This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HIJACKTHISLOG PLZ HELP! COOLSEARCH oh no

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:29:00 PM, on 6/21/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\leenbrooke\Desktop\VundoFix.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\iftuyszv.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DT HPW] "C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe" -HPW
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [aecb1da8] "rundll32.exe" "C:\Windows\system32\ljnsqjtr.dll",b
O4 - HKLM\..\Run: [MSServer] "rundll32.exe" C:\Windows\system32\iifebArq.dll,#1
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [HPAdvisor] "C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [Host Process] C:\Users\leenbrooke\svchost.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2…15035/CTPID.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® Viiv™ Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\Windows\444.470.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 11480 bytes




COOLwww SEARCH Will not go away ….my task manager is gone….tried everything…..some apps on pc load strange .and stop all together….
Hello

Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
Are you sure i should download the recovery for XP and not VISTA i have vista….i managed to get my tast manger back and quarentened coolsearch but i have smithfraud and a few others..im sure coolsearch is still there…….my pc is not running quite right tho my game is taking along time to log onto the server also im getting alot of hourglass for nothing ……does vista have a recovery i can download???
ComboFix 08-06-20.4 - leenbrooke 2008-06-22 18:49:50.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1331 [GMT -4:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\Windows\astctl32.ocx
C:\Windows\cpan.dll
C:\Windows\ctfmon32.exe
C:\Windows\directx32.exe
C:\Windows\dnsrelay.dll
C:\Windows\editpad.exe
C:\Windows\explorer32.exe
C:\Windows\funniest.exe
C:\Windows\funny.exe
C:\Windows\gfmnaaa.dll
C:\Windows\helpcvs.exe
C:\Windows\inetinf.exe
C:\Windows\internet.exe
C:\Windows\mainms.vpi
C:\Windows\megavid.cdt
C:\Windows\msconfd.dll
C:\Windows\msspi.dll
C:\Windows\mswsc10.dll
C:\Windows\mswsc20.dll
C:\Windows\muotr.so
C:\Windows\qttasks.exe
C:\Windows\quicken.exe
C:\Windows\rundll16.exe
C:\Windows\rundll32.vbe
C:\Windows\searchword.dll
C:\Windows\svchost32.exe
C:\Windows\svcinit.exe
C:\Windows\System32\AKlRBJlm.ini
C:\Windows\System32\AKlRBJlm.ini2
C:\Windows\system32\drivers\core.cache(138).dsk
C:\Windows\System32\gMpWFfhk.ini
C:\Windows\System32\gMpWFfhk.ini2
C:\Windows\system32\hljwugsf.bin
C:\Windows\system32\klUEOqss.ini
C:\Windows\System32\klUEOqss.ini2
C:\Windows\system32\MSINET.oca
C:\Windows\system32\pac.txt
C:\Windows\system32\rtjqsnjl.ini
C:\Windows\time.exe
C:\Windows\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MsSecurity1.209.4


((((((((((((((((((((((((( Files Created from 2008-05-22 to 2008-06-22 )))))))))))))))))))))))))))))))
.

2008-06-22 18:54 . 2008-06-22 18:54 d——– C:\TEMP\tn3
2008-06-21 22:11 . 2008-06-21 22:11 d——– C:\VundoFix Backups
2008-06-21 17:41 . 2008-06-21 23:49 d——– C:\ProgramData\SecTaskMan
2008-06-21 15:53 . 2008-06-21 15:56 d——– C:\ProgramData\Lavasoft
2008-06-21 15:53 . 2008-06-21 15:53 d——– C:\Program Files\Lavasoft
2008-06-21 15:31 . 2008-06-21 15:31 167,976 ——— C:\Windows\System32\drivers\core.cache.dsk
2008-06-21 13:37 . 2008-06-21 13:37 d——– C:\Users\leenbrooke\AppData\Roaming\TrojanHunter
2008-06-21 13:24 . 2008-06-21 23:49 d——– C:\Program Files\TrojanHunter 5.0
2008-06-21 12:17 . 2008-06-21 12:17 130,560 –a—— C:\Windows\System32\mktxyohb.dll
2008-06-21 12:12 . 2008-06-21 12:12 128,512 –a—— C:\Windows\System32\bqoauodn.dll
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\Users\leenbrooke\AppData\Roaming\Webroot
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\ProgramData\Webroot
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\Program Files\Webroot
2008-06-21 12:03 . 2008-01-04 20:56 1,526,640 –a—— C:\Windows\WRSetup.dll
2008-06-21 12:03 . 2008-01-04 20:34 163,696 –a—— C:\Windows\System32\drivers\ssidrv.sys
2008-06-21 12:03 . 2008-01-04 20:34 23,920 –a—— C:\Windows\System32\drivers\sskbfd.sys
2008-06-21 12:03 . 2008-01-04 20:34 21,872 –a—— C:\Windows\System32\drivers\sshrmd.sys
2008-06-21 12:03 . 2008-01-04 20:34 20,336 –a—— C:\Windows\System32\drivers\SSFS0BB9.sys
2008-06-21 10:55 . 2008-06-21 10:55 130,560 –a—— C:\Windows\System32\mqpabfea.dll
2008-06-21 10:53 . 2008-06-21 10:53 128,512 –a—— C:\Windows\System32\rpxcxvsi.dll
2008-06-21 10:43 . 2008-06-22 18:43 339 –a—— C:\Windows\wininit.ini
2008-06-21 09:48 . 2008-06-21 09:48 128,512 –a—— C:\Windows\System32\fxolrdtw.dll
2008-06-20 15:51 . 2008-06-20 15:51 d——– C:\Program Files\Trend Micro
2008-06-20 13:39 . 2008-06-20 13:39 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-06-20 13:38 . 2008-06-20 13:38 d——– C:\Users\leenbrooke\AppData\Roaming\SUPERAntiSpyware.com
2008-06-20 13:38 . 2008-06-20 13:38 d——– C:\Program Files\SUPERAntiSpyware
2008-06-19 16:22 . 2008-06-19 16:23 d——– C:\Program Files\Common Files\BitDefender
2008-06-19 16:03 . 2008-06-21 10:20 d——– C:\ProgramData\Spybot - Search & Destroy
2008-06-19 16:03 . 2008-06-21 10:18 d——– C:\Program Files\Spybot - Search & Destroy
2008-06-19 15:58 . 2008-06-19 18:26 d-a—— C:\ProgramData\TEMP
2008-06-19 14:55 . 2008-06-19 14:55 d——– C:\ProgramData\McAfee
2008-06-19 14:49 . 2008-06-19 14:49 1,879,040 –a—— C:\Users\leenbrooke\winlogon.exe
2008-06-19 14:49 . 2008-06-19 14:49 554 –a—— C:\Users\leenbrooke\748.bat
2008-06-19 14:46 . 2008-06-21 12:31 d–hs—- C:\Windows\bGVlbmJyb29rZQ
2008-06-19 14:44 . 2008-06-19 14:44 d——– C:\Windows\System32\netrax05
2008-06-19 14:44 . 2008-06-21 09:36 d——– C:\Windows\System32\eb10
2008-06-19 14:44 . 2008-06-22 00:07 d——– C:\Windows\System32\bgi
2008-06-19 14:44 . 2008-06-22 00:07 d——– C:\Windows\System32\axc
2008-06-19 14:44 . 2008-06-21 12:31 d——– C:\Windows\System32\1049a
2008-06-19 14:44 . 2008-06-19 14:44 d——– C:\TEMP\itmp4
2008-06-19 14:44 . 2008-06-19 14:44 86,144 –a—— C:\Windows\System32\drivers\irenumm.sys
2008-06-07 22:16 . 2008-06-07 22:16 32,768 –a—— C:\Windows\System32\netrax05\netrax051080.exe
2008-05-31 11:48 . 2008-05-31 11:48 0 –ah—– C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-05-30 15:12 . 2008-03-07 22:08 4,240,384 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-30 15:12 . 2008-03-08 00:21 1,695,744 –a—— C:\Windows\System32\gameux.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-22 17:12 ——— d—–w C:\Program Files\Steam
2008-06-21 19:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 13:36 ——— d—–w C:\Program Files\Norton Internet Security
2008-06-19 19:27 ——— d—–w C:\Users\leenbrooke\AppData\Roaming\LimeWire
2008-06-13 17:35 ——— d—–w C:\Program Files\Common Files\Steam
2008-06-07 05:35 ——— d—–w C:\Program Files\PokerStars.NET
2008-06-07 00:59 ——— d—–w C:\ProgramData\NVIDIA
2008-06-01 23:26 ——— d—–w C:\Program Files\HP
2008-05-27 01:54 22,328 —-a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-05-27 01:54 103,736 —-a-w C:\Windows\System32\PnkBstrB.exe
2008-05-26 23:32 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-20 17:51 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-05-16 15:58 12,632 —-a-w C:\Windows\System32\lsdelete.exe
2008-05-16 01:10 ——— d—–w C:\ProgramData\Creative
2008-05-13 17:59 409,600 —-a-w C:\Windows\System32\wrap_oal.dll
2008-05-13 17:59 114,688 —-a-w C:\Windows\System32\OpenAL32.dll
2008-05-13 17:52 ——— d—–w C:\ProgramData\Microsoft Help
2008-05-13 17:52 ——— d—–w C:\Program Files\Windows Mail
2008-05-06 15:04 ——— d—–w C:\Program Files\Java
2008-05-05 01:31 ——— d—–w C:\Users\leenbrooke\AppData\Roaming\SystemRequirementsLab
2008-05-05 01:31 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-05-03 02:46 795,104 —-a-w C:\Windows\System32\dpinst.exe
2008-05-03 02:46 768,544 —-a-w C:\Windows\System32\nvcplui.exe
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcodhins.dll
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcodh.dll
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcod130.dll
2008-05-03 02:46 313,888 —-a-w C:\Windows\System32\nvexpbar.dll
2008-05-03 02:46 118,784 —-a-w C:\Windows\System32\nvvsvc.exe
2008-04-30 21:27 442,368 —-a-w C:\Windows\System32\nvuninst.exe
2008-04-29 15:20 15,648 —-a-w C:\Windows\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 —-a-w C:\Windows\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 —-a-w C:\Windows\system32\drivers\Awrtpd.sys
2008-03-22 03:14 319,456 —-a-w C:\Windows\DIFxAPI.dll
2008-03-21 00:30 174 –sha-w C:\Program Files\desktop.ini
2007-10-13 01:06 22,328 —-a-w C:\Users\leenbrooke\AppData\Roaming\PnkBstrK.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-12 20:44 1773568]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 03:33 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 03:33 202240]
"Host Process"="C:\Users\leenbrooke\svchost.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 09:42 65536]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 19:36 178712]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 18:22 184320]
"SPIRunE"="SPIRunE.dll" [2007-05-09 05:07 18432 C:\Windows\System32\SpiRunE.dll]
"CCUTRAYICON"="FactoryMode" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"DT HPW"="C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2007-09-28 15:52 81920]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 06:59 118784]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 09:56 236016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-11 17:06 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-11 17:06 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-11 17:06 81920]
"aecb1da8"="C:\Windows\system32\ljnsqjtr.dll" [ ]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-06-21 15:55 2468200]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 20:56 5367664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="C:\Windows\SMINST\launcher.exe" [2007-03-07 14:09 44168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{4E06327D-0415-475F-898B-6ACFB316073E}"= C:\Windows\system32\iifebArq.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0B1590FC-B3A1-474D-813C-665716ADE513}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{65B84EE2-BD44-455B-9709-5B7ED0FBCDE2}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{FBE2BE16-21D7-494C-92D6-785333D212BD}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{4CD6B41D-DE30-45B3-BA4D-7F6869901BA2}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{24D94B5D-4AE1-43BC-881A-B134621FD15E}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{633B92B8-18EC-4D76-B927-1DE7A7715DAB}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{4C5BDB23-DE52-464F-870F-F9DE80C88082}"= TCP:9442:127.0.0.1:Intel® Viiv™ Media Server Discovery
"{1BEC42A8-8BB3-4012-9DEC-7A626F906150}"= TCP:1900:LocalSubnet:LocalSubnet:Intel® Viiv™ Media Server UPnP Discovery
"{B6B9630C-964B-432B-BC68-79587F01A73B}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9BEED121-2A98-4FBE-A7F9-C849A490DC14}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B226F91-4C4A-4491-AE42-87FA392F602B}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BE450CF8-F510-4C9C-9616-F7DC3FACCC2F}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{365B7FAB-8542-4836-ABBF-4846E04F2A70}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6BA9AC15-F85F-4912-A603-6B6CB349DE80}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A9F0B794-7AED-4C9C-9CFF-AD190772B89D}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{67AB14DF-E68C-499A-939E-DAC67E220DCE}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D5E4F9FF-A123-437C-8566-83A21A91FA6B}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5CB913E1-9B75-4ABC-93A6-CDF90A7EF8C6}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{6E1549F4-97A3-4C3E-BF19-CFB0FD1E4585}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FE094B77-EF29-4E64-BDC8-C22FFEB1A1C9}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0DF25708-FEC2-4EE7-ABE2-D2C307852F2C}"= UDP:C:\Program Files\Steam\Steam.exe:Steam Client
"{46C00868-AAA9-4C34-A3B2-2CACFDC2DB77}"= TCP:C:\Program Files\Steam\Steam.exe:Steam Client
"{86AD77FC-1E93-481F-A1AD-0212309E7BF8}"= UDP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{824E2870-F4FC-4E3B-B1CC-BF330C6058EF}"= TCP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{5AC03833-D8B1-4E33-B0DC-A81AF50E56C8}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{85A7C75D-291B-4BD2-9A64-570D1912AB76}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{31C3BEC3-E271-4084-BB68-ED62570A99A1}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{BA12A1BC-F222-4CDF-B20B-1BBC7F0B8B94}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{37DE7D8B-0714-4278-BF35-5F50DCDD71FE}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{79A5C645-431B-4525-A27B-8A1EE5098DAC}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{532E2A4B-09F2-43D4-BF9F-54BC4EF92587}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"UDP Query User{CF1D7F7F-8BA0-443E-BC70-CBBCB049BD5A}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"{284B6EB5-C392-4BD2-ABC9-07B9E59EE40C}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{431398BF-9A2F-44CB-9C44-EA245D6A47AB}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"TCP Query User{3C15B82E-FF8F-4736-841B-0B50EA77B5C2}C:\\program files\\roxio\\media manager 9\\mediamanager9.exe"= UDP:C:\program files\roxio\media manager 9\mediamanager9.exe:MediaManager9 Module
"UDP Query User{5C412AC8-6BCF-406D-9009-332FEE3A3D66}C:\\program files\\roxio\\media manager 9\\mediamanager9.exe"= TCP:C:\program files\roxio\media manager 9\mediamanager9.exe:MediaManager9 Module
"{4E2D1FA3-0745-4C56-991C-551CE76DA848}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{1CA18CA3-57F3-4294-9DEF-81E48306BFB9}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{722B19E6-B291-407E-856E-C5EC9854CC6C}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{057A55ED-8CB1-4630-85D9-013B0BFA9F4D}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{2EEABA05-B99D-4963-899F-E5FBF2271158}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{0DCEB5D1-8616-45B5-8943-6127F222B9C0}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"TCP Query User{269BADEC-EC66-490B-8795-3147B59DC1A6}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"UDP Query User{37F4494B-C095-40CD-B0F2-AF237F4D017A}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"TCP Query User{C752B154-483E-4F1B-A9D2-B1F574267C24}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{2A3B3F10-DE55-4B2F-A8A7-9BED4E3E06DB}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{914F9EFA-916E-4A77-BACB-B465201C1E72}C:\\program files\\aim\\aim pro\\aimpro.exe"= UDP:C:\program files\aim\aim pro\aimpro.exe:AIM Pro
"UDP Query User{064B5D90-048E-4095-821A-304800802BB7}C:\\program files\\aim\\aim pro\\aimpro.exe"= TCP:C:\program files\aim\aim pro\aimpro.exe:AIM Pro
"{DC5FA85B-7AC3-4E8E-8D34-D8072F7FBAC0}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D7098655-C16A-4134-8DA6-3DCC5A5EF500}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C9844078-0FE4-4E72-9D65-2F015A1A4E72}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AB18838B-051B-4FBF-BFD3-F643F1805553}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{75329D7B-B5C8-4BDD-A036-551D13341274}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{756E719B-29FF-48D7-A281-F1F3CAEDCBC4}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{5FA02C3D-AACA-4481-8880-184B11A8C249}"= Disabled:UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{5944F2CE-5489-4E73-B1C2-CB571137F5B8}"= Disabled:TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"TCP Query User{6E2B55FB-CCC7-4B59-B5EB-633806659D99}C:\\program files\\mozilla firefox\\firefox.exe"= Disabled:UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{6E33F0D4-0408-47CD-8F4C-7286431DA609}C:\\program files\\mozilla firefox\\firefox.exe"= Disabled:TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{D91FA5EE-0215-405D-B06F-54F81E487CB7}"= Disabled:UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{DF40EBF9-88A7-46C5-9D48-21296AAE6042}"= Disabled:TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R2 CTAudSvcService;Creative Audio Service;C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2007-11-26 09:22]
R2 DQLWinService;DQLWinService;"C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe" [2006-09-03 13:32]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys [2007-06-11 13:49]
R3 t3;Sound Blaster X-Fi Xtreme Audio (Vista);C:\Windows\system32\drivers\t3.sys [2008-01-29 03:03]
S2 IntelDHSvcConf;Intel DH Service;"C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe" [2006-05-10 12:13]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;"C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe" [2008-01-06 22:08]
S3 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20070108.003\IDSvix86.sys [2006-12-27 18:48]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-06-11 21:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2795ffd3-5c24-11dc-a37c-806e6f6e6963}]
\shell\AutoRun\command - E:\install.exe

*Newly Created Service* - COMHOST
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-22 18:54:23
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Windows\System32\nvvsvc.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\PnkBstrA.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehrecvr.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-06-22 18:58:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-22 22:58:11

Pre-Run: 168,247,492,608 bytes free
Post-Run: 168,555,745,280 bytes free

302 — E O F — 2008-05-30 19:13:03
Ran spybot and didnt find coolsearch just smithfraud but coolsearc is quarenteened in spysweeper if i delte from there it comes back so im nervous to delte it again….also im getting system 32\linjnsqiter.ll a different from a day ago i am getting random popups from IE THANK YOU FOR THE HELP
Hello

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.whatthetech.com/HIJACKTHISLO…_no_t92961.html

Collect::
C:\Windows\System32\drivers\irenumm.sys

KillAll::

Suspect::

File::
C:\Windows\system32\drivers\core.cache.dsk
C:\Windows\System32\mktxyohb.dll
C:\Windows\System32\bqoauodn.dll
C:\Windows\System32\mqpabfea.dll
C:\Windows\System32\rpxcxvsi.dll
C:\Windows\System32\fxolrdtw.dll
C:\Users\leenbrooke\winlogon.exe
C:\Users\leenbrooke\748.bat
E:\install.exe

Folder::
C:\TEMP\tn3
C:\Windows\bGVlbmJyb29rZQ
C:\Windows\System32\netrax05
C:\Windows\System32\eb10
C:\Windows\System32\bgi
C:\Windows\System32\axc
C:\Windows\System32\1049a
C:\TEMP\itmp4
C:\Windows\System32\netrax05

Driver::

Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{4E06327D-0415-475F-898B-6ACFB316073E}"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2795ffd3-5c24-11dc-a37c-806e6f6e6963}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished running, it will generate the ComboFix.log which will appear on your screen.

8. If CF-Submit.htm is detected, ComboFix will generate this message box:

[external image: Posted Image]

Clicking OK will cause the machine's browser to load CF-Submit.htm

[external image: Posted Image]

9. Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, please DELETE both files on your desktop.

11. Post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log (run after ComboFix has finished its work.)
OK first before i have done any of this i have scanned my pc and no program finds coolsearch but spybot finds smithfraud c-core services..also on spysweeper its telling me i have a trogen.gen. thats all but still pc is acting a little strange and im missing a dll file…anyways i did the cfscript and it ran in combo fix but NEVER could find submitdateand time zip it just scanned..so heres the logs……………….ComboFix 08-06-20.4 - leenbrooke 2008-06-23 13:50:51.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1293 [GMT -4:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\leenbrooke\Desktop\CFScript.lnk
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\tn3

.
((((((((((((((((((((((((( Files Created from 2008-05-23 to 2008-06-23 )))))))))))))))))))))))))))))))
.

2008-06-21 22:11 . 2008-06-21 22:11 d——– C:\VundoFix Backups
2008-06-21 17:41 . 2008-06-21 23:49 d——– C:\ProgramData\SecTaskMan
2008-06-21 15:53 . 2008-06-21 15:56 d——– C:\ProgramData\Lavasoft
2008-06-21 15:53 . 2008-06-21 15:53 d——– C:\Program Files\Lavasoft
2008-06-21 13:37 . 2008-06-21 13:37 d——– C:\Users\leenbrooke\AppData\Roaming\TrojanHunter
2008-06-21 13:24 . 2008-06-21 23:49 d——– C:\Program Files\TrojanHunter 5.0
2008-06-21 12:17 . 2008-06-21 12:17 130,560 –a—— C:\Windows\System32\mktxyohb.dll
2008-06-21 12:12 . 2008-06-21 12:12 128,512 –a—— C:\Windows\System32\bqoauodn.dll
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\Users\leenbrooke\AppData\Roaming\Webroot
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\ProgramData\Webroot
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\Program Files\Webroot
2008-06-21 12:03 . 2008-01-04 20:56 1,526,640 –a—— C:\Windows\WRSetup.dll
2008-06-21 12:03 . 2008-01-04 20:34 163,696 –a—— C:\Windows\System32\drivers\ssidrv.sys
2008-06-21 12:03 . 2008-01-04 20:34 23,920 –a—— C:\Windows\System32\drivers\sskbfd.sys
2008-06-21 12:03 . 2008-01-04 20:34 21,872 –a—— C:\Windows\System32\drivers\sshrmd.sys
2008-06-21 12:03 . 2008-01-04 20:34 20,336 –a—— C:\Windows\System32\drivers\SSFS0BB9.sys
2008-06-21 10:55 . 2008-06-21 10:55 130,560 –a—— C:\Windows\System32\mqpabfea.dll
2008-06-21 10:53 . 2008-06-21 10:53 128,512 –a—— C:\Windows\System32\rpxcxvsi.dll
2008-06-21 10:43 . 2008-06-22 20:19 403 –a—— C:\Windows\wininit.ini
2008-06-21 09:48 . 2008-06-21 09:48 128,512 –a—— C:\Windows\System32\fxolrdtw.dll
2008-06-20 15:51 . 2008-06-20 15:51 d——– C:\Program Files\Trend Micro
2008-06-20 13:39 . 2008-06-20 13:39 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-06-20 13:38 . 2008-06-20 13:38 d——– C:\Users\leenbrooke\AppData\Roaming\SUPERAntiSpyware.com
2008-06-20 13:38 . 2008-06-20 13:38 d——– C:\Program Files\SUPERAntiSpyware
2008-06-19 16:22 . 2008-06-19 16:23 d——– C:\Program Files\Common Files\BitDefender
2008-06-19 16:03 . 2008-06-21 10:20 d——– C:\ProgramData\Spybot - Search & Destroy
2008-06-19 16:03 . 2008-06-21 10:18 d——– C:\Program Files\Spybot - Search & Destroy
2008-06-19 15:58 . 2008-06-19 18:26 d-a—— C:\ProgramData\TEMP
2008-06-19 14:55 . 2008-06-19 14:55 d——– C:\ProgramData\McAfee
2008-06-19 14:49 . 2008-06-19 14:49 1,879,040 –a—— C:\Users\leenbrooke\winlogon.exe
2008-06-19 14:49 . 2008-06-19 14:49 554 –a—— C:\Users\leenbrooke\748.bat
2008-06-19 14:46 . 2008-06-21 12:31 d–hs—- C:\Windows\bGVlbmJyb29rZQ
2008-06-19 14:44 . 2008-06-22 19:52 d——– C:\Windows\System32\netrax05
2008-06-19 14:44 . 2008-06-22 19:52 d——– C:\Windows\System32\eb10
2008-06-19 14:44 . 2008-06-22 00:07 d——– C:\Windows\System32\bgi
2008-06-19 14:44 . 2008-06-22 00:07 d——– C:\Windows\System32\axc
2008-06-19 14:44 . 2008-06-21 12:31 d——– C:\Windows\System32\1049a
2008-06-19 14:44 . 2008-06-19 14:44 d——– C:\TEMP\itmp4
2008-05-31 11:48 . 2008-05-31 11:48 0 –ah—– C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-05-30 15:12 . 2008-03-07 22:08 4,240,384 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-30 15:12 . 2008-03-08 00:21 1,695,744 –a—— C:\Windows\System32\gameux.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-23 03:26 ——— d—–w C:\Program Files\Steam
2008-06-23 00:02 ——— d—–w C:\Program Files\Windows Mail
2008-06-21 19:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 13:36 ——— d—–w C:\Program Files\Norton Internet Security
2008-06-19 19:27 ——— d—–w C:\Users\leenbrooke\AppData\Roaming\LimeWire
2008-06-13 17:35 ——— d—–w C:\Program Files\Common Files\Steam
2008-06-07 05:35 ——— d—–w C:\Program Files\PokerStars.NET
2008-06-07 00:59 ——— d—–w C:\ProgramData\NVIDIA
2008-06-01 23:26 ——— d—–w C:\Program Files\HP
2008-05-27 01:54 22,328 —-a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-05-27 01:54 103,736 —-a-w C:\Windows\System32\PnkBstrB.exe
2008-05-26 23:32 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-20 17:51 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-05-16 15:58 12,632 —-a-w C:\Windows\System32\lsdelete.exe
2008-05-16 01:10 ——— d—–w C:\ProgramData\Creative
2008-05-13 17:59 409,600 —-a-w C:\Windows\System32\wrap_oal.dll
2008-05-13 17:59 114,688 —-a-w C:\Windows\System32\OpenAL32.dll
2008-05-13 17:52 ——— d—–w C:\ProgramData\Microsoft Help
2008-05-10 01:33 113,664 —-a-w C:\Windows\system32\drivers\rmcast.sys
2008-05-06 15:04 ——— d—–w C:\Program Files\Java
2008-05-05 01:31 ——— d—–w C:\Users\leenbrooke\AppData\Roaming\SystemRequirementsLab
2008-05-05 01:31 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-05-03 02:46 795,104 —-a-w C:\Windows\System32\dpinst.exe
2008-05-03 02:46 768,544 —-a-w C:\Windows\System32\nvcplui.exe
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcodhins.dll
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcodh.dll
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcod130.dll
2008-05-03 02:46 313,888 —-a-w C:\Windows\System32\nvexpbar.dll
2008-05-03 02:46 118,784 —-a-w C:\Windows\System32\nvvsvc.exe
2008-04-30 21:27 442,368 —-a-w C:\Windows\System32\nvuninst.exe
2008-04-29 15:20 15,648 —-a-w C:\Windows\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 —-a-w C:\Windows\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 —-a-w C:\Windows\system32\drivers\Awrtpd.sys
2008-04-26 08:08 1,314,816 —-a-w C:\Windows\System32\quartz.dll
2008-04-25 04:35 826,880 —-a-w C:\Windows\System32\wininet.dll
2008-04-23 04:42 428,544 —-a-w C:\Windows\System32\EncDec.dll
2008-04-23 04:42 293,376 —-a-w C:\Windows\System32\psisdecd.dll
2008-03-21 00:30 174 –sha-w C:\Program Files\desktop.ini
2007-10-13 01:06 22,328 —-a-w C:\Users\leenbrooke\AppData\Roaming\PnkBstrK.sys
.

((((((((((((((((((((((((((((( snapshot@2008-06-22_18.57.48.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-19 07:38:31 140,288 —-a-w C:\Windows\assembly\GAC_32\mcupdate\6.0.6000.0__31bf3856ad364e35\mcupdate.exe
+ 2008-04-23 04:44:47 140,288 —-a-w C:\Windows\assembly\GAC_32\mcupdate\6.0.6000.0__31bf3856ad364e35\mcupdate.exe
- 2008-01-19 07:38:21 4,046,848 —-a-w C:\Windows\assembly\GAC_MSIL\ehshell\6.0.6000.0__31bf3856ad364e35\ehshell.dll
+ 2008-04-23 04:44:14 4,046,848 —-a-w C:\Windows\assembly\GAC_MSIL\ehshell\6.0.6000.0__31bf3856ad364e35\ehshell.dll
- 2008-01-19 07:38:36 1,957,888 —-a-w C:\Windows\assembly\GAC_MSIL\Microsoft.MediaCenter.UI\6.0.6000.0__31bf3856ad364e35\Microsoft.MediaCenter.UI.dll
+ 2008-04-23 04:45:00 1,957,888 —-a-w C:\Windows\assembly\GAC_MSIL\Microsoft.MediaCenter.UI\6.0.6000.0__31bf3856ad364e35\Microsoft.MediaCenter.UI.dll
- 2008-06-22 22:54:10 67,584 –s-a-w C:\Windows\bootstat.dat
+ 2008-06-23 17:28:16 67,584 –s-a-w C:\Windows\bootstat.dat
- 2008-01-19 07:34:08 373,248 —-a-w C:\Windows\ehome\ehglid.dll
+ 2008-04-23 04:42:33 373,248 —-a-w C:\Windows\ehome\ehglid.dll
- 2008-01-19 07:34:08 103,936 —-a-w C:\Windows\ehome\ehPresenter.dll
+ 2008-04-23 04:42:33 105,472 —-a-w C:\Windows\ehome\ehPresenter.dll
- 2008-01-19 07:34:08 254,464 —-a-w C:\Windows\ehome\ehReplay.dll
+ 2008-04-23 04:42:33 254,464 —-a-w C:\Windows\ehome\ehReplay.dll
- 2008-01-19 07:38:21 4,046,848 —-a-w C:\Windows\ehome\ehshell.dll
+ 2008-04-23 04:44:14 4,046,848 —-a-w C:\Windows\ehome\ehshell.dll
- 2008-02-14 02:07:21 18,944 —-a-w C:\Windows\ehome\ehtrace.dll
+ 2008-04-23 04:27:00 18,944 —-a-w C:\Windows\ehome\ehtrace.dll
- 2008-01-19 07:34:09 522,240 —-a-w C:\Windows\ehome\ehui.dll
+ 2008-04-23 04:42:33 522,240 —-a-w C:\Windows\ehome\ehui.dll
- 2008-01-19 07:38:31 140,288 —-a-w C:\Windows\ehome\mcupdate.exe
+ 2008-04-23 04:44:47 140,288 —-a-w C:\Windows\ehome\mcupdate.exe
- 2008-01-19 07:38:36 1,957,888 —-a-w C:\Windows\ehome\Microsoft.MediaCenter.UI.dll
+ 2008-04-23 04:45:00 1,957,888 —-a-w C:\Windows\ehome\Microsoft.MediaCenter.UI.dll
- 2008-04-09 03:14:35 665,600 —-a-w C:\Windows\inf\drvindex.dat
+ 2008-06-23 00:02:50 665,600 —-a-w C:\Windows\inf\drvindex.dat
- 2008-06-07 00:56:48 51,200 —-a-w C:\Windows\inf\infpub.dat
+ 2008-06-23 00:02:50 51,200 —-a-w C:\Windows\inf\infpub.dat
- 2008-05-16 15:32:23 86,016 —-a-w C:\Windows\inf\infstor.dat
+ 2008-06-23 00:02:50 86,016 —-a-w C:\Windows\inf\infstor.dat
- 2008-06-07 00:56:48 143,360 —-a-w C:\Windows\inf\infstrng.dat
+ 2008-06-23 00:02:50 143,360 —-a-w C:\Windows\inf\infstrng.dat
+ 2008-06-23 17:28:16 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-06-23 17:28:16 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-06-22 22:54:19 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-06-23 17:29:49 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-06-22 22:54:19 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-23 17:52:52 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-23 17:52:52 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-06-21 16:08:48 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
+ 2008-06-23 02:19:41 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
- 2008-06-22 22:30:17 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-23 17:43:34 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-23 00:29:50 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008062220080623\index.dat
- 2008-06-22 22:30:17 49,152 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-23 17:43:34 49,152 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-22 22:30:17 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-23 17:43:34 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-06-22 03:56:44 2,764 —-a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\S-1-5-19.dat
+ 2008-06-23 02:55:09 2,764 —-a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\S-1-5-19.dat
- 2008-06-22 03:56:44 2,764 —-a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\S-1-5-20.dat
+ 2008-06-23 02:55:09 2,764 —-a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\S-1-5-20.dat
- 2008-06-22 03:56:44 5,644 —-a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\S-1-5-21-1982417792-272363597-2047950319-1000.dat
+ 2008-06-23 02:55:09 5,644 —-a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\S-1-5-21-1982417792-272363597-2047950319-1000.dat
- 2008-06-22 22:54:39 774,472 —-a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\settings.dat
+ 2008-06-23 17:46:10 66,136 —-a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\settings.dat
+ 2008-01-19 05:53:38 19,456 —-a-w C:\Windows\System32\DriverStore\FileRepository\bth.inf_03301a54\bthenum.sys
+ 2008-04-29 01:42:23 220,160 —-a-w C:\Windows\System32\DriverStore\FileRepository\bth.inf_03301a54\bthport.sys
+ 2008-04-29 01:42:21 29,184 —-a-w C:\Windows\System32\DriverStore\FileRepository\bth.inf_03301a54\BTHUSB.SYS
+ 2008-04-29 03:54:02 181,760 —-a-w C:\Windows\System32\DriverStore\FileRepository\bth.inf_03301a54\fsquirt.exe
+ 2008-04-29 01:42:12 19,456 —-a-w C:\Windows\System32\DriverStore\FileRepository\bth.inf_c206c850\bthenum.sys
+ 2008-04-29 01:42:12 220,160 —-a-w C:\Windows\System32\DriverStore\FileRepository\bth.inf_c206c850\bthport.sys
+ 2008-04-29 01:42:08 29,184 —-a-w C:\Windows\System32\DriverStore\FileRepository\bth.inf_c206c850\BTHUSB.SYS
+ 2008-04-29 03:50:12 181,760 —-a-w C:\Windows\System32\DriverStore\FileRepository\bth.inf_c206c850\fsquirt.exe
- 2008-02-22 04:58:23 28,160 —-a-w C:\Windows\System32\jsproxy.dll
+ 2008-04-25 04:35:13 28,160 —-a-w C:\Windows\System32\jsproxy.dll
- 2008-02-22 05:01:41 64,512 —-a-w C:\Windows\System32\migration\WininetPlugin.dll
+ 2008-04-25 04:35:24 64,512 —-a-w C:\Windows\System32\migration\WininetPlugin.dll
- 2008-05-09 21:35:04 16,863,864 —-a-w C:\Windows\System32\mrt.exe
+ 2008-05-29 23:35:11 17,486,968 —-a-w C:\Windows\System32\mrt.exe
- 2008-02-22 04:59:30 3,578,368 —-a-w C:\Windows\System32\mshtml.dll
+ 2008-04-25 04:35:14 3,578,368 —-a-w C:\Windows\System32\mshtml.dll
- 2008-02-22 04:59:51 671,232 —-a-w C:\Windows\System32\mstime.dll
+ 2008-04-25 04:35:16 671,232 —-a-w C:\Windows\System32\mstime.dll
- 2008-06-22 22:34:22 101,144 —-a-w C:\Windows\System32\perfc009.dat
+ 2008-06-23 17:32:45 101,144 —-a-w C:\Windows\System32\perfc009.dat
- 2008-06-22 22:34:22 595,446 —-a-w C:\Windows\System32\perfh009.dat
+ 2008-06-23 17:32:45 595,446 —-a-w C:\Windows\System32\perfh009.dat
- 2008-05-30 19:16:38 6,291,456 —-a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
+ 2008-06-23 00:25:07 6,291,456 —-a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
- 2008-02-22 05:01:33 1,166,336 —-a-w C:\Windows\System32\urlmon.dll
+ 2008-04-25 04:35:19 1,166,336 —-a-w C:\Windows\System32\urlmon.dll
- 2008-06-22 22:30:24 11,308 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1982417792-272363597-2047950319-1001_UserData.bin
+ 2008-06-23 17:30:27 11,970 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1982417792-272363597-2047950319-1001_UserData.bin
- 2008-06-22 22:30:24 65,922 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-06-23 17:30:27 66,270 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-06-22 22:30:22 54,752 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-06-23 17:30:26 55,246 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-23 04:27:53 864,256 —-a-w C:\Windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6000.16679_none_d97a4d2ed1f284d2\ehepg.dll
+ 2008-04-23 14:12:49 864,256 —-a-w C:\Windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6000.20821_none_da31f92beaeecb56\ehepg.dll
+ 2008-04-23 04:27:55 135,168 —-a-w C:\Windows\winsxs\msil_ehexthost_31bf3856ad364e35_6.0.6000.16679_none_bcbfc9e4c1e1e81d\ehexthost.exe
+ 2008-04-23 14:12:50 135,168 —-a-w C:\Windows\winsxs\msil_ehexthost_31bf3856ad364e35_6.0.6000.20821_none_bd7775e1dade2ea1\ehexthost.exe
+ 2008-04-23 04:27:56 77,824 —-a-w C:\Windows\winsxs\msil_ehiextens_31bf3856ad364e35_6.0.6000.16679_none_fba2d0c909e74612\ehiExtens.dll
+ 2008-04-23 14:12:51 77,824 —-a-w C:\Windows\winsxs\msil_ehiextens_31bf3856ad364e35_6.0.6000.20821_none_fc5a7cc622e38c96\ehiExtens.dll
+ 2008-04-23 04:27:59 4,374,528 —-a-w C:\Windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6000.16679_none_896d686f44a61324\ehshell.dll
+ 2008-04-23 14:12:55 4,382,720 —-a-w C:\Windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6000.20821_none_8a25146c5da259a8\ehshell.dll
+ 2008-04-23 04:44:14 4,046,848 —-a-w C:\Windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6001.18061_none_8b5674b141cbbd6c\ehshell.dll
+ 2008-04-23 04:36:58 4,046,848 —-a-w C:\Windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6001.22165_none_8be412a45ae5c292\ehshell.dll
+ 2008-04-23 04:28:14 1,196,032 —-a-w C:\Windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.16679_none_4e6b0
c2698ea89ba\Microsoft.MediaCenter.Shell.dll
+ 2008-04-23 14:13:09 1,269,760 —-a-w C:\Windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.20821_none_4f22b
823b1e6d03e\Microsoft.MediaCenter.Shell.dll
+ 2008-04-23 04:28:14 2,342,912 —-a-w C:\Windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.16679_none_30f95ad6
5a3e86d4\Microsoft.MediaCenter.UI.dll
+ 2008-04-23 14:13:09 2,351,104 —-a-w C:\Windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.20821_none_31b106d3
733acd58\Microsoft.MediaCenter.UI.dll
+ 2008-04-23 04:45:00 1,957,888 —-a-w C:\Windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.18061_none_32e26718
5764311c\Microsoft.MediaCenter.UI.dll
+ 2008-04-23 04:37:38 1,957,888 —-a-w C:\Windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.22165_none_3370050b
707e3642\Microsoft.MediaCenter.UI.dll
+ 2008-04-23 04:28:13 217,088 —-a-w C:\Windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.16679_none_2354b3c9cf5
6f2ea\Microsoft.MediaCenter.dll
+ 2008-04-23 14:13:08 217,088 —-a-w C:\Windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.20821_none_240c5fc6e85
3396e\Microsoft.MediaCenter.dll
+ 2008-04-29 01:42:12 19,456 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6000.16682_none_700a06c9bea9b8da\bthenum.sys
+ 2008-04-29 01:42:12 220,160 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6000.16682_none_700a06c9bea9b8da\bthport.sys
+ 2008-04-29 01:42:08 29,184 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6000.16682_none_700a06c9bea9b8da\BTHUSB.SYS
+ 2008-04-29 03:50:12 181,760 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6000.16682_none_700a06c9bea9b8da\fsquirt.exe
+ 2008-04-29 01:35:24 19,456 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6000.20824_none_70d68596d794e0d3\bthenum.sys
+ 2008-04-29 01:35:25 220,160 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6000.20824_none_70d68596d794e0d3\bthport.sys
+ 2008-04-29 01:35:23 29,184 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6000.20824_none_70d68596d794e0d3\BTHUSB.SYS
+ 2008-04-29 01:35:24 181,760 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6000.20824_none_70d68596d794e0d3\fsquirt.exe
+ 2008-01-19 05:53:38 19,456 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6001.18064_none_7207e5dbbbbe4497\bthenum.sys
+ 2008-04-29 01:42:23 220,160 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6001.18064_none_7207e5dbbbbe4497\bthport.sys
+ 2008-04-29 01:42:21 29,184 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6001.18064_none_7207e5dbbbbe4497\BTHUSB.SYS
+ 2008-04-29 03:54:02 181,760 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6001.18064_none_7207e5dbbbbe4497\fsquirt.exe
+ 2008-04-29 01:43:50 19,456 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6001.22168_none_729583ced4d849bd\bthenum.sys
+ 2008-04-29 01:43:50 220,160 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6001.22168_none_729583ced4d849bd\bthport.sys
+ 2008-04-29 01:43:48 29,184 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6001.22168_none_729583ced4d849bd\BTHUSB.SYS
+ 2008-04-29 01:43:51 181,760 —-a-w C:\Windows\winsxs\x86_bth.inf_31bf3856ad364e35_6.0.6001.22168_none_729583ced4d849bd\fsquirt.exe
+ 2008-04-23 04:28:09 136,704 —-a-w C:\Windows\winsxs\x86_mcupdate_31bf3856ad364e35_6.0.6000.16679_none_c673e63faed8754d\mcupdate.exe
+ 2008-04-23 14:13:03 136,704 —-a-w C:\Windows\winsxs\x86_mcupdate_31bf3856ad364e35_6.0.6000.20821_none_c72b923cc7d4bbd1\mcupdate.exe
+ 2008-04-23 04:44:47 140,288 —-a-w C:\Windows\winsxs\x86_mcupdate_31bf3856ad364e35_6.0.6001.18061_none_c85cf281abfe1f95\mcupdate.exe
+ 2008-04-23 04:37:28 140,288 —-a-w C:\Windows\winsxs\x86_mcupdate_31bf3856ad364e35_6.0.6001.22165_none_c8ea9074c51824bb\mcupdate.exe
+ 2008-04-25 04:23:05 124,928 —-a-w C:\Windows\winsxs\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.16681_none_a98fa7bdf5e9f5de\advpack.dll
+ 2008-04-25 04:06:14 124,928 —-a-w C:\Windows\winsxs\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.20823_none_aa5c268b0ed51dd7\advpack.dll
+ 2008-04-26 08:02:05 1,327,104 —-a-w C:\Windows\winsxs\x86_microsoft-windows-directshow-core_31bf3856ad364e35_6.0.6000.16681_none_a4347a24f0ff937a\quartz.dll
+ 2008-04-26 07:41:59 1,327,616 —-a-w C:\Windows\winsxs\x86_microsoft-windows-directshow-core_31bf3856ad364e35_6.0.6000.20823_none_a500f8f209eabb73\quartz.dll
+ 2008-04-26 08:08:15 1,314,816 —-a-w C:\Windows\winsxs\x86_microsoft-windows-directshow-core_31bf3856ad364e35_6.0.6001.18063_none_a6325936ee141f37\quartz.dll
+ 2008-04-26 07:57:58 1,314,816 —-a-w C:\Windows\winsxs\x86_microsoft-windows-directshow-core_31bf3856ad364e35_6.0.6001.22167_none_a6bff72a072e245d\quartz.dll
+ 2008-04-23 04:27:00 252,416 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.16679_none_128e8c93a2bce482\ehReplay.dll
+ 2008-04-23 05:11:36 254,464 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.20821_none_13463890bbb92b06\ehReplay.dll
+ 2008-04-23 04:42:33 254,464 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18061_none_147798d59fe28eca\ehReplay.dll
+ 2008-04-23 04:30:25 254,464 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22165_none_150536c8b8fc93f0\ehReplay.dll
+ 2008-04-23 04:27:01 6,656 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16679_none_3200fce9dd0448e0\McrMgr.dll
+ 2008-04-23 04:26:31 173,056 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16679_none_3200fce9dd0448e0\McrMgr.exe
+ 2008-04-23 05:11:51 6,656 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.20821_none_32b8a8e6f6008f64\McrMgr.dll
+ 2008-04-23 03:56:48 172,544 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.20821_none_32b8a8e6f6008f64\McrMgr.exe
+ 2008-04-23 04:27:00 21,504 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.16679_none_2db4cba1854c2050\ehdebug.dll
+ 2008-04-23 05:11:35 21,504 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.20821_none_2e6c779e9e4866d4\ehdebug.dll
+ 2008-04-23 04:27:00 372,224 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.16679_none_2d12eef96d2c252b\ehglid.dll
+ 2008-04-23 05:11:35 372,736 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.20821_none_2dca9af686286baf\ehglid.dll
+ 2008-04-23 04:42:33 373,248 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18061_none_2efbfb3b6a51cf73\ehglid.dll
+ 2008-04-23 04:30:24 373,248 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22165_none_2f89992e836bd499\ehglid.dll
+ 2008-04-23 04:27:00 105,472 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.16679_none_249fac1865043b1f\ehPresenter.dll
+ 2008-04-23 05:11:36 105,472 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.20821_none_255758157e0081a3\ehPresenter.dll
+ 2008-04-23 04:42:33 105,472 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18061_none_2688b85a6229e567\ehPresenter.dll
+ 2008-04-23 04:30:25 105,472 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22165_none_2716564d7b43ea8d\ehPresenter.dll
+ 2008-04-23 04:22:35 10,094,080 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.16679_none_4fe31875538242d1\ehres.dll
+ 2008-04-23 05:11:36 10,103,808 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.20821_none_509ac4726c7e8955\ehres.dll
+ 2008-04-23 04:27:00 18,944 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.16679_none_3693dda116ea05e6\ehtrace.dll
+ 2008-04-23 05:11:36 18,944 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.20821_none_374b899e2fe64c6a\ehtrace.dll
+ 2008-04-23 04:27:00 517,632 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.16679_none_cc9b30cbcc71d8eb\ehui.dll
+ 2008-04-23 05:11:36 521,216 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.20821_none_cd52dcc8e56e1f6f\ehui.dll
+ 2008-04-23 04:42:33 522,240 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18061_none_ce843d0dc9978333\ehui.dll
+ 2008-04-23 04:30:33 522,240 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22165_none_cf11db00e2b18859\ehui.dll
+ 2008-04-23 04:27:00 1,497,600 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.16679_none_39e223022e478d8d\ehuihlp.dll
+ 2008-04-23 05:11:36 1,498,112 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.20821_none_3a99ceff4743d411\ehuihlp.dll
+ 2008-04-25 04:23:10 44,544 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.16681_none_eb8ab16d1682dbdd\pngfilt.dll
+ 2008-04-25 04:09:24 44,544 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_6.0.6000.20823_none_ec57303a2f6e03d6\pngfilt.dll
+ 2008-04-25 04:23:11 1,159,680 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.16681_none_b2a75a1fd9e35341\urlmon.dll
+ 2008-04-25 04:09:51 1,162,752 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.20823_none_b373d8ecf2ce7b3a\urlmon.dll
+ 2008-04-25 04:35:19 1,166,336 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18063_none_b4a53931d6f7defe\urlmon.dll
+ 2008-04-25 04:21:54 1,166,336 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22167_none_b532d724f011e424\urlmon.dll
+ 2008-04-25 04:23:09 671,232 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.16681_none_de89e8e87f8c12b0\mstime.dll
+ 2008-04-25 04:08:10 671,232 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6000.20823_none_df5667b598773aa9\mstime.dll
+ 2008-04-25 04:35:16 671,232 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.18063_none_e087c7fa7ca09e6d\mstime.dll
+ 2008-04-25 04:20:09 671,232 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..mlrenderingadvanced_31bf3856ad364e35_6.0.6001.22167_none_e11565ed95baa393\mstime.dll
+ 2008-04-25 04:23:06 27,648 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16681_none_ffad35c1a4ec79d4\jsproxy.dll
+ 2008-04-25 04:23:11 826,368 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16681_none_ffad35c1a4ec79d4\wininet.dll
+ 2008-04-25 04:23:11 64,512 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16681_none_ffad35c1a4ec79d4\WininetPlugin.dll
+ 2008-04-25 04:07:19 27,648 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20823_none_0079b48ebdd7a1cd\jsproxy.dll
+ 2008-04-25 04:09:57 827,392 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20823_none_0079b48ebdd7a1cd\wininet.dll
+ 2008-04-25 04:09:57 64,512 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20823_none_0079b48ebdd7a1cd\WininetPlugin.dll
+ 2008-04-25 04:35:13 28,160 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18063_none_01ab14d3a2010591\jsproxy.dll
+ 2008-04-25 04:35:23 826,880 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18063_none_01ab14d3a2010591\wininet.dll
+ 2008-04-25 04:35:24 64,512 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18063_none_01ab14d3a2010591\WininetPlugin.dll
+ 2008-04-25 04:19:00 28,160 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22167_none_0238b2c6bb1b0ab7\jsproxy.dll
+ 2008-04-25 04:22:01 826,880 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22167_none_0238b2c6bb1b0ab7\wininet.dll
+ 2008-04-25 04:22:01 64,512 —-a-w C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22167_none_0238b2c6bb1b0ab7\WininetPlugin.dll
+ 2007-09-13 00:55:10 2,455,488 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16681_none_f956589b6ed7f427\ieapfltr.dat
+ 2008-04-25 04:23:06 383,488 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16681_none_f956589b6ed7f427\ieapfltr.dll
+ 2007-09-13 00:55:10 2,455,488 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.20823_none_fa22d76887c31c20\ieapfltr.dat
+ 2008-04-25 04:07:00 383,488 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.20823_none_fa22d76887c31c20\ieapfltr.dll
+ 2008-04-25 04:23:06 347,136 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16681_none_958a915384bd7a55\dxtmsft.dll
+ 2008-04-25 04:23:06 214,528 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16681_none_958a915384bd7a55\dxtrans.dll
+ 2008-04-25 04:06:44 347,136 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.20823_none_965710209da8a24e\dxtmsft.dll
+ 2008-04-25 04:06:44 214,528 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.20823_none_965710209da8a24e\dxtrans.dll
+ 2008-04-25 04:23:07 478,208 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.16681_none_45ed2bab467e2ce2\mshtmled.dll
+ 2008-04-25 04:07:54 478,208 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_6.0.6000.20823_none_46b9aa785f6954db\mshtmled.dll
+ 2008-04-25 04:23:07 3,591,680 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16681_none_110754e02542e30a\mshtml.dll
+ 2008-04-25 04:07:54 3,593,728 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20823_none_11d3d3ad3e2e0b03\mshtml.dll
+ 2008-04-25 04:35:14 3,578,368 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18063_none_130533f222576ec7\mshtml.dll
+ 2008-04-25 04:19:50 3,578,368 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22167_none_1392d1e53b7173ed\mshtml.dll
+ 2008-04-25 04:23:06 63,488 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.16681_none_585fc1aa67576f13\icardie.dll
+ 2008-04-25 04:06:59 63,488 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_6.0.6000.20823_none_592c40778042970c\icardie.dll
+ 2008-04-25 04:22:36 26,624 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\ieUnatt.exe
+ 2008-04-25 04:22:36 625,664 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\iexplore.exe
+ 2008-04-25 02:03:49 26,624 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\ieUnatt.exe
+ 2008-04-25 02:04:08 625,664 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\iexplore.exe
+ 2008-04-25 04:22:36 70,656 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16681_none_c394f7686192b15c\ie4uinit.exe
+ 2008-04-25 04:23:06 44,544 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16681_none_c394f7686192b15c\iernonce.dll
+ 2008-04-25 04:23:06 56,320 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.16681_none_c394f7686192b15c\iesetup.dll
+ 2008-04-25 02:03:38 70,656 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20823_none_c46176357a7dd955\ie4uinit.exe
+ 2008-04-25 04:07:06 44,544 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20823_none_c46176357a7dd955\iernonce.dll
+ 2008-04-25 04:07:06 56,320 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_6.0.6000.20823_none_c46176357a7dd955\iesetup.dll
+ 2008-04-25 04:23:06 52,736 —-a-w C:\Windows\winsxs\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.16681_none_29ba0dd8684286b9\iebrshim.dll
+ 2008-04-25 04:07:00 52,736 —-a-w C:\Windows\winsxs\x86_microsoft-windows-iebrshim_31bf3856ad364e35_6.0.6000.20823_none_2a868ca5812daeb2\iebrshim.dll
+ 2008-04-25 04:23:06 6,066,176 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16681_none_6266aee3b1387137\ieframe.dll
+ 2008-04-25 04:23:06 180,736 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16681_none_6266aee3b1387137\ieui.dll
+ 2008-04-25 04:07:06 6,068,224 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.20823_none_63332db0ca239930\ieframe.dll
+ 2008-04-25 04:07:06 180,736 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.20823_none_63332db0ca239930\ieui.dll
+ 2008-04-25 04:22:36 263,168 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.16681_none_e6601b6294bbc56f\ieinstal.exe
+ 2008-04-25 02:04:02 263,168 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_6.0.6000.20823_none_e72c9a2fada6ed68\ieinstal.exe
+ 2008-04-25 04:22:36 301,568 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.16681_none_0b08507ed7368521\ieuser.exe
+ 2008-04-25 02:04:03 301,568 —-a-w C:\Windows\winsxs\x86_microsoft-windows-ieuser_31bf3856ad364e35_6.0.6000.20823_none_0bd4cf4bf021ad1a\ieuser.exe
+ 2008-04-23 04:27:01 1,244,672 —-a-w C:\Windows\winsxs\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.16679_none_3d017dbd628e4075\mcmde.dll
+ 2008-04-23 05:11:51 1,244,672 —-a-w C:\Windows\winsxs\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.20821_none_3db929ba7b8a86f9\mcmde.dll
+ 2008-05-02 22:21:56 2,413,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16688_none_f0535e6e6e8d6c76\OESpamFilter.dat
+ 2008-05-02 22:17:48 2,413,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20833_none_f10e0b498786feff\OESpamFilter.dat
+ 2008-05-02 22:18:31 2,413,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18071_none_f23d6afa6bb23015\OESpamFilter.dat
+ 2008-05-02 22:17:54 2,413,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22178_none_f2ce09cb84c98140\OESpamFilter.dat
+ 2008-05-10 01:21:06 113,664 —-a-w C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.0.6000.16687_none_524810318afeff68\rmcast.sys
+ 2008-05-10 03:30:50 14,848 —-a-w C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.0.6000.16687_none_524810318afeff68\wshrm.dll
+ 2008-05-10 01:15:20 113,664 —-a-w C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.0.6000.20832_none_5302bd0ca3f891f1\rmcast.sys
+ 2008-05-10 03:14:30 14,848 —-a-w C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.0.6000.20832_none_5302bd0ca3f891f1\wshrm.dll
+ 2008-05-10 01:33:10 113,664 —-a-w C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.0.6001.18069_none_5445ef4388138b25\rmcast.sys
+ 2006-11-02 09:46:14 14,848 —-a-w C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.0.6001.18069_none_5445ef4388138b25\wshrm.dll
+ 2008-05-10 01:20:02 113,664 —-a-w C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.0.6001.22176_none_54c1bb44a13bfadb\rmcast.sys
+ 2008-05-10 03:22:18 14,848 —-a-w C:\Windows\winsxs\x86_microsoft-windows-rmcast_31bf3856ad364e35_6.0.6001.22176_none_54c1bb44a13bfadb\wshrm.dll
+ 2008-04-23 04:27:00 428,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.16679_none_de4f2af09170b787\EncDec.dll
+ 2008-04-23 05:11:36 428,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.20821_none_df06d6edaa6cfe0b\EncDec.dll
+ 2008-04-23 04:42:37 428,544 —-a-w C:\Windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18061_none_e03837328e9661cf\EncDec.dll
+ 2008-04-23 04:34:41 428,544 —-a-w C:\Windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22165_none_e0c5d525a7b066f5\EncDec.dll
+ 2008-04-23 04:27:04 292,352 —-a-w C:\Windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.16679_none_d9d44caa5a19bb32\psisdecd.dll
+ 2008-04-23 05:12:30 292,352 —-a-w C:\Windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.20821_none_da8bf8a7731601b6\psisdecd.dll
+ 2008-04-23 04:42:37 293,376 —-a-w C:\Windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18061_none_dbbd58ec573f657a\psisdecd.dll
+ 2008-04-23 04:34:47 293,376 —-a-w C:\Windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22165_none_dc4af6df70596aa0\psisdecd.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-12 20:44 1773568]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 03:33 125952]
"Host Process"="C:\Users\leenbrooke\svchost.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 03:33 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 09:42 65536]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 19:36 178712]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 18:22 184320]
"CCUTRAYICON"="FactoryMode" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"DT HPW"="C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2007-09-28 15:52 81920]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 06:59 118784]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 09:56 236016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-11 17:06 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-11 17:06 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-11 17:06 81920]
"aecb1da8"="C:\Windows\system32\ljnsqjtr.dll" [ ]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-06-21 15:55 2468200]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 20:56 5367664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="C:\Windows\SMINST\launcher.exe" [2007-03-07 14:09 44168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{4E06327D-0415-475F-898B-6ACFB316073E}"= C:\Windows\system32\iifebArq.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0B1590FC-B3A1-474D-813C-665716ADE513}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{65B84EE2-BD44-455B-9709-5B7ED0FBCDE2}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{FBE2BE16-21D7-494C-92D6-785333D212BD}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{4CD6B41D-DE30-45B3-BA4D-7F6869901BA2}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{24D94B5D-4AE1-43BC-881A-B134621FD15E}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{633B92B8-18EC-4D76-B927-1DE7A7715DAB}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{4C5BDB23-DE52-464F-870F-F9DE80C88082}"= TCP:9442:127.0.0.1:Intel® Viiv™ Media Server Discovery
"{1BEC42A8-8BB3-4012-9DEC-7A626F906150}"= TCP:1900:LocalSubnet:LocalSubnet:Intel® Viiv™ Media Server UPnP Discovery
"{B6B9630C-964B-432B-BC68-79587F01A73B}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9BEED121-2A98-4FBE-A7F9-C849A490DC14}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B226F91-4C4A-4491-AE42-87FA392F602B}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BE450CF8-F510-4C9C-9616-F7DC3FACCC2F}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{365B7FAB-8542-4836-ABBF-4846E04F2A70}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6BA9AC15-F85F-4912-A603-6B6CB349DE80}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A9F0B794-7AED-4C9C-9CFF-AD190772B89D}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{67AB14DF-E68C-499A-939E-DAC67E220DCE}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D5E4F9FF-A123-437C-8566-83A21A91FA6B}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5CB913E1-9B75-4ABC-93A6-CDF90A7EF8C6}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{6E1549F4-97A3-4C3E-BF19-CFB0FD1E4585}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FE094B77-EF29-4E64-BDC8-C22FFEB1A1C9}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0DF25708-FEC2-4EE7-ABE2-D2C307852F2C}"= UDP:C:\Program Files\Steam\Steam.exe:Steam Client
"{46C00868-AAA9-4C34-A3B2-2CACFDC2DB77}"= TCP:C:\Program Files\Steam\Steam.exe:Steam Client
"{86AD77FC-1E93-481F-A1AD-0212309E7BF8}"= UDP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{824E2870-F4FC-4E3B-B1CC-BF330C6058EF}"= TCP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{5AC03833-D8B1-4E33-B0DC-A81AF50E56C8}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{85A7C75D-291B-4BD2-9A64-570D1912AB76}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{31C3BEC3-E271-4084-BB68-ED62570A99A1}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{BA12A1BC-F222-4CDF-B20B-1BBC7F0B8B94}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{37DE7D8B-0714-4278-BF35-5F50DCDD71FE}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{79A5C645-431B-4525-A27B-8A1EE5098DAC}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{532E2A4B-09F2-43D4-BF9F-54BC4EF92587}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"UDP Query User{CF1D7F7F-8BA0-443E-BC70-CBBCB049BD5A}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"{284B6EB5-C392-4BD2-ABC9-07B9E59EE40C}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{431398BF-9A2F-44CB-9C44-EA245D6A47AB}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"TCP Query User{3C15B82E-FF8F-4736-841B-0B50EA77B5C2}C:\\program files\\roxio\\media manager 9\\mediamanager9.exe"= UDP:C:\program files\roxio\media manager 9\mediamanager9.exe:MediaManager9 Module
"UDP Query User{5C412AC8-6BCF-406D-9009-332FEE3A3D66}C:\\program files\\roxio\\media manager 9\\mediamanager9.exe"= TCP:C:\program files\roxio\media manager 9\mediamanager9.exe:MediaManager9 Module
"{4E2D1FA3-0745-4C56-991C-551CE76DA848}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{1CA18CA3-57F3-4294-9DEF-81E48306BFB9}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{722B19E6-B291-407E-856E-C5EC9854CC6C}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{057A55ED-8CB1-4630-85D9-013B0BFA9F4D}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{2EEABA05-B99D-4963-899F-E5FBF2271158}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{0DCEB5D1-8616-45B5-8943-6127F222B9C0}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"TCP Query User{269BADEC-EC66-490B-8795-3147B59DC1A6}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"UDP Query User{37F4494B-C095-40CD-B0F2-AF237F4D017A}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"TCP Query User{C752B154-483E-4F1B-A9D2-B1F574267C24}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{2A3B3F10-DE55-4B2F-A8A7-9BED4E3E06DB}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{914F9EFA-916E-4A77-BACB-B465201C1E72}C:\\program files\\aim\\aim pro\\aimpro.exe"= UDP:C:\program files\aim\aim pro\aimpro.exe:AIM Pro
"UDP Query User{064B5D90-048E-4095-821A-304800802BB7}C:\\program files\\aim\\aim pro\\aimpro.exe"= TCP:C:\program files\aim\aim pro\aimpro.exe:AIM Pro
"{DC5FA85B-7AC3-4E8E-8D34-D8072F7FBAC0}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D7098655-C16A-4134-8DA6-3DCC5A5EF500}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C9844078-0FE4-4E72-9D65-2F015A1A4E72}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AB18838B-051B-4FBF-BFD3-F643F1805553}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{75329D7B-B5C8-4BDD-A036-551D13341274}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{756E719B-29FF-48D7-A281-F1F3CAEDCBC4}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{5FA02C3D-AACA-4481-8880-184B11A8C249}"= Disabled:UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{5944F2CE-5489-4E73-B1C2-CB571137F5B8}"= Disabled:TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"TCP Query User{6E2B55FB-CCC7-4B59-B5EB-633806659D99}C:\\program files\\mozilla firefox\\firefox.exe"= Disabled:UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{6E33F0D4-0408-47CD-8F4C-7286431DA609}C:\\program files\\mozilla firefox\\firefox.exe"= Disabled:TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{D91FA5EE-0215-405D-B06F-54F81E487CB7}"= Disabled:UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{DF40EBF9-88A7-46C5-9D48-21296AAE6042}"= Disabled:TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R2 CTAudSvcService;Creative Audio Service;C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2007-11-26 09:22]
R2 DQLWinService;DQLWinService;"C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe" [2006-09-03 13:32]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys [2007-06-11 13:49]
R3 t3;Sound Blaster X-Fi Xtreme Audio (Vista);C:\Windows\system32\drivers\t3.sys [2008-01-29 03:03]
S2 IntelDHSvcConf;Intel DH Service;"C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe" [2006-05-10 12:13]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;"C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe" [2008-01-06 22:08]
S3 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20070108.003\IDSvix86.sys [2006-12-27 18:48]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-06-11 21:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2795ffd3-5c24-11dc-a37c-806e6f6e6963}]
\shell\AutoRun\command - E:\install.exe

*Newly Created Service* - AD-WATCH_REGISTRY_FILTER
*Newly Created Service* - COMHOST
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-23 13:52:53
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-23 13:53:47
ComboFix-quarantined-files.txt 2008-06-23 17:53:43
ComboFix2.txt 2008-06-22 22:58:20

Pre-Run: 167,630,327,808 bytes free
Post-Run: 167,595,687,936 bytes free

478 — E O F — 2008-06-23 00:02:32
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:03:34 PM, on 6/23/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DT HPW] "C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe" -HPW
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [aecb1da8] "rundll32.exe" "C:\Windows\system32\ljnsqjtr.dll",b
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [HPAdvisor] "C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Host Process] C:\Users\leenbrooke\svchost.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2…15035/CTPID.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® Viiv™ Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 9982 bytes
Hello

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Windows\System32\mktxyohb.dll
C:\Windows\System32\bqoauodn.dll
C:\Windows\System32\mqpabfea.dll
C:\Windows\System32\rpxcxvsi.dll
C:\Windows\System32\fxolrdtw.dll
C:\Users\leenbrooke\winlogon.exe
C:\Users\leenbrooke\748.bat
E:\install.exe

Folder::
C:\Windows\bGVlbmJyb29rZQ
C:\Windows\System32\netrax05
C:\Windows\System32\eb10
C:\Windows\System32\bgi
C:\Windows\System32\axc
C:\Windows\System32\1049a
C:\TEMP\itmp4

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2795ffd3-5c24-11dc-a37c-806e6f6e6963}]

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
ComboFix 08-06-20.4 - leenbrooke 2008-06-23 14:27:54.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1240 [GMT -4:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\leenbrooke\Desktop\CFscript.lnk
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-05-23 to 2008-06-23 )))))))))))))))))))))))))))))))
.

2008-06-21 22:11 . 2008-06-21 22:11 d——– C:\VundoFix Backups
2008-06-21 17:41 . 2008-06-21 23:49 d——– C:\ProgramData\SecTaskMan
2008-06-21 15:53 . 2008-06-21 15:56 d——– C:\ProgramData\Lavasoft
2008-06-21 15:53 . 2008-06-21 15:53 d——– C:\Program Files\Lavasoft
2008-06-21 13:37 . 2008-06-21 13:37 d——– C:\Users\leenbrooke\AppData\Roaming\TrojanHunter
2008-06-21 13:24 . 2008-06-21 23:49 d——– C:\Program Files\TrojanHunter 5.0
2008-06-21 12:17 . 2008-06-21 12:17 130,560 –a—— C:\Windows\System32\mktxyohb.dll
2008-06-21 12:12 . 2008-06-21 12:12 128,512 –a—— C:\Windows\System32\bqoauodn.dll
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\Users\leenbrooke\AppData\Roaming\Webroot
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\ProgramData\Webroot
2008-06-21 12:03 . 2008-06-21 12:03 d——– C:\Program Files\Webroot
2008-06-21 12:03 . 2008-01-04 20:56 1,526,640 –a—— C:\Windows\WRSetup.dll
2008-06-21 12:03 . 2008-01-04 20:34 163,696 –a—— C:\Windows\System32\drivers\ssidrv.sys
2008-06-21 12:03 . 2008-01-04 20:34 23,920 –a—— C:\Windows\System32\drivers\sskbfd.sys
2008-06-21 12:03 . 2008-01-04 20:34 21,872 –a—— C:\Windows\System32\drivers\sshrmd.sys
2008-06-21 12:03 . 2008-01-04 20:34 20,336 –a—— C:\Windows\System32\drivers\SSFS0BB9.sys
2008-06-21 10:55 . 2008-06-21 10:55 130,560 –a—— C:\Windows\System32\mqpabfea.dll
2008-06-21 10:53 . 2008-06-21 10:53 128,512 –a—— C:\Windows\System32\rpxcxvsi.dll
2008-06-21 10:43 . 2008-06-22 20:19 403 –a—— C:\Windows\wininit.ini
2008-06-21 09:48 . 2008-06-21 09:48 128,512 –a—— C:\Windows\System32\fxolrdtw.dll
2008-06-20 15:51 . 2008-06-20 15:51 d——– C:\Program Files\Trend Micro
2008-06-20 13:39 . 2008-06-20 13:39 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-06-20 13:38 . 2008-06-20 13:38 d——– C:\Users\leenbrooke\AppData\Roaming\SUPERAntiSpyware.com
2008-06-20 13:38 . 2008-06-20 13:38 d——– C:\Program Files\SUPERAntiSpyware
2008-06-19 16:22 . 2008-06-19 16:23 d——– C:\Program Files\Common Files\BitDefender
2008-06-19 16:03 . 2008-06-21 10:20 d——– C:\ProgramData\Spybot - Search & Destroy
2008-06-19 16:03 . 2008-06-21 10:18 d——– C:\Program Files\Spybot - Search & Destroy
2008-06-19 15:58 . 2008-06-19 18:26 d-a—— C:\ProgramData\TEMP
2008-06-19 14:55 . 2008-06-19 14:55 d——– C:\ProgramData\McAfee
2008-06-19 14:49 . 2008-06-19 14:49 1,879,040 –a—— C:\Users\leenbrooke\winlogon.exe
2008-06-19 14:49 . 2008-06-19 14:49 554 –a—— C:\Users\leenbrooke\748.bat
2008-06-19 14:46 . 2008-06-21 12:31 d–hs—- C:\Windows\bGVlbmJyb29rZQ
2008-06-19 14:44 . 2008-06-22 19:52 d——– C:\Windows\System32\netrax05
2008-06-19 14:44 . 2008-06-22 19:52 d——– C:\Windows\System32\eb10
2008-06-19 14:44 . 2008-06-22 00:07 d——– C:\Windows\System32\bgi
2008-06-19 14:44 . 2008-06-22 00:07 d——– C:\Windows\System32\axc
2008-06-19 14:44 . 2008-06-21 12:31 d——– C:\Windows\System32\1049a
2008-06-19 14:44 . 2008-06-19 14:44 d——– C:\TEMP\itmp4
2008-05-31 11:48 . 2008-05-31 11:48 0 –ah—– C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-05-30 15:12 . 2008-03-07 22:08 4,240,384 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-30 15:12 . 2008-03-08 00:21 1,695,744 –a—— C:\Windows\System32\gameux.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-23 03:26 ——— d—–w C:\Program Files\Steam
2008-06-23 00:02 ——— d—–w C:\Program Files\Windows Mail
2008-06-21 19:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 13:36 ——— d—–w C:\Program Files\Norton Internet Security
2008-06-19 19:27 ——— d—–w C:\Users\leenbrooke\AppData\Roaming\LimeWire
2008-06-13 17:35 ——— d—–w C:\Program Files\Common Files\Steam
2008-06-07 05:35 ——— d—–w C:\Program Files\PokerStars.NET
2008-06-07 00:59 ——— d—–w C:\ProgramData\NVIDIA
2008-06-01 23:26 ——— d—–w C:\Program Files\HP
2008-05-27 01:54 22,328 —-a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-05-27 01:54 103,736 —-a-w C:\Windows\System32\PnkBstrB.exe
2008-05-26 23:32 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-20 17:51 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-05-16 15:58 12,632 —-a-w C:\Windows\System32\lsdelete.exe
2008-05-16 01:10 ——— d—–w C:\ProgramData\Creative
2008-05-13 17:59 409,600 —-a-w C:\Windows\System32\wrap_oal.dll
2008-05-13 17:59 114,688 —-a-w C:\Windows\System32\OpenAL32.dll
2008-05-13 17:52 ——— d—–w C:\ProgramData\Microsoft Help
2008-05-10 01:33 113,664 —-a-w C:\Windows\system32\drivers\rmcast.sys
2008-05-06 15:04 ——— d—–w C:\Program Files\Java
2008-05-05 01:31 ——— d—–w C:\Users\leenbrooke\AppData\Roaming\SystemRequirementsLab
2008-05-05 01:31 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-05-03 02:46 795,104 —-a-w C:\Windows\System32\dpinst.exe
2008-05-03 02:46 768,544 —-a-w C:\Windows\System32\nvcplui.exe
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcodhins.dll
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcodh.dll
2008-05-03 02:46 41,984 —-a-w C:\Windows\System32\nvcod130.dll
2008-05-03 02:46 313,888 —-a-w C:\Windows\System32\nvexpbar.dll
2008-05-03 02:46 118,784 —-a-w C:\Windows\System32\nvvsvc.exe
2008-04-30 21:27 442,368 —-a-w C:\Windows\System32\nvuninst.exe
2008-04-29 15:20 15,648 —-a-w C:\Windows\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 —-a-w C:\Windows\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 —-a-w C:\Windows\system32\drivers\Awrtpd.sys
2008-04-26 08:08 1,314,816 —-a-w C:\Windows\System32\quartz.dll
2008-04-25 04:35 826,880 —-a-w C:\Windows\System32\wininet.dll
2008-04-23 04:42 428,544 —-a-w C:\Windows\System32\EncDec.dll
2008-04-23 04:42 293,376 —-a-w C:\Windows\System32\psisdecd.dll
2008-03-21 00:30 174 –sha-w C:\Program Files\desktop.ini
2007-10-13 01:06 22,328 —-a-w C:\Users\leenbrooke\AppData\Roaming\PnkBstrK.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-23_13.53.25.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-23 17:52:52 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-23 18:29:09 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-23 18:29:09 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-12 20:44 1773568]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 03:33 125952]
"Host Process"="C:\Users\leenbrooke\svchost.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 03:33 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 09:42 65536]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 19:36 178712]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 18:22 184320]
"CCUTRAYICON"="FactoryMode" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"DT HPW"="C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2007-09-28 15:52 81920]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 06:59 118784]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 09:56 236016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-11 17:06 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-11 17:06 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-11 17:06 81920]
"aecb1da8"="C:\Windows\system32\ljnsqjtr.dll" [ ]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-06-21 15:55 2468200]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 20:56 5367664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="C:\Windows\SMINST\launcher.exe" [2007-03-07 14:09 44168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{4E06327D-0415-475F-898B-6ACFB316073E}"= C:\Windows\system32\iifebArq.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0B1590FC-B3A1-474D-813C-665716ADE513}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{65B84EE2-BD44-455B-9709-5B7ED0FBCDE2}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{FBE2BE16-21D7-494C-92D6-785333D212BD}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{4CD6B41D-DE30-45B3-BA4D-7F6869901BA2}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv™ Media Server
"{24D94B5D-4AE1-43BC-881A-B134621FD15E}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{633B92B8-18EC-4D76-B927-1DE7A7715DAB}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{4C5BDB23-DE52-464F-870F-F9DE80C88082}"= TCP:9442:127.0.0.1:Intel® Viiv™ Media Server Discovery
"{1BEC42A8-8BB3-4012-9DEC-7A626F906150}"= TCP:1900:LocalSubnet:LocalSubnet:Intel® Viiv™ Media Server UPnP Discovery
"{B6B9630C-964B-432B-BC68-79587F01A73B}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9BEED121-2A98-4FBE-A7F9-C849A490DC14}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B226F91-4C4A-4491-AE42-87FA392F602B}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BE450CF8-F510-4C9C-9616-F7DC3FACCC2F}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{365B7FAB-8542-4836-ABBF-4846E04F2A70}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6BA9AC15-F85F-4912-A603-6B6CB349DE80}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A9F0B794-7AED-4C9C-9CFF-AD190772B89D}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{67AB14DF-E68C-499A-939E-DAC67E220DCE}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D5E4F9FF-A123-437C-8566-83A21A91FA6B}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5CB913E1-9B75-4ABC-93A6-CDF90A7EF8C6}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{6E1549F4-97A3-4C3E-BF19-CFB0FD1E4585}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FE094B77-EF29-4E64-BDC8-C22FFEB1A1C9}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0DF25708-FEC2-4EE7-ABE2-D2C307852F2C}"= UDP:C:\Program Files\Steam\Steam.exe:Steam Client
"{46C00868-AAA9-4C34-A3B2-2CACFDC2DB77}"= TCP:C:\Program Files\Steam\Steam.exe:Steam Client
"{86AD77FC-1E93-481F-A1AD-0212309E7BF8}"= UDP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{824E2870-F4FC-4E3B-B1CC-BF330C6058EF}"= TCP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{5AC03833-D8B1-4E33-B0DC-A81AF50E56C8}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{85A7C75D-291B-4BD2-9A64-570D1912AB76}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{31C3BEC3-E271-4084-BB68-ED62570A99A1}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{BA12A1BC-F222-4CDF-B20B-1BBC7F0B8B94}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{37DE7D8B-0714-4278-BF35-5F50DCDD71FE}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{79A5C645-431B-4525-A27B-8A1EE5098DAC}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{532E2A4B-09F2-43D4-BF9F-54BC4EF92587}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"UDP Query User{CF1D7F7F-8BA0-443E-BC70-CBBCB049BD5A}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"{284B6EB5-C392-4BD2-ABC9-07B9E59EE40C}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{431398BF-9A2F-44CB-9C44-EA245D6A47AB}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"TCP Query User{3C15B82E-FF8F-4736-841B-0B50EA77B5C2}C:\\program files\\roxio\\media manager 9\\mediamanager9.exe"= UDP:C:\program files\roxio\media manager 9\mediamanager9.exe:MediaManager9 Module
"UDP Query User{5C412AC8-6BCF-406D-9009-332FEE3A3D66}C:\\program files\\roxio\\media manager 9\\mediamanager9.exe"= TCP:C:\program files\roxio\media manager 9\mediamanager9.exe:MediaManager9 Module
"{4E2D1FA3-0745-4C56-991C-551CE76DA848}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{1CA18CA3-57F3-4294-9DEF-81E48306BFB9}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{722B19E6-B291-407E-856E-C5EC9854CC6C}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{057A55ED-8CB1-4630-85D9-013B0BFA9F4D}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{2EEABA05-B99D-4963-899F-E5FBF2271158}"= UDP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"{0DCEB5D1-8616-45B5-8943-6127F222B9C0}"= TCP:C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:RoxioUPnPRenderer9
"TCP Query User{269BADEC-EC66-490B-8795-3147B59DC1A6}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"UDP Query User{37F4494B-C095-40CD-B0F2-AF237F4D017A}C:\\program files\\steam\\steamapps\\[removed]\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\[removed]\counter-strike source\hl2.exe:hl2
"TCP Query User{C752B154-483E-4F1B-A9D2-B1F574267C24}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{2A3B3F10-DE55-4B2F-A8A7-9BED4E3E06DB}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{914F9EFA-916E-4A77-BACB-B465201C1E72}C:\\program files\\aim\\aim pro\\aimpro.exe"= UDP:C:\program files\aim\aim pro\aimpro.exe:AIM Pro
"UDP Query User{064B5D90-048E-4095-821A-304800802BB7}C:\\program files\\aim\\aim pro\\aimpro.exe"= TCP:C:\program files\aim\aim pro\aimpro.exe:AIM Pro
"{DC5FA85B-7AC3-4E8E-8D34-D8072F7FBAC0}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D7098655-C16A-4134-8DA6-3DCC5A5EF500}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C9844078-0FE4-4E72-9D65-2F015A1A4E72}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AB18838B-051B-4FBF-BFD3-F643F1805553}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{75329D7B-B5C8-4BDD-A036-551D13341274}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{756E719B-29FF-48D7-A281-F1F3CAEDCBC4}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{5FA02C3D-AACA-4481-8880-184B11A8C249}"= Disabled:UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{5944F2CE-5489-4E73-B1C2-CB571137F5B8}"= Disabled:TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"TCP Query User{6E2B55FB-CCC7-4B59-B5EB-633806659D99}C:\\program files\\mozilla firefox\\firefox.exe"= Disabled:UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{6E33F0D4-0408-47CD-8F4C-7286431DA609}C:\\program files\\mozilla firefox\\firefox.exe"= Disabled:TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{D91FA5EE-0215-405D-B06F-54F81E487CB7}"= Disabled:UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{DF40EBF9-88A7-46C5-9D48-21296AAE6042}"= Disabled:TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R2 CTAudSvcService;Creative Audio Service;C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2007-11-26 09:22]
R2 DQLWinService;DQLWinService;"C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe" [2006-09-03 13:32]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys [2007-06-11 13:49]
R3 t3;Sound Blaster X-Fi Xtreme Audio (Vista);C:\Windows\system32\drivers\t3.sys [2008-01-29 03:03]
S2 IntelDHSvcConf;Intel DH Service;"C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe" [2006-05-10 12:13]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;"C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe" [2008-01-06 22:08]
S3 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20070108.003\IDSvix86.sys [2006-12-27 18:48]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-06-11 21:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2795ffd3-5c24-11dc-a37c-806e6f6e6963}]
\shell\AutoRun\command - E:\install.exe

*Newly Created Service* - AD-WATCH_REGISTRY_FILTER
*Newly Created Service* - COMHOST
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-23 14:29:21
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-23 14:30:17
ComboFix-quarantined-files.txt 2008-06-23 18:30:07
ComboFix2.txt 2008-06-23 17:53:48
ComboFix3.txt 2008-06-22 22:58:20

Pre-Run: 165,686,034,432 bytes free
Post-Run: 165,651,218,432 bytes free

236 — E O F — 2008-06-23 00:02:32
Doesn't seem to be working

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\Windows\System32\mktxyohb.dll
    C:\Windows\System32\bqoauodn.dll
    C:\Windows\System32\mqpabfea.dll
    C:\Windows\System32\rpxcxvsi.dll
    C:\Windows\System32\fxolrdtw.dll
    C:\Users\leenbrooke\winlogon.exe
    C:\Users\leenbrooke\748.bat
    E:\install.exe
    C:\Windows\bGVlbmJyb29rZQ
    C:\Windows\System32\netrax05
    C:\Windows\System32\eb10
    C:\Windows\System32\bgi
    C:\Windows\System32\axc
    C:\Windows\System32\1049a
    C:\TEMP\itmp4
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2795ffd3-5c24-11dc-a37c-806e6f6e6963}
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.




Reboot and do this

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Explorer killed successfully DllUnregisterServer procedure not found in C:\Windows\System32\mktxyohb.dll C:\Windows\System32\mktxyohb.dll NOT unregistered. C:\Windows\System32\mktxyohb.dll moved successfully. LoadLibrary failed for C:\Windows\System32\bqoauodn.dll C:\Windows\System32\bqoauodn.dll NOT unregistered. C:\Windows\System32\bqoauodn.dll moved successfully. DllUnregisterServer procedure not found in C:\Windows\System32\mqpabfea.dll C:\Windows\System32\mqpabfea.dll NOT unregistered. C:\Windows\System32\mqpabfea.dll moved successfully. LoadLibrary failed for C:\Windows\System32\rpxcxvsi.dll C:\Windows\System32\rpxcxvsi.dll NOT unregistered. C:\Windows\System32\rpxcxvsi.dll moved successfully. LoadLibrary failed for C:\Windows\System32\fxolrdtw.dll C:\Windows\System32\fxolrdtw.dll NOT unregistered. C:\Windows\System32\fxolrdtw.dll moved successfully. C:\Users\leenbrooke\winlogon.exe moved successfully. C:\Users\leenbrooke\748.bat moved successfully. File move failed. E:\install.exe scheduled to be moved on reboot. C:\Windows\bGVlbmJyb29rZQ moved successfully. C:\Windows\System32\netrax05 moved successfully. C:\Windows\System32\eb10 moved successfully. C:\Windows\System32\bgi moved successfully. C:\Windows\System32\axc moved successfully. C:\Windows\System32\1049a moved successfully. C:\TEMP\itmp4 moved successfully. < HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2795ffd3-5c24-11dc-a37c-806e6f6e6963} > Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2795ffd3-5c24-11dc-a37c-806e6f6e6963}\\ deleted successfully. < purity > < EmptyTemp > File delete failed. C:\Windows\temp\nmsmc_DQLWinService.log scheduled to be deleted on reboot. Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06232008_145336 Files moved on Reboot… File move failed. E:\install.exe scheduled to be moved on reboot. File move failed. C:\Windows\temp\nmsmc_DQLWinService.log scheduled to be moved on reboot. THE other program im gnna run now and log for u just wanted to post this before i loose it or something THANKS!
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-06-23 15:00:40
Computer is in Normal Mode.
——————————————————————————–

– Last 5 Restore Point(s) –
10: 2008-06-23 18:27:26 UTC - RP423 - ComboFix created restore point
9: 2008-06-23 17:50:08 UTC - RP422 - ComboFix created restore point
8: 2008-06-22 23:59:05 UTC - RP421 - Windows Update
7: 2008-06-22 22:49:02 UTC - RP420 - ComboFix created restore point
6: 2008-06-22 18:52:58 UTC - RP419 - Scheduled Checkpoint


– First Restore Point –
1: 2008-06-21 19:53:39 UTC - RP410 - Installed Ad-Aware


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as leenbrooke.exe) ——————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:02:21 PM, on 6/23/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\notepad.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\leenbrooke\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\leenbrooke.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DT HPW] "C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe" -HPW
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [aecb1da8] "rundll32.exe" "C:\Windows\system32\ljnsqjtr.dll",b
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [HPAdvisor] "C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Host Process] C:\Users\leenbrooke\svchost.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2…15035/CTPID.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® Viiv™ Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 10059 bytes

– HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ———–

backup-20080620-155448-974 O4 - HKLM\..\Run: [RE.exe] C:\Program Files\Registry Easy\RE.exe
backup-20080620-183450-664 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
backup-20080620-183450-746 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
backup-20080620-183450-771 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
backup-20080621-135351-755 O2 - BHO: (no name) - {D30E51EA-307E-4EF8-B645-87EF57FA473B} - C:\Windows\system32\mlJBRlKA.dll (file missing)
backup-20080621-135446-114 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
backup-20080621-135446-629 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
backup-20080621-135446-883 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

– File Associations ———————————————————–

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

All drivers whitelisted.


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

R2 CTAudSvcService (Creative Audio Service) - c:\program files\creative\shared files\ctaudsvc.exe
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O4 - HKLM\..\Run: [aecb1da8] "rundll32.exe" "C:\Windows\system32\ljnsqjtr.dll",b


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




Now we need to fix your problems by making a .reg file. Copy the code below into a Notepad file. Name the file as fix.reg, change the "Save as Type" to "All files" and save it on the desktop.

Windows Registry Editor Version 5.00


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4E06327D-0415-475F-898B-6ACFB316073E}"=-

[-HKEY_CLASSES_ROOT\CLSID\{4E06327D-0415-475F-898B-6ACFB316073E}]


Then double click on the fix.reg file, when it prompts to merge click "Yes".




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Reboot and post a new DSS log
Malwarebytes' Anti-Malware 1.18
Database version: 883

3:23:05 PM 6/23/2008
mbam-log-6-23-2008 (15-23-05).txt

Scan type: Quick Scan
Objects scanned: 36328
Time elapsed: 2 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Host Process (Worm.IRCBot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
ALSO
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-06-23 15:23:54
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as leenbrooke.exe) ——————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:24:00 PM, on 6/23/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\leenbrooke\Desktop\dss.exe
C:\Windows\system32\SearchFilterHost.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\LEENBR~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DT HPW] "C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe" -HPW
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [HPAdvisor] "C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2…15035/CTPID.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® Viiv™ Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 9837 bytes

– Files created between 2008-05-23 and 2008-06-23 —————————–

2008-06-23 15:19:16 0 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-06-23 14:27:05 161792 –a—— C:\Windows\swreg.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI