I did not find MYWEBSEARCH
Here are the OTMoveit2 resultsExplorer killed successfully
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D >
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D\\ deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7} >
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}\\ deleted successfully.
File/Folder C:\PROGRA~1\MYWEBS~1 not found.
< purity >
< EmptyTemp >
File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFF4E8.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\hsperfdata_Compaq_Owner\2240 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JETC478.tmp scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07102008_163643
Files moved on Reboot...
DllUnregisterServer procedure not found in C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll NOT unregistered.
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll moved successfully.
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFF4E8.tmp moved successfully.
File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\hsperfdata_Compaq_Owner\2240 not found!
File C:\WINDOWS\temp\JETC478.tmp not found!
Here are the Kaspersky results-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, July 10, 2008 7:51:24 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 10/07/2008
Kaspersky Anti-Virus database records: 936629
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan Statistics:
Total number of scanned objects: 131838
Number of viruses found: 22
Number of infected objects: 68
Number of suspicious objects: 1
Duration of the scan process: 02:04:33
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e5e3afafd149af59bc10e3107706e49_74673abe-e0d7-4bce-8fdc-cb3c8f6a2156 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\ccSubSDK\submissions.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\volatile.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-07-10_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{F5339D95-65A1-41EE-8066-91BFE521106B}.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{F5339D95-65A1-41EE-8066-91BFE521106B}.sds Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\407A08F5.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\D608FA65.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\MySpace\IM\Logs\MySpaceIM-20080710-164018.log Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\MSHist012008071020080711\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\hsperfdata_Compaq_Owner\3704 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\~DF3F12.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\My Documents\KH030510.exe Infected: Hoax.Win32.Renos.vaff skipped
C:\Documents and Settings\Compaq_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Compaq_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\$shtdwn$.req Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\admparse.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\admparse.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\advpack.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\advpack.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\browseui.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\corpol.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\custsat.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\dxtmsft.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\dxtrans.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\extmgr.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\extmgr.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\feeddisc.wav Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\hmmapi.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\hmmapi.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\html.iec Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\html.iec.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\icardie.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\icardie.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\icrav03.rat Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ie4uinit.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ie4uinit.exe.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieakeng.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieakeng.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieakmmc.chm Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieaksie.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieaksie.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieakui.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieakui.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieapfltr.dat Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieapfltr.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iedkcs32.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iedkcs32.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iedw.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iedw.exe.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieencode.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieeula.chm Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieframe.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieframe.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iepeers.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iepeers.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieproxy.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iernonce.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iernonce.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iertutil.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iesetup.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iesetup.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iesupp.chm Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieudinit.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieui.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieui.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieuinit.inf Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ieunatt.exe.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iexplore.chm Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iexplore.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\iexplore.exe.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\imgutil.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\inetcorp.iem Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\inetcpl.cpl Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\inetcpl.cpl.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\inetres.adm Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\inetset.iem Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\infobar.wav Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\inseng.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\inseng.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\install.ins Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\jscript.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\jsproxy.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\licmgr10.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\licmgr10.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msfeeds.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msfeeds.mof Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msfeedsbs.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msfeedsbs.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msfeedsbs.mof Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msfeedssync.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshta.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshta.exe.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshtml.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshtml.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshtml.tlb Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshtmled.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshtmled.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshtmler.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mshtmler.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msls31.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msrating.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\msrating.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\mstime.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\navstart.wav Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\occache.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\occache.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\occache.ini Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\pngfilt.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\popupblk.wav Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\shdocvw.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\shlwapi.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\spmsg.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\spuninst.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\spupdsvc.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\tdc.ocx Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\ticrf.rat Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\eula.rtf Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\idndl.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\ie7.cat Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\iecustom.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\iereseticons.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\iesetup.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\legitlibm.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\nlsdl.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\update.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\update.exe.manifest Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\update.inf Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\update.ver Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\updspapi.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\update\xmllitesetup.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\url.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\urlmon.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\urlmon.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\vbscript.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\vgx.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\webcheck.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\webcheck.dll.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\webcheck.ini Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\winfxdocobj.exe Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\winfxdocobj.exe.mui Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\wininet.dll Object is locked skipped
C:\ee376f019e8a88031df0a5e010fdc2\wininet.dll.mui Object is locked skipped
C:\hp\bin\wbug\CompaqPresario_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
C:\hp\bin\wbug\CompaqPresario_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
C:\hp\bin\wbug\CompaqPresario_Spring06.exe WiseSFX: infected - 2 skipped
C:\hp\bin\wbug\CompaqPresario_Spring06.exe WiseSFXDropper: infected - 2 skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\L0000013.FCS Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.me Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.mm Object is locked skipped
C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe/data0004 Infected: not-a-virus:AdWare.Win32.Agent.aeh skipped
C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe NSIS: infected - 1 skipped
C:\Program Files\Spyware Doctor\tools\swpg.DAT Infected: not-a-virus:Monitor.Win32.KeyLogger.dq skipped
C:\RECYCLER\S-1-5-21-1610297878-485223862-1635446001-1009\Dc24.exe/file090 Infected: not-a-virus:Monitor.Win32.KeyLogger.dq skipped
C:\RECYCLER\S-1-5-21-1610297878-485223862-1635446001-1009\Dc24.exe Inno: infected - 1 skipped
C:\RECYCLER\S-1-5-21-1610297878-485223862-1635446001-1009\Dc40.wm Infected: Trojan-Downloader.WMA.Wimad.m skipped
C:\SDFix\backups\catchme.zip/uoyzsydz.exe Infected: Hoax.Win32.Renos.vaff skipped
C:\SDFix\backups\catchme.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP300\A0174802.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP339\A0177784.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP340\A0177790.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP341\A0177793.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP342\A0177808.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP343\A0177813.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP344\A0177827.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP345\A0177829.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP346\A0177833.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP347\A0177837.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP348\A0177839.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP349\A0177843.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP350\A0177847.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP351\A0177849.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP352\A0177852.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP353\A0177855.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP354\A0177858.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP355\A0177860.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP355\A0178692.dll Infected: Trojan-Downloader.Win32.Agent.vaq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP355\A0180760.exe Infected: not-a-virus:FraudTool.Win32.SpyAway.q skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP355\A0180767.exe Infected: not-a-virus:FraudTool.Win32.SpyAway.r skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP355\A0182799.exe Infected: Hoax.Win32.Renos.vaff skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182817.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182818.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182819.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182820.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182821.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182822.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182824.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182825.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182826.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182827.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182828.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182829.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182830.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182831.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182832.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182833.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182834.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182835.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182836.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182837.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182838.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182839.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182840.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182845.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP356\A0182853.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP358\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\JETC96A.tmp Object is locked skipped
C:\WINDOWS\update2.html Suspicious: Packed.Win32.Morphine.a skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\I386\Apps\APP27596\src\CompaqPresario_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\Apps\APP27596\src\CompaqPresario_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\Apps\APP27596\src\CompaqPresario_Spring06.exe WiseSFX: infected - 2 skipped
D:\I386\Apps\APP27596\src\CompaqPresario_Spring06.exe WiseSFXDropper: infected - 2 skipped
D:\I386\Apps\APP27596\src\HPPavillion_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\Apps\APP27596\src\HPPavillion_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\Apps\APP27596\src\HPPavillion_Spring06.exe WiseSFX: infected - 2 skipped
D:\I386\Apps\APP27596\src\HPPavillion_Spring06.exe WiseSFXDropper: infected - 2 skipped
Scan process completed.
Here is the DSS report main.txt (extra.txt did not pop up again)Deckard's System Scanner v20071014.68
Run by Compaq_Owner on 2008-07-10 19:51:54
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Compaq_Owner.exe) ----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:52:09 PM, on 7/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Sierra\Planner\Plnrnote.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\Compaq_Owner\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\COMPAQ~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...a...&pf=desktopR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.h...a...&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://www.crawler.c...spx?tb_id=60327R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
http://dnl.crawler.c...aspx?TbId=60327R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.h...a...&pf=desktopR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://dnl.crawler.c...aspx?TbId=60327R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Congoo Netpass - {40498DEF-8B13-44A6-A1A7-69DFE36E9210} - C:\Program Files\Congoo Netpass\congootb.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Common\helper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Congoo Netpass - {40498DEF-8B13-44A6-A1A7-69DFE36E9210} - C:\Program Files\Congoo Netpass\congootb.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] c:\hp\bin\cloaker.exe c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Compaq Organize.lnk = ?
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: (no name) - {0AD475F1-D955-40a7-9FFF-C3BF075F04AA} - C:\Program Files\Congoo Netpass\congootb.dll
O9 - Extra 'Tools' menuitem: Congoo Netpass - {0AD475F1-D955-40a7-9FFF-C3BF075F04AA} - C:\Program Files\Congoo Netpass\congootb.dll
O9 - Extra button: (no name) - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
O9 - Extra 'Tools' menuitem: Congoo Toolbar - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .eml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) -
https://webdl.symant...ex/symdlmgr.cabO18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 10567 bytes
-- Files created between 2008-06-10 and 2008-07-10 -----------------------------
2008-07-10 16:46:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-10 16:46:41 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-07-10 16:46:41 0 d-------- C:\WINDOWS\LastGood
2008-07-09 16:14:11 0 d-------- C:\WINDOWS\ERUNT
2008-07-09 15:50:56 1447803 --a------ C:\SDFix.exe
2008-07-09 15:40:01 0 d-------- C:\Program Files\Crawler
2008-07-09 15:39:51 141312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-07-09 15:39:50 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Spyware Terminator
2008-07-09 15:39:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-07-09 15:39:48 0 d-------- C:\Program Files\Spyware Terminator
2008-07-08 19:24:58 0 d-------- C:\Program Files\Trend Micro
2008-07-08 18:12:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-08 17:51:47 0 d-------- C:\Program Files\XoftSpySE
2008-07-08 16:49:35 0 d-------- C:\Program Files\Windows Sidebar
2008-07-08 16:49:35 0 d-------- C:\Program Files\Norton AntiVirus
2008-07-06 09:16:21 0 d-------- C:\Shell mp3
2008-07-03 13:39:46 0 d-------- C:\Program Files\Common
-- Find3M Report ---------------------------------------------------------------
2008-07-10 16:47:17 40210 --a------ C:\logfile
2008-07-10 16:41:03 3649 --a------ C:\WINDOWS\viassary-hp.reg
2008-07-09 16:30:38 0 d-------- C:\Program Files\Common Files
2008-07-09 15:36:34 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-08 18:12:46 0 d-------- C:\Program Files\Lavasoft
2008-07-08 18:12:07 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-08 16:50:11 0 d-------- C:\Program Files\Symantec
2008-06-04 12:59:22 3976 --a----c- C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40498DEF-8B13-44A6-A1A7-69DFE36E9210}]
03/05/2007 03:39 PM 915160 --------- C:\Program Files\Congoo Netpass\congootb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
07/08/2008 04:51 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}]
07/03/2008 01:39 PM 118796 --a------ C:\Program Files\Common\helper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [09/21/2005 12:41 PM]
"_SetRes"="c:\hp\bin\cloaker c:\hp\bin\res.bat" []
"IcoSet"="c:\hp\bin\cloaker.exe" [11/07/1999 02:11 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [02/17/2005 09:11 AM]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [05/04/2004 02:21 AM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/22/2003 08:38 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [12/21/2005 04:01 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/01/2006 04:57 PM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/25/2008 08:47 PM]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [02/07/2008 01:49 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/26/2007 03:41 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 07:00 AM]
"ares"="C:\Program Files\Ares\Ares.exe" [05/14/2007 05:37 PM]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [02/01/2008 03:32 PM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\
Compaq Organize.lnk - C:\Program Files\Hewlett-Packard\Compaq Organize\bin\displayAgent.exe [12/21/2005 4:17:08 PM]
DING!.lnk - C:\Program Files\Southwest Airlines\Ding\Ding.exe [6/22/2006 2:15:48 PM]
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [1/29/2007 4:33:41 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe [12/21/2005 4:17:43 PM]
Event Planner Reminders Tray Icon.lnk - C:\Program Files\Sierra\Planner\Plnrnote.exe [12/22/2007 9:48:03 PM]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2/20/2007 6:10:26 AM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e835cfc-0a55-11dc-9e87-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
-- End of Deckard's System Scanner: finished at 2008-07-10 19:52:32 ------------