hi thanks for helping me out, so far so good after running the combofix, not 1 link yet has redirected me, but it still may happen ill post if it does again.
ComboFix.txt
ComboFix 09-07-07.A0 - Compaq_Owner 07/07/2009 16:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2558.2093 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\93748896.ini
c:\program files\Common Files\WinNT 32
c:\recycler\S-1-5-21-0118572615-6279061686-770590742-4414
c:\recycler\S-1-5-21-2175534412-17650542-472631733-1009
c:\recycler\S-1-5-21-2690721932-1787350863-311928929-5646
c:\recycler\S-1-5-21-5853572181-6534452423-363847467-1135
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Installer\103eb43.msi
c:\windows\Installer\14a263.msi
c:\windows\Installer\17af22.msp
c:\windows\Installer\17af5e.msp
c:\windows\Installer\17af75.msp
c:\windows\Installer\17af8e.msp
c:\windows\Installer\17afa7.msp
c:\windows\Installer\17afbd.msp
c:\windows\Installer\17afd5.msp
c:\windows\Installer\1a69b1.msi
c:\windows\Installer\1a69b7.msi
c:\windows\Installer\2010b.msi
c:\windows\Installer\206a3b.msp
c:\windows\Installer\26ddd5.msp
c:\windows\Installer\26ddd6.msp
c:\windows\Installer\26ddd7.msp
c:\windows\Installer\26ddd8.msp
c:\windows\Installer\26ddd9.msp
c:\windows\Installer\26ddda.msp
c:\windows\Installer\26dddb.msp
c:\windows\Installer\26dddc.msp
c:\windows\Installer\26dddd.msp
c:\windows\Installer\26ddde.msp
c:\windows\Installer\288c7.msi
c:\windows\Installer\298652.msi
c:\windows\Installer\2b2778.msp
c:\windows\Installer\2c9886.msi
c:\windows\Installer\2c988e.msp
c:\windows\Installer\2c9895.msp
c:\windows\Installer\2c989e.msp
c:\windows\Installer\2c98a5.msp
c:\windows\Installer\2c98ae.msp
c:\windows\Installer\2c98b7.msp
c:\windows\Installer\2c98c0.msp
c:\windows\Installer\2c98c9.msp
c:\windows\Installer\2c98d2.msp
c:\windows\Installer\2c98db.msp
c:\windows\Installer\2e4de.msp
c:\windows\Installer\308295.msp
c:\windows\Installer\308296.msp
c:\windows\Installer\308297.msp
c:\windows\Installer\308298.msp
c:\windows\Installer\308299.msp
c:\windows\Installer\30829a.msp
c:\windows\Installer\30829b.msp
c:\windows\Installer\30829c.msp
c:\windows\Installer\30829d.msp
c:\windows\Installer\30829e.msp
c:\windows\Installer\34b50.msp
c:\windows\Installer\34b5c.msp
c:\windows\Installer\3a2e22.msi
c:\windows\Installer\3a2e28.msi
c:\windows\Installer\3a2e2e.msi
c:\windows\Installer\3a2e34.msi
c:\windows\Installer\3a2e3a.msi
c:\windows\Installer\3a2e40.msi
c:\windows\Installer\3a2e46.msi
c:\windows\Installer\3a2e4c.msi
c:\windows\Installer\3a2e52.msi
c:\windows\Installer\3a2e59.msi
c:\windows\Installer\3a2e5f.msi
c:\windows\Installer\3a2e66.msp
c:\windows\Installer\405c9.msi
c:\windows\Installer\413c1b.msp
c:\windows\Installer\51c09b.msi
c:\windows\Installer\529ac.msi
c:\windows\Installer\529b2.msi
c:\windows\Installer\529b6.msi
c:\windows\Installer\552fe.msp
c:\windows\Installer\59ccbb.msp
c:\windows\Installer\59ccd5.msp
c:\windows\Installer\59cce1.msp
c:\windows\Installer\59cce2.msp
c:\windows\Installer\59cd02.msp
c:\windows\Installer\59ce52.msp
c:\windows\Installer\59ce5d.msp
c:\windows\Installer\59ce67.msp
c:\windows\Installer\59ce6f.msp
c:\windows\Installer\5df9c.msi
c:\windows\Installer\5dfa2.msi
c:\windows\Installer\5dfa8.msi
c:\windows\Installer\5dfae.msi
c:\windows\Installer\5dfb4.msi
c:\windows\Installer\5dfb8.msi
c:\windows\Installer\624ce2.msi
c:\windows\Installer\624ce3.msp
c:\windows\Installer\624ce4.msp
c:\windows\Installer\624ce5.msp
c:\windows\Installer\624ce6.msp
c:\windows\Installer\624ce7.msp
c:\windows\Installer\624ce8.msp
c:\windows\Installer\624ce9.msp
c:\windows\Installer\624cea.msp
c:\windows\Installer\624ceb.msp
c:\windows\Installer\666934.msi
c:\windows\Installer\666935.msp
c:\windows\Installer\666936.msp
c:\windows\Installer\666937.msp
c:\windows\Installer\666938.msp
c:\windows\Installer\666939.msp
c:\windows\Installer\66693a.msp
c:\windows\Installer\66693b.msp
c:\windows\Installer\66693c.msp
c:\windows\Installer\66693d.msp
c:\windows\Installer\66693e.msp
c:\windows\Installer\68005b.msi
c:\windows\Installer\68006a.msp
c:\windows\Installer\6fe10.msi
c:\windows\Installer\6fe28.msi
c:\windows\Installer\6ff5a.msi
c:\windows\Installer\97682.msi
c:\windows\Installer\9a2cf.msi
c:\windows\Installer\c5530.msp
c:\windows\Installer\df36f.msi
c:\windows\Installer\df375.msi
c:\windows\Installer\df37b.msi
c:\windows\Installer\df381.msi
c:\windows\Installer\df387.msi
c:\windows\Installer\df391.msi
c:\windows\Installer\df397.msi
c:\windows\Installer\df39d.msi
c:\windows\Installer\df3a3.msi
c:\windows\Installer\df3a9.msi
c:\windows\Installer\df3b0.msi
c:\windows\Installer\df3b7.msi
c:\windows\Installer\df3bd.msi
c:\windows\Installer\df3c3.msi
c:\windows\Installer\df3c9.msi
c:\windows\Installer\df3cf.msi
c:\windows\Installer\df3d5.msi
c:\windows\Installer\df3db.msi
c:\windows\Installer\df3fa.msi
c:\windows\Installer\e2d6b.msp
c:\windows\system32\ATIODCLI.exe
c:\windows\system32\ATIODE.exe
c:\windows\system32\drivers\hjgruitkxcvagk.sys
c:\windows\system32\hjgruiecrplqya.dll
c:\windows\system32\hjgruiryonhwao.dat
c:\windows\system32\hjgruitknipbxe.dll
c:\windows\system32\hjgruitrawfnyl.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_hjgruilbnukjvl
((((((((((((((((((((((((( Files Created from 2009-06-07 to 2009-07-07 )))))))))))))))))))))))))))))))
.
2009-07-07 02:18 . 2009-07-07 02:49 ——– d—–w- c:\program files\WM Converter
2009-07-06 15:01 . 2009-07-06 15:01 ——– d—–w- c:\program files\Trend Micro
2009-07-06 04:20 . 2009-07-06 17:56 117760 —-a-w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-06 04:20 . 2009-07-06 04:20 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-06 04:19 . 2009-07-06 04:19 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-07-06 04:19 . 2009-07-06 04:19 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\SUPERAntiSpyware.com
2009-07-06 04:19 . 2009-07-06 04:19 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-05 18:04 . 2009-07-05 18:14 ——– d—–w- c:\windows\BDOSCAN8
2009-07-05 04:04 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-07-02 04:20 . 2008-04-26 20:14 42672 ——w- c:\windows\system32\wbsys.dll
2009-07-02 03:52 . 2009-07-02 03:52 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\AdobeUM
2009-07-02 03:52 . 2009-07-02 03:52 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\Adobe
2009-07-02 02:31 . 2009-07-02 02:31 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\Sonic
2009-07-02 02:31 . 2009-07-02 02:31 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\Leadertech
2009-07-01 19:00 . 2009-07-01 19:00 ——– d—–w- c:\program files\PowerISO
2009-06-30 17:17 . 2008-10-16 18:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-06-30 16:11 . 2009-07-06 19:01 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Tracing
2009-06-30 01:56 . 2009-06-30 01:56 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\Ahead
2009-06-30 01:54 . 2009-06-30 01:56 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\Ahead
2009-06-30 01:51 . 2009-06-30 01:51 ——– d—–w- c:\program files\Nero
2009-06-29 23:08 . 2001-08-18 02:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2009-06-29 23:08 . 2008-04-14 00:12 159232 —-a-w- c:\windows\system32\ptpusd.dll
2009-06-29 23:08 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-06-29 23:08 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2009-06-29 22:49 . 2009-06-29 22:49 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\WinBatch
2009-06-29 22:48 . 2009-07-07 20:14 81984 —-a-w- c:\windows\system32\bdod.bin
2009-06-29 22:29 . 2009-06-29 22:29 ——– d—–w- c:\program files\NetDragon
2009-06-29 22:29 . 2009-06-29 22:29 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\InstallShield
2009-06-29 22:22 . 2009-06-29 22:25 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-06-29 22:22 . 2009-06-29 22:22 ——– d—–w- c:\windows\system32\LogFiles
2009-06-29 22:14 . 2009-07-02 02:44 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\Apple Computer
2009-06-29 22:14 . 2009-03-19 20:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-29 22:14 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-29 22:13 . 2009-06-29 22:13 ——– d—–w- c:\program files\iPod
2009-06-29 22:13 . 2009-06-29 22:14 ——– d—–w- c:\program files\iTunes
2009-06-29 22:12 . 2009-06-29 22:12 ——– d—–w- c:\program files\Bonjour
2009-06-29 22:11 . 2009-06-29 22:12 ——– d—–w- c:\program files\QuickTime
2009-06-29 22:11 . 2009-06-29 22:11 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\Apple
2009-06-29 22:11 . 2009-05-29 17:36 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-29 22:11 . 2009-05-29 17:36 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-06-29 22:10 . 2009-06-29 22:14 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\Apple Computer
2009-06-29 22:04 . 2009-06-29 22:04 ——– d—–w- c:\program files\EA GAMES
2009-06-29 21:58 . 2009-06-29 21:58 ——– d—–w- c:\program files\Pure Networks
2009-06-29 21:56 . 2009-06-29 21:56 ——– d—–w- c:\program files\WebEx
2009-06-29 21:56 . 2008-12-12 22:05 23984 —-a-w- c:\windows\system32\drivers\pnarp.sys
2009-06-29 21:55 . 2008-12-12 22:05 25264 —-a-w- c:\windows\system32\drivers\purendis.sys
2009-06-29 21:44 . 2009-06-29 21:44 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\BitDefender
2009-06-29 21:44 . 2009-06-29 21:44 ——– d—–w- C:\Binaries
2009-06-29 21:44 . 2009-06-29 21:48 ——– d—–w- c:\documents and settings\All Users\Application Data\BitDefender
2009-06-29 21:44 . 2009-06-29 21:44 ——– d—–w- c:\program files\BitDefender
2009-06-29 21:38 . 2009-06-29 21:38 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-06-29 21:37 . 2009-06-29 21:40 ——– d—–w- c:\windows\SxsCaPendDel
2009-06-29 21:29 . 2009-06-29 22:14 ——– dc—-w- c:\windows\system32\DRVSTORE
2009-06-29 21:27 . 2009-06-29 21:27 ——– d—–w- c:\program files\Logitech
2009-06-29 21:21 . 2009-06-29 21:21 ——– d—–w- c:\program files\DAEMON Tools Toolbar
2009-06-29 21:21 . 2009-06-29 21:21 ——– d—–w- c:\program files\DAEMON Tools Lite
2009-06-29 21:17 . 2009-06-29 21:17 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-06-29 21:17 . 2009-06-29 22:01 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\DAEMON Tools Lite
2009-06-29 21:00 . 2009-06-29 21:00 ——– d—–w- c:\windows\system32\logs
2009-06-29 20:57 . 2009-06-29 20:57 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\ATI
2009-06-29 20:57 . 2009-06-29 20:57 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\ATI
2009-06-29 20:57 . 2009-06-29 20:57 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI
2009-06-29 20:52 . 2009-06-29 20:52 190792 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-29 20:52 . 2009-06-29 20:52 ——– d—–w- c:\windows\system32\XPSViewer
2009-06-29 20:50 . 2009-06-29 20:50 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\HPQ
2009-06-29 20:31 . 2009-07-07 16:43 34 —-a-w- c:\documents and settings\Compaq_Owner.MOHAMMED\jagex_runescape_preferences.dat
2009-06-29 19:49 . 2009-06-29 19:49 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\Microsoft Help
2009-06-29 19:37 . 2008-04-13 18:45 60032 —-a-w- c:\windows\system32\drivers\usbaudio.sys
2009-06-29 19:37 . 2009-06-29 19:37 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\PCHealth
2009-06-29 19:37 . 2001-08-17 20:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-06-29 19:37 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-06-29 19:37 . 2008-04-13 18:45 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2009-06-29 19:37 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-06-29 19:28 . 2009-06-29 19:29 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-29 19:25 . 2009-05-16 01:05 593920 ——w- c:\windows\system32\ati2sgag.exe
2009-06-29 19:22 . 2009-06-29 19:22 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-06-29 19:22 . 2009-06-29 19:22 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-06-29 19:21 . 2009-07-06 20:07 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\Xfire
2009-06-29 19:21 . 2009-07-02 04:05 ——– d—–w- c:\program files\Xfire
2009-06-29 19:19 . 2006-06-29 17:07 14048 ——w- c:\windows\system32\spmsg2.dll
2009-06-29 19:16 . 2009-06-29 19:16 ——– d—–w- c:\program files\TheWeatherNetwork
2009-06-29 19:11 . 2009-06-29 19:11 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\Stardock
2009-06-29 19:10 . 2009-06-29 19:10 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\Mozilla
2009-06-29 19:10 . 2009-07-02 04:20 ——– d—–w- c:\program files\Stardock
2009-06-29 18:55 . 2009-06-29 18:55 ——– d—–w- c:\program files\uTorrent
2009-06-29 18:55 . 2009-07-06 04:26 ——– d—–w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\uTorrent
2009-06-29 18:52 . 2009-06-29 18:52 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-29 18:36 . 2009-06-29 18:36 ——– d—–w- c:\windows\system32\scripting
2009-06-29 18:36 . 2009-06-29 18:36 ——– d—–w- c:\windows\system32\en
2009-06-29 18:36 . 2009-06-29 18:36 ——– d—–w- c:\windows\system32\bits
2009-06-29 18:21 . 2008-04-14 00:09 6144 ——w- c:\windows\system32\kbdbhc.dll
2009-06-29 18:04 . 2009-06-29 18:04 ——– d-sh–w- c:\documents and settings\Compaq_Owner.MOHAMMED\IECompatCache
2009-06-29 18:04 . 2009-06-29 18:04 ——– d-sh–w- c:\documents and settings\Compaq_Owner.MOHAMMED\PrivacIE
2009-06-29 18:03 . 2009-06-29 18:03 ——– d-sh–w- c:\documents and settings\Compaq_Owner.MOHAMMED\IETldCache
2009-06-29 17:59 . 2009-04-30 21:22 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2009-06-29 17:59 . 2009-04-30 21:22 1985024 ——w- c:\windows\system32\dllcache\iertutil.dll
2009-06-29 17:59 . 2009-04-30 21:22 11064832 ——w- c:\windows\system32\dllcache\ieframe.dll
2009-06-29 17:59 . 2009-04-30 21:22 246272 ——w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-29 17:19 . 2009-03-06 14:22 284160 ——w- c:\windows\system32\dllcache\pdh.dll
2009-06-29 17:19 . 2009-02-09 12:10 401408 ——w- c:\windows\system32\dllcache\rpcss.dll
2009-06-29 17:19 . 2009-02-09 12:10 473600 ——w- c:\windows\system32\dllcache\fastprox.dll
2009-06-29 17:19 . 2009-02-06 11:11 110592 ——w- c:\windows\system32\dllcache\services.exe
2009-06-29 17:19 . 2009-02-09 12:10 453120 ——w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-06-29 17:19 . 2009-02-06 10:10 227840 ——w- c:\windows\system32\dllcache\wmiprvse.exe
2009-06-29 17:19 . 2009-02-09 12:10 729088 ——w- c:\windows\system32\dllcache\lsasrv.dll
2009-06-29 17:19 . 2009-02-09 12:10 714752 ——w- c:\windows\system32\dllcache\ntdll.dll
2009-06-29 17:19 . 2009-02-09 12:10 617472 ——w- c:\windows\system32\dllcache\advapi32.dll
2009-06-29 17:19 . 2009-02-06 11:06 2145280 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-06-29 17:19 . 2009-02-06 11:08 2189056 ——w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-06-29 17:19 . 2009-02-06 10:32 2023936 ——w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-06-29 17:15 . 2008-10-24 11:21 455296 ——w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-29 17:14 . 2008-12-11 10:57 333952 ——w- c:\windows\system32\dllcache\srv.sys
2009-06-29 17:13 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\dllcache\bthport.sys
2009-06-29 17:13 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-06-29 17:13 . 2008-05-08 14:02 203136 ——w- c:\windows\system32\dllcache\rmcast.sys
2009-06-29 17:13 . 2008-04-11 19:04 691712 ——w- c:\windows\system32\dllcache\inetcomm.dll
2009-06-29 17:00 . 2008-10-15 16:34 337408 ——w- c:\windows\system32\dllcache\netapi32.dll
2009-06-29 16:52 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-06-29 16:52 . 2008-04-21 12:08 215552 ——w- c:\windows\system32\dllcache\wordpad.exe
2009-06-29 16:35 . 2009-06-29 16:35 ——– d-sh–w- c:\documents and settings\Compaq_Owner.MOHAMMED\UserData
2009-06-29 16:08 . 2009-06-30 02:33 45832 —-a-w- c:\documents and settings\Compaq_Owner.MOHAMMED\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-29 16:03 . 2009-06-29 16:03 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-29 16:00 . 2009-06-29 16:00 152576 —-a-w- c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-29 15:51 . 2004-08-04 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-06-29 15:51 . 2004-10-25 22:17 90112 —-a-w- c:\windows\system32\ps2.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-07 02:31 . 2009-06-02 14:53 ——– d—–w- c:\program files\Common Files\logishrd
2009-07-05 18:19 . 2009-07-05 18:19 ——– d—–w- c:\documents and settings\Administrator\Application Data\BitDefender
2009-07-05 04:04 . 2009-07-05 04:04 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-05 04:04 . 2009-07-05 04:04 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-06-30 02:32 . 2009-06-01 20:14 ——– d—–w- c:\program files\Microsoft Silverlight
2009-06-30 00:11 . 2005-12-02 23:04 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-29 23:47 . 2005-12-02 23:21 ——– d—–w- c:\program files\Hewlett-Packard
2009-06-29 21:59 . 2008-08-12 22:40 242184 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2009-06-29 21:59 . 2008-04-23 22:34 192512 —-a-w- c:\windows\system32\txmlutil.dll
2009-06-29 21:59 . 2008-08-14 22:54 104328 —-a-w- c:\windows\system32\drivers\bdfndisf.sys
2009-06-29 21:59 . 2008-08-12 22:40 111112 —-a-w- c:\windows\system32\drivers\bdfm.sys
2009-06-29 21:59 . 2008-07-02 17:07 82696 —-a-w- c:\windows\system32\drivers\BDVEDISK.sys
2009-06-29 21:56 . 2009-06-01 19:15 8673792 —-a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-06-29 21:44 . 2009-06-04 01:59 ——– d—–w- c:\program files\Common Files\BitDefender
2009-06-29 19:52 . 2005-12-02 23:26 ——– d—–w- c:\program files\Microsoft.NET
2009-06-29 19:52 . 2009-06-01 20:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-29 19:27 . 2005-12-02 23:04 ——– d—–w- c:\program files\ATI Technologies
2009-06-29 18:38 . 2005-06-25 05:31 82623 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-29 18:38 . 2009-06-29 18:38 45056 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2009-06-29 18:38 . 2009-06-29 18:38 61440 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2009-06-29 18:38 . 2009-06-29 18:38 44032 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2009-06-29 18:38 . 2009-06-29 18:38 40960 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2009-06-29 18:38 . 2009-06-29 18:38 341048 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2009-06-29 18:38 . 2009-06-29 18:38 32768 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2009-06-29 18:38 . 2009-06-29 18:38 32768 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2009-06-29 18:38 . 2009-06-29 18:38 163840 —-a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2009-06-29 16:36 . 2005-12-02 23:24 ——– d—–w- c:\program files\Microsoft Works
2009-06-29 16:33 . 2005-12-02 23:30 ——– d—–w- c:\program files\Quicken
2009-06-29 15:51 . 2009-06-29 15:51 1830 –sha-r- c:\windows\system32\drivers\103C_HP_CPC_EL435AA-ABA SR1720NX NA611_YC_0Pres_QMX7550_E61NAheRED1_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.13_T051115_WXH2_L409_M2559_J160_7AMD_8Sempron_91.99_#080509_N10EC8
139_Z11C10620_G.MRK
2009-06-10 03:01 . 2009-06-01 20:14 ——– d—–w- c:\program files\Microsoft
2009-06-06 16:32 . 2009-06-06 16:32 ——– d—–w- c:\program files\Common Files\NetDragon
2009-06-03 19:44 . 2009-06-03 19:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Insight Software Solutions
2009-06-03 19:44 . 2009-06-03 19:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Insight Software
2009-06-03 19:44 . 2009-06-03 19:44 ——– d—–w- c:\program files\Common Files\Insight Software Solutions
2009-06-03 13:18 . 2009-06-03 13:18 ——– d—–w- c:\program files\Common Files\Skype
2009-06-02 21:40 . 2009-06-02 02:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-06-02 17:18 . 2009-06-02 14:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Logishrd
2009-06-02 14:57 . 2009-06-02 14:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Logitech
2009-06-02 02:28 . 2009-06-02 02:26 ——– d—–w- c:\program files\Common Files\Apple
2009-06-02 02:28 . 2009-06-02 02:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-02 02:27 . 2009-06-02 02:27 ——– d—–w- c:\program files\Apple Software Update
2009-06-02 02:25 . 2009-06-02 02:25 ——– d—–w- c:\program files\MSXML 4.0
2009-06-01 20:49 . 2009-06-01 20:49 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-06-01 20:14 . 2009-06-01 20:13 ——– d—–w- c:\program files\Windows Live
2009-06-01 20:10 . 2009-06-01 20:10 ——– d—–w- c:\program files\Common Files\Windows Live
2009-06-01 19:57 . 2009-06-01 19:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Ahead
2009-06-01 19:55 . 2009-06-01 19:54 ——– d—–w- c:\program files\Common Files\Ahead
2009-06-01 19:54 . 2009-06-01 19:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2009-06-01 19:15 . 2009-06-01 19:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks
2009-06-01 19:15 . 2009-06-01 19:15 ——– d—–w- c:\program files\Common Files\Pure Networks Shared
2009-06-01 18:58 . 2009-06-01 18:58 ——– d—–w- c:\program files\Common Files\Stardock
2009-06-01 18:53 . 2009-06-01 18:53 0 —-a-w- c:\windows\nsreg.dat
2009-06-01 18:35 . 2009-06-01 18:35 0 —-a-w- c:\windows\ativpsrm.bin
2009-06-01 18:30 . 2009-06-01 18:30 ——– d—–w- c:\program files\Common Files\ATI Technologies
2009-06-01 18:25 . 2009-06-01 18:25 ——– d—–w- c:\program files\MSBuild
2009-06-01 18:22 . 2009-06-01 18:22 ——– d—–w- c:\program files\Reference Assemblies
2009-05-30 16:50 . 2009-05-30 16:50 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-16 03:58 . 2005-12-02 23:04 4069888 —-a-w- c:\windows\system32\drivers\ati2mtag.sys
2009-05-16 03:39 . 2009-05-16 03:39 442368 —-a-w- c:\windows\system32\ATIDEMGX.dll
2009-05-16 03:38 . 2005-12-02 23:04 335872 —-a-w- c:\windows\system32\ati2dvag.dll
2009-05-16 03:18 . 2009-05-16 03:18 204800 —-a-w- c:\windows\system32\atipdlxx.dll
2009-05-16 03:17 . 2009-05-16 03:17 155648 —-a-w- c:\windows\system32\Oemdspif.dll
2009-05-16 03:17 . 2009-05-16 03:17 26112 —-a-w- c:\windows\system32\Ati2mdxx.exe
2009-05-16 03:17 . 2009-05-16 03:17 43520 —-a-w- c:\windows\system32\ati2edxx.dll
2009-05-16 03:17 . 2005-12-02 23:04 155648 —-a-w- c:\windows\system32\ati2evxx.dll
2009-05-16 03:15 . 2009-05-16 03:15 602112 —-a-w- c:\windows\system32\ati2evxx.exe
2009-05-16 03:14 . 2009-05-16 03:14 53248 —-a-w- c:\windows\system32\ATIDDC.DLL
2009-05-16 03:07 . 2005-12-02 23:04 2987136 —-a-w- c:\windows\system32\ati3duag.dll
2009-05-16 02:55 . 2009-05-16 02:55 11423744 —-a-w- c:\windows\system32\atioglxx.dll
2009-05-16 02:54 . 2005-12-02 23:04 2122624 —-a-w- c:\windows\system32\ativvaxx.dll
2009-05-16 02:54 . 2009-05-16 02:54 887724 —-a-w- c:\windows\system32\ativva6x.dat
2009-05-16 02:54 . 2009-05-16 02:54 3 —-a-w- c:\windows\system32\ativva5x.dat
2009-05-16 02:51 . 2005-12-02 23:04 311296 —-a-w- c:\windows\system32\atiiiexx.dll
2009-05-16 02:38 . 2009-05-16 02:38 49664 —-a-w- c:\windows\system32\atimpc32.dll
2009-05-16 02:38 . 2009-05-16 02:38 49664 —-a-w- c:\windows\system32\amdpcom32.dll
2009-05-16 02:33 . 2009-05-16 02:33 479232 —-a-w- c:\windows\system32\atikvmag.dll
2009-05-16 02:31 . 2009-05-16 02:31 139264 —-a-w- c:\windows\system32\atiadlxx.dll
2009-05-16 02:31 . 2009-05-16 02:31 17408 —-a-w- c:\windows\system32\atitvo32.dll
2009-05-16 02:30 . 2009-05-16 02:30 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll
2009-05-16 02:26 . 2009-05-16 02:26 376832 —-a-w- c:\windows\system32\atiok3x2.dll
2009-05-16 02:24 . 2005-12-02 23:04 651264 —-a-w- c:\windows\system32\ati2cqag.dll
2009-05-16 01:35 . 2009-05-16 01:35 45056 —-a-w- c:\windows\system32\aticalrt.dll
2009-05-16 01:34 . 2009-05-16 01:34 45056 —-a-w- c:\windows\system32\aticalcl.dll
2009-05-16 01:33 . 2009-05-16 01:33 3158016 —-a-w- c:\windows\system32\aticaldd.dll
2009-05-13 05:15 . 2004-08-04 12:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-13 01:03 . 2009-06-01 19:14 30420528 —-a-r- c:\documents and settings\All Users\Application Data\Pure Networks\Setup\nmsetup.exe
2009-05-09 05:14 . 2009-05-09 05:14 1418120 —-a-w- c:\windows\system32\wdfcoinstaller01005.dll
2009-05-09 05:14 . 2009-05-09 05:14 14736 —-a-w- c:\windows\system32\drivers\nuidfltr.sys
2009-05-07 15:32 . 2004-08-04 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-05 19:33 . 2009-05-05 19:33 118784 —-a-w- c:\windows\system32\atibtmon.exe
2009-04-23 19:04 . 2009-04-23 19:04 189051 —-a-w- c:\windows\system32\atiicdxx.dat
2009-04-17 12:26 . 2004-08-04 12:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-29 21:59 . 2008-08-13 23:02 49664 —-a-w- c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-29 148888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-06-29 778240]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-06-29 69632]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-06-29 467240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
c:\documents and settings\Compaq_Owner.MOHAMMED\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-6-29 3450608]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-12-2 27136]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/06/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/06/2009 11:01 AM 72944]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [02/07/2008 1:07 PM 82696]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [20/07/2007 6:40 PM 84992]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [12/08/2008 6:40 PM 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [14/08/2008 6:54 PM 104328]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [17/07/2008 1:06 PM 118784]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/06/2009 11:01 AM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-07-07 c:\windows\Tasks\User_Feed_Synchronization-{4507849F-F40E-49E6-9965-1C0599900EAD}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
2009-07-07 c:\windows\Tasks\User_Feed_Synchronization-{EE695528-7E4D-4B3E-9A4B-F824197AB31B}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_CA&c;=Q106&bd;=presario&pf;=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_CA&c;=Q106&bd;=presario&pf;=desktop
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: {5F146E4F-0A1C-4598-BCBF-10D6EEBBFCA4} = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Compaq_Owner.MOHAMMED\Application Data\Mozilla\Firefox\Profiles\atcg6yi6.default\
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-07 16:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(924)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-07-07 16:28
ComboFix-quarantined-files.txt 2009-07-07 20:28
Pre-Run: 117,860,982,784 bytes free
Post-Run: 118,140,452,864 bytes free
529 — E O F — 2009-07-07 15:02
hijackthis.log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:16:40 PM, on 07/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - S-1-5-18 Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1246329508328
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{5F146E4F-0A1C-4598-BCBF-10D6EEBBFCA4}: NameServer = 192.168.0.1
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L.
http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
–
End of file - 9323 bytes