-25 00:11:12 55808 --a------ C:\WINDOWS\portsv.exe
2008-06-24 16:55:19 0 d-------- C:\Program Files\?icrosoft.NET
2008-06-24 10:55:57 0 d-------- C:\Documents and Settings\Guest\Application Data\Viewpoint
2008-06-23 15:54:32 0 d-------- C:\WINDOWS\system32\?icrosoft.NET
2008-06-23 15:07:43 6680 --a------ C:\WINDOWS\system32\iehlpr32.dll
2008-06-22 09:54:56 0 d-------- C:\Documents and Settings\Guest\Application Data\Malwarebytes
2008-06-22 03:56:51 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\?ppPatch
2008-06-22 03:56:40 0 d-------- C:\WINDOWS\system32\??pPatch
2008-06-22 03:56:27 118784 --a------ C:\Documents and Settings\All Users\Application Data\gdqlexyz.dll
2008-06-22 03:55:54 88537 --a------ C:\WINDOWS\lfn.exe


-- Find3M Report ---------------------------------------------------------------

2008-07-20 16:04:30 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\AVG7
2008-07-10 14:51:59 0 d-------- C:\Program Files\MSN Encarta Standard
2008-07-08 20:23:03 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-08 16:30:37 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\Orbit
2008-07-06 22:46:27 0 d-------- C:\Program Files\Common Files
2008-07-06 00:16:13 14 --a------ C:\1
2008-07-05 14:05:37 0 d-------- C:\Program Files\Common Files\?icrosoft.NET
2008-07-02 16:11:26 0 d-------- C:\Program Files\pointgo
2008-07-02 16:11:15 113169 -----n--- C:\WINDOWS\system32\dabdbdcccffed.dll
2008-07-01 17:17:42 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-06-25 10:09:20 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\?ppPatch
2008-06-25 04:39:45 0 d-------- C:\Program Files\Avidemux 2.4
2008-06-25 04:34:48 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\gtk-2.0
2008-06-24 16:55:19 0 d-------- C:\Program Files\?icrosoft.NET
2008-06-22 17:33:00 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-06-14 07:28:41 135168 --a------ C:\WINDOWS\bwzwpmju.dll
2008-06-14 03:22:17 0 d-------- C:\Program Files\Aegisub
2008-06-06 06:48:55 401972 --a------ C:\WINDOWS\system32\g68.exe
2008-06-04 14:48:57 49191 --a------ C:\WINDOWS\system32\jjwnw64l.exe
2008-06-03 03:30:38 1540096 -ra------ C:\WINDOWS\system32\clubbox.exe
2008-06-01 08:07:20 0 d-------- C:\Program Files\Apple Software Update
2008-06-01 07:44:27 862 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-06-01 07:44:23 88961 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-06-01 07:44:23 200768 --a------ C:\WINDOWS\system32\kcntkkdm.exe
2008-06-01 07:44:23 298311 --a------ C:\WINDOWS\system32\gside.exe
2008-06-01 05:06:19 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\GRETECH
2008-05-27 03:38:14 370176 --a------ C:\WINDOWS\system32\{fe834001-d193-795e-f829-3eea5cdb4f56}.dll
2008-05-27 00:49:18 0 d-------- C:\Program Files\Soulseek
2008-05-21 22:05:23 0 d-------- C:\Documents and Settings\HP_Administrator\Application Data\HP
2008-05-09 17:16:51 46 --a------ C:\WINDOWS\system32\DonationCoder_urlsnooper_InstallInfo.dat


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A704A86-579B-4979-BC9A-D06625ADE606}]
C:\Program Files\MSN\metocolovC:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\CEMG555077.exe.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51E30BDC-0E41-4AED-8FBE-7813CB42497B}]
04/01/2006 09:21 PM 51216 --a------ C:\WINDOWS\system32\ppobo.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{651f6428-3394-5721-1c3a-ece197d3a6c2}]
C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94F8F350-B1A4-4488-A55A-1FEE8494004F}]
02/20/2007 04:06 AM 868424 --a------ C:\PROGRA~1\SEARCH~1\search.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A13E6D04-17B3-40FC-B69A-C47914BA377E}]
C:\PROGRA~1\CashOn\bin\NCHO12~1.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4139E6D-2AAB-0F58-F935-7FA2979C1EE7}]
05/29/2008 08:34 AM 60928 --a------ C:\WINDOWS\system32\qrtblr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA18CDFC-11E1-48e4-BFEE-775890B9AE44}]
C:\Program Files\ShopPoint\ShopPoint.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{D9CECB1C-55D7-4DF4-BC51-08D15C95DE5E}"= C:\Program Files\Search Toolbar\search.dll [02/20/2007 04:06 AM 868424]

[-HKEY_CLASSES_ROOT\CLSID\{D9CECB1C-55D7-4DF4-BC51-08D15C95DE5E}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/05/2005 06:56 PM]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [08/02/2005 09:19 PM C:\WINDOWS\arpwrmsg.exe]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [06/01/2005 08:35 PM]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [09/21/2005 07:41 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [05/12/2005 04:12 AM]
"ClubBox"="" []
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/10/2004 02:00 AM]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [08/10/2004 02:00 AM]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [08/10/2004 02:00 AM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/10/2004 02:00 AM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/10/2004 02:00 AM]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [11/29/2005 07:19 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/25/2006 06:58 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/30/2006 09:36 AM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [12/20/2007 07:43 PM]
"pgo.exe"="C:\Program Files\pointgo\pgo.exe" [04/17/2008 02:31 PM]
"HostManager"="C:\Program Files\Common Files\AOL\1141644703\ee\AOLSoftware.exe" [11/02/2005 05:01 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/10/2004 02:00 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" []
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [11/29/2005 07:19 PM]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 11:34 AM]
"internet_webplayer"="C:\Program Files\internet_webplayer\internet_webplayer.exe" [02/13/2007 04:02 AM]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [12/12/2006 04:55 PM]
"ǵTV̴"="C:\Program Files\PandoraTVMini\MiniUpdate.exe" []
"confile"="C:\Program Files\confile\confile.exe" []
"ShopPoint"="C:\Program Files\ShopPoint\ShopPoint.exe" []
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [03/15/2007 06:16 PM]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 04:45 PM]
"upfilemans"="C:\WINDOWS\upfilemans.exe" [03/29/2008 03:36 PM]
"choifile.exe"="C:\WINDOWS\system32\choifile.exe" [04/05/2008 02:24 PM]
"inupdaters.exe"="C:\WINDOWS\inupdaters.exe" [04/04/2008 01:39 PM]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [11/02/2005 05:01 PM]
"Scbu"="C:\PROGRA~1\COMMON~1\ICROSO~1.NET\services.exe" [07/05/2008 02:05 PM]
"Microsoft Windows Installer"="C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11822.exe" [07/05/2008 02:05 PM]
"Llx"="C:\WINDOWS\s?stem\m?config.exe" []
"ncevlkqd"="C:\WINDOWS\system32\bepyxwvk.exe" []
"myddslyn"="C:\WINDOWS\system32\fevehkty.exe" []
"nfvzuerq"="C:\WINDOWS\system32\enslihod.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [5/12/2005 4:23:26 AM]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [12/8/2005 7:20:00 AM]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [3/7/2006 2:44:17 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [06/22/2008 05:33 PM 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gdqlexyz"= {88fe03e6-19ba-4610-9d40-3ff9ccca9b91} - C:\Documents and Settings\All Users\Application Data\gdqlexyz.dll [06/22/2008 03:56 AM 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dabdbdcccffed]
C:\WINDOWS\system32\dabdbdcccffed.dll 07/02/2008 04:11 PM 113169 C:\WINDOWS\system32\dabdbdcccffed.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cashonupdate]
C:\Program Files\CashOn\bin\CashOnUpdate02101900.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DISCover]
C:\Program Files\DISC\DISCover.exe nogui

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lphcldrj0elce]
C:\WINDOWS\system32\lphcldrj0elce.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ncservice]
C:\Program Files\CashOn\bin\ncservice08151758.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCUP]
C:\WINDOWS\system32\NCUP12122051.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMrhcgdrj0elce]
C:\Program Files\rhcgdrj0elce\rhcgdrj0elce.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPUP]
C:\WINDOWS\system32\SPUPDAT02111445.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wtkjmvmb]
regsvr32 /u "C:\Documents and Settings\All Users\Application Data\wtkjmvmb.dll"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{3ee73c2a-1f35-7807-482d-aee9d0bb277d}]
C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll" DllStart


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51375106-a9bd-11da-b0b0-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480




-- End of Deckard's System Scanner: finished at 2008-07-20 18:20:35 ------------

---------------------------------------------------------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 X2 Dual Core Processor 4200+
CPU 1: AMD Athlon™ 64 X2 Dual Core Processor 4200+
Percentage of Memory in Use: 49%
Physical Memory (total/avail): 958.48 MiB / 484.39 MiB
Pagefile Memory (total/avail): 2313.54 MiB / 1939.9 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1896.07 MiB

C: is Fixed (NTFS) - 224.37 GiB total, 10.48 GiB free.
D: is Fixed (FAT32) - 8.5 GiB total, 1.13 GiB free.
E: is CDROM (UDF)
F: is CDROM (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
J: is Removable (No Media)

\\.\PHYSICALDRIVE0 - ST3250823AS - 232.88 GiB - 2 partitions
\PARTITION0 - Unknown - 8.51 GiB - D:
\PARTITION1 (bootable) - Installable File System - 224.37 GiB - C:

\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device

\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device

\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device

\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

AV: AVG 7.5.516 v7.5.516 (Grisoft) Outdated

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\WINDOWS\\system32\\fscagent.exe"="C:\\WINDOWS\\system32\\fscagent.exe:*:Enabled:???? ???? ??"
"C:\\WINDOWS\\system32\\clubbox.exe"="C:\\WINDOWS\\system32\\clubbox.exe:*:Enabled:嬷 "
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\WINDOWS\\system32\\pdrtvsvr.exe"="C:\\WINDOWS\\system32\\pdrtvsvr.exe:*:Enabled:PandoraTV VoD Control"
"C:\\Program Files\\Gizmo Project for LJ Talk\\mDNSResponder.exe"="C:\\Program Files\\Gizmo Project for LJ Talk\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Gizmo Project for LJ Talk\\Gizmo-LJ.exe"="C:\\Program Files\\Gizmo Project for LJ Talk\\Gizmo-LJ.exe:*:Enabled:Gizmo Project for LJ Talk"
"C:\\WINDOWS\\system32\\grdmgr.exe"="C:\\WINDOWS\\system32\\grdmgr.exe:*:Enabled:CDN ???? ??"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\WINDOWS\\kdx\\KHost.exe"="C:\\WINDOWS\\kdx\\KHost.exe:*:Enabled:Delivery Manager"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\system32\\P3MxSvr.exe"="C:\\WINDOWS\\system32\\P3MxSvr.exe:*:Enabled:Maxmp3 AoD Control"
"C:\\WINDOWS\\system32\\p3mxvsvr.exe"="C:\\WINDOWS\\system32\\p3mxvsvr.exe:*:Enabled:MAXMP3 VOD Control"
"C:\\WINDOWS\\system32\\muzmvsvr.exe"="C:\\WINDOWS\\system32\\muzmvsvr.exe:*:Enabled:MUZ VOD Control"
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"="C:\\Program Files\\Orbitdownloader\\orbitdm.exe:*:Enabled:Orbit"
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"="C:\\Program Files\\Orbitdownloader\\orbitnet.exe:*:Enabled:Orbit"
"C:\\WINDOWS\\system32\\BugsSvr.exe"="C:\\WINDOWS\\system32\\BugsSvr.exe:*:Enabled:Bugs Music Player Control"
"C:\\WINDOWS\\system32\\p3bvsvr.exe"="C:\\WINDOWS\\system32\\p3bvsvr.exe:*:Enabled:Bugs Music VoD Control"
"C:\\WINDOWS\\system32\\skcbgm.exe"="C:\\WINDOWS\\system32\\skcbgm.exe:*:Enabled:SK Communications Cyworld BGM Player"
"C:\\Program Files\\DISC\\DISCover.exe"="C:\\Program Files\\DISC\\DISCover.exe:*:Enabled:DISCover Drop & Play System"
"C:\\Program Files\\DISC\\DiscStreamHub.exe"="C:\\Program Files\\DISC\\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub"
"C:\\Program Files\\DISC\\myFTP.exe"="C:\\Program Files\\DISC\\myFTP.exe:*:Enabled:DISCover FTP"
"C:\\Program Files\\pandora.tv\\minilite\\MiniStream.exe"="C:\\Program Files\\pandora.tv\\minilite\\MiniStream.exe:*:Enabled:MiniStream.exe"
"C:\\WINDOWS\\system32\\mnetasvr.exe"="C:\\WINDOWS\\system32\\mnetasvr.exe:*:Enabled:MNet AoD Server"
"C:\\WINDOWS\\system32\\mnetvsvr.exe"="C:\\WINDOWS\\system32\\mnetvsvr.exe:*:Enabled:MNet VoD Server"
"C:\\Program Files\\pandora.tv\\minilite\\MiniLite.exe"="C:\\Program Files\\pandora.tv\\minilite\\MiniLite.exe:*:Enabled:MiniLite.exe"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:Torrent"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\HP_Administrator\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_05\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=OHANA
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\HP_Administrator
LOGONSERVER=\\OHANA
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\ESTsoft\ALZip\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\ESTsoft\ALZip\;;C:\PROGRA~1\COMMON~1\MUVEET~1\030625;C:\PROGRA~1\COMMON~1\MUVEET~1\030625
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 43 Stepping 1, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=2b01
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_05\lib\ext\QTJava.zip
SESSIONNAME=Console
SonicCentral=c:\Program Files\Common Files\Sonic Shared\Sonic Central\
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
USERDOMAIN=OHANA
USERNAME=HP_Administrator
USERPROFILE=C:\Documents and Settings\HP_Administrator
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

HP_Administrator (admin)
Administrator (admin)
Guest (guest)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
--> c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
--> c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
--> c:\WINDOWS\system32\\MSIEXEC.EXE /x {F80239D8-7811-4D5E-B033-0D0BBFE32920}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
̹÷̾ --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79BE13F7-95CB-4E02-818A-5EC7954E886E}\Setup.exe"
ͳ-÷̾ --> "C:\Program Files\internet_webplayer\internet_webplayer.exe" /UNINSTALL
ǵTV ̴϶Ʈ --> "C:\Program Files\Pandora.tv\MiniLite\unins000.exe"
Torrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
5 Card Slingo from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\AF012B1F-AFCE-45DB-8D6C-8AB06ADC1D6F\Uninstall.exe"
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Adobe Reader Korean Fonts --> MsiExec.exe /I{AC76BA86-7AD7-5676-5A64-7E8A45000001}
Aegisub 1.10 (Remove Only) --> C:\Program Files\Aegisub\Uninstall.exe
ALZip --> "C:\Program Files\ESTsoft\ALZip\unins000.exe"
AOL HI-Q Video --> C:\WINDOWS\kdx\KHost.exe -u -p aolhqvprod
AOL Uninstaller (Choose which Products to Remove) --> C:\Program Files\Common Files\AOL\uninstaller.exe
Apple Software Update --> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
AstroPop Deluxe from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\E44A47AF-C94B-4E3F-81A0-979FBA9DAC57\Uninstall.exe"
ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Auto Gordian Knot 2.27 --> C:\Program Files\AutoGK\uninst.exe
AVG Free Edition --> C:\Program Files\Grisoft\AVG Free\setup.exe /UNINSTALL
Avidemux 2.4 --> C:\Program Files\Avidemux 2.4\uninstall.exe
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Barnyard Invasion from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\049D60AF-B425-4F8A-BD66-9D8C1B519D59\Uninstall.exe"
Bejeweled 2 Deluxe from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\47D5A62B-1B41-4DB1-8267-ADA434FA782B\Uninstall.exe"
BitComet 0.84 --> C:\Program Files\BitComet\uninst.exe
Blackhawk Striker 2 from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\758619C0-7C97-42BB-B1E9-775F72FDAD1E\Uninstall.exe"
Blasterball 2 from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\D2DACBCD-E1FE-4C32-A49B-1EB0743D1E79\Uninstall.exe"
Blasterball 2 Remix from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\0C84A7C5-2762-4932-96BF-44A77202DCC3\Uninstall.exe"
Boggle Supreme from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\90EA5584-4290-407B-B8F2-D6E6D65A4796\Uninstall.exe"
Bookworm Deluxe from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\E59F75D0-A38B-40F4-ABA2-CA35A7735473\Uninstall.exe"
Bounce Symphony from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\5DAA9E44-1B31-41CD-88A8-228EDED6E36E\Uninstall.exe"
CDBurnerXP Pro 3 --> MsiExec.exe /I{896D642C-7125-44F0-AC49-A23ABF82209C}
Chuzzle Deluxe from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\BA42B721-D70B-4412-ABA6-057B5823FDE9\Uninstall.exe"
Crystal Maze from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\3D61540E-C88C-4358-B6A1-DC26648F2A3D\Uninstall.exe"
Customer Experience Enhancement --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1033
Data Fax SoftModem with SmartCP --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1\HXFSETUP.EXE -U -IAsu200Ck.inf
Daum ActiveX Ʈ - ?? ?? ??? --> Rundll32.exe C:\WINDOWS\system32\DaumActiveX_2_0_0_4.dll,InfInst -u -f:"C:\Program Files\Daum\DaumActiveX\modules\{6A2E758A-028B-46BB-A11D-0608AB5A4ED3}\0,0,1,1\opt.txt"
Daum ActiveX Ʈ - ?? ??? --> "C:\WINDOWS\system32\xmaninf.exe" -u -f:"C:\Program Files\Daum\Xman\modules\{91011241-B724-4758-83E6-E13D5AD35B7B}\0,0,1,5\opt.txt"
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivXLand Media Subtitler --> C:\WINDOWS\unvise32.exe C:\Program Files\DivXLand\Media Subtitler\uninstal.log
Drivers Install For Linksys Easylink Advisor --> MsiExec.exe /I{A1960A82-DB70-474D-A86B-FA74466103C6}
DVD2SVCD 1.2.3 Build 1 --> "C:\Program Files\DVD2SVCD\unins000.exe"
Easy Internet Sign-up --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1033
Enhancement Browser Tools Targetedbanner --> C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll-uninst.exe
FATE from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\3320769C-062B-4670-BD6B-AA4B3D0E9903\Uninstall.exe"
FlashGet(JetCar) --> C:\PROGRA~1\FlashGet\UNWISE.EXE C:\PROGRA~1\FlashGet\INSTALL.LOG
GemMaster Mystic --> "C:\Program Files\GemMaster\uninstallgemmaster.exe"
GOM Player --> "C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
Google Earth --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar5.dll"
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Boot Optimizer --> C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe /uninstall
HP Deskjet Printer Preload --> MsiExec.exe /I{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}
HP DigitalMedia Archive --> MsiExec.exe /I{F80239D8-7811-4D5E-B033-0D0BBFE32920}
HP Document Viewer 5.3 --> C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
HP Game Console and games --> C:\Program Files\WildTangent\Apps\hpuninstall.exe
HP Games 3.43.97 --> "C:\Program Files\DISC\uninstall.exe"
HP Image Zone 5.3 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Image Zone for Media Center PC --> c:\Program Files\HP\Digital Imaging\bin\mcpc\setupmcl.exe /u
HP Imaging Device Functions 5.3 --> C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP Multimedia Keyboard Software --> C:\HP\KBD\Install.exe /remove
HP Photosmart 330,380,420,470,7800,8000,8200 Series --> C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\setup\hpzscr01.exe -d MsiRollbackUninstaller -datfile hphscr08.dat
HP Photosmart Cameras 5.0 --> C:\Program Files\HP\Digital Imaging\{C83A12B9-B31B-461A-BBD4-CE9B988094F1}\setup\hpzscr01.exe -datfile hpiscr01.dat
HP PSC & OfficeJet 5.3.A --> "C:\Program Files\HP\Digital Imaging\{3E386744-10FA-44b2-98C9-DF7A270DECB3}\setup\hpzscr01.exe" -datfile hposcr06.dat
HP PSC & OfficeJet 5.3.B --> "C:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
HP Software Update --> MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
HP Solution Center & Imaging Support Tools 5.3 --> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
Huffyuv AVI lossless video codec (Remove Only) --> rundll.exe setupx.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\HUFFYUV.INF
Image Resizer Powertoy for Windows XP --> MsiExec.exe /I{1CB92574-96F2-467B-B793-5CEB35C40C29}
ImageMixer VCD/DVD2 for OLYMPUS --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}\Setup.exe" -l0x9 UNINSTALL
Insaniquarium Deluxe from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\A09026AE-8F16-4929-B4E6-1825535844DB\Uninstall.exe"
InterVideo WinDVD Player --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
iPod for Windows 2006-06-28 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BD57EA4D-026E-4F08-9B93-080E282B81FE} /l1033
iTunes --> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
J2SE Runtime Environment 5.0 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
K-Lite Codec Pack 2.70 Full --> "C:\Program Files\K-Lite Codec Pack\unins000.exe"
Last.fm Player 1.1.4 --> "C:\Program Files\Last.fm Player\unins000.exe"
Learn2.com Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe
Lemonade Tycoon 2 from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\F38688AF-57C2-4A9C-BFEF-25F3AEC11F1E\Uninstall.exe"
Lexibox Deluxe from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\9844050E-4CA4-4901-A53D-A5D14C63789B\Uninstall.exe"
Linksys EasyLink Advisor 1.6 (0032) --> rundll32 C:\PROGRA~1\LINKSY~1\AUInst.dll,ExUninstall
Mah Jong Quest from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\538B9061-0C77-4FB2-903F-EC42A1FF5DD8\Uninstall.exe"
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Mega Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}\setup.exe" -l0x9 -removeonly
MegaUpload Toolbar --> C:\Program Files\MegauploadToolbar\uninstall.exe
Microsoft Away Mode -->
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Money 2005 --> C:\Program Files\Microsoft Money 2005\MNYCoreFiles\Setup\uninst.exe /s:120
Microsoft Office 2003 Edition 60 Days Trial Welcome Tour --> MsiExec.exe /I{A01FC76F-CC09-4658-9E37-5C2F635EE708}
Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR) --> MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Works --> MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
mIRC --> "C:\Program Files\mIRC\mirc.exe" -uninstall
Mnet.com ո 2.0 --> "C:\Program Files\MnetPlayerModule\UNWebPlayerSetup.exe"
MPEG Encoder 3 --> C:\Program Files\ImTOO\MPEG Encoder 3\Uninstall.exe
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MultiTranse 3.7.1 --> "C:\Program Files\MultiTranse\unins000.exe"
muvee autoProducer 4.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E7137AFD-4E43-47A6-BDC7-533808F72B36}\setup.exe" -l0x9
muvee autoProducer unPlugged 1.2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DFB0FED6-0010-4E9B-A402-E513F2459161}\setup.exe" -l0x9
OLYMPUS Master --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{BA820A24-704B-428D-9904-71A10DAC1372} /l1033 /zUNINSTALL
Orbit Downloader --> "C:\Program Files\Orbitdownloader\unins000.exe"
Otto --> "C:\Program Files\EnglishOtto\uninstallotto.exe"
PandoraTV WebPlayer Uninstaller --> "C:\WINDOWS\unins000.exe"
PC-Doctor 5 for Windows --> C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
pointgo --> C:\Program Files\pointgo\uninstall.exe
Polar Bowler from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\1FFA88DF-0AC3-4D9E-9139-5FF98813C12C\Uninstall.exe"
Polar Golfer from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\55275778-F7D9-4BA0-95F4-DEFD71ADDFD9\Uninstall.exe"
PS2 --> C:\WINDOWS\system32\ps2.exe uninstall
Python 2.2.3 --> C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
Quicken 2006 --> MsiExec.exe /X{2818095F-FB6C-42C8-827E-0A406CC9AFF5}
QuickTime --> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
Real Alternative 1.47 --> "C:\Program Files\Real Alternative\unins000.exe"
Remove IntelliMover Demo --> c:\hp\bin\cloaker.exe c:\hp\bin\commands.exe /c "C:\Program Files\IntelliMoverDemo\clean.bat"
Rhapsody Player Engine --> MsiExec.exe /I{30C2FCD0-FF7B-4FFA-8DDE-43A22E01A1E7}
Ricochet Lost Worlds from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\0AA27562-3C4E-4860-8742-7ADEBE2EFC43\Uninstall.exe"
Scientific-Atlanta WebSTAR 2000 series Cable Modem --> UNDPX2A.EXE
SCRABBLE from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\B7217206-A362-446B-A0F7-A2622B82F821\Uninstall.exe"
Search Toolbar --> regsvr32 /u /s "C:\Program Files\Search Toolbar\search.dll"
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Shooting Stars Pool from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\B2AA88B1-4920-462B-9F7C-019782B3C4DB\Uninstall.exe"
Shop-Point --> C:\Program Files\SPoint\bin\UnInstallTool.exe
ShopPoint Uninstall --> C:\Program Files\ShopPoint\ShopPoint.exe /UNINSTALL
Shrek 2 Ogre Bowler from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\581538B9-2ED3-45E2-96CB-22AD8F811D2A\Uninstall.exe"
Slingo Deluxe from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\E0998E52-9D08-4AEE-A4F5-0BB1D8537F6E\Uninstall.exe"
Smart Menus (Windows Live Toolbar) --> MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
Snowboard SuperJam from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\038D56DF-B15D-47F7-959F-59FA1FBB63FC\Uninstall.exe"
Sonic Express Labeler --> MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Sonic MyDVD Plus --> MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow Audio --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Sony Media Manager 2.2 --> MsiExec.exe /X{47AA42FD-0450-4CB4-ADAF-B6E770AA7B2F}
Sony Vegas 7.0b --> MsiExec.exe /X{EC6BAAC5-F5E0-48D4-B4B6-7C654DD54086}
SoulSeek Client 156c --> "C:\Program Files\Soulseek\uninstall.exe"
Sub Station Alpha v4.08 --> C:\WINDOWS\uninst.exe -f"C:\Program Files\Sub Station Alpha v4.08\DeIsL1.isu" -c"C:\Program Files\Sub Station Alpha v4.08\_ISREG32.DLL"
Subtitle Workshop 2.51 --> "C:\Program Files\URUSoft\Subtitle Workshop\uninstall.exe"
SUPER Version 2008.bld.25 (Feb 5, 2008) --> C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
Super Granny from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\0C20CAB1-F8BC-4AC1-A796-535B005C1B83\Uninstall.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
The Print Shop CD Label Creator --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AF872EF-E6C5-41C8-BCA2-1990396D21DE}\Setup.exe" -l0x9 anything
Tradewinds from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\B3FF79F4-CDA8-4845-A7C0-9CE017719F36\Uninstall.exe"
TVAnts 1.0 --> C:\PROGRA~1\TVAnts\UNWISE.EXE C:\PROGRA~1\TVAnts\INSTALL.LOG
Update Rollup 2 for Windows XP Media Center Edition 2005 -->
Updates from HP (remove only) --> C:\WINDOWS\HPCPCUninstall-9972322\HPBWSetup.exe -appid 9972322 -uninstall
URL Snooper v2.21.01 --> "C:\Program Files\URLSnooper2\unins000.exe"
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
WinAVIVideoConverter --> "C:\Program Files\WinAVIVideoConverter\unins000.exe"
Windows Driver for Cashontool --> C:\Program Files\CashOn\bin\uninToolbar.exe
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Live Toolbar --> "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Toolbar --> MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Media Encoder 9 Series --> msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Encoder 9 Series --> MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows XP Media Center Edition 2005 KB925766 --> "C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
WinPcap 4.1 beta2 --> C:\Program Files\WinPcap\uninstall.exe
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
WM Recorder 12.0 --> C:\Program Files\WMR11\Uninstal.exe
Xvid 1.1.2 final uninstall --> "C:\Program Files\Xvid\unins000.exe"
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
Zuma Deluxe from HP Media Center (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\901E0096-B2AC-469E-A99E-2725A39C0B47\Uninstall.exe"


-- Application Event Log -------------------------------------------------------

Event Record #/Type13007 / Error
Event Submitted/Written: 07/20/2008 06:19:33 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: with error: The specified server cannot perform the requested operation.

Event Record #/Type13006 / Error
Event Submitted/Written: 07/20/2008 06:19:00 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: with error: This operation returned because the timeout period expired.

Event Record #/Type12972 / Error
Event Submitted/Written: 07/16/2008 11:54:24 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application gom.exe, version 2.1.9.3754, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
Processing media-specific event for [gom.exe!ws!]

Event Record #/Type12971 / Error
Event Submitted/Written: 07/16/2008 11:54:18 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2900.3156, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
Processing media-specific event for [explorer.exe!ws!]

Event Record #/Type12947 / Error
Event Submitted/Written: 07/15/2008 02:38:44 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2900.3156, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
Processing media-specific event for [explorer.exe!ws!]



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type282695 / Error
Event Submitted/Written: 07/20/2008 06:02:01 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 59 minutes.
NtpClient has no source of accurate time.

Event Record #/Type282694 / Error
Event Submitted/Written: 07/20/2008 06:02:01 PM
Event ID/Source: 17 / W32Time
Event Description:
Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Event Record #/Type282693 / Error
Event Submitted/Written: 07/20/2008 05:32:01 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 29 minutes.
NtpClient has no source of accurate time.

Event Record #/Type282692 / Error
Event Submitted/Written: 07/20/2008 05:32:01 PM
Event ID/Source: 17 / W32Time
Event Description:
Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Event Record #/Type282691 / Error
Event Submitted/Written: 07/20/2008 05:17:01 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 14 minutes.
NtpClient has no source of accurate time.



-- End of Deckard's System Scanner: finished at 2008-07-20 18:20:35 ------------

Fix code tags. ~ OB

Edited by Orange Blossom, 21 July 2008 - 03:26 PM.


BC AdBot (Login to Remove)

 


#2 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:05:56 PM

Posted 23 July 2008 - 04:22 AM

Hello Yoori and welcome to BleepingComputer,

1. * Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Under Browsing History, click Delete.
  • Click Delete Files, Delete cookies and Delete history
  • Click Close below.
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu..
  • Click the Clear now button below.. A new window will popup what to clear.
  • Select all and click the Clear button again.
  • Click OK to close the Options window
* Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.
2. Please download Malwarebytes' Anti-Malware from Here or Here

Doubleclick mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

3. Restart your computer.

4. Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first (not for Windows Vista users !).
The Windows Recovery Console will allow you to boot up into a special recovery mode, in case your computer has a problem after an attempted removal of malware. This allows us to help you. (WinXP SP3 users, please download the appropriate SP2 file, Home or Pro, to install the RC)

In the event you already have Combofix, delete your current version and download the latest version as described in the tutorial.
It must be saved directly to your desktop.


Note: Make sure not to click ComboFix's window while it's running. That may cause it to stall or freeze.

Please post the log from ComboFix (can also be found as C:\ComboFix.txt) in your next reply. :thumbsup:

If you have any questions along the way, STOP and ask them before proceeding !!

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#3 yoori

yoori
  • Topic Starter

  • Members
  • 149 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:In Your Dreams
  • Local time:05:56 AM

Posted 24 July 2008 - 06:50 AM

Thank you Thunder for your help. I haven't tried it out yet, but I will asap
and post up the results ^____^.

#4 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:05:56 PM

Posted 24 July 2008 - 07:47 AM

Very well, Yoori

I'll see your logs in your next reply then. :thumbsup:

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#5 yoori

yoori
  • Topic Starter

  • Members
  • 149 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:In Your Dreams
  • Local time:05:56 AM

Posted 06 August 2008 - 09:20 PM

Sorry Thunder for the long wait.

here are my logs

---------------------------------------
Malwarebytes' Anti-Malware 1.08
Database version: 471

Scan type: Quick Scan
Objects scanned: 55551
Time elapsed: 34 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
--------------------------------------------
ComboFix 08-07-22.4 - HP_Administrator 2008-08-06 15:27:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.484 [GMT -10:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\icroso~1.net\?icrosoft.NET\
C:\Program Files\Common Files\icroso~1.net\services.exe
C:\Program Files\icroso~1.net
C:\WINDOWS\444.471
C:\WINDOWS\lfn.exe
C:\WINDOWS\mainms.vpi
C:\WINDOWS\portsv.exe
C:\WINDOWS\pppatc~1
C:\WINDOWS\sstem~1
C:\WINDOWS\sstem~1\m?config.exe
C:\WINDOWS\system32\gside.exe
C:\WINDOWS\system32\icroso~1.net
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mysidesearch_sidebar.dll
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\system32\ppatch~1
C:\WINDOWS\system32\winpfz33.sys
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-07-07 to 2008-08-07 )))))))))))))))))))))))))))))))
.

2008-07-22 05:11 . 2008-07-31 19:08 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-07-20 17:14 . 2008-07-20 17:14 <DIR> d-------- C:\Deckard
2008-07-20 16:14 . 2008-08-06 14:59 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\uTorrent
2008-07-16 22:36 . 2008-07-16 22:36 113,169 --------- C:\WINDOWS\system32\07a415ca8d50e0c64247c07f15daa594.TMP
2008-07-11 01:27 . 2008-07-11 01:27 <DIR> d-------- C:\Program Files\SPoint
2008-07-09 02:08 . 2008-07-09 02:09 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-08 16:20 . 2008-07-12 17:33 <DIR> d-------- C:\SDFix
2008-07-08 16:18 . 2008-07-08 16:18 109,056 --a------ C:\WINDOWS\system32\ojevepwl.exe
2008-07-08 15:44 . 2008-07-08 15:44 137 --a------ C:\WINDOWS\system32\MRT.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-07 01:24 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\AVG7
2008-08-07 00:59 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Orbit
2008-08-04 12:27 --------- d-----w C:\Program Files\pointgo
2008-07-21 02:14 --------- d-----w C:\Program Files\uTorrent
2008-07-17 08:33 --------- d-----w C:\Documents and Settings\Guest\Application Data\AVG7
2008-07-11 00:51 --------- d-----w C:\Program Files\MSN Encarta Standard
2008-07-11 00:22 94,208 ----a-w C:\WINDOWS\system32\pphcldrj0elce.exe
2008-07-09 06:23 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 06:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-06 14:51 63,909 ----a-w C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll-uninst.exe
2008-07-06 13:48 64,317 ----a-w C:\WINDOWS\system32\lzhlvjexgdlfth.exe
2008-07-06 00:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\fgfwxovs
2008-07-05 22:52 113,169 ------w C:\WINDOWS\system32\da61156c48785f1b2b27248a057e8332.TMP
2008-07-05 22:51 --------- d-----w C:\Documents and Settings\Guest\Application Data\uTorrent
2008-07-05 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\pyvszqzu
2008-07-04 23:18 113,169 ------w C:\WINDOWS\system32\f6ebeadfb8f1d467d4e928c42bc0c729.TMP
2008-07-04 01:51 113,169 ------w C:\WINDOWS\system32\735c0ea36c98215d074f6722ab077fd2.TMP
2008-07-03 02:11 113,169 ------w C:\WINDOWS\system32\ea9f12518e978d877aa66a9b8fbdf220.TMP
2008-07-03 02:11 113,169 ------w C:\WINDOWS\system32\dabdbdcccffed.dll
2008-07-02 09:34 158,208 ----a-w C:\WINDOWS\system32\drvokevwqsuoqmfp.dll
2008-07-02 03:17 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-07-02 03:00 113,169 ------w C:\WINDOWS\system32\7fafca53883fe2e0922ec2222bb981aa.TMP
2008-07-01 01:58 113,169 ------w C:\WINDOWS\system32\072a99c59a97fc3c4ed0d12d2fe88933.TMP
2008-06-30 01:12 113,169 ------w C:\WINDOWS\system32\47821e887545df5af4b99c1ede062d3b.TMP
2008-06-28 01:49 113,169 ------w C:\WINDOWS\system32\f2c7e529e3d4f561571bfab109bd7d37.TMP
2008-06-27 00:29 113,169 ------w C:\WINDOWS\system32\6d85a8ff8b298bfe40e11565e9a085ff.TMP
2008-06-26 00:38 113,169 ------w C:\WINDOWS\system32\28a9b35becbf2d162d941e1de349c381.TMP
2008-06-25 20:09 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\?ppPatch
2008-06-25 14:39 --------- d-----w C:\Program Files\Avidemux 2.4
2008-06-25 14:34 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\gtk-2.0
2008-06-24 20:55 --------- d-----w C:\Documents and Settings\Guest\Application Data\Viewpoint
2008-06-24 01:07 6,680 ----a-w C:\WINDOWS\system32\iehlpr32.dll
2008-06-23 03:33 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-06-22 19:54 --------- d-----w C:\Documents and Settings\Guest\Application Data\Malwarebytes
2008-06-22 13:56 118,784 ----a-w C:\Documents and Settings\All Users\Application Data\gdqlexyz.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-18 02:04 1,836,384 ----a-w C:\WINDOWS\system32\DaumActiveX_2_0_0_4.dll
2008-06-14 17:28 135,168 ----a-w C:\WINDOWS\bwzwpmju.dll
2008-06-14 13:22 --------- d-----w C:\Program Files\Aegisub
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 11:58 9,085 ----a-w C:\WINDOWS\system32\fscflist.ini.tmp
2008-06-06 16:49 63,918 ----a-w C:\WINDOWS\system32\{fe834001-d193-795e-f829-3eea5cdb4f56}.dll-uninst.exe
2008-06-06 16:48 401,972 ----a-w C:\WINDOWS\system32\g68.exe
2008-06-05 00:48 49,191 ----a-w C:\WINDOWS\system32\jjwnw64l.exe
2008-06-03 13:30 1,540,096 ----a-r C:\WINDOWS\system32\clubbox.exe
2008-06-01 17:44 200,768 ----a-w C:\WINDOWS\system32\kcntkkdm.exe
2008-05-29 18:34 60,928 ----a-w C:\WINDOWS\system32\qrtblr.dll
2008-05-27 13:38 370,176 ----a-w C:\WINDOWS\system32\{fe834001-d193-795e-f829-3eea5cdb4f56}.dll
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-07-29 00:54 964 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2007-07-11 23:16 694 ----a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat
2008-02-07 09:41 217,073 --sha-r C:\WINDOWS\meta4.exe
2005-07-14 22:31 27,648 --sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-27 01:32 616,448 --sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 08:37 45,568 --sha-r C:\WINDOWS\system32\cygz.dll
2006-05-03 10:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2004-01-25 10:00 70,656 --sha-r C:\WINDOWS\system32\i420vfw.dll
2007-02-21 11:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 13:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
2008-02-04 19:26 151,040 --sh--w C:\WINDOWS\system32\VistaUltm.dll
2005-02-28 23:16 240,128 --sha-r C:\WINDOWS\system32\x.264.exe
2004-01-25 10:00 70,656 --sha-r C:\WINDOWS\system32\yv12vfw.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4139E6D-2AAB-0F58-F935-7FA2979C1EE7}]
2008-05-29 08:34 60928 --a------ C:\WINDOWS\system32\qrtblr.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D9CECB1C-55D7-4DF4-BC51-08D15C95DE5E}"= "C:\Program Files\Search Toolbar\search.dll" [2007-02-20 04:06 868424]

[HKEY_CLASSES_ROOT\clsid\{d9cecb1c-55d7-4df4-bc51-08d15c95de5e}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D9CECB1C-55D7-4DF4-BC51-08D15C95DE5E}"= "C:\Program Files\Search Toolbar\search.dll" [2007-02-20 04:06 868424]

[HKEY_CLASSES_ROOT\clsid\{d9cecb1c-55d7-4df4-bc51-08d15c95de5e}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Llx"="C:\WINDOWS\s?stem\m?config.exe" [?]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 02:00 15360]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-29 19:19 57344]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"internet_webplayer"="C:\Program Files\internet_webplayer\internet_webplayer.exe" [2007-02-13 04:02 262656]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2006-12-12 16:55 2242120]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"upfilemans"="C:\WINDOWS\upfilemans.exe" [2008-03-29 15:36 524288]
"choifile.exe"="C:\WINDOWS\system32\choifile.exe" [2008-04-05 14:24 525312]
"inupdaters.exe"="C:\WINDOWS\inupdaters.exe" [2008-04-04 13:39 526336]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2005-11-02 17:01 50792]
"Microsoft Windows Installer"="C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11822.exe" [2008-07-05 14:05 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 18:56 64512]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 20:35 49152]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 07:41 1605740]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 02:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 02:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 02:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 02:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 02:00 455168]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-29 19:19 40960]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-20 19:43 579072]
"pgo.exe"="C:\Program Files\pointgo\pgo.exe" [2008-04-17 14:31 229888]
"HostManager"="C:\Program Files\Common Files\AOL\1141644703\ee\AOLSoftware.exe" [2005-11-02 17:01 50792]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 21:19 77312 C:\WINDOWS\arpwrmsg.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-23 16:41 219136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 02:00 15360]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2005-12-08 06:25:33 27136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 04:23:26 282624]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2005-12-08 07:20:00 36903]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-03-07 14:44:17 106560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-06-22 17:33 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gdqlexyz"= {88fe03e6-19ba-4610-9d40-3ff9ccca9b91} - C:\Documents and Settings\All Users\Application Data\gdqlexyz.dll [2008-06-22 03:56 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dabdbdcccffed]
2008-07-02 16:11 113169 C:\WINDOWS\system32\dabdbdcccffed.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.divxa32"= msaud32_divx.acm
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.YV12"= yv12vfw.dll
"VIDC.MJPG"= pvmjpg21.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_SZ msv1_0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DISCover]
--a------ 2007-10-30 16:57 1095256 C:\Program Files\DISC\DISCover.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCUP]
--a------ 2007-12-12 20:52 243712 C:\WINDOWS\system32\NCUP12122051.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPUP]
--a------ 2008-02-11 14:46 243712 C:\WINDOWS\system32\SPUPDAT02111445.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\WINDOWS\\system32\\fscagent.exe"=
"C:\\WINDOWS\\system32\\clubbox.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aim6.exe"=
"C:\\WINDOWS\\system32\\pdrtvsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\WINDOWS\\kdx\\KHost.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\P3MxSvr.exe"=
"C:\\WINDOWS\\system32\\p3mxvsvr.exe"=
"C:\\WINDOWS\\system32\\muzmvsvr.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\WINDOWS\\system32\\BugsSvr.exe"=
"C:\\WINDOWS\\system32\\p3bvsvr.exe"=
"C:\\WINDOWS\\system32\\skcbgm.exe"=
"C:\\Program Files\\DISC\\DISCover.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\pandora.tv\\minilite\\MiniStream.exe"=
"C:\\WINDOWS\\system32\\mnetasvr.exe"=
"C:\\WINDOWS\\system32\\mnetvsvr.exe"=
"C:\\Program Files\\pandora.tv\\minilite\\MiniLite.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10259:TCP"= 10259:TCP:BitComet 10259 TCP
"10259:UDP"= 10259:UDP:BitComet 10259 UDP

S2 PlugPlayRPC;Plug and Play (RPC);C:\WINDOWS\portsv.exe service []
S2 shpsv;Shop-Guide Updater Service;C:\WINDOWS\system32\svchost.exe [2004-08-10 02:00]
S3 CXFALCON;Conexant Falcon II NTSC Video Capture;C:\WINDOWS\system32\drivers\cxfalcon.sys [2005-08-16 12:24]
S3 NOWMEMDF;NOWMEMDF;C:\WINDOWS\system32\NOWMEMDF.sys [2005-11-02 01:23]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-14 09:40]
S3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 07:44]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder
"2008-06-01 18:01:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-08-07 00:37:09 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2006-05-01 07:00:00 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exef/remind /LaunchPoint reminder /App C:\Program Files\Hewlett-Packard\Easy Internet signup\StartEIS.aml
.
- - - - ORPHANS REMOVED - - - -

BHO-{2A704A86-579B-4979-BC9A-D06625ADE606} - C:\Program Files\MSN\metocolovC:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\CEMG555077.exe.dll
BHO-{651f6428-3394-5721-1c3a-ece197d3a6c2} - C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll
HKCU-Run-swg - C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
HKCU-Run-ǵTV̴ - C:\Program Files\PandoraTVMini\MiniUpdate.exe
HKCU-Run-confile - C:\Program Files\confile\confile.exe
HKCU-Run-ShopPoint - C:\Program Files\ShopPoint\ShopPoint.exe
HKCU-Run-Scbu - C:\PROGRA~1\COMMON~1\ICROSO~1.NET\services.exe
HKCU-Run-ncevlkqd - C:\WINDOWS\system32\bepyxwvk.exe
HKCU-Run-myddslyn - C:\WINDOWS\system32\fevehkty.exe
HKCU-Run-nfvzuerq - C:\WINDOWS\system32\enslihod.exe
HKLM-Run-PCDrProfiler - (no file)
HKLM-Run-ClubBox - (no file)
MSConfigStartUp-Cashonupdate - C:\Program Files\CashOn\bin\CashOnUpdate02101900.exe
MSConfigStartUp-lphcldrj0elce - C:\WINDOWS\system32\lphcldrj0elce.exe
MSConfigStartUp-ncservice - C:\Program Files\CashOn\bin\ncservice08151758.exe
MSConfigStartUp-SMrhcgdrj0elce - C:\Program Files\rhcgdrj0elce\rhcgdrj0elce.exe
MSConfigStartUp-wtkjmvmb - C:\Documents and Settings\All Users\Application Data\wtkjmvmb.dll
MSConfigStartUp-{3ee73c2a-1f35-7807-482d-aee9d0bb277d} - C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.daum.net/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
O8 -: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 -: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 -: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 -: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 -: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 -: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 -: Download All by FlashGet - C:\Documents and Settings\HP_Administrator\Favorites\FlashGet\jc_all.htm
O8 -: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 -: Download using FlashGet - C:\Documents and Settings\HP_Administrator\Favorites\FlashGet\jc_link.htm
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O16 -: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} - hxxp://www2.stlu.com/plugins/Plugin5.0.0219//streetnoagent7.cab
C:\WINDOWS\Downloaded Program Files\streetcv.inf
C:\WINDOWS\Downloaded Program Files\7thAgent7.ocx
C:\WINDOWS\Downloaded Program Files\iestm32.dll

O16 -: {21FDDE58-51A6-402A-8040-39DA033DC196} - hxxp://image.pullbbang.com/newTop/Pull0Control.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\Pull0Control.ocx

O16 -: {2FDAF918-389E-4402-9DA1-F5348615BC30} - hxxp://www.dosirak.com/Commons/Activex/MROpen.cab
C:\WINDOWS\Downloaded Program Files\MROpen.inf
C:\WINDOWS\system32\MROpen.ocx

O16 -: {3270EED1-B285-4828-A0A7-F55913A9B724} - hxxp://listen.daum.net/52st/52street/S2MusicPlayer.dll
C:\WINDOWS\Downloaded Program Files\S2MusicPlayer.dll

O16 -: {3942BD43-B5CE-465F-9AC3-16BA93994273} - hxxp://www.dosirak.com/Commons/Activex/DosirakControl.ocx
C:\WINDOWS\Downloaded Program Files\DosirakControl.ocx

O16 -: {40A217E1-BDDA-44DE-9BBC-D678C7B48603} - hxxp://www.bluemountainsoft.com/agent/EspressoAgent.ocx
C:\WINDOWS\Downloaded Program Files\EspressoAgent.ocx

O16 -: {68253470-5D4F-4CDF-8D9C-353C14A2F013} - hxxp://imgcdn.pandora.tv/pan_img/liveupdate/SVPorsche.cab
C:\WINDOWS\Downloaded Program Files\SVPorsche.inf
C:\WINDOWS\system32\default2003.sbd
C:\WINDOWS\system32\SVPorsche.ocx
C:\WINDOWS\system32\gdiplus.dll

O16 -: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} - hxxp://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
C:\WINDOWS\Downloaded Program Files\DaumBGM.inf
C:\WINDOWS\system32\OIBox.dll
C:\WINDOWS\system32\DaumCrypt.dll
C:\WINDOWS\system32\DaumBGM.dll

O16 -: {7606693A-C18D-4567-AF85-6194FF70761E} - hxxp://app.gomtv.com/gom/GomWeb.cab
C:\WINDOWS\Downloaded Program Files\gomweb.inf
C:\WINDOWS\Downloaded Program Files\gomweb3.dll

O16 -: {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} - hxxp://www.mnet.com/Ver2/App/totalApp/maxhelper/maxhelper.cab
C:\WINDOWS\Downloaded Program Files\MaxHelper.inf
C:\WINDOWS\Downloaded Program Files\MaxHelper.ocx

O16 -: {913BF18F-672D-4676-9855-F9A192A88886} - hxxp://touch.imbc.com/ocx/Online.cab
C:\WINDOWS\Downloaded Program Files\Touch.inf
C:\WINDOWS\Downloaded Program Files\iMBCContents.ocx
C:\WINDOWS\Downloaded Program Files\iMBCDrmControl.ocx
C:\WINDOWS\Downloaded Program Files\iMBCFilesize.ocx
C:\WINDOWS\Downloaded Program Files\TouchBrowser.ocx
C:\WINDOWS\Downloaded Program Files\iMBCClient.ocx
C:\WINDOWS\Downloaded Program Files\CloseLicenseDlg.ocx
C:\WINDOWS\system32\TouchWeb.dll
C:\WINDOWS\Downloaded Program Files\Touch.ocx

O16 -: {938527D1-CDB7-4147-998A-B20FCA5CC976} - hxxp://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
C:\WINDOWS\Downloaded Program Files\dmcc2.inf
C:\WINDOWS\system32\dmvm.dll
C:\WINDOWS\Downloaded Program Files\dmcc2.dll

O16 -: {9B75502C-BBED-4BBD-8FE2-822E5E0AD32C} - hxxp://www.diodeo.com/DioDeoPlayer.cab
C:\WINDOWS\Downloaded Program Files\DioDeoPlayer.inf
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\Downloaded Program Files\MagicLockOCX.ocx
C:\WINDOWS\Downloaded Program Files\DioDeoPlayer.ocx

O16 -: {A0E7D0C1-9854-497E-8645-38C19AA00724} - hxxp://www.teenkorean.net/Penta/KoreanSecurity.cab
C:\WINDOWS\Downloaded Program Files\IssacWebSE.inf
C:\WINDOWS\system32\iwebsd_tray.exe
C:\WINDOWS\Downloaded Program Files\IssacWebSE.dll

O16 -: {AF60D574-F249-4243-8040-5521AAA5BB5E} - hxxp://imgcdn.pandora.tv/pan_img/p3player/package/pdrtvset.cab
C:\WINDOWS\Downloaded Program Files\pdrtvset.inf
C:\WINDOWS\system32\atl.dll
C:\WINDOWS\system32\pdrtvset.dll

O16 -: {B8C4B31D-6DCE-4DF0-BF73-44686849F67D} - hxxp://imgcdn.pandora.tv/pan_img/p3player/package/pdrinst.cab
C:\WINDOWS\Downloaded Program Files\pdrinst.inf
C:\WINDOWS\system32\atl.dll
C:\WINDOWS\pdrinst2.dll
C:\WINDOWS\pdrinst1.dll

O16 -: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} - hxxp://cafeimg.hanmail.net/cto/xman.cab?ver=1,2,3,3
C:\WINDOWS\Downloaded Program Files\xman.inf
C:\WINDOWS\system32\xmaninf.exe
C:\WINDOWS\system32\extract.exe
C:\WINDOWS\system32\xman.dll

O16 -: {BBFD2D10-EC6E-4259-91D1-1E38C826E5E2} - hxxp://app.gomtv.com/gomtv/gomtvx.cab
C:\WINDOWS\Downloaded Program Files\gomtvx.inf
C:\WINDOWS\Downloaded Program Files\gomtvx.dll

O16 -: {BCA935CA-7E41-4F73-BA9C-FAB4393DBAC0} - hxxp://www.csafer.net/ActiveX/MAStreamCtrl.cab
C:\WINDOWS\Downloaded Program Files\MAStreamCtrl.inf
C:\WINDOWS\system32\StreamSaferFilter.dll
C:\WINDOWS\system32\MAStreamCtrl.ocx

O16 -: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} - hxxp://install.bugs.co.kr/install/BugsInstallerEx.cab
C:\WINDOWS\Downloaded Program Files\BugsInstallerEx.inf
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\Downloaded Program Files\BugsInstallerEx.ocx
C:\WINDOWS\system32\bugs_install.gif

O16 -: {BD6BB450-7C69-43B8-96F3-689CAE57AB51} - hxxp://netv.sbs.co.kr/object/player/SBSWebPlayer.cab
C:\WINDOWS\Downloaded Program Files\SBSWebPlayer.inf
C:\WINDOWS\Downloaded Program Files\SBSWebPlayer.dll

O16 -: {BD6F8792-B90E-4431-B0AB-08CF414E9D35} - hxxp://bgm.iple.com/Cab/SMMusicPlayerX.cab
C:\WINDOWS\Downloaded Program Files\SMMusicPlayerX.inf
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\system32\vorbis_vx.dll
C:\WINDOWS\system32\ogg_vx.dll
C:\WINDOWS\system32\VxovSrc4dmi.ax
C:\WINDOWS\system32\SMMusicPlayerX.ocx

O16 -: {C394A9A2-C51D-4C26-BB2C-6DEB30A890F4} - hxxp://www.diodeo.com/ActiveDiodeoPlayer.cab
C:\WINDOWS\Downloaded Program Files\ActiveDiodeoPlayer.inf
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\Downloaded Program Files\MagicLockOCX.ocx
C:\WINDOWS\Downloaded Program Files\ActiveDiodeoPlayer.ocx

O16 -: {CEE326E8-7571-4086-B347-3C0ACA9A9DE8} - hxxp://player.muz.co.kr/package/installer2007_02/p3Instal.cab
C:\WINDOWS\Downloaded Program Files\p3Instal.inf
C:\WINDOWS\system32\atl.dll
C:\WINDOWS\system32\p3Instl2.dll
C:\WINDOWS\system32\p3Instl1.dll

O16 -: {CF362BDB-4EA2-11D5-AB47-000102913414} - hxxp://touch.imbc.com/ocx/SetGlb.cab
C:\WINDOWS\Downloaded Program Files\setglb.inf
C:\WINDOWS\system32\setglb.ocx
C:\WINDOWS\system32\hkstart.exe
C:\WINDOWS\system32\hksock2.dll
C:\WINDOWS\system32\hksock1.dll
C:\WINDOWS\system32\hkmsg2.dll
C:\WINDOWS\system32\hkmsg1.dll
C:\WINDOWS\system32\HkDnsRes.dll

O16 -: {CFCBEE6F-BE54-4682-84F6-0E3FCDFAE3E2} - hxxp://www.clubbox.co.kr/neo.fld/NowCAFE.cab
C:\WINDOWS\Downloaded Program Files\NowCAFE.inf
C:\WINDOWS\system32\atl.dll
C:\WINDOWS\Downloaded Program Files\NowCAFE.ocx

O16 -: {D1160D6F-214B-4B4E-A361-977817ACC516} - hxxp://www.websafe.co.kr/websafe_player.cab
C:\WINDOWS\Downloaded Program Files\websafe_player.inf
C:\WINDOWS\Downloaded Program Files\websafe_player.ocx

O16 -: {D26A941D-7E89-4098-B583-43291FC14218} - hxxp://image.pullbbang.com/images/Pull0Control.ocx
C:\WINDOWS\Downloaded Program Files\Pull0Control.ocx

O16 -: {F4A1D5E2-AF49-47A7-A945-23038106F3A4} - hxxp://imgcdn.pandora.tv/pan_img/launcher/codebase/Pandora_SetUpAX.cab
C:\WINDOWS\Downloaded Program Files\Pandora_SetUpAX.inf
C:\WINDOWS\system32\Pandora_SetUpAX.ocx

O16 -: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} - hxxp://www.clubbox.co.kr/neo.fld/MultiUpload.cab
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\MultiUpload.inf
C:\WINDOWS\system32\atl.dll
C:\WINDOWS\Downloaded Program Files\MultiUpload.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MultiUpload.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\MultiUpload.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\MultiUpload.ocx


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-06 15:31:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\WINDOWS\system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys 36864 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\8852cd8aca0d0b86c1b0f9109edb6cab]
"ImagePath"="system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\dabdbdcccffed.dll
.
Completion time: 2008-08-06 15:34:30
ComboFix-quarantined-files.txt 2008-08-07 01:34:20

Pre-Run: 10,328,014,848 bytes free
Post-Run: 10,678,730,752 bytes free

470 --- E O F --- 2008-08-01 04:39:55

#6 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:05:56 PM

Posted 07 August 2008 - 02:22 AM

Hello Yoori,

Please delete your current version of ComboFix from your desktop,
and download the latest version.
DO NOT run it yet !!

Then, let's clean up some more :

Open Notepad - don't use any other texteditor than Notepad or the script will fail !
Copy/paste the bold, blue text below into an empty notepad window:http://www.bleepingcomputer.com/forums/t/158846/infected-by-nasty-malware-viruses/
Collect::[9]
C:\WINDOWS\system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys
C:\WINDOWS\upfilemans.exe
C:\WINDOWS\system32\choifile.exe
C:\WINDOWS\inupdaters.exe
C:\WINDOWS\system32\ojevepwl.exe
C:\WINDOWS\system32\dabdbdcccffed.dll
C:\WINDOWS\system32\drvokevwqsuoqmfp.dll
C:\Documents and Settings\All Users\Application Data\gdqlexyz.dll
C:\WINDOWS\bwzwpmju.dll
C:\WINDOWS\system32\{fe834001-d193-795e-f829-3eea5cdb4f56}.dll-uninst.exe
C:\WINDOWS\system32\g68.exe
C:\WINDOWS\system32\jjwnw64l.exe
C:\WINDOWS\system32\pphcldrj0elce.exe
C:\WINDOWS\system32\lzhlvjexgdlfth.exe
C:\WINDOWS\system32\kcntkkdm.exe
C:\WINDOWS\system32\qrtblr.dll
C:\WINDOWS\system32\{fe834001-d193-795e-f829-3eea5cdb4f56}.dll
File::
C:\WINDOWS\system32\07a415ca8d50e0c64247c07f15daa594.TMP
C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll-uninst.exe
C:\WINDOWS\system32\da61156c48785f1b2b27248a057e8332.TMP
C:\WINDOWS\system32\f6ebeadfb8f1d467d4e928c42bc0c729.TMP
C:\WINDOWS\system32\735c0ea36c98215d074f6722ab077fd2.TMP
C:\WINDOWS\system32\ea9f12518e978d877aa66a9b8fbdf220.TMP
C:\WINDOWS\system32\f6ebeadfb8f1d467d4e928c42bc0c729.TMP
C:\WINDOWS\system32\735c0ea36c98215d074f6722ab077fd2.TMP
C:\WINDOWS\system32\ea9f12518e978d877aa66a9b8fbdf220.TMP
C:\WINDOWS\system32\7fafca53883fe2e0922ec2222bb981aa.TMP
C:\WINDOWS\system32\072a99c59a97fc3c4ed0d12d2fe88933.TMP
C:\WINDOWS\system32\47821e887545df5af4b99c1ede062d3b.TMP
C:\WINDOWS\system32\f2c7e529e3d4f561571bfab109bd7d37.TMP
C:\WINDOWS\system32\6d85a8ff8b298bfe40e11565e9a085ff.TMP
C:\WINDOWS\system32\28a9b35becbf2d162d941e1de349c381.TMP
Folder::
C:\Documents and Settings\All Users\Application Data\pyvszqzu
C:\Documents and Settings\All Users\Application Data\fgfwxovs
Driver::
PlugPlayRPC
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4139E6D-2AAB-0F58-F935-7FA2979C1EE7}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Llx"=-
"upfilemans"=-
"choifile.exe"=-
"inupdaters.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gdqlexyz"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dabdbdcccffed]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\8852cd8aca0d0b86c1b0f9109edb6cab]

Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again. Upon reboot, (in case it asks to reboot), post the contents of the Combofix log in your next reply, as well as a fresh HijackThislog.

When CF finishes running, the ComboFix log will open along with a message box, --do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis.

Ensure you are connected to the internet and click OK on the message box. A browser will open.
Simply follow the instructions to copy/paste/send the requested file [9]-Submit_Date_Time.zip.

Are you still having problems ?

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#7 yoori

yoori
  • Topic Starter

  • Members
  • 149 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:In Your Dreams
  • Local time:05:56 AM

Posted 07 August 2008 - 10:37 PM

Where do I download the latest version? Is it in the Combofix guide?

I still have problems, if the internet is turned on these malware called "Outerinfo" and "internet security suite" comes back. And I get these error boxes when I shut down the computer. If I want to go online I'd have to always put my computer to safe mode and use my sisters laptop I'm using right now.

Edited by yoori, 07 August 2008 - 10:49 PM.


#8 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:05:56 PM

Posted 08 August 2008 - 04:11 PM

Hello Yoori,

ComboFix is updated several times a day.
Your version isn't up-to-date anymore, so rightclick on ComboFix and delete,
then go to the download link you used before, and download a fresh copy.

Then drop the CFScript on it to start the ComboFix run.

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#9 yoori

yoori
  • Topic Starter

  • Members
  • 149 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:In Your Dreams
  • Local time:05:56 AM

Posted 11 August 2008 - 05:56 AM

Okay. Thanks, I'll go do it and post it up by tomorrow ^__^

#10 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:05:56 PM

Posted 11 August 2008 - 03:17 PM

Very well, Yoori,

I'll look forward to the ComboFix log. :thumbsup:

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#11 yoori

yoori
  • Topic Starter

  • Members
  • 149 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:In Your Dreams
  • Local time:05:56 AM

Posted 11 August 2008 - 09:58 PM

I submitted my file.

here's my log

-----------------------------
ComboFix 08-08-10.06 - HP_Administrator 2008-08-11 16:27:11.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.489 [GMT -10:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll-uninst.exe
C:\WINDOWS\system32\072a99c59a97fc3c4ed0d12d2fe88933.TMP
C:\WINDOWS\system32\07a415ca8d50e0c64247c07f15daa594.TMP
C:\WINDOWS\system32\28a9b35becbf2d162d941e1de349c381.TMP
C:\WINDOWS\system32\47821e887545df5af4b99c1ede062d3b.TMP
C:\WINDOWS\system32\6d85a8ff8b298bfe40e11565e9a085ff.TMP
C:\WINDOWS\system32\735c0ea36c98215d074f6722ab077fd2.TMP
C:\WINDOWS\system32\7fafca53883fe2e0922ec2222bb981aa.TMP
C:\WINDOWS\system32\da61156c48785f1b2b27248a057e8332.TMP
C:\WINDOWS\system32\ea9f12518e978d877aa66a9b8fbdf220.TMP
C:\WINDOWS\system32\f2c7e529e3d4f561571bfab109bd7d37.TMP
C:\WINDOWS\system32\f6ebeadfb8f1d467d4e928c42bc0c729.TMP
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\fgfwxovs
C:\Documents and Settings\All Users\Application Data\fgfwxovs\vszufyby.exe
C:\Documents and Settings\All Users\Application Data\gdqlexyz.dll
C:\Documents and Settings\All Users\Application Data\pyvszqzu
C:\Documents and Settings\All Users\Application Data\pyvszqzu\pmxavupi.exe
C:\Documents and Settings\Guest\Application Data\macromedia\Flash Player\#SharedObjects\838SCC2V\interclick.com
C:\Documents and Settings\Guest\Application Data\macromedia\Flash Player\#SharedObjects\838SCC2V\interclick.com\ud.sol
C:\Documents and Settings\Guest\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Guest\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\11105.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\11275.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\11961.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\12101.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\12594.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\12820.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\13831.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\14479.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\14739.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\15553.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\15583.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\15666.dll
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\1611.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\17010.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\18470.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\19155.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\19695.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\19886.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\20289.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\21494.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\21930.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\21930.exe~
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\22278.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\22550.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\22869.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\23839.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\24022.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\24062.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\24087.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\24443.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\24532.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\24666.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\24858.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\25034.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\25264.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\26452.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\26726.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\27043.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\27246.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\27372.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\27912.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\28235.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\28331.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\28402.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\30136.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\30177.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\3022.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\30698.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\31083.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\32035.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\32360.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\32391.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\3500.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\4756.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\5215.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\5347.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\5590.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\6410.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\644.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\6788.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\7050.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\7163.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\7235.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\7728.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\8000.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\8103.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\8452.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\8574.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\8736.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\9145.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\9305.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\9368.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\9472.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\9715.exe
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\9895.dll
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\id
C:\Documents and Settings\Guest\Application Data\Microsoft\dtsc\s
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\#SharedObjects\6QXLDS7S\interclick.com
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\#SharedObjects\6QXLDS7S\interclick.com\ud.sol
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10039.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10083.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10097.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10105.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10197.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10223.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10250.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1030.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1039.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10495.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10702.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10805.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10848.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10926.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\10974.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11167.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11630.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11765.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11822.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11889.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\12105.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1214.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\12196.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\12319.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\12558.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\12669.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\12726.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1274.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\12844.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\12918.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13112.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13121.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13318.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13494.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13577.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13635.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13640.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13749.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1377.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13862.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\13863.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14134.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14254.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14345.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14467.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14496.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14549.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14611.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14723.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\14745.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15285.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15337.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15430.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15436.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15553.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1574.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15773.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15838.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15864.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15897.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\159.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\15951.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1610.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\16260.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\16578.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\16621.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\16732.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\16763.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\16824.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1689.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1693.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\17041.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1706.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\17090.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1716.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\17567.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\17624.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1774.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\17772.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1791.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\18060.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1816.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\18162.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\18279.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\18345.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\18564.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\18792.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\18793.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\18827.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\1898.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\19443.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\19460.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\19473.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\19590.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\19651.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\19655.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\19747.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\20216.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\20274.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\20632.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\20751.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\20755.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\20851.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2087.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\20889.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21079.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21121.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2120.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21460.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21492.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2155.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21557.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21625.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21638.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2166.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21725.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\21970.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22242.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22251.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2226.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22285.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22368.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22544.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22613.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22716.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22866.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22933.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\22952.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23080.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\231.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23196.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23258.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23313.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23346.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2341.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23481.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23526.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23727.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23807.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23815.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\23880.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24067.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24230.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24450.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24482.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24490.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24566.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24639.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24692.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24836.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24937.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\24978.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25111.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25126.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25224.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25389.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25397.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25677.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25791.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25824.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25962.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\25987.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26050.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26204.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26300.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2645.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26475.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26501.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26669.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26744.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26787.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\26986.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27083.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27215.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27357.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27408.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27441.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27446.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27609.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27774.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2794.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\27982.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\2800.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\28109.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\28395.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\28405.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\28597.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\28688.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\28719.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\28724.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\28906.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29083.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29173.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29343.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29483.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29669.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29773.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29849.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29864.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\29909.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\30060.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\30373.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\30374.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\30730.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\30765.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\30861.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31006.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\311.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\3131.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31365.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31397.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31669.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31764.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31858.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31919.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31927.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\31954.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\32039.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\32067.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\32141.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\32174.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\32189.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\32372.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\32455.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\32529.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\3388.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\3680.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\3848.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4059.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4123.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4275.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4281.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4402.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4444.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4538.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4656.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4749.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4756.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4850.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4912.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4997.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\4999.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\5026.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\5194.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\522.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\5383.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\5543.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\5590.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\563.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\5816.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\593.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\5940.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\6041.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\6163.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\641.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\6538.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\6613.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\6620.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\6743.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\6905.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\6915.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7001.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7141.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7216.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7241.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7278.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7293.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7392.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7418.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7423.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7672.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7736.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7848.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\7932.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\8098.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\8471.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\8769.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\8836.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\8943.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\9181.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\9197.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\9304.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\932.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\9402.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\9418.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\9558.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\9824.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\s
C:\Documents and Settings\HP_Administrator\Application Data\PPPATC~1
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\ISpandora.exe
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA.cfg
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA0.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA1.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA2.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA3.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA4.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA5.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA6.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA7.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA8.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETA9.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV.cfg
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV0.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV1.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV2.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV3.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV4.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV5.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV6.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV7.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV8.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MNETV9.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV.cfg
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV0.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV1.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV2.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV3.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV4.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV5.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV6.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV7.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV8.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\MUZMV9.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV.cfg
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV0.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV1.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV2.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV3.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV4.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV5.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV6.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV7.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV8.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\P3MXV9.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM.cfg
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM0.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM1.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM2.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM3.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM4.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM5.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM6.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM7.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM8.che
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\SKBGM9.che
C:\WINDOWS\bwzwpmju.dll
C:\WINDOWS\inupdaters.exe
C:\WINDOWS\system32\{e5c751be-3ef8-ffa0-1678-2cb090924039}.dll-uninst.exe
C:\WINDOWS\system32\{fe834001-d193-795e-f829-3eea5cdb4f56}.dll-uninst.exe
C:\WINDOWS\system32\{fe834001-d193-795e-f829-3eea5cdb4f56}.dll
C:\WINDOWS\system32\072a99c59a97fc3c4ed0d12d2fe88933.TMP
C:\WINDOWS\system32\07a415ca8d50e0c64247c07f15daa594.TMP
C:\WINDOWS\system32\1804\9482.dll
C:\WINDOWS\system32\28a9b35becbf2d162d941e1de349c381.TMP
C:\WINDOWS\system32\47821e887545df5af4b99c1ede062d3b.TMP
C:\WINDOWS\system32\6d85a8ff8b298bfe40e11565e9a085ff.TMP
C:\WINDOWS\system32\735c0ea36c98215d074f6722ab077fd2.TMP
C:\WINDOWS\system32\7fafca53883fe2e0922ec2222bb981aa.TMP
C:\WINDOWS\system32\choifile.exe
C:\WINDOWS\system32\da61156c48785f1b2b27248a057e8332.TMP
C:\WINDOWS\system32\dabdbdcccffed.dll
C:\WINDOWS\system32\drvokevwqsuoqmfp.dll
C:\WINDOWS\system32\ea9f12518e978d877aa66a9b8fbdf220.TMP
C:\WINDOWS\system32\f2c7e529e3d4f561571bfab109bd7d37.TMP
C:\WINDOWS\system32\f6ebeadfb8f1d467d4e928c42bc0c729.TMP
C:\WINDOWS\system32\g68.exe
C:\WINDOWS\system32\jjwnw64l.exe
C:\WINDOWS\system32\kcntkkdm.exe
C:\WINDOWS\system32\lzhlvjexgdlfth.exe
C:\WINDOWS\system32\ojevepwl.exe
C:\WINDOWS\system32\pphcldrj0elce.exe
C:\WINDOWS\system32\qrtblr.dll
C:\WINDOWS\upfilemans.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_PLUGPLAYRPC
-------\Service_PlugPlayRPC


((((((((((((((((((((((((( Files Created from 2008-07-12 to 2008-08-12 )))))))))))))))))))))))))))))))
.

2008-07-22 05:11 . 2008-07-31 19:08 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-07-20 17:14 . 2008-07-20 17:14 <DIR> d-------- C:\Deckard
2008-07-20 16:14 . 2008-08-11 16:31 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\uTorrent

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-11 22:53 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\AVG7
2008-08-07 00:59 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Orbit
2008-08-04 12:27 --------- d-----w C:\Program Files\pointgo
2008-07-21 02:14 --------- d-----w C:\Program Files\uTorrent
2008-07-17 08:33 --------- d-----w C:\Documents and Settings\Guest\Application Data\AVG7
2008-07-11 11:27 --------- d-----w C:\Program Files\SPoint
2008-07-11 00:51 --------- d-----w C:\Program Files\MSN Encarta Standard
2008-07-09 06:23 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 06:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-05 22:51 --------- d-----w C:\Documents and Settings\Guest\Application Data\uTorrent
2008-07-02 03:17 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-06-25 14:39 --------- d-----w C:\Program Files\Avidemux 2.4
2008-06-25 14:34 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\gtk-2.0
2008-06-24 20:55 --------- d-----w C:\Documents and Settings\Guest\Application Data\Viewpoint
2008-06-23 03:33 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-06-22 19:54 --------- d-----w C:\Documents and Settings\Guest\Application Data\Malwarebytes
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 13:22 --------- d-----w C:\Program Files\Aegisub
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2007-07-29 00:54 964 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2007-07-11 23:16 694 ----a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat
2008-02-07 09:41 217,073 --sha-r C:\WINDOWS\meta4.exe
2005-07-14 22:31 27,648 --sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-27 01:32 616,448 --sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 08:37 45,568 --sha-r C:\WINDOWS\system32\cygz.dll
2006-05-03 10:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2004-01-25 10:00 70,656 --sha-r C:\WINDOWS\system32\i420vfw.dll
2007-02-21 11:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 13:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
2008-02-04 19:26 151,040 --sh--w C:\WINDOWS\system32\VistaUltm.dll
2005-02-28 23:16 240,128 --sha-r C:\WINDOWS\system32\x.264.exe
2004-01-25 10:00 70,656 --sha-r C:\WINDOWS\system32\yv12vfw.dll
.

((((((((((((((((((((((((((((( snapshot@2008-08-06_15.34.08.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 06:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
+ 2008-07-03 20:21:10 36,864 ----a-w C:\WINDOWS\system32\8852cd8aca0d0b86c1b0f9109edb6cab.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D9CECB1C-55D7-4DF4-BC51-08D15C95DE5E}"= "C:\Program Files\Search Toolbar\search.dll" [2007-02-20 04:06 868424]

[HKEY_CLASSES_ROOT\clsid\{d9cecb1c-55d7-4df4-bc51-08d15c95de5e}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D9CECB1C-55D7-4DF4-BC51-08D15C95DE5E}"= "C:\Program Files\Search Toolbar\search.dll" [2007-02-20 04:06 868424]

[HKEY_CLASSES_ROOT\clsid\{d9cecb1c-55d7-4df4-bc51-08d15c95de5e}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\XBTB05340.XBTB05340]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 02:00 15360]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-29 19:19 57344]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"internet_webplayer"="C:\Program Files\internet_webplayer\internet_webplayer.exe" [2007-02-13 04:02 262656]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2006-12-12 16:55 2242120]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2005-11-02 17:01 50792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 18:56 64512]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 20:35 49152]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 07:41 1605740]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 02:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 02:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 02:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 02:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 02:00 455168]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-29 19:19 40960]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-20 19:43 579072]
"pgo.exe"="C:\Program Files\pointgo\pgo.exe" [2008-04-17 14:31 229888]
"HostManager"="C:\Program Files\Common Files\AOL\1141644703\ee\AOLSoftware.exe" [2005-11-02 17:01 50792]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 21:19 77312 C:\WINDOWS\arpwrmsg.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-23 16:41 219136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 02:00 15360]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2005-12-08 06:25:33 27136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 04:23:26 282624]
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2005-12-08 07:20:00 36903]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-03-07 14:44:17 106560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-06-22 17:33 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.divxa32"= msaud32_divx.acm
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.YV12"= yv12vfw.dll
"VIDC.MJPG"= pvmjpg21.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DISCover]
--a------ 2007-10-30 16:57 1095256 C:\Program Files\DISC\DISCover.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NCUP]
--a------ 2007-12-12 20:52 243712 C:\WINDOWS\system32\NCUP12122051.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPUP]
--a------ 2008-02-11 14:46 243712 C:\WINDOWS\system32\SPUPDAT02111445.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\WINDOWS\\system32\\fscagent.exe"=
"C:\\WINDOWS\\system32\\clubbox.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1141644703\\ee\\aim6.exe"=
"C:\\WINDOWS\\system32\\pdrtvsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\WINDOWS\\kdx\\KHost.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\P3MxSvr.exe"=
"C:\\WINDOWS\\system32\\p3mxvsvr.exe"=
"C:\\WINDOWS\\system32\\muzmvsvr.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\WINDOWS\\system32\\BugsSvr.exe"=
"C:\\WINDOWS\\system32\\p3bvsvr.exe"=
"C:\\WINDOWS\\system32\\skcbgm.exe"=
"C:\\Program Files\\DISC\\DISCover.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\pandora.tv\\minilite\\MiniStream.exe"=
"C:\\WINDOWS\\system32\\mnetasvr.exe"=
"C:\\WINDOWS\\system32\\mnetvsvr.exe"=
"C:\\Program Files\\pandora.tv\\minilite\\MiniLite.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10259:TCP"= 10259:TCP:BitComet 10259 TCP
"10259:UDP"= 10259:UDP:BitComet 10259 UDP

S2 shpsv;Shop-Guide Updater Service;C:\WINDOWS\system32\svchost.exe [2004-08-10 02:00]
S3 CXFALCON;Conexant Falcon II NTSC Video Capture;C:\WINDOWS\system32\drivers\cxfalcon.sys [2005-08-16 12:24]
S3 NOWMEMDF;NOWMEMDF;C:\WINDOWS\system32\NOWMEMDF.sys [2005-11-02 01:23]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-14 09:40]
S3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 07:44]
.
Contents of the 'Scheduled Tasks' folder

2008-06-01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 17:13]

2008-08-12 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

2006-05-01 C:\WINDOWS\Tasks\Easy Internet Sign-up.job
- C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-08 17:23]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Microsoft Windows Installer - C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\dtsc\11822.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-11 16:33:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\arservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2008-08-11 16:39:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-12 02:39:24
ComboFix2.txt 2008-08-07 01:34:31

Pre-Run: 10,596,048,896 bytes free
Post-Run: 10,441,248,768 bytes free

719 --- E O F --- 2008-08-01 04:39:55

#12 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:05:56 PM

Posted 12 August 2008 - 03:36 AM

Hello Yoori,

Can I see a fresh HijackThis log please ?

Still having problems ?

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#13 yoori

yoori
  • Topic Starter

  • Members
  • 149 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:In Your Dreams
  • Local time:05:56 AM

Posted 12 August 2008 - 06:21 AM

Sorry, I'll scan tomorrow and have it posted up.
Yeah, seems like everything is working fine now ^____^
Thanks so much Thunder for taking time to help me out
I appreicate it alot.

-Yoori-

#14 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:05:56 PM

Posted 12 August 2008 - 10:53 AM

OK, Yoori,

See you tomorrow then. :thumbsup:

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#15 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:05:56 PM

Posted 11 September 2008 - 04:11 AM

Since there is no feedback anymore, I assume this issue is resolved ... so, this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users