This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Clicker.TQR, Trojan Clicker.SXT

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,
I believe I am infected with some sort of virus, I have been experiencing some mouse click noises, beeps, and voices saying "Congratulations", with the occasional pop up and an avg virus alert. It also causes the window I am currently viewing to become deselected(?) it makes typing a little difficult. Other than these symptoms, the computer seems no different from before the infection.

I ran a few anti spyware programs but nothing seems to help. I had only the free versions of AVG and Ad-Aware installed before, but I just recently installed Spybot - Search & Destroy and Malwarebytes….not sure if that was a bad thing to do :unsure:

Please let me know if i have done anything wrong, This is my first time posting and I may have missed a rule or two.

Here are the Hijackthis log and Malwarebytes log.
Thanks for your time.

Logfile of HijackThis v1.99.1
Scan saved at 3:24:27 AM, on 11/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\WINDOWS\System32\svchost.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Smart Start UP] C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe /Automation
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\RunOnce: [NoIE4StubProcessing] C:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {E85362EF-40D4-4E5D-BE07-D6B036CCA277} (GoPets Control) - https://secure.gopetslive.com/dev/gopets.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Procedure Manager(TPM) (RPCM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Speech\csvde.exe (file missing)



——————————————-

Malwarebytes' Anti-Malware 1.30
Database version: 1368
Windows 5.1.2600 Service Pack 2

11/6/2008 2:59:11 AM
mbam-log-2008-11-06 (02-59-06).txt

Scan type: Quick Scan
Objects scanned: 76456
Time elapsed: 17 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\HP_Administrator\Application Data\AntispywareBot (Rogue.AntiSpywareBot) -> No action taken.

Files Infected:
C:\WINDOWS\system32\EvxqIl61.exe.a_a (Trojan.Agent) -> No action taken.

———-

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed.


Hi dewgerbil

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
If you can do these things, everything should go smoothly.
  • If you're using XP, you'll need Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
  • If you're using Vista, it will be necessary to right click all tools we use and select —-> Run as Admistrator

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


OK, you've got Malwarbytes' Anti-Malware, but you didn't run it correctly, so it didn't try to remove what it found.

Re-run Malwarebytes' Anti-Malware using the instructions below. I've higlighted in red the important points.

First

I need you to disable Spybot S&D Teatimer, as it will interfere with what we're trying to do.

To disable Spybot S&D TeaTimer

First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
Second step:
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go To the bottom of the Vertical Panel on the Left, Click Tools
  • then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.

Then

  • Click on the Malwarebytes' Anti-Malware icon to launch the programme.
    • Click the Updates tab.
    • Click Check for Updates and allow the programme to download the latest definitions. (this is important)
  • Click the Scanner tab.
    • Check Perform Full Scan.
    • Click Scan and wait for the scan to complete.
    • When the scan is complete, click OK, then Show Results.
    • Ensure all items are checked then click Remove Selected.
    • A box will pop-up telling you that files have been quarantined.
    • A log will pop-up.
  • Post the log in your next reply please.

You can also access the log by doing the following
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open

Next

  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.

Then

I need you to run an online scan for me

  • Please go to Kaspersky Online Scanner.
  • Read through the requirements and privacy statement and click on the Accept button.
  • It will start downloading and installing the scanner and virus definitions.
    • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they're not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers and other potentially dangerous programs.
    • Archives.
    • Mail databases.
  • Under Scan, click on My Computer.
  • Once the scan is complete, it will display the results.
    • Click on View Scan Report.
  • You will see a list of infected items.
    • Click the Save Report As… button (see red arrow below)

      [external image: Posted Image]
    • In the Save as… prompt, select Desktop
    • In the File name box, name the file KAVScan
    • In the Save as type prompt, select Text file (see below)

      [external image: Posted Image]
    • Copy and paste that information in your next post please.

Finally

Run a new scan with HJT and post me the log please.

Summary of the logs I need from you in your next post:
  • MBAM log
  • Kaspersky log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
Hi Gary R, Here are the logs you requested. Malwarebytes' Anti-Malware 1.30 Database version: 1370 Windows 5.1.2600 Service Pack 2 11/6/2008 8:48:07 PM mbam-log-2008-11-06 (20-48-06).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 185341 Time elapsed: 3 hour(s), 7 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\EvxqIl61.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Friday, November 7, 2008 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, November 07, 2008 02:15:08 Records in database: 1373055 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ I:\ J:\ K:\ L:\ M:\ Scan statistics: Files scanned: 122242 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 03:58:12 File name / Threat name / Threats count C:\Documents and Settings\HP_Administrator\Desktop\Stuff\3wPlayer-1.0.0.3-setup-0401.exe Infected: Trojan.Win32.Obfuscated.en 1 The selected area was scanned.
Logfile of HijackThis v1.99.1
Scan saved at 10:39:34 AM, on 11/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\EvxqIl61.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0be5b88b-ca63-4c98-8837-cdfb94e7837e} - C:\WINDOWS\system32\lotuvowu.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Smart Start UP] C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe /Automation
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [fumenuyero] Rundll32.exe "C:\WINDOWS\system32\memilimi.dll",s
O4 - HKLM\..\Run: [34d4f0c4] rundll32.exe "C:\WINDOWS\system32\losadutu.dll",b
O4 - HKLM\..\Run: [CPM37e7c358] Rundll32.exe "C:\WINDOWS\system32\yabokiya.dll",a
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {E85362EF-40D4-4E5D-BE07-D6B036CCA277} (GoPets Control) - https://secure.gopetslive.com/dev/gopets.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll C:\WINDOWS\system32\nivifutu.dll c:\windows\system32\yabokiya.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yabokiya.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Procedure Manager(TPM) (RPCM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Speech\csvde.exe (file missing)
OK, still there, we need to run another tool to establish what's re-installing the file.

This tool will not fully remove the infection first time round, but should give us the information we need to get it the next time.

Download ComboFix from one of these locations and save it to your Desktop:

Link 1
Link 2
Link 3

IMPORTANT !!! ComboFix.exe must be run from your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with Combofix. There are details for disabling many programmes here.
  • Double click on ComboFix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install Microsoft Windows Recovery Console.

**Please note: If Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

Once Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you.

Please include this log in your next reply. ……… (it can also be found at C:\ComboFix.txt)

IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.
If you have any problems with these instructions, a detailed Tutorial for how to use Combofix is available here.
Thanks for the help,
Here's the ComboFix log:

ComboFix 08-11-07.01 - HP_Administrator 2008-11-07 15:33:21.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1274 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
The following files were disabled during the run:
c:\windows\system32\avgrsstx.dll
c:\windows\system32\nivifutu.dll
c:\windows\system32\yabokiya.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log
c:\windows\IE4 Error Log.txt
c:\windows\system32\EvxqIl61.exe.a_a
c:\windows\system32\utudasol.ini

.
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.

2008-11-07 15:40 . 2008-11-07 15:40 121 —hs—- c:\windows\system32\utudasol.ini
2008-11-06 03:09 . 2008-10-03 11:41 6,066,176 ——— c:\windows\system32\dllcache\ieframe.dll
2008-11-06 03:09 . 2007-04-17 03:32 2,455,488 ——— c:\windows\system32\dllcache\ieapfltr.dat
2008-11-06 03:09 . 2007-03-07 23:10 991,232 ——— c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-06 03:09 . 2008-08-26 01:24 459,264 ——— c:\windows\system32\dllcache\msfeeds.dll
2008-11-06 03:09 . 2008-08-26 01:24 383,488 ——— c:\windows\system32\dllcache\ieapfltr.dll
2008-11-06 03:09 . 2008-08-26 01:24 267,776 ——— c:\windows\system32\dllcache\iertutil.dll
2008-11-06 03:09 . 2008-08-26 01:24 63,488 ——— c:\windows\system32\dllcache\icardie.dll
2008-11-06 03:09 . 2008-08-26 01:24 52,224 ——— c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-06 03:09 . 2008-08-25 02:38 13,824 ——— c:\windows\system32\dllcache\ieudinit.exe
2008-11-05 21:21 . 2008-11-05 21:21 d——– c:\documents and settings\HP_Administrator\Application Data\Uniblue
2008-11-05 19:21 . 2008-11-05 21:51 d——– c:\documents and settings\HP_Administrator\.housecall6.6
2008-11-04 23:09 . 2008-11-04 23:09 d——– c:\documents and settings\NetworkService\Application Data\AdobeUM
2008-11-04 19:44 . 2008-11-07 15:39 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-04 19:44 . 2008-11-07 15:37 1,409 –a—— c:\windows\QTFont.for
2008-11-04 18:20 . 2008-11-05 16:58 d——– c:\program files\Spybot - Search & Destroy
2008-11-04 18:20 . 2008-11-04 19:44 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-04 04:15 . 2008-11-04 04:15 d——– c:\program files\ERUNT
2008-11-04 01:27 . 2008-11-07 14:14 41,986 –a—— c:\windows\system32\EvxqIl61.exe
2008-11-04 01:27 . 2008-11-05 19:11 41,474 –a—— c:\windows\system32\EvxqIl61.exe_
2008-11-03 15:36 . 2008-11-03 20:44 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-03 15:36 . 2008-11-03 15:36 d——– c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2008-11-03 15:36 . 2008-11-03 15:36 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-03 15:36 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-03 15:36 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-03 04:32 . 2008-11-03 05:10 d——– c:\documents and settings\All Users\Application Data\ZILLAbar
2008-11-03 04:30 . 2008-11-03 04:30 d——– c:\documents and settings\HP_Administrator\Application Data\STOPzilla!
2008-11-03 03:21 . 2008-11-03 03:21 d——– c:\program files\Common Files\iS3
2008-11-03 03:21 . 2008-11-03 20:44 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2008-11-03 03:21 . 2008-11-03 03:21 d——– c:\documents and settings\All Users\Application Data\SITEguard
2008-11-02 13:00 . 2008-11-05 16:02 d——– c:\documents and settings\NetworkService\Application Data\AVGTOOLBAR
2008-11-02 00:46 . 2008-11-02 00:45 31,744 –a—— c:\windows\system32\e0W1BIq5.exe
2008-11-02 00:45 . 2008-11-02 00:45 31,744 –a—— c:\windows\system32\6u5jsxP8.exe
2008-10-31 21:20 . 2008-10-31 21:20 244 –ah—– C:\sqmnoopt06.sqm
2008-10-31 21:20 . 2008-10-31 21:20 232 –ah—– C:\sqmdata07.sqm
2008-10-31 18:28 . 2008-10-31 18:28 d——– c:\program files\WinAVIVideoConverter
2008-10-10 14:33 . 2008-10-10 14:33 d——– c:\documents and settings\HP_Administrator\Application Data\Media Player Classic

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 21:40 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\Hamachi
2008-11-07 20:35 ——— d—–w c:\program files\WarCraft III
2008-11-07 20:09 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\uTorrent
2008-11-07 20:02 ——— d—–w c:\program files\Garena
2008-11-05 22:30 ——— d—–w c:\program files\EternityRO
2008-11-05 21:19 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-11-05 18:10 ——— d—–w c:\documents and settings\All Users\Application Data\HP
2008-11-02 23:25 ——— d—–w c:\program files\uTorrent
2008-11-01 02:29 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\dvdcss
2008-10-30 19:35 ——— d—–w c:\program files\EuphRO
2008-10-10 20:05 ——— d—–w c:\program files\Combined Community Codec Pack
2008-10-02 19:21 ——— d—–w c:\program files\NVIDIA nTune Performance Application
2008-10-02 19:21 ——— d—–w c:\program files\NVIDIA Corporation
2008-10-02 19:09 22,328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-02 19:09 22,328 —-a-w c:\documents and settings\HP_Administrator\Application Data\PnkBstrK.sys
2008-10-02 19:08 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-02 18:15 ——— d—–w c:\program files\Activision
2008-09-15 05:29 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-09-15 05:26 ——— d—–w c:\program files\Lavasoft
2008-09-15 05:26 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-09-12 16:58 ——— d—–w c:\program files\Windows Live Safety Center
2008-09-10 13:58 ——— d—–w c:\program files\MSN Messenger
2008-09-10 13:58 ——— d—–w c:\program files\Messenger Plus! Live
2008-09-06 15:08 394 —-a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2008-09-06 15:06 56,032 —-a-w c:\documents and settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-09-29 06:38 251 —-a-w c:\program files\wt3d.ini
.

((((((((((((((((((((((((((((( snapshot@2008-11-03_20.11.05.98 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\11-4-2008\ERDNT.EXE
+ 2008-11-04 10:17:45 10,158,080 —-a-w c:\windows\ERDNT\11-4-2008\Users\00000001\ntuser.dat
+ 2008-11-04 10:17:45 28,672 —-a-w c:\windows\ERDNT\11-4-2008\Users\00000002\UsrClass.dat
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\11-4-2008\ERDNT.EXE
+ 2008-11-05 01:44:34 10,190,848 —-a-w c:\windows\ERDNT\AutoBackup\11-4-2008\Users\00000001\ntuser.dat
+ 2008-11-05 01:44:34 28,672 —-a-w c:\windows\ERDNT\AutoBackup\11-4-2008\Users\00000002\UsrClass.dat
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\11-5-2008\ERDNT.EXE
+ 2008-11-05 20:57:48 10,174,464 —-a-w c:\windows\ERDNT\AutoBackup\11-5-2008\Users\00000001\ntuser.dat
+ 2008-11-05 20:57:48 28,672 —-a-w c:\windows\ERDNT\AutoBackup\11-5-2008\Users\00000002\UsrClass.dat
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\11-6-2008\ERDNT.EXE
+ 2008-11-06 22:57:42 13,189,120 —-a-w c:\windows\ERDNT\AutoBackup\11-6-2008\Users\00000001\ntuser.dat
+ 2008-11-06 22:57:42 2,985,984 —-a-w c:\windows\ERDNT\AutoBackup\11-6-2008\Users\00000002\UsrClass.dat
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\11-7-2008\ERDNT.EXE
+ 2008-11-07 21:29:48 13,283,328 —-a-w c:\windows\ERDNT\AutoBackup\11-7-2008\Users\00000001\ntuser.dat
+ 2008-11-07 21:29:48 2,985,984 —-a-w c:\windows\ERDNT\AutoBackup\11-7-2008\Users\00000002\UsrClass.dat
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\2008-11-07\ERDNT.EXE
+ 2008-11-07 21:40:45 13,283,328 —-a-w c:\windows\ERDNT\AutoBackup\2008-11-07\Users\00000001\ntuser.dat
+ 2008-11-07 21:40:46 2,985,984 —-a-w c:\windows\ERDNT\AutoBackup\2008-11-07\Users\00000002\UsrClass.dat
+ 2005-10-21 02:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2004-08-10 04:00:00 61,440 -c–a-w c:\windows\ie7\admparse.dll
+ 2004-08-10 04:00:00 99,840 -c–a-w c:\windows\ie7\advpack.dll
+ 2004-08-10 04:00:00 35,328 -c–a-w c:\windows\ie7\corpol.dll
+ 2006-06-03 11:40:49 33,792 -c–a-w c:\windows\ie7\custsat.dll
+ 2008-08-20 05:33:18 357,888 -c–a-w c:\windows\ie7\dxtmsft.dll
+ 2008-08-20 05:33:18 205,312 -c–a-w c:\windows\ie7\dxtrans.dll
+ 2008-08-20 05:33:18 55,808 -c–a-w c:\windows\ie7\extmgr.dll
+ 2004-08-10 04:00:00 38,912 -c–a-w c:\windows\ie7\hmmapi.dll
+ 2004-08-10 04:00:00 34,304 -c–a-w c:\windows\ie7\ie4uinit.exe
+ 2004-08-10 04:00:00 139,264 -c–a-w c:\windows\ie7\ieakeng.dll
+ 2004-08-10 04:00:00 216,576 -c–a-w c:\windows\ie7\ieaksie.dll
+ 2004-08-10 04:00:00 221,184 -c–a-w c:\windows\ie7\ieakui.dll
+ 2004-08-10 04:00:00 323,584 -c–a-w c:\windows\ie7\iedkcs32.dll
+ 2008-08-19 09:38:57 18,432 -c–a-w c:\windows\ie7\iedw.exe
+ 2004-08-10 04:00:00 81,920 -c–a-w c:\windows\ie7\ieencode.dll
+ 2008-08-20 05:33:18 251,904 -c–a-w c:\windows\ie7\iepeers.dll
+ 2004-08-10 04:00:00 48,640 -c–a-w c:\windows\ie7\iernonce.dll
+ 2004-08-10 04:00:00 62,976 -c–a-w c:\windows\ie7\iesetup.dll
+ 2004-08-10 04:00:00 93,184 -c–a-w c:\windows\ie7\iexplore.exe
+ 2004-08-10 04:00:00 35,840 -c–a-w c:\windows\ie7\imgutil.dll
+ 2008-08-20 05:33:18 96,256 -c–a-w c:\windows\ie7\inseng.dll
+ 2007-12-18 14:40:58 450,560 -c–a-w c:\windows\ie7\jscript.dll
+ 2008-08-20 05:33:19 16,384 -c–a-w c:\windows\ie7\jsproxy.dll
+ 2004-08-10 04:00:00 22,016 -c–a-w c:\windows\ie7\licmgr10.dll
+ 2004-08-10 04:00:00 29,184 -c–a-w c:\windows\ie7\mshta.exe
+ 2008-08-20 05:33:20 3,067,392 -c–a-w c:\windows\ie7\mshtml.dll
+ 2008-08-20 05:33:19 449,024 -c–a-w c:\windows\ie7\mshtmled.dll
+ 2004-08-10 04:00:00 56,832 -c–a-w c:\windows\ie7\mshtmler.dll
+ 2004-08-10 04:00:00 146,432 -c–a-w c:\windows\ie7\msls31.dll
+ 2008-08-20 05:33:18 146,432 -c–a-w c:\windows\ie7\msrating.dll
+ 2008-08-20 05:33:18 532,480 -c–a-w c:\windows\ie7\mstime.dll
+ 2004-08-10 04:00:00 96,256 -c–a-w c:\windows\ie7\occache.dll
+ 2008-08-20 05:33:18 39,424 -c–a-w c:\windows\ie7\pngfilt.dll
+ 2007-08-14 00:54:42 32,960 -c–a-w c:\windows\ie7\spuninst\iecustom.dll
+ 2007-08-14 00:52:06 66,048 -c–a-w c:\windows\ie7\spuninst\ieResetIcons.exe
+ 2006-09-06 23:43:16 213,216 -c–a-w c:\windows\ie7\spuninst\spuninst.exe
+ 2006-09-06 23:43:18 371,424 -c–a-w c:\windows\ie7\spuninst\updspapi.dll
+ 2004-08-10 04:00:00 37,888 -c–a-w c:\windows\ie7\url.dll
+ 2008-08-20 05:33:19 619,008 -c–a-w c:\windows\ie7\urlmon.dll
+ 2007-12-18 14:40:58 417,792 -c–a-w c:\windows\ie7\vbscript.dll
+ 2007-06-26 15:13:22 851,968 -c–a-w c:\windows\ie7\vgx.dll
+ 2004-08-10 04:00:00 276,480 -c–a-w c:\windows\ie7\webcheck.dll
+ 2008-08-20 05:33:19 667,648 -c–a-w c:\windows\ie7\wininet.dll
+ 2007-08-14 00:39:00 123,904 -c—-w c:\windows\ie7updates\KB956390-IE7\advpack.dll
+ 2007-08-14 00:35:46 346,624 -c—-w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll
+ 2007-08-14 00:35:38 214,528 -c—-w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll
+ 2007-08-14 00:54:10 131,584 -c—-w c:\windows\ie7updates\KB956390-IE7\extmgr.dll
+ 2007-08-14 00:36:26 61,952 -c—-w c:\windows\ie7updates\KB956390-IE7\icardie.dll
+ 2007-08-14 00:39:06 54,784 -c—-w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe
+ 2007-08-14 00:39:26 152,064 -c—-w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll
+ 2007-08-14 00:39:54 229,376 -c—-w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll
+ 2007-08-13 23:56:54 161,792 -c—-w c:\windows\ie7updates\KB956390-IE7\ieakui.dll
+ 2007-02-12 22:10:12 2,451,312 -c—-w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dat
+ 2007-07-11 18:27:48 383,488 -c—-w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dll
+ 2007-08-14 00:39:50 382,976 -c—-w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll
+ 2007-08-14 00:54:10 6,049,280 -c—-w c:\windows\ie7updates\KB956390-IE7\ieframe.dll
+ 2007-08-14 00:39:10 43,008 -c—-w c:\windows\ie7updates\KB956390-IE7\iernonce.dll
+ 2007-08-14 00:34:04 266,752 -c—-w c:\windows\ie7updates\KB956390-IE7\iertutil.dll
+ 2007-08-14 00:39:10 13,312 -c—-w c:\windows\ie7updates\KB956390-IE7\ieudinit.exe
+ 2007-08-14 00:43:56 622,080 -c—-w c:\windows\ie7updates\KB956390-IE7\iexplore.exe
+ 2007-08-14 00:54:10 27,136 -c—-w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll
+ 2007-08-14 00:54:10 458,752 -c—-w c:\windows\ie7updates\KB956390-IE7\msfeeds.dll
+ 2007-08-14 00:54:10 50,688 -c—-w c:\windows\ie7updates\KB956390-IE7\msfeedsbs.dll
+ 2007-08-14 00:54:12 3,578,368 -c—-w c:\windows\ie7updates\KB956390-IE7\mshtml.dll
+ 2007-08-14 00:54:10 475,648 -c—-w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll
+ 2007-08-14 00:44:26 192,000 -c—-w c:\windows\ie7updates\KB956390-IE7\msrating.dll
+ 2007-08-14 00:54:10 670,720 -c—-w c:\windows\ie7updates\KB956390-IE7\mstime.dll
+ 2007-08-14 00:44:06 101,376 -c—-w c:\windows\ie7updates\KB956390-IE7\occache.dll
+ 2007-08-14 00:36:12 44,544 -c—-w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB956390-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB956390-IE7\spuninst\updspapi.dll
+ 2007-08-14 00:44:30 105,984 -c—-w c:\windows\ie7updates\KB956390-IE7\url.dll
+ 2007-08-14 00:54:10 1,162,240 -c—-w c:\windows\ie7updates\KB956390-IE7\urlmon.dll
+ 2007-08-14 00:54:10 231,424 -c—-w c:\windows\ie7updates\KB956390-IE7\webcheck.dll
+ 2007-08-14 00:54:10 818,688 -c—-w c:\windows\ie7updates\KB956390-IE7\wininet.dll
+ 2006-06-03 11:40:49 33,792 ——w c:\windows\network diagnostic\custsat.dll
+ 2006-10-10 12:44:50 557,568 ——w c:\windows\network diagnostic\xpnetdiag.exe
+ 2008-11-07 15:03:07 2,082 —-a-w c:\windows\SoftwareDistribution\EventCache\{69379926-336E-4E9A-A99E-73AC1FF49B2E}.bin
- 2004-08-10 04:00:00 61,440 ——w c:\windows\system32\admparse.dll
+ 2007-08-14 00:39:20 71,680 —-a-w c:\windows\system32\admparse.dll
- 2004-08-10 04:00:00 99,840 ——w c:\windows\system32\advpack.dll
+ 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\advpack.dll
- 2004-08-10 04:00:00 61,440 ——w c:\windows\system32\dllcache\admparse.dll
+ 2007-08-14 00:39:20 71,680 —-a-w c:\windows\system32\dllcache\admparse.dll
- 2004-08-10 04:00:00 99,840 ——w c:\windows\system32\dllcache\advpack.dll
+ 2008-08-26 07:24:28 124,928 ——w c:\windows\system32\dllcache\advpack.dll
- 2004-08-10 04:00:00 28,672 ——w c:\windows\system32\dllcache\custsat.dll
+ 2007-08-14 00:54:10 33,792 —-a-w c:\windows\system32\dllcache\custsat.dll
- 2008-08-20 05:33:18 357,888 ——w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-08-26 07:24:28 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-20 05:33:18 205,312 ——w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-08-26 07:24:28 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-20 05:33:18 55,808 ——w c:\windows\system32\dllcache\extmgr.dll
+ 2008-08-26 07:24:28 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
- 2004-08-10 04:00:00 38,912 —-a-w c:\windows\system32\dllcache\hmmapi.dll
+ 2007-08-14 00:18:02 60,416 —-a-w c:\windows\system32\dllcache\hmmapi.dll
- 2004-08-10 04:00:00 34,304 ——w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-08-25 08:37:59 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
- 2004-08-10 04:00:00 139,264 ——w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-08-26 07:24:28 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-10 04:00:00 216,576 ——w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-08-26 07:24:28 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
- 2004-08-10 04:00:00 221,184 ——w c:\windows\system32\dllcache\ieakui.dll
+ 2008-08-23 05:54:51 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
- 2004-08-10 04:00:00 323,584 ——w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-08-26 07:24:29 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-08-19 09:38:57 18,432 —-a-w c:\windows\system32\dllcache\iedw.exe
+ 2007-08-14 00:44:02 69,120 —-a-w c:\windows\system32\dllcache\iedw.exe
- 2004-08-10 04:00:00 81,920 ——w c:\windows\system32\dllcache\ieencode.dll
+ 2007-08-14 00:45:18 78,336 —-a-w c:\windows\system32\dllcache\ieencode.dll
- 2008-08-20 05:33:18 251,904 ——w c:\windows\system32\dllcache\iepeers.dll
+ 2007-08-14 00:54:10 191,488 —-a-w c:\windows\system32\dllcache\iepeers.dll
- 2004-08-10 04:00:00 48,640 ——w c:\windows\system32\dllcache\iernonce.dll
+ 2008-08-26 07:24:29 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
- 2004-08-10 04:00:00 62,976 ——w c:\windows\system32\dllcache\iesetup.dll
+ 2007-08-14 00:39:12 55,296 —-a-w c:\windows\system32\dllcache\iesetup.dll
- 2004-08-10 04:00:00 93,184 ——w c:\windows\system32\dllcache\iexplore.exe
+ 2008-08-23 05:56:15 635,848 ——w c:\windows\system32\dllcache\iexplore.exe
- 2004-08-10 04:00:00 35,840 ——w c:\windows\system32\dllcache\imgutil.dll
+ 2007-08-14 00:36:06 36,352 —-a-w c:\windows\system32\dllcache\imgutil.dll
- 2008-08-20 05:33:18 96,256 ——w c:\windows\system32\dllcache\inseng.dll
+ 2007-08-14 00:39:02 92,672 —-a-w c:\windows\system32\dllcache\inseng.dll
- 2007-12-18 14:40:58 450,560 ——w c:\windows\system32\dllcache\jscript.dll
+ 2007-08-14 00:38:04 491,520 —-a-w c:\windows\system32\dllcache\jscript.dll
- 2008-08-20 05:33:19 16,384 ——w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-08-26 07:24:30 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
- 2004-08-10 04:00:00 22,016 ——w c:\windows\system32\dllcache\licmgr10.dll
+ 2007-08-14 00:44:18 40,960 —-a-w c:\windows\system32\dllcache\licmgr10.dll
- 2004-08-10 04:00:00 29,184 ——w c:\windows\system32\dllcache\mshta.exe
+ 2007-08-14 00:32:30 45,568 —-a-w c:\windows\system32\dllcache\mshta.exe
- 2008-08-20 05:33:20 3,067,392 ——w c:\windows\system32\dllcache\mshtml.dll
+ 2008-08-27 19:54:32 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-20 05:33:19 449,024 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-08-26 07:24:30 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
- 2004-08-10 04:00:00 56,832 ——w c:\windows\system32\dllcache\mshtmler.dll
+ 2007-08-14 00:01:12 48,128 —-a-w c:\windows\system32\dllcache\mshtmler.dll
- 2004-08-10 04:00:00 146,432 ——w c:\windows\system32\dllcache\msls31.dll
+ 2007-08-14 00:54:10 156,160 —-a-w c:\windows\system32\dllcache\msls31.dll
- 2008-08-20 05:33:18 146,432 ——w c:\windows\system32\dllcache\msrating.dll
+ 2008-08-26 07:24:30 193,024 ——w c:\windows\system32\dllcache\msrating.dll
- 2008-08-20 05:33:18 532,480 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-08-26 07:24:30 671,232 ——w c:\windows\system32\dllcache\mstime.dll
- 2004-08-10 04:00:00 96,256 ——w c:\windows\system32\dllcache\occache.dll
+ 2008-08-26 07:24:30 102,912 ——w c:\windows\system32\dllcache\occache.dll
- 2008-08-20 05:33:18 39,424 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-08-26 07:24:30 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
- 2004-08-10 04:00:00 37,888 ——w c:\windows\system32\dllcache\url.dll
+ 2008-08-26 07:24:30 105,984 ——w c:\windows\system32\dllcache\url.dll
- 2008-08-20 05:33:19 619,008 ——w c:\windows\system32\dllcache\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 ——w c:\windows\system32\dllcache\urlmon.dll
- 2007-12-18 14:40:58 417,792 ——w c:\windows\system32\dllcache\vbscript.dll
+ 2007-08-14 00:54:10 413,696 —-a-w c:\windows\system32\dllcache\vbscript.dll
- 2007-06-26 15:13:22 851,968 ——w c:\windows\system32\dllcache\vgx.dll
+ 2007-08-14 00:54:10 765,952 —-a-w c:\windows\system32\dllcache\VGX.dll
- 2004-08-10 04:00:00 49,152 ——w c:\windows\system32\dllcache\wdigest.dll
+ 2006-03-24 04:37:50 49,152 ——w c:\windows\system32\dllcache\wdigest.dll
- 2004-08-10 04:00:00 276,480 ——w c:\windows\system32\dllcache\webcheck.dll
+ 2008-08-26 07:24:31 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-20 05:33:19 667,648 ——w c:\windows\system32\dllcache\wininet.dll
+ 2008-08-26 07:24:31 826,368 ——w c:\windows\system32\dllcache\wininet.dll
- 2008-08-20 05:33:18 357,888 ——w c:\windows\system32\dxtmsft.dll
+ 2008-08-26 07:24:28 347,136 ——w c:\windows\system32\dxtmsft.dll
- 2008-08-20 05:33:18 205,312 ——w c:\windows\system32\dxtrans.dll
+ 2008-08-26 07:24:28 214,528 ——w c:\windows\system32\dxtrans.dll
- 2008-08-20 05:33:18 55,808 ——w c:\windows\system32\extmgr.dll
+ 2008-08-26 07:24:28 133,120 ——w c:\windows\system32\extmgr.dll
+ 2008-08-26 07:24:28 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2006-06-29 14:05:44 26,112 ——w c:\windows\system32\idndl.dll
- 2004-08-10 04:00:00 34,304 ——w c:\windows\system32\ie4uinit.exe
+ 2008-08-25 08:37:59 70,656 ——w c:\windows\system32\ie4uinit.exe
- 2004-08-10 04:00:00 139,264 ——w c:\windows\system32\ieakeng.dll
+ 2008-08-26 07:24:28 153,088 ——w c:\windows\system32\ieakeng.dll
- 2004-08-10 04:00:00 216,576 ——w c:\windows\system32\ieaksie.dll
+ 2008-08-26 07:24:28 230,400 ——w c:\windows\system32\ieaksie.dll
- 2004-08-10 04:00:00 221,184 ——w c:\windows\system32\ieakui.dll
+ 2008-08-23 05:54:51 161,792 ——w c:\windows\system32\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w c:\windows\system32\ieapfltr.dat
+ 2008-08-26 07:24:28 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2004-08-10 04:00:00 323,584 ——w c:\windows\system32\iedkcs32.dll
+ 2008-08-26 07:24:29 384,512 ——w c:\windows\system32\iedkcs32.dll
- 2004-08-10 04:00:00 81,920 ——w c:\windows\system32\ieencode.dll
+ 2007-08-14 00:45:18 78,336 —-a-w c:\windows\system32\ieencode.dll
+ 2008-10-03 17:41:15 6,066,176 —-a-w c:\windows\system32\ieframe.dll
- 2008-08-20 05:33:18 251,904 ——w c:\windows\system32\iepeers.dll
+ 2007-08-14 00:54:10 191,488 —-a-w c:\windows\system32\iepeers.dll
- 2004-08-10 04:00:00 48,640 ——w c:\windows\system32\iernonce.dll
+ 2008-08-26 07:24:29 44,544 ——w c:\windows\system32\iernonce.dll
+ 2008-08-26 07:24:29 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2004-08-10 04:00:00 62,976 ——w c:\windows\system32\iesetup.dll
+ 2007-08-14 00:39:12 55,296 —-a-w c:\windows\system32\iesetup.dll
+ 2008-08-25 08:38:00 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2007-08-14 00:54:10 180,736 ——w c:\windows\system32\ieui.dll
- 2004-08-10 04:00:00 35,840 ——w c:\windows\system32\imgutil.dll
+ 2007-08-14 00:36:06 36,352 —-a-w c:\windows\system32\imgutil.dll
- 2008-08-20 05:33:18 96,256 ——w c:\windows\system32\inseng.dll
+ 2007-08-14 00:39:02 92,672 —-a-w c:\windows\system32\inseng.dll
- 2007-12-18 14:40:58 450,560 ——w c:\windows\system32\jscript.dll
+ 2007-08-14 00:38:04 491,520 —-a-w c:\windows\system32\jscript.dll
- 2008-08-20 05:33:19 16,384 ——w c:\windows\system32\jsproxy.dll
+ 2008-08-26 07:24:30 27,648 —-a-w c:\windows\system32\jsproxy.dll
- 2004-08-10 04:00:00 22,016 ——w c:\windows\system32\licmgr10.dll
+ 2007-08-14 00:44:18 40,960 —-a-w c:\windows\system32\licmgr10.dll
+ 2008-11-07 16:18:58 86,580 –sha-w c:\windows\system32\losadutu.dll
+ 2008-08-07 16:13:53 60,928 –sha-w c:\windows\system32\lotuvowu.dll
+ 2008-08-07 16:13:53 60,928 –sha-w c:\windows\system32\memilimi.dll
+ 2008-08-26 07:24:30 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2007-08-14 00:36:40 12,288 ——w c:\windows\system32\msfeedssync.exe
- 2004-08-10 04:00:00 29,184 ——w c:\windows\system32\mshta.exe
+ 2007-08-14 00:32:30 45,568 —-a-w c:\windows\system32\mshta.exe
- 2008-08-20 05:33:20 3,067,392 —-a-w c:\windows\system32\mshtml.dll
+ 2008-08-27 19:54:32 3,593,216 —-a-w c:\windows\system32\mshtml.dll
- 2008-08-20 05:33:19 449,024 ——w c:\windows\system32\mshtmled.dll
+ 2008-08-26 07:24:30 477,696 ——w c:\windows\system32\mshtmled.dll
- 2004-08-10 04:00:00 56,832 ——w c:\windows\system32\mshtmler.dll
+ 2007-08-14 00:01:12 48,128 —-a-w c:\windows\system32\mshtmler.dll
- 2004-08-10 04:00:00 146,432 ——w c:\windows\system32\msls31.dll
+ 2007-08-14 00:54:10 156,160 —-a-w c:\windows\system32\msls31.dll
- 2008-08-20 05:33:18 146,432 ——w c:\windows\system32\msrating.dll
+ 2008-08-26 07:24:30 193,024 ——w c:\windows\system32\msrating.dll
- 2008-08-20 05:33:18 532,480 ——w c:\windows\system32\mstime.dll
+ 2008-08-26 07:24:30 671,232 ——w c:\windows\system32\mstime.dll
+ 2006-06-28 23:59:26 24,576 ——w c:\windows\system32\nlsdl.dll
+ 2006-06-29 14:05:44 23,552 ——w c:\windows\system32\normaliz.dll
- 2004-08-10 04:00:00 96,256 ——w c:\windows\system32\occache.dll
+ 2008-08-26 07:24:30 102,912 ——w c:\windows\system32\occache.dll
- 2008-08-20 05:33:18 39,424 ——w c:\windows\system32\pngfilt.dll
+ 2008-08-26 07:24:30 44,544 ——w c:\windows\system32\pngfilt.dll
- 2008-11-02 22:33:23 334,000 —-a-w c:\windows\system32\Restore\rstrlog.dat
+ 2008-11-04 02:45:34 1,908,548 —-a-w c:\windows\system32\Restore\rstrlog.dat
- 2005-06-28 15:21:34 22,752 —-a-w c:\windows\system32\spupdsvc.exe
+ 2006-09-06 23:43:16 22,752 —-a-w c:\windows\system32\spupdsvc.exe
- 2004-08-10 04:00:00 37,888 ——w c:\windows\system32\url.dll
+ 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\url.dll
- 2008-08-20 05:33:19 619,008 —-a-w c:\windows\system32\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 —-a-w c:\windows\system32\urlmon.dll
- 2007-12-18 14:40:58 417,792 ——w c:\windows\system32\vbscript.dll
+ 2007-08-14 00:54:10 413,696 —-a-w c:\windows\system32\vbscript.dll
- 2004-08-10 04:00:00 49,152 —-a-w c:\windows\system32\wdigest.dll
+ 2006-03-24 04:37:50 49,152 —-a-w c:\windows\system32\wdigest.dll
- 2004-08-10 04:00:00 276,480 —-a-w c:\windows\system32\webcheck.dll
+ 2008-08-26 07:24:31 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2007-08-14 00:45:16 206,336 ——w c:\windows\system32\WinFXDocObj.exe
- 2008-08-20 05:33:19 667,648 —-a-w c:\windows\system32\wininet.dll
+ 2008-08-26 07:24:31 826,368 —-a-w c:\windows\system32\wininet.dll
+ 2006-07-14 15:51:51 121,856 ——w c:\windows\system32\xmllite.dll
+ 2008-11-07 21:41:24 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_bbc.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0be5b88b-ca63-4c98-8837-cdfb94e7837e}]
2008-08-07 10:13 60928 –ahs—- c:\windows\system32\lotuvowu.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-09 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-05-28 180269]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2003-07-13 155648]
"Smart Start UP"="c:\program files\NewSoft\Smart Start UP\PnPDetect.exe" [2003-01-21 98304]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-02 1234712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-07-11 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-04 81920]
"fumenuyero"="c:\windows\system32\memilimi.dll" [2008-08-07 60928]
"34d4f0c4"="c:\windows\system32\losadutu.dll" [2008-11-07 86580]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2007-12-04 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2008-06-08 625952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless USB Utility.lnk - c:\program files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe [2005-10-28 1404928]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-05-28 36903]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\nivifutu.dll
"LoadAppInit_DLLs"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.NSVI"= NSVIDEO.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\windows\system32\nivifutu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\patchget.dat"=
"c:\\Ntreev\\Grand Chase\\main.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\WarCraft III\\lancraft.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\WINDOWS\\ehome\\ehtray.exe"=

R0 Achernar;Achernar - SCSI Command Filters;c:\windows\system32\Drivers\Achernar.sys [2004-02-11 16855]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-30 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-07-04 76040]
R3 Aldebaran;Aldebaran - SCSI Command Filters;c:\windows\system32\Drivers\Aldebaran.sys [2004-02-11 21808]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2006-09-26 21920]
S2 Ca536av;FashionCam Video Camera Device;c:\windows\system32\Drivers\Ca536av.sys [2003-09-05 514859]
S2 RPCM;Remote Procedure Manager(TPM);c:\program files\Common Files\Microsoft Shared\Speech\csvde.exe [ ]
S3 npkycryp;npkycryp;c:\documents and settings\HP_Administrator\Desktop\Stuff\Ragnorok\EuphRO\npkycryp.sys [ ]
S3 USBCamera;FashionCam Digital Still Camera Device;c:\windows\system32\Drivers\Bulk536.sys [2003-05-14 11048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-11-07 c:\windows\Tasks\At1.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At10.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At11.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At12.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At13.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At14.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At15.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At16.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-05 c:\windows\Tasks\At17.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-06 c:\windows\Tasks\At18.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At19.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At2.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At20.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At21.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At22.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At23.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At24.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At25.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At26.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At27.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At28.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At29.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At3.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At30.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At31.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At32.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At33.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At34.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At35.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At36.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At37.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At38.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At39.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At4.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At40.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-05 c:\windows\Tasks\At41.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-06 c:\windows\Tasks\At42.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At43.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At44.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At45.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At46.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At47.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At48.job
- c:\windows\system32\e0W1BIq5.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At49.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At5.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At50.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At51.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At52.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At53.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At54.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At55.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At56.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At57.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At58.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At59.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At6.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At60.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At61.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At62.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At63.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At64.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-05 c:\windows\Tasks\At65.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-06 c:\windows\Tasks\At66.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At67.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At68.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At69.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At7.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At70.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At71.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At72.job
- c:\windows\system32\EvxqIl61.exe [2008-11-07 14:14]

2008-11-07 c:\windows\Tasks\At8.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\At9.job
- c:\windows\system32\6u5jsxP8.exe [2008-11-02 00:45]

2008-11-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-CPM37e7c358 - c:\windows\system32\yabokiya.dll
SharedTaskScheduler-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yabokiya.dll
SSODL-SSODL-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yabokiya.dll


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ttfh0r5c.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmnqmp07030901.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 15:39:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\utudasol.ini 1931386 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: c:\windows\explorer.exe
-> c:\windows\system32\memilimi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\rundll32.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\dllhost.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2008-11-07 15:45:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-07 21:45:40
ComboFix2.txt 2008-11-04 02:11:37

Pre-Run: 156,951,154,688 bytes free
Post-Run: 156,960,116,736 bytes free

682 — E O F — 2008-11-01 10:48:44
Download OTMoveIt3 by Old Timer and save it to your Desktop.
  • Double-click OTMoveIt3.exe to run it.
  • Copy the lines in the codebox below.
:Files
c:\windows\system32\utudasol.ini
c:\windows\system32\EvxqIl61.exe
c:\windows\system32\EvxqIl61.exe_
c:\windows\system32\e0W1BIq5.exe
c:\windows\system32\6u5jsxP8.exe
C:\sqmnoopt06.sqm
C:\sqmdata07.sqm
c:\windows\Tasks\At*.job
c:\windows\system32\lotuvowu.dll
c:\windows\system32\memilimi.dll
c:\windows\system32\losadutu.dll

:Reg
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0be5b88b-ca63-4c98-8837-cdfb94e7837e}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fumenuyero"=-
"34d4f0c4"=-
  • Return to OTMoveIt3, right click in the Paste Instructions for Items to be Moved window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTMoveIt3

Next

Please download Malwarebytes' Anti-Malware to your Desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.

  • Click on the Malwarebytes' Anti-Malware icon to launch the programme.
    • Click the Updates tab.
    • Click Check for Updates and allow the programme to download the latest definitions.
  • Click the Scanner tab.
    • Check Perform Full Scan.
    • Click Scan and wait for the scan to complete.
    • When the scan is complete, click OK, then Show Results.
    • Ensure all items are checked then click Remove Selected.
    • A box will pop-up telling you that files have been quarantined.
    • A log will pop-up.
  • Post the log in your next reply please.

You can also access the log by doing the following
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open

Next

Run a scan with Combofix
  • First
    • Important! Temporarily disable your anti-virus, and anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its files which may cause unpredictable results.
    • Click here to see a list of programs that should be disabled (ignore the firewalls). The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Double click combofix.exe & follow the prompts.
  • Note: Combofix will automatically disconnect your Internet connection when it runs, do not reconnect it.
  • When finished, it will
    • Produce a log for you. (it can also be found at C:\Combofix.txt)
    • Restore your Internet connection.
  • Post the log in your next reply please.
  • Now run a new HJT scan and send me the log from that as well please.
IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.
If you have any problems with these instructions, a detailed Tutorial for how to use Combofix is available here.

Summary of the logs I need from you in your next post:
  • OTMoveIt log
  • MBAM log
  • Combofix log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
Here they are: OTMoveIt log first- ========== FILES ========== c:\windows\system32\utudasol.ini moved successfully. c:\windows\system32\EvxqIl61.exe moved successfully. c:\windows\system32\EvxqIl61.exe_ moved successfully. c:\windows\system32\e0W1BIq5.exe moved successfully. c:\windows\system32\6u5jsxP8.exe moved successfully. C:\sqmnoopt06.sqm moved successfully. C:\sqmdata07.sqm moved successfully. c:\windows\Tasks\At1.job moved successfully. c:\windows\Tasks\At10.job moved successfully. c:\windows\Tasks\At11.job moved successfully. c:\windows\Tasks\At12.job moved successfully. c:\windows\Tasks\At13.job moved successfully. c:\windows\Tasks\At14.job moved successfully. c:\windows\Tasks\At15.job moved successfully. c:\windows\Tasks\At16.job moved successfully. c:\windows\Tasks\At17.job moved successfully. c:\windows\Tasks\At18.job moved successfully. c:\windows\Tasks\At19.job moved successfully. c:\windows\Tasks\At2.job moved successfully. c:\windows\Tasks\At20.job moved successfully. c:\windows\Tasks\At21.job moved successfully. c:\windows\Tasks\At22.job moved successfully. c:\windows\Tasks\At23.job moved successfully. c:\windows\Tasks\At24.job moved successfully. c:\windows\Tasks\At25.job moved successfully. c:\windows\Tasks\At26.job moved successfully. c:\windows\Tasks\At27.job moved successfully. c:\windows\Tasks\At28.job moved successfully. c:\windows\Tasks\At29.job moved successfully. c:\windows\Tasks\At3.job moved successfully. c:\windows\Tasks\At30.job moved successfully. c:\windows\Tasks\At31.job moved successfully. c:\windows\Tasks\At32.job moved successfully. c:\windows\Tasks\At33.job moved successfully. c:\windows\Tasks\At34.job moved successfully. c:\windows\Tasks\At35.job moved successfully. c:\windows\Tasks\At36.job moved successfully. c:\windows\Tasks\At37.job moved successfully. c:\windows\Tasks\At38.job moved successfully. c:\windows\Tasks\At39.job moved successfully. c:\windows\Tasks\At4.job moved successfully. c:\windows\Tasks\At40.job moved successfully. c:\windows\Tasks\At41.job moved successfully. c:\windows\Tasks\At42.job moved successfully. c:\windows\Tasks\At43.job moved successfully. c:\windows\Tasks\At44.job moved successfully. c:\windows\Tasks\At45.job moved successfully. c:\windows\Tasks\At46.job moved successfully. c:\windows\Tasks\At47.job moved successfully. c:\windows\Tasks\At48.job moved successfully. c:\windows\Tasks\At49.job moved successfully. c:\windows\Tasks\At5.job moved successfully. c:\windows\Tasks\At50.job moved successfully. c:\windows\Tasks\At51.job moved successfully. c:\windows\Tasks\At52.job moved successfully. c:\windows\Tasks\At53.job moved successfully. c:\windows\Tasks\At54.job moved successfully. c:\windows\Tasks\At55.job moved successfully. c:\windows\Tasks\At56.job moved successfully. c:\windows\Tasks\At57.job moved successfully. c:\windows\Tasks\At58.job moved successfully. c:\windows\Tasks\At59.job moved successfully. c:\windows\Tasks\At6.job moved successfully. c:\windows\Tasks\At60.job moved successfully. c:\windows\Tasks\At61.job moved successfully. c:\windows\Tasks\At62.job moved successfully. c:\windows\Tasks\At63.job moved successfully. c:\windows\Tasks\At64.job moved successfully. c:\windows\Tasks\At65.job moved successfully. c:\windows\Tasks\At66.job moved successfully. c:\windows\Tasks\At67.job moved successfully. c:\windows\Tasks\At68.job moved successfully. c:\windows\Tasks\At69.job moved successfully. c:\windows\Tasks\At7.job moved successfully. c:\windows\Tasks\At70.job moved successfully. c:\windows\Tasks\At71.job moved successfully. c:\windows\Tasks\At72.job moved successfully. c:\windows\Tasks\At8.job moved successfully. c:\windows\Tasks\At9.job moved successfully. DllUnregisterServer procedure not found in c:\windows\system32\lotuvowu.dll c:\windows\system32\lotuvowu.dll NOT unregistered. c:\windows\system32\lotuvowu.dll moved successfully. DllUnregisterServer procedure not found in c:\windows\system32\memilimi.dll c:\windows\system32\memilimi.dll NOT unregistered. c:\windows\system32\memilimi.dll moved successfully. DllUnregisterServer procedure not found in c:\windows\system32\losadutu.dll c:\windows\system32\losadutu.dll NOT unregistered. c:\windows\system32\losadutu.dll moved successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0be5b88b-ca63-4c98-8837-cdfb94e7837e}\\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\fumenuyero deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\34d4f0c4 deleted successfully. OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11072008_170318
Malwarebytes' Anti-Malware 1.30 Database version: 1373 Windows 5.1.2600 Service Pack 2 11/7/2008 6:00:48 PM mbam-log-2008-11-07 (18-00-48).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 157539 Time elapsed: 49 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\fumenuyero (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\EvxqIl61.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
ComboFix 08-11-07.01 - HP_Administrator 2008-11-07 18:04:11.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1179 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
The following files were disabled during the run:
c:\windows\system32\nivifutu.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log

.
((((((((((((((((((((((((( Files Created from 2008-10-08 to 2008-11-08 )))))))))))))))))))))))))))))))
.

2008-11-07 17:03 . 2008-11-07 17:03 d——– C:\_OTMoveIt
2008-11-06 03:09 . 2008-10-03 11:41 6,066,176 ——— c:\windows\system32\dllcache\ieframe.dll
2008-11-06 03:09 . 2007-04-17 03:32 2,455,488 ——— c:\windows\system32\dllcache\ieapfltr.dat
2008-11-06 03:09 . 2007-03-07 23:10 991,232 ——— c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-06 03:09 . 2008-08-26 01:24 459,264 ——— c:\windows\system32\dllcache\msfeeds.dll
2008-11-06 03:09 . 2008-08-26 01:24 383,488 ——— c:\windows\system32\dllcache\ieapfltr.dll
2008-11-06 03:09 . 2008-08-26 01:24 267,776 ——— c:\windows\system32\dllcache\iertutil.dll
2008-11-06 03:09 . 2008-08-26 01:24 63,488 ——— c:\windows\system32\dllcache\icardie.dll
2008-11-06 03:09 . 2008-08-26 01:24 52,224 ——— c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-06 03:09 . 2008-08-25 02:38 13,824 ——— c:\windows\system32\dllcache\ieudinit.exe
2008-11-05 21:21 . 2008-11-05 21:21 d——– c:\documents and settings\HP_Administrator\Application Data\Uniblue
2008-11-05 19:21 . 2008-11-05 21:51 d——– c:\documents and settings\HP_Administrator\.housecall6.6
2008-11-04 23:09 . 2008-11-04 23:09 d——– c:\documents and settings\NetworkService\Application Data\AdobeUM
2008-11-04 19:44 . 2008-11-07 18:09 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-04 19:44 . 2008-11-07 18:07 1,409 –a—— c:\windows\QTFont.for
2008-11-04 18:20 . 2008-11-05 16:58 d——– c:\program files\Spybot - Search & Destroy
2008-11-04 18:20 . 2008-11-04 19:44 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-04 04:15 . 2008-11-04 04:15 d——– c:\program files\ERUNT
2008-11-03 15:36 . 2008-11-07 17:06 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-03 15:36 . 2008-11-03 15:36 d——– c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2008-11-03 15:36 . 2008-11-03 15:36 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-03 15:36 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-03 15:36 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-03 04:32 . 2008-11-03 05:10 d——– c:\documents and settings\All Users\Application Data\ZILLAbar
2008-11-03 04:30 . 2008-11-03 04:30 d——– c:\documents and settings\HP_Administrator\Application Data\STOPzilla!
2008-11-03 03:21 . 2008-11-03 03:21 d——– c:\program files\Common Files\iS3
2008-11-03 03:21 . 2008-11-03 20:44 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2008-11-03 03:21 . 2008-11-03 03:21 d——– c:\documents and settings\All Users\Application Data\SITEguard
2008-11-02 13:00 . 2008-11-05 16:02 d——– c:\documents and settings\NetworkService\Application Data\AVGTOOLBAR
2008-10-31 18:28 . 2008-10-31 18:28 d——– c:\program files\WinAVIVideoConverter
2008-10-10 14:33 . 2008-10-10 14:33 d——– c:\documents and settings\HP_Administrator\Application Data\Media Player Classic

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-08 00:09 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\Hamachi
2008-11-07 20:35 ——— d—–w c:\program files\WarCraft III
2008-11-07 20:09 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\uTorrent
2008-11-07 20:02 ——— d—–w c:\program files\Garena
2008-11-05 22:30 ——— d—–w c:\program files\EternityRO
2008-11-05 21:19 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-11-05 18:10 ——— d—–w c:\documents and settings\All Users\Application Data\HP
2008-11-02 23:25 ——— d—–w c:\program files\uTorrent
2008-11-01 02:29 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\dvdcss
2008-10-30 19:35 ——— d—–w c:\program files\EuphRO
2008-10-10 20:05 ——— d—–w c:\program files\Combined Community Codec Pack
2008-10-02 19:21 ——— d—–w c:\program files\NVIDIA nTune Performance Application
2008-10-02 19:21 ——— d—–w c:\program files\NVIDIA Corporation
2008-10-02 19:09 22,328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-02 19:09 22,328 —-a-w c:\documents and settings\HP_Administrator\Application Data\PnkBstrK.sys
2008-10-02 19:08 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-02 18:15 ——— d—–w c:\program files\Activision
2008-09-15 05:29 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-09-15 05:26 ——— d—–w c:\program files\Lavasoft
2008-09-15 05:26 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-09-12 16:58 ——— d—–w c:\program files\Windows Live Safety Center
2008-09-10 13:58 ——— d—–w c:\program files\MSN Messenger
2008-09-10 13:58 ——— d—–w c:\program files\Messenger Plus! Live
2008-09-06 15:08 394 —-a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2008-09-06 15:06 56,032 —-a-w c:\documents and settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-09-29 06:38 251 —-a-w c:\program files\wt3d.ini
.

((((((((((((((((((((((((((((( snapshot_2008-11-07_15.45.05.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-07 15:03:07 2,082 —-a-w c:\windows\SoftwareDistribution\EventCache\{69379926-336E-4E9A-A99E-73AC1FF49B2E}.bin
+ 2008-11-07 21:45:43 2,716 —-a-w c:\windows\SoftwareDistribution\EventCache\{69379926-336E-4E9A-A99E-73AC1FF49B2E}.bin
+ 2008-07-04 13:52:46 10,520 —-a-w c:\windows\system32\avgrsstx.dll
+ 2008-11-07 16:18:58 92,212 —-a-w c:\windows\system32\yabokiya.dll
+ 2008-11-08 00:10:36 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_eb8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-09 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-05-28 180269]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2003-07-13 155648]
"Smart Start UP"="c:\program files\NewSoft\Smart Start UP\PnPDetect.exe" [2003-01-21 98304]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-02 1234712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-07-11 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-04 81920]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2007-12-04 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2008-06-08 625952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless USB Utility.lnk - c:\program files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe [2005-10-28 1404928]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-05-28 36903]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\nivifutu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.NSVI"= NSVIDEO.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\patchget.dat"=
"c:\\Ntreev\\Grand Chase\\main.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\WarCraft III\\lancraft.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\WINDOWS\\ehome\\ehtray.exe"=

R0 Achernar;Achernar - SCSI Command Filters;c:\windows\system32\Drivers\Achernar.sys [2004-02-11 16855]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-30 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-07-04 76040]
R3 Aldebaran;Aldebaran - SCSI Command Filters;c:\windows\system32\Drivers\Aldebaran.sys [2004-02-11 21808]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2006-09-26 21920]
S2 Ca536av;FashionCam Video Camera Device;c:\windows\system32\Drivers\Ca536av.sys [2003-09-05 514859]
S2 RPCM;Remote Procedure Manager(TPM);c:\program files\Common Files\Microsoft Shared\Speech\csvde.exe [ ]
S3 npkycryp;npkycryp;c:\documents and settings\HP_Administrator\Desktop\Stuff\Ragnorok\EuphRO\npkycryp.sys [ ]
S3 USBCamera;FashionCam Digital Still Camera Device;c:\windows\system32\Drivers\Bulk536.sys [2003-05-14 11048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-11-08 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0be5b88b-ca63-4c98-8837-cdfb94e7837e} - c:\windows\system32\lotuvowu.dll
HKLM-Run-fumenuyero - c:\windows\system32\memilimi.dll


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ttfh0r5c.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmnqmp07030901.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 18:09:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\rundll32.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\dllhost.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2008-11-07 18:14:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-08 00:14:09
ComboFix2.txt 2008-11-07 21:45:48
ComboFix3.txt 2008-11-04 02:11:37

Pre-Run: 156,941,451,264 bytes free
Post-Run: 156,928,479,232 bytes free

249 — E O F — 2008-11-01 10:48:44
Logfile of HijackThis v1.99.1
Scan saved at 6:18:07 PM, on 11/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\explorer.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0be5b88b-ca63-4c98-8837-cdfb94e7837e} - C:\WINDOWS\system32\lotuvowu.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Smart Start UP] C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe /Automation
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [fumenuyero] Rundll32.exe "C:\WINDOWS\system32\memilimi.dll",s
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {E85362EF-40D4-4E5D-BE07-D6B036CCA277} (GoPets Control) - https://secure.gopetslive.com/dev/gopets.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\nivifutu.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Procedure Manager(TPM) (RPCM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Speech\csvde.exe (file missing)

——

~Thanks
Looking better but still some work to do

  • Double-click OTMoveIt3.exe to run it.
  • Copy the lines in the codebox below.
:Files
C:\WINDOWS\system32\nivifutu.dll
C:\WINDOWS\system32\memilimi.dll
c:\windows\system32\yabokiya.dll
  • Return to OTMoveIt3, right click in the Paste Instructions for Items to be Moved window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTMoveIt3

Next

Run a scan with HJT and when finished check the following items (if found).

R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: (no name) - {0be5b88b-ca63-4c98-8837-cdfb94e7837e} - C:\WINDOWS\system32\lotuvowu.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O4 - HKLM\..\Run: [fumenuyero] Rundll32.exe "C:\WINDOWS\system32\memilimi.dll",s
O20 - AppInit_DLLs: C:\WINDOWS\system32\nivifutu.dll


Now close all open windows and click Fix Checked to remove them.

Next

  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.

Then

I need you to run an online scan for me
  • Please go to Kaspersky Online Scanner.
  • Read through the requirements and privacy statement and click on the Accept button.
  • It will start downloading and installing the scanner and virus definitions.
    • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they're not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers and other potentially dangerous programs.
    • Archives.
    • Mail databases.
  • Under Scan, click on My Computer.
  • Once the scan is complete, it will display the results.
    • Click on View Scan Report.
  • You will see a list of infected items.
    • Click the Save Report As… button (see red arrow below)

      [external image: Posted Image]
    • In the Save as… prompt, select Desktop
    • In the File name box, name the file KAVScan
    • In the Save as type prompt, select Text file (see below)

      [external image: Posted Image]
    • Copy and paste that information in your next post please.

Finally

Run a new HJT scan and post me the log please.

Summary of the logs I need from you in your next post:
  • OTMoveIt log
  • Kaspersky log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI