This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Have a virus and beyond my knowledge

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm running Windows XP and have been having issues with my computer for a couple weeks now. Two weeks ago my computer froze up while surfing the internet. I had gone to take a shower and when I came back the computer was froze on the site I was looking at before I left, www.sfgate.com website (I use Mozilla Firefox). When I rebooted my computer I got this message
Windows XP could not start because the following file is missing or corrupt: \WINDOWS\SYSTEM32\CONFIG\SYSTEM
So I followed the instructions on http://support.microsoft.com/kb/307545 and was able to recover the registry and the computer appeared to work fine. A couple days ago my computer froze again while checking my e-mail (yahoo). I rebooted and everything seemed fine. While browsing no a message board I began to notice my images were skewed. Some were pixilated, others were cut off, and others were inverted. I ran AVG (the most current version, and I check for updates every week) and the computer shut off when it reached c:\program files\common files. After it rebooted my computer has been in the same state since. I tried to run AVG again and again and each time the computer shut off. Tonight I started the computer in safe mode and again the computer shut off every time I ran AVG. Eventually the anti virus scanned the entire computer not find anything. In web browsing for an answer I found this site and I downloaded hijackthis to an usb drive from my work laptop (which I'm currently on). I ran hijack this in normal setup got the log file tried to save it and the computer said the file could not be saved. Then the computer shut down. I restarted and tried to run hijackthisagain and the computer shut down when I tried to click on my usb drive. After two times trying this I let the computer start in normal set up again and I then put my flash drive in the computer and was able to open it in the pop up that comes up when you enter an usb drive, disc, etc. I was able to run hijackthisagain and when I tried to save the log file back to the flash drive, one I couldn’t save it, and two I had new files loaded onto the flash drive
USB drives with new files loaded onto computer automatically or see attachment jpg
I can't delete these files; they don't open, so I'm guessing the flash drive is done.
In an effort to try another antivirus, I tried to use Symantec security check. After going through all my WebPages being messed up, not running scripts right, and coming up with either a blank webpage, or with code, I got to the site. When I tried to run the virus check and install the active x, the program would not allow me to run the active x because the signature is unknown. So after giving up I took some screenshots of what my favorite websites look like, and my hijack log. Hope you guys can help. As bad as it looks I'm thinking wiping the hard drive is my only option. *****Edit- On a further note I did not have a firewall installed at the time, and the computer has been disconnected from the LAN except when trying to fix it******
this is what cbssportsline.com looks like.
CBS Sportsline with code showing
drudgereport
Drudgreport with messed up images
and yahoo
Blank Yahoo screen/

and here is my hijackthis log file
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:44 PM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ActivCard\acachsrv.exe
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\ActivCard\acautoup.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\ActivCard\ActivCard Gold\acevtsrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
E:\HiJackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [acEventServ] "C:\Program Files\ActivCard\ActivCard Gold\acevtsrv.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\RunOnce: [FFTI] C:\Documents and Settings\Birk\Application Data\Mozilla\Firefox\Profiles\r5tz385y.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="C:\Documents and Settings\Birk\Application Data\Mozilla\Firefox\Profiles/r5tz385y.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: ActivCard Gold Smart Card Agent.lnk = C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1112463699528
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: acAuth - C:\WINDOWS\SYSTEM32\acauth.dll
O23 - Service: ActivCard Authentication Service (ACachSrv) - ActivCard - C:\Program Files\Common Files\ActivCard\acachsrv.exe
O23 - Service: ActivCard Gold Autoregister (acautoreg) - ActivCard S.A. - C:\Program Files\Common Files\ActivCard\acautoreg.exe
O23 - Service: ActivCard Auto-Update Service (acautoupdate) - ActivCard S.A. - C:\Program Files\Common Files\ActivCard\acautoup.exe
O23 - Service: ActivCard Gold service (Accoca) - ActivCard - C:\Program Files\Common Files\ActivCard\accoca.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

–
End of file - 7537 bytes


Thanks for any input!!!!!!!!!

Attachments:

Hello and welcome to the forum. Sorry about the delay in responding :( If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread. Also please describe how your computer behaves at the moment.
Thanks for the reply. I know you guys are busy with the holidays and everything. My computrer is still acting the same. I can only get it load in normal mode after I turn the power supply off, and then turn it on and start the computer. Whenever I attempt to to plug in the internert (it's been unplugged since the 16th) the computer freezes, crashes, and then i get the Windows XP could not start because the following file is missing or corrupt: \WINDOWS\SYSTEM32\CONFIG\SYSTEM message. So i go through the steps to recover it and now the computer will not allow me to go back to any restore points. The system time is three hours behind everytime i start the computer no matter how many times i change it. I recently installed norton to see if that would find it. After fighting for a couyple hours to get it installed, the scan came up negative. I have a card reader i use to access military websites and the drivers were unistalled, and I can not reinstall them. Everytime I logon I get a registry file restored successfully message. I ran hijackthis v 2.0 not realising you guys dont use it, so I went and run the hijackthis 1.9 in normal mode but the computer froze up when I ran the hijackthis.exe. Now the comp restarts everytime xp loads. And I have no way of getting the log off my computer since I cant write to disc, and I'm afraid to put anymore USB drives in my computer after what happened the last time I did that. Looks lke im going to have to wipe. Here is the log i ran in 2.0. I'll keep trying to to get on in normal mode and run 1.9.

Logfile of Trend Micro HijackThis
Scan saved at 9:17:39 AM, on 11/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navw32.exe
C:\Documents and Settings\Birk\Desktop\HiJackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\RunOnce: [FFTI] C:\Documents and Settings\Birk\Application Data\Mozilla\Firefox\Profiles\r5tz385y.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="C:\Documents and Settings\Birk\Application Data\Mozilla\Firefox\Profiles/r5tz385y.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: ActivCard Gold Smart Card Agent.lnk = C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1112463699528
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

–
End of file - 8531 bytes

Looks lke im going to have to wipe. Here is the log i ran in 2.0. I'll keep trying to to get on in normal mode and run 1.9.

We look at either version so just let me have a look :thumbup:
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
UltimateBet
EmpirePoker


Next:

Download Dr.Web CureIt to the desktop -> ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Restart your computer to the safe mode:
Restart your computer
Start tapping the F8 key when the computer restarts.
When the start menu opens, choose Safe mode
Press Enter. The computer then begins to start in Safe mode.

Run a scan with Dr.Web CureIt

Doubleclick the drweb-cureit.exe file and Allow to run the express scan
This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, you should now mark the drives that you want to scan.
Select all drives. A red dot shows which drives have been chosen.
Click the green arrow at the right, and the scan will start.
Click 'Yes to all' if it asks if you want to cure/move the file.

When the scan has finished, look if you can click next icon next to the files found
[external image: Posted Image]
If so, click it and then click the next icon right below and select Move incurable
After the scan, in the menu, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.

Reboot the computer in Normal Mode,
Post the Cure-it report and a fresh HijackThis log
Was able to unistall ultimatebet program. Empire poker could not find the install.log so I can't remove it. I had to run Dr. Web five times to get it to work. The first couple of times I ran it, it froze around 2-5% completion. After that it got up to 17% and found a trojan horse and a virus and I said yes to all and it was able to delete them. After that the program froze and I restarted the computer. I tried running the program a 4th time and it froze while preparing for the express scan. The 5th attempt was successful and found another virus. When I opened up in normal mode the computer ran a NFTS check restarted and I was able to log on. When I logged on in normal mode the computer started up in classic mode, and the windows task bar said I could take a tour of XP as if I had never logged on to my computer before. I get an error message stating an error occured while starting the applicaio. Close all other programs and try again, but it doesnt mention which application. The computer is also trying to open the drivers for my secure card reader. When trying to access My Computer, it took about 40 seconds to find everything in the My Computer folder. My Local Area Connection continues to show the cable is unplugged even though the LAN is connected to it. I am unable to access my CD drive or my usb flash drive. So I can't get the logs off my computer either. The dr.web log is as follows

MiniBugTransporter.dll;C:\ProgamFiles\CommonFiles\Real\WeatherBug;Adware.MiniBug;incurable.Moved.;
A0102148.exe;C:\System Volume Information\_restore{87A92E4A-C019-4CCA-BC39-7D9CCA801D1F}\RP504;Trojan.PWS.Banker.12189;Deleted.;

Here is the HIJACK this log as it shows up in notepad. (I copied some of old hijackthis log that was the same as the new one ran to save time typing it all)
Logfile Tren Micro HijackThis
Scan saved at 6:48:17PM, on 11/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running Processes
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\Atievxx.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\PROGRAM FILES\Common Files\Symantec Shared\CCSVCHST.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grrsoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\SYSTEM32\svchost.exe


R0- HCKU\Software\Microsoft\Internet Explorer\Tollbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2
\CoIEPlg.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: ActivCard Gold Smart Card Agent.lnk = C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1112463699528
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

–
End of file - 7670 bytes
Lets try this now:

To completely uninstall Symantec AntiVirus?
Problem: The solution to many problems with Symantec AntiVirus is to completely uninstall Symantec AntiVirus, then re-install. You can use these instructions to completely uninstall Symantec AntiVirus.

Solution: In order to completely uninstall Symantec AntiVirus and all related components you need to follow these instructions.
Note: This procedure will remove all Symantec products, not just Symantec AntiVirus.

1.Click on Start | Settings | Control Panel
2.In the control panel double-click on Add / Remove Programs
3.Look through the list of installed programs for any item that says either "Norton" or "Symantec" or "LiveUpdate". (for example "Symantec AntiVirus Corporate Edition" or "Norton AntiVirus 2000")
4.For each "Norton", "Symantec", or "LiveUpdate" item, select the item and click Add / Remove. Follow the instructions, and click Yes or Yes to all when prompted.
When you are done there should be no items in the list that say "Norton", "Symantec", or "LiveUpdate".
5.Click OK to close the Add / Remove Programs window.
6.Reboot your computer if it hasn't already automatically rebooted.
7.Delete the c:\Program Files\Symantec AntiVirus (or c:\Program Files\Norton) folder.
8.Delete the c:\Program Files\Symantec folder.
9.Delete the c:\Program Files\Common Files\Symantec Shared folder.



If uninstalling Symantec AntiVirus using Add / Remove Programs does not work, you can use the directions on this Symantec website to manually remove all elements of Symantec Antivirus from your computer.
http://service1.symantec.com/SUPPORT/ent-s…src=bar_sch_nam
I was able to unistall all of symantec products. I have access to my usb and cd drive again. Thanks. My Local are connection still refuses to work. I try to disable it and I get the message "It is not possible to disable the connection at this time. This connection may be using one or more protocols that do not support Plug-and-Play, or it mayhave been initiated by another user account." Do I need to re-install the drivers for my ethernet port? The computer also shows the toolbars and task menu in a pre XP style, yet I'm in category view. Should I try to restore my computer to a previous point since some of the programs I had installed a couple days before this happened have disappeared. Thanks for all your help. Here is the new hijackthis log I got from the computer

Logfile of Trend Micro HijackThis
Scan saved at 7:04:55 AM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Birk\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: ActivCard Gold Smart Card Agent&lnk
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1112463699528
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

–
End of file - 6123 bytes
If you do a system restore you'll put back everything we just fixed.

I suggest you post the below here:

http://forums.whatthetech.com/Networking_f128.html

Let them know we just cleaned it and add this link:
http://forums.whatthetech.com/Have_a_virus…447#entry418447

My Local are connection still refuses to work. I try to disable it and I get the message "It is not possible to disable the connection at this time. This connection may be using one or more protocols that do not support Plug-and-Play, or it mayhave been initiated by another user account." Do I need to re-install the drivers for my ethernet port? The computer also shows the toolbars and task menu in a pre XP style, yet I'm in category view.

Ive tried to restore my computer to four different points, even back to sept., and the computer won't restore at all. Do I still have something on my machine I need to get rid of?
Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall

Note:
Combofix should never take more that 20 minutes including the reboot if malware is detected,
if it does open task-manager > use the processes tab (press ctrl alt and del at the same time) and end
any process's of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know and what process you had to end.
Heres my combofix log
ComboFix 07-11-19.3 - Birk 2007-11-24 9:34:39.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-10-24 to 2007-11-24 )))))))))))))))))))))))))))))))
.

2007-11-24 09:16 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2007-11-23 19:13 d–hs—- C:\found.004
2007-11-23 17:27 d——– C:\Documents and Settings\Administrator.JONATHAN-44HJU4.003\DoctorWeb
2007-11-23 08:02 d——– C:\Documents and Settings\Birk\Application Data\Symantec
2007-11-23 07:58 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-23 07:55 d——– C:\Program Files\Common Files\Symantec Shared
2007-11-20 18:27 d–hs—- C:\found.003
2007-11-19 15:54 d–hs—- C:\found.002
2007-11-16 18:18 d——– C:\Documents and Settings\Administrator.JONATHAN-44HJU4.001\Application Data\AVG7
2007-11-16 17:55 d——– C:\Program Files\DVD Shrink
2007-11-16 17:55 d——– C:\Program Files\BitTorrent
2007-11-16 17:54 d——– C:\TempDVD
2007-11-16 17:28 d–hs—- C:\found.001
2007-11-11 15:05 d——– C:\Program Files\Bonjour
2007-11-11 15:03 d——– C:\Documents and Settings\All Users\Application Data\Kodak
2007-11-11 15:01 d——– C:\Program Files\Kodak
2007-11-02 05:12 3,416 –a—— C:\WINDOWS\system32\PerfStringBackup.TMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-24 17:30 ——— d—–w C:\Program Files\Teamspeak2_RC2
2007-11-24 16:00 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-24 01:23 ——— d—–w C:\Program Files\UltimateBet
2007-11-24 01:23 ——— d—–w C:\Program Files\UBNet
2007-11-19 23:59 28,972 —-a-w C:\Documents and Settings\Birk\Application Data\wklnhst.dat
2007-11-19 23:56 ——— d—–w C:\Documents and Settings\Birk\Application Data\AVG7
2007-11-17 01:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Media Center Programs
2007-11-17 01:55 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-17 01:55 ——— d—–w C:\Program Files\EmpirePoker
2007-11-11 22:57 ——— d—–w C:\Documents and Settings\Birk\Application Data\Skype
2007-11-05 02:54 ——— d—–w C:\Program Files\Warcraft III
2007-10-17 05:26 ——— d–h–r C:\Documents and Settings\Birk\Application Data\SecuROM
2007-10-17 05:21 ——— d—–w C:\Program Files\Sierra Entertainment
2007-10-14 04:43 ——— d—–w C:\Program Files\Apple Software Update
2007-10-13 22:27 ——— d—–w C:\Program Files\iTunes
2007-10-13 22:27 ——— d—–w C:\Program Files\iPod
2005-07-14 19:06 34,160 —-a-w C:\Documents and Settings\Birk\Application Data\GDIPFONTCACHEV1.DAT
2005-04-02 17:41 11,306,068 —-a-w C:\Program Files\avg70free_308a468.exe
2004-07-26 10:16 1,117,491 —-a-w C:\Program Files\dvdshrink32setup.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-10-26 22:49 C:\WINDOWS\SOUNDMAN.EXE]
"Control Center"="C:\Program Files\ASUS\WLAN Card Utilities\Center.exe" [2004-08-13 19:07]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-10-26 17:14]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-26 17:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ActivCard Gold Smart Card Agent&lnk [2007-09-06 20:51:41]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-12-25 19:14:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\PROGRA~1\AIM\aim.exe -cnetwait.odl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI DeviceDetect]
2004-06-15 22:17 69705 –a—— C:\Program Files\ATI Multimedia\main\ATIDtct.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
2004-06-15 22:22 106571 –a—— C:\Program Files\ATI Multimedia\main\launchpd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Remote Control]
2004-08-26 23:51 200704 –a—— C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-07-17 21:10 339968 –a—— C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-09-26 13:42 267064 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
KHALMNPR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
C:\Program Files\WildTangent\Apps\GameChannel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\C:\WINDOWS\system32\ASNDIS5.SYS
S3 ASPI;Advanced SCSI Programming Interface Driver;\??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys
S3 BVRPMPR5;BVRPMPR5 NDIS Protocol Driver;\??\D:\INSTAL~E\Core\BVRPMPR5.SYS
S3 iscFlash;iscFlash;\??\C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys
S3 W8100XP;Marvell Libertas 802.11b/g SoftAP Driver for Windows XP ;C:\WINDOWS\system32\DRIVERS\mrv8ka51.sys

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {3CBBEE47-C8F4-316A-92FF-ED7E3DFAE41E} /qb
.
Contents of the 'Scheduled Tasks' folder
"2007-11-20 00:00:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 09:35:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-24 9:36:15
.
— E O F —
And my HijackThis log
Logfile of Trend Micro HijackThis
Scan saved at 9:36:59 AM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Birk\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: ActivCard Gold Smart Card Agent&lnk
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing)
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1112463699528
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

–
End of file - 6100 bytes
Not seeing much.

Open notepad and copy/paste the text in the quotebox below into it:

Folder::
C:\found.004
C:\found.003
C:\found.002
C:\found.001
C:\Program Files\UltimateBet
C:\Program Files\EmpirePoker


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
ComboFix log
ComboFix 07-11-19.3 - Birk 2007-11-24 10:29:43.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.643 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Birk\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-10-24 to 2007-11-24 )))))))))))))))))))))))))))))))
.

2007-11-24 09:16 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2007-11-23 19:13 d–hs—- C:\found.004
2007-11-23 17:27 d——– C:\Documents and Settings\Administrator.JONATHAN-44HJU4.003\DoctorWeb
2007-11-23 08:02 d——– C:\Documents and Settings\Birk\Application Data\Symantec
2007-11-23 07:58 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-23 07:55 d——– C:\Program Files\Common Files\Symantec Shared
2007-11-20 18:27 d–hs—- C:\found.003
2007-11-19 15:54 d–hs—- C:\found.002
2007-11-16 18:18 d——– C:\Documents and Settings\Administrator.JONATHAN-44HJU4.001\Application Data\AVG7
2007-11-16 17:55 d——– C:\Program Files\DVD Shrink
2007-11-16 17:55 d——– C:\Program Files\BitTorrent
2007-11-16 17:54 d——– C:\TempDVD
2007-11-16 17:28 d–hs—- C:\found.001
2007-11-11 15:05 d——– C:\Program Files\Bonjour
2007-11-11 15:04 d——– C:\WINDOWS\system32\color
2007-11-11 15:03 d——– C:\Documents and Settings\All Users\Application Data\Kodak
2007-11-11 15:01 d——– C:\Program Files\Kodak
2007-11-02 05:12 3,416 –a—— C:\WINDOWS\system32\PerfStringBackup.TMP
2007-11-01 20:52 d——– C:\WINDOWS\tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-24 17:30 ——— d—–w C:\Program Files\Teamspeak2_RC2
2007-11-24 16:00 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-24 01:23 ——— d—–w C:\Program Files\UltimateBet
2007-11-24 01:23 ——— d—–w C:\Program Files\UBNet
2007-11-19 23:59 28,972 —-a-w C:\Documents and Settings\Birk\Application Data\wklnhst.dat
2007-11-19 23:56 ——— d—–w C:\Documents and Settings\Birk\Application Data\AVG7
2007-11-17 01:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Media Center Programs
2007-11-17 01:55 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-17 01:55 ——— d—–w C:\Program Files\EmpirePoker
2007-11-11 22:57 ——— d—–w C:\Documents and Settings\Birk\Application Data\Skype
2007-11-05 02:54 ——— d—–w C:\Program Files\Warcraft III
2007-10-17 05:26 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-17 05:26 ——— d–h–r C:\Documents and Settings\Birk\Application Data\SecuROM
2007-10-17 05:21 ——— d—–w C:\Program Files\Sierra Entertainment
2007-10-14 04:43 ——— d—–w C:\Program Files\Apple Software Update
2007-10-13 22:27 ——— d—–w C:\Program Files\iTunes
2007-10-13 22:27 ——— d—–w C:\Program Files\iPod
2005-07-14 19:06 34,160 —-a-w C:\Documents and Settings\Birk\Application Data\GDIPFONTCACHEV1.DAT
2005-04-02 17:41 11,306,068 —-a-w C:\Program Files\avg70free_308a468.exe
2004-07-26 10:16 1,117,491 —-a-w C:\Program Files\dvdshrink32setup.exe
.

((((((((((((((((((((((((((((( snapshot@2007-11-24_ 9.35.54.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 07:56:43 122,368 —-a-w C:\WINDOWS\system32\oobe\msobcomm.dll
+ 2004-08-04 07:56:43 16,384 —-a-w C:\WINDOWS\system32\oobe\msobdl.dll
+ 2004-08-04 07:56:43 561,664 —-a-w C:\WINDOWS\system32\oobe\msobmain.dll
+ 2004-08-04 07:56:43 30,720 —-a-w C:\WINDOWS\system32\oobe\msobshel.dll
+ 2004-08-04 07:56:43 18,944 —-a-w C:\WINDOWS\system32\oobe\msobweb.dll
+ 2001-08-30 10:30:00 28,160 —-a-w C:\WINDOWS\system32\oobe\msoobe.exe
+ 2004-08-04 07:56:54 51,200 —-a-w C:\WINDOWS\system32\oobe\oobebaln.exe
+ 2004-07-18 01:20:05 233,472 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2cqag.dll
+ 2004-07-18 02:11:43 208,896 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2dvag.dll
+ 2004-07-18 02:07:53 30,720 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2edxx.dll
+ 2004-07-18 02:07:41 86,016 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2evxx.dll
+ 2004-07-18 02:06:19 389,120 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2evxx.exe
+ 2004-07-18 02:08:00 65,536 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\Ati2mdxx.exe
+ 2004-07-18 02:11:24 768,512 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2mtag.sys
+ 2004-07-18 01:55:05 2,176,480 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati3duag.dll
+ 2004-07-18 02:05:56 81,920 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ATIDDC.DLL
+ 2004-07-18 03:55:19 135,168 —-a-r C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ATIDEMGR.dll
+ 2004-07-18 04:17:14 294,912 —-a-r C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atiiiexx.dll
+ 2004-07-18 02:31:01 6,451,200 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atioglxx.dll
+ 2004-07-18 02:08:20 118,784 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atipdlxx.dll
+ 2004-07-18 01:26:56 17,408 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atitvo32.dll
+ 2001-11-09 14:01:04 24,064 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ativcoxx.dll
+ 2004-07-18 01:35:40 484,064 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ativvaxx.dll
+ 2004-07-18 02:08:07 102,400 —-a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\Oemdspif.dll
+ 2004-07-18 01:20:05 233,472 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2cqag.dll
+ 2004-07-18 02:11:43 208,896 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2dvag.dll
+ 2007-02-02 19:56:41 42,496 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2edxx.dll
+ 2004-07-18 02:07:41 86,016 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2evxx.dll
+ 2007-02-02 19:55:08 446,464 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2evxx.exe
+ 2007-02-02 19:56:48 26,112 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\Ati2mdxx.exe
+ 2007-02-02 20:03:25 1,975,296 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2mtag.sys
+ 2004-07-18 01:55:05 2,176,480 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati3duag.dll
+ 2007-02-02 19:54:20 53,248 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ATIDDC.DLL
+ 2004-07-18 03:55:19 135,168 —-a-r C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ATIDEMGR.dll
+ 2007-02-02 20:17:00 307,200 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atiiiexx.dll
+ 2007-02-02 19:19:49 5,312,512 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atioglxx.dll
+ 2007-02-02 19:57:08 118,784 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atipdlxx.dll
+ 2007-02-02 19:25:54 17,408 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atitvo32.dll
+ 2001-11-09 14:01:04 24,064 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ativcoxx.dll
+ 2004-07-18 01:35:40 484,064 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ativvaxx.dll
+ 2007-02-02 19:56:56 110,592 —-a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\Oemdspif.dll
+ 2001-08-30 10:30:00 35,840 —-a-w C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\isapnp.sys
+ 2001-08-30 10:30:00 62,464 —-a-w C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\pci.sys
+ 2001-08-17 21:58:06 62,464 —-a-w C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\pci.sys
+ 2001-08-17 21:58:06 62,464 —-a-w C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\pci.sys
+ 2001-08-17 21:58:06 62,464 —-a-w C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\pci.sys
+ 2001-08-17 21:58:06 62,464 —-a-w C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\pci.sys
+ 2001-08-30 10:30:00 86,656 —-a-w C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\i386\atapi.sys
+ 2001-08-30 10:30:00 23,680 —-a-w C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\i386\pciidex.sys
+ 2001-08-30 10:30:00 4,352 —-a-w C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\i386\viaide.sys
+ 2001-08-30 10:30:00 30,592 —-a-w C:\WINDOWS\system32\ReinstallBackups\0013\DriverFiles\i386\processr.sys
+ 2004-08-04 06:14:36 52,736 —-a-w C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\i8042prt.sys
+ 2004-08-04 05:58:32 23,040 —-a-w C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\mouclass.sys
+ 2001-08-17 21:58:06 62,464 —-a-w C:\WINDOWS\system32\ReinstallBackups\0015\DriverFiles\i386\pci.sys
+ 2004-06-16 15:14:00 180,480 —-a-w C:\WINDOWS\system32\ReinstallBackups\0016\DriverFiles\yk51x86.sys
+ 2007-11-24 17:16:43 1,029,496 —-a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2004-08-04 07:56:55 380,416 —-a-w C:\WINDOWS\system32\Restore\rstrui.exe
+ 2001-08-30 10:30:00 47,104 —-a-w C:\WINDOWS\system32\Restore\srdiag.exe
+ 2001-08-30 10:30:00 259,584 —-a-w C:\WINDOWS\system32\Setup\comsetup.dll
+ 2004-08-04 07:56:42 32,828 —-a-w C:\WINDOWS\system32\Setup\fp40ext.dll
+ 2001-08-30 10:30:00 6,144 —-a-w C:\WINDOWS\system32\Setup\fsconins.dll
+ 2004-08-04 07:56:42 132,608 —-a-w C:\WINDOWS\system32\Setup\fxsocm.dll
+ 2004-08-04 07:56:42 505,344 —-a-w C:\WINDOWS\system32\Setup\iis.dll
+ 2001-08-30 10:30:00 115,712 —-a-w C:\WINDOWS\system32\Setup\imsinsnt.dll
+ 2001-08-30 10:30:00 82,432 —-a-w C:\WINDOWS\system32\Setup\msdtcstp.dll
+ 2004-08-04 07:56:43 15,360 —-a-w C:\WINDOWS\system32\Setup\msgrocm.dll
+ 2004-08-04 07:56:44 77,312 —-a-w C:\WINDOWS\system32\Setup\netoc.dll
+ 2004-08-04 07:56:44 62,976 —-a-w C:\WINDOWS\system32\Setup\ntoc.dll
+ 2004-08-04 07:56:44 15,872 —-a-w C:\WINDOWS\system32\Setup\ocgen.dll
+ 2004-08-04 07:56:44 17,408 —-a-w C:\WINDOWS\system32\Setup\ocmsn.dll
+ 2004-08-04 07:56:44 101,376 —-a-w C:\WINDOWS\system32\Setup\setupqry.dll
+ 2004-08-04 07:56:45 22,016 —-a-w C:\WINDOWS\system32\Setup\startoc.dll
+ 2004-08-04 07:56:46 121,856 —-a-w C:\WINDOWS\system32\Setup\tsoc.dll
+ 2001-08-30 10:30:00 8,261 —-a-w C:\WINDOWS\system32\Setup\zoneoc.dll
+ 2005-05-26 11:16:30 41,240 —-a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\5.8.0.2469\wups.dll
+ 2007-04-17 05:47:36 33,624 —-a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.374\wups.dll
+ 2007-07-31 02:18:40 33,624 —-a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2007-04-17 05:45:20 43,352 —-a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.374\wups2.dll
+ 2007-07-31 02:19:12 43,352 —-a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll
+ 2001-08-18 06:36:10 23,040 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNB2100.DLL
+ 2001-08-18 06:36:10 107,520 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNBJDRV2.DLL
+ 2001-08-18 06:36:10 265,216 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNBJUI2.DLL
+ 2001-08-18 06:36:10 10,752 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\CNBOSTD.DLL
+ 2002-04-30 10:19:12 57,476 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpop2007.dat
+ 2002-04-30 10:19:12 56,698 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpop2107.dat
+ 2002-04-30 10:19:14 57,501 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpop2207.dat
+ 2002-04-23 16:00:46 57,512 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpop6107.dat
+ 2002-04-22 22:46:00 118,784 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpz2ku05.dll
+ 2002-04-22 22:46:08 245,760 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcfg05.exe
+ 2002-04-22 21:58:26 46,592 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcin05.exe
+ 2002-04-22 22:46:16 208,896 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcoi05.dll
+ 2002-04-22 22:46:24 266,240 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcon05.dll
+ 2002-05-08 17:35:10 802,816 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzeng05.exe
+ 2002-04-22 22:46:42 81,920 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzflt05.dll
+ 2002-04-22 21:58:36 274,432 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzglu05.exe
+ 2002-04-22 22:47:14 200,704 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzime05.dll
+ 2002-04-22 21:58:44 76,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzion00.sys
+ 2002-04-22 21:58:52 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpziou01.dll
+ 2002-04-22 21:59:00 28,722 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzjlog.dll
+ 2002-04-22 21:59:08 417,849 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzjpp01.dll
+ 2002-04-22 22:47:34 192,512 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzjui05.dll
+ 2002-04-22 21:59:16 249,913 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzjut01.dll
+ 2002-04-22 21:59:26 49,212 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzjvp01.dll
+ 2002-04-22 22:47:42 147,512 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzlnt05.dll
+ 2002-04-22 22:47:50 294,912 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzntp05.dll
+ 2002-04-22 22:47:58 135,168 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpcl05.dll
+ 2002-04-22 21:59:32 212,992 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpnp05.dll
+ 2002-04-22 21:59:42 48,640 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpom04.dll
+ 2002-04-22 22:48:06 286,720 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpre05.exe
+ 2002-04-22 22:48:14 7,151,616 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzr3205.dll
+ 2002-04-22 22:48:34 122,880 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzres05.dll
+ 2002-04-22 22:48:42 409,600 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzrp305.dll
+ 2002-04-22 21:59:48 180,224 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzscr05.dll
+ 2002-04-22 22:48:50 323,584 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzslk05.dll
+ 2002-04-22 22:48:58 184,386 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzsnt05.dll
+ 2002-04-22 22:49:06 376,832 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzstc05.exe
+ 2002-04-22 22:49:14 172,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzstw05.exe
+ 2002-04-22 22:49:22 73,728 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbi05.dll
+ 2002-04-22 22:49:30 188,416 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbu05.exe
+ 2002-04-22 22:49:38 425,984 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbx05.exe
+ 2002-04-22 21:59:56 13,792 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzuci02.dll
+ 2002-04-22 22:00:04 113,024 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzusb00.sys
+ 2002-04-22 22:49:46 155,699 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzvip05.dll
+ 2003-06-19 01:31:44 758,784 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2003-06-19 01:31:46 35,328 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2004-08-04 07:56:46 264,704 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrv.dll
+ 2004-08-04 07:56:46 197,120 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll
+ 2004-08-04 07:56:34 619,520 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll
+ 2002-04-30 10:19:12 57,476 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpop2007.dat
+ 2002-04-30 10:19:12 56,698 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpop2107.dat
+ 2002-04-30 10:19:14 57,501 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpop2207.dat
+ 2002-04-23 16:00:46 57,512 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpop6107.dat
+ 2002-04-22 22:46:00 118,784 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpz2ku05.dll
+ 2002-04-22 22:46:08 245,760 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzcfg05.exe
+ 2002-04-22 21:58:26 46,592 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzcin05.exe
+ 2002-04-22 22:46:16 208,896 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzcoi05.dll
+ 2002-04-22 22:46:24 266,240 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzcon05.dll
+ 2002-05-08 17:35:10 802,816 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzeng05.exe
+ 2002-04-22 22:46:42 81,920 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzflt05.dll
+ 2002-04-22 21:58:36 274,432 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzglu05.exe
+ 2002-04-22 22:47:14 200,704 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzime05.dll
+ 2002-04-22 21:58:44 76,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzion00.sys
+ 2002-04-22 21:58:52 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpziou01.dll
+ 2002-04-22 21:59:00 28,722 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzjlog.dll
+ 2002-04-22 21:59:08 417,849 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzjpp01.dll
+ 2002-04-22 22:47:34 192,512 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzjui05.dll
+ 2002-04-22 21:59:16 249,913 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzjut01.dll
+ 2002-04-22 21:59:26 49,212 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzjvp01.dll
+ 2002-04-22 22:47:42 147,512 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzlnt05.dll
+ 2002-04-22 22:47:50 294,912 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzntp05.dll
+ 2002-04-22 22:47:58 135,168 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzpcl05.dll
+ 2002-04-22 21:59:32 212,992 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzpnp05.dll
+ 2002-04-22 21:59:42 48,640 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzpom04.dll
+ 2002-04-22 22:48:06 286,720 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzpre05.exe
+ 2002-04-22 22:48:14 7,151,616 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzr3205.dll
+ 2002-04-22 22:48:34 122,880 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzres05.dll
+ 2002-04-22 22:48:42 409,600 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzrp305.dll
+ 2002-04-22 21:59:48 180,224 —-a-r C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzscr05.dll
+ 2002-04-22 22:48:50 323,584 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzslk05.dll
+ 2002-04-22 22:48:58 184,386 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzsnt05.dll
+ 2002-04-22 22:49:06 376,832 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzstc05.exe
+ 2002-04-22 22:49:14 172,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzstw05.exe
+ 2002-04-22 22:49:22 73,728 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpztbi05.dll
+ 2002-04-22 22:49:30 188,416 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpztbu05.exe
+ 2002-04-22 22:49:38 425,984 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpztbx05.exe
+ 2002-04-22 21:59:56 13,792 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzuci02.dll
+ 2002-04-22 22:00:04 113,024 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzusb00.sys
+ 2002-04-22 22:49:46 155,699 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\hewlett_packardpsc_2110e\hpzvip05.dll
+ 2003-06-19 01:31:44 758,784 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
+ 2003-06-19 01:31:46 35,328 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
+ 2003-06-19 01:31:48 18,944 —-a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2003-02-21 02:06:20 282,624 —-a-w C:\WINDOWS\system32\URTTemp\fusion.dll
+ 2003-02-21 02:06:24 155,648 —-a-w C:\WINDOWS\system32\URTTemp\mscoree.dll
+ 2003-02-21 02:09:18 77,824 —-a-w C:\WINDOWS\system32\URTTemp\mscorsn.dll
+ 2003-02-21 02:08:32 2,482,176 —-a-w C:\WINDOWS\system32\URTTemp\mscorwks.dll
+ 2003-02-21 11:42:22 348,160 —-a-w C:\WINDOWS\system32\URTTemp\msvcr71.dll
+ 2003-02-21 12:16:08 49,152 —-a-w C:\WINDOWS\system32\URTTemp\regtlib.exe
+ 2004-08-04 07:56:42 123,904 —-a-w C:\WINDOWS\system32\usmt\guitrn.dll
+ 2004-08-04 07:56:42 108,544 —-a-w C:\WINDOWS\system32\usmt\guitrn_a.dll
+ 2004-08-04 07:56:42 4,096 —-a-w C:\WINDOWS\system32\usmt\iconlib.dll
+ 2004-08-04 07:56:42 19,968 —-a-w C:\WINDOWS\system32\usmt\log.dll
+ 2004-08-04 07:56:42 201,216 —-a-w C:\WINDOWS\system32\usmt\migism.dll
+ 2004-08-04 07:56:42 192,512 —-a-w C:\WINDOWS\system32\usmt\migism_a.dll
+ 2004-08-04 07:56:50 103,424 —-a-w C:\WINDOWS\system32\usmt\migload.exe
+ 2004-08-04 07:56:51 240,128 —-a-w C:\WINDOWS\system32\usmt\migwiz.exe
+ 2004-08-04 07:56:51 236,032 —-a-w C:\WINDOWS\system32\usmt\migwiz_a.exe
+ 2004-08-04 07:56:44 202,752 —-a-w C:\WINDOWS\system32\usmt\script.dll
+ 2004-08-04 07:56:44 188,416 —-a-w C:\WINDOWS\system32\usmt\script_a.dll
+ 2004-08-04 07:56:46 168,960 —-a-w C:\WINDOWS\system32\usmt\sysmod.dll
+ 2004-08-04 07:56:46 155,648 —-a-w C:\WINDOWS\system32\usmt\sysmod_a.dll
+ 2004-08-04 07:56:41 1,352,192 —-a-w C:\WINDOWS\system32\wbem\cimwin32.dll
+ 2001-08-30 10:30:00 120,320 —-a-w C:\WINDOWS\system32\wbem\dsprov.dll
+ 2004-08-04 07:56:42 247,808 —-a-w C:\WINDOWS\system32\wbem\esscli.dll
+ 2004-08-04 07:56:42 22,016 —-a-w C:\WINDOWS\system32\wbem\evntrprv.dll
+ 2004-08-04 07:56:42 472,064 —-a-w C:\WINDOWS\system32\wbem\fastprox.dll
+ 2004-08-04 07:56:42 185,856 —-a-w C:\WINDOWS\system32\wbem\framedyn.dll
+ 2001-08-30 10:30:00 53,248 —-a-w C:\WINDOWS\system32\wbem\fwdprov.dll
+ 2004-08-04 07:56:42 24,576 —-a-w C:\WINDOWS\system32\wbem\krnlprov.dll
+ 2004-08-04 07:56:51 16,384 —-a-w C:\WINDOWS\system32\wbem\mofcomp.exe
+ 2004-08-04 07:56:42 123,904 —-a-w C:\WINDOWS\system32\wbem\mofd.dll
+ 2001-08-30 10:30:00 273,920 —-a-w C:\WINDOWS\system32\wbem\msiprov.dll
+ 2004-08-04 07:56:44 47,104 —-a-w C:\WINDOWS\system32\wbem\ncprov.dll
+ 2004-08-04 07:56:44 212,992 —-a-w C:\WINDOWS\system32\wbem\ntevt.dll
+ 2004-08-04 07:56:44 237,056 —-a-w C:\WINDOWS\system32\wbem\provthrd.dll
+ 2004-08-04 07:56:44 177,152 —-a-w C:\WINDOWS\system32\wbem\repdrvfs.dll
+ 2004-08-04 07:56:55 36,864 —-a-w C:\WINDOWS\system32\wbem\scrcons.exe
+ 2001-08-30 10:30:00 40,960 —-a-w C:\WINDOWS\system32\wbem\smtpcons.dll
+ 2004-08-04 07:56:45 86,528 —-a-w C:\WINDOWS\system32\wbem\stdprov.dll
+ 2001-08-30 10:30:00 61,952 —-a-w C:\WINDOWS\system32\wbem\tmplprov.dll
+ 2001-08-30 10:30:00 59,904 —-a-w C:\WINDOWS\system32\wbem\trnsprov.dll
+ 2001-08-30 10:30:00 16,896 —-a-w C:\WINDOWS\system32\wbem\unsecapp.exe
+ 2001-08-30 10:30:00 116,224 —-a-w C:\WINDOWS\system32\wbem\updprov.dll
+ 2004-08-04 07:56:46 131,584 —-a-w C:\WINDOWS\system32\wbem\viewprov.dll
+ 2001-08-30 10:30:00 12,288 —-a-w C:\WINDOWS\system32\wbem\wbemads.dll
+ 2004-08-04 07:56:46 196,608 —-a-w C:\WINDOWS\system32\wbem\wbemcntl.dll
+ 2004-08-04 07:56:46 214,528 —-a-w C:\WINDOWS\system32\wbem\wbemcomn.dll
+ 2004-08-04 07:56:46 71,680 —-a-w C:\WINDOWS\system32\wbem\wbemcons.dll
+ 2004-08-04 07:56:46 530,944 —-a-w C:\WINDOWS\system32\wbem\wbemcore.dll
+ 2004-08-04 07:56:46 178,176 —-a-w C:\WINDOWS\system32\wbem\wbemdisp.dll
+ 2004-08-04 07:56:46 273,920 —-a-w C:\WINDOWS\system32\wbem\wbemess.dll
+ 2004-08-04 07:56:46 43,008 —-a-w C:\WINDOWS\system32\wbem\wbemperf.dll
+ 2004-08-04 07:56:46 18,944 —-a-w C:\WINDOWS\system32\wbem\wbemprox.dll
+ 2004-08-04 07:56:46 43,520 —-a-w C:\WINDOWS\system32\wbem\wbemsvc.dll
+ 2004-08-04 07:56:57 116,224 —-a-w C:\WINDOWS\system32\wbem\wbemtest.exe
+ 2004-08-04 07:56:46 197,120 —-a-w C:\WINDOWS\system32\wbem\wbemupgd.dll
+ 2001-08-30 10:30:00 13,312 —-a-w C:\WINDOWS\system32\wbem\winmgmt.exe
+ 2001-08-30 10:30:00 16,384 —-a-w C:\WINDOWS\system32\wbem\winmgmtr.dll
+ 2004-08-04 07:56:57 196,608 —-a-w C:\WINDOWS\system32\wbem\wmiadap.exe
+ 2004-08-04 07:56:35 6,656 —-a-w C:\WINDOWS\system32\wbem\wmiapres.dll
+ 2004-08-04 07:56:46 89,088 —-a-w C:\WINDOWS\system32\wbem\wmiaprpl.dll
+ 2004-08-04 07:56:57 126,464 —-a-w C:\WINDOWS\system32\wbem\wmiapsrv.exe
+ 2004-08-04 07:56:46 60,928 —-a-w C:\WINDOWS\system32\wbem\wmicookr.dll
+ 2004-08-04 07:56:46 140,800 —-a-w C:\WINDOWS\system32\wbem\wmidcprv.dll
+ 2001-08-30 10:30:00 61,440 —-a-w C:\WINDOWS\system32\wbem\wmimsg.dll
+ 2004-08-04 07:56:46 156,672 —-a-w C:\WINDOWS\system32\wbem\wmipcima.dll
+ 2004-08-04 07:56:46 132,096 —-a-w C:\WINDOWS\system32\wbem\wmipdskq.dll
+ 2001-08-30 10:30:00 75,264 —-a-w C:\WINDOWS\system32\wbem\wmipicmp.dll
+ 2004-08-04 07:56:46 62,464 —-a-w C:\WINDOWS\system32\wbem\wmipiprt.dll
+ 2004-08-04 07:56:46 62,976 —-a-w C:\WINDOWS\system32\wbem\wmipjobj.dll
+ 2004-08-04 07:56:46 144,896 —-a-w C:\WINDOWS\system32\wbem\wmiprov.dll
+ 2004-08-04 07:56:46 437,248 —-a-w C:\WINDOWS\system32\wbem\wmiprvsd.dll
+ 2004-08-04 07:56:57 218,112 —-a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
+ 2004-08-04 07:56:46 41,472 —-a-w C:\WINDOWS\system32\wbem\wmipsess.dll
+ 2004-08-04 07:56:46 144,896 —-a-w C:\WINDOWS\system32\wbem\wmisvc.dll
+ 2001-08-30 10:30:00 52,224 —-a-w C:\WINDOWS\system32\wbem\wmitimep.dll
+ 2004-08-04 07:56:46 95,232 —-a-w C:\WINDOWS\system32\wbem\wmiutils.dll
+ 2001-08-30 10:30:00 45,568 —-a-w C:\WINDOWS\system32\wbem\xml\wmi2xml.dll
+ 2002-11-06 10:45:32 327,680 —-a-w C:\WINDOWS\system32\windows media\server\wmsservertypelib.dll
+ 2005-05-10 16:22:25 1,233,920 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
+ 2006-11-04 22:17:02 1,245,696 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll
+ 2007-05-08 22:06:44 1,275,392 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
+ 2005-05-10 16:22:25 82,432 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll
+ 2001-08-30 10:30:00 74,802 —-a-r C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\atl.dll
+ 2001-08-30 10:30:00 995,383 —-a-r C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\mfc42.dll
+ 2001-08-30 10:30:00 995,384 —-a-r C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\mfc42u.dll
+ 2001-08-30 10:30:00 401,462 —-a-r C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\msvcp60.dll
+ 2007-01-19 20:15:24 74,802 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2007-01-19 20:15:24 995,383 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2007-01-19 20:15:24 1,011,774 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2007-01-19 20:15:24 401,462 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2005-09-23 07:49:12 95,744 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2006-12-02 06:56:00 96,256 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-06-05 21:14:28 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
+ 2006-06-05 21:14:28 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
+ 2006-06-05 21:14:28 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
+ 2005-09-23 07:48:08 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-23 07:48:08 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 07:48:06 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2006-12-02 05:54:32 479,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-02 05:54:34 548,864 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-02 05:54:32 626,688 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-02 08:25:52 1,101,824 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-02 08:25:56 1,093,120 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-02 08:25:58 69,632 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-02 08:26:00 57,856 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-02 08:08:00 40,960 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-02 08:08:00 45,056 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-02 08:08:00 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-02 08:08:00 57,344 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-02 08:08:00 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-02 08:08:00 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-02 08:08:00 61,440 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-02 08:08:00 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-02 08:08:00 49,152 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-02 08:46:44 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
+ 2001-08-30 10:30:00 921,088 —-a-r C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
+ 2004-08-04 07:57:00 1,050,624 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
+ 2006-08-25 15:45:55 1,054,208 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
+ 2001-08-30 10:30:00 50,688 —-a-r C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcirt.dll
+ 2001-08-30 10:30:00 322,560 —-a-r C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll
+ 2004-08-04 07:57:00 54,784 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\msvcirt.dll
+ 2004-08-04 07:57:00 343,040 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\msvcrt.dll
+ 2001-08-30 10:30:00 1,700,352 —-a-r C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13\GdiPlus.dll
+ 2004-03-02 21:19:47 1,638,400 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.1360_x-ww_24a2ed47\GdiPlus.dll
+ 2004-08-04 07:56:58 1,712,128 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\GdiPlus.dll
+ 2004-08-04 07:56:59 853,504 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
+ 2004-08-04 07:56:59 991,232 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
+ 2004-08-04 07:55:56 132,096 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc
0\rtcres.dll
+ 2007-07-10 21:48:09 258,048 —-a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2007-07-10 21:48:09 114,176 —-a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2003-09-25 16:47:58 176,195 —-a-w C:\WINDOWS\wt\bgmtat.exe
+ 2005-09-02 20:50:11 9,168 —-a-w C:\WINDOWS\wt\updater\wcmdmgr.exe
+ 2005-09-02 20:50:11 9,168 —-a-w C:\WINDOWS\wt\updater\wcmdmgrl.exe
+ 2002-04-11 00:08:48 40,960 —-a-w C:\WINDOWS\wt\WDInUsePlugin.dll
+ 2004-05-14 15:56:26 102,400 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll
+ 2004-05-14 15:56:16 45,056 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll
+ 2004-05-14 15:55:44 65,536 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll
+ 2004-05-14 15:55:32 155,648 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll
+ 2004-05-14 15:56:08 98,304 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\sound.dll
+ 2004-05-14 15:55:20 737,280 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll
+ 2004-05-14 15:58:04 712,704 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll
+ 2004-04-26 22:19:32 61,440 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe
+ 2004-04-26 22:19:36 57,344 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll
+ 2004-03-10 02:57:24 73,728 —-a-w C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll
+ 2003-08-20 22:45:56 98,304 —-a-w C:\WINDOWS\wt\webdriver\actorobject.dll
+ 2003-08-20 22:45:06 40,960 —-a-w C:\WINDOWS\wt\webdriver\dx5drv.dll
+ 2003-08-20 22:44:50 61,440 —-a-w C:\WINDOWS\wt\webdriver\dx7drv.dll
+ 2003-08-20 22:53:16 167,936 —-a-w C:\WINDOWS\wt\webdriver\jdriver.dll
+ 2003-08-20 22:44:20 147,456 —-a-w C:\WINDOWS\wt\webdriver\objectbundle.dll
+ 2003-08-20 22:53:48 159,744 —-a-w C:\WINDOWS\wt\webdriver\rdriver.dll
+ 2003-08-20 22:43:50 98,304 —-a-w C:\WINDOWS\wt\webdriver\sound.dll
+ 2003-08-20 22:42:44 708,608 —-a-w C:\WINDOWS\wt\webdriver\wdengine.dll
+ 2003-08-20 22:50:56 712,704 —-a-w C:\WINDOWS\wt\webdriver\webdriver.dll
+ 2003-10-27 20:42:46 36,864 —-a-w C:\WINDOWS\wt\webdriver\wtdmmp.dll
+ 2003-11-11 02:38:26 49,152 —-a-w C:\WINDOWS\wt\webdriver\wtdmmpv.dll
+ 2003-08-20 22:54:46 61,440 —-a-w C:\WINDOWS\wt\webdriver\wthost.exe
+ 2003-08-20 22:54:54 57,344 —-a-w C:\WINDOWS\wt\webdriver\wthostctl.dll
+ 2003-08-20 22:12:42 73,728 —-a-w C:\WINDOWS\wt\webdriver\wtmulti.dll
+ 2004-06-03 00:50:26 893,386 —-a-w C:\WINDOWS\wt\wtcda\wtcdatt.exe
+ 2003-09-04 23:12:09 21,504 —-a-w C:\WINDOWS\wt\wtDRM\DRM0302.dll
+ 2003-09-04 23:13:57 24,576 —-a-w C:\WINDOWS\wt\wtDRM\jDRM0302.dll
+ 2003-09-04 23:14:01 24,576 —-a-w C:\WINDOWS\wt\wtDRM\rDRM0302.dll
+ 2003-02-06 00:16:58 40,960 —-a-w C:\WINDOWS\wt\wtgutils\wtgutils.dll
+ 2004-06-17 23:54:30 38,344 —-a-w C:\WINDOWS\wt\wtupdates\CDALogger\4.1.0.001\files\CDALogger0401.dll
+ 2003-10-27 20:42:46 36,864 —-a-w C:\WINDOWS\wt\wtupdates\DMMP\3.0.2.000\files\wtdmmp.dll
+ 2003-11-11 02:38:26 49,152 —-a-w C:\WINDOWS\wt\wtupdates\DMMP\3.0.2.000\files\wtdmmpv.dll
+ 2003-09-05 00:12:10 21,504 —-a-w C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll
+ 2003-09-05 00:13:58 24,576 —-a-w C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll
+ 2003-09-05 00:14:02 24,576 —-a-w C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll
+ 2004-05-14 15:56:26 102,400 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll
+ 2004-05-14 15:56:16 45,056 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll
+ 2004-05-14 15:55:44 65,536 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll
+ 2003-08-20 22:53:16 167,936 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll
+ 2004-04-26 22:19:28 32,768 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll
+ 2004-05-14 15:55:32 155,648 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll
+ 2003-08-20 22:53:48 159,744 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll
+ 2004-05-14 15:56:08 98,304 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll
+ 2004-05-14 15:55:20 737,280 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll
+ 2004-05-14 15:58:04 712,704 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll
+ 2004-04-26 22:19:32 61,440 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe
+ 2004-04-26 22:19:36 57,344 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll
+ 2004-03-10 02:57:24 73,728 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll
+ 2004-02-16 18:47:10 53,248 —-a-w C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll
+ 2004-06-03 00:50:26 893,386 —-a-w C:\WINDOWS\wt\wtupdates\wtcda\files\4.0.0.370\wtcdatt.exe
+ 2003-09-10 00:09:26 36,864 —-a-w C:\WINDOWS\wt\wtupdates\wtdmmp\files\3.0.0.005\wtdmmp.dll
+ 2003-09-19 23:50:30 49,152 —-a-w C:\WINDOWS\wt\wtupdates\wtdmmp\files\3.0.0.005\wtdmmpv.dll
+ 2003-08-20 22:45:56 98,304 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\actorobject.dll
+ 2003-08-20 22:45:06 40,960 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\dx5drv.dll
+ 2003-08-20 22:44:50 61,440 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\dx7drv.dll
+ 2003-08-20 22:53:16 167,936 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\jdriver.dll
+ 2003-08-20 22:54:34 36,864 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll
+ 2002-07-08 21:48:42 32,768 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwtplug.dll
+ 2003-08-20 22:44:20 147,456 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\objectbundle.dll
+ 2003-08-20 22:53:48 159,744 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\rdriver.dll
+ 2003-08-20 22:43:50 98,304 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\sound.dll
+ 2003-08-20 22:42:44 708,608 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\wdengine.dll
+ 2003-08-20 22:50:56 712,704 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\webdriver.dll
+ 2003-08-20 22:54:46 61,440 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.exe
+ 2003-08-20 22:54:54 57,344 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthostctl.dll
+ 2003-08-20 22:12:42 73,728 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.dll
+ 2003-08-20 22:40:18 53,248 —-a-w C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtvh.dll
+ 2004-02-16 18:47:10 53,248 —-a-w C:\WINDOWS\wt\wtvh.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-10-26 22:49 C:\WINDOWS\SOUNDMAN.EXE]
"Control Center"="C:\Program Files\ASUS\WLAN Card Utilities\Center.exe" [2004-08-13 19:07]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-10-26 17:14]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-26 17:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ActivCard Gold Smart Card Agent&lnk [2007-09-06 20:51:41]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-12-25 19:14:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\PROGRA~1\AIM\aim.exe -cnetwait.odl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI DeviceDetect]
2004-06-15 22:17 69705 –a—— C:\Program Files\ATI Multimedia\main\ATIDtct.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
2004-06-15 22:22 106571 –a—— C:\Program Files\ATI Multimedia\main\launchpd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Remote Control]
2004-08-26 23:51 200704 –a—— C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-07-17 21:10 339968 –a—— C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-09-26 13:42 267064 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
KHALMNPR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
C:\Program Files\WildTangent\Apps\GameChannel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\C:\WINDOWS\system32\ASNDIS5.SYS
S3 ASPI;Advanced SCSI Programming Interface Driver;\??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys
S3 BVRPMPR5;BVRPMPR5 NDIS Protocol Driver;\??\D:\INSTAL~E\Core\BVRPMPR5.SYS
S3 iscFlash;iscFlash;\??\C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys
S3 W8100XP;Marvell Libertas 802.11b/g SoftAP Driver for Windows XP ;C:\WINDOWS\system32\DRIVERS\mrv8ka51.sys

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {3CBBEE47-C8F4-316A-92FF-ED7E3DFAE41E} /qb
.
Contents of the 'Scheduled Tasks' folder
"2007-11-20 00:00:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 10:30:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-24 10:31:10
C:\ComboFix2.txt … 2007-11-24 09:36
.
— E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI