lol that took awhile
well here the log
ComboFix 08-06-20.4 - HP_Administrator 2008-06-27 15:46:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.306 [GMT -7:00]
Running from: C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\bigclaw\Application Data\FunWebProducts
C:\Documents and Settings\bigclaw\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Guest\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\HP_Administrator\Application Data\FunWebProducts
C:\Documents and Settings\HP_Administrator\Application Data\FunWebProducts\Data\HP_Administrator\avatar.dat
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\jeremiah\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\jesse\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\kids\Application Data\FunWebProducts
C:\Documents and Settings\kids\Application Data\FunWebProducts\Data\kids\avatar.dat
C:\Documents and Settings\kids\Application Data\FunWebProducts\Data\kids\wffavs.dat
C:\Documents and Settings\kids\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\rachel\Application Data\FunWebProducts
C:\Documents and Settings\rachel\Application Data\FunWebProducts\Data\rachel\avatar.dat
C:\Documents and Settings\rachel\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\roundeye\Application Data\FunWebProducts
C:\Documents and Settings\roundeye\Application Data\FunWebProducts\Data\roundeye\avatar.dat
C:\Documents and Settings\roundeye\Application Data\FunWebProducts\Data\roundeye\wffavs.dat
C:\Documents and Settings\roundeye\Application Data\macromedia\Flash Player\#SharedObjects\DQN4Y3T4\www.broadcaster.com
C:\Documents and Settings\roundeye\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\roundeye\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\roundeye\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Cache\
00D58BE8.jpg
C:\Program Files\FunWebProducts\ScreenSaver\Cache\
00D97BE7
C:\Program Files\FunWebProducts\ScreenSaver\Cache\files.ini
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00059988.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00177D4E.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\
001E466D.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\
0023FB0F.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\
0049A0E0.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00D3E2DB.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00D59FBE.dat
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00D85F4B.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00D9BD93.dat
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00DC15FA.dat
C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\
00D59FBE.jpg
C:\Program Files\FunWebProducts\ScreenSaver\Images\f3wallpp.bmp
C:\Program Files\FunWebProducts\ScreenSaver\Images\wrkparam.lst
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MySignatureInsertBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn-new.html
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn-new.htmlx
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\6.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\6.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\6.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\6.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\6.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\6.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\6.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\6.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\6.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\6.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\6.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\6.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\6.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\6.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\6.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\6.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\6.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\6.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\6.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\6.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\6.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\6.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\6.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\6.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\
0002B6C3
C:\Program Files\MyWebSearch\bar\Cache\
00086327.bin
C:\Program Files\MyWebSearch\bar\Cache\
0008677D.bin
C:\Program Files\MyWebSearch\bar\Cache\
00086B84.bin
C:\Program Files\MyWebSearch\bar\Cache\
00086F3D.bin
C:\Program Files\MyWebSearch\bar\Cache\
00087383.bin
C:\Program Files\MyWebSearch\bar\Cache\
009FD377.bin
C:\Program Files\MyWebSearch\bar\Cache\
009FDCBE.bin
C:\Program Files\MyWebSearch\bar\Cache\
009FEB35.bin
C:\Program Files\MyWebSearch\bar\Cache\
009FF0E2.bin
C:\Program Files\MyWebSearch\bar\Cache\
00A00044.bin
C:\Program Files\MyWebSearch\bar\Cache\
00A0046A.bin
C:\Program Files\MyWebSearch\bar\Cache\
00A0302D.bin
C:\Program Files\MyWebSearch\bar\Cache\
00A034B2.bin
C:\Program Files\MyWebSearch\bar\Cache\
00A04413
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Message\COMMON\ask_logo.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\center.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\index.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\mid_dots.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\mws_logo.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\protect.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\shocked.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\stop.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\systray.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\systrayp.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\tp_grad.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\warn.gif
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\SrchAstt\6.bin\MWSSRCAS.DLL
C:\Program Files\outlook
C:\Temp\gbRve12
C:\WINDOWS\Fonts\'
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\system32\_000001_.tmp.dll
C:\WINDOWS\system32\_000004_.tmp.dll
C:\WINDOWS\system32\_000005_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\aqVreo18
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\DMTEdMoq.ini
C:\WINDOWS\system32\DMTEdMoq.ini2
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\rightonadz-uninst.exe
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
C:\WINDOWS\system32\yccdd.ini
C:\WINDOWS\system32\yccdd.ini2
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.
2008-06-27 14:28 . 2008-01-14 14:36 267,592 --a------ C:\Program Files\Uninstall Ask Toolbar.dll
2008-06-26 21:54 . 2008-06-26 21:54 <DIR> d-------- C:\Program Files\Avira
2008-06-26 21:54 . 2008-06-26 21:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-06-21 06:16 . 2008-06-21 06:16 <DIR> d-------- C:\Program Files\idlebias
2008-06-20 14:57 . 2008-06-20 14:57 <DIR> d-------- C:\Program Files\IObit
2008-06-18 16:19 . 2008-06-18 16:19 285,696 --a------ C:\WINDOWS\system32\qoMdETMD.dll
2008-06-18 16:14 . 2008-06-05 18:24 47 --a------ C:\Documents and Settings\HP_Administrator\readme.bat
2008-06-17 23:15 . 2008-06-17 23:15 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Zinaps2008
2008-06-14 15:44 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-06-14 15:41 . 2008-06-14 15:44 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-06-14 15:41 . 2008-06-18 09:21 <DIR> d-------- C:\WINDOWS\Logs
2008-06-14 15:36 . 2008-06-14 15:36 <DIR> d-------- C:\Program Files\NovaLogic
2008-06-13 15:05 . 2008-06-13 15:05 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\vlc
2008-06-13 15:02 . 2008-06-13 15:02 <DIR> d-------- C:\Program Files\VideoLAN
2008-06-11 05:47 . 2008-06-11 05:47 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-10 12:36 . 2008-06-13 06:10 272,128 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 12:36 . 2008-06-13 06:10 272,128 --a------ C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-08 20:04 . 2008-06-08 20:04 <DIR> d--hs---- C:\found.001
2008-06-05 13:01 . 2008-06-05 13:02 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\MSNInstaller
2008-06-03 15:08 . 2008-06-04 09:00 <DIR> d-------- C:\Documents and Settings\kids\Contacts
2008-06-01 19:59 . 2008-06-01 19:59 1,409 --a------ C:\WINDOWS\system32\tmpEC30C.FOT
2008-06-01 19:59 . 2008-06-01 19:59 1,409 --a------ C:\WINDOWS\system32\tmpA540C.FOT
2008-06-01 19:59 . 2008-06-01 19:59 1,409 --a------ C:\WINDOWS\system32\tmp7D40C.FOT
2008-06-01 19:59 . 2008-06-01 19:59 1,409 --a------ C:\WINDOWS\system32\tmp5920C.FOT
2008-06-01 19:59 . 2008-06-01 19:59 1,409 --a------ C:\WINDOWS\system32\tmp1530C.FOT
2008-05-29 16:51 . 2008-05-29 16:51 1,409 --a------ C:\WINDOWS\system32\tmpE5325.FOT
2008-05-29 16:51 . 2008-05-29 16:51 1,409 --a------ C:\WINDOWS\system32\tmpC1125.FOT
2008-05-29 16:51 . 2008-05-29 16:51 1,409 --a------ C:\WINDOWS\system32\tmp99125.FOT
2008-05-29 16:51 . 2008-05-29 16:51 1,409 --a------ C:\WINDOWS\system32\tmp90F15.FOT
2008-05-29 16:51 . 2008-05-29 16:51 1,409 --a------ C:\WINDOWS\system32\tmp14025.FOT
2008-05-28 17:17 . 2008-05-28 17:18 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-05-28 17:17 . 2008-05-28 17:17 <DIR> d-------- C:\Program Files\Windows Live Favorites
2008-05-28 17:17 . 2008-06-11 21:48 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Contacts
2008-05-28 17:12 . 2008-05-28 17:16 <DIR> d-------- C:\Program Files\Windows Live
2008-05-28 17:12 . 2008-05-28 17:15 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-28 17:11 . 2008-05-28 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 23:15 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\LimeWire
2008-06-27 22:42 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\MSN6
2008-06-27 21:38 --------- d-----w C:\Program Files\free-downloads.net
2008-06-27 21:38 --------- d-----w C:\Program Files\Conduit
2008-06-27 17:56 --------- d-----w C:\Documents and Settings\kids\Application Data\MSN6
2008-06-23 03:27 --------- d-----w C:\Program Files\Google
2008-06-21 13:17 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\idlebias
2008-06-21 13:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\part dead amok eggs
2008-06-20 05:18 --------- d-----w C:\Program Files\Trend Micro
2008-06-18 16:21 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Walgreens
2008-06-15 08:24 --------- d-----w C:\Program Files\FrostWire
2008-06-14 22:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-11 13:36 6,924 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2008-06-09 15:52 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-07 20:22 --------- d-----w C:\Program Files\LimeWire
2008-05-27 01:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\SierraHome
2008-05-27 01:12 --------- d-----w C:\Program Files\SierraHome
2008-05-27 01:12 --------- d-----w C:\Program Files\Common Files\Nova Development
2008-05-24 01:48 --------- d-----w C:\Program Files\My.Freeze.com Toolbar with NetAssistant
2008-05-24 01:38 --------- d-----w C:\Program Files\MSN Messenger
2008-05-24 01:37 --------- d-----w C:\Program Files\GemMaster
2008-05-23 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-05-23 19:12 --------- d-----w C:\Program Files\Microsoft Money 2006
2008-05-23 19:12 --------- d-----w C:\Program Files\Atari
2008-05-22 02:25 --------- d-----w C:\Program Files\Yahoo!
2008-05-16 23:29 --------- d-----w C:\Program Files\AGEIA Technologies
2008-05-16 23:05 6,506 ----a-w C:\Documents and Settings\kids\Application Data\wklnhst.dat
2008-05-16 04:13 --------- d-----w C:\Program Files\Freeze.com
2008-05-16 04:13 --------- d-----w C:\Program Files\Free Offers from Freeze.com
2008-05-16 04:13 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\WeatherBug
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-29 03:26 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\U3
2008-04-29 03:22 --------- d-----w C:\Documents and Settings\kids\Application Data\U3
2008-04-27 00:04 --------- d-----w C:\Program Files\Prison Tycoon
2007-10-03 01:55 270 ----a-w C:\Documents and Settings\jesse\Application Data\wklnhst.dat
2007-09-03 06:34 144 ----a-w C:\Documents and Settings\rachel\Application Data\wklnhst.dat
2007-08-22 13:49 5,192 ----a-w C:\Documents and Settings\bigclaw\Application Data\wklnhst.dat
2007-05-23 23:00 2,912 ----a-w C:\Documents and Settings\roundeye\Application Data\wklnhst.dat
2007-04-08 21:29 32 ----a-r C:\Documents and Settings\All Users\hash.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31B51B6C-14D7-452F-9325-77293A8E9614}]
2008-06-18 16:19 285696 --a------ C:\WINDOWS\system32\qoMdETMD.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"Walgreens PhotoShow Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [2006-04-19 23:35 237568]
"Exit Ooze"="C:\DOCUME~1\HP_ADM~1\APPLIC~1\idlebias\Ping Send New.exe" [2008-06-21 06:16 674304]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [ ]
"Zinaps2008"="C:\Documents and Settings\HP_Administrator\Application Data\Zinaps2008\Zinaps.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-26 13:39 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 22:01 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 14:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 00:19 77312 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 15:50 7311360]
"nwiz"="nwiz.exe" [2006-05-09 15:50 1519616 C:\WINDOWS\system32\nwiz.exe]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 10:05 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"QUICKCARE"="C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe" [2006-11-07 21:07 192512]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [ ]
"Mouse Suite 98 Daemon"="ICO.EXE" [2003-11-20 14:08 57344 C:\WINDOWS\system32\ico.exe]
"Picasa Media Detector"="C:\Documents and Settings\HP_Administrator\My Documents\My Downloads\Picasa2\PicasaMediaDetector.exe" [2007-05-01 23:08 366400]
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\6.bin\m3SrchMn.exe" [ ]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 18:09 842584]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"Amok Eggs Four Web"="C:\Documents and Settings\All Users\Application Data\part dead amok eggs\Show Trust.exe" [2008-06-27 16:16 4920320]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 20:56 5367664]
C:\Documents and Settings\rachel\Start Menu\Programs\Startup\
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-11-11 20:13:14 27136]
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-11-11 20:13:14 27136]
C:\Documents and Settings\jesse\Start Menu\Programs\Startup\
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-11-11 20:13:14 27136]
C:\Documents and Settings\kids\Start Menu\Programs\Startup\
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-11-11 20:13:14 27136]
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-02-08 14:32:57 147456]
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-05-12 18:39:06 344064]
PowerReg Scheduler V3.exe [2008-03-22 20:12:27 225280]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmklLc]
pmnmklLc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvtqpq]
tuvtqpq.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=C:\WINDOWS\pss\Updates From HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-03-11 21:34 49152 C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
--a------ 2006-02-15 23:34 249856 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 16:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2006-06-13 20:05 16239616 C:\WINDOWS\RTHDCPL.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN\\MSNCoreFiles\\msn.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Documents and Settings\\HP_Administrator\\Desktop\\YGOJoey\\Yu-Gi-Oh! Power of Chaos 3 - Joey The Passion\\joey_pc.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
S3 pelmouse;Mouse Suite Driver;C:\WINDOWS\system32\DRIVERS\pelmouse.sys [2003-01-10 13:55]
S3 pelusblf;USB Mouse Low Filter Driver;C:\WINDOWS\system32\DRIVERS\pelusblf.sys [2004-09-22 11:16]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa9d2bf2-b8fc-11dc-8c17-0018f35b46a4}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-06-11 00:31:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-27 23:16:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-06-27 23:19:49 C:\WINDOWS\Tasks\DMATask 0 {D2B22905-47C9-4b82-8E74-47AA9D2DE378} 0~0.job"
- c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe;Sched DMATask 0 {D2B22905-47C9-4b82-8E74-47AA9D2DE378} 0~0
"2008-05-01 04:55:26 C:\WINDOWS\Tasks\DMATask 1 {D2B22905-47C9-4b82-8E74-47AA9D2DE378} 0~0.job"
- c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe;Sched DMATask 1 {D2B22905-47C9-4b82-8E74-47AA9D2DE378} 0~0
"2008-06-21 16:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
"2008-06-21 22:52:11 C:\WINDOWS\Tasks\WebReg Deskjet F4100 series.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
"2008-06-24 00:00:00 C:\WINDOWS\Tasks\wrSpySweeper_BB3012046B894F5D89F2914D4688E739.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe=/ScheduleSweep=wrSpySweeper_BB3012046B894F5D89F2914D4688E739
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- C:\
"2008-03-10 13:00:00 C:\WINDOWS\Tasks\wrSpySweeper_FE4624BB07B5462794BBAE776A3C0EC1.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe=/ScheduleSweep=wrSpySweeper_FE4624BB07B5462794BBAE776A3C0EC1
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- C:\
"2008-03-10 12:00:00 C:\WINDOWS\Tasks\wrSpySweeper_FFA7BF52D5B44FBEA7950F4AA5B91CA6.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe=/ScheduleSweep=wrSpySweeper_FFA7BF52D5B44FBEA7950F4AA5B91CA6
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- C:\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-27 16:14:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\FSRremoS.EXE
C:\Program Files\Walgreens\Walgreens PhotoShow 4\data\Xtras\mssysmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\Webroot\Spy Sweeper\ssu.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-06-27 16:26:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-27 23:25:38
Pre-Run: 109,187,633,152 bytes free
Post-Run: 113,687,810,048 bytes free
427 --- E O F --- 2008-06-21 13:14:22
and again thank u so much