This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Painful Popups

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I guess ill give a brief history here, i picked up the internet speed monitor trojan malwar the other day and its a been a pain ever since. I think i've gotten rid of that, the random popups that was doing have stopped but now it they are acting dfferently as of today and i get these things popping up when i load internet explorer occasionally asking me to install somekind of program to remove history files or something like that with a dialog box thats yes or cancel. It also looks like when i start IE that its connecting to other things on each page i see it flashing to like adyeildmaster or something and some other things going by too fast to read. Kind of dissapointed this is the first infection i've had on this PC and its been 3 years hard to believe but this has been a nasty little bugger and im expended on my own personal investigation on trying to remove this. Guess I'll start with my HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:09:31 PM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\LEXPPS .EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\bdsyqfqo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr .exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon .exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore .exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ytmnd.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [903855c8] rundll32.exe "C:\WINDOWS\system32\ohcshogn.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab55200.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\bdsyqfqo.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe (file missing)
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Unknown owner - C:\WINDOWS\system32\sfrem01.exe (file missing)
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

–
End of file - 7651 bytes
I am still in training and therefore need my replies checked first by senior staff here before responding, so I will respond to you once I have approval.
Welcome to What the Tech, sorry if there was a delay, it's a busy forum.

Please either print or save these instructions to a program like Notepad because you wont have Internet access during some of them.

Please rename the file listed in bold to HJT.exe
C:\Program Files\Hijackthis\HijackThis.exe <– This file


Please manually disconnect your computer from the Internet.

  • Download ComboFix and save it to the Desktop.
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix just before manually reconnecting to the Internet.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


I don't see any evidence of a firewall in your log, are you using Windows Firewall? If you're not sure please follow these instructions.

Click on the Windows Start button in the left hand corner of your screen.
Go to Control Panel or settings Control Panel
Double click on Windows Firewall
The two main options are On and Off. Tell me whether there's a checkmark next to On or Off.

Please reboot and post a new HijackThis(HJT) log and let me know how your computer is running.

Logs to include in your reply
ComboFix
HJT
well computer is running still at least and i've had windows firewall on, been browsing a couple sites and not seeing any ads yet, sorry forgot the combo fix log here it is

ComboFix 07-12-31.4 - Brandon 2008-01-02 10:53:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1044 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\History\search
C:\Program Files\QdrDrive
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\wininstall.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bdsyqfqo.exe
C:\WINDOWS\system32\ddcyv.dll
C:\WINDOWS\system32\ddcyv.exe
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\hxsxoryl.dll
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ngohscho.ini
C:\WINDOWS\system32\ohcshogn.dll
C:\WINDOWS\system32\vtuvtrs.dll
C:\WINDOWS\system32\vycdd.ini
C:\WINDOWS\system32\vycdd.ini2
C:\WINDOWS\system32\wapiisv.exe
C:\WINDOWS\system32\xuyasapf.dll
C:\WINDOWS\wnsxs~1

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_SFSYNC02
——-\DomainService
——-\sfsync02


((((((((((((((((((((((((( Files Created from 2007-12-02 to 2008-01-02 )))))))))))))))))))))))))))))))
.

2008-01-02 10:52 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-01 22:51 . 2008-01-01 22:51 339,456 –a—— C:\WINDOWS\system32\RCX12.tmp
2008-01-01 22:39 . 2008-01-01 22:39 339,456 –a—— C:\WINDOWS\system32\RCX16.tmp
2008-01-01 22:29 . 2008-01-01 22:29 339,456 –a—— C:\WINDOWS\system32\RCX15.tmp
2008-01-01 22:26 . 2008-01-01 22:26 339,456 –a—— C:\WINDOWS\system32\RCX14.tmp
2008-01-01 22:13 . 2008-01-01 22:13 d——– C:\Program Files\Trend Micro
2008-01-01 22:05 . 2008-01-01 22:05 339,456 –a—— C:\WINDOWS\system32\RCX655.tmp
2008-01-01 00:40 . 2008-01-01 00:40 1,031,139 –ahs—- C:\WINDOWS\system32\upqiywfn.ini
2007-12-30 21:27 . 2008-01-01 23:16 174,592 –a—— C:\WINDOWS\system32\lexpps .exe
2007-12-30 21:19 . 2008-01-01 23:17 d——– C:\WTablet
2007-12-30 21:19 . 2007-12-30 21:19 339,456 –a—— C:\WINDOWS\system32\RCX22.tmp
2007-12-30 14:08 . 2007-12-30 14:08 d——– C:\Program Files\PCPitstop
2007-12-25 21:54 . 2007-12-25 21:54 0 –a—— C:\WINDOWS\PowerReg.dat
2007-12-25 21:33 . 2007-12-25 21:33 d——– C:\Program Files\Infogrames
2007-12-24 23:31 . 2007-12-24 23:34 d——– C:\WINDOWS\NV72169392.TMP
2007-12-24 20:25 . 2007-12-24 20:25 1,270 –a—— C:\batmanpink.bmp
2007-12-24 20:12 . 2007-12-24 20:12 1,270 –a—— C:\taco.bmp
2007-12-06 20:40 . 2007-12-06 20:42 d——– C:\Documents and Settings\Brandon\Application Data\Yahoo!
2007-12-06 20:40 . 2007-12-06 20:42 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2007-12-06 20:38 . 2007-12-06 20:43 d——– C:\Program Files\Yahoo!
2007-12-05 01:41 . 2007-12-05 01:41 1,089,536 –a—— C:\WINDOWS\system32\nvcuda.dll
2007-12-03 22:57 . 2008-01-02 11:04 d——– C:\Documents and Settings\Brandon\Application Data\WTablet

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-02 15:59 ——— d—–w C:\Program Files\QuickTime
2008-01-02 15:59 ——— d—–w C:\Program Files\Lexmark X1100 Series
2007-12-26 03:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-21 21:32 ——— d—–w C:\Program Files\Opera
2007-12-13 02:45 ——— d—–w C:\Program Files\Lineage 2
2007-12-05 06:41 7,435,392 —-a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-11-17 21:00 ——— d—–w C:\Documents and Settings\Brandon\Application Data\Ventrilo
2007-11-15 03:53 ——— d—–w C:\Program Files\Ventrilo
2007-11-15 03:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-08 22:09 ——— d—–w C:\Documents and Settings\Brandon\Application Data\GetRightToGo
2007-11-04 02:48 ——— d—–w C:\Program Files\Logitech
2007-11-04 02:48 ——— d—–w C:\Program Files\Common Files\Logitech
2007-11-04 02:48 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech
2005-06-27 21:00 56 –sh–r C:\WINDOWS\system32\9D1CD01361.sys
2007-01-29 08:56 12,314 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
—-a-w			81,920 2008-01-02 04:16:49  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		 1,132,056 2008-01-02 04:16:53  C:\Program Files\Common Files\Logitech\G-series Software\LGDCore .exe
—-a-w			94,208 2008-01-02 04:16:55  C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR .EXE
—-a-w		   774,168 2008-01-02 04:16:51  C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon .exe
—-a-w			57,344 2008-01-02 04:16:50  C:\Program Files\Lexmark X1100 Series\lxbkbmgr .exe
—-a-w		   131,072 2007-12-31 02:27:25  C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray .exe
—-a-w		   174,592 2008-01-02 04:16:41  C:\WINDOWS\system32\lexpps .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [ ]
"Logitech Hardware Abstraction Layer"="C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [ ]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 11:03 94208 C:\WINDOWS\KHALMNPR.Exe]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"Launch LCDMon"="C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe" [ ]
"Launch LGDCore"="C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" [ ]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-10-10 15:52:44]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]
C:\Program Files\Radeon Omega Drivers\v3.8.291\ATI Tray Tools\atitray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2005-03-04 03:36 36975 –a—— C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

R1 XPROTECTOR;XPROTECTOR;C:\WINDOWS\system32\drivers\Oreans.sys [2005-07-23 17:26]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-09-01 11:32]
R2 TabletServicePen;TabletServicePen;C:\WINDOWS\system32\Pen_Tablet.exe [2007-09-07 10:16]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 10:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 09:30]
R3 WacomVKHid;Virtual Keyboard Driver;C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-15 15:11]
S1 atitray;atitray;C:\Program Files\Radeon Omega Drivers\v3.8.291\ATI Tray Tools\atitray.sys []

.
Contents of the 'Scheduled Tasks' folder
"2006-05-06 02:06:20 C:\WINDOWS\Tasks\dfrg.job"
- C:\WINDOWS\system32\dfrg.msc
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-02 11:04:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-02 11:11:18 - machine was rebooted
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-02 16:11:14
.
2007-12-30 19:39:44 — E O F —

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:12:49 AM, on 1/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ytmnd.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab55200.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe (file missing)
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Unknown owner - C:\WINDOWS\system32\sfrem01.exe (file missing)
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

–
End of file - 6973 bytes
Please either print out or save these instructions again like last time.

Please copy the following to a program like Notepad and save it as CFScript.txt to your Desktop.

File::
C:\WINDOWS\system32\upqiywfn.ini


Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime


RENV::
—-a-w			81,920 2008-01-02 04:16:49  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		 1,132,056 2008-01-02 04:16:53  C:\Program Files\Common Files\Logitech\G-series Software\LGDCore .exe
—-a-w			94,208 2008-01-02 04:16:55  C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR .EXE
—-a-w		   774,168 2008-01-02 04:16:51  C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon .exe
—-a-w			57,344 2008-01-02 04:16:50  C:\Program Files\Lexmark X1100 Series\lxbkbmgr .exe
—-a-w		   131,072 2007-12-31 02:27:25  C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray .exe
—-a-w		   174,592 2008-01-02 04:16:41  C:\WINDOWS\system32\lexpps .exe

Please drag CFScript onto ComboFix as shown in the following image. ComboFix will start to run and don't be alarmed if it wants to reboot, just allow it to.
[external image: Posted Image]

Afterwards please post the contents of its log.

If you haven't already rebooted your system please do so and post a new HJT log.

Logs to include in your reply
ComboFix
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:02:13 PM, on 1/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ytmnd.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab55200.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe (file missing)
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Unknown owner - C:\WINDOWS\system32\sfrem01.exe (file missing)
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

–
End of file - 7778 bytes

ComboFix 08-01-11.3 - Brandon 2008-01-11 21:47:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1119 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Brandon\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\upqiywfn.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\RCX12.tmp
C:\WINDOWS\system32\RCX14.tmp
C:\WINDOWS\system32\RCX15.tmp
C:\WINDOWS\system32\RCX16.tmp
C:\WINDOWS\system32\RCX22.tmp
C:\WINDOWS\system32\upqiywfn.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))
.

2008-01-08 17:52 . 2008-01-08 17:52 d——– C:\WINDOWS\LastGood
2008-01-02 10:52 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-01 22:13 . 2008-01-01 22:13 d——– C:\Program Files\Trend Micro
2008-01-01 22:05 . 2008-01-01 22:05 339,456 –a—— C:\WINDOWS\system32\RCX655.tmp
2007-12-30 21:27 . 2008-01-01 23:16 174,592 –a—— C:\WINDOWS\system32\lexpps.exe
2007-12-30 21:19 . 2008-01-01 23:17 d——– C:\WTablet
2007-12-30 14:08 . 2007-12-30 14:08 d——– C:\Program Files\PCPitstop
2007-12-25 21:54 . 2007-12-25 21:54 0 –a—— C:\WINDOWS\PowerReg.dat
2007-12-25 21:33 . 2007-12-25 21:33 d——– C:\Program Files\Infogrames
2007-12-24 23:31 . 2007-12-24 23:34 d——– C:\WINDOWS\NV72169392.TMP
2007-12-24 20:25 . 2007-12-24 20:25 1,270 –a—— C:\batmanpink.bmp
2007-12-24 20:12 . 2007-12-24 20:12 1,270 –a—— C:\taco.bmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 02:47 ——— d—–w C:\Program Files\Lexmark X1100 Series
2008-01-07 17:03 ——— d—–w C:\Program Files\StepMania
2008-01-03 19:22 ——— d—–w C:\Documents and Settings\Brandon\Application Data\WTablet
2008-01-03 19:20 ——— d—–w C:\Program Files\Yahoo!
2008-01-03 19:18 ——— d—–w C:\Documents and Settings\Brandon\Application Data\Yahoo!
2008-01-03 19:18 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2008-01-02 15:59 ——— d—–w C:\Program Files\QuickTime
2007-12-26 03:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-21 21:32 ——— d—–w C:\Program Files\Opera
2007-12-13 02:45 ——— d—–w C:\Program Files\Lineage 2
2007-12-05 07:53 356,352 -c–a-w C:\WINDOWS\system32\NVUninst.exe
2007-12-05 06:41 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-12-05 06:41 81,920 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-12-05 06:41 8,523,776 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-12-05 06:41 753,664 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-12-05 06:41 7,435,392 —-a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-05 06:41 6,901,760 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-12-05 06:41 6,549,504 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-12-05 06:41 5,773,568 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-12-05 06:41 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-12-05 06:41 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-12-05 06:41 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-12-05 06:41 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-12-05 06:41 385,024 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-12-05 06:41 356,352 —-a-w C:\WINDOWS\system32\nvudisp.exe
2007-12-05 06:41 35,328 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-12-05 06:41 35,328 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-12-05 06:41 307,200 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-12-05 06:41 3,710,976 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-12-05 06:41 3,420,160 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-12-05 06:41 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-12-05 06:41 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-12-05 06:41 2,498,560 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-12-05 06:41 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-12-05 06:41 155,716 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-12-05 06:41 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-12-05 06:41 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-12-05 06:41 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-12-05 06:41 1,474,560 —-a-w C:\WINDOWS\system32\nview.dll
2007-12-05 06:41 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-12-05 06:41 1,228,800 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-12-05 06:41 1,089,536 —-a-w C:\WINDOWS\system32\nvcuda.dll
2007-12-05 06:41 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
2007-11-17 21:00 ——— d—–w C:\Documents and Settings\Brandon\Application Data\Ventrilo
2007-11-15 03:53 ——— d—–w C:\Program Files\Ventrilo
2007-11-15 03:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll
2005-06-27 21:00 56 –sh–r C:\WINDOWS\system32\9D1CD01361.sys
2007-01-29 08:56 12,314 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-01-02_11.11.04.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2000-08-31 13:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2008-01-12 02:47:30 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-12 02:47:30 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-12 02:47:31 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-12 02:47:31 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-12 02:47:31 11,509,760 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
+ 2008-01-12 02:47:31 430,080 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2007-11-21 00:04:14 218,496 —-a-w C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe
- 2007-12-07 01:40:20 48,749 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-01-03 19:17:33 74,137 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2007-12-30 21:27 131072]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2008-01-01 23:16 81920]
"Logitech Hardware Abstraction Layer"="C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2008-01-01 23:16 94208]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 11:03 94208 C:\WINDOWS\KHALMNPR.Exe]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2008-01-01 23:16 57344]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"Launch LCDMon"="C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe" [2008-01-01 23:16 774168]
"Launch LGDCore"="C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" [2008-01-01 23:16 1132056]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-10-10 15:52:44]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]
C:\Program Files\Radeon Omega Drivers\v3.8.291\ATI Tray Tools\atitray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-03-04 03:36 36975 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

R1 XPROTECTOR;XPROTECTOR;C:\WINDOWS\system32\drivers\Oreans.sys [2005-07-23 17:26]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-09-01 11:32]
R2 TabletServicePen;TabletServicePen;C:\WINDOWS\system32\Pen_Tablet.exe [2007-09-07 10:16]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 10:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 09:30]
R3 WacomVKHid;Virtual Keyboard Driver;C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-15 15:11]
S1 atitray;atitray;C:\Program Files\Radeon Omega Drivers\v3.8.291\ATI Tray Tools\atitray.sys []

*Newly Created Service* - NPKCUSB
.
Contents of the 'Scheduled Tasks' folder
"2006-05-06 02:06:20 C:\WINDOWS\Tasks\dfrg.job"
- C:\WINDOWS\system32\dfrg.msc
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-11 21:53:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-11 21:54:39
ComboFix-quarantined-files.txt 2008-01-12 02:54:01
ComboFix2.txt 2008-01-02 16:11:18
.
2007-12-30 19:39:44 — E O F —
Please either print out save these instructions like before.

Click on the Windows Start button in the left hand corner of your screen.
Go to Control Panel or Settings>Control Panel
Double click on Add or Remove Programs and uninstall
QuickTime

Please reboot.

Please copy the following to a program like Notepad and save it as CFScript.txt to your Desktop. Overwrite the previous file if needed.
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]

Please drag CFScript onto ComboFix as shown in the following image. ComboFix will start to run and don't be alarmed if it wants to reboot, just allow it to.
[external image: Posted Image]

Afterwards please post the contents of its log.

If you haven't already rebooted your system please do so now.

Please download QuickTime and install it.


Open up HijackThis, do a System Scan and select the following entries(if present)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
Then close all other windows (you can keep the current browser window open if you like) and press Fix checked and close the program.


I'd also like to see an Uninstall List.
Please open up HijackThis.
Click on Open the Misc Tools section button
Click on Open Uninstall Manager
Click on Save
A notepad document will open with a list of your installed programs. Please copy that into your reply.

Now please reboot and post a new HJT log. Also please let me know how your computer is running now.

Logs to include in your reply
ComboFix
HJT
ComboFix 08-01-11.3 - Brandon 2008-01-18 12:10:56.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1126 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Brandon\Desktop\CFScript.txt.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.

2008-01-18 11:28 . 2008-01-18 11:28 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-18 11:28 . 2008-01-18 11:28 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-15 03:24 . 2008-01-15 03:24 d——– C:\Program Files\Windows Media Connect 2
2008-01-15 03:22 . 2008-01-15 03:23 d——– C:\WINDOWS\system32\drivers\UMDF
2008-01-02 10:52 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-01 22:13 . 2008-01-01 22:13 d——– C:\Program Files\Trend Micro
2008-01-01 22:05 . 2008-01-01 22:05 339,456 –a—— C:\WINDOWS\system32\RCX655.tmp
2007-12-30 21:27 . 2008-01-01 23:16 174,592 –a—— C:\WINDOWS\system32\lexpps.exe
2007-12-30 21:19 . 2008-01-01 23:17 d——– C:\WTablet
2007-12-30 14:08 . 2007-12-30 14:08 d——– C:\Program Files\PCPitstop
2007-12-25 21:54 . 2007-12-25 21:54 0 –a—— C:\WINDOWS\PowerReg.dat
2007-12-25 21:33 . 2007-12-25 21:33 d——– C:\Program Files\Infogrames
2007-12-24 23:31 . 2007-12-24 23:34 d——– C:\WINDOWS\NV72169392.TMP
2007-12-24 20:25 . 2007-12-24 20:25 1,270 –a—— C:\batmanpink.bmp
2007-12-24 20:12 . 2007-12-24 20:12 1,270 –a—— C:\taco.bmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-18 16:37 ——— d—–w C:\Documents and Settings\Brandon\Application Data\WTablet
2008-01-18 16:28 ——— d—–w C:\Program Files\QuickTime
2008-01-12 02:47 ——— d—–w C:\Program Files\Lexmark X1100 Series
2008-01-07 17:03 ——— d—–w C:\Program Files\StepMania
2008-01-03 19:20 ——— d—–w C:\Program Files\Yahoo!
2008-01-03 19:18 ——— d—–w C:\Documents and Settings\Brandon\Application Data\Yahoo!
2008-01-03 19:18 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2007-12-26 03:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-21 21:32 ——— d—–w C:\Program Files\Opera
2007-12-13 02:45 ——— d—–w C:\Program Files\Lineage 2
2007-12-05 07:53 356,352 -c–a-w C:\WINDOWS\system32\NVUninst.exe
2007-12-05 06:41 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-12-05 06:41 81,920 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-12-05 06:41 8,523,776 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-12-05 06:41 753,664 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-12-05 06:41 7,435,392 —-a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-05 06:41 6,901,760 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-12-05 06:41 6,549,504 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-12-05 06:41 5,773,568 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-12-05 06:41 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-12-05 06:41 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-12-05 06:41 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-12-05 06:41 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-12-05 06:41 385,024 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-12-05 06:41 356,352 —-a-w C:\WINDOWS\system32\nvudisp.exe
2007-12-05 06:41 35,328 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-12-05 06:41 35,328 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-12-05 06:41 307,200 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-12-05 06:41 3,710,976 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-12-05 06:41 3,420,160 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-12-05 06:41 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-12-05 06:41 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-12-05 06:41 2,498,560 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-12-05 06:41 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-12-05 06:41 155,716 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-12-05 06:41 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-12-05 06:41 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-12-05 06:41 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-12-05 06:41 1,474,560 —-a-w C:\WINDOWS\system32\nview.dll
2007-12-05 06:41 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-12-05 06:41 1,228,800 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-12-05 06:41 1,089,536 —-a-w C:\WINDOWS\system32\nvcuda.dll
2007-12-05 06:41 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2005-06-27 21:00 56 –sh–r C:\WINDOWS\system32\9D1CD01361.sys
2007-01-29 08:56 12,314 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-01-02_11.11.04.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-10-30 16:53:32 360,832 —-a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
+ 2007-11-07 09:50:47 727,040 —-a-w C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB943485\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB943485\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB943485\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB943485\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB943485\update\updspapi.dll
+ 2006-10-04 14:05:26 39,424 ——w C:\WINDOWS\AppPatch\acadproc.dll
+ 2000-08-31 13:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2008-01-18 17:10:39 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-18 17:10:39 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-18 17:10:39 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-18 17:10:39 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-18 17:10:40 11,743,232 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
+ 2008-01-18 17:10:40 430,080 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2004-09-22 23:46:10 192,512 —-a-w C:\WINDOWS\inf\unregmp2.exe
+ 2007-06-27 03:10:26 317,440 —-a-w C:\WINDOWS\inf\unregmp2.exe
- 2004-09-22 23:45:36 8,192 -c–a-w C:\WINDOWS\system32\asferror.dll
+ 2006-10-19 02:47:08 7,168 —-a-w C:\WINDOWS\system32\asferror.dll
- 2004-09-22 23:45:36 480,768 —-a-w C:\WINDOWS\system32\Audiodev.dll
+ 2006-10-19 02:47:08 276,992 —-a-w C:\WINDOWS\system32\audiodev.dll
- 2004-09-22 23:45:38 233,472 -c–a-w C:\WINDOWS\system32\blackbox.dll
+ 2006-10-19 02:47:10 542,720 —-a-w C:\WINDOWS\system32\blackbox.dll
- 2004-09-22 23:45:38 161,792 -c–a-w C:\WINDOWS\system32\cewmdm.dll
+ 2006-10-19 02:47:10 229,376 —-a-w C:\WINDOWS\system32\cewmdm.dll
- 2004-09-22 23:45:36 8,192 -c–a-w C:\WINDOWS\system32\dllcache\asferror.dll
+ 2006-10-19 02:47:08 7,168 -c–a-w C:\WINDOWS\system32\dllcache\asferror.dll
- 2004-09-22 23:45:38 233,472 -c–a-w C:\WINDOWS\system32\dllcache\blackbox.dll
+ 2006-10-19 02:47:10 542,720 -c–a-w C:\WINDOWS\system32\dllcache\blackbox.dll
- 2004-09-22 23:45:38 161,792 -c–a-w C:\WINDOWS\system32\dllcache\cewmdm.dll
+ 2006-10-19 02:47:10 229,376 -c–a-w C:\WINDOWS\system32\dllcache\cewmdm.dll
- 2004-09-22 23:45:42 527,360 -c–a-w C:\WINDOWS\system32\dllcache\drmv2clt.dll
+ 2006-10-19 02:47:10 991,744 -c–a-w C:\WINDOWS\system32\dllcache\drmv2clt.dll
- 2004-09-22 23:45:44 6,656 -c–a-w C:\WINDOWS\system32\dllcache\laprxy.dll
+ 2006-10-19 02:47:14 11,264 -c–a-w C:\WINDOWS\system32\dllcache\LAPRXY.dll
- 2004-09-22 23:45:44 96,768 -c–a-w C:\WINDOWS\system32\dllcache\logagent.exe
+ 2006-10-19 01:03:58 100,864 -c–a-w C:\WINDOWS\system32\dllcache\logagent.exe
- 2006-08-17 12:28:27 721,920 -c—-w C:\WINDOWS\system32\dllcache\lsasrv.dll
+ 2007-11-07 09:26:56 721,920 -c—-w C:\WINDOWS\system32\dllcache\lsasrv.dll
- 2004-08-04 07:56:42 384,512 -c–a-w C:\WINDOWS\system32\dllcache\mp4sdmod.dll
+ 2006-10-19 02:47:14 4,096 -c–a-w C:\WINDOWS\system32\dllcache\MP4SDMOD.dll
- 2004-09-22 23:45:52 344,064 -c–a-w C:\WINDOWS\system32\dllcache\mpvis.dll
+ 2006-10-19 02:47:14 243,712 -c–a-w C:\WINDOWS\system32\dllcache\mpvis.dll
- 2004-09-22 23:45:52 141,312 -c–a-w C:\WINDOWS\system32\dllcache\msnetobj.dll
+ 2006-10-19 02:47:16 179,712 -c–a-w C:\WINDOWS\system32\dllcache\msnetobj.dll
- 2004-09-22 23:45:54 25,088 -c–a-w C:\WINDOWS\system32\dllcache\mspmsnsv.dll
+ 2006-10-19 02:47:16 27,136 -c–a-w C:\WINDOWS\system32\dllcache\mspmsnsv.dll
- 2004-09-22 23:45:54 169,472 -c–a-w C:\WINDOWS\system32\dllcache\mspmsp.dll
+ 2006-10-19 02:47:16 175,616 -c–a-w C:\WINDOWS\system32\dllcache\mspmsp.dll
- 2004-09-22 23:45:56 360,176 -c–a-w C:\WINDOWS\system32\dllcache\msscp.dll
+ 2006-12-04 21:21:50 414,720 -c–a-w C:\WINDOWS\system32\dllcache\msscp.dll
- 2004-09-22 23:45:56 311,296 -c–a-w C:\WINDOWS\system32\dllcache\mswmdm.dll
+ 2006-10-19 02:47:16 321,536 -c–a-w C:\WINDOWS\system32\dllcache\mswmdm.dll
- 2004-09-22 23:46:02 221,184 -c–a-w C:\WINDOWS\system32\dllcache\qasf.dll
+ 2006-10-19 02:47:18 211,456 -c–a-w C:\WINDOWS\system32\dllcache\qasf.dll
- 2004-09-22 23:46:04 819,200 -c–a-w C:\WINDOWS\system32\dllcache\setup_wm.exe
+ 2006-11-01 23:31:38 1,669,120 -c–a-w C:\WINDOWS\system32\dllcache\setup_wm.exe
- 2006-04-20 11:51:50 359,808 -c—-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2007-10-30 17:20:55 360,064 -c—-w C:\WINDOWS\system32\dllcache\tcpip.sys
- 2004-09-22 23:46:10 192,512 -c–a-w C:\WINDOWS\system32\dllcache\unregmp2.exe
+ 2007-06-27 03:10:26 317,440 -c–a-w C:\WINDOWS\system32\dllcache\unregmp2.exe
- 2004-09-22 23:46:10 380,144 -c–a-w C:\WINDOWS\system32\dllcache\wmadmod.dll
+ 2006-10-19 02:47:18 757,248 -c–a-w C:\WINDOWS\system32\dllcache\WMADMOD.dll
- 2004-09-22 23:46:10 712,704 -c–a-w C:\WINDOWS\system32\dllcache\wmadmoe.dll
+ 2006-10-19 02:47:18 1,117,696 -c–a-w C:\WINDOWS\system32\dllcache\WMADMOE.dll
- 2007-10-27 22:40:06 227,328 -c–a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2007-10-27 22:40:30 222,720 -c–a-w C:\WINDOWS\system32\dllcache\wmasf.dll
- 2004-09-22 23:46:12 30,208 -c–a-w C:\WINDOWS\system32\dllcache\wmdmlog.dll
+ 2006-10-19 02:47:18 33,792 -c–a-w C:\WINDOWS\system32\dllcache\wmdmlog.dll
- 2004-09-22 23:46:12 34,304 -c–a-w C:\WINDOWS\system32\dllcache\wmdmps.dll
+ 2006-10-19 02:47:18 37,376 -c–a-w C:\WINDOWS\system32\dllcache\wmdmps.dll
- 2004-09-22 23:46:14 189,440 -c–a-w C:\WINDOWS\system32\dllcache\wmerror.dll
+ 2006-10-19 02:47:20 227,328 -c–a-w C:\WINDOWS\system32\dllcache\wmerror.dll
- 2004-09-22 23:46:14 150,016 -c–a-w C:\WINDOWS\system32\dllcache\wmidx.dll
+ 2006-10-19 02:47:20 157,184 -c–a-w C:\WINDOWS\system32\dllcache\wmidx.dll
- 2004-09-22 23:46:16 1,027,072 -c–a-w C:\WINDOWS\system32\dllcache\wmnetmgr.dll
+ 2006-10-19 02:47:20 937,984 -c–a-w C:\WINDOWS\system32\dllcache\WMNetMgr.dll
- 2007-04-30 12:20:24 5,537,792 -c–a-w C:\WINDOWS\system32\dllcache\wmp.dll
+ 2007-06-12 04:51:12 10,834,944 -c–a-w C:\WINDOWS\system32\dllcache\wmp.dll
- 2004-09-22 23:46:20 135,168 -c–a-w C:\WINDOWS\system32\dllcache\wmpasf.dll
+ 2006-10-19 02:47:20 242,688 -c–a-w C:\WINDOWS\system32\dllcache\wmpasf.dll
- 2004-09-22 23:46:20 77,824 -c–a-w C:\WINDOWS\system32\dllcache\wmpband.dll
+ 2006-10-19 02:47:20 96,256 -c–a-w C:\WINDOWS\system32\dllcache\wmpband.dll
- 2004-09-22 23:46:20 282,624 -c–a-w C:\WINDOWS\system32\dllcache\wmpdxm.dll
+ 2006-10-19 02:47:20 314,880 -c–a-w C:\WINDOWS\system32\dllcache\wmpdxm.dll
- 2004-09-22 23:46:22 73,728 -c–a-w C:\WINDOWS\system32\dllcache\wmplayer.exe
+ 2006-10-19 02:46:20 64,000 -c–a-w C:\WINDOWS\system32\dllcache\wmplayer.exe
- 2004-09-22 23:46:22 3,371,008 -c–a-w C:\WINDOWS\system32\dllcache\wmploc.dll
+ 2006-10-19 02:47:20 8,231,936 -c–a-w C:\WINDOWS\system32\dllcache\wmploc.dll
- 2004-09-22 23:46:24 86,016 -c–a-w C:\WINDOWS\system32\dllcache\wmpshell.dll
+ 2006-10-19 02:47:20 99,840 -c–a-w C:\WINDOWS\system32\dllcache\wmpshell.dll
- 2004-09-22 23:46:26 773,368 -c–a-w C:\WINDOWS\system32\dllcache\wmsdmod.dll
+ 2006-10-19 02:47:22 4,096 -c–a-w C:\WINDOWS\system32\dllcache\wmsdmod.dll
- 2004-09-22 23:46:26 1,116,160 -c–a-w C:\WINDOWS\system32\dllcache\wmsdmoe2.dll
+ 2006-10-19 02:47:22 4,096 -c–a-w C:\WINDOWS\system32\dllcache\wmsdmoe2.dll
- 2004-09-22 23:46:30 531,192 -c–a-w C:\WINDOWS\system32\dllcache\wmspdmod.dll
+ 2006-10-19 02:47:22 603,648 -c–a-w C:\WINDOWS\system32\dllcache\WMSPDMOD.dll
- 2004-09-22 23:46:30 936,960 -c–a-w C:\WINDOWS\system32\dllcache\wmspdmoe.dll
+ 2006-10-19 02:47:22 1,329,152 -c–a-w C:\WINDOWS\system32\dllcache\WMSPDMOE.dll
- 2006-12-07 06:40:49 2,362,184 -c–a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2006-10-19 02:47:22 2,450,944 -c–a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
- 2004-09-22 23:46:34 871,160 -c–a-w C:\WINDOWS\system32\dllcache\wmvdmod.dll
+ 2006-10-19 02:47:22 4,096 -c–a-w C:\WINDOWS\system32\dllcache\wmvdmod.dll
- 2004-09-22 23:46:34 999,424 -c–a-w C:\WINDOWS\system32\dllcache\wmvdmoe2.dll
+ 2006-10-19 02:47:22 4,096 -c–a-w C:\WINDOWS\system32\dllcache\wmvdmoe2.dll
+ 2007-04-17 02:46:34 33,792 —-a-w C:\WINDOWS\system32\drivers\AmdPPM.sys
- 2006-04-20 11:51:50 359,808 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2007-10-30 17:20:55 360,064 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2006-10-19 02:47:22 671,232 ——w C:\WINDOWS\system32\drivers\UMDF\wpdmtpdr.dll
- 2004-09-22 23:46:38 18,944 -c–a-w C:\WINDOWS\system32\drivers\wpdusb.sys
+ 2006-10-19 01:00:00 38,528 —-a-w C:\WINDOWS\system32\drivers\wpdusb.sys
+ 2006-09-28 23:55:50 77,568 ——w C:\WINDOWS\system32\drivers\WudfPf.sys
+ 2006-09-29 00:00:34 82,944 ——w C:\WINDOWS\system32\drivers\WudfRd.sys
+ 2006-10-19 01:00:46 249,856 ——w C:\WINDOWS\system32\drmupgds.exe
- 2004-09-22 23:45:42 527,360 -c–a-w C:\WINDOWS\system32\drmv2clt.dll
+ 2006-10-19 02:47:10 991,744 —-a-w C:\WINDOWS\system32\drmv2clt.dll
- 2004-09-22 23:45:44 6,656 -c–a-w C:\WINDOWS\system32\laprxy.dll
+ 2006-10-19 02:47:14 11,264 —-a-w C:\WINDOWS\system32\LAPRXY.dll
- 2007-04-24 15:32:06 1,485,696 —-a-w C:\WINDOWS\system32\LegitCheckControl.DLL
+ 2007-10-11 19:12:48 1,468,968 —-a-w C:\WINDOWS\system32\LegitCheckControl.dll
- 2004-09-22 23:45:44 96,768 -c–a-w C:\WINDOWS\system32\logagent.exe
+ 2006-10-19 01:03:58 100,864 —-a-w C:\WINDOWS\system32\logagent.exe
+ 2007-11-21 00:04:14 218,496 —-a-w C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe
- 2007-12-07 01:40:20 48,749 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-01-03 19:17:33 74,137 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2006-10-19 02:47:14 212,992 ——w C:\WINDOWS\system32\MFPLAT.dll
+ 2006-10-19 02:47:14 259,072 ——w C:\WINDOWS\system32\MP43DECD.dll
- 2004-08-04 07:56:42 310,272 —-a-w C:\WINDOWS\system32\mp43dmod.dll
+ 2006-10-19 02:47:14 4,096 —-a-w C:\WINDOWS\system32\MP43DMOD.dll
+ 2006-10-19 02:47:14 317,440 ——w C:\WINDOWS\system32\MP4SDECD.dll
- 2004-08-04 07:56:42 384,512 -c–a-w C:\WINDOWS\system32\mp4sdmod.dll
+ 2006-10-19 02:47:14 4,096 —-a-w C:\WINDOWS\system32\MP4SDMOD.dll
+ 2006-10-19 02:47:14 259,072 ——w C:\WINDOWS\system32\MPG4DECD.dll
- 2004-08-04 07:56:42 240,640 —-a-w C:\WINDOWS\system32\mpg4dmod.dll
+ 2006-10-19 02:47:14 4,096 —-a-w C:\WINDOWS\system32\MPG4DMOD.dll
- 2007-12-02 20:00:06 18,684,536 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-01-02 18:21:36 17,642,616 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2006-10-02 20:28:42 312,128 ——w C:\WINDOWS\system32\msdelta.dll
- 2004-09-22 23:45:52 141,312 -c–a-w C:\WINDOWS\system32\msnetobj.dll
+ 2006-10-19 02:47:16 179,712 —-a-w C:\WINDOWS\system32\msnetobj.dll
- 2004-09-22 23:45:54 25,088 -c–a-w C:\WINDOWS\system32\MsPMSNSv.dll
+ 2006-10-19 02:47:16 27,136 —-a-w C:\WINDOWS\system32\mspmsnsv.dll
- 2004-09-22 23:45:54 169,472 —-a-w C:\WINDOWS\system32\MsPMSP.dll
+ 2006-10-19 02:47:16 175,616 —-a-w C:\WINDOWS\system32\mspmsp.dll
- 2004-09-22 23:45:56 360,176 -c–a-w C:\WINDOWS\system32\MSSCP.dll
+ 2006-12-04 21:21:50 414,720 —-a-w C:\WINDOWS\system32\msscp.dll
- 2004-09-22 23:45:56 311,296 —-a-w C:\WINDOWS\system32\MSWMDM.dll
+ 2006-10-19 02:47:16 321,536 —-a-w C:\WINDOWS\system32\mswmdm.dll
+ 2006-10-19 02:47:18 284,160 ——w C:\WINDOWS\system32\PortableDeviceApi.dll
+ 2006-10-19 02:47:18 101,888 ——w C:\WINDOWS\system32\PortableDeviceClassExtension.dll
+ 2006-10-19 02:47:18 166,912 ——w C:\WINDOWS\system32\PortableDeviceTypes.dll
+ 2006-10-19 02:47:18 132,096 ——w C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
+ 2006-10-19 02:47:18 199,168 ——w C:\WINDOWS\system32\PortableDeviceWMDRM.dll
- 2004-09-22 23:46:02 221,184 —-a-w C:\WINDOWS\system32\qasf.dll
+ 2006-10-19 02:47:18 211,456 —-a-w C:\WINDOWS\system32\qasf.dll
+ 2004-08-04 05:59:17 35,328 —-a-w C:\WINDOWS\system32\ReinstallBackups\0046\DriverFiles\i386\processr.sys
- 2006-12-10 19:10:02 14,640 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2006-09-25 22:58:48 14,640 ——w C:\WINDOWS\system32\spmsg.dll
- 2006-09-06 20:43:16 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-09-25 22:58:48 23,856 —-a-w C:\WINDOWS\system32\spupdsvc.exe
- 2004-09-22 23:46:10 47,104 -c–a-w C:\WINDOWS\system32\uwdf.exe
+ 2006-10-19 02:58:00 8,704 —-a-w C:\WINDOWS\system32\uwdf.exe
- 2004-09-22 23:46:10 15,872 -c–a-w C:\WINDOWS\system32\wdfapi.dll
+ 2006-10-19 02:47:18 4,096 —-a-w C:\WINDOWS\system32\wdfapi.dll
- 2004-09-22 23:46:10 38,912 —-a-w C:\WINDOWS\system32\wdfmgr.exe
+ 2006-10-19 02:58:00 8,704 —-a-w C:\WINDOWS\system32\wdfmgr.exe
- 2004-09-22 23:46:10 380,144 —-a-w C:\WINDOWS\system32\wmadmod.dll
+ 2006-10-19 02:47:18 757,248 —-a-w C:\WINDOWS\system32\WMADMOD.dll
- 2004-09-22 23:46:10 712,704 -c–a-w C:\WINDOWS\system32\wmadmoe.dll
+ 2006-10-19 02:47:18 1,117,696 —-a-w C:\WINDOWS\system32\WMADMOE.dll
- 2004-09-22 23:46:12 30,208 —-a-w C:\WINDOWS\system32\WMDMLOG.dll
+ 2006-10-19 02:47:18 33,792 —-a-w C:\WINDOWS\system32\wmdmlog.dll
- 2004-09-22 23:46:12 34,304 —-a-w C:\WINDOWS\system32\WMDMPS.dll
+ 2006-10-19 02:47:18 37,376 —-a-w C:\WINDOWS\system32\wmdmps.dll
- 2004-09-22 23:46:12 344,064 -c–a-w C:\WINDOWS\system32\WMDRMdev.dll
+ 2006-10-19 02:47:18 429,056 —-a-w C:\WINDOWS\system32\wmdrmdev.dll
- 2004-09-22 23:46:14 290,816 -c–a-w C:\WINDOWS\system32\WMDRMNet.dll
+ 2006-10-19 02:47:20 348,672 —-a-w C:\WINDOWS\system32\wmdrmnet.dll
+ 2006-10-19 02:47:20 535,040 ——w C:\WINDOWS\system32\wmdrmsdk.dll
- 2004-09-22 23:46:14 189,440 —-a-w C:\WINDOWS\system32\wmerror.dll
+ 2006-10-19 02:47:20 227,328 —-a-w C:\WINDOWS\system32\wmerror.dll
- 2004-09-22 23:46:14 150,016 -c–a-w C:\WINDOWS\system32\wmidx.dll
+ 2006-10-19 02:47:20 157,184 —-a-w C:\WINDOWS\system32\wmidx.dll
- 2004-09-22 23:46:16 1,027,072 —-a-w C:\WINDOWS\system32\wmnetmgr.dll
+ 2006-10-19 02:47:20 937,984 —-a-w C:\WINDOWS\system32\WMNetMgr.dll
- 2007-04-30 12:20:24 5,537,792 —-a-w C:\WINDOWS\system32\wmp.dll
+ 2007-06-12 04:51:12 10,834,944 —-a-w C:\WINDOWS\system32\wmp.dll
- 2004-09-22 23:46:20 135,168 —-a-w C:\WINDOWS\system32\wmpasf.dll
+ 2006-10-19 02:47:20 242,688 —-a-w C:\WINDOWS\system32\wmpasf.dll
- 2004-09-22 23:46:20 282,624 —-a-w C:\WINDOWS\system32\wmpdxm.dll
+ 2006-10-19 02:47:20 314,880 —-a-w C:\WINDOWS\system32\wmpdxm.dll
+ 2006-10-19 02:47:20 295,936 ——w C:\WINDOWS\system32\wmpeffects.dll
- 2004-09-22 23:46:20 1,589,760 -c–a-w C:\WINDOWS\system32\wmpencen.dll
+ 2006-10-19 02:47:20 1,661,440 —-a-w C:\WINDOWS\system32\wmpencen.dll
- 2004-09-22 23:46:22 3,371,008 —-a-w C:\WINDOWS\system32\wmploc.dll
+ 2006-10-19 02:47:20 8,231,936 —-a-w C:\WINDOWS\system32\wmploc.dll
+ 2006-10-19 02:47:20 613,376 ——w C:\WINDOWS\system32\wmpmde.dll
+ 2006-10-19 02:47:20 130,048 ——w C:\WINDOWS\system32\wmpps.dll
- 2004-09-22 23:46:24 86,016 —-a-w C:\WINDOWS\system32\wmpshell.dll
+ 2006-10-19 02:47:20 99,840 —-a-w C:\WINDOWS\system32\wmpshell.dll
- 2004-09-22 23:46:24 175,104 -c–a-w C:\WINDOWS\system32\wmpsrcwp.dll
+ 2006-10-19 02:47:20 204,288 —-a-w C:\WINDOWS\system32\wmpsrcwp.dll
- 2004-09-22 23:46:26 773,368 -c–a-w C:\WINDOWS\system32\wmsdmod.dll
+ 2006-10-19 02:47:22 4,096 —-a-w C:\WINDOWS\system32\wmsdmod.dll
- 2004-09-22 23:46:26 1,116,160 -c–a-w C:\WINDOWS\system32\wmsdmoe2.dll
+ 2006-10-19 02:47:22 4,096 —-a-w C:\WINDOWS\system32\wmsdmoe2.dll
- 2004-09-22 23:46:30 531,192 -c–a-w C:\WINDOWS\system32\wmspdmod.dll
+ 2006-10-19 02:47:22 603,648 —-a-w C:\WINDOWS\system32\WMSPDMOD.dll
- 2004-09-22 23:46:30 936,960 -c–a-w C:\WINDOWS\system32\wmspdmoe.dll
+ 2006-10-19 02:47:22 1,329,152 —-a-w C:\WINDOWS\system32\WMSPDMOE.dll
- 2004-09-22 23:46:32 1,181,944 -c–a-w C:\WINDOWS\system32\wmvadvd.dll
+ 2006-10-19 02:47:22 4,096 —-a-w C:\WINDOWS\system32\WMVADVD.dll
- 2004-09-22 23:46:32 1,509,376 -c–a-w C:\WINDOWS\system32\WMVADVE.DLL
+ 2006-10-19 02:47:22 4,096 —-a-w C:\WINDOWS\system32\WMVADVE.DLL
- 2006-12-07 06:40:49 2,362,184 —-a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-10-19 02:47:22 2,450,944 —-a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-10-19 02:47:22 1,543,680 ——w C:\WINDOWS\system32\WMVDECOD.dll
- 2004-09-22 23:46:34 871,160 —-a-w C:\WINDOWS\system32\wmvdmod.dll
+ 2006-10-19 02:47:22 4,096 —-a-w C:\WINDOWS\system32\wmvdmod.dll
- 2004-09-22 23:46:34 999,424 -c–a-w C:\WINDOWS\system32\wmvdmoe2.dll
+ 2006-10-19 02:47:22 4,096 —-a-w C:\WINDOWS\system32\wmvdmoe2.dll
+ 2006-10-19 02:47:22 1,574,912 ——w C:\WINDOWS\system32\WMVENCOD.dll
+ 2006-10-19 02:47:22 1,382,912 ——w C:\WINDOWS\system32\WMVSDECD.dll
+ 2006-10-19 02:47:22 767,488 ——w C:\WINDOWS\system32\WMVSENCD.dll
+ 2006-10-19 02:47:22 656,896 ——w C:\WINDOWS\system32\WMVXENCD.dll
- 2004-09-22 23:46:38 38,912 -c–a-w C:\WINDOWS\system32\wpd_ci.dll
+ 2006-10-19 02:47:22 629,760 —-a-w C:\WINDOWS\system32\wpd_ci.dll
- 2004-09-22 23:46:36 61,952 -c–a-w C:\WINDOWS\system32\wpdconns.dll
+ 2006-10-19 02:47:22 35,840 —-a-w C:\WINDOWS\system32\wpdconns.dll
- 2004-09-22 23:46:36 114,176 -c–a-w C:\WINDOWS\system32\wpdmtp.dll
+ 2006-10-19 02:47:22 154,624 —-a-w C:\WINDOWS\system32\wpdmtp.dll
- 2004-09-22 23:46:36 66,560 -c–a-w C:\WINDOWS\system32\wpdmtpus.dll
+ 2006-10-19 02:47:22 63,488 —-a-w C:\WINDOWS\system32\wpdmtpus.dll
+ 2006-10-19 02:47:22 2,603,008 ——w C:\WINDOWS\system32\WpdShext.dll
+ 2006-10-19 01:00:14 17,408 ——w C:\WINDOWS\system32\wpdshextautoplay.exe
+ 2006-10-19 02:47:22 38,400 ——w C:\WINDOWS\system32\wpdshextres.dll
+ 2006-10-19 02:47:22 133,632 ——w C:\WINDOWS\system32\WPDShServiceObj.dll
- 2004-09-22 23:46:36 327,680 -c–a-w C:\WINDOWS\system32\wpdsp.dll
+ 2006-10-19 02:47:22 356,352 —-a-w C:\WINDOWS\system32\wpdsp.dll
+ 2006-09-29 01:13:26 95,344 ——w C:\WINDOWS\system32\WUDFCoinstaller.dll
+ 2006-09-28 23:56:38 146,432 ——w C:\WINDOWS\system32\WudfHost.exe
+ 2006-09-28 23:56:16 165,376 ——w C:\WINDOWS\system32\WudfPlatform.dll
+ 2006-09-28 23:56:14 55,808 ——w C:\WINDOWS\system32\WudfSvc.dll
+ 2006-09-28 23:56:38 316,416 ——w C:\WINDOWS\system32\WUDFx.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2007-12-30 21:27 131072]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2008-01-01 23:16 81920]
"Logitech Hardware Abstraction Layer"="C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2008-01-01 23:16 94208]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 11:03 94208 C:\WINDOWS\KHALMNPR.Exe]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2008-01-01 23:16 57344]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"Launch LCDMon"="C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe" [2008-01-01 23:16 774168]
"Launch LGDCore"="C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" [2008-01-01 23:16 1132056]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-10-10 15:52:44]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]
C:\Program Files\Radeon Omega Drivers\v3.8.291\ATI Tray Tools\atitray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-03-04 03:36 36975 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

R1 AmdPPM;AMD HwPState Processor Driver;C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 21:46]
R1 XPROTECTOR;XPROTECTOR;C:\WINDOWS\system32\drivers\Oreans.sys [2005-07-23 17:26]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-09-01 11:32]
R2 TabletServicePen;TabletServicePen;C:\WINDOWS\system32\Pen_Tablet.exe [2007-09-07 10:16]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 10:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 09:30]
R3 WacomVKHid;Virtual Keyboard Driver;C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-15 15:11]
S1 atitray;atitray;C:\Program Files\Radeon Omega Drivers\v3.8.291\ATI Tray Tools\atitray.sys []

.
Contents of the 'Scheduled Tasks' folder
"2006-05-06 02:06:20 C:\WINDOWS\Tasks\dfrg.job"
- C:\WINDOWS\system32\dfrg.msc
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-18 12:15:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-18 12:16:30
ComboFix-quarantined-files.txt 2008-01-18 17:15:51
ComboFix2.txt 2008-01-12 02:54:40
ComboFix3.txt 2008-01-02 16:11:18
.
2008-01-15 17:27:32 — E O F —



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:27:11 PM, on 1/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ytmnd.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab55200.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe (file missing)
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Unknown owner - C:\WINDOWS\system32\sfrem01.exe (file missing)
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

–
End of file - 7734 bytes



AC3Filter (remove only)
Ad-Aware SE Personal
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player ActiveX
Adobe Photoshop CS
Adobe Reader 7.0
Adobe Shockwave Player
AOL Instant Messenger
Apple Software Update
ATI DVD Decoder 2.2.0.0
BitLord 1.1
BitTorrent 3.4.2
Client Fix 1.9.2
Comcast High-Speed Internet Install Wizard
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
EAX4 Unified Redist
EncVorbis 1.1
EndItAll 2.0
Fraps (remove only)
GameShadow
Garry's Mod 4a
Google Earth
Guild Wars
Half-Life SDK v2.3
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
J2SE Runtime Environment 5.0 Update 2
KhalSetup
Lexmark X1100 Series
Lineage II
Logitech G15 Keyboard Software 1.04
Logitech SetPoint
LucasArts' Jedi Knight
Macromedia Flash Player
Manhunt
Max Payne 2
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Halo
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual Basic .NET Standard 2003 - English
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 6.0 Docs
Microsoft Visual C++ 6.0 Introductory Edition
Microsoft XML Parser and SDK
mIRC
MSN Music Assistant
MSN Toolbar
MSXML 4.0
MSXML 4.0
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
NVIDIA Drivers
NvMixer
Opera 9.10
PCPitstop Panda AntiVirus Scan (remove only)
Peggle Extreme
Pen Tablet
People Shooter 1.01
Pivot Stickfigure Animator
Porrasturvat - Stair Dismount (remove only)
QuickTime
RealPlayer Basic
Realtek AC'97 Audio
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Sony Media Manager 2.2
Sony Vegas 7.0
Star Wars Jedi Knight Jedi Academy
Starcraft
Steam
StepMania (remove only)
Team Fortress 2
TeamSpeak 2 RC2
TES Construction Set
TrackMania Nations ESWC 1.7.9
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Ventrilo Client
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
Xfire (remove only)
Yahoo! Messenger
Your ComboFix and HJT logs look clean. :thumbup:

You have BitLord installed, it contains advertisements and since you already have Bit Torrent and it does the same thing, I recommend you uninstall it. For more information please go to this Wikipedia aritcle. If you want to do so please follow these instructions

Click on the Windows Start button in the left hand corner of your screen.
Go to Control Panel or Settings>Control Panel
Double click on Add or Remove Programs and uninstall
BitLord

You aren't running an antivirus program, this is an essential program when using the Internet and not having one is very dangerous for computer security. I highly recommend you install one. Here are some free versions of commercial programs:
Free AVG
Avast 4 Home Edition

Windows Firewall is not very adequate as it only blocks incoming connections and not outgoing, while this is better than nothing, a 3rd party firewall will block both and increase your security. Therefore I highly recommend you install one of the following free versions of commercial products.
FREE Comodo Firewall Pro
Outpost Free Firewall
Once either of these programs are installed Windows Firewall will automatically turn itself off.

The infection you had caused the unrecoverable corruption of a file that is needed to play games using Starforce protection. If you still play any game using this protection I highly recommend you backup any save games, settings, etc and then uninstall and reinstall the game. It will replace the file, please note you only need to do this with one game using Starforce protection.

Please let me know how the installations of the antivirus and firewall products went.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI