This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] The "Bad Image" Warning

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Everytime I open a new window or program, I get the "Bad Image" message and then once I close the message everything else is okay. I also have this adware I can't remove and it makes my background blue as well as having a link to some random adware removal program.

The error message is: "The application or DLL C:\Windows\system32\msansspc.dll is not a valid windows image. please check this against your installation diskette."

Any help appreciated!

Here you go:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:38:58 AM, on 10/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\uesiuqcr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn1\yt.dll
R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\SSPlus\SAddr1.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\uesiuqcr.exe,
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: getsn32.msiesn - {32FD16DC-537C-4186-9BD6-C718A308342B} - C:\WINDOWS\system32\getsn32.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: (no name) - {C4DFA6F3-1245-41E5-8E60-7D31427F01B3} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [stup.exe] Rundll32.exe C:\PROGRA~1\TENCENT\SSPlus\SPlus1.dll,Rundll32 R
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [VoipStunt] "C:\VOIP\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: UseFlashGet - C:\Program Files\FlashGet Network\Flashget\GetUrl.htm
O8 - Extra context menu item: UseFlashGetDownloadAllLink - C:\Program Files\FlashGet Network\Flashget\GetAllUrl.htm
O8 - Extra context menu item: Ìí¼Óµ½QQ±íÇé - C:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolgate.com/redirect.php (file missing)
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [TBH] SOSO AddressBar Search
O16 - DPF: Yahoo! Blackjack - http://download2.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Dominoes - http://download2.games.yahoo.com/games/clients/y/dot9_x.cab
O16 - DPF: Yahoo! Games Voice Chat - http://presence.games.yahoo.com/yog/y/va1_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O20 - AppInit_DLLs: karna.dat
O22 - SharedTaskScheduler: ablator - {fce1c203-ff2b-4ec1-9983-e2900d29bbd8} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

–
End of file - 9118 bytes
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
sorry, but last night, I downloaded the malware program that some people were recommending others. It worked except now my internet connection does not work on the desktop. Im on the laptop and this wireless connection works. The modem connects, but when I go onto an internet browser, I just get the page cannot be found message.
What program was that This forum clearly states not to follow steps in other peoples threads, its for a valid reason. Bit pointless me helping if you don't actually follow my advice don't you think ?
It was malwarebytes' anti-malware. I did it last night because I was desperate. sorry. I can add a hijackthis if you want by using a flashdrive to bring it over to the laptop.
Okay, I have the hijackthis log and the walware byte's log.

Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:50:40 AM, on 10/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\SBC Self Support Tool\bin\MotiveBrowser.exe
C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE
C:\Program Files\SBC Self Support Tool\bin\mad.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn1\yt.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: (no name) - {C4DFA6F3-1245-41E5-8E60-7D31427F01B3} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [VoipStunt] "C:\VOIP\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: UseFlashGet - C:\Program Files\FlashGet Network\Flashget\GetUrl.htm
O8 - Extra context menu item: UseFlashGetDownloadAllLink - C:\Program Files\FlashGet Network\Flashget\GetAllUrl.htm
O8 - Extra context menu item: Ìí¼Óµ½QQ±íÇé - C:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Blackjack - http://download2.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Dominoes - http://download2.games.yahoo.com/games/clients/y/dot9_x.cab
O16 - DPF: Yahoo! Games Voice Chat - http://presence.games.yahoo.com/yog/y/va1_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O20 - AppInit_DLLs: karna.dat
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

–
End of file - 8329 bytes







Malware Bytes:
Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 5.1.2600 Service Pack 3

10/26/2008 10:10:18 AM
mbam-log-2008-10-26 (10-10-18).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 183837
Time elapsed: 1 hour(s), 0 minute(s), 59 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 46
Registry Values Infected: 11
Registry Data Items Infected: 5
Folders Infected: 3
Files Infected: 25

Memory Processes Infected:
C:\WINDOWS\system32\uesiuqcr.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Memory Modules Infected:
C:\WINDOWS\system32\smwin32.dll (Trojan.FakeAlert) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\tctrl.tweb (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{b1a7c2cf-bf40-4597-8142-7615d74d0cc3} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3084bc3d-c0d6-4a28-a8a4-5857165886ee} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{90b1ecb2-fc3b-49ae-a6bd-f5f11bf5c4ad} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0979850f-6c3e-4294-b225-b3d3c4a6f2a1} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1bb2da5f-b78f-44ea-bda1-771cbe1dec68} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2a4e73c5-ba3c-4391-b7e5-ffe8d3bd6245} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{44a923ca-f430-4f85-9f84-5153ecdb882e} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4e6e21ec-9d72-4164-8a53-74786a467872} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{631e9e48-b066-43da-92ac-6dadf61b173b} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{65c1361c-e696-4af0-9e21-81910193f352} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{77dce805-c8ce-48aa-a47f-bfa6cc7704b3} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8d42769f-07d8-494d-aab4-aa1652c541fa} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a1922071-390c-418d-916d-91209e95d286} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a1f8cd95-cfb3-43d1-a956-63441cc058c1} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a63b46ad-96a7-4a2c-bd8f-8cd097e1593a} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a65f98dd-2360-468c-b76e-b1b84c0d547c} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{ae2aeed0-be1b-4ba2-826e-20d1991081b8} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d7f73787-6206-4bba-bdc0-7cfa9940dbcb} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e770f739-2968-4ed9-a63c-dc1938dc82a2} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0c7c23ef-a848-485b-873c-0ed954731014} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a57e074f-56d8-4a33-8112-aac9693aa909} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{db8b2393-7a6c-4c76-88ce-6b1f6ff6ffe9} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{669751ed-d558-49ae-b01a-3b374cc7910e} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{cfafa83c-855b-4e3d-92b9-a587995b675a} (Rogue.VirusProtect) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\GetModule (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{a0442dfa-1f7e-4dce-b75c-a90993d6e7fc} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{268706f0-841c-446a-b757-8c1ef84527dc} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{32fd16dc-537c-4186-9bd6-c718a308342b} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32fd16dc-537c-4186-9bd6-c718a308342b} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\TBH (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{27861bda-a645-491d-8599-dcab5969dc34} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4cf05127-d66d-4125-b2d9-15909b83842a} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{475a8380-dc57-448b-8d9f-5600df0a8476} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\getsn32.msiesn (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\smwin32.mdr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{db8b2393-7a6c-4c76-88ce-6b1f6ff6ffe9} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0c7c23ef-a848-485b-873c-0ed954731014} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{a57e074f-56d8-4a33-8112-aac9693aa909} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{db8b2393-7a6c-4c76-88ce-6b1f6ff6ffe9} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{669751ed-d558-49ae-b01a-3b374cc7910e} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{fce1c203-ff2b-4ec1-9983-e2900d29bbd8} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\stup.exe (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Desktop) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Trojan.Agent) -> Data: msansspc.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\uesiuqcr.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\uesiuqcr.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\uesiuqcr.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\iCheck (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetModule (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Application Data\Facegame (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\Scrax.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Tencent\SSPlus\SAddr1.dll (Adware.Agent) -> Delete on reboot.
C:\WINDOWS\system32\SSup.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\iCheck\iCheck.exe (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\iCheck\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Application Data\Facegame\Facegame.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\default.htm (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msansspc.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\getsn32.dll (Trojan.Agent) -> Delete on reboot.
C:\Program Files\Tencent\SSPlus\SPlus1.dll (Adware.Agent) -> Delete on reboot.
C:\WINDOWS\system32\delself.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\rs.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smwin32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uesiuqcr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\brastk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\ENCSC-Download.com.2.5.1040.0.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Favorites\Online Security Test.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSehys.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSirxy.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSlubs.log (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\TDSSnmxh.log (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\TDSSoipa.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSqxnr.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSyavu.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\TDSSmxoe.sys (Rootkit.Agent) -> Delete on reboot.
Do this, you will need to use your flash drive

Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program.
  • Under the Custom Scans box at the bottom left put this into it

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root|tds /rs
    C:\Documents and Settings\Brian\%appdata%\Adobe\*.exe

  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
Hello

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
I put it as a file for you to download as well as to see here.

ComboFix 08-10-25.01 - HP_Administrator 2008-10-26 12:10:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.572 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\All Users\Application Data\FlashGetBHO
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlashGetBHO.dll
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlvDetector.exe
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\FlvDetector.ini
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\LiveQuery.exe
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\LiveQuery.ini
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\LiveSupport.exe
C:\Documents and Settings\All Users\Application Data\FlashGetBHO\zlib.dll
C:\Documents and Settings\HP_Administrator\Application Data\BITS
C:\Documents and Settings\HP_Administrator\Application Data\BITS\BITS.ini
C:\Documents and Settings\HP_Administrator\Application Data\BITS\DHTTable.dat
C:\Documents and Settings\HP_Administrator\Application Data\BITS\ProxyList.ini
C:\Documents and Settings\HP_Administrator\Application Data\BITS\UPnP.ini
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\fbk.sts
C:\Program Files\FlashGet Network
C:\Program Files\FlashGet Network\Flashget\Bhocfg.ini
C:\Program Files\FlashGet Network\Flashget\dbtrans_verbose.log
C:\Program Files\FlashGet Network\Flashget\fgoption.ini
C:\Program Files\FlashGet Network\Flashget\Flvdetector.htm
C:\Program Files\FlashGet Network\Flashget\FlvDetector.ini
C:\Program Files\FlashGet Network\Flashget\InmediaInfo.ini
C:\Program Files\FlashGet Network\Flashget\JCCHS.INI
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\0.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\1.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\10.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\11.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\12.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\13.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\14.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\15.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\16.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\17.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\18.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\19.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\2.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\20.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\21.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\3.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\4.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\5.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\6.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\7.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\8.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\9.bmp
C:\Program Files\FlashGet Network\Flashget\modules\garage\Headers\nologin.bmp
C:\Program Files\FlashGet Network\Flashget\P2PCfg.ini
C:\Program Files\FlashGet Network\Flashget\p2spmgr.ini
C:\Program Files\FlashGet Network\Flashget\P4PClientInfo.ini
C:\Program Files\FlashGet Network\Flashget\p4spmgr.ini
C:\Program Files\FlashGet Network\Flashget\Profiles\config.dat
C:\Program Files\FlashGet Network\Flashget\Profiles\tasks.dat
C:\Program Files\FlashGet Network\Flashget\StatInfo.ini
C:\Program Files\FlashGet Network\Flashget\transaction.log
C:\Program Files\TENCENT\SSPlus\SData.dat
C:\Program Files\TENCENT\SSPlus\stdtbh.dat
C:\WINDOWS\dat.txt
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\admshare.dat
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-09-26 to 2008-10-26 )))))))))))))))))))))))))))))))
.

2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-26 03:45 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-26 03:45 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-26 03:42 . 2008-10-26 03:42 d——– C:\Program Files\ERUNT
2008-10-26 03:38 . 2008-10-26 03:38 d——– C:\Program Files\Trend Micro
2008-10-26 01:35 . 2008-10-26 01:35 d——– C:\Documents and Settings\HP_Administrator\Application Data\Uniblue
2008-10-26 01:32 . 2008-10-26 10:25 d——– C:\Program Files\Crawler
2008-10-25 23:25 . 2008-10-25 23:25 d——– C:\Documents and Settings\Administrator\Application Data\Spyware Terminator
2008-10-25 23:15 . 2008-10-26 01:30 d——– C:\Program Files\WinClamAVShield
2008-10-25 23:14 . 2008-10-26 10:19 d——– C:\Program Files\Spyware Terminator
2008-10-25 23:14 . 2008-10-26 10:19 d——– C:\Documents and Settings\HP_Administrator\Application Data\Spyware Terminator
2008-10-25 23:14 . 2008-10-26 03:33 d——– C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-10-25 23:14 . 2008-10-25 23:14 141,312 –a—— C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-10-25 19:41 . 2008-10-25 19:41 d——– C:\Program Files\Alwil Software
2008-10-25 12:18 . 2008-10-25 12:18 164 –a—— C:\WINDOWS\system32\TDSSmupe.dat
2008-10-23 20:33 . 2008-10-15 12:34 337,408 ——— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 08:22 . 2008-09-15 08:12 1,846,400 ——— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 08:22 . 2008-09-08 06:41 333,824 ——— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 08:21 . 2008-08-14 06:11 2,189,184 ——— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 08:21 . 2008-08-14 06:09 2,145,280 ——— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 08:21 . 2008-08-14 05:33 2,066,048 ——— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 08:21 . 2008-08-14 05:33 2,023,936 ——— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-12 17:09 . 2008-10-12 17:09 d——– C:\Program Files\Combined Community Codec Pack
2008-10-12 16:53 . 2008-10-12 17:09 d——– C:\Program Files\VideoLAN
2008-10-10 21:36 . 2008-10-10 21:36 d——– C:\Documents and Settings\All Users\Application Data\acccore
2008-10-10 00:19 . 2008-10-10 00:19 d——– C:\Program Files\eRightSoft
2008-10-09 22:51 . 2008-10-09 23:15 d——– C:\Program Files\Red Kawa
2008-10-09 22:51 . 2008-10-09 22:51 d——– C:\Program Files\AviSynth 2.5
2008-10-09 22:32 . 2005-02-27 21:48 356,352 –a—— C:\WINDOWS\system32\RealMediaSplitter.ax
2008-10-09 21:38 . 2008-10-09 21:38 d——– C:\ConverterOutput
2008-10-09 21:38 . 2007-03-25 00:51 3,049,984 –a—— C:\WINDOWS\system32\libavcodec.dll
2008-10-09 21:38 . 2007-03-25 21:40 2,174,976 –a—— C:\WINDOWS\system32\ffdshow.ax
2008-10-09 21:38 . 2007-03-25 00:51 404,480 –a—— C:\WINDOWS\system32\libmplayer.dll
2008-10-09 21:38 . 2003-03-30 20:08 372,736 –a—— C:\WINDOWS\system32\xvid.ax
2008-10-09 21:38 . 2007-01-01 05:30 200,704 –a—— C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-10-09 21:38 . 2007-03-25 00:51 114,688 –a—— C:\WINDOWS\system32\libmpeg2_ff.dll
2008-10-09 21:38 . 2004-09-10 13:50 34,820 –a—— C:\WINDOWS\system32\ffdshow.reg
2008-10-09 21:37 . 2008-10-09 23:29 d——– C:\Program Files\Cucusoft
2008-10-09 21:34 . 2008-10-09 23:50 d——– C:\Program Files\Handbrake
2008-10-09 20:26 . 2008-10-25 19:42 d——– C:\Documents and Settings\HP_Administrator\Application Data\BitTorrent
2008-10-09 20:25 . 2008-10-09 20:25 d——– C:\Program Files\DNA
2008-10-09 20:25 . 2008-10-09 20:26 d——– C:\Program Files\BitTorrent
2008-10-09 20:25 . 2008-10-26 12:16 d——– C:\Documents and Settings\HP_Administrator\Application Data\DNA
2008-10-05 00:15 . 2008-10-05 00:15 d——– C:\Program Files\iTunes
2008-10-05 00:15 . 2008-10-05 00:15 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-05 00:12 . 2008-10-01 13:01 32,000 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-25 23:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-25 18:06 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\FrostWire
2008-10-24 20:30 ——— d—–w C:\Program Files\AIM6
2008-10-24 20:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-10-24 07:07 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-15 22:18 60,512 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2008-10-13 02:08 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Printer Info Cache
2008-10-13 02:08 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Image Zone Express
2008-10-12 23:41 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Yahoo!
2008-10-05 19:09 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
2008-10-05 04:15 ——— d—–w C:\Program Files\iPod
2008-09-24 22:09 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-09-10 03:37 ——— d—–w C:\Program Files\QuickTime
2008-09-10 03:16 ——— d—–w C:\Program Files\Bonjour
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-05 03:43 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\U3
2006-11-28 23:49 320 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2006-06-24 15:13 251 —-a-w C:\Program Files\wt3d.ini
2006-05-03 09:06 163,328 –sh–r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 –sh–r C:\WINDOWS\system32\msfDX.dll
2008-03-16 12:30 216,064 –sh–r C:\WINDOWS\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"VoipStunt"="C:\VOIP\VoipStunt.exe" [2007-12-19 8824112]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-10-17 49960]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-10-09 289088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-27 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-09 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-10-25 1783808]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-13 C:\WINDOWS\system32\narrator.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T Self Support Tool.lnk
backup=C:\WINDOWS\pss\AT&T Self Support Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Color Calibration.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Color Calibration.lnk
backup=C:\WINDOWS\pss\Color Calibration.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MagicTune 3.6.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MagicTune 3.6.lnk
backup=C:\WINDOWS\pss\MagicTune 3.6.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk
backup=C:\WINDOWS\pss\SBC Self Support Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=C:\WINDOWS\pss\Updates From HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-10-17 10:45 49960 C:\Program Files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMAScheduler]
–a—— 2005-11-01 06:01 90112 c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2005-08-05 17:56 64512 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2005-05-12 03:12 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
–a—— 2005-11-09 13:29 249856 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD08]
–a—— 2005-06-01 19:35 49152 c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a–c— 2004-07-27 20:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-10-01 18:57 289576 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
–a—— 2005-02-02 16:44 61440 C:\hp\KBD\kbd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
–a—— 2006-11-13 23:17 380928 C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-05-09 22:50 7311360 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
–a–c— 2006-06-06 08:54 81920 C:\NVIDIA Corporation\nTune\nTuneCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2006-05-09 22:50 86016 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrSmartMonitor]
–a—— 2005-12-20 07:34 368640 C:\Program Files\PC-Doctor 5 for Windows\PcdSmartMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2005-07-22 19:14 237568 C:\WINDOWS\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
–a—— 2004-12-13 23:23 663552 C:\WINDOWS\CREATOR\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-03-27 22:04 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
–a—— 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipStunt]
–a—— 2007-12-19 00:23 8824112 C:\VOIP\voipstunt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-08-30 18:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
–a—— 2006-07-21 17:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
–a—— 2007-10-26 16:42 509224 C:\PROGRA~1\Yahoo!\YOP\yop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlwaysReady Power Message APP]
–a—— 2005-08-02 20:19 77312 C:\WINDOWS\arpwrmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2006-05-09 22:50 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2006-01-23 06:53 15969280 C:\WINDOWS\RTHDCPL.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YPCService"=3 (0x3)
"NVSvc"=2 (0x2)
"nTuneService"=2 (0x2)
"iPod Service"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"ARSVC"=2 (0x2)
"Apple Mobile Device"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\yserver.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\VOIP\\VoipStunt.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=

R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-10-25 141312]
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{788e6454-b783-11dc-944d-00173123d0af}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1cb0076-e091-11db-937b-00173123d0af}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-10-24 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe []

2008-10-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{65F8A3D2-4C22-4A33-9633-73167EAEEC45} - (no file)
MSConfigStartUp-BJCFD - C:\Program Files\BroadJump\Client Foundation\CFD.exe
MSConfigStartUp-ccApp - C:\Program Files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-DISCover - C:\Program Files\DISC\DISCover.exe
MSConfigStartUp-DiscUpdateManager - C:\Program Files\DISC\DiscUpdateMgr.exe
MSConfigStartUp-HostManager - C:\Program Files\Common Files\AOL\1151512646\ee\AOLSoftware.exe
MSConfigStartUp-MsnMsgr - C:\Program Files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-PlaxoUpdate - C:\Program Files\Plaxo\2.11.1.5\PlaxoHelper.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\sdz096v1.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30401.0.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
.
——- File Associations ——-
.
chm.file="hh.exe" %1
JSEFile=NOTEPAD.EXE %1
txtfile=C:\WINDOWS\notepad.exe %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-26 12:26:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\~DF62F0.tmp 49152 bytes
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\~DF6415.tmp 512 bytes

scan completed successfully
hidden files: 2

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmxoe.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-10-26 12:31:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-26 16:31:03

Pre-Run: 133,361,573,888 bytes free
Post-Run: 136,463,486,976 bytes free

396 — E O F — 2008-10-24 07:01:14

Attachments:

Hello


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\windows\system32\drivers\TDSSmxoe.sys

Folder::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{788e6454-b783-11dc-944d-00173123d0af}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1cb0076-e091-11db-937b-00173123d0af}]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDSSserv.sys]



Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Also run a quick scan with MBAM and post that log
Here it is:

ComboFix 08-10-25.01 - HP_Administrator 2008-10-26 14:17:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.553 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt.txt
* Created a new restore point

FILE ::
C:\windows\system32\drivers\TDSSmxoe.sys
.

((((((((((((((((((((((((( Files Created from 2008-09-26 to 2008-10-26 )))))))))))))))))))))))))))))))
.

2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-26 03:45 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-26 03:45 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-26 03:42 . 2008-10-26 03:42 d——– C:\Program Files\ERUNT
2008-10-26 03:38 . 2008-10-26 03:38 d——– C:\Program Files\Trend Micro
2008-10-26 01:35 . 2008-10-26 01:35 d——– C:\Documents and Settings\HP_Administrator\Application Data\Uniblue
2008-10-26 01:32 . 2008-10-26 10:25 d——– C:\Program Files\Crawler
2008-10-25 23:25 . 2008-10-25 23:25 d——– C:\Documents and Settings\Administrator\Application Data\Spyware Terminator
2008-10-25 23:15 . 2008-10-26 01:30 d——– C:\Program Files\WinClamAVShield
2008-10-25 23:14 . 2008-10-26 10:19 d——– C:\Program Files\Spyware Terminator
2008-10-25 23:14 . 2008-10-26 10:19 d——– C:\Documents and Settings\HP_Administrator\Application Data\Spyware Terminator
2008-10-25 23:14 . 2008-10-26 03:33 d——– C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-10-25 23:14 . 2008-10-25 23:14 141,312 –a—— C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-10-25 19:41 . 2008-10-25 19:41 d——– C:\Program Files\Alwil Software
2008-10-25 12:18 . 2008-10-25 12:18 164 –a—— C:\WINDOWS\system32\TDSSmupe.dat
2008-10-23 20:33 . 2008-10-15 12:34 337,408 ——— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 08:22 . 2008-09-15 08:12 1,846,400 ——— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 08:22 . 2008-09-08 06:41 333,824 ——— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 08:21 . 2008-08-14 06:11 2,189,184 ——— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 08:21 . 2008-08-14 06:09 2,145,280 ——— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 08:21 . 2008-08-14 05:33 2,066,048 ——— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 08:21 . 2008-08-14 05:33 2,023,936 ——— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-12 17:09 . 2008-10-12 17:09 d——– C:\Program Files\Combined Community Codec Pack
2008-10-12 16:53 . 2008-10-12 17:09 d——– C:\Program Files\VideoLAN
2008-10-10 21:36 . 2008-10-10 21:36 d——– C:\Documents and Settings\All Users\Application Data\acccore
2008-10-10 00:19 . 2008-10-10 00:19 d——– C:\Program Files\eRightSoft
2008-10-09 22:51 . 2008-10-09 23:15 d——– C:\Program Files\Red Kawa
2008-10-09 22:51 . 2008-10-09 22:51 d——– C:\Program Files\AviSynth 2.5
2008-10-09 22:32 . 2005-02-27 21:48 356,352 –a—— C:\WINDOWS\system32\RealMediaSplitter.ax
2008-10-09 21:38 . 2008-10-09 21:38 d——– C:\ConverterOutput
2008-10-09 21:38 . 2007-03-25 00:51 3,049,984 –a—— C:\WINDOWS\system32\libavcodec.dll
2008-10-09 21:38 . 2007-03-25 21:40 2,174,976 –a—— C:\WINDOWS\system32\ffdshow.ax
2008-10-09 21:38 . 2007-03-25 00:51 404,480 –a—— C:\WINDOWS\system32\libmplayer.dll
2008-10-09 21:38 . 2003-03-30 20:08 372,736 –a—— C:\WINDOWS\system32\xvid.ax
2008-10-09 21:38 . 2007-01-01 05:30 200,704 –a—— C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-10-09 21:38 . 2007-03-25 00:51 114,688 –a—— C:\WINDOWS\system32\libmpeg2_ff.dll
2008-10-09 21:38 . 2004-09-10 13:50 34,820 –a—— C:\WINDOWS\system32\ffdshow.reg
2008-10-09 21:37 . 2008-10-09 23:29 d——– C:\Program Files\Cucusoft
2008-10-09 21:34 . 2008-10-09 23:50 d——– C:\Program Files\Handbrake
2008-10-09 20:26 . 2008-10-25 19:42 d——– C:\Documents and Settings\HP_Administrator\Application Data\BitTorrent
2008-10-09 20:25 . 2008-10-09 20:25 d——– C:\Program Files\DNA
2008-10-09 20:25 . 2008-10-09 20:26 d——– C:\Program Files\BitTorrent
2008-10-09 20:25 . 2008-10-26 14:17 d——– C:\Documents and Settings\HP_Administrator\Application Data\DNA
2008-10-05 00:15 . 2008-10-05 00:15 d——– C:\Program Files\iTunes
2008-10-05 00:15 . 2008-10-05 00:15 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-05 00:12 . 2008-10-01 13:01 32,000 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-25 23:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-25 18:06 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\FrostWire
2008-10-24 20:30 ——— d—–w C:\Program Files\AIM6
2008-10-24 20:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-10-24 07:07 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-15 22:18 60,512 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2008-10-13 02:08 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Printer Info Cache
2008-10-13 02:08 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Image Zone Express
2008-10-12 23:41 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Yahoo!
2008-10-05 19:09 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
2008-10-05 04:15 ——— d—–w C:\Program Files\iPod
2008-10-03 17:41 6,066,176 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-24 22:09 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-12 01:31 61,440 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2008-09-12 01:31 45,056 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2008-09-12 01:31 44,032 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2008-09-12 01:31 40,960 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2008-09-12 01:31 341,048 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2008-09-12 01:31 32,768 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2008-09-12 01:31 32,768 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2008-09-12 01:31 217,088 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
2008-09-12 01:31 163,840 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2008-09-10 03:37 ——— d—–w C:\Program Files\QuickTime
2008-09-10 03:16 ——— d—–w C:\Program Files\Bonjour
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-05 03:43 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\U3
2008-08-29 14:18 87,336 —-a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 13:53 61,440 —-a-w C:\WINDOWS\system32\dnssd.dll
2008-08-27 08:24 3,593,216 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-25 08:38 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-25 08:37 70,656 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-23 05:56 635,848 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-14 10:11 2,189,184 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 10:04 138,496 ——w C:\WINDOWS\system32\dllcache\afd.sys
2008-08-14 09:33 2,066,048 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2006-11-28 23:49 320 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2006-06-24 15:13 251 —-a-w C:\Program Files\wt3d.ini
2006-05-03 09:06 163,328 –sh–r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 –sh–r C:\WINDOWS\system32\msfDX.dll
2008-03-16 12:30 216,064 –sh–r C:\WINDOWS\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"VoipStunt"="C:\VOIP\VoipStunt.exe" [2007-12-19 8824112]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-10-17 49960]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-10-09 289088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-27 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-09 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-10-25 1783808]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-13 C:\WINDOWS\system32\narrator.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T Self Support Tool.lnk
backup=C:\WINDOWS\pss\AT&T Self Support Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Color Calibration.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Color Calibration.lnk
backup=C:\WINDOWS\pss\Color Calibration.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MagicTune 3.6.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MagicTune 3.6.lnk
backup=C:\WINDOWS\pss\MagicTune 3.6.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk
backup=C:\WINDOWS\pss\SBC Self Support Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=C:\WINDOWS\pss\Updates From HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-10-17 10:45 49960 C:\Program Files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMAScheduler]
–a—— 2005-11-01 06:01 90112 c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2005-08-05 17:56 64512 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2005-05-12 03:12 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
–a—— 2005-11-09 13:29 249856 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD08]
–a—— 2005-06-01 19:35 49152 c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a–c— 2004-07-27 20:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-10-01 18:57 289576 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
–a—— 2005-02-02 16:44 61440 C:\hp\KBD\kbd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
–a—— 2006-11-13 23:17 380928 C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-05-09 22:50 7311360 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
–a–c— 2006-06-06 08:54 81920 C:\NVIDIA Corporation\nTune\nTuneCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2006-05-09 22:50 86016 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrSmartMonitor]
–a—— 2005-12-20 07:34 368640 C:\Program Files\PC-Doctor 5 for Windows\PcdSmartMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2005-07-22 19:14 237568 C:\WINDOWS\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
–a—— 2004-12-13 23:23 663552 C:\WINDOWS\CREATOR\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-03-27 22:04 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
–a—— 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipStunt]
–a—— 2007-12-19 00:23 8824112 C:\VOIP\voipstunt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-08-30 18:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
–a—— 2006-07-21 17:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
–a—— 2007-10-26 16:42 509224 C:\PROGRA~1\Yahoo!\YOP\yop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlwaysReady Power Message APP]
–a—— 2005-08-02 20:19 77312 C:\WINDOWS\arpwrmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2006-05-09 22:50 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2006-01-23 06:53 15969280 C:\WINDOWS\RTHDCPL.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YPCService"=3 (0x3)
"NVSvc"=2 (0x2)
"nTuneService"=2 (0x2)
"iPod Service"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"ARSVC"=2 (0x2)
"Apple Mobile Device"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\yserver.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\VOIP\\VoipStunt.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=

R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-10-25 141312]
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [ ]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder

2008-10-24 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe []

2008-10-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-26 14:18:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmxoe.sys"
.
Completion time: 2008-10-26 14:19:03
ComboFix-quarantined-files.txt 2008-10-26 18:18:57
ComboFix2.txt 2008-10-26 16:31:07

Pre-Run: 136,401,625,088 bytes free
Post-Run: 136,386,273,280 bytes free

301 — E O F — 2008-10-24 07:01:14


















Here is the MBAM:

Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 5.1.2600 Service Pack 3

10/26/2008 2:45:17 PM
mbam-log-2008-10-26 (14-45-17).txt

Scan type: Quick Scan
Objects scanned: 55894
Time elapsed: 8 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
Here is the report.txt:


SDFix: Version 1.237
Run by [removed] on Sun 10/26/2008 at 03:07 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\wiaservv.log - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-26 16:41:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSmxoe.sys"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules]
"TDSSserv"="\systemroot\system32\drivers\TDSSmxoe.sys"
"TDSSl"="\systemroot\system32\TDSSoipa.dll"
"tdssservers"="\systemroot\system32\TDSSmupe.dat"
"tdssmain"="\systemroot\system32\TDSSirxy.dll"
"tdsslog"="\systemroot\system32\TDSSyavu.dll"
"tdssadw"="\systemroot\system32\TDSSncur.dll"
"tdssinit"="\systemroot\system32\TDSSqxnr.dll"
"tdssurls"="\systemroot\system32\TDSSnmxh.log"
"tdsspanels"="\systemroot\system32\TDSSsahc.dll"
"tdssserf"="\systemroot\system32\TDSSehys.dll"
"tdsserrors"="\systemroot\system32\TDSSwghd.log"
"TDSSproc"="\systemroot\system32\TDSSlubs.log"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv.sys]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSmxoe.sys"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules]
"TDSSserv"="\systemroot\system32\drivers\TDSSmxoe.sys"
"TDSSl"="\systemroot\system32\TDSSoipa.dll"
"tdssservers"="\systemroot\system32\TDSSmupe.dat"
"tdssmain"="\systemroot\system32\TDSSirxy.dll"
"tdsslog"="\systemroot\system32\TDSSyavu.dll"
"tdssadw"="\systemroot\system32\TDSSncur.dll"
"tdssinit"="\systemroot\system32\TDSSqxnr.dll"
"tdssurls"="\systemroot\system32\TDSSnmxh.log"
"tdsspanels"="\systemroot\system32\TDSSsahc.dll"
"tdssserf"="\systemroot\system32\TDSSehys.dll"
"tdsserrors"="\systemroot\system32\TDSSwghd.log"
"TDSSproc"="\systemroot\system32\TDSSlubs.log"

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\yserver.exe"="C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\yserver.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\VOIP\\VoipStunt.exe"="C:\\VOIP\\VoipStunt.exe:*:Enabled:VoipStunt"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\FrostWire\\FrostWire.exe"="C:\\Program Files\\FrostWire\\FrostWire.exe:*:Enabled:FrostWire"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Fri 23 Jun 2006 211 A.SHR — "C:\BOOT.BAK"
Wed 3 May 2006 163,328 ..SHR — "C:\WINDOWS\system32\flvDX.dll"
Wed 21 Feb 2007 31,232 ..SHR — "C:\WINDOWS\system32\msfDX.dll"
Sun 16 Mar 2008 216,064 ..SHR — "C:\WINDOWS\system32\nbDX.dll"
Mon 16 Apr 2007 16 …H. — "C:\WINDOWS\system32\sdmyqru.dll"
Mon 3 Jul 2006 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0001.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0003.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0117.tmp"
Sat 10 Mar 2007 28,160 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0179.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0339.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0359.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0423.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0456.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0637.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0738.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0753.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0762.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0875.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0885.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL0924.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1021.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1150.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1238.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1251.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1276.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1308.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1315.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1412.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1432.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1452.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1544.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1554.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1581.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1582.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1676.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1867.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1868.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL1920.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2001.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2002.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2112.tmp"
Sat 10 Mar 2007 28,160 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2178.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2180.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2205.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2232.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2250.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2326.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2337.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2451.tmp"
Thu 28 Sep 2006 57,856 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2469.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2607.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2740.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2750.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2754.tmp"
Sat 10 Mar 2007 28,160 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2853.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2865.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL2918.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3131.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3270.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3281.tmp"
Sat 10 Mar 2007 29,696 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3339.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3365.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3474.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3577.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3636.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3768.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3843.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3847.tmp"
Sat 10 Mar 2007 29,184 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL3960.tmp"
Sat 10 Mar 2007 28,672 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\~WRL4044.tmp"
Wed 10 Jan 2007 27,648 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0003.tmp"
Sat 10 Mar 2007 25,088 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0004.tmp"
Wed 19 Jul 2006 11,168 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0005.tmp"
Thu 11 Jan 2007 27,648 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0006.tmp"
Mon 8 Sep 2008 41,984 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0007.tmp"
Wed 2 Jan 2008 76,800 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0033.tmp"
Wed 25 Apr 2007 25,088 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0071.tmp"
Tue 1 Jan 2008 50,688 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0134.tmp"
Tue 1 Jan 2008 32,256 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0136.tmp"
Wed 2 Jan 2008 70,656 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0139.tmp"
Wed 2 Jan 2008 68,096 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0147.tmp"
Wed 2 Jan 2008 75,264 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0161.tmp"
Sat 13 Sep 2008 43,008 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0238.tmp"
Wed 2 Jan 2008 64,000 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0280.tmp"
Tue 1 Jan 2008 50,176 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0284.tmp"
Tue 3 Jun 2008 2,557,952 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0285.tmp"
Tue 1 Jan 2008 31,232 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0315.tmp"
Thu 11 Jan 2007 26,624 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0316.tmp"
Sat 13 Sep 2008 42,496 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0331.tmp"
Wed 25 Apr 2007 25,088 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0348.tmp"
Thu 12 Jun 2008 25,600 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0359.tmp"
Mon 31 Dec 2007 25,088 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0387.tmp"
Tue 1 Jan 2008 53,248 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0509.tmp"
Wed 2 Jan 2008 73,216 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0637.tmp"
Tue 1 Jan 2008 34,304 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0650.tmp"
Tue 3 Jun 2008 3,669,504 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0693.tmp"
Tue 1 Jan 2008 56,320 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0751.tmp"
Thu 11 Jan 2007 26,112 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0788.tmp"
Tue 3 Jun 2008 3,719,680 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0866.tmp"
Tue 1 Jan 2008 59,392 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0896.tmp"
Sun 11 Mar 2007 26,624 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0905.tmp"
Tue 3 Jun 2008 2,557,952 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0966.tmp"
Tue 1 Jan 2008 56,320 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0987.tmp"
Tue 1 Jan 2008 53,760 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1003.tmp"
Tue 1 Jan 2008 52,224 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1051.tmp"
Tue 1 Jan 2008 43,008 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1059.tmp"
Wed 25 Apr 2007 25,088 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1136.tmp"
Thu 11 Jan 2007 25,088 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1223.tmp"
Tue 1 Jan 2008 60,928 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1305.tmp"
Wed 2 Jan 2008 68,608 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1363.tmp"
Tue 1 Jan 2008 45,056 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1405.tmp"
Sun 11 Mar 2007 27,648 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1455.tmp"
Sat 13 Sep 2008 42,496 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1515.tmp"
Sat 10 Mar 2007 25,600 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1587.tmp"
Tue 1 Jan 2008 56,832 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1597.tmp"
Wed 2 Jan 2008 72,192 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1650.tmp"
Tue 1 Jan 2008 58,880 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1658.tmp"
Wed 2 Jan 2008 65,024 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1792.tmp"
Tue 3 Jun 2008 3,153,920 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1808.tmp"
Tue 1 Jan 2008 28,672 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1839.tmp"
Wed 2 Jan 2008 75,776 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1848.tmp"
Tue 1 Jan 2008 46,080 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1850.tmp"
Tue 1 Jan 2008 45,568 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1854.tmp"
Tue 1 Jan 2008 58,880 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1932.tmp"
Wed 2 Jan 2008 72,704 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL1996.tmp"
Wed 2 Jan 2008 73,216 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2003.tmp"
Tue 1 Jan 2008 59,392 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2030.tmp"
Tue 1 Jan 2008 56,832 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2050.tmp"
Tue 1 Jan 2008 29,696 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2067.tmp"
Wed 2 Jan 2008 70,144 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2089.tmp"
Tue 3 Jun 2008 3,828,736 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2100.tmp"
Tue 1 Jan 2008 53,760 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2121.tmp"
Thu 14 Dec 2006 24,576 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2126.tmp"
Tue 3 Jun 2008 2,628,608 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2191.tmp"
Sat 13 Sep 2008 43,008 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2276.tmp"
Tue 1 Jan 2008 48,128 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2298.tmp"
Tue 1 Jan 2008 56,832 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2328.tmp"
Sun 11 Mar 2007 27,648 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2363.tmp"
Thu 11 Jan 2007 25,600 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2405.tmp"
Tue 3 Jun 2008 3,028,992 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2415.tmp"
Tue 1 Jan 2008 30,720 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2454.tmp"
Tue 1 Jan 2008 44,544 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2557.tmp"
Sat 10 Mar 2007 25,600 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2587.tmp"
Wed 2 Jan 2008 67,584 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2661.tmp"
Tue 1 Jan 2008 52,224 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2677.tmp"
Wed 25 Apr 2007 24,064 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2680.tmp"
Wed 2 Jan 2008 75,776 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2708.tmp"
Thu 11 Jan 2007 25,600 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2729.tmp"
Tue 1 Jan 2008 56,832 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2750.tmp"
Tue 3 Jun 2008 3,375,104 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2775.tmp"
Thu 11 Jan 2007 26,624 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2859.tmp"
Wed 2 Jan 2008 64,000 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2879.tmp"
Tue 1 Jan 2008 27,136 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL2937.tmp"
Tue 1 Jan 2008 28,160 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3012.tmp"
Thu 11 Jan 2007 24,576 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3039.tmp"
Thu 12 Jun 2008 24,576 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3165.tmp"
Wed 2 Jan 2008 72,704 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3203.tmp"
Sun 11 Mar 2007 27,136 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3237.tmp"
Tue 1 Jan 2008 58,880 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3246.tmp"
Tue 1 Jan 2008 48,128 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3272.tmp"
Thu 11 Jan 2007 25,088 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3282.tmp"
Sun 11 Mar 2007 27,136 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3327.tmp"
Mon 31 Dec 2007 24,064 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3328.tmp"
Tue 1 Jan 2008 42,496 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3370.tmp"
Tue 1 Jan 2008 54,272 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3440.tmp"
Tue 1 Jan 2008 50,176 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3450.tmp"
Tue 1 Jan 2008 31,232 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3484.tmp"
Tue 1 Jan 2008 54,272 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3500.tmp"
Wed 2 Jan 2008 64,000 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3547.tmp"
Tue 1 Jan 2008 52,224 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3552.tmp"
Tue 1 Jan 2008 61,952 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3605.tmp"
Wed 2 Jan 2008 64,512 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3614.tmp"
Tue 1 Jan 2008 31,232 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3659.tmp"
Wed 2 Jan 2008 70,144 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3666.tmp"
Sat 10 Mar 2007 25,600 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3716.tmp"
Thu 11 Jan 2007 26,112 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3718.tmp"
Tue 1 Jan 2008 60,928 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3737.tmp"
Sun 11 Mar 2007 26,112 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3764.tmp"
Wed 2 Jan 2008 73,728 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3765.tmp"
Wed 2 Jan 2008 70,144 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3786.tmp"
Tue 1 Jan 2008 31,744 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3787.tmp"
Tue 1 Jan 2008 57,856 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3792.tmp"
Sat 13 Sep 2008 43,008 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3843.tmp"
Wed 2 Jan 2008 69,120 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3864.tmp"
Tue 1 Jan 2008 58,880 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3906.tmp"
Wed 2 Jan 2008 70,144 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3928.tmp"
Sat 13 Sep 2008 41,984 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3962.tmp"
Wed 2 Jan 2008 73,216 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3968.tmp"
Thu 12 Jun 2008 24,064 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL3990.tmp"
Wed 25 Apr 2007 24,576 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL4025.tmp"
Wed 2 Jan 2008 72,192 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL4036.tmp"
Tue 3 Jun 2008 5,206,016 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL4037.tmp"
Wed 25 Apr 2007 25,600 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL4089.tmp"
Sun 26 Jun 2005 616,448 ..SHR — "C:\Program Files\eRightSoft\SUPER\cygwin1.dll"
Tue 21 Jun 2005 45,568 ..SHR — "C:\Program Files\eRightSoft\SUPER\cygz.dll"
Fri 10 Oct 2008 72,704 ..SHR — "C:\Program Files\eRightSoft\SUPER\Setup.exe"
Sun 9 Dec 2007 480 A..H. — "C:\Program Files\InterActual\InterActual Player\itiA7.tmp"
Tue 4 Jun 2002 84,992 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
Tue 4 Jun 2002 44,032 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
Mon 9 Dec 2002 73,766 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
Mon 9 Dec 2002 65,575 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
Sun 9 Jun 2002 36,864 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll"
Tue 4 Jun 2002 20,480 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
Mon 9 Dec 2002 102,437 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll"
Mon 9 Dec 2002 176,165 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
Mon 9 Dec 2002 208,935 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
Mon 9 Dec 2002 217,127 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
Sun 9 Jun 2002 40,448 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll"
Sat 3 Nov 2001 225,280 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
Tue 10 Apr 2001 225,280 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
Fri 20 Feb 2004 232,960 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
Sun 9 Jun 2002 525,824 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll"
Mon 9 Dec 2002 245,805 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll"
Mon 9 Dec 2002 45,093 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll"
Mon 9 Dec 2002 98,341 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll"
Mon 9 Dec 2002 94,247 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll"
Mon 9 Dec 2002 90,151 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll"
Mon 9 Dec 2002 102,439 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
Sun 9 Jun 2002 49,152 …HR — "C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll"
Thu 20 Mar 2008 5,632 ..SHR — "C:\Program Files\eRightSoft\SUPER\spk\1stRun.exe"
Sun 26 Oct 2008 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\c3c51eedc7427a3e31252078c1ba6da4\BIT3.tmp"
Thu 7 Dec 2006 3,096,576 A..H. — "C:\Documents and Settings\HP_Administrator\Application Data\U3\temp\Launchpad Removal.exe"

Finished!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI