ComboFix 10-07-20.01 - Compaq_Administrator 07/20/2010 16:12:22.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.404 [GMT -7:00]
Running from: c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\bold.log
C:\desktop.ini
c:\docume~1\COMPAQ~1.001\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\20090224190429656.log
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090224174848890.log
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090224175755546.log
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090224185902312.log
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Temp\IadHide5.dll
c:\documents and settings\Compaq_Administrator\Application Data\alot
c:\documents and settings\Compaq_Administrator\Application Data\AntiSpywareBot
c:\documents and settings\Compaq_Administrator\Application Data\DriveCleaner Freeware
c:\documents and settings\Compaq_Administrator\Application Data\FunWebProducts
c:\documents and settings\Compaq_Administrator\Favorites\Mp3 Download.url
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Download programs.url
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Games.url
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Translator.url
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Videos.url
c:\documents and settings\Elani.YOUR-4DACD0EA75\Start Menu\Antivirus 2009
c:\documents and settings\LocalService\Application Data\NetMon
c:\documents and settings\LocalService\Application Data\NetMon\domains.txt
c:\documents and settings\LocalService\Application Data\NetMon\log.txt
c:\documents and settings\LocalService\Desktop\Sysinternals Antivirus.lnk
c:\documents and settings\LocalService\Start Menu\Programs\Sysinternals Antivirus
c:\documents and settings\LocalService\Start Menu\Programs\Sysinternals Antivirus\Sysinternals Antivirus.lnk
c:\documents and settings\pat\Start Menu\Programs\Startup\Deewoo.lnk
c:\documents and settings\pat\Start Menu\Programs\Startup\DW_Start.lnk
c:\program files\adc_w32.dll
c:\program files\alot
c:\program files\alot\alotUninst.exe
c:\program files\Antivirus 2009
c:\program files\Common Files\miwu
c:\program files\Common Files\miwu\miwua.lck
c:\program files\Common Files\miwu\miwud\class-barrel
c:\program files\Common Files\miwu\miwud\vocabulary
c:\program files\Common Files\miwu\miwuh
c:\program files\Common Files\miwu\miwul.lck
c:\program files\Common Files\miwu\miwum.lck
c:\program files\CyberDefender
c:\program files\CyberDefender\AntiSpyware\config.ini
c:\program files\CyberDefender\AntiSpyware\WsLiveUpdateHost.ini
c:\program files\CyberDefender\AntiSpyware\wslvucfg.ini
c:\program files\CyberDefender\cdinstx.exe
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Images\01F1633C.urr
c:\program files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
c:\program files\FunWebProducts\Shared\Cache\MailStampBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\inetget2
c:\program files\Mjcore
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Avatar\COMMON\avatar.htm
c:\program files\MyWebSearch\bar\Avatar\COMMON\bgfadel.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\bgfader.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\common-x.css
c:\program files\MyWebSearch\bar\Avatar\COMMON\common.css
c:\program files\MyWebSearch\bar\Avatar\COMMON\cornerbl.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\cornerbr.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\ext_def.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\ext_roll.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\include.js
c:\program files\MyWebSearch\bar\Avatar\COMMON\index.htm
c:\program files\MyWebSearch\bar\Avatar\COMMON\loader.htm
c:\program files\MyWebSearch\bar\Avatar\COMMON\loading.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\logo.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\max_def.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\max_roll.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\min_def.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\min_roll.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\noflash.htm
c:\program files\MyWebSearch\bar\Avatar\COMMON\res_def.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\res_roll.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\spacer.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\spacer.swf
c:\program files\MyWebSearch\bar\Avatar\COMMON\topgrad.gif
c:\program files\MyWebSearch\bar\Avatar\COMMON\window.ico
c:\program files\MyWebSearch\bar\Cache\0003AEFE
c:\program files\MyWebSearch\bar\Cache\0015113F
c:\program files\MyWebSearch\bar\Cache\00151F59.bin
c:\program files\MyWebSearch\bar\Cache\001523CD.bin
c:\program files\MyWebSearch\bar\Cache\00152583.bin
c:\program files\MyWebSearch\bar\Cache\001527C5.bin
c:\program files\MyWebSearch\bar\Cache\00153504.bin
c:\program files\MyWebSearch\bar\Cache\001543C9
c:\program files\MyWebSearch\bar\Cache\005ADDE6.bin
c:\program files\MyWebSearch\bar\Cache\005ADF4E.bin
c:\program files\MyWebSearch\bar\Cache\005AECBB.bin
c:\program files\MyWebSearch\bar\Cache\005AEECF.bin
c:\program files\MyWebSearch\bar\Cache\00AEF483.bin
c:\program files\MyWebSearch\bar\Cache\00AEF6E4.bin
c:\program files\MyWebSearch\bar\Cache\00AF04BF.bin
c:\program files\MyWebSearch\bar\Cache\00AF0646.bin
c:\program files\MyWebSearch\bar\Cache\02AFC3EE
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search2
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Message\COMMON\ask_logo.gif
c:\program files\MyWebSearch\bar\Message\COMMON\autoup.gif
c:\program files\MyWebSearch\bar\Message\COMMON\autoup.htm
c:\program files\MyWebSearch\bar\Message\COMMON\center.htm
c:\program files\MyWebSearch\bar\Message\COMMON\index.htm
c:\program files\MyWebSearch\bar\Message\COMMON\mid_dots.gif
c:\program files\MyWebSearch\bar\Message\COMMON\mws_logo.gif
c:\program files\MyWebSearch\bar\Message\COMMON\protect.htm
c:\program files\MyWebSearch\bar\Message\COMMON\shocked.gif
c:\program files\MyWebSearch\bar\Message\COMMON\stop.gif
c:\program files\MyWebSearch\bar\Message\COMMON\systray.htm
c:\program files\MyWebSearch\bar\Message\COMMON\systrayp.htm
c:\program files\MyWebSearch\bar\Message\COMMON\tp_grad.gif
c:\program files\MyWebSearch\bar\Message\COMMON\warn.gif
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
c:\program files\network monitor
c:\program files\scdata
c:\program files\Shared
c:\program files\Shared\lib.sig
c:\program files\Sysinternals Antivirus
c:\program files\Sysinternals Antivirus\Sysinternals Antivirus.exe
c:\program files\webhancer
c:\program files\webhancer\Programs\license.txt
c:\program files\webhancer\Programs\readme.txt
c:\program files\webhancer\Programs\sporder.dll
c:\program files\webhancer\Programs\whagent.ini
c:\program files\webhancer\Programs\whinstaller.exe
c:\program files\WinBudget
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\tn3
c:\windows\010112010146118114.dat
c:\windows\0101120101464849.dat
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.0.inf
c:\windows\IA
c:\windows\wiaserviv.log
c:\windows\xpsp1hfm.log
c:\windows\yfet.scr
D:\Autorun.inf
Infected copy of c:\windows\system32\kernel32.dll was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\kernel32.dll
.
((((((((((((((((((((((((( Files Created from 2010-06-20 to 2010-07-20 )))))))))))))))))))))))))))))))
.
2010-07-18 00:13 . 2010-07-18 00:13 -------- d-----w- c:\windows\system32\wbem\Repository
2010-07-15 20:50 . 2010-07-15 20:50 -------- d-----w- c:\windows\system32\scripting
2010-07-15 20:50 . 2010-07-15 20:50 -------- d-----w- c:\windows\system32\en
2010-07-15 20:50 . 2010-07-15 20:50 -------- d-----w- c:\windows\system32\bits
2010-07-15 19:00 . 2006-04-10 21:02 74240 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp054.dll
2010-07-15 19:00 . 2006-01-04 09:12 77824 ----a-r- c:\windows\system32\HPZIDS01.dll
2010-07-15 19:00 . 2006-04-10 21:03 38400 ----a-w- c:\windows\system32\hpz3l054.dll
2010-07-15 18:27 . 2009-11-27 17:11 17920 ------w- c:\windows\system32\dllcache\msyuv.dll
2010-07-15 18:22 . 2009-11-27 16:07 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll
2010-07-14 01:04 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-13 17:58 . 2010-07-13 17:58 -------- d-----w- c:\documents and settings\Elani's\Local Settings\Application Data\Identities
2010-07-11 02:12 . 2010-07-11 01:58 4560 ---ha-w- c:\temp\t4.bak2
2010-07-11 02:00 . 2010-07-11 02:00 -------- d-----w- c:\documents and settings\Elani's\Application Data\MSNInstaller
2010-07-11 00:40 . 2010-07-11 00:40 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\CyberLink
2010-07-11 00:40 . 2010-07-11 00:40 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\DVDPlay
2010-07-10 23:58 . 2010-07-10 23:58 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Microsoft Help
2010-07-10 23:50 . 2004-08-04 02:41 180360 ------w- c:\windows\system32\drivers\ntmtlfax.sys
2010-07-10 23:23 . 2010-06-01 03:32 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-07-10 22:20 . 2010-07-10 22:20 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Identities
2010-07-10 21:13 . 2010-07-10 21:13 -------- d-----w- C:\_OTL
2010-07-10 20:11 . 2010-07-10 20:11 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\NCH Swift Sound
2010-07-10 19:58 . 2010-07-10 19:58 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\IsolatedStorage
2010-07-10 19:58 . 2010-07-10 19:58 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\HP
2010-07-09 16:35 . 2010-07-09 16:35 -------- d-----w- c:\documents and settings\Elani's\Local Settings\Application Data\Mozilla
2010-07-09 03:36 . 2010-07-09 03:36 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Mozilla
2010-07-09 03:10 . 2010-07-09 03:10 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-07-08 23:53 . 2010-07-08 23:53 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-07-08 23:49 . 2010-07-08 23:49 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-07-08 14:42 . 2010-07-08 14:42 -------- d-sh--w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\IECompatCache
2010-07-08 14:42 . 2010-07-08 14:42 -------- d-sh--w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\PrivacIE
2010-07-08 14:41 . 2010-07-08 14:41 -------- d-sh--w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\IETldCache
2010-07-08 12:13 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-07-08 12:12 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2010-07-08 12:11 . 2009-10-15 16:28 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2010-07-08 12:11 . 2009-10-15 16:28 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2010-07-08 12:11 . 2009-12-31 16:50 353792 ------w- c:\windows\system32\dllcache\srv.sys
2010-07-08 12:09 . 2010-02-24 13:11 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-07-08 12:09 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-07-08 12:07 . 2009-10-12 13:38 149504 ------w- c:\windows\system32\dllcache\rastls.dll
2010-07-08 12:07 . 2009-10-12 13:38 79872 ------w- c:\windows\system32\dllcache\raschap.dll
2010-07-08 12:06 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2010-07-08 12:06 . 2009-02-09 12:10 729088 ------w- c:\windows\system32\dllcache\lsasrv.dll
2010-07-08 12:06 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2010-07-08 12:06 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-07-08 12:06 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2010-07-08 12:06 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
2010-07-08 12:06 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2010-07-08 12:06 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2010-07-08 12:06 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2010-07-08 12:06 . 2009-02-06 11:06 2145280 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-07-08 12:06 . 2009-02-06 11:08 2189056 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-07-08 12:06 . 2009-02-06 10:32 2023936 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-07-08 12:01 . 2009-06-10 06:14 132096 ------w- c:\windows\system32\dllcache\wkssvc.dll
2010-07-08 11:57 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2010-07-08 11:53 . 2009-04-15 14:51 585216 ------w- c:\windows\system32\dllcache\rpcrt4.dll
2010-07-08 11:51 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-07-08 11:51 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2010-07-08 11:42 . 2010-07-08 11:42 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-07-06 20:43 . 2010-07-06 20:43 -------- d-sh--w- c:\documents and settings\Elani's\IECompatCache
2010-07-06 20:43 . 2010-07-06 20:43 -------- d-sh--w- c:\documents and settings\Elani's\PrivacIE
2010-07-06 20:39 . 2010-07-06 20:39 -------- d-sh--w- c:\documents and settings\Elani's\IETldCache
2010-07-06 20:19 . 2010-05-06 10:41 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-07-06 20:19 . 2010-05-06 10:41 599040 ------w- c:\windows\system32\dllcache\msfeeds.dll
2010-07-06 20:19 . 2010-05-06 10:41 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-07-06 20:19 . 2010-05-06 10:41 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-07-06 20:19 . 2010-05-06 10:41 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2010-07-06 20:19 . 2010-05-06 10:41 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2010-07-06 20:19 . 2010-05-06 10:41 11076096 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-07-06 20:10 . 2010-04-16 11:43 41984 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-07-06 20:08 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
2010-07-06 20:08 . 2008-10-23 12:36 286720 ------w- c:\windows\system32\dllcache\gdi32.dll
2010-07-06 19:04 . 2001-08-17 20:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-07-06 19:04 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-07-06 19:04 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-07-06 19:03 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-07-06 18:14 . 2010-07-20 23:24 -------- d-sh--r- c:\windows\system32\dllcache
2010-07-06 18:06 . 2010-07-06 18:06 -------- d-s---w- c:\documents and settings\Elani's\UserData
2010-07-06 17:58 . 2010-07-06 17:58 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\AdobeUM
2010-07-06 17:57 . 2010-07-06 17:57 -------- d-s---w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\UserData
2010-07-06 16:41 . 2010-07-06 17:57 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Adobe
2010-07-06 16:17 . 2010-02-16 14:08 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-07-06 16:13 . 2008-11-14 23:37 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\HPQ
2010-07-06 16:13 . 2008-11-14 23:33 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\HP
2010-07-06 16:13 . 2006-05-05 10:42 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Symantec
2010-07-06 16:13 . 2006-05-05 10:20 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Intuit
2010-07-06 16:13 . 2006-05-05 10:20 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-07-06 15:00 . 2010-07-06 15:00 -------- d-----w- C:\found.002
2010-07-04 17:55 . 2010-07-06 00:40 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.000\Application Data\WTablet
2010-07-04 17:55 . 2010-07-04 17:55 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.000\Application Data\WTouch
2010-07-03 04:24 . 2010-07-03 04:24 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\otoctrqmg
2010-06-28 00:12 . 2010-06-28 00:12 -------- d-----w- c:\program files\TabletPlugins
2010-06-27 23:34 . 2010-06-27 23:34 -------- d-----w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Local Settings\Application Data\Panda3D
2010-06-26 00:43 . 2010-06-26 15:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2010-06-24 23:28 . 2010-06-24 23:57 -------- d-----w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Application Data\GetRightToGo
2010-06-24 12:26 . 2010-07-05 18:25 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet
2010-06-22 17:54 . 2010-06-22 17:54 -------- d-----w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Application Data\Corel
2010-06-22 17:27 . 2010-06-30 20:44 -------- d-----w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Application Data\WTablet
2010-06-22 17:27 . 2010-06-22 17:27 -------- d-----w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Application Data\WTouch
2010-06-22 17:27 . 2010-06-28 00:12 -------- d-----w- c:\program files\WTouch
2010-06-22 17:24 . 2010-06-28 00:11 -------- d-----w- c:\program files\Tablet
2010-06-21 23:10 . 2010-06-25 04:24 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-20 23:26 . 2006-05-05 10:07 148672 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-15 20:53 . 2005-08-31 04:01 92947 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-07-15 20:53 . 2010-07-15 20:53 45056 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2010-07-15 20:53 . 2010-07-15 20:53 61440 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2010-07-15 20:53 . 2010-07-15 20:53 44032 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\scripts\devcon.exe
2010-07-15 20:53 . 2010-07-15 20:53 40960 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2010-07-15 20:53 . 2010-07-15 20:53 341048 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2010-07-15 20:53 . 2010-07-15 20:53 32768 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2010-07-15 20:53 . 2010-07-15 20:53 32768 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2010-07-15 20:53 . 2010-07-15 20:53 217088 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
2010-07-15 20:53 . 2010-07-15 20:53 163840 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2010-07-15 18:10 . 2010-07-06 18:04 48056 ----a-w- c:\documents and settings\Elani's\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-11 03:26 . 2009-12-14 01:11 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-11 00:03 . 2009-09-13 18:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-10 22:00 . 2006-05-05 10:35 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-07-10 22:00 . 2006-05-05 10:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-07-10 20:58 . 2006-05-05 09:45 -------- d-----w- c:\program files\Java
2010-07-10 20:57 . 2006-05-05 10:16 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-10 20:20 . 2009-01-17 15:31 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2010-07-10 20:06 . 2006-05-05 10:10 -------- d-----w- c:\program files\WildTangent
2010-07-10 20:05 . 2006-05-05 10:09 -------- d-----w- c:\program files\Sonic
2010-07-10 20:02 . 2006-05-05 09:40 -------- d-----w- c:\program files\GemMaster
2010-07-10 19:58 . 2010-07-06 16:15 163 ----a-w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\fusioncache.dat
2010-07-06 20:05 . 2006-05-05 10:36 -------- d-----w- c:\program files\Norton Internet Security
2010-07-06 16:22 . 2010-07-06 16:22 1871 --sha-r- c:\windows\system32\drivers\103C_HP_CPC_EX325AA-ABA SR1950NX NA670_YC_0Pres_Qcnx622_E63NAemREA2_48_INAGAMI2_SASUSTek Computer INC._V2.00_B3.11_T060919_WXP2_L409_M959_J250_7AMD_8Athlon 64_92.4_#060914_N_Z11C10620_G10DE0241.MRK
2010-07-04 14:24 . 2010-04-19 21:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-07-04 14:24 . 2006-10-07 01:26 -------- d-----w- c:\program files\Yahoo!
2010-07-02 21:05 . 2010-04-14 19:26 -------- d-----w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Application Data\gtk-2.0
2010-06-28 18:59 . 2010-02-13 02:07 69040 ----a-w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-25 13:29 . 2010-05-18 21:13 -------- d-----w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Application Data\NCH Swift Sound
2010-06-25 13:28 . 2009-08-15 16:26 -------- d-----w- c:\program files\Electronic Arts
2010-06-25 13:19 . 2009-07-09 01:00 -------- d-----w- c:\program files\EA GAMES
2010-06-22 17:43 . 2009-09-21 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Corel
2010-06-22 17:43 . 2009-09-21 22:04 -------- d-----w- c:\program files\Corel
2010-06-17 15:15 . 2010-06-17 15:15 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.000\Application Data\NCH Swift Sound
2010-06-17 15:15 . 2010-03-12 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-06-17 15:15 . 2009-08-20 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2010-06-17 15:15 . 2009-08-20 20:29 -------- d-----w- c:\program files\NCH Swift Sound
2010-06-15 15:30 . 2010-02-13 02:07 148 ----a-w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Local Settings\Application Data\fusioncache.dat
2010-06-14 14:31 . 2004-08-10 04:00 744448 ------w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-13 15:19 . 2010-03-21 17:30 -------- d-----w- c:\documents and settings\Elani.YOUR-4DACD0EA75.000\Application Data\Apple Computer
2010-06-03 01:00 . 2009-10-15 19:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-06-01 03:32 . 2010-02-13 19:26 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-06-01 03:32 . 2010-02-13 19:26 88480 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2010-06-01 03:32 . 2010-02-13 19:26 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-06-01 03:32 . 2010-02-13 19:26 82952 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2010-06-01 03:32 . 2010-02-13 19:26 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-06-01 03:32 . 2010-02-13 19:26 51688 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-06-01 03:32 . 2010-02-13 19:26 385880 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-06-01 03:32 . 2010-02-13 19:26 312616 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-06-01 03:32 . 2010-02-13 19:26 152320 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-05-27 01:12 . 2010-05-27 01:12 -------- d-----w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.000\Application Data\Apple Computer
2010-05-27 00:54 . 2010-05-27 00:53 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-27 00:54 . 2007-07-13 17:54 -------- d-----w- c:\program files\iTunes
2010-05-27 00:53 . 2007-12-26 01:22 -------- d-----w- c:\program files\iPod
2010-05-27 00:48 . 2007-07-13 17:47 -------- d-----w- c:\program files\QuickTime
2010-05-27 00:44 . 2010-05-27 00:44 -------- d-----w- c:\program files\Bonjour
2010-05-06 10:41 . 2004-08-10 04:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 04:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2008-10-18 20:15 . 2008-10-18 20:15 14391 ----a-w- c:\program files\Common Files\opyribu.sys
2008-10-18 20:15 . 2008-10-18 20:15 13450 ----a-w- c:\program files\Common Files\nebyg.bat
2008-10-13 04:02 . 2008-10-13 04:02 15307 ----a-w- c:\program files\Common Files\ganejum.bin
2005-01-21 00:53 . 2008-05-25 03:07 45056 ------r- c:\program files\SetAttrib.exe
2010-06-01 03:32 . 2010-07-10 23:23 24376 ----a-w- c:\program files\mozilla firefox\components\scriptff.dll
.
------- Sigcheck -------
[-] 2010-02-17 . D41C3CBAD0E1C0728D1CDFD541F60CFA . 2189952 . . [5.1.2600.5938] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2010-02-16 . 048DB3459FAB4CA741DCC84E1F374D65 . 2146304 . . [5.1.2600.5938] . . c:\windows\system32\ntoskrnl.exe
[-] 2010-02-16 . E1F653A542449D54FA2D27463D99B6B6 . 2190080 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe
[-] 2009-12-09 . 05BE3D9A71972223AFF6A3C823BA51B1 . 2189312 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe
[-] 2009-12-09 . 05BE3D9A71972223AFF6A3C823BA51B1 . 2189312 . . [5.1.2600.5913] . . c:\windows\SoftwareDistribution\Download\1e737459aaabc35cf71b0434922b4d59\SP3QFE\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\$NtUninstallKB979683$\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\SoftwareDistribution\Download\1e737459aaabc35cf71b0434922b4d59\SP3GDR\ntoskrnl.exe
[-] 2009-12-08 . 5648297DBF1C631164F779863DF9D5BF . 2180352 . . [5.1.2600.3654] . . c:\windows\SoftwareDistribution\Download\1e737459aaabc35cf71b0434922b4d59\SP2GDR\ntoskrnl.exe
[-] 2009-12-08 . 128D88B3176E70B2E3088ECEB842B673 . 2185984 . . [5.1.2600.3654] . . c:\windows\SoftwareDistribution\Download\1e737459aaabc35cf71b0434922b4d59\SP2QFE\ntoskrnl.exe
[-] 2009-08-05 . 8415D9C7C050E7022AED8ABF281BE4A6 . 2189184 . . [5.1.2600.5857] . . c:\windows\$NtUninstallKB977165$\ntoskrnl.exe
[-] 2009-08-04 . FDE779EA1A564EBFE16F4E0F82B61BAD . 2189312 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe
[7] 2009-02-08 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntoskrnl.exe
[7] 2009-02-07 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[7] 2009-02-06 . FACEBB0CA3154F77009CDFEE78A00BBB . 2180480 . . [5.1.2600.3520] . . c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
[7] 2009-02-06 . FACEBB0CA3154F77009CDFEE78A00BBB . 2180480 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntoskrnl.exe
[7] 2009-02-06 . 7A95B10A73737EBF24139AAA63F5212B . 2189056 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntoskrnl.exe
[7] 2009-02-06 . 7A95B10A73737EBF24139AAA63F5212B . 2189056 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB971486$\ntoskrnl.exe
[7] 2009-02-06 . 7A95B10A73737EBF24139AAA63F5212B . 2189056 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntoskrnl.exe
[7] 2009-02-06 . 7A95B10A73737EBF24139AAA63F5212B . 2189056 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\ntoskrnl.exe
[7] 2009-02-06 . 6A936E9D7BADAF3CAAEED1E1966EC1B0 . 2186112 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntoskrnl.exe
[7] 2009-02-06 . 6A936E9D7BADAF3CAAEED1E1966EC1B0 . 2186112 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntoskrnl.exe
[-] 2008-08-14 . 31914172342BFF330063F343AC6958FE . 2189184 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 . EEAF32F8E15A24F62BECB1BD403BB5C5 . 2189184 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
[-] 2008-08-14 . CE69DBD54221F2D40E49FF6DB77C6507 . 2185984 . . [5.1.2600.3427] . . c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
[7] 2008-04-13 . 0C89243C7C3EE199B96FCC16990E0679 . 2188928 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[7] 2008-04-13 . 0C89243C7C3EE199B96FCC16990E0679 . 2188928 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ntoskrnl.exe
[7] 2008-04-13 . 0C89243C7C3EE199B96FCC16990E0679 . 2188928 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntoskrnl.exe
[-] 2007-02-28 . 5A5C8DB4AA962C714C8371FBDF189FC9 . 2182144 . . [5.1.2600.3093] . . c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
[-] 2006-12-19 . CEF243F6DEFD20BE4ADDE26C7ECACB54 . 2182016 . . [5.1.2600.3051] . . c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
[-] 2005-03-02 . 28187802B7C368C0D3AEF7D4C382AABB . 2179456 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
[-] 2005-03-02 . 4D4CF2C14550A4B7718E94A6E581856E . 2179328 . . [5.1.2600.2622] . . c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
[-] 2010-02-16 . A046C627EC20456E2959B7BD628E1FD0 . 2066816 . . [5.1.2600.5938] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2010-02-16 . E8B8801DE921912EBDEEFC76662F7EAD . 2024448 . . [5.1.2600.5938] . . c:\windows\system32\ntkrnlpa.exe
[-] 2010-02-16 . DED8B5A89B085284634502E9D75AC78C . 2066944 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe
[-] 2009-12-09 . FFDCE1EEA79C678C40237D4E031E5B51 . 2066176 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe
[-] 2009-12-09 . FFDCE1EEA79C678C40237D4E031E5B51 . 2066176 . . [5.1.2600.5913] . . c:\windows\SoftwareDistribution\Download\1e737459aaabc35cf71b0434922b4d59\SP3QFE\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\SoftwareDistribution\Download\1e737459aaabc35cf71b0434922b4d59\SP3GDR\ntkrnlpa.exe
[-] 2009-12-08 . 384B15FBDCE2A54089A922886DED4EA0 . 2057728 . . [5.1.2600.3654] . . c:\windows\SoftwareDistribution\Download\1e737459aaabc35cf71b0434922b4d59\SP2GDR\ntkrnlpa.exe
[-] 2009-12-08 . BC123D9238A0C9BB3D853E407EE77254 . 2063104 . . [5.1.2600.3654] . . c:\windows\SoftwareDistribution\Download\1e737459aaabc35cf71b0434922b4d59\SP2QFE\ntkrnlpa.exe
[-] 2009-08-04 . 363B2BBEE0AEDC9E5433616D0AD0236A . 2066176 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe
[-] 2009-08-04 . 7437BA6F538E89381A2E3643AED296C7 . 2066048 . . [5.1.2600.5857] . . c:\windows\$NtUninstallKB977165$\ntkrnlpa.exe
[7] 2009-02-08 . 5BA7F2141BC6DB06100D0E5A732C617A . 2066048 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntkrnlpa.exe
[7] 2009-02-08 . 5BA7F2141BC6DB06100D0E5A732C617A . 2066048 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[7] 2009-02-08 . 5BA7F2141BC6DB06100D0E5A732C617A . 2066048 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntkrnlpa.exe
[7] 2009-02-07 . 5BA7F2141BC6DB06100D0E5A732C617A . 2066048 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB971486$\ntkrnlpa.exe
[7] 2009-02-06 . 3006410E24772CC6953F0B5C01BEB35F . 2057728 . . [5.1.2600.3520] . . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
[7] 2009-02-06 . 3006410E24772CC6953F0B5C01BEB35F . 2057728 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntkrnlpa.exe
[7] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[7] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntkrnlpa.exe
[7] 2009-02-06 . 9D832AF3FD1917DB0E1E8B2F000A2E3A . 2062976 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntkrnlpa.exe
[7] 2009-02-06 . 9D832AF3FD1917DB0E1E8B2F000A2E3A . 2062976 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntkrnlpa.exe
[-] 2008-08-14 . A25E9B86EFFB2AF33BF51E676B68BFB0 . 2066048 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 . 4AC58F03EB94A72809949D757FC39D80 . 2066048 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
[-] 2008-08-14 . 63EC865DFF6CCFC7BEF94B5C50297CAD . 2062976 . . [5.1.2600.3427] . . c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
[7] 2008-04-13 . 109F8E3E3C82E337BB71B6BC9B895D61 . 2065792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[7] 2008-04-13 . 109F8E3E3C82E337BB71B6BC9B895D61 . 2065792 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ntkrnlpa.exe
[7] 2008-04-13 . 109F8E3E3C82E337BB71B6BC9B895D61 . 2065792 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntkrnlpa.exe
[-] 2007-02-28 . 4D3DBDCCBF97F5BA1E74F322B155C3BA . 2059392 . . [5.1.2600.3093] . . c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
[-] 2006-12-19 . BA4B97C00A437C1CC3DA365D93EE1E9D . 2059392 . . [5.1.2600.3051] . . c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
[-] 2005-03-02 . 81013F36B21C7F72CF784CC6731E0002 . 2056832 . . [5.1.2600.2622] . . c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
[-] 2005-03-01 . D8ABA3EAB509627E707A3B14F00FBB6B . 2056832 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 16010240]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-25 7311360]
"nwiz"="nwiz.exe" [2006-01-25 1519616]
"DISCover"="c:\program files\DISC\DISCover.exe" [2006-03-16 1077248]
"DiscUpdateManager"="c:\program files\DISC\DiscUpdMgr.exe" [2006-03-16 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - c:\program files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-5-5 36903]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2/13/2010 12:26 PM 82952]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [2/13/2010 12:26 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\Mcafee\SystemCore\mfevtps.exe [2/13/2010 12:26 PM 141792]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2/13/2010 12:26 PM 312616]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2/13/2010 12:26 PM 88480]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2/13/2010 12:26 PM 55456]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2/13/2010 12:26 PM 88480]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2/13/2010 12:26 PM 83496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-07-06 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]
2010-07-20 c:\windows\Tasks\User_Feed_Synchronization-{3D7370D9-BB56-4205-ACA0-75F832ABBCC5}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
2010-07-20 c:\windows\Tasks\User_Feed_Synchronization-{82FFFFBC-33AC-4947-8AC4-3989044E9374}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/iguDefault_Search_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktopmSearch Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktopuInternet Settings,ProxyOverride =
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\Mozilla\Firefox\Profiles\6u037g1x.default\
FF - prefs.js: network.proxy.type - 4
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-20 16:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2175479376-3905921851-941298651-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3508)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\arservice.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\ARPWRMSG.EXE
c:\windows\eHome\ehmsas.exe
c:\program files\DISC\DiscStreamHub.exe
c:\hp\KBD\KBD.EXE
.
**************************************************************************
.
Completion time: 2010-07-20 16:44:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-20 23:44
Pre-Run: 110,372,380,672 bytes free
Post-Run: 110,892,453,888 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 52B007B13D31A68CBEF864736E701995