Here is my combofix log. Thanks again.
ComboFix 09-07-09.06 - hpadmin 07/09/2009 17:48.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.528 [GMT -8:00]
Running from: c:\documents and settings\Administrator\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Sygate Security Agent *enabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\-1532635710
C:\PLAYTRAC.EXE
c:\windows\Install.txt
c:\windows\Installer\218643.msp
c:\windows\Installer\218659.msp
c:\windows\Installer\4c9e7.msp
c:\windows\Installer\7d301.msp
c:\windows\Installer\85589.msp
c:\windows\Installer\855db.msp
c:\windows\Installer\a8f88.msi
c:\windows\Installer\ab83be.msp
c:\windows\Installer\ab83e4.msp
c:\windows\Installer\afb85.msi
c:\windows\Installer\afb8b.msi
c:\windows\Installer\c06c.msi
c:\windows\Installer\cabfa.msp
c:\windows\jsr468ijdfghfjsw3rw3i6tjag81.exe
c:\windows\system32\drivers\mrxdavv.sys
c:\windows\system32\drivers\MSIVXkbwkvjrursktkoxuxajswvqehjdnwldf.sys
c:\windows\system32\drivers\SKYNETbmgucyok.sys
c:\windows\system32\drivers\UACgdxeiubyvpktitk.sys
c:\windows\system32\kwave.sys
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXnipdooxrflkkqcnnygetrpqbkfljxupu.dll
c:\windows\system32\MSIVXwjqepylvaieayffhmtnvnkqqkocfrtrk.dll
c:\windows\system32\SKYNETferpcfir.dll
c:\windows\system32\SKYNETmbqcxhxs.dll
c:\windows\system32\SKYNETxylrsdun.dat
c:\windows\system32\UACcsobduycokyrddd.dll
c:\windows\system32\UACepdqlnxfbckmnbe.dll
c:\windows\system32\UACfvaqepoyojjcvjl.dat
c:\windows\system32\UACimqkgxdiggyujnv.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkxjtvrboedtoitx.dll
c:\windows\system32\UACodtdwtoklydeaqo.dll
c:\windows\system32\UACqavyojkyudsnrjv.dll
c:\windows\system32\UACtioqpcoiipivvnc.log
c:\windows\system32\uactmp.db
c:\windows\system32\UACwhnrdskpiuiajuw.log
c:\windows\system32\UACxlxmmtmpjcacpbd.db
c:\windows\system32\UACxrcsmrnafyhbaba.log
c:\windows\system32\zip32.dll
c:\windows\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETtpygwnhl
-------\Service_UACd.sys
-------\Legacy_MSNCACHE
-------\Legacy_NPF
-------\Legacy_PASSWORD
-------\Legacy_SOPIDKC
-------\Service_MSIVXserv.sys
-------\Legacy_jsr468ijdfghfjsw3rw3i6tjag80
-------\Service_jsr468ijdfghfjsw3rw3i6tjag80
((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 )))))))))))))))))))))))))))))))
.
2009-07-10 01:03 . 2009-07-10 01:03 -------- d-----w- c:\program files\microsoft frontpage
2009-06-24 18:32 . 2009-06-24 18:32 -------- d-----w- c:\program files\Trend Micro
2009-06-20 05:47 . 2009-06-20 05:47 -------- d-----w- c:\program files\CCleaner
2009-06-19 22:03 . 2009-06-19 22:03 3584 ----a-w- c:\windows\system32\00setup.exe
2009-06-19 21:09 . 2009-06-19 21:10 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-06-19 21:04 . 2009-06-19 21:04 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
2009-06-19 06:20 . 2009-03-30 18:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-19 06:20 . 2009-03-25 00:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-19 06:20 . 2009-02-13 20:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-19 06:20 . 2009-02-13 20:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-19 06:19 . 2009-06-19 06:19 -------- d-----w- c:\program files\Avira
2009-06-19 06:19 . 2009-06-19 06:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-12 18:32 . 2009-06-12 18:32 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-12 17:42 . 2009-06-12 18:31 -------- d-----w- c:\documents and settings\All Users\Application Data\11088264
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-10 02:13 . 2004-11-05 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\HDThermal
2009-07-10 02:08 . 2008-11-24 21:02 251 ----a-w- c:\windows\system32\tablet.dat
2009-07-08 01:53 . 2008-12-27 19:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-19 23:54 . 2009-03-12 23:49 7 ----a-w- c:\windows\system32\nar.bin
2009-06-19 03:34 . 2009-06-19 03:34 104 ----a-w- c:\program files\Shortcut to Recycle Bin.lnk
2009-06-19 03:33 . 2004-11-15 19:56 -------- d-----w- c:\program files\AIM
2009-06-19 03:33 . 2004-11-12 18:36 -------- d-----w- c:\program files\eRoom 6
2009-06-17 01:08 . 2009-01-11 17:39 -------- d-----w- c:\documents and settings\All Users\Application Data\TrackMania
2009-06-11 07:28 . 2009-02-21 05:30 -------- d-----w- c:\program files\Bridge Building Game
2009-05-25 17:27 . 2004-07-27 09:56 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-17 19:18 . 2009-05-17 19:18 7926 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E087918A-C795-4C5E-B81C-00F55CD7E13D}\_7a5a767d.exe
2009-05-17 19:18 . 2009-05-17 19:18 7926 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E087918A-C795-4C5E-B81C-00F55CD7E13D}\_701f5d03.exe
2009-05-17 19:18 . 2009-05-17 19:18 7926 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E087918A-C795-4C5E-B81C-00F55CD7E13D}\_45091238.exe
2009-05-17 19:18 . 2009-05-17 19:18 7926 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E087918A-C795-4C5E-B81C-00F55CD7E13D}\_3b251e1f.exe
2009-05-17 19:18 . 2009-05-17 19:18 2238 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E087918A-C795-4C5E-B81C-00F55CD7E13D}\_428b26a6.exe
2009-05-17 19:18 . 2009-05-17 19:18 7926 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E087918A-C795-4C5E-B81C-00F55CD7E13D}\_74d4dc8.exe
2009-05-17 19:18 . 2009-05-17 19:18 2238 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E087918A-C795-4C5E-B81C-00F55CD7E13D}\_644366bb.exe
2009-05-17 19:18 . 2009-05-17 19:18 19686 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{E087918A-C795-4C5E-B81C-00F55CD7E13D}\_39b32d12.exe
2009-05-17 19:18 . 2009-05-17 19:18 -------- d-----w- c:\program files\Cutout Pro
2009-04-30 05:37 . 2009-04-30 01:08 176286 ----a-w- c:\windows\hpwins19.dat
2009-04-22 22:53 . 2009-04-23 02:52 51200 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\k4eqv20c.default\extensions\{57eb5b9c-8fce-4df6-99af-d8940861a355}\components\FFExternalAlert.dll
2009-04-22 22:53 . 2009-04-23 02:52 114688 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\k4eqv20c.default\extensions\{57eb5b9c-8fce-4df6-99af-d8940861a355}\components\npmozax.dll
2009-04-15 23:49 . 2008-05-22 05:45 113688 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-29 02:28 . 2009-04-29 02:28 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-03 401491]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-04 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"IDA"="c:\program files\Hewlett-Packard\PC COE\IDA.EXE" [2002-11-07 176128]
"QuickPassword"="c:\program files\ActivCard\ActivCard Gold\agquickp.exe" [2004-05-28 208896]
"eabconfg.cpl"="c:\program files\Compaq\EAB\EABSERVR.EXE" [2002-11-12 229376]
"hkss"="c:\program files\Compaq\Hotkey Software\hkss.exe" [2002-09-19 192512]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-05-22 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-05-22 610304]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-12-04 176128]
"HPHmon04"="c:\windows\System32\hphmon04.exe" [2002-11-22 348160]
"HPHUPD04"="c:\program files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" [2002-11-22 49152]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2004-02-02 495616]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2002-11-23 631362]
"SmcService"="c:\progra~1\Sygate\SSA\smc.exe" [2005-08-06 2582240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\qsb.exe" [2009-03-15 68592]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-04-29 30192]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-13 136600]
c:\documents and settings\dxni\Start Menu\Programs\Startup\
Monitor My eRooms.lnk - c:\program files\eRoom 6\ERClient.exe [2004-11-12 65586]
c:\documents and settings\wendy_castilone\Start Menu\Programs\Startup\
Monitor My eRooms (V7).lnk - c:\program files\eRoom 7\ERClient7.exe [2006-4-6 153352]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader\reader_sl.exe [2005-9-23 29696]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-6-2 565309]
Connected TaskBar Icon.LNK - c:\program files\Connected\CBSysTray.exe [2005-6-2 118851]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2004-9-8 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableNT4Policy"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{0cab0400-7395-11d0-a5e5-0020afe2fdd9}"= "qvphook.dll" [2002-04-10 45056]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=c:\windows\pss\TabUserW.exe.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\00setup.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 vburner;vburner;c:\windows\system32\drivers\vburner.sys [4/7/2009 11:14 AM 15872]
R1 DhaHelper;DhaHelper;c:\windows\system32\drivers\dhahelper.sys [1/22/2009 6:06 PM 7168]
R2 acautoreg;ActivCard Gold Autoregister;c:\program files\Common Files\ActivCard\acautoreg.exe [10/29/2003 3:27 AM 53248]
R2 Accoca;ActivCard Gold service;c:\program files\Common Files\ActivCard\accoca.exe [5/12/2004 2:51 PM 143360]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/18/2009 10:20 PM 108289]
R2 HPSygControl;HP Sygate Icon Control;c:\progra~1\sygate\ssa\syg_hp.exe [5/20/2005 6:38 AM 40960]
R2 radexecd;Radia Notify Daemon;c:\program files\Hewlett-Packard\PC COE 3\OV CMS\radexecd.exe [5/4/2005 3:35 PM 217268]
R2 radsched;Radia Scheduler Daemon;c:\program files\Hewlett-Packard\PC COE 3\OV CMS\radsched.exe [8/25/2004 12:05 PM 245940]
R2 Radstgms;Radia MSI Redirector;c:\program files\Hewlett-Packard\PC COE 3\OV CMS\Radstgms.exe [10/22/2004 3:53 PM 327860]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [1/15/2009 6:24 PM 2368]
R3 akbus;ActivCard Virtual Reader Enumerator;c:\windows\system32\drivers\akbus.sys [5/12/2004 5:10 PM 13567]
R3 akpcsc;ActivCard Virtual PC/SC Device Driver;c:\windows\system32\drivers\akpcsc.sys [11/9/2004 10:47 AM 9537]
R3 RadiaMsi;RadiaMsi;c:\windows\system32\drivers\radiamsi.sys [9/10/2004 2:45 PM 21504]
R3 SCM488C;SCM Microsystems SCR120 PCMCIA Smart Card Reader;c:\windows\system32\drivers\pscr.sys [11/11/2004 4:06 PM 16128]
R3 wlcom51b;Compaq USB Driver;c:\windows\system32\drivers\wlcom51b.sys [8/25/2004 11:27 AM 183296]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [11/12/2004 8:27 AM 114016]
S3 EL556ND5;3Com 10/100 MiniPCI Ethernet Adapter Driver;c:\windows\system32\drivers\EL556ND5.sys [7/6/2004 6:22 AM 55999]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [4/28/2009 6:28 PM 30192]
S3 GrooveAuditService;Groove Audit Service;c:\program files\Groove Networks\Groove\Bin\GrooveAuditService.exe [12/22/2004 11:01 AM 53248]
S3 GrooveInstallerService;Groove Installer Service;c:\program files\Groove Networks\Groove\Bin\GrooveInstallerService.exe [12/22/2004 11:01 AM 115200]
S3 GrooveRunOnceInstaller;GrooveRunOnceInstaller;c:\program files\Groove Networks\Groove\Bin\GrooveRunOnceInstaller.exe [12/22/2004 11:01 AM 11776]
S3 libusb0;LibUsb-Win32 - Kernel Driver 03/20/2007, 0.1.12.1;c:\windows\system32\drivers\libusb0.sys [1/26/2009 3:58 PM 24576]
S3 LinksysFVNETusbl(AR)®;Linksys FVNETusbl(AR)® Service for Instant Wireless USB Network Adapter ver.2.6;c:\windows\system32\drivers\vnetusbl.sys [3/9/2004 7:48 PM 108032]
S3 LSWPCv4;Wireless-B Notebook Adapter Driver;c:\windows\system32\drivers\rtl8180.sys [10/1/2003 10:54 AM 184832]
S3 maestro;ESS Maestro 3 Audio Driver (WDM);c:\windows\system32\drivers\es198x.sys [7/6/2004 6:22 AM 174464]
S3 magaService;Lan Discover Agent;c:\program files\sygate\ssa\Maga\Maga.exe [8/5/2005 5:18 PM 323670]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [12/27/2008 11:08 AM 38496]
S3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [4/7/2009 11:32 AM 23096]
S3 SndTVideo;SndTVideo;c:\windows\system32\drivers\SndTVideo.sys [4/7/2009 11:32 AM 3768]
S3 WDHAALBA;WDHAALBAMiniPCI Winmodem;c:\windows\system32\drivers\WDHAALBA.sys [7/6/2004 6:22 AM 701386]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
2009-06-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2009-07-10 c:\windows\Tasks\IDA{07A2D605-F561-11D1-BEE5-AC785AC8CD4E}000.job
- c:\progra~1\HEWLET~1\PCCOE~1\Aimsi.dll [2005-10-06 20:09]
2009-07-10 c:\windows\Tasks\IDA{5B940D5F-0A3F-11D2-95B5-080009DC8202}000.job
- c:\program files\Hewlett-Packard\PC COE\coecinvt.exe [2001-03-29 16:08]
2009-07-10 c:\windows\Tasks\IDA{884F3959-E5F7-11D1-9B15-080009F878E4}000.job
- c:\progra~1\HEWLET~1\PCCOE~1\reltrksi.dll [2005-01-27 16:32]
2009-07-10 c:\windows\Tasks\IDA{E1B2A4DD-AE06-4B97-9B55-8E8F1348E7FB}000.job
- c:\progra~1\HEWLET~1\PCCOE~1\critupsi.dll [2004-12-15 16:36]
.
- - - - ORPHANS REMOVED - - - -
Notify-NavLogon - (no file)
SafeBoot-eeekp.sys
SafeBoot-TiglUsb.sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
Trusted Zone: compaq.com\ie.config.asia
Trusted Zone: compaq.com\ie.config.eur
Trusted Zone: compaq.com\ie.config.im.hou
Trusted Zone: compaq.com\ie.config.jp
Trusted Zone: dec.com\ie.config.ecom
Trusted Zone: ketsujin.com\fighterace
Trusted Zone: ketsujin.com\primary
Trusted Zone: ketsujin.com\update
Trusted Zone: ketsujin.com\www
Trusted Zone: stormofaces.com\www
Trusted Zone: tandem.com\ie.config
Trusted Zone: compaq.com\ie.config.asia
Trusted Zone: compaq.com\ie.config.eur
Trusted Zone: compaq.com\ie.config.im.hou
Trusted Zone: compaq.com\ie.config.jp
Trusted Zone: dec.com\ie.config.ecom
Trusted Zone: tandem.com\ie.config
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: HPVC component - hxxp://vrm10.win2000.hpe-learning.com/hpvcpw/lib/hp/dc/lib/component4100.cab
DPF: HPVC resources - hxxp://vrm10.win2000.hpe-learning.com/hpvcpw/lib/hp/dc/lib/resources4100.cab
DPF: HPVC signed - hxxp://vrm10.win2000.hpe-learning.com/hpvcpw/lib/hp/dc/lib/signed4100.cab
DPF: HPVC support - hxxp://vrm10.win2000.hpe-learning.com/hpvcpw/lib/hp/dc/lib/support4100.cab
DPF: HPVC vminfo - hxxp://vrm04.win2000.hpe-learning.com/Room1//requirements/vminfo.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {08F04139-8DFC-11D2-80E9-006008B066EE} - hxxps://onsite.verisign.com/services/CollabNetIncHPCDP3rdPartyCertificateAuthority/vscnfchk.cab
DPF: {DF7B8990-6141-4677-B0B2-977169DB4A7E} - hxxp://vrm04.win2000.hpe-learning.com/Room1/misc/HPPptDrop.CAB
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\k4eqv20c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2236827&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2236827&SearchSource=2&q=
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\k4eqv20c.default\extensions\{57eb5b9c-8fce-4df6-99af-d8940861a355}\components\FFExternalAlert.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Adobe\Reader\browser\nppdf32.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-09 18:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\vsdatant]
"ImagePath"=""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1002098830-1651734163-3894283646-500\Software\Sony Creative Software\M*e*d*i*a* *M*a*n*a*g*e*r* *f*o*r* *P*S*P*"!\3.0]
"FRT"="QDOcHnOB/VP/XCEs9xRUNw2UlVDCOrAhppsJkDpIHwv/enaAhHQB9A=="
"PLCK"="ejTRCcnCI6Mll9CwnO6UpIW/mU3JUTri"
"Percents"="0 0.1116 0.3658 0.3848 0.4822 0.6829 0.69 "
"Increment"=".009174"
"PHSH"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2052)
c:\windows\System32\tabhook.dll
c:\windows\system32\msi.dll
c:\program files\Logitech\iTouch\iTchHk.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\scardsvr.exe
c:\program files\Connected\AgentSrv.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\mnmsrvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\Tablet.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\HPQ\SHARED\hpqwmi.exe
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
.
**************************************************************************
.
Completion time: 2009-07-10 18:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-10 02:21
Pre-Run: 8,468,320,256 bytes free
Post-Run: 9,639,493,120 bytes free
318