This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Bancos Trojan

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

CA and Pest Patrol both show a Bancos.Trojan when I scan my system. They show the following registry key: hkey_local_machine \software\sos

Double checked the registry to see if the key actually exists, and it is in there.

If I use CA or Pest Patrol to remove the key, or if I remove it manually, the key shows up again after reboot. I can not find the initiating program that puts this key in the registry at start up.

No other malware scanning program flags this key as a problem.

The following is my HiJackThis log, and Ant-Malware log…

HiJackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:13:15 PM, on 12/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\kmw_run.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\ASUS\Ai Booster\OverClk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wlns.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [kmw_run.exe] "C:\WINDOWS\system32\kmw_run.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [ADUserMon] "C:\Program Files\Iomega\AutoDisk\ADUserMon.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [Deskup] "C:\Program Files\Iomega\DriveIcons\deskup.exe" /IMGSTART
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\Ai Booster\OverClk.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PestPatrol Control Center] "c:\PROGRA~1\PESTPA~1\PPControl.exe"
O4 - HKLM\..\Run: [PPMemCheck] "c:\PROGRA~1\PESTPA~1\PPMemCheck.exe"
O4 - HKLM\..\Run: [CookiePatrol] "c:\PROGRA~1\PESTPA~1\CookiePatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {03DF0933-6E10-4D32-9835-B9A815622831} (WSSystemInfo Class) - https://gopublic.wspan.com/secure/DLLs/WSSy…Information.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {52454909-B15F-11D3-83A3-000083613743} (SCMDir Class) - https://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173070605140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1173112912250
O16 - DPF: {6FC2871E-004B-4141-B9C0-59708BD96CCE} (WSEmul Control 3) - https://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {7B72C3FC-34B5-4504-B4BE-EB38971A0888} (WSFileIO Class 3) - https://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
O16 - DPF: {7DB7E238-1425-4434-8B05-6453AD6A49C6} (WSPrint3 Control) - https://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
O16 - DPF: {85788258-6ACF-4FC1-A2CD-3BD248065AB9} (WSKeyboardMap Class) - https://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
O16 - DPF: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D} (WSFileIO Class 2) - https://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {A4D41E3A-613D-11D3-85B2-400011500081} (WSCustInst Class) - https://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4233B6D-88A0-11D3-BC29-400011500032} (WspGoCal Class) - https://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D} (SCM Class1) - https://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O20 - AppInit_DLLs: sgaunh.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 12898 bytes


Anti-Malware Log:

Malwarebytes' Anti-Malware 1.31
Database version: 1571
Windows 5.1.2600 Service Pack 3

12/29/2008 8:37:57 PM
mbam-log-2008-12-29 (20-37-57).txt

Scan type: Quick Scan
Objects scanned: 64026
Time elapsed: 6 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Thanks for your help!!!!
Hello and Welcome to the forum.

Please let them know to close you're topic here:


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


1. launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""



2. Save this text as fixme.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop. Include the word REGEDIT4

3. Double-click on fixme.reg. When it asks you to merge the information to the registry click Yes.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Hi, Thanks for your response.

I completed the "REGEDIT4" install into the registry.

Ran ATF Cleaner

Ran ComboFix

The following is the ComboFix and HiJackThis reports:

ComboFix File:

ComboFix 08-12-31.01 - Charlie 2009-01-01 17:37:02.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.595 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: Webroot Internet Security Essentials *disabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\windows\system32\hpowiax7.dll

.
((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.

2008-12-30 13:58 . 2008-12-30 13:58 d——– c:\program files\ASUS
2008-12-30 13:58 . 2004-02-27 00:00 962,612 –a—— c:\windows\system32\mfc42d.dll
2008-12-30 13:58 . 2004-02-17 00:00 434,252 –a—— c:\windows\system32\MSVCRTD.DLL
2008-12-30 13:58 . 2005-01-28 03:44 24,576 -ra—— c:\windows\system32\AsIO.dll
2008-12-30 13:58 . 2004-09-07 11:41 5,120 –a—— c:\windows\system32\drivers\AsInsHelp64.sys
2008-12-30 13:58 . 2004-10-14 04:52 4,962 -ra—— c:\windows\system32\drivers\AsIO.sys
2008-12-30 13:58 . 2004-03-10 14:31 3,328 –a—— c:\windows\system32\drivers\AsInsHelp32.sys
2008-12-30 13:57 . 2008-12-30 13:57 5,950 –a—— c:\windows\Ascd_tmp.ini
2008-12-30 12:28 . 2008-12-30 12:28 48,035 –a—— c:\windows\BS_DEF.sys
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\Charlie\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 20:19 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 19:13 . 2008-12-29 19:13 d——– c:\program files\ERUNT
2008-12-28 20:59 . 2008-12-28 20:59 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-12-27 14:03 . 2008-12-27 14:03 d——– c:\documents and settings\Kelli\Application Data\HP
2008-12-20 13:22 . 2009-01-01 14:22 d——– c:\documents and settings\Kelli\Application Data\HPAppData
2008-12-19 21:02 . 2009-01-01 17:34 d——– c:\documents and settings\Charlie\Application Data\HPAppData
2008-12-19 20:58 . 2008-12-19 20:58 d——– c:\documents and settings\Charlie\Application Data\HP
2008-12-19 20:54 . 2008-12-19 20:54 d——– c:\documents and settings\All Users\Application Data\WEBREG
2008-12-19 20:53 . 2008-12-19 20:53 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-19 20:53 . 2007-10-30 04:25 49,920 -ra—— c:\windows\system32\drivers\HPZid412.sys
2008-12-19 20:53 . 2007-10-30 04:25 16,496 -ra—— c:\windows\system32\drivers\HPZipr12.sys
2008-12-19 20:52 . 2007-11-08 09:52 271,704 -ra—— c:\windows\system32\hpzids01.dll
2008-12-19 20:52 . 2007-10-20 18:25 117,760 –a—— c:\windows\system32\hpzll5mu.dll
2008-12-19 20:52 . 2007-10-30 04:25 21,568 -ra—— c:\windows\system32\drivers\HPZius12.sys
2008-12-19 20:51 . 2007-10-30 04:11 581,632 -ra—— c:\windows\system32\hpotscl6.dll
2008-12-19 20:51 . 2007-10-30 04:25 372,736 -ra—— c:\windows\system32\hppldcoi.dll
2008-12-19 20:51 . 2007-10-30 04:25 309,760 -ra—— c:\windows\system32\difxapi.dll
2008-12-19 20:51 . 2007-10-30 04:11 303,104 -ra—— c:\windows\system32\hpovst15.dll
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP
2008-12-19 20:45 . 2008-12-19 20:45 d——– c:\program files\Common Files\Hewlett-Packard
2008-12-19 20:44 . 2008-12-19 20:46 d——– c:\program files\Hewlett-Packard
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-12-19 20:42 . 2008-12-19 20:54 157,480 –a—— c:\windows\hpoins27.dat
2008-12-19 20:42 . 2008-01-18 10:56 932 ——— c:\windows\hpomdl27.dat
2008-12-10 21:14 . 2008-12-10 21:14 d——– c:\windows\system32\ernet explorer
2008-12-09 16:22 . 2008-10-03 05:02 247,326 —–c— c:\windows\system32\dllcache\strmdll.dll
2008-12-01 17:15 . 2008-12-01 17:18 250 –a—— c:\windows\gmer.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-01 22:33 ——— d—–w c:\program files\PestPatrol
2009-01-01 22:23 7,304 —-a-w c:\windows\TMP0001.TMP
2008-12-30 18:58 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-30 18:17 ——— d—–w c:\program files\Common Files\InstallShield
2008-12-20 01:48 ——— d—–w c:\program files\HP
2008-12-09 00:07 ——— d—–w c:\program files\Common Files\Adobe
2008-12-07 05:02 ——— d—–w c:\program files\Java
2008-12-01 22:08 ——— d—–w c:\program files\TrojanHunter 5.0
2008-12-01 22:02 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-01 22:02 ——— d—–w c:\program files\Panda Security
2008-12-01 22:02 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-01 22:00 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-01 21:58 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-01 21:58 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-27 05:39 ——— d—–w c:\program files\iTunes
2008-11-27 05:34 ——— d—–w c:\program files\Common Files\LightScribe
2008-11-27 05:33 ——— d—–w c:\program files\Bonjour
2008-11-27 04:08 ——— d—–w c:\documents and settings\Charlie\Application Data\TrojanHunter
2008-11-26 05:31 ——— d—–w c:\documents and settings\All Users\Application Data\PrevxCSI
2008-11-25 22:40 ——— d—–w c:\program files\QuickTime
2008-11-25 22:25 2,001 —-a-w c:\program files\uninstal.log
2008-11-21 18:41 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-21 18:20 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-11-21 18:20 10,671 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-21 17:02 ——— d—–w c:\documents and settings\Charlie\Application Data\Symantec
2008-11-21 05:08 ——— d—–w c:\program files\AVG
2008-11-21 04:02 ——— d—–w c:\program files\F-Group
2008-11-20 21:44 ——— d—–w c:\program files\Trend Micro
2008-11-20 20:24 164 —-a-w C:\install.dat
2008-11-20 20:14 ——— d—–w c:\program files\Rhapsody
2008-11-19 03:02 ——— d—–w c:\program files\Exterminate It!
2008-11-13 22:11 1,553,272 —-a-w c:\windows\WRSetup.dll
2008-11-12 21:02 29,808 —-a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 21:02 23,152 —-a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 21:02 170,608 —-a-w c:\windows\system32\drivers\ssidrv.sys
2008-11-10 10:43 410,984 —-a-w c:\windows\system32\deploytk.dll
2008-10-23 22:27 183,120 —-a-w c:\windows\system32\PnkBstrB.exe
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-08-03 01:11 22,328 —-a-w c:\documents and settings\Charlie\Application Data\PnkBstrK.sys
2002-05-21 15:00 1,362 —-a-r c:\program files\ReadMe.txt
.

((((((((((((((((((((((((((((( snapshot_2009-01-01_17.10.52.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-01 22:23:14 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-01 22:23:14 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-01 21:44:09 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-01 22:23:14 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-01 22:24:43 16,384 —-atw c:\windows\temp\Perflib_Perfdata_6b0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kmw_run.exe"="c:\windows\system32\kmw_run.exe" [2006-08-03 106496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 147456]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 86016]
"Deskup"="c:\program files\Iomega\DriveIcons\deskup.exe" [2002-07-16 32768]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-10-07 1630208]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"PestPatrol Control Center"="c:\progra~1\PESTPA~1\PPControl.exe" [2004-11-15 98304]
"PPMemCheck"="c:\progra~1\PESTPA~1\PPMemCheck.exe" [2004-04-02 148480]
"CookiePatrol"="c:\progra~1\PESTPA~1\CookiePatrol.exe" [2005-01-10 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-03-28 724992]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2624:UDP"= 2624:UDP:Windows Media Format SDK (iexplore.exe)
"2630:UDP"= 2630:UDP:Windows Media Format SDK (iexplore.exe)
"2638:UDP"= 2638:UDP:Windows Media Format SDK (iexplore.exe)
"2648:UDP"= 2648:UDP:Windows Media Format SDK (iexplore.exe)
"2650:UDP"= 2650:UDP:Windows Media Format SDK (iexplore.exe)

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-10-02 29808]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-07-07 24652]
R2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" [2008-10-20 1086840]
S3 BS_DEF;BS_DEF;\??\c:\windows\BS_DEF.sys [2008-12-30 48035]
S3 EraserUtilDrv10621;EraserUtilDrv10621;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10621.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-12-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\,d:\,e:\,f:\,g:\,h:\ []

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []

2008-12-30 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-30 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-30 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.wlns.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O16 -: DirectAnimation Java Classes - c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\WSSystemInformation.dll - O16 -: {03DF0933-6E10-4D32-9835-B9A815622831}
hxxps://gopublic.wspan.com/secure/DLLs/WSSystemInformation.cab
c:\windows\Downloaded Program Files\WSSystemInformation.inf

c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\SysReqLab3.osd

c:\windows\Downloaded Program Files\CONFLICT.1\Manager.exe - c:\windows\Downloaded Program Files\CONFLICT.1\DownloadManagerV2.ocx
O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
c:\windows\Downloaded Program Files\DownloadManagerV2.inf

c:\windows\Downloaded Program Files\ScmDirCtl.dll - O16 -: {52454909-B15F-11D3-83A3-000083613743}
hxxps://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
c:\windows\Downloaded Program Files\ScmDirCtl.inf

c:\windows\Downloaded Program Files\WSEmul3.ocx - O16 -: {6FC2871E-004B-4141-B9C0-59708BD96CCE}
hxxps://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
c:\windows\Downloaded Program Files\wsemul3.inf

c:\windows\Downloaded Program Files\CONFLICT.1\WSMap.vbs - c:\windows\Downloaded Program Files\CONFLICT.1\WSFileIO3.dll
O16 -: {7B72C3FC-34B5-4504-B4BE-EB38971A0888}
hxxps://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
c:\windows\Downloaded Program Files\CONFLICT.1\wsfileio3.inf

c:\windows\Downloaded Program Files\WSPrint3.ocx - O16 -: {7DB7E238-1425-4434-8B05-6453AD6A49C6}
hxxps://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
c:\windows\Downloaded Program Files\wsprint3.inf

c:\windows\Downloaded Program Files\WSKeyBoardTranslator.dll - O16 -: {85788258-6ACF-4FC1-A2CD-3BD248065AB9}
hxxps://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
c:\windows\Downloaded Program Files\WSKeyBoardTranslator.inf

c:\windows\Downloaded Program Files\WSMap.vbs - c:\windows\Downloaded Program Files\WSFileIO2.dll
O16 -: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D}
hxxps://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
c:\windows\Downloaded Program Files\wsfileio2.inf

c:\windows\Downloaded Program Files\WSBrowserConfig.dll - O16 -: {9145A52A-9B22-4858-AEE7-74D6C7D3F366}
hxxps://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
c:\windows\Downloaded Program Files\wsbrowserconfig.inf

c:\windows\Downloaded Program Files\WSCustInstSrv.dll - O16 -: {A4D41E3A-613D-11D3-85B2-400011500081}
hxxps://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
c:\windows\Downloaded Program Files\WSCustInst.inf

c:\windows\Downloaded Program Files\wspancal.dll - O16 -: {D4233B6D-88A0-11D3-BC29-400011500032}
hxxps://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
c:\windows\Downloaded Program Files\wspancal.inf

c:\windows\WSODBC32.dll - c:\windows\Downloaded Program Files\SCMCtl1.dll
O16 -: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D}
hxxps://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
c:\windows\Downloaded Program Files\WSSCM1.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-01 17:39:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\msv1_0.dll
.
Completion time: 2009-01-01 17:41:40
ComboFix-quarantined-files.txt 2009-01-01 22:41:38
ComboFix2.txt 2008-11-21 16:07:49
ComboFix3.txt 2008-11-20 04:57:46

Pre-Run: 53,289,730,048 bytes free
Post-Run: 53,280,407,552 bytes free

308 — E O F — 2008-12-18 01:19:28



HiJackThis File:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:48:27 PM, on 1/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\kmw_run.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wlns.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [kmw_run.exe] "C:\WINDOWS\system32\kmw_run.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [ADUserMon] "C:\Program Files\Iomega\AutoDisk\ADUserMon.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [Deskup] "C:\Program Files\Iomega\DriveIcons\deskup.exe" /IMGSTART
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PestPatrol Control Center] "c:\PROGRA~1\PESTPA~1\PPControl.exe"
O4 - HKLM\..\Run: [PPMemCheck] "c:\PROGRA~1\PESTPA~1\PPMemCheck.exe"
O4 - HKLM\..\Run: [CookiePatrol] "c:\PROGRA~1\PESTPA~1\CookiePatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {03DF0933-6E10-4D32-9835-B9A815622831} (WSSystemInfo Class) - https://gopublic.wspan.com/secure/DLLs/WSSy…Information.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {52454909-B15F-11D3-83A3-000083613743} (SCMDir Class) - https://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173070605140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1173112912250
O16 - DPF: {6FC2871E-004B-4141-B9C0-59708BD96CCE} (WSEmul Control 3) - https://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {7B72C3FC-34B5-4504-B4BE-EB38971A0888} (WSFileIO Class 3) - https://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
O16 - DPF: {7DB7E238-1425-4434-8B05-6453AD6A49C6} (WSPrint3 Control) - https://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
O16 - DPF: {85788258-6ACF-4FC1-A2CD-3BD248065AB9} (WSKeyboardMap Class) - https://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
O16 - DPF: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D} (WSFileIO Class 2) - https://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {A4D41E3A-613D-11D3-85B2-400011500081} (WSCustInst Class) - https://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4233B6D-88A0-11D3-BC29-400011500032} (WspGoCal Class) - https://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D} (SCM Class1) - https://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 11989 bytes


The "hkey_local_machine \software\sos" registry key still exists. The computer seems to be running faster though.

Something I didn't add to my last post as far as symptoms go….I've noticed when playing online games my ping time has doubled since I started having this problem. It went from 55 - 60 to 130+.

The "hkey_local_machine \software\sos" registry key still exists.

Can you give me the exact key?

I see a lot of 016's that go to WorldSpan.
Do you work for WorldSpan or use the pc for travel?
Hi, The exact key is: hkey_local_machine \software\sos It is still in the registry and is what CA and PestPatrol consider a Bancos.Trojan file. Yes, we use WorldSpan for travel stuff. Thanks for you help.
You can do it this way or use regedit and delete the key

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\SOS]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.

BTW, I use to work for WorldSpan as a technician about 9 yrs ago. The TWA sale to American cost about 30% of WS employees job.
Ran CFScrip.txt with ComboFix

It removed hkey_local_machine \software\sos, however, this registry key appeared again after restart.

The following is the ComboFix and HiJackThis log files:


ComboFix:


ComboFix 09-01-01.02 - Charlie 2009-01-02 23:19:56.10 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.601 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Charlie\Desktop\CFScript.txt
FW: Webroot Internet Security Essentials *disabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-12-03 to 2009-01-03 )))))))))))))))))))))))))))))))
.

2008-12-30 13:58 . 2008-12-30 13:58 d——– c:\program files\ASUS
2008-12-30 13:58 . 2004-02-27 00:00 962,612 –a—— c:\windows\system32\mfc42d.dll
2008-12-30 13:58 . 2004-02-17 00:00 434,252 –a—— c:\windows\system32\MSVCRTD.DLL
2008-12-30 13:58 . 2005-01-28 03:44 24,576 -ra—— c:\windows\system32\AsIO.dll
2008-12-30 13:58 . 2004-09-07 11:41 5,120 –a—— c:\windows\system32\drivers\AsInsHelp64.sys
2008-12-30 13:58 . 2004-10-14 04:52 4,962 -ra—— c:\windows\system32\drivers\AsIO.sys
2008-12-30 13:58 . 2004-03-10 14:31 3,328 –a—— c:\windows\system32\drivers\AsInsHelp32.sys
2008-12-30 13:57 . 2008-12-30 13:57 5,950 –a—— c:\windows\Ascd_tmp.ini
2008-12-30 12:28 . 2008-12-30 12:28 48,035 –a—— c:\windows\BS_DEF.sys
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\Charlie\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 20:19 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 19:13 . 2008-12-29 19:13 d——– c:\program files\ERUNT
2008-12-28 20:59 . 2008-12-28 20:59 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-12-27 14:03 . 2008-12-27 14:03 d——– c:\documents and settings\Kelli\Application Data\HP
2008-12-20 13:22 . 2009-01-01 19:21 d——– c:\documents and settings\Kelli\Application Data\HPAppData
2008-12-19 21:02 . 2009-01-02 23:18 d——– c:\documents and settings\Charlie\Application Data\HPAppData
2008-12-19 20:58 . 2008-12-19 20:58 d——– c:\documents and settings\Charlie\Application Data\HP
2008-12-19 20:54 . 2008-12-19 20:54 d——– c:\documents and settings\All Users\Application Data\WEBREG
2008-12-19 20:53 . 2008-12-19 20:53 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-19 20:53 . 2007-10-30 04:25 49,920 -ra—— c:\windows\system32\drivers\HPZid412.sys
2008-12-19 20:53 . 2007-10-30 04:25 16,496 -ra—— c:\windows\system32\drivers\HPZipr12.sys
2008-12-19 20:52 . 2007-11-08 09:52 271,704 -ra—— c:\windows\system32\hpzids01.dll
2008-12-19 20:52 . 2007-10-20 18:25 117,760 –a—— c:\windows\system32\hpzll5mu.dll
2008-12-19 20:52 . 2007-10-30 04:25 21,568 -ra—— c:\windows\system32\drivers\HPZius12.sys
2008-12-19 20:51 . 2007-10-30 04:11 581,632 -ra—— c:\windows\system32\hpotscl6.dll
2008-12-19 20:51 . 2007-10-30 04:25 372,736 -ra—— c:\windows\system32\hppldcoi.dll
2008-12-19 20:51 . 2007-10-30 04:25 309,760 -ra—— c:\windows\system32\difxapi.dll
2008-12-19 20:51 . 2007-10-30 04:11 303,104 -ra—— c:\windows\system32\hpovst15.dll
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP
2008-12-19 20:45 . 2008-12-19 20:45 d——– c:\program files\Common Files\Hewlett-Packard
2008-12-19 20:44 . 2008-12-19 20:46 d——– c:\program files\Hewlett-Packard
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-12-19 20:42 . 2008-12-19 20:54 157,480 –a—— c:\windows\hpoins27.dat
2008-12-19 20:42 . 2008-01-18 10:56 932 ——— c:\windows\hpomdl27.dat
2008-12-10 21:14 . 2008-12-10 21:14 d——– c:\windows\system32\ernet explorer
2008-12-09 16:22 . 2008-10-03 05:02 247,326 —–c— c:\windows\system32\dllcache\strmdll.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-03 04:12 ——— d—–w c:\program files\PestPatrol
2009-01-03 02:35 7,304 —-a-w c:\windows\TMP0001.TMP
2008-12-30 18:58 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-30 18:17 ——— d—–w c:\program files\Common Files\InstallShield
2008-12-20 01:48 ——— d—–w c:\program files\HP
2008-12-09 00:07 ——— d—–w c:\program files\Common Files\Adobe
2008-12-07 05:02 ——— d—–w c:\program files\Java
2008-12-01 22:08 ——— d—–w c:\program files\TrojanHunter 5.0
2008-12-01 22:02 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-01 22:02 ——— d—–w c:\program files\Panda Security
2008-12-01 22:02 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-01 22:00 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-01 21:58 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-01 21:58 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-27 05:39 ——— d—–w c:\program files\iTunes
2008-11-27 05:34 ——— d—–w c:\program files\Common Files\LightScribe
2008-11-27 05:33 ——— d—–w c:\program files\Bonjour
2008-11-27 04:08 ——— d—–w c:\documents and settings\Charlie\Application Data\TrojanHunter
2008-11-26 05:31 ——— d—–w c:\documents and settings\All Users\Application Data\PrevxCSI
2008-11-25 22:40 ——— d—–w c:\program files\QuickTime
2008-11-25 22:25 2,001 —-a-w c:\program files\uninstal.log
2008-11-21 18:41 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-21 18:20 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-11-21 18:20 10,671 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-21 17:02 ——— d—–w c:\documents and settings\Charlie\Application Data\Symantec
2008-11-21 05:08 ——— d—–w c:\program files\AVG
2008-11-21 04:02 ——— d—–w c:\program files\F-Group
2008-11-20 21:44 ——— d—–w c:\program files\Trend Micro
2008-11-20 20:24 164 —-a-w C:\install.dat
2008-11-20 20:14 ——— d—–w c:\program files\Rhapsody
2008-11-19 03:02 ——— d—–w c:\program files\Exterminate It!
2008-11-13 22:11 1,553,272 —-a-w c:\windows\WRSetup.dll
2008-11-12 21:02 29,808 —-a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 21:02 23,152 —-a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 21:02 170,608 —-a-w c:\windows\system32\drivers\ssidrv.sys
2008-11-10 10:43 410,984 —-a-w c:\windows\system32\deploytk.dll
2008-10-23 22:27 183,120 —-a-w c:\windows\system32\PnkBstrB.exe
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-08-03 01:11 22,328 —-a-w c:\documents and settings\Charlie\Application Data\PnkBstrK.sys
2002-05-21 15:00 1,362 —-a-r c:\program files\ReadMe.txt
.

((((((((((((((((((((((((((((( snapshot_2009-01-01_17.10.52.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-03 02:35:03 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-03 02:35:03 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-01 21:44:09 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-03 02:35:03 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-30 16:21:37 59,984 —-a-w c:\windows\system32\perfc009.dat
+ 2009-01-02 02:54:58 59,780 —-a-w c:\windows\system32\perfc009.dat
- 2008-12-30 16:21:37 397,890 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-02 02:54:58 397,560 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-03 02:36:34 16,384 —-atw c:\windows\temp\Perflib_Perfdata_6f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kmw_run.exe"="c:\windows\system32\kmw_run.exe" [2006-08-03 106496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 147456]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 86016]
"Deskup"="c:\program files\Iomega\DriveIcons\deskup.exe" [2002-07-16 32768]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-10-07 1630208]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"PestPatrol Control Center"="c:\progra~1\PESTPA~1\PPControl.exe" [2004-11-15 98304]
"PPMemCheck"="c:\progra~1\PESTPA~1\PPMemCheck.exe" [2004-04-02 148480]
"CookiePatrol"="c:\progra~1\PESTPA~1\CookiePatrol.exe" [2005-01-10 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-03-28 724992]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2624:UDP"= 2624:UDP:Windows Media Format SDK (iexplore.exe)
"2630:UDP"= 2630:UDP:Windows Media Format SDK (iexplore.exe)
"2638:UDP"= 2638:UDP:Windows Media Format SDK (iexplore.exe)
"2648:UDP"= 2648:UDP:Windows Media Format SDK (iexplore.exe)
"2650:UDP"= 2650:UDP:Windows Media Format SDK (iexplore.exe)

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-10-02 29808]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-07-07 24652]
R2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" [2008-10-20 1086840]
S3 BS_DEF;BS_DEF;\??\c:\windows\BS_DEF.sys [2008-12-30 48035]
S3 EraserUtilDrv10621;EraserUtilDrv10621;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10621.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\,d:\,e:\,f:\,g:\,h:\ []

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.wlns.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O16 -: DirectAnimation Java Classes - c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\WSSystemInformation.dll - O16 -: {03DF0933-6E10-4D32-9835-B9A815622831}
hxxps://gopublic.wspan.com/secure/DLLs/WSSystemInformation.cab
c:\windows\Downloaded Program Files\WSSystemInformation.inf

c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\SysReqLab3.osd

c:\windows\Downloaded Program Files\CONFLICT.1\Manager.exe - c:\windows\Downloaded Program Files\CONFLICT.1\DownloadManagerV2.ocx
O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
c:\windows\Downloaded Program Files\DownloadManagerV2.inf

c:\windows\Downloaded Program Files\ScmDirCtl.dll - O16 -: {52454909-B15F-11D3-83A3-000083613743}
hxxps://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
c:\windows\Downloaded Program Files\ScmDirCtl.inf

c:\windows\Downloaded Program Files\WSEmul3.ocx - O16 -: {6FC2871E-004B-4141-B9C0-59708BD96CCE}
hxxps://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
c:\windows\Downloaded Program Files\wsemul3.inf

c:\windows\Downloaded Program Files\CONFLICT.1\WSMap.vbs - c:\windows\Downloaded Program Files\CONFLICT.1\WSFileIO3.dll
O16 -: {7B72C3FC-34B5-4504-B4BE-EB38971A0888}
hxxps://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
c:\windows\Downloaded Program Files\CONFLICT.1\wsfileio3.inf

c:\windows\Downloaded Program Files\WSPrint3.ocx - O16 -: {7DB7E238-1425-4434-8B05-6453AD6A49C6}
hxxps://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
c:\windows\Downloaded Program Files\wsprint3.inf

c:\windows\Downloaded Program Files\WSKeyBoardTranslator.dll - O16 -: {85788258-6ACF-4FC1-A2CD-3BD248065AB9}
hxxps://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
c:\windows\Downloaded Program Files\WSKeyBoardTranslator.inf

c:\windows\Downloaded Program Files\WSMap.vbs - c:\windows\Downloaded Program Files\WSFileIO2.dll
O16 -: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D}
hxxps://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
c:\windows\Downloaded Program Files\wsfileio2.inf

c:\windows\Downloaded Program Files\WSBrowserConfig.dll - O16 -: {9145A52A-9B22-4858-AEE7-74D6C7D3F366}
hxxps://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
c:\windows\Downloaded Program Files\wsbrowserconfig.inf

c:\windows\Downloaded Program Files\WSCustInstSrv.dll - O16 -: {A4D41E3A-613D-11D3-85B2-400011500081}
hxxps://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
c:\windows\Downloaded Program Files\WSCustInst.inf

c:\windows\Downloaded Program Files\wspancal.dll - O16 -: {D4233B6D-88A0-11D3-BC29-400011500032}
hxxps://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
c:\windows\Downloaded Program Files\wspancal.inf

c:\windows\WSODBC32.dll - c:\windows\Downloaded Program Files\SCMCtl1.dll
O16 -: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D}
hxxps://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
c:\windows\Downloaded Program Files\WSSCM1.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 23:22:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
Completion time: 2009-01-02 23:23:22
ComboFix-quarantined-files.txt 2009-01-03 04:23:02
ComboFix2.txt 2009-01-03 02:31:53
ComboFix3.txt 2009-01-01 22:41:42
ComboFix4.txt 2008-11-21 16:07:49
ComboFix5.txt 2009-01-03 04:19:22

Pre-Run: 53,248,303,104 bytes free
Post-Run: 53,239,111,680 bytes free

304 — E O F — 2008-12-18 01:19:28




HiJackThis:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:08 PM, on 1/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\kmw_run.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wlns.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [kmw_run.exe] "C:\WINDOWS\system32\kmw_run.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [ADUserMon] "C:\Program Files\Iomega\AutoDisk\ADUserMon.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [Deskup] "C:\Program Files\Iomega\DriveIcons\deskup.exe" /IMGSTART
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PestPatrol Control Center] "c:\PROGRA~1\PESTPA~1\PPControl.exe"
O4 - HKLM\..\Run: [PPMemCheck] "c:\PROGRA~1\PESTPA~1\PPMemCheck.exe"
O4 - HKLM\..\Run: [CookiePatrol] "c:\PROGRA~1\PESTPA~1\CookiePatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {03DF0933-6E10-4D32-9835-B9A815622831} (WSSystemInfo Class) - https://gopublic.wspan.com/secure/DLLs/WSSy…Information.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {52454909-B15F-11D3-83A3-000083613743} (SCMDir Class) - https://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173070605140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1173112912250
O16 - DPF: {6FC2871E-004B-4141-B9C0-59708BD96CCE} (WSEmul Control 3) - https://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {7B72C3FC-34B5-4504-B4BE-EB38971A0888} (WSFileIO Class 3) - https://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
O16 - DPF: {7DB7E238-1425-4434-8B05-6453AD6A49C6} (WSPrint3 Control) - https://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
O16 - DPF: {85788258-6ACF-4FC1-A2CD-3BD248065AB9} (WSKeyboardMap Class) - https://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
O16 - DPF: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D} (WSFileIO Class 2) - https://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {A4D41E3A-613D-11D3-85B2-400011500081} (WSCustInst Class) - https://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4233B6D-88A0-11D3-BC29-400011500032} (WspGoCal Class) - https://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D} (SCM Class1) - https://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 12125 bytes



Note, the new HiJackThis log file was produced after restart.

No change in how the computer is running.



P.S. My wife has been in the travel business for over 10 years and also teaches students at our local community college how to use WorldSpan. She remembers things changing from WorldSpan to SABRE when American bought out TWA.
WS was a really nice company to work for. TWA owed I don't remember how many millions to WS, but they (TWA) owned 33% of WS. The other owners were Delta and Northwest.

I'd worry more about that key if it had a file with it.
Let see what we can find.

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Here is the Kaspersky report: Scan —- Scanned: 1323772 Detected: 0 Untreated: 0 Start time: 1/3/2009 1:05:25 AM Duration: 04:13:13 Finish time: 1/3/2009 5:18:38 AM
Disable SpySweeper, and try the fix again
SpySweeper

To disable SpySweeper Shields

  • Open SpySweeper.
  • Click Shield Settings on the right
    (or Shields on the left, depending what screen you're on).
  • Click Internet Explorer and uncheck all items.
  • Click Windows System and uncheck all items.
  • Click Hosts File and uncheck all items.
  • Click Startup Programs and uncheck all items.
  • Close SpySweeper.After all of the fixes are complete it is very important that you enable Real-time Protection again.

I turned off the IE SpySweeper settings. Actually, I had SpySweeper completely shutdown when I did the previous CFScript fix. This time around, I only shut off the IE settings as suggested.

Here are the ComboFix and HijackThis logs, both prior to restart after fix:

Combofix

ComboFix 09-01-02.01 - Charlie 2009-01-04 20:04:19.11 - NTFSx86

Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Charlie\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2008-12-05 to 2009-01-05 )))))))))))))))))))))))))))))))
.

2009-01-04 18:13 . 2009-01-04 18:13 d——– c:\documents and settings\Kelli\Application Data\Apple Computer
2008-12-30 13:58 . 2008-12-30 13:58 d——– c:\program files\ASUS
2008-12-30 13:58 . 2004-02-27 00:00 962,612 –a—— c:\windows\system32\mfc42d.dll
2008-12-30 13:58 . 2004-02-17 00:00 434,252 –a—— c:\windows\system32\MSVCRTD.DLL
2008-12-30 13:58 . 2005-01-28 03:44 24,576 -ra—— c:\windows\system32\AsIO.dll
2008-12-30 13:58 . 2004-09-07 11:41 5,120 –a—— c:\windows\system32\drivers\AsInsHelp64.sys
2008-12-30 13:58 . 2004-10-14 04:52 4,962 -ra—— c:\windows\system32\drivers\AsIO.sys
2008-12-30 13:58 . 2004-03-10 14:31 3,328 –a—— c:\windows\system32\drivers\AsInsHelp32.sys
2008-12-30 13:57 . 2008-12-30 13:57 5,950 –a—— c:\windows\Ascd_tmp.ini
2008-12-30 12:28 . 2008-12-30 12:28 48,035 –a—— c:\windows\BS_DEF.sys
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\Charlie\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 20:19 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 19:13 . 2008-12-29 19:13 d——– c:\program files\ERUNT
2008-12-28 20:59 . 2008-12-28 20:59 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-12-27 14:03 . 2008-12-27 14:03 d——– c:\documents and settings\Kelli\Application Data\HP
2008-12-20 13:22 . 2009-01-04 18:06 d——– c:\documents and settings\Kelli\Application Data\HPAppData
2008-12-19 21:02 . 2009-01-04 20:01 d——– c:\documents and settings\Charlie\Application Data\HPAppData
2008-12-19 20:58 . 2008-12-19 20:58 d——– c:\documents and settings\Charlie\Application Data\HP
2008-12-19 20:54 . 2008-12-19 20:54 d——– c:\documents and settings\All Users\Application Data\WEBREG
2008-12-19 20:53 . 2008-12-19 20:53 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-19 20:53 . 2007-10-30 04:25 49,920 -ra—— c:\windows\system32\drivers\HPZid412.sys
2008-12-19 20:53 . 2007-10-30 04:25 16,496 -ra—— c:\windows\system32\drivers\HPZipr12.sys
2008-12-19 20:52 . 2007-11-08 09:52 271,704 -ra—— c:\windows\system32\hpzids01.dll
2008-12-19 20:52 . 2007-10-20 18:25 117,760 –a—— c:\windows\system32\hpzll5mu.dll
2008-12-19 20:52 . 2007-10-30 04:25 21,568 -ra—— c:\windows\system32\drivers\HPZius12.sys
2008-12-19 20:51 . 2007-10-30 04:11 581,632 -ra—— c:\windows\system32\hpotscl6.dll
2008-12-19 20:51 . 2007-10-30 04:25 372,736 -ra—— c:\windows\system32\hppldcoi.dll
2008-12-19 20:51 . 2007-10-30 04:25 309,760 -ra—— c:\windows\system32\difxapi.dll
2008-12-19 20:51 . 2007-10-30 04:11 303,104 -ra—— c:\windows\system32\hpovst15.dll
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP
2008-12-19 20:45 . 2008-12-19 20:45 d——– c:\program files\Common Files\Hewlett-Packard
2008-12-19 20:44 . 2008-12-19 20:46 d——– c:\program files\Hewlett-Packard
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-12-19 20:42 . 2008-12-19 20:54 157,480 –a—— c:\windows\hpoins27.dat
2008-12-19 20:42 . 2008-01-18 10:56 932 ——— c:\windows\hpomdl27.dat
2008-12-10 21:14 . 2008-12-10 21:14 d——– c:\windows\system32\ernet explorer
2008-12-09 16:22 . 2008-10-03 05:02 247,326 —–c— c:\windows\system32\dllcache\strmdll.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-05 00:28 ——— d—–w c:\program files\PestPatrol
2009-01-04 22:51 7,304 —-a-w c:\windows\TMP0001.TMP
2008-12-30 18:58 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-30 18:17 ——— d—–w c:\program files\Common Files\InstallShield
2008-12-20 01:48 ——— d—–w c:\program files\HP
2008-12-09 00:07 ——— d—–w c:\program files\Common Files\Adobe
2008-12-07 05:02 ——— d—–w c:\program files\Java
2008-12-01 22:08 ——— d—–w c:\program files\TrojanHunter 5.0
2008-12-01 22:02 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-01 22:02 ——— d—–w c:\program files\Panda Security
2008-12-01 22:02 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-01 22:00 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-01 21:58 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-01 21:58 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-27 05:39 ——— d—–w c:\program files\iTunes
2008-11-27 05:34 ——— d—–w c:\program files\Common Files\LightScribe
2008-11-27 05:33 ——— d—–w c:\program files\Bonjour
2008-11-27 04:08 ——— d—–w c:\documents and settings\Charlie\Application Data\TrojanHunter
2008-11-26 05:31 ——— d—–w c:\documents and settings\All Users\Application Data\PrevxCSI
2008-11-25 22:40 ——— d—–w c:\program files\QuickTime
2008-11-25 22:25 2,001 —-a-w c:\program files\uninstal.log
2008-11-21 18:41 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-21 18:20 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-11-21 18:20 10,671 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-21 17:02 ——— d—–w c:\documents and settings\Charlie\Application Data\Symantec
2008-11-21 05:08 ——— d—–w c:\program files\AVG
2008-11-21 04:02 ——— d—–w c:\program files\F-Group
2008-11-20 21:44 ——— d—–w c:\program files\Trend Micro
2008-11-20 20:24 164 —-a-w C:\install.dat
2008-11-20 20:14 ——— d—–w c:\program files\Rhapsody
2008-11-19 03:02 ——— d—–w c:\program files\Exterminate It!
2008-11-13 22:11 1,553,272 —-a-w c:\windows\WRSetup.dll
2008-11-12 21:02 29,808 —-a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 21:02 23,152 —-a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 21:02 170,608 —-a-w c:\windows\system32\drivers\ssidrv.sys
2008-11-10 10:43 410,984 —-a-w c:\windows\system32\deploytk.dll
2008-10-23 22:27 183,120 —-a-w c:\windows\system32\PnkBstrB.exe
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-08-03 01:11 22,328 —-a-w c:\documents and settings\Charlie\Application Data\PnkBstrK.sys
2002-05-21 15:00 1,362 —-a-r c:\program files\ReadMe.txt
.

((((((((((((((((((((((((((((( snapshot_2009-01-01_17.10.52.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-15 02:17:55 102,400 —-a-r c:\windows\Installer\{3DE0053C-FD9A-483E-B7C9-B06E4392206E}\iTunesIco.exe
+ 2009-01-04 23:13:34 102,400 —-a-r c:\windows\Installer\{3DE0053C-FD9A-483E-B7C9-B06E4392206E}\iTunesIco.exe
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-03 04:27:48 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-03 04:27:48 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-01 21:44:09 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-03 04:27:48 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-30 16:21:37 59,984 —-a-w c:\windows\system32\perfc009.dat
+ 2009-01-02 02:54:58 59,780 —-a-w c:\windows\system32\perfc009.dat
- 2008-12-30 16:21:37 397,890 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-02 02:54:58 397,560 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-04 22:53:05 16,384 —-atw c:\windows\temp\Perflib_Perfdata_608.dat
+ 2009-01-05 01:09:02 3,472 —-a-w c:\windows\temp\wrstemp\S-1-5-18.dat
+ 2009-01-05 01:09:02 4,182 —-a-w c:\windows\temp\wrstemp\S-1-5-19.dat
+ 2009-01-05 01:09:02 4,250 —-a-w c:\windows\temp\wrstemp\S-1-5-20.dat
+ 2009-01-05 01:09:02 5,060 —-a-w c:\windows\temp\wrstemp\S-1-5-21-2052111302-1123561945-839522115-1004.dat
+ 2009-01-05 01:09:02 4,930 —-a-w c:\windows\temp\wrstemp\S-1-5-21-2052111302-1123561945-839522115-1005.dat
+ 2009-01-05 01:09:02 4,460 —-a-w c:\windows\temp\wrstemp\S-1-5-21-2052111302-1123561945-839522115-500.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kmw_run.exe"="c:\windows\system32\kmw_run.exe" [2006-08-03 106496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 147456]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 86016]
"Deskup"="c:\program files\Iomega\DriveIcons\deskup.exe" [2002-07-16 32768]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-10-07 1630208]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"PestPatrol Control Center"="c:\progra~1\PESTPA~1\PPControl.exe" [2004-11-15 98304]
"PPMemCheck"="c:\progra~1\PESTPA~1\PPMemCheck.exe" [2004-04-02 148480]
"CookiePatrol"="c:\progra~1\PESTPA~1\CookiePatrol.exe" [2005-01-10 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-03-28 724992]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2624:UDP"= 2624:UDP:Windows Media Format SDK (iexplore.exe)
"2630:UDP"= 2630:UDP:Windows Media Format SDK (iexplore.exe)
"2638:UDP"= 2638:UDP:Windows Media Format SDK (iexplore.exe)
"2648:UDP"= 2648:UDP:Windows Media Format SDK (iexplore.exe)
"2650:UDP"= 2650:UDP:Windows Media Format SDK (iexplore.exe)


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\,d:\,e:\,f:\,g:\,h:\ []

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.wlns.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O16 -: DirectAnimation Java Classes - c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\WSSystemInformation.dll - O16 -: {03DF0933-6E10-4D32-9835-B9A815622831}
hxxps://gopublic.wspan.com/secure/DLLs/WSSystemInformation.cab
c:\windows\Downloaded Program Files\WSSystemInformation.inf

c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\SysReqLab3.osd

c:\windows\Downloaded Program Files\CONFLICT.1\Manager.exe - c:\windows\Downloaded Program Files\CONFLICT.1\DownloadManagerV2.ocx
O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
c:\windows\Downloaded Program Files\DownloadManagerV2.inf

c:\windows\Downloaded Program Files\ScmDirCtl.dll - O16 -: {52454909-B15F-11D3-83A3-000083613743}
hxxps://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
c:\windows\Downloaded Program Files\ScmDirCtl.inf

c:\windows\Downloaded Program Files\WSEmul3.ocx - O16 -: {6FC2871E-004B-4141-B9C0-59708BD96CCE}
hxxps://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
c:\windows\Downloaded Program Files\wsemul3.inf

c:\windows\Downloaded Program Files\CONFLICT.1\WSMap.vbs - c:\windows\Downloaded Program Files\CONFLICT.1\WSFileIO3.dll
O16 -: {7B72C3FC-34B5-4504-B4BE-EB38971A0888}
hxxps://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
c:\windows\Downloaded Program Files\CONFLICT.1\wsfileio3.inf

c:\windows\Downloaded Program Files\WSPrint3.ocx - O16 -: {7DB7E238-1425-4434-8B05-6453AD6A49C6}
hxxps://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
c:\windows\Downloaded Program Files\wsprint3.inf

c:\windows\Downloaded Program Files\WSKeyBoardTranslator.dll - O16 -: {85788258-6ACF-4FC1-A2CD-3BD248065AB9}
hxxps://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
c:\windows\Downloaded Program Files\WSKeyBoardTranslator.inf

c:\windows\Downloaded Program Files\WSMap.vbs - c:\windows\Downloaded Program Files\WSFileIO2.dll
O16 -: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D}
hxxps://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
c:\windows\Downloaded Program Files\wsfileio2.inf

c:\windows\Downloaded Program Files\WSBrowserConfig.dll - O16 -: {9145A52A-9B22-4858-AEE7-74D6C7D3F366}
hxxps://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
c:\windows\Downloaded Program Files\wsbrowserconfig.inf

c:\windows\Downloaded Program Files\WSCustInstSrv.dll - O16 -: {A4D41E3A-613D-11D3-85B2-400011500081}
hxxps://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
c:\windows\Downloaded Program Files\WSCustInst.inf

c:\windows\Downloaded Program Files\wspancal.dll - O16 -: {D4233B6D-88A0-11D3-BC29-400011500032}
hxxps://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
c:\windows\Downloaded Program Files\wspancal.inf

c:\windows\WSODBC32.dll - c:\windows\Downloaded Program Files\SCMCtl1.dll
O16 -: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D}
hxxps://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
c:\windows\Downloaded Program Files\WSSCM1.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-04 20:08:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3520)
c:\windows\system32\kmw_dll.dll
c:\windows\system32\WOW32.dll
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
c:\program files\Iomega\DriveIcons\IMGHOOK.DLL

- - - - - - - > 'explorer.exe'(1024)
c:\windows\system32\kmw_dll.dll
c:\windows\system32\WOW32.dll
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
.
Completion time: 2009-01-04 20:09:51
ComboFix-quarantined-files.txt 2009-01-05 01:09:45
ComboFix2.txt 2009-01-03 04:23:22
ComboFix3.txt 2009-01-03 02:31:53
ComboFix4.txt 2009-01-01 22:41:42
ComboFix5.txt 2009-01-05 01:03:45

Pre-Run: 52,995,940,352 bytes free
Post-Run: 53,046,767,616 bytes free

315 — E O F — 2008-12-18 01:19:28


HiJackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:10:47 PM, on 1/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\kmw_run.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wlns.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [kmw_run.exe] "C:\WINDOWS\system32\kmw_run.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [ADUserMon] "C:\Program Files\Iomega\AutoDisk\ADUserMon.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [Deskup] "C:\Program Files\Iomega\DriveIcons\deskup.exe" /IMGSTART
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PestPatrol Control Center] "c:\PROGRA~1\PESTPA~1\PPControl.exe"
O4 - HKLM\..\Run: [PPMemCheck] "c:\PROGRA~1\PESTPA~1\PPMemCheck.exe"
O4 - HKLM\..\Run: [CookiePatrol] "c:\PROGRA~1\PESTPA~1\CookiePatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1004\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" (User '?')
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1004\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User '?')
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1004\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (User '?')
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1004\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe" (User '?')
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1005\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe" (User '?')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O16 - DPF: {03DF0933-6E10-4D32-9835-B9A815622831} (WSSystemInfo Class) - https://gopublic.wspan.com/secure/DLLs/WSSy…Information.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {52454909-B15F-11D3-83A3-000083613743} (SCMDir Class) - https://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173070605140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1173112912250
O16 - DPF: {6FC2871E-004B-4141-B9C0-59708BD96CCE} (WSEmul Control 3) - https://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {7B72C3FC-34B5-4504-B4BE-EB38971A0888} (WSFileIO Class 3) - https://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
O16 - DPF: {7DB7E238-1425-4434-8B05-6453AD6A49C6} (WSPrint3 Control) - https://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
O16 - DPF: {85788258-6ACF-4FC1-A2CD-3BD248065AB9} (WSKeyboardMap Class) - https://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
O16 - DPF: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D} (WSFileIO Class 2) - https://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {A4D41E3A-613D-11D3-85B2-400011500081} (WSCustInst Class) - https://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4233B6D-88A0-11D3-BC29-400011500032} (WspGoCal Class) - https://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D} (SCM Class1) - https://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe

–
End of file - 11783 bytes



Before restart, the fix deleted the "SOS" registry key, however the key did come back after restart.

One other note, over the past couple weeks I get a message now and then telling me Windows had to restore a registry key, doesn't say which one, but just says one had to be restored.
Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Here is the GMER Log:

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-04 23:52:55
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.14 —-

SSDT 86DD6A08 ZwAllocateVirtualMemory
SSDT 86DAE840 ZwCreateKey
SSDT 86DD6F30 ZwCreateProcess
SSDT 86DD6EB8 ZwCreateProcessEx
SSDT 86DD6CD8 ZwCreateThread
SSDT 86CEA148 ZwDeleteKey
SSDT 86DD6FA8 ZwDeleteValueKey
SSDT 86DD6A80 ZwQueueApcThread
SSDT 86DD6918 ZwReadVirtualMemory
SSDT 86CEE0A8 ZwRenameKey
SSDT 86DD6B70 ZwSetContextThread
SSDT 86CED0B0 ZwSetInformationKey
SSDT 86DD6DC8 ZwSetInformationProcess
SSDT 86DD6BE8 ZwSetInformationThread
SSDT 86D3D470 ZwSetValueKey
SSDT 86DD6D50 ZwSuspendProcess
SSDT 86DD6AF8 ZwSuspendThread
SSDT 86DD6E40 ZwTerminateProcess
SSDT 86DD6C60 ZwTerminateThread
SSDT 86DD6990 ZwWriteVirtualMemory

—- User code sections - GMER 1.0.14 —-

.text C:\WINDOWS\Explorer.EXE[636] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\WINDOWS\Explorer.EXE[636] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1180] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe[1180] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Iomega\DriveIcons\ImgIcon.exe[1648] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Iomega\DriveIcons\ImgIcon.exe[1648] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3604] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe[3604] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Documents and Settings\Charlie\Desktop\gmer\gmer.exe[3652] SHELL32.dll!SHFileOperationW 7CA7083C 5 Bytes JMP 3000141E C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)
.text C:\Documents and Settings\Charlie\Desktop\gmer\gmer.exe[3652] SHELL32.dll!SHFileOperation 7CA70B24 5 Bytes JMP 30001430 C:\Program Files\Iomega\DriveIcons\IMGHOOK.DLL (IMGHOOK/Iomega Corporation)

—- Kernel IAT/EAT - GMER 1.0.14 —-

IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] 86DD67A8
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] 86DD68A0
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] 86DD68A0
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] 86DD67A8
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] 86DD67A8
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] 86DD68A0
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] 86DD68A0
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] 86DD67A8
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] 86DD68A0
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] 86DD67A8
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] 86DD68A0
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] 86DD67A8
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] 86DD68A0

—- User IAT/EAT - GMER 1.0.14 —-

IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [63601740] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3704] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)

—- Devices - GMER 1.0.14 —-

AttachedDevice \FileSystem\Ntfs \Ntfs ssfs0bbc.sys (Spy Sweeper FileSystem Filter Driver/Webroot Software, Inc. (www.webroot.com))

Device \Driver\Tcpip \Device\Ip 868410C8
Device \Driver\Tcpip \Device\Ip 86DD4A88
Device \Driver\Tcpip \Device\Ip 86CCBCF0
Device \Driver\Tcpip \Device\Ip 869B50C8
Device \Driver\Tcpip \Device\Ip 86ABCAE8
Device \Driver\Tcpip \Device\Tcp 868410C8
Device \Driver\Tcpip \Device\Tcp 86DD4A88
Device \Driver\Tcpip \Device\Tcp 86CCBCF0
Device \Driver\Tcpip \Device\Tcp 869B50C8
Device \Driver\Tcpip \Device\Tcp 86ABCAE8
Device \Driver\Tcpip \Device\Udp 868410C8
Device \Driver\Tcpip \Device\Udp 86DD4A88
Device \Driver\Tcpip \Device\Udp 86CCBCF0
Device \Driver\Tcpip \Device\Udp 869B50C8
Device \Driver\Tcpip \Device\Udp 86ABCAE8
Device \Driver\Tcpip \Device\RawIp 868410C8
Device \Driver\Tcpip \Device\RawIp 86DD4A88
Device \Driver\Tcpip \Device\RawIp 86CCBCF0
Device \Driver\Tcpip \Device\RawIp 869B50C8
Device \Driver\Tcpip \Device\RawIp 86ABCAE8
Device \Driver\Tcpip \Device\IPMULTICAST 868410C8
Device \Driver\Tcpip \Device\IPMULTICAST 86DD4A88
Device \Driver\Tcpip \Device\IPMULTICAST 86CCBCF0
Device \Driver\Tcpip \Device\IPMULTICAST 869B50C8
Device \Driver\Tcpip \Device\IPMULTICAST 86ABCAE8

—- EOF - GMER 1.0.14 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI