Here are the logs for C:\ComboFix.txt from step 1.
The content of C:\lopR.txt from step 2.
ComboFix 09-01-19.05 - HP_Administrator 2009-01-20 1:29:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.579 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Start Menu\Live Safety Center.lnk
c:\documents and settings\HP_Administrator\Application Data\FunWebProducts
c:\windows\system32\aahatlhy.dll
c:\windows\system32\adbyglnt.dll
c:\windows\system32\adilukil.ini
c:\windows\system32\afijipok.ini
c:\windows\system32\atudadij.ini
c:\windows\system32\avafiyer.ini
c:\windows\system32\ayodalip.ini
c:\windows\system32\ccbeg.ini
c:\windows\system32\ccbeg.ini2
c:\windows\system32\civsadev.ini
c:\windows\system32\csrpde.dll
c:\windows\system32\devspdyn.ini
c:\windows\system32\dffMlnpo.ini
c:\windows\system32\dffMlnpo.ini2
c:\windows\system32\djgcenhq.ini
c:\windows\system32\ebenimit.ini
c:\windows\system32\efureyiy.ini
c:\windows\system32\eskgofvk.ini
c:\windows\system32\hnoknl.dll
c:\windows\system32\htvhaojc.ini
c:\windows\system32\igawusuw.ini
c:\windows\system32\ijeyukid.ini
c:\windows\system32\iwitesod.ini
c:\windows\system32\iwudebez.ini
c:\windows\system32\jbjyvnap.ini
c:\windows\system32\kpmkrmwa.ini
c:\windows\system32\lkixtdch.dll
c:\windows\system32\mwgwiybj.ini
c:\windows\system32\nfhqllaa.ini
c:\windows\system32\nqngjasw.ini
c:\windows\system32\ogakofop.ini
c:\windows\system32\ojkwtlud.dll
c:\windows\system32\onipiyis.ini
c:\windows\system32\opafafuf.ini
c:\windows\system32\osojegey.ini
c:\windows\system32\pkerltqu.ini
c:\windows\system32\rupbkipd.ini
c:\windows\system32\sacjyknl.ini
c:\windows\system32\test.ttt
c:\windows\system32\tncxgoba.dll
c:\windows\system32\tvcfcpbm.ini
c:\windows\system32\uditezay.ini
c:\windows\system32\uduburuh.ini
c:\windows\system32\umezozak.ini
c:\windows\system32\umuwenak.ini
c:\windows\system32\uniboyil.ini
c:\windows\system32\uniq.tll
c:\windows\system32\uyiyugon.ini
c:\windows\system32\vxhotjet.ini
c:\windows\system32\win32hlp.cnf
c:\windows\system32\wyredc.dll
c:\windows\system32\xntpbaeu.ini
c:\windows\system32\yxlbhcgh.ini
c:\windows\system32\YxyayGgh.ini
c:\windows\system32\YxyayGgh.ini2
c:\windows\Tasks\ephndtne.job
D:\Autorun.inf
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.
2009-01-20 00:09 . 2009-01-20 00:09 <DIR> d-------- c:\program files\Trend Micro
2009-01-19 22:55 . 2009-01-19 22:55 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-19 22:55 . 2009-01-19 22:55 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-01-19 22:55 . 2009-01-19 22:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-19 22:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-19 22:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-19 21:14 . 2009-01-19 21:14 578,560 --a------ c:\windows\system32\dllcache\user32.dll
2009-01-19 21:11 . 2009-01-19 21:11 <DIR> d-------- c:\windows\ERUNT
2009-01-19 20:59 . 2009-01-19 21:34 <DIR> d-------- C:\SDFix
2009-01-19 18:12 . 2009-01-19 18:12 <DIR> d-------- c:\program files\Symantec
2009-01-19 18:12 . 2009-01-19 18:12 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-19 18:12 . 2009-01-19 18:12 60,808 --a------ c:\windows\system32\S32EVNT1.DLL
2009-01-19 18:12 . 2009-01-19 18:11 36,272 -ra------ c:\windows\system32\drivers\SymIM.sys
2009-01-19 18:12 . 2009-01-19 18:12 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-19 18:12 . 2009-01-19 18:12 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- c:\windows\system32\drivers\NAV
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- c:\program files\Windows Sidebar
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- c:\program files\NortonInstaller
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- c:\program files\Norton AntiVirus
2009-01-19 18:01 . 2009-01-19 18:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avg8
2009-01-19 02:00 . 2009-01-19 02:00 <DIR> d-------- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-01-07 01:01 . 2009-01-18 18:37 <DIR> d-------- c:\documents and settings\LocalService\Application Data\SACore
2009-01-07 00:59 . 2009-01-07 00:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-01-07 00:39 . 2009-01-19 00:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\McAfee
2009-01-05 17:47 . 2009-01-19 18:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Norton
2009-01-05 17:44 . 2009-01-05 17:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2008-12-25 20:46 . 2008-12-25 20:46 <DIR> d-------- c:\program files\Sony Setup
2008-12-25 20:46 . 2008-12-25 20:46 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Sony Setup
2008-12-21 18:53 . 2008-12-21 18:53 <DIR> d-------- c:\windows\system32\LogFiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-20 02:13 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-20 02:13 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-01-07 23:46 --------- d-----w c:\program files\MSN Messenger
2009-01-07 08:26 --------- d-----w c:\program files\MySpace
2009-01-06 01:23 --------- d-----w c:\program files\Norton 360
2008-12-28 06:51 --------- d-----w c:\program files\InterActual
2008-12-20 02:00 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\Symantec
2008-11-07 09:35 1,520 -c--a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 61,440 2005-02-03 00:44:24 c:\hp\KBD\bak\KBD.EXE
-c--a-w 106,496 2004-09-27 15:09:06 c:\program files\CA\eTrust PestPatrol\bak\PPActiveDetection.exe
-c--a-w 180,269 2005-05-27 19:46:58 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
-c--a-w 579,072 2007-12-20 20:50:05 c:\program files\Grisoft\AVG7\bak\avgcc.exe
-c--a-w 41 2008-02-06 16:55:37 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.csv
-c--a-w 5,601 2008-02-04 21:49:16 c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.csv
----a-w 6,435 2009-01-20 07:59:37 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\bak\HPBootOp.csv
-c--a-w 5,601 2008-02-04 21:49:16 c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.csv
----a-w 245,760 2005-02-26 05:34:02 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\bak\HPBootOp.exe
----a-w 6,435 2009-01-20 07:59:37 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\bak\HPBootOp.csv
-c--a-w 41 2008-02-06 16:55:37 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.csv
----a-w 245,760 2005-02-26 05:34:02 c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\bak\HPBootOp.exe
-c--a-w 1,694,208 2004-10-13 23:24:38 c:\program files\Messenger\bak\msmsgs.exe
------w 1,695,232 2008-04-14 00:12:28 c:\program files\Messenger\msmsgs.exe
-c--a-w 98,304 2005-05-27 19:57:29 c:\program files\QuickTime\bak\qttask.exe
----a-w 413,696 2008-09-06 22:09:14 c:\program files\QuickTime\QTTask.exe
-c--a-w 4,670,704 2007-08-31 01:43:18 c:\program files\Yahoo!\Messenger\bak\YahooMessenger.exe
----a-w 4,670,704 2007-08-31 00:43:18 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
-c--a-w 59,392 2004-08-10 18:04:42 c:\windows\ehome\bak\ehtray.exe
----a-w 59,392 2004-08-10 18:04:42 c:\windows\ehome\ehtray.exe
-c--a-w 15,360 2004-08-10 12:00:00 c:\windows\system32\bak\ctfmon.exe
----a-w 15,360 2008-04-14 00:12:16 c:\windows\system32\ctfmon.exe
-c--a-w 77,824 2005-04-05 21:19:18 c:\windows\system32\bak\hkcmd.exe
-c--a-w 659,456 2004-06-07 18:42:30 c:\windows\system32\bak\hphmon06.exe
-c--a-w 114,688 2005-04-05 21:23:14 c:\windows\system32\bak\igfxpers.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [N/A]
"Persistence"="c:\windows\system32\igfxpers.exe" [N/A]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\bak\bak\HPBootOp.exe" [2005-02-25 245760]
"IcoSet"="c:\hp\bin\cloaker.exe" [1999-11-06 27136]
"regcmdcons"="c:\hp\bin\cloaker.exe" [1999-11-06 27136]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [N/A]
"KBD"="c:\hp\KBD\KBD.EXE" [N/A]
"NI.UGA6P_0001_N122M2210"="c:\documents and settings\hp_administrator\application data\install_en[1].exe" [N/A]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [N/A]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-12 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=c:\windows\pss\SpySubtract.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-09-10 16:40 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MalwareAlarm]
c:\program files\MalwareAlarm\MalwareAlarm.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 16:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
c:\program files\MySpace\IM\MySpaceIM.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 16:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\Ymsgr_tray.exe"=
"c:\\WINDOWS\\RTHDCPL.EXE"=
"%windir%\\system32\\drivers\\svchost.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1002000.007\SymEFA.sys [2009-01-19 309296]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1002000.007\BHDrvx86.sys [2009-01-19 255536]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1002000.007\cchpx86.sys [2009-01-19 362544]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090115.001\IDSxpx86.sys [2009-01-19 274808]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-01-19 99376]
R4 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe [2009-01-19 115560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder
2009-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{AACD7047-0D61-450C-BC22-5A8C59228DBE} - (no file)
BHO-{E89B71D5-1173-4250-835D-3CFEE9E713C8} - (no file)
Notify-ddcAppmn - ddcAppmn.dll
Notify-fccaaba - fccaaba.dll
Notify-fihhigrw - fihhigrw.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.aol.com/?src=customie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: www.select2perform.com
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-20 01:35:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4166429689-3702264920-1142536906-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-20 1:40:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-20 09:40:03
Pre-Run: 210,847,711,232 bytes free
Post-Run: 210,750,722,048 bytes free
281 --- E O F --- 2009-01-05 16:01:05
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 2.80GHz )
BIOS : Phoenix - Award BIOS v6.00PG
USER : HP_Administrator ( Administrator )
BOOT : Normal boot
Antivirus : Norton AntiVirus 16.2.0.7 (Not Activated)
C:\ (Local Disk) - NTFS - Total:271 Go (Free:196 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:1 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Tue 01/20/2009| 1:46 )
--------------------\\ Listing folders in APPLIC~1
[05/27/2005|11:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Apple Computer
[01/27/2005|05:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[05/27/2005|12:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InterMute
[01/19/2009|06:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[05/27/2005|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Real
[05/27/2005|12:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SampleView
[05/27/2005|12:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Symantec
[09/15/2008|01:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[06/24/2008|03:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[12/04/2007|12:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL
[05/21/2006|12:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL Downloads
[02/28/2008|02:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[02/28/2008|02:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[10/06/2008|07:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Applications
[03/24/2006|12:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ArcSoft
[01/19/2009|06:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Avg8
[12/03/2007|07:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CA
[09/23/2008|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> DVD Shrink
[12/04/2007|12:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[05/27/2005|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Hewlett-Packard
[05/27/2005|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[01/19/2009|10:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
[01/19/2009|12:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee
[03/03/2008|07:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[09/21/2006|08:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MSScanAppDataDir
[12/14/2005|03:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> muvee Technologies
[01/19/2009|06:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Norton
[01/05/2009|05:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NortonInstaller
[08/25/2005|10:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Pure Networks
[05/27/2005|11:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> QuickTime
[11/15/2006|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> RoboForm
[04/28/2006|12:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Roxio
[05/27/2005|11:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SBSI
[01/07/2009|12:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SiteAdvisor
[01/19/2009|06:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec
[10/06/2008|06:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Trend Micro
[01/21/2007|02:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Verizon
[04/14/2007|03:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Viewpoint
[02/08/2008|11:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[07/11/2008|03:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Yahoo!
[04/11/2007|09:00] C:\DOCUME~1\APPLIC~1\APPLIC~1\<DIR> Microsoft
[05/27/2005|11:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Apple Computer
[01/27/2005|05:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[05/27/2005|12:17] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> InterMute
[05/27/2005|12:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[05/27/2005|11:47] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Real
[05/27/2005|12:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> SampleView
[05/27/2005|12:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Symantec
[02/16/2008|11:09] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Adobe
[06/24/2008|03:38] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> AdobeUM
[08/26/2005|08:11] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> AOL
[07/11/2008|10:25] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Apple Computer
[03/24/2006|12:29] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> ArcSoft
[02/05/2008|05:10] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> bak
[02/09/2006|06:35] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> EBookSys
[01/13/2009|08:26] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Google
[02/23/2006|07:58] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Help
[08/26/2005|12:37] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Hewlett-Packard
[05/30/2006|06:59] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> ICAClient
[01/27/2005|05:44] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Identities
[05/27/2005|12:17] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> InterMute
[04/14/2006|06:34] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> InterVideo
[10/11/2005|12:20] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Leadertech
[01/23/2008|06:26] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Macromedia
[01/19/2009|10:55] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Malwarebytes
[05/22/2008|09:57] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Microsoft
[10/26/2008|03:15] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Move Networks
[08/31/2006|03:38] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> MSNInstaller
[12/14/2005|03:04] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> muvee Technologies
[11/26/2006|12:26] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> MySpace
[10/13/2007|02:02] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Real
[10/07/2006|08:54] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Roxio
[05/27/2005|12:12] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> SampleView
[05/23/2007|10:32] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Snapfish
[10/11/2005|12:20] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Sonic
[12/25/2008|08:46] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Sony Setup
[09/19/2005|10:08] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Sun
[12/19/2008|06:00] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Symantec
[10/17/2005|07:38] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Template
[01/10/2008|08:48] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> U3
[10/21/2006|08:20] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Verizon
[04/14/2007|03:21] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Viewpoint
[07/11/2008|03:47] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> Yahoo!
[08/25/2005|10:14] C:\DOCUME~1\HP_ADM~1\APPLIC~1\<DIR> You've Got Pictures Screensaver
[01/19/2009|06:01] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[01/18/2009|06:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> SACore
[02/28/2006|09:25] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Symantec
[01/19/2009|06:01] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[01/13/2009 01:55 PM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[01/20/2009 01:34 AM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/10/2004 10:00 AM][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing Folders in C:\Program Files
[02/03/2008|06:28] C:\Program Files\<DIR> Adobe
[11/27/2006|10:02] C:\Program Files\<DIR> America Online 9.0
[12/04/2007|12:54] C:\Program Files\<DIR> AOL
[09/15/2008|01:18] C:\Program Files\<DIR> Apple Software Update
[02/09/2006|08:02] C:\Program Files\<DIR> ArcSoft
[01/05/2006|08:58] C:\Program Files\<DIR> AviSynth 2.5
[05/27/2005|12:01] C:\Program Files\<DIR> BackWeb
[09/15/2008|01:15] C:\Program Files\<DIR> Bonjour
[12/03/2007|02:13] C:\Program Files\<DIR> CA
[03/21/2006|01:59] C:\Program Files\<DIR> Canon
[05/13/2007|06:54] C:\Program Files\<DIR> Challenger Tetris
[05/30/2006|06:54] C:\Program Files\<DIR> Citrix
[11/15/2008|05:08] C:\Program Files\<DIR> CleanUp!
[01/20/2009|01:31] C:\Program Files\<DIR> Common Files
[12/04/2007|04:59] C:\Program Files\<DIR> ComPlus Applications
[09/23/2008|09:29] C:\Program Files\<DIR> DVD Shrink
[11/12/2007|03:17] C:\Program Files\<DIR> Easy Internet signup
[05/27/2005|11:49] C:\Program Files\<DIR> EnglishOtto
[05/27/2005|11:49] C:\Program Files\<DIR> GemMaster
[07/07/2008|08:10] C:\Program Files\<DIR> Google
[10/12/2007|11:52] C:\Program Files\<DIR> Grisoft
[05/27/2005|12:28] C:\Program Files\<DIR> Hewlett-Packard
[05/27/2005|11:40] C:\Program Files\<DIR> HP
[05/27/2005|12:02] C:\Program Files\<DIR> HPQ
[02/26/2008|07:39] C:\Program Files\<DIR> InstallShield Installation Information
[05/27/2005|11:53] C:\Program Files\<DIR> IntelliMover Data Transfer Demo
[12/27/2008|10:51] C:\Program Files\<DIR> InterActual
[05/27/2005|12:00] C:\Program Files\<DIR> InterMute
[01/05/2009|08:28] C:\Program Files\<DIR> Internet Explorer
[05/27/2005|12:30] C:\Program Files\<DIR> InterVideo
[09/15/2008|01:17] C:\Program Files\<DIR> iPod
[09/15/2008|01:17] C:\Program Files\<DIR> iTunes
[07/11/2008|09:52] C:\Program Files\<DIR> Java
[08/25/2005|10:14] C:\Program Files\<DIR> Learn2.com
[09/05/2006|02:43] C:\Program Files\<DIR> LEGO Media
[01/19/2009|10:55] C:\Program Files\<DIR> Malwarebytes' Anti-Malware
[12/10/2006|11:00] C:\Program Files\<DIR> MARS
[09/25/2008|04:42] C:\Program Files\<DIR> Messenger
[05/27/2005|11:56] C:\Program Files\<DIR> Microsoft ActiveSync
[01/27/2005|05:46] C:\Program Files\<DIR> microsoft frontpage
[12/06/2006|07:38] C:\Program Files\<DIR> Microsoft Money 2005
[10/06/2008|07:12] C:\Program Files\<DIR> Microsoft Office
[05/27/2005|11:54] C:\Program Files\<DIR> Microsoft Plus! Dancer LE
[05/27/2005|11:54] C:\Program Files\<DIR> Microsoft Plus! Digital Media Edition
[05/27/2005|11:54] C:\Program Files\<DIR> Microsoft Plus! Photo Story 2 LE
[05/27/2005|11:55] C:\Program Files\<DIR> Microsoft Visual Studio
[11/07/2008|01:34] C:\Program Files\<DIR> Microsoft Works
[05/27/2005|11:55] C:\Program Files\<DIR> Microsoft.NET
[04/04/2006|05:17] C:\Program Files\<DIR> Motorola
[09/25/2008|04:36] C:\Program Files\<DIR> Movie Maker
[01/27/2005|05:46] C:\Program Files\<DIR> MSN
[09/21/2005|08:27] C:\Program Files\<DIR> MSN Apps
[05/27/2005|11:46] C:\Program Files\<DIR> MSN Encarta Standard
[01/27/2005|05:47] C:\Program Files\<DIR> MSN Gaming Zone
[01/07/2009|03:46] C:\Program Files\<DIR> MSN Messenger
[11/15/2006|03:27] C:\Program Files\<DIR> MSXML 4.0
[02/26/2008|07:40] C:\Program Files\<DIR> muvee Technologies
[01/07/2009|12:26] C:\Program Files\<DIR> MySpace
[09/25/2008|04:34] C:\Program Files\<DIR> NetMeeting
[01/05/2009|05:23] C:\Program Files\<DIR> Norton 360
[01/19/2009|06:11] C:\Program Files\<DIR> Norton AntiVirus
[01/19/2009|06:11] C:\Program Files\<DIR> NortonInstaller
[05/27/2005|12:10] C:\Program Files\<DIR> Online Services
[09/25/2008|04:33] C:\Program Files\<DIR> Outlook Express
[05/27/2005|12:06] C:\Program Files\<DIR> PC-Doctor for DOS
[05/27/2005|12:06] C:\Program Files\<DIR> PC-Doctor for Windows
[12/03/2007|07:41] C:\Program Files\<DIR> PCPitstop
[10/21/2006|08:22] C:\Program Files\<DIR> PlayLinc
[08/25/2005|10:14] C:\Program Files\<DIR> Pure Networks
[09/15/2008|01:15] C:\Program Files\<DIR> QuickTime
[05/27/2005|11:46] C:\Program Files\<DIR> Real
[04/28/2006|12:18] C:\Program Files\<DIR> Roxio
[07/11/2008|09:58] C:\Program Files\<DIR> Safari
[11/15/2006|10:52] C:\Program Files\<DIR> Siber Systems
[05/27/2005|11:51] C:\Program Files\<DIR> Sonic
[12/25/2008|08:46] C:\Program Files\<DIR> Sony Setup
[01/19/2009|06:12] C:\Program Files\<DIR> Symantec
[01/20/2009|12:09] C:\Program Files\<DIR> Trend Micro
[01/27/2005|01:38] C:\Program Files\<DIR> Uninstall Information
[05/27/2005|12:01] C:\Program Files\<DIR> Updates from HP
[10/21/2006|08:22] C:\Program Files\<DIR> Verizon
[10/21/2006|08:28] C:\Program Files\<DIR> Verizon Online
[08/25/2005|10:14] C:\Program Files\<DIR> Viewpoint
[03/08/2007|09:08] C:\Program Files\<DIR> Virtools
[05/27/2005|11:49] C:\Program Files\<DIR> WildTangent
[10/13/2007|01:17] C:\Program Files\<DIR> Windows Media Player
[09/25/2008|04:33] C:\Program Files\<DIR> Windows NT
[01/27/2005|05:47] C:\Program Files\<DIR> Windows Plus
[01/19/2009|06:11] C:\Program Files\<DIR> Windows Sidebar
[01/27/2005|01:38] C:\Program Files\<DIR> WindowsUpdate
[01/27/2005|05:48] C:\Program Files\<DIR> xerox
[07/13/2007|02:20] C:\Program Files\<DIR> Xvid
[07/18/2008|11:50] C:\Program Files\<DIR> Yahoo!
--------------------\\ Listing Folders in C:\Program Files\Common Files
[06/24/2008|03:39] C:\Program Files\Common Files\<DIR> Adobe
[07/06/2006|05:01] C:\Program Files\Common Files\<DIR> AOL
[08/25/2005|10:14] C:\Program Files\Common Files\<DIR> aolshare
[09/15/2008|01:14] C:\Program Files\Common Files\<DIR> Apple
[05/27/2005|11:55] C:\Program Files\Common Files\<DIR> DESIGNER
[05/27/2005|11:38] C:\Program Files\Common Files\<DIR> Hewlett-Packard
[05/27/2005|11:34] C:\Program Files\Common Files\<DIR> HP
[05/27/2005|11:59] C:\Program Files\Common Files\<DIR> InstallShield
[05/27/2005|12:31] C:\Program Files\Common Files\<DIR> InterVideo
[05/27/2005|11:15] C:\Program Files\Common Files\<DIR> Java
[05/27/2005|11:56] C:\Program Files\Common Files\<DIR> L&H
[08/25/2005|10:05] C:\Program Files\Common Files\<DIR> LightScribe
[10/06/2008|07:12] C:\Program Files\Common Files\<DIR> Microsoft Shared
[10/21/2006|08:28] C:\Program Files\Common Files\<DIR> MotiveBrowser
[01/27/2005|05:46] C:\Program Files\Common Files\<DIR> MSSoap
[08/25/2005|10:14] C:\Program Files\Common Files\<DIR> Nullsoft
[01/27/2005|05:46] C:\Program Files\Common Files\<DIR> ODBC
[05/27/2005|11:47] C:\Program Files\Common Files\<DIR> Real
[04/28/2006|12:20] C:\Program Files\Common Files\<DIR> Roxio Shared
[07/07/2008|09:12] C:\Program Files\Common Files\<DIR> Scanner
[10/13/2007|01:17] C:\Program Files\Common Files\<DIR> Services
[05/27/2005|11:46] C:\Program Files\Common Files\<DIR> Sonic Shared
[01/27/2005|05:46] C:\Program Files\Common Files\<DIR> SpeechEngines
[10/21/2006|07:49] C:\Program Files\Common Files\<DIR> SupportSoft
[05/27/2005|11:46] C:\Program Files\Common Files\<DIR> SureThing Shared
[11/10/2006|03:47] C:\Program Files\Common Files\<DIR> SWF Studio
[01/19/2009|06:13] C:\Program Files\Common Files\<DIR> Symantec Shared
[09/25/2008|04:33] C:\Program Files\Common Files\<DIR> System
[05/27/2005|11:51] C:\Program Files\Common Files\<DIR> TiVo Shared
[10/21/2006|08:28] C:\Program Files\Common Files\<DIR> Verizon Online
[05/27/2005|11:47] C:\Program Files\Common Files\<DIR> xing shared
--------------------\\ Process
( 42 Processes )
... OK !
--------------------\\ Searching with S_Lop
No Lop folder found !
--------------------\\ Searching for Lop Files - Folders
No Lop folder found !
--------------------\\ Searching within the Registry
..... OK !
--------------------\\ Checking the Hosts file
Hosts file CLEAN
--------------------\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net Rootkit scan 2009-01-20 01:47:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Searching for other infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\HP_ADM~1\My Documents\My Music\The Notorious B.I.G\Life After Death Disc 2\05 Ten Crack Commandments.mp3
C:\DOCUME~1\HP_ADM~1\My Documents\My Music\The Notorious B.I.G\Life After Death Disc 2\05 Ten Crack Commandments.wma
[F:1][D:1]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
[F:45][D:0]-> C:\DOCUME~1\HP_ADM~1\Cookies
[F:199][D:4]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Tue 01/20/2009| 1:49 - Option : [1]
--------------------\\ Scan completed at 1:49:12