SO SLOWWWWW!! HELP!

Hi and Happy Holidays,
My PC and every application associated with it seems to be crawling. This seems to have started after my PC crashed and I had to do a restore. However, I'm really not sure if it is a restore problem or a virus/hijack/whoknowswhat problem.

I've run AdAware, Spybot and SpyBlaster. I don't seem to have anything major going on. Then again, what do I know. I'm attaching a Hijack This report (see below) , and would greatly appreciated it if you could take a look and see if anything jumps out at you as a problem.

If you see nothing, maybe I just need more memory? Currently 512. Again, thanks for your time and efforts on my behalf. Awaiting your reply. Thanks!!

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:20:22 PM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\MDM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\bfgclient\bfggameservices.exe
C:\Program Files\Verizon\McciBrowser.exe
C:\Documents and Settings\Owner\My Documents\Mom\popups\hijack this software\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [USB] C:\WINDOWS\system32\usb.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 10815 bytes

Comments

  • edited January 2009
    Hello. :)

    Please run HijackThis and place a tick by the following entry:
    O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')

    Then close all other windows except HijackThis and press "Fix Checked". Next restart the computer.



    Now, please go HERE to run Panda ActiveScan 2.0
    • Click the big green Scan now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • Once the scan is completed, please hit the notepad icon next to the text Export to:
    • Save it to a convenient location such as your Desktop
    • Post the contents of the ActiveScan.txt and a new HijackThis log in your next reply
  • edited January 2009
    Per your request Chiaz, I've done what you asked. Listed below are the results of the Activescan and new HijackThis logs. I see that although I did what you asked as it relates to: O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user'), the new HijackThis log is still showing it?? Thanks for your help!

    ;***********************************************************************************************************************************************************************************
    ANALYSIS: 2009-01-03 20:18:34
    PROTECTIONS: 2
    MALWARE: 21
    SUSPECTS: 7
    ;***********************************************************************************************************************************************************************************
    PROTECTIONS
    Description Version Active Updated
    ;===================================================================================================================================================================================
    McAfee Internet Security Suite 2007 8.1 No Yes
    McAfee VirusScan Plus 12.1 No No
    ;===================================================================================================================================================================================
    MALWARE
    Id Description Type Active Severity Disinfectable Disinfected Location
    ;===================================================================================================================================================================================
    00018331 adware/gator Adware No 0 Yes No c:\gatorpatch.log
    00020302 adware/ncase Adware No 0 Yes No c:\temp\salm_kyf.dat
    00020302 adware/ncase Adware No 0 Yes No c:\temp\salmau.dat
    00020302 adware/ncase Adware No 0 Yes No c:\temp\fleok
    00027660 adware/savenow Adware No 0 Yes No c:\windows\system32\wsxsvc
    00029767 adware/delfinmedia Adware No 1 Yes No c:\windows\system32\vmss
    00029767 adware/delfinmedia Adware No 1 Yes No c:\keys.ini
    00041904 adware/sidesearch Adware No 0 Yes No c:\program files\lycos
    00064331 adware/msview Adware No 0 Yes No c:\windows\inf\msview.inf
    00140418 Adware/ISearch Adware No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc19\build2.exe
    00144935 Adware/IPInsight Adware No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc28.tmp\farmmext.inf
    00162730 Cookie/Belnk TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@dist.belnk[2].txt
    00167690 Cookie/Rightmedia TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@rightmedia[2].txt
    00167776 Cookie/Kount TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@kount[1].txt
    00170087 Cookie/Hbmediapro TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@adopt.hbmediapro[1].txt
    00171718 Cookie/Enhance TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@c.enhance[1].txt
    00176502 Cookie/Media-motor TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@mmm.media-motor[1].txt
    00188480 Cookie/Paypopup TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@paypopup[1].txt
    00521370 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP150\A0022886.dll
    00521370 Spyware/Iehelp Spyware No 1 No No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinGamesHookIE.dll]
    02893773 Spyware/Iehelp Spyware No 1 Yes No C:\Program Files\iWin Games\AdminWorker.exe
    02893774 Spyware/Iehelp Spyware No 1 Yes No C:\Program Files\iWin Games\WebInstaller.exe
    02893775 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP150\A0022885.exe
    02893775 Spyware/Iehelp Spyware No 1 No No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinArcadeLauncher.exe]
    04262614 Bck/Ciadoor.FQ Virus/Trojan No 1 No No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP142\A0022130.exe[α
    Ç.]
    04262614 Bck/Ciadoor.FQ Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP142\A0022121.exe
    04396338 W32/Gaobot.OXI.worm Virus/Worm No 1 Yes No C:\Program Files\Dream Day Wedding - Married in Manhattan\vcwcmrq.exe
    ;===================================================================================================================================================================================
    SUSPECTS
    Sent Location
    ;===================================================================================================================================================================================
    No C:\hp\bin\ProcessLogger.exe
    No C:\Program Files\Discovery - A Seek and Find Adventure\Discovery.exe
    No C:\Program Files\Discovery - A Seek and Find Adventure\npqxpgj.exe
    No C:\Program Files\Hidden Expedition - Amazon\vdztdsj.exe
    No C:\Program Files\Hidden Secrets - The Nightmare\wnhbdgs.exe
    No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinGames.exe]
    No C:\Program Files\Mystery Case Files - Return to Ravenhearst\dppxxpn.exe
    ;===================================================================================================================================================================================
    VULNERABILITIES
    Id Severity Description
    ;===================================================================================================================================================================================
    ;===================================================================================================================================================================================


    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 8:20:50 PM, on 1/3/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\lg_fwupdate\fwupdate.exe
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\Program Files\Verizon\McciTrayApp.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Owner\My Documents\Mom\popups\hijack this software\HiJackThis_v2.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [USB] C:\WINDOWS\system32\usb.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
    O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

    --
    End of file - 10849 bytes
  • edited January 2009
    I just noticed that the version of HijackThis you have is outdated. Please delete the current copy that you have, and download the new installer from here:
    http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

    Post a new HijackThis log.
  • edited January 2009
    chiaz wrote:
    I just noticed that the version of HijackThis you have is outdated. Please delete the current copy that you have, and download the new installer from here:
    http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

    Post a new HijackThis log.

    Hi......Deleted old HijackThis and installed new per your link. New log follows:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:25:26 PM, on 1/4/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\lg_fwupdate\fwupdate.exe
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\Program Files\Verizon\McciTrayApp.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [USB] C:\WINDOWS\system32\usb.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
    O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

    --
    End of file - 10603 bytes
  • edited January 2009
    All right, please first go to Control Panel > Add/Remove Programs and uninstall the following if found:
    gator
    ncase
    savenow
    delfinmedia
    sidesearch
    msview
    ISearch
    IPInsight
    iWin Games
    iWin.com


    Do not worry if some of the above are not listed, just remove whatever you can find.


    After the uninstallation, reboot your computer. We now need to get into the Safe Mode. As the computer is booting up, press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode" and press your Enter key. Do note that in Safe Mode internet connection is not available, so it is advisable to copy and paste my entire post to a Notepad file or to print it out.
    For more help on booting into Safe Mode, check out:
    http://www.computerhope.com/issues/chsafe.htm


    Once you're in Safe Mode, please run HijackThis again and place a tick by the following entry:
    O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')

    Press the "Fix Checked" button, then close HijackThis and restart the computer again, but this time normally.


    Finally, I need you to download ComboFix.exe. Please download from one of these webpages:

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    http://www.forospyware.com/sUBs/ComboFix.exe
    http://subs.geekstogo.com/ComboFix.exe


    * IMPORTANT !!! Save ComboFix.exe to your Desktop


    Disable your AntiVirus and AntiSpyware applications, usually via a right-click on the System Tray icon. They may otherwise interfere with our tools. You may need to re-enable them after we are done here.

    Double-click on ComboFix.exe & follow the prompts.

    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.Recovery Console can be installed from your disc if you have Vista if you wish.

    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


    RcAuto1.gif


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


    whatnext.png


    Click on Yes to continue scanning for malware.


    When finished, it shall produce a log for you. Please include the ComboFix and the HijackThis logs in your new reply.
  • edited January 2009
    Hi!

    I did everything you asked and the outcome and logs you requested follow:

    1. Found none of the files you listed in the Ctrl Panel.
    2. In safe mode, checked the "04 -.Default user startup......" file but I see its still there in the report. Hijackthis unable to fix?
    3. PC still slowwwwwwww.

    Here are the logs:

    ComboFix 09-01-05.01 - Owner 2009-01-05 10:38:32.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.230 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    AV: McAfee VirusScan *On-access scanning disabled* (Updated)
    FW: McAfee Personal Firewall *enabled*
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\inf\MSView.inf
    c:\windows\system\oeminfo.ini
    c:\windows\system32\mdm.exe
    c:\windows\system32\packet.dll
    c:\windows\system32\usb.exe
    c:\windows\system32\vmss
    c:\windows\system32\wpcap.dll

    .
    ((((((((((((((((((((((((( Files Created from 2008-12-05 to 2009-01-05 )))))))))))))))))))))))))))))))
    .

    2009-01-04 13:22 . 2009-01-04 13:22 <DIR> d
    c:\program files\Trend Micro
    2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d
    c:\program files\Panda Security
    2009-01-03 17:50 . 2008-06-19 17:24 28,544 --a
    c:\windows\SYSTEM32\drivers\pavboot.sys
    2009-01-03 17:19 . 2009-01-03 17:19 <DIR> d
    c:\program files\Heartwild Solitaire
    2009-01-03 17:12 . 2009-01-03 17:13 <DIR> d
    c:\program files\Haunted Hotel II - Believe the Lies
    2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
    c:\documents and settings\Owner\Application Data\blg
    2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
    c:\documents and settings\All Users\Application Data\blg
    2009-01-01 14:28 . 2009-01-01 14:28 <DIR> d
    c:\program files\Lost Realms - Legacy of the Sun Princess
    2008-12-29 20:26 . 2008-12-29 20:26 <DIR> d
    c:\documents and settings\Owner\Freeze Tag - Dream Machine
    2008-12-29 16:42 . 2008-12-29 16:44 <DIR> d
    c:\program files\Mystery in London
    2008-12-27 19:52 . 2008-12-27 19:52 <DIR> d
    c:\documents and settings\Owner\Application Data\Cat's Eye Games
    2008-12-27 19:44 . 2008-12-27 19:44 <DIR> d
    c:\documents and settings\All Users\Application Data\Arkadium
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\Suspects and Clues Prefs
    2008-12-27 19:26 . 2008-12-27 19:27 <DIR> d
    c:\documents and settings\Owner\Application Data\Suspects and Clues Players
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\Spinapse
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\IOMediaSupport6SZZ001s
    2008-12-27 15:27 . 2008-12-27 15:28 <DIR> d
    c:\program files\Suspects and Clues
    2008-12-27 09:15 . 2008-12-27 09:15 <DIR> d
    c:\documents and settings\All Users\Application Data\SiteAdvisor
    2008-12-27 09:15 . 2009-01-05 10:27 6,651 --a
    c:\windows\SYSTEM32\Config.MPF
    2008-12-27 09:10 . 2007-11-22 06:44 201,320 --a
    c:\windows\SYSTEM32\drivers\mfehidk.sys
    2008-12-27 09:10 . 2007-07-13 06:20 113,952 --a
    c:\windows\SYSTEM32\drivers\Mpfp.sys
    2008-12-27 09:10 . 2007-11-22 06:44 79,304 --a
    c:\windows\SYSTEM32\drivers\mfeavfk.sys
    2008-12-27 09:10 . 2007-12-02 12:51 40,488 --a
    c:\windows\SYSTEM32\drivers\mfesmfk.sys
    2008-12-27 09:10 . 2007-11-22 06:44 35,240 --a
    c:\windows\SYSTEM32\drivers\mfebopk.sys
    2008-12-27 09:10 . 2007-11-22 06:44 33,832 --a
    c:\windows\SYSTEM32\drivers\mferkdk.sys
    2008-12-27 09:09 . 2008-12-27 09:09 <DIR> d
    c:\program files\McAfee.com
    2008-12-27 09:08 . 2008-12-27 09:14 <DIR> d
    c:\program files\McAfee
    2008-12-27 09:08 . 2008-12-27 09:10 <DIR> d
    c:\program files\Common Files\McAfee
    2008-12-26 20:19 . 2008-12-27 09:15 <DIR> d
    c:\documents and settings\All Users\Application Data\McAfee
    2008-12-24 16:01 . 2009-01-02 14:30 <DIR> d
    c:\program files\Mystery Case Files - Return to Ravenhearst
    2008-12-20 20:18 . 2006-10-22 12:22 208,896 --a
    c:\windows\SYSTEM32\nvudisp.exe
    2008-12-20 20:18 . 2009-01-05 10:23 88,566 --a
    c:\windows\SYSTEM32\nvapps.xml
    2008-12-20 20:18 . 2006-10-22 12:22 17,056 --a
    c:\windows\SYSTEM32\nvdisp.nvu
    2008-12-20 20:17 . 2008-12-20 20:17 <DIR> d
    C:\NVIDIA
    2008-12-20 20:17 . 2006-10-22 15:06 208,896 --a
    c:\windows\SYSTEM32\NVUNINST.EXE
    2008-12-20 20:14 . 2008-12-20 20:14 <DIR> d
    c:\program files\SystemRequirementsLab
    2008-12-20 19:56 . 2008-05-30 14:11 3,850,760 --a
    c:\windows\SYSTEM32\D3DX9_38.dll
    2008-12-20 19:55 . 2005-05-26 15:34 2,297,552 --a
    c:\windows\SYSTEM32\d3dx9_26.dll
    2008-12-20 19:49 . 2008-12-20 19:49 <DIR> d
    c:\windows\Logs
    2008-12-20 18:55 . 2008-12-20 18:55 <DIR> d
    c:\documents and settings\All Users\Application Data\AdventureChronicles1
    2008-12-20 18:35 . 2008-12-20 18:35 <DIR> d
    c:\documents and settings\All Users\Application Data\PlayPond
    2008-12-12 19:25 . 2008-12-12 19:25 <DIR> d
    c:\program files\Caere

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-05 15:23
    d
    w c:\program files\lg_fwupdate
    2009-01-03 22:19
    d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-01-03 22:10
    d
    w c:\documents and settings\All Users\Application Data\BigFishGamesCache
    2009-01-03 00:34
    d
    w c:\documents and settings\All Users\Application Data\Google Updater
    2009-01-02 00:52
    d
    w c:\program files\SpywareBlaster
    2008-12-21 23:52
    d
    w c:\program files\Google
    2008-12-21 18:27
    d
    w c:\documents and settings\LocalService\Application Data\SACore
    2008-12-13 06:40 3,593,216
    w c:\windows\SYSTEM32\dllcache\mshtml.dll
    2008-12-13 00:43
    d
    w c:\program files\RealArcade
    2008-12-10 21:42
    d
    w c:\program files\Val`Gor
    2008-12-10 21:00
    d
    w c:\documents and settings\Owner\Application Data\Games
    2008-12-09 00:19
    d
    w c:\program files\iWin Games
    2008-12-05 23:28
    d
    w c:\documents and settings\Owner\Application Data\PlayFirst
    2008-12-05 23:28
    d
    w c:\documents and settings\All Users\Application Data\PlayFirst
    2008-12-03 23:48
    d
    w c:\documents and settings\All Users\Application Data\NeptunesAdve
    2008-12-03 23:26
    d
    w c:\documents and settings\Owner\Application Data\Shape games
    2008-12-03 21:15
    d
    w c:\documents and settings\Owner\Application Data\MysteryStudio
    2008-12-03 00:28
    d
    w c:\documents and settings\All Users\Application Data\Alawar Stargaze
    2008-11-25 00:10
    d
    w c:\program files\Escape The Museum
    2008-11-23 19:30
    d
    w c:\documents and settings\Owner\Application Data\Gold Casual Games
    2008-11-23 19:30
    d
    w c:\documents and settings\All Users\Application Data\Gold Casual Games
    2008-11-23 16:28
    d
    w c:\program files\Spybot - Search & Destroy
    2008-11-21 20:59
    d
    w c:\documents and settings\Owner\Application Data\Gogii Games
    2008-11-21 20:59
    d
    w c:\documents and settings\All Users\Application Data\Gogii Games
    2008-11-18 21:36
    d
    w c:\documents and settings\Owner\Application Data\Artogon
    2008-11-17 01:17
    d
    w c:\documents and settings\Owner\Application Data\cerasus.media
    2008-11-05 21:34
    d
    w c:\program files\bfgclient
    2008-10-27 15:04 70,992 ----a-w c:\windows\SYSTEM32\XAPOFX1_2.dll
    2008-10-27 15:04 514,384 ----a-w c:\windows\SYSTEM32\XAudio2_3.dll
    2008-10-27 15:04 235,856 ----a-w c:\windows\SYSTEM32\xactengine3_3.dll
    2008-10-27 15:04 23,376 ----a-w c:\windows\SYSTEM32\X3DAudio1_5.dll
    2008-10-24 11:21 455,296
    w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
    2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
    2008-10-23 12:36 286,720
    w c:\windows\SYSTEM32\dllcache\gdi32.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\dllcache\cdm.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
    2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
    2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
    2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\dllcache\wups.dll
    2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
    2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
    2008-10-16 13:11 70,656
    w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
    2008-10-16 13:11 13,824
    w c:\windows\SYSTEM32\dllcache\ieudinit.exe
    2008-10-15 16:34 337,408
    w c:\windows\SYSTEM32\dllcache\netapi32.dll
    2008-10-15 07:06 633,632
    w c:\windows\SYSTEM32\dllcache\iexplore.exe
    2008-10-15 07:04 161,792
    w c:\windows\SYSTEM32\dllcache\ieakui.dll
    2008-10-10 09:52 452,440 ----a-w c:\windows\SYSTEM32\d3dx10_40.dll
    2008-10-10 09:52 4,379,984 ----a-w c:\windows\SYSTEM32\D3DX9_40.dll
    2008-10-10 09:52 2,036,576 ----a-w c:\windows\SYSTEM32\D3DCompiler_40.dll
    2008-07-08 02:12 774,144 -c--a-w c:\program files\RngInterstitial.dll
    2008-02-26 19:53 0 -c--a-w c:\program files\temp01
    2006-06-16 00:24 308 -c--a-w c:\documents and settings\Owner\Application Data\bbbconfig.dat
    2005-03-28 16:42 284 -c--a-w c:\documents and settings\Owner\Application Data\ViewerApp.dat
    2002-05-20 12:19 61,440 -c--a-w c:\windows\INF\i386\onetUSD.dll
    2002-05-16 12:22 36,864 -c--a-w c:\windows\INF\i386\Vizmicro.dll
    2002-05-16 12:21 286,720 -c--a-w c:\windows\INF\i386\rtscan.dll
    2002-05-16 12:20 172,032 -c--a-w c:\windows\INF\i386\viceo.dll
    2001-08-03 22:29 13,824 -c--a-w c:\windows\INF\i386\Usbscan.sys
    1998-12-09 02:53 99,840 -c--a-w c:\program files\Common Files\IRAABOUT.DLL
    1998-12-09 02:53 70,144 -c--a-w c:\program files\Common Files\IRAMDMTR.DLL
    1998-12-09 02:53 48,640 -c--a-w c:\program files\Common Files\IRALPTTR.DLL
    1998-12-09 02:53 31,744 -c--a-w c:\program files\Common Files\IRAWEBTR.DLL
    1998-12-09 02:53 186,368 -c--a-w c:\program files\Common Files\IRAREG.DLL
    1998-12-09 02:53 17,920 -c--a-w c:\program files\Common Files\IRASRIAL.DLL
    2007-09-16 06:35 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
    2007-09-16 06:35 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
    2007-09-16 06:35 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
    2007-09-16 06:35 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
    2007-09-16 06:35 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
    2008-08-26 16:52 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082620080827\index.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
    "PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~2\PSFree.exe" [2005-03-17 536576]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
    "KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
    "IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
    "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
    "PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
    "HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-04 196608]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
    "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
    "LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-07-08 249856]
    "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
    "SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
    "InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
    "Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
    "DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-10-02 94208]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "S3TRAY2"="S3tray2.exe" [2001-10-04 c:\windows\SYSTEM32\S3tray2.exe]
    "nwiz"="nwiz.exe" [2006-10-22 c:\windows\SYSTEM32\nwiz.exe]

    c:\documents and settings\Administrator.YOUR-W92P4BHLZG\Start Menu\Programs\Startup\
    AutoPlay.exe [2001-09-17 36864]

    c:\documents and settings\Administrator.YOUR-W92P4BHLZG.000\Start Menu\Programs\Startup\
    AutoPlay.exe [2001-09-17 36864]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-13 805392]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.I420"= vdrcodec.dll
    "VIDC.DVSD"= miroDV2avi.DLL
    "VIDC.PIM1"= pclepim1.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=&quot;"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
    backup=c:\windows\pss\hp center UI.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
    backup=c:\windows\pss\hp center.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
    backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a
    2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCActiveMenu]
    2001-10-02 22:23 94208 c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCM]
    c--- 2001-10-02 22:21 155648 c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
    c--- 2001-07-25 13:00 184376 c:\program files\Microsoft Money\System\Money Express.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --a
    2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
    --a
    1999-10-14 11:50 53248 c:\program files\Caere\OmniPagePro10.0\OPware32.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
    --a
    2002-05-20 07:17 86016 c:\program files\Visioneer OneTouch\OneTouchMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

    R0 pavboot;pavboot;c:\windows\SYSTEM32\drivers\pavboot.sys [2009-01-03 28544]
    R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-27 203280]
    S4 0040461230474749mcinstcleanup;McAfee Application Installer Cleanup (0040461230474749);c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - InCDrec

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-27 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

    2008-12-27 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-USB - c:\windows\system32\usb.exe
    MSConfigStartUp-Zero Knowledge Freedom - c:\program files\Zero Knowledge\Freedom\AutoStarterR.exe


    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Search_URL = hxxp://srch-us4.hpwis.com/
    mSearch Bar = hxxp://srch-us4.hpwis.com/
    uInternet Settings,ProxyOverride = localhost
    Trusted Zone: *.internet
    Trusted Zone: *.mcafee.com

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

    c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
    hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    c:\windows\Downloaded Program Files\sysreqlab.osd
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-05 10:41:44
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    **************************************************************************
    .
    DLLs Loaded Under Running Processes

    - - - - - - - > 'winlogon.exe'(672)
    c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    c:\program files\common files\logishrd\bluetooth\LBTServ.dll
    .
    Completion time: 2009-01-05 10:45:35
    ComboFix-quarantined-files.txt 2009-01-05 15:44:17

    Pre-Run: 83,093,610,496 bytes free
    Post-Run: 83,058,831,360 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows Whistler Personal" /fastdetect /NoExecute=OptIn

    287 --- E O F --- 2008-12-18 21:59:33


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:02:47 AM, on 1/5/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\lg_fwupdate\fwupdate.exe
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\Program Files\Verizon\McciTrayApp.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
    O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

    --
    End of file - 10068 bytes


    THANKS AGAIN FOR YOUR TIME AND ASSISTANCE!!!!!!!!
  • edited January 2009
    Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
    It's IMPORTANT to carry out the instructions in the sequence listed below.
    1. Close any open browsers.
    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    Open *notepad* and copy/paste the text in the quotebox below into it:

    File::
    c:\documents and settings\Administrator.YOUR-W92P4BHLZG\Start Menu\Programs\Startup\AutoPlay.exe
    c:\documents and settings\Administrator.YOUR-W92P4BHLZG.000\Start Menu\Programs\Startup\AutoPlay.exe

    Folder::
    c:\program files\temp01
    Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.

    CFScript.gif
    Refering to the picture above, drag CFScript.txt into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt
    Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.

    *Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*
  • edited January 2009
    Good Morning,
    Followed your directions and the ComboFix and HijackThis logs follow (note: the "04........" still exists.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:13:44 AM, on 1/6/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\lg_fwupdate\fwupdate.exe
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\Program Files\Verizon\McciTrayApp.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    c:\Program Files\Microsoft Money\System\urlmap.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
    O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

    --
    End of file - 10316 bytes
    ComboFix 09-01-05.01 - Owner 2009-01-06 9:51:04.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.275 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
    AV: McAfee VirusScan *On-access scanning disabled* (Updated)
    FW: McAfee Personal Firewall *enabled*
    * Created a new restore point

    FILE ::
    c:\documents and settings\Administrator.YOUR-W92P4BHLZG.000\Start Menu\Programs\Startup\AutoPlay.exe
    c:\documents and settings\Administrator.YOUR-W92P4BHLZG\Start Menu\Programs\Startup\AutoPlay.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Administrator.YOUR-W92P4BHLZG.000\Start Menu\Programs\Startup\AutoPlay.exe
    c:\documents and settings\Administrator.YOUR-W92P4BHLZG\Start Menu\Programs\Startup\AutoPlay.exe
    c:\program files\temp01\

    .
    ((((((((((((((((((((((((( Files Created from 2008-12-06 to 2009-01-06 )))))))))))))))))))))))))))))))
    .

    2009-01-04 13:22 . 2009-01-04 13:22 <DIR> d
    c:\program files\Trend Micro
    2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d
    c:\program files\Panda Security
    2009-01-03 17:50 . 2008-06-19 17:24 28,544 --a
    c:\windows\SYSTEM32\drivers\pavboot.sys
    2009-01-03 17:19 . 2009-01-03 17:19 <DIR> d
    c:\program files\Heartwild Solitaire
    2009-01-03 17:12 . 2009-01-03 17:13 <DIR> d
    c:\program files\Haunted Hotel II - Believe the Lies
    2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
    c:\documents and settings\Owner\Application Data\blg
    2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
    c:\documents and settings\All Users\Application Data\blg
    2009-01-01 14:28 . 2009-01-01 14:28 <DIR> d
    c:\program files\Lost Realms - Legacy of the Sun Princess
    2008-12-29 20:26 . 2008-12-29 20:26 <DIR> d
    c:\documents and settings\Owner\Freeze Tag - Dream Machine
    2008-12-29 16:42 . 2008-12-29 16:44 <DIR> d
    c:\program files\Mystery in London
    2008-12-27 19:52 . 2008-12-27 19:52 <DIR> d
    c:\documents and settings\Owner\Application Data\Cat's Eye Games
    2008-12-27 19:44 . 2008-12-27 19:44 <DIR> d
    c:\documents and settings\All Users\Application Data\Arkadium
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\Suspects and Clues Prefs
    2008-12-27 19:26 . 2008-12-27 19:27 <DIR> d
    c:\documents and settings\Owner\Application Data\Suspects and Clues Players
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\Spinapse
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\IOMediaSupport6SZZ001s
    2008-12-27 15:27 . 2008-12-27 15:28 <DIR> d
    c:\program files\Suspects and Clues
    2008-12-27 09:15 . 2008-12-27 09:15 <DIR> d
    c:\documents and settings\All Users\Application Data\SiteAdvisor
    2008-12-27 09:15 . 2009-01-06 09:28 7,113 --a
    c:\windows\SYSTEM32\Config.MPF
    2008-12-27 09:10 . 2007-11-22 06:44 201,320 --a
    c:\windows\SYSTEM32\drivers\mfehidk.sys
    2008-12-27 09:10 . 2007-07-13 06:20 113,952 --a
    c:\windows\SYSTEM32\drivers\Mpfp.sys
    2008-12-27 09:10 . 2007-11-22 06:44 79,304 --a
    c:\windows\SYSTEM32\drivers\mfeavfk.sys
    2008-12-27 09:10 . 2007-12-02 12:51 40,488 --a
    c:\windows\SYSTEM32\drivers\mfesmfk.sys
    2008-12-27 09:10 . 2007-11-22 06:44 35,240 --a
    c:\windows\SYSTEM32\drivers\mfebopk.sys
    2008-12-27 09:10 . 2007-11-22 06:44 33,832 --a
    c:\windows\SYSTEM32\drivers\mferkdk.sys
    2008-12-27 09:09 . 2008-12-27 09:09 <DIR> d
    c:\program files\McAfee.com
    2008-12-27 09:08 . 2008-12-27 09:14 <DIR> d
    c:\program files\McAfee
    2008-12-27 09:08 . 2008-12-27 09:10 <DIR> d
    c:\program files\Common Files\McAfee
    2008-12-26 20:19 . 2008-12-27 09:15 <DIR> d
    c:\documents and settings\All Users\Application Data\McAfee
    2008-12-24 16:01 . 2009-01-05 19:04 <DIR> d
    c:\program files\Mystery Case Files - Return to Ravenhearst
    2008-12-20 20:18 . 2006-10-22 12:22 208,896 --a
    c:\windows\SYSTEM32\nvudisp.exe
    2008-12-20 20:18 . 2009-01-06 09:24 88,566 --a
    c:\windows\SYSTEM32\nvapps.xml
    2008-12-20 20:18 . 2006-10-22 12:22 17,056 --a
    c:\windows\SYSTEM32\nvdisp.nvu
    2008-12-20 20:17 . 2008-12-20 20:17 <DIR> d
    C:\NVIDIA
    2008-12-20 20:17 . 2006-10-22 15:06 208,896 --a
    c:\windows\SYSTEM32\NVUNINST.EXE
    2008-12-20 20:14 . 2008-12-20 20:14 <DIR> d
    c:\program files\SystemRequirementsLab
    2008-12-20 19:56 . 2008-05-30 14:11 3,850,760 --a
    c:\windows\SYSTEM32\D3DX9_38.dll
    2008-12-20 19:55 . 2005-05-26 15:34 2,297,552 --a
    c:\windows\SYSTEM32\d3dx9_26.dll
    2008-12-20 19:49 . 2008-12-20 19:49 <DIR> d
    c:\windows\Logs
    2008-12-20 18:55 . 2008-12-20 18:55 <DIR> d
    c:\documents and settings\All Users\Application Data\AdventureChronicles1
    2008-12-20 18:35 . 2008-12-20 18:35 <DIR> d
    c:\documents and settings\All Users\Application Data\PlayPond
    2008-12-12 19:25 . 2008-12-12 19:25 <DIR> d
    c:\program files\Caere

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-06 14:31
    d
    w c:\documents and settings\All Users\Application Data\Google Updater
    2009-01-06 14:25
    d
    w c:\program files\lg_fwupdate
    2009-01-06 01:53
    d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-01-06 01:53
    d
    w c:\documents and settings\All Users\Application Data\BigFishGamesCache
    2009-01-02 00:52
    d
    w c:\program files\SpywareBlaster
    2008-12-21 23:52
    d
    w c:\program files\Google
    2008-12-21 18:27
    d
    w c:\documents and settings\LocalService\Application Data\SACore
    2008-12-13 06:40 3,593,216
    w c:\windows\SYSTEM32\dllcache\mshtml.dll
    2008-12-13 00:43
    d
    w c:\program files\RealArcade
    2008-12-10 21:42
    d
    w c:\program files\Val`Gor
    2008-12-10 21:00
    d
    w c:\documents and settings\Owner\Application Data\Games
    2008-12-09 00:19
    d
    w c:\program files\iWin Games
    2008-12-05 23:28
    d
    w c:\documents and settings\Owner\Application Data\PlayFirst
    2008-12-05 23:28
    d
    w c:\documents and settings\All Users\Application Data\PlayFirst
    2008-12-03 23:48
    d
    w c:\documents and settings\All Users\Application Data\NeptunesAdve
    2008-12-03 23:26
    d
    w c:\documents and settings\Owner\Application Data\Shape games
    2008-12-03 21:15
    d
    w c:\documents and settings\Owner\Application Data\MysteryStudio
    2008-12-03 00:28
    d
    w c:\documents and settings\All Users\Application Data\Alawar Stargaze
    2008-11-25 00:10
    d
    w c:\program files\Escape The Museum
    2008-11-23 19:30
    d
    w c:\documents and settings\Owner\Application Data\Gold Casual Games
    2008-11-23 19:30
    d
    w c:\documents and settings\All Users\Application Data\Gold Casual Games
    2008-11-23 16:28
    d
    w c:\program files\Spybot - Search & Destroy
    2008-11-21 20:59
    d
    w c:\documents and settings\Owner\Application Data\Gogii Games
    2008-11-21 20:59
    d
    w c:\documents and settings\All Users\Application Data\Gogii Games
    2008-11-18 21:36
    d
    w c:\documents and settings\Owner\Application Data\Artogon
    2008-11-17 01:17
    d
    w c:\documents and settings\Owner\Application Data\cerasus.media
    2008-10-27 15:04 70,992 ----a-w c:\windows\SYSTEM32\XAPOFX1_2.dll
    2008-10-27 15:04 514,384 ----a-w c:\windows\SYSTEM32\XAudio2_3.dll
    2008-10-27 15:04 235,856 ----a-w c:\windows\SYSTEM32\xactengine3_3.dll
    2008-10-27 15:04 23,376 ----a-w c:\windows\SYSTEM32\X3DAudio1_5.dll
    2008-10-24 11:21 455,296
    w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
    2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
    2008-10-23 12:36 286,720
    w c:\windows\SYSTEM32\dllcache\gdi32.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\dllcache\cdm.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
    2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
    2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
    2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\dllcache\wups.dll
    2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
    2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
    2008-10-16 13:11 70,656
    w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
    2008-10-16 13:11 13,824
    w c:\windows\SYSTEM32\dllcache\ieudinit.exe
    2008-10-15 16:34 337,408
    w c:\windows\SYSTEM32\dllcache\netapi32.dll
    2008-10-15 07:06 633,632
    w c:\windows\SYSTEM32\dllcache\iexplore.exe
    2008-10-15 07:04 161,792
    w c:\windows\SYSTEM32\dllcache\ieakui.dll
    2008-10-10 09:52 452,440 ----a-w c:\windows\SYSTEM32\d3dx10_40.dll
    2008-10-10 09:52 4,379,984 ----a-w c:\windows\SYSTEM32\D3DX9_40.dll
    2008-10-10 09:52 2,036,576 ----a-w c:\windows\SYSTEM32\D3DCompiler_40.dll
    2008-07-08 02:12 774,144 -c--a-w c:\program files\RngInterstitial.dll
    2008-02-26 19:53 0 -c--a-w c:\program files\temp01
    2006-06-16 00:24 308 -c--a-w c:\documents and settings\Owner\Application Data\bbbconfig.dat
    2005-03-28 16:42 284 -c--a-w c:\documents and settings\Owner\Application Data\ViewerApp.dat
    2002-05-20 12:19 61,440 -c--a-w c:\windows\INF\i386\onetUSD.dll
    2002-05-16 12:22 36,864 -c--a-w c:\windows\INF\i386\Vizmicro.dll
    2002-05-16 12:21 286,720 -c--a-w c:\windows\INF\i386\rtscan.dll
    2002-05-16 12:20 172,032 -c--a-w c:\windows\INF\i386\viceo.dll
    2001-08-03 22:29 13,824 -c--a-w c:\windows\INF\i386\Usbscan.sys
    1998-12-09 02:53 99,840 -c--a-w c:\program files\Common Files\IRAABOUT.DLL
    1998-12-09 02:53 70,144 -c--a-w c:\program files\Common Files\IRAMDMTR.DLL
    1998-12-09 02:53 48,640 -c--a-w c:\program files\Common Files\IRALPTTR.DLL
    1998-12-09 02:53 31,744 -c--a-w c:\program files\Common Files\IRAWEBTR.DLL
    1998-12-09 02:53 186,368 -c--a-w c:\program files\Common Files\IRAREG.DLL
    1998-12-09 02:53 17,920 -c--a-w c:\program files\Common Files\IRASRIAL.DLL
    2007-09-16 06:35 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
    2007-09-16 06:35 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
    2007-09-16 06:35 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
    2007-09-16 06:35 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
    2007-09-16 06:35 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
    2008-08-26 16:52 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082620080827\index.dat
    .

    ((((((((((((((((((((((((((((( snapshot@2009-01-05_10.43.09.82 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
    + 2009-01-06 14:33:44 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
    - 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    + 2009-01-06 14:33:44 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
    "PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~2\PSFree.exe" [2005-03-17 536576]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
    "KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
    "IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
    "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
    "PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
    "HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-04 196608]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
    "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
    "LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-07-08 249856]
    "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
    "SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
    "InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
    "Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
    "DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-10-02 94208]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "S3TRAY2"="S3tray2.exe" [2001-10-04 c:\windows\SYSTEM32\S3tray2.exe]
    "nwiz"="nwiz.exe" [2006-10-22 c:\windows\SYSTEM32\nwiz.exe]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-13 805392]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.I420"= vdrcodec.dll
    "VIDC.DVSD"= miroDV2avi.DLL
    "VIDC.PIM1"= pclepim1.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=&quot;"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
    backup=c:\windows\pss\hp center UI.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
    backup=c:\windows\pss\hp center.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
    backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a
    2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCActiveMenu]
    2001-10-02 22:23 94208 c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCM]
    c--- 2001-10-02 22:21 155648 c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
    c--- 2001-07-25 13:00 184376 c:\program files\Microsoft Money\System\Money Express.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --a
    2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
    --a
    1999-10-14 11:50 53248 c:\program files\Caere\OmniPagePro10.0\OPware32.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
    --a
    2002-05-20 07:17 86016 c:\program files\Visioneer OneTouch\OneTouchMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

    R0 pavboot;pavboot;c:\windows\SYSTEM32\drivers\pavboot.sys [2009-01-03 28544]
    R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-27 203280]
    S4 0040461230474749mcinstcleanup;McAfee Application Installer Cleanup (0040461230474749);c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - InCDrec

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-27 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

    2008-12-27 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Search_URL = hxxp://srch-us4.hpwis.com/
    mSearch Bar = hxxp://srch-us4.hpwis.com/
    uInternet Settings,ProxyOverride = localhost
    Trusted Zone: *.internet
    Trusted Zone: *.mcafee.com

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

    c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
    hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    c:\windows\Downloaded Program Files\sysreqlab.osd
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-06 09:57:52
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    **************************************************************************
    .
    DLLs Loaded Under Running Processes

    - - - - - - - > 'winlogon.exe'(668)
    c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    c:\program files\common files\logishrd\bluetooth\LBTServ.dll
    .
    Completion time: 2009-01-06 10:01:37
    ComboFix-quarantined-files.txt 2009-01-06 15:00:19
    ComboFix2.txt 2009-01-05 15:45:37

    Pre-Run: 83,635,527,680 bytes free
    Post-Run: 83,582,976,000 bytes free

    281 --- E O F --- 2008-12-18 21:59:33
  • edited January 2009
    It's OK, don't worry too much about the Autoplay.exe. It belongs to HP Backweb, and although it can be considered as adware for some it is still a legitimate program.


    I need you to open Notepad again, and copy and paste the following:
    File::
    c:\gatorpatch.log
    c:\temp\salm_kyf.dat
    c:\temp\salmau.dat
    c:\temp\fleok
    c:\windows\system32\wsxsvc
    c:\windows\system32\vmss
    c:\keys.ini
    c:\windows\inf\msview.inf
    
    Folder::
    c:\program files\lycos
    C:\Program Files\iWin.com 
    C:\Program Files\iWin Games
    C:\Program Files\Dream Day Wedding - Married in Manhattan\
    
    

    Save this as CFScript2.txt, in the same location as ComboFix.exe which is on the Desktop.

    CFScript.gif
    Refering to the picture above, drag CFScript.txt into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt
    Please copy and paste the ComboFix.txt along with a fresh Panda ActiveScan log in your next reply please.

    *Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*
  • edited January 2009
    HI!

    ComboFix 09-01-05.01 - Owner 2009-01-07 10:25:45.3 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.211 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Owner\Desktop\CFScript2.txt
    AV: McAfee VirusScan *On-access scanning disabled* (Updated)
    FW: McAfee Personal Firewall *enabled*
    * Created a new restore point

    FILE ::
    c:\gatorpatch.log
    c:\keys.ini
    c:\temp\fleok
    c:\temp\salm_kyf.dat
    c:\temp\salmau.dat
    c:\windows\inf\msview.inf
    c:\windows\system32\vmss
    c:\windows\system32\wsxsvc
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\gatorpatch.log
    c:\keys.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\
    c:\program files\Dream Day Wedding - Married in Manhattan\\activation_info.xml
    c:\program files\Dream Day Wedding - Married in Manhattan\\Bathroom_a6.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Bedroom_a1.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\bfgstate.xml
    c:\program files\Dream Day Wedding - Married in Manhattan\\Central_Park_s16.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Cloud_Nine_Travel_s6.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\data.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Desk_a2.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Dream Day Wedding - Married in Manhattan.exe
    c:\program files\Dream Day Wedding - Married in Manhattan\\Empire_Bridal_Crisis_s12.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Empire_Bridal_s9.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\FeliCitySpa_escape_e1.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\FeliCitySpa_s2.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Flora_crisis_s11.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Flora_s5.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\fmodex.dll
    c:\program files\Dream Day Wedding - Married in Manhattan\\Grand_Ballroom_s8.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Heirloom_Stationery_s10.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Honeymoon_Italy_s23.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bathroom_a6_7.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bathroom_a6_8.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bedroom_a1_1.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bedroom_a1_2.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bedroom_a1_3.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Central_Park_s16.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Cloud_Nine_Travel_s6.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Desk_a2_4.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Desk_a2_5.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Desk_a2_6.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Empire_Bridal_Crisis_s12.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Empire_Bridal_s9.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\FeliCitySpa_escape_e1.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\FeliCitySpa_s2.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Flora_crisis_s11.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Flora_s5.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Grand_Ballroom_s8.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Heirloom_Stationery_s10.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Honeymoon_Italy_s23.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Kitchen_a4_7.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Kitchen_a4_8.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\La_Creme_Bakery_crisis_s7.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\La_Creme_Bakery_s1.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Living_room_A_a5_4.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Living_room_A_a5_5.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Living_room_A_a5_6.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\living_room_a3_1.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\living_room_a3_2.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\living_room_a3_3.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Lux_Photo_Design_s19.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Magician's_cabinet_escape_e2.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Party_Rentals_s3.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Pennys_Flowers_crisis_s18.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Pennys_Flowers_s14.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Sabrinas_Gown_Butique_s20.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Sabrinas_Wedding_Crisis_s22.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Savory_Catering_escape_e3.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Savory_Catering_s15.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Subway_escape_e4.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Subway_s4.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Sugarplum_Crisis_s21.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Sugarplum_s17.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Tahiti_s13.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Attic_TutorialDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Attic_WinDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_afterBAIdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_Before_Honeymoon.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_crisiswondialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Book_FocusTestOver.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_gamewondialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Book_HouseCompleteDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_levelwondialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_magazinedialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_tutorialcrisisdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_tutorialcrisisdialogB.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_tutorialdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_tutorialintrodialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CAS_ConfirmSkipDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CBook.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CBuildObject.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CGameSlotHold.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CIrp.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CIrpMan.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Con_GameMenuDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Con_LoseDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\con_tutorialdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\con_tutorialmixerdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Con_WinDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\connectionmap.xml
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\connections.xml
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\ConPanel.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CreditsDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CRollHoldChoice.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CTraceEffectMovie.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CVector2.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\FloristTransition.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_BadClickDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\game_bluebirddialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_ConfirmPanicDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_GiftFoundDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_InApartmentDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_InApartmentDialogB.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_InEscapeDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_LoseDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_OutApartmentDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_OutEscapeDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_OverDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_PhoneDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_PhoneFoundDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_PhoneLostDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_RegistryIntroDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_SecretBluebirdDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TicketCloseDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialBigHintDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialBluebirdDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialCASItemDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialCASReminderDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialDogSlowDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialHintDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialHowToPlayAppDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialInventoryDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialSuperclueDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_WinDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_WrongItemUsageDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\GameMenuDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\helpdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\ISpyPanel.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\ISpyPanel_esc.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\ItemMouseButton.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LevelIntroDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_LoseDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_TutorialDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_TutorialTwoDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_WinDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_WinHoneymoonDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkPanel.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\mainmenudialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\menu_confirmdeletedialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Menu_ConfirmInGameQuitDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\menu_confirmquitdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\menu_highscoresdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Menu_ProfileDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\menu_refusedeletedialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Minigame_ConfirmQuitDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Minigame_SolveDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\MiniGameEffects.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\OptionsDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\PartMouseButton.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\playdemodialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Refinish_TutorialDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Refinish_WinDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\RSVP_CardPlacingDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\RSVP_ConfirmResetDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\settings.xml
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\SlidersCell.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StandardMouseButton.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StandardRadioButton.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StateMachine.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StickMouseButton.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\story_tutorialdialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\story_tutorialdialogB.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Story_TutorialSpecialItemDialog.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StoryEffects.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Transitions.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\util.lua
    c:\program files\Dream Day Wedding - Married in Manhattan\\items_animations.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Kitchen_a4.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\La_Creme_Bakery_crisis_s7.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\La_Creme_Bakery_s1.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\LaunchGame.bfg
    c:\program files\Dream Day Wedding - Married in Manhattan\\Living_room_A_a5.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\living_room_a3.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Lux_Photo_Design_s19.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Magician_cabinet_escape_e2.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\MiniGameChooser.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\OberonSplash.dll
    c:\program files\Dream Day Wedding - Married in Manhattan\\particles.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\partner_splash.jpg
    c:\program files\Dream Day Wedding - Married in Manhattan\\Party_Rentals_s3.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Pennys_Flowers_crisis_s18.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Pennys_Flowers_s14.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\pics\60x40.jpg
    c:\program files\Dream Day Wedding - Married in Manhattan\\pics\80x80.jpg
    c:\program files\Dream Day Wedding - Married in Manhattan\\pics\feature.jpg
    c:\program files\Dream Day Wedding - Married in Manhattan\\pipes.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\rsvp.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Sabrinas_Gown_Butique_s20.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Sabrinas_Wedding_Crisis_s22.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Savory_Catering_escape_e3.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Savory_Catering_s15.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Splash.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\storygame.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Subway_escape_e4.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Subway_s4.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Sugarplum_Crisis_s21.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Sugarplum_s17.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\SwiftShader.dll
    c:\program files\Dream Day Wedding - Married in Manhattan\\SwiftShader.ini
    c:\program files\Dream Day Wedding - Married in Manhattan\\Tahiti_s13.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\ui.dat
    c:\program files\Dream Day Wedding - Married in Manhattan\\Uninstall.exe
    c:\program files\Dream Day Wedding - Married in Manhattan\\UnlockGame.bfg
    c:\program files\Dream Day Wedding - Married in Manhattan\\vcwcmrq.exe
    c:\program files\iWin Games
    c:\program files\iWin Games\AdminWorker.exe
    c:\program files\iWin Games\DesktopAlerts.exe
    c:\program files\iWin Games\firefox\chrome\iwinarcade.jar
    c:\program files\iWin Games\firefox\install.rdf
    c:\program files\iWin Games\ftdownload.dat
    c:\program files\iWin Games\host.cfg
    c:\program files\iWin Games\iWinGames.exe
    c:\program files\iWin Games\pages\alert32x32.gif
    c:\program files\iWin Games\pages\blank.html
    c:\program files\iWin Games\pages\blank2.html
    c:\program files\iWin Games\pages\error.html
    c:\program files\iWin Games\pages\iwin_logo.gif
    c:\program files\iWin Games\pages\login.html
    c:\program files\iWin Games\pages\maintenance.html
    c:\program files\iWin Games\pages\offline_tag.gif
    c:\program files\iWin Games\pages\offlineBg.gif
    c:\program files\iWin Games\sounds\animation.wav
    c:\program files\iWin Games\sounds\animationBack.wav
    c:\program files\iWin Games\sounds\button_click.wav
    c:\program files\iWin Games\sounds\download_completed.wav
    c:\program files\iWin Games\sounds\start.wav
    c:\program files\iWin Games\Uninstall.exe
    c:\program files\iWin Games\WebInstaller.exe
    c:\program files\iWin Games\WebUpdater.bmp
    c:\program files\iWin Games\WebUpdater.exe
    c:\program files\iWin.com
    c:\program files\iWin.com\Mystery of the Mummy\GLWorker.exe
    c:\program files\lycos
    c:\temp\salm_kyf.dat
    c:\temp\salmau.dat
    .
    ((((((((((( Files Created from 2008-12-07 to 2009-01-07 )))))))))))))))))
    .

    2009-01-06 19:03 . 2009-01-06 19:03 <DIR> d
    c:\documents and settings\All Users\Application Data\SpecialBit
    2009-01-04 13:22 . 2009-01-04 13:22 <DIR> d
    c:\program files\Trend Micro
    2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d
    c:\program files\Panda Security
    2009-01-03 17:50 . 2008-06-19 17:24 28,544 --a
    c:\windows\SYSTEM32\drivers\pavboot.sys
    2009-01-03 17:12 . 2009-01-03 17:13 <DIR> d
    c:\program files\Haunted Hotel II - Believe the Lies
    2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
    c:\documents and settings\Owner\Application Data\blg
    2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
    c:\documents and settings\All Users\Application Data\blg
    2008-12-29 20:26 . 2008-12-29 20:26 <DIR> d
    c:\documents and settings\Owner\Freeze Tag - Dream Machine
    2008-12-29 16:42 . 2008-12-29 16:44 <DIR> d
    c:\program files\Mystery in London
    2008-12-27 19:52 . 2008-12-27 19:52 <DIR> d
    c:\documents and settings\Owner\Application Data\Cat's Eye Games
    2008-12-27 19:44 . 2008-12-27 19:44 <DIR> d
    c:\documents and settings\All Users\Application Data\Arkadium
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\Suspects and Clues Prefs
    2008-12-27 19:26 . 2008-12-27 19:27 <DIR> d
    c:\documents and settings\Owner\Application Data\Suspects and Clues Players
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\Spinapse
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\IOMediaSupport6SZZ001s
    2008-12-27 15:27 . 2008-12-27 15:28 <DIR> d
    c:\program files\Suspects and Clues
    2008-12-27 09:15 . 2008-12-27 09:15 <DIR> d
    c:\documents and settings\All Users\Application Data\SiteAdvisor
    2008-12-27 09:15 . 2009-01-07 09:03 7,113 --a
    c:\windows\SYSTEM32\Config.MPF
    2008-12-27 09:10 . 2007-11-22 06:44 201,320 --a
    c:\windows\SYSTEM32\drivers\mfehidk.sys
    2008-12-27 09:10 . 2007-07-13 06:20 113,952 --a
    c:\windows\SYSTEM32\drivers\Mpfp.sys
    2008-12-27 09:10 . 2007-11-22 06:44 79,304 --a
    c:\windows\SYSTEM32\drivers\mfeavfk.sys
    2008-12-27 09:10 . 2007-12-02 12:51 40,488 --a
    c:\windows\SYSTEM32\drivers\mfesmfk.sys
    2008-12-27 09:10 . 2007-11-22 06:44 35,240 --a
    c:\windows\SYSTEM32\drivers\mfebopk.sys
    2008-12-27 09:10 . 2007-11-22 06:44 33,832 --a
    c:\windows\SYSTEM32\drivers\mferkdk.sys
    2008-12-27 09:09 . 2008-12-27 09:09 <DIR> d
    c:\program files\McAfee.com
    2008-12-27 09:08 . 2008-12-27 09:14 <DIR> d
    c:\program files\McAfee
    2008-12-27 09:08 . 2008-12-27 09:10 <DIR> d
    c:\program files\Common Files\McAfee
    2008-12-26 20:19 . 2008-12-27 09:15 <DIR> d
    c:\documents and settings\All Users\Application Data\McAfee
    2008-12-24 16:01 . 2009-01-05 19:04 <DIR> d
    c:\program files\Mystery Case Files - Return to Ravenhearst
    2008-12-20 20:18 . 2006-10-22 12:22 208,896 --a
    c:\windows\SYSTEM32\nvudisp.exe
    2008-12-20 20:18 . 2009-01-07 09:00 88,566 --a
    c:\windows\SYSTEM32\nvapps.xml
    2008-12-20 20:18 . 2006-10-22 12:22 17,056 --a
    c:\windows\SYSTEM32\nvdisp.nvu
    2008-12-20 20:17 . 2008-12-20 20:17 <DIR> d
    C:\NVIDIA
    2008-12-20 20:17 . 2006-10-22 15:06 208,896 --a
    c:\windows\SYSTEM32\NVUNINST.EXE
    2008-12-20 20:14 . 2008-12-20 20:14 <DIR> d
    c:\program files\SystemRequirementsLab
    2008-12-20 19:56 . 2008-05-30 14:11 3,850,760 --a
    c:\windows\SYSTEM32\D3DX9_38.dll
    2008-12-20 19:55 . 2005-05-26 15:34 2,297,552 --a
    c:\windows\SYSTEM32\d3dx9_26.dll
    2008-12-20 19:49 . 2008-12-20 19:49 <DIR> d
    c:\windows\Logs
    2008-12-20 18:55 . 2008-12-20 18:55 <DIR> d
    c:\documents and settings\All Users\Application Data\AdventureChronicles1
    2008-12-20 18:35 . 2008-12-20 18:35 <DIR> d
    c:\documents and settings\All Users\Application Data\PlayPond
    2008-12-12 19:25 . 2008-12-12 19:25 <DIR> d
    c:\program files\Caere

    .
    ((((((((((((((((((( Find3M Report )))))))))))))))))))))))
    .
    2009-01-07 14:00
    d
    w c:\program files\lg_fwupdate
    2009-01-07 00:47
    d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-01-07 00:32
    d
    w c:\documents and settings\All Users\Application Data\Sandlot Games
    2009-01-06 14:31
    d
    w c:\documents and settings\All Users\Application Data\Google Updater
    2009-01-06 01:53
    d
    w c:\documents and settings\All Users\Application Data\BigFishGamesCache
    2009-01-02 00:52
    d
    w c:\program files\SpywareBlaster
    2008-12-21 23:52
    d
    w c:\program files\Google
    2008-12-21 18:27
    d
    w c:\documents and settings\LocalService\Application Data\SACore
    2008-12-13 06:40 3,593,216
    w c:\windows\SYSTEM32\dllcache\mshtml.dll
    2008-12-13 00:43
    d
    w c:\program files\RealArcade
    2008-12-10 21:42
    d
    w c:\program files\Val`Gor
    2008-12-10 21:00
    d
    w c:\documents and settings\Owner\Application Data\Games
    2008-12-05 23:28
    d
    w c:\documents and settings\Owner\Application Data\PlayFirst
    2008-12-05 23:28
    d
    w c:\documents and settings\All Users\Application Data\PlayFirst
    2008-12-03 23:48
    d
    w c:\documents and settings\All Users\Application Data\NeptunesAdve
    2008-12-03 23:26
    d
    w c:\documents and settings\Owner\Application Data\Shape games
    2008-12-03 21:15
    d
    w c:\documents and settings\Owner\Application Data\MysteryStudio
    2008-12-03 00:28
    d
    w c:\documents and settings\All Users\Application Data\Alawar Stargaze
    2008-11-25 00:10
    d
    w c:\program files\Escape The Museum
    2008-11-23 19:30
    d
    w c:\documents and settings\Owner\Application Data\Gold Casual Games
    2008-11-23 19:30
    d
    w c:\documents and settings\All Users\Application Data\Gold Casual Games
    2008-11-23 16:28
    d
    w c:\program files\Spybot - Search & Destroy
    2008-11-21 20:59
    d
    w c:\documents and settings\Owner\Application Data\Gogii Games
    2008-11-21 20:59
    d
    w c:\documents and settings\All Users\Application Data\Gogii Games
    2008-11-18 21:36
    d
    w c:\documents and settings\Owner\Application Data\Artogon
    2008-11-17 01:17
    d
    w c:\documents and settings\Owner\Application Data\cerasus.media
    2008-10-27 15:04 70,992 ----a-w c:\windows\SYSTEM32\XAPOFX1_2.dll
    2008-10-27 15:04 514,384 ----a-w c:\windows\SYSTEM32\XAudio2_3.dll
    2008-10-27 15:04 235,856 ----a-w c:\windows\SYSTEM32\xactengine3_3.dll
    2008-10-27 15:04 23,376 ----a-w c:\windows\SYSTEM32\X3DAudio1_5.dll
    2008-10-24 11:21 455,296
    w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
    2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
    2008-10-23 12:36 286,720
    w c:\windows\SYSTEM32\dllcache\gdi32.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\dllcache\cdm.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
    2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
    2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
    2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\dllcache\wups.dll
    2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
    2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
    2008-10-16 13:11 70,656
    w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
    2008-10-16 13:11 13,824
    w c:\windows\SYSTEM32\dllcache\ieudinit.exe
    2008-10-15 16:34 337,408
    w c:\windows\SYSTEM32\dllcache\netapi32.dll
    2008-10-15 07:06 633,632
    w c:\windows\SYSTEM32\dllcache\iexplore.exe
    2008-10-15 07:04 161,792
    w c:\windows\SYSTEM32\dllcache\ieakui.dll
    2008-10-10 09:52 452,440 ----a-w c:\windows\SYSTEM32\d3dx10_40.dll
    2008-10-10 09:52 4,379,984 ----a-w c:\windows\SYSTEM32\D3DX9_40.dll
    2008-10-10 09:52 2,036,576 ----a-w c:\windows\SYSTEM32\D3DCompiler_40.dll
    2008-07-08 02:12 774,144 -c--a-w c:\program files\RngInterstitial.dll
    2008-02-26 19:53 0 -c--a-w c:\program files\temp01
    2006-06-16 00:24 308 -c--a-w c:\documents and settings\Owner\Application Data\bbbconfig.dat
    2005-03-28 16:42 284 -c--a-w c:\documents and settings\Owner\Application Data\ViewerApp.dat
    2002-05-20 12:19 61,440 -c--a-w c:\windows\INF\i386\onetUSD.dll
    2002-05-16 12:22 36,864 -c--a-w c:\windows\INF\i386\Vizmicro.dll
    2002-05-16 12:21 286,720 -c--a-w c:\windows\INF\i386\rtscan.dll
    2002-05-16 12:20 172,032 -c--a-w c:\windows\INF\i386\viceo.dll
    2001-08-03 22:29 13,824 -c--a-w c:\windows\INF\i386\Usbscan.sys
    1998-12-09 02:53 99,840 -c--a-w c:\program files\Common Files\IRAABOUT.DLL
    1998-12-09 02:53 70,144 -c--a-w c:\program files\Common Files\IRAMDMTR.DLL
    1998-12-09 02:53 48,640 -c--a-w c:\program files\Common Files\IRALPTTR.DLL
    1998-12-09 02:53 31,744 -c--a-w c:\program files\Common Files\IRAWEBTR.DLL
    1998-12-09 02:53 186,368 -c--a-w c:\program files\Common Files\IRAREG.DLL
    1998-12-09 02:53 17,920 -c--a-w c:\program files\Common Files\IRASRIAL.DLL
    2007-09-16 06:35 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
    2007-09-16 06:35 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
    2007-09-16 06:35 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
    2007-09-16 06:35 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
    2007-09-16 06:35 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
    2008-08-26 16:52 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082620080827\index.dat
    .

    ((((((((((((((( snapshot@2009-01-05_10.43.09.82 )))))))))))))
    .
    - 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
    + 2009-01-07 14:07:00 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
    - 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    + 2009-01-07 14:07:00 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    .
    (((((((((((((((( Reg Loading Points ))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
    "PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~2\PSFree.exe" [2005-03-17 536576]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
    "KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
    "IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
    "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
    "PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
    "HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-04 196608]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
    "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
    "LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-07-08 249856]
    "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
    "SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
    "InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
    "Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
    "DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-10-02 94208]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "S3TRAY2"="S3tray2.exe" [2001-10-04 c:\windows\SYSTEM32\S3tray2.exe]
    "nwiz"="nwiz.exe" [2006-10-22 c:\windows\SYSTEM32\nwiz.exe]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-13 805392]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.I420"= vdrcodec.dll
    "VIDC.DVSD"= miroDV2avi.DLL
    "VIDC.PIM1"= pclepim1.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=&quot;"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
    backup=c:\windows\pss\hp center UI.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
    backup=c:\windows\pss\hp center.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
    backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a
    2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCActiveMenu]
    2001-10-02 22:23 94208 c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCM]
    c--- 2001-10-02 22:21 155648 c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
    c--- 2001-07-25 13:00 184376 c:\program files\Microsoft Money\System\Money Express.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --a
    2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
    --a
    1999-10-14 11:50 53248 c:\program files\Caere\OmniPagePro10.0\OPware32.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
    --a
    2002-05-20 07:17 86016 c:\program files\Visioneer OneTouch\OneTouchMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

    R0 pavboot;pavboot;c:\windows\SYSTEM32\drivers\pavboot.sys [2009-01-03 28544]
    R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-27 203280]
    S4 0040461230474749mcinstcleanup;McAfee Application Installer Cleanup (0040461230474749);c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - InCDrec

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-27 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

    2008-12-27 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Search_URL = hxxp://srch-us4.hpwis.com/
    mSearch Bar = hxxp://srch-us4.hpwis.com/
    uInternet Settings,ProxyOverride = localhost
    Trusted Zone: *.internet
    Trusted Zone: *.mcafee.com

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

    c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
    hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    c:\windows\Downloaded Program Files\sysreqlab.osd
    .

    *********************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-07 10:32:43
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    ********************
    DLLs Loaded Under Running Processes

    - - - - - - - > 'winlogon.exe'(676)
    c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    c:\program files\common files\logishrd\bluetooth\LBTServ.dll
    .
    Completion time: 2009-01-07 10:40:09
    ComboFix-quarantined-files.txt 2009-01-07 15:38:13
    ComboFix2.txt 2009-01-06 15:01:40
    ComboFix3.txt 2009-01-05 15:45:37

    Pre-Run: 83,703,099,392 bytes free
    Post-Run: 83,633,156,096 bytes free

    521 --- E O F --- 2008-12-18 21:59:33

    ;****************************************************************
    ANALYSIS: 2009-01-07 15:39:41
    PROTECTIONS: 2
    MALWARE: 9
    SUSPECTS: 7
    ;*******************************************************************************************************************
    PROTECTIONS
    Description Version Active Updated
    ;=========================================================================================================================================McAFee Internet Security Suite 2007 8.1 No Yes
    McAfee VirusScan Plus 12.1 No No
    ;===================================================================================================================================================================================
    MALWARE
    Id Description Type Active Severity Disinfectable Disinfected Location
    ;===================================================================================================================================================================================
    00020302 adware/ncase Adware No 0 Yes No c:\temp\fleok
    00027660 adware/savenow Adware No 0 Yes No c:\windows\system32\wsxsvc
    00144935 Adware/IPInsight Adware No 0 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP171\A0028098.inf
    00521370 Spyware/Iehelp Spyware No 1 No No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinGamesHookIE.dll]
    00521370 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP150\A0022886.dll
    02893773 Spyware/Iehelp Spyware No 1 Yes No C:\Qoobox\Quarantine\C\Program Files\iWin Games\AdminWorker.exe.vir
    02893773 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP173\A0028392.exe
    02893774 Spyware/Iehelp Spyware No 1 Yes No C:\Qoobox\Quarantine\C\Program Files\iWin Games\WebInstaller.exe.vir
    02893774 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP173\A0028397.exe
    02893775 Spyware/Iehelp Spyware No 1 No No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinArcadeLauncher.exe]
    02893775 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP150\A0022885.exe
    03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\Documents and Settings\Owner\Desktop\ComboFix.exe
    04396338 W32/Gaobot.OXI.worm Virus/Worm No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP173\A0028391.exe
    04396338 W32/Gaobot.OXI.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\Program Files\Dream Day Wedding - Married in Manhattan\vcwcmrq.exe.vir
    ;===================================================================================================================================================================================
    SUSPECTS
    Sent Location `}
    ;===================================================================================================================================================================================
    No C:\hp\bin\ProcessLogger.exe `}
    No C:\Program Files\Discovery - A Seek and Find Adventure\Discovery.exe `}
    No C:\Program Files\Discovery - A Seek and Find Adventure\npqxpgj.exe `}
    No C:\Program Files\Hidden Expedition - Amazon\vdztdsj.exe `}
    No C:\Program Files\Hidden Secrets - The Nightmare\wnhbdgs.exe `}
    No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinGames.exe] `}
    No C:\Program Files\Mystery Case Files - Return to Ravenhearst\dppxxpn.exe `}
    ;===================================================================================================================================================================================
    VULNERABILITIES
    Id Severity Description `}
    ;=========================================================================================================================================================================================================================================
  • edited January 2009
    Open Notepad again, and copy and paste the following:
    Folder::
    c:\temp\fleok
    c:\windows\system32\wsxsvc
    c:\windows\system32\vmss
    C:\Program Files\iWin.com Games\
    
    

    Save this as CFScript3.txt, in the same location as ComboFix.exe which is on the Desktop.

    CFScript.gif
    Refering to the picture above, drag CFScript.txt into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt
    Please copy and paste the ComboFix.txt in your next reply please.

    *Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*
    \



    How's your PC running now?
  • edited January 2009
    Hi,

    Performed the scan and am posting the ComboFix log below. The PC appears to be running a little quicker, but maybe I just want to believe that it is. Need a little time to tell. However, I've encountered a few things since starting all these scans, et al. For example:

    (1) I have two (paid for) games that now no longer run. When I checked them out, I see that they have an extension of ".vir" rather than the typical "exe". The Combo logs indicate that both these games were worked on in the logs. Were these games infected? How do I get them back? If I remove the .vir extension and the game gets executed, do I reinfect, or maybe it won't work at all?
    (2) A few directories have been created that I'm not familiar with. Was this part of the cleanup? Can I delete them once I get resolved?
    (3) Does ComboFix reset my restore point or will I have to do that?
    (4) My antivirus is picking up the file "Tool-NirCmd" as a PUP and it wants me to respond to remove, ignore or quarantine. I researched this file and apparently its part of ComboFix? How should I respond to McAfee's question?

    Combo Log follows:
    ComboFix 09-01-05.01 - Owner 2009-01-08 13:37:24.4 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.221 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Owner\Desktop\CFScript3.txt
    AV: McAfee VirusScan *On-access scanning disabled* (Updated)
    FW: McAfee Personal Firewall *enabled*
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\iWin.com Games\
    c:\program files\iWin.com Games\\Mysteryville\BASS.DLL
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back01.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back02.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back03.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back04.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back05.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back06.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back07.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back08.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\backs\back09.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\effects\click.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\effect01.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\effect02.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\endtime1.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\fieldeffect.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\gametip.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\gametip2.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\gametipclick.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\levelc.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\miss.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\ring1.par
    c:\program files\iWin.com Games\\Mysteryville\data\effects\timebegin.par
    c:\program files\iWin.com Games\\Mysteryville\data\font.dat
    c:\program files\iWin.com Games\\Mysteryville\data\jpeg.dat
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage01\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage01\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage02\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage02\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage03\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage03\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage04\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage04\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage05\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage05\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage06\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage06\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage07\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage07\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage08\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage08\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage09\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage09\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage10\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage10\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage11\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage11\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage12\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage12\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage13\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage13\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage14\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage14\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage15\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage15\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage16\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage16\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage17\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage17\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage18\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage18\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage19\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage19\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage20\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage20\level_02.lev
    c:\program files\iWin.com Games\\Mysteryville\data\levels\stage21\level_01.lev
    c:\program files\iWin.com Games\\Mysteryville\data\loadbar.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\loadscreen.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\map_mask.dat
    c:\program files\iWin.com Games\\Mysteryville\data\music\dialog1.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\music\dialog2.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\music\dialog3.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\music\music1.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\music\music2.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\music\music3.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\music\music4.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\objects\objects.dat
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_badagent.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_barwoman.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_chinee.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_curator.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_fortuneteller.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_ghost.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_goodagent.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_monk.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_pilot.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_professor.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_sheriff.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\settings.txt
    c:\program files\iWin.com Games\\Mysteryville\data\settings\hiscore.dat
    c:\program files\iWin.com Games\\Mysteryville\data\settings\profiles.dat
    c:\program files\iWin.com Games\\Mysteryville\data\settings\records.dat
    c:\program files\iWin.com Games\\Mysteryville\data\settings\settings.dat
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\chpok1.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\defeat.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\find.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\levelcomplete.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\menu.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\menu2.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\miss_full.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\miss_one.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\timeup.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\tip_full.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\sounds\tip_use.ogg
    c:\program files\iWin.com Games\\Mysteryville\data\splash1.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\splash2.jpg
    c:\program files\iWin.com Games\\Mysteryville\data\targa.dat
    c:\program files\iWin.com Games\\Mysteryville\data\texts.dat
    c:\program files\iWin.com Games\\Mysteryville\data\txt\1\classicnames.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\1\comics.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\1\credits.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\1\menutext.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\1\persdesc.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\1\strings.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\1\tips.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\2\classicnames.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\2\comics.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\2\credits.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\2\menutext.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\2\persdesc.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\2\strings.txt
    c:\program files\iWin.com Games\\Mysteryville\data\txt\2\tips.txt
    c:\program files\iWin.com Games\\Mysteryville\iWinGamesSetupR.exe
    c:\program files\iWin.com Games\\Mysteryville\mysteryville.exe
    c:\program files\iWin.com Games\\Mysteryville\Uninstall.exe
    c:\temp\fleok
    c:\windows\system32\wsxsvc
    c:\windows\system32\wsxsvc\License.txt
    c:\windows\system32\wsxsvc\uninstall.html

    .
    ((((((((((((((((((((((((( Files Created from 2008-12-08 to 2009-01-08 )))))))))))))))))))))))))))))))
    .

    2009-01-06 19:03 . 2009-01-06 19:03 <DIR> d
    c:\documents and settings\All Users\Application Data\SpecialBit
    2009-01-04 13:22 . 2009-01-04 13:22 <DIR> d
    c:\program files\Trend Micro
    2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d
    c:\program files\Panda Security
    2009-01-03 17:50 . 2008-06-19 17:24 28,544 --a
    c:\windows\SYSTEM32\drivers\pavboot.sys
    2009-01-03 17:12 . 2009-01-03 17:13 <DIR> d
    c:\program files\Haunted Hotel II - Believe the Lies
    2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
    c:\documents and settings\Owner\Application Data\blg
    2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
    c:\documents and settings\All Users\Application Data\blg
    2008-12-29 20:26 . 2008-12-29 20:26 <DIR> d
    c:\documents and settings\Owner\Freeze Tag - Dream Machine
    2008-12-29 16:42 . 2008-12-29 16:44 <DIR> d
    c:\program files\Mystery in London
    2008-12-27 19:52 . 2008-12-27 19:52 <DIR> d
    c:\documents and settings\Owner\Application Data\Cat's Eye Games
    2008-12-27 19:44 . 2008-12-27 19:44 <DIR> d
    c:\documents and settings\All Users\Application Data\Arkadium
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\Suspects and Clues Prefs
    2008-12-27 19:26 . 2008-12-27 19:27 <DIR> d
    c:\documents and settings\Owner\Application Data\Suspects and Clues Players
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\Spinapse
    2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
    c:\documents and settings\Owner\Application Data\IOMediaSupport6SZZ001s
    2008-12-27 15:27 . 2008-12-27 15:28 <DIR> d
    c:\program files\Suspects and Clues
    2008-12-27 09:15 . 2008-12-27 09:15 <DIR> d
    c:\documents and settings\All Users\Application Data\SiteAdvisor
    2008-12-27 09:15 . 2009-01-08 08:41 7,113 --a
    c:\windows\SYSTEM32\Config.MPF
    2008-12-27 09:10 . 2007-11-22 06:44 201,320 --a
    c:\windows\SYSTEM32\drivers\mfehidk.sys
    2008-12-27 09:10 . 2007-07-13 06:20 113,952 --a
    c:\windows\SYSTEM32\drivers\Mpfp.sys
    2008-12-27 09:10 . 2007-11-22 06:44 79,304 --a
    c:\windows\SYSTEM32\drivers\mfeavfk.sys
    2008-12-27 09:10 . 2007-12-02 12:51 40,488 --a
    c:\windows\SYSTEM32\drivers\mfesmfk.sys
    2008-12-27 09:10 . 2007-11-22 06:44 35,240 --a
    c:\windows\SYSTEM32\drivers\mfebopk.sys
    2008-12-27 09:10 . 2007-11-22 06:44 33,832 --a
    c:\windows\SYSTEM32\drivers\mferkdk.sys
    2008-12-27 09:09 . 2008-12-27 09:09 <DIR> d
    c:\program files\McAfee.com
    2008-12-27 09:08 . 2008-12-27 09:14 <DIR> d
    c:\program files\McAfee
    2008-12-27 09:08 . 2008-12-27 09:10 <DIR> d
    c:\program files\Common Files\McAfee
    2008-12-26 20:19 . 2008-12-27 09:15 <DIR> d
    c:\documents and settings\All Users\Application Data\McAfee
    2008-12-24 16:01 . 2009-01-05 19:04 <DIR> d
    c:\program files\Mystery Case Files - Return to Ravenhearst
    2008-12-20 20:18 . 2006-10-22 12:22 208,896 --a
    c:\windows\SYSTEM32\nvudisp.exe
    2008-12-20 20:18 . 2009-01-08 08:38 88,566 --a
    c:\windows\SYSTEM32\nvapps.xml
    2008-12-20 20:18 . 2006-10-22 12:22 17,056 --a
    c:\windows\SYSTEM32\nvdisp.nvu
    2008-12-20 20:17 . 2008-12-20 20:17 <DIR> d
    C:\NVIDIA
    2008-12-20 20:17 . 2006-10-22 15:06 208,896 --a
    c:\windows\SYSTEM32\NVUNINST.EXE
    2008-12-20 20:14 . 2008-12-20 20:14 <DIR> d
    c:\program files\SystemRequirementsLab
    2008-12-20 19:56 . 2008-05-30 14:11 3,850,760 --a
    c:\windows\SYSTEM32\D3DX9_38.dll
    2008-12-20 19:55 . 2005-05-26 15:34 2,297,552 --a
    c:\windows\SYSTEM32\d3dx9_26.dll
    2008-12-20 19:49 . 2008-12-20 19:49 <DIR> d
    c:\windows\Logs
    2008-12-20 18:55 . 2008-12-20 18:55 <DIR> d
    c:\documents and settings\All Users\Application Data\AdventureChronicles1
    2008-12-20 18:35 . 2008-12-20 18:35 <DIR> d
    c:\documents and settings\All Users\Application Data\PlayPond
    2008-12-12 19:25 . 2008-12-12 19:25 <DIR> d
    c:\program files\Caere

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-08 16:31
    d
    w c:\documents and settings\All Users\Application Data\Google Updater
    2009-01-08 13:38
    d
    w c:\program files\lg_fwupdate
    2009-01-08 01:14
    d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-01-08 01:13
    d
    w c:\program files\SpywareBlaster
    2009-01-07 00:32
    d
    w c:\documents and settings\All Users\Application Data\Sandlot Games
    2009-01-06 01:53
    d
    w c:\documents and settings\All Users\Application Data\BigFishGamesCache
    2008-12-21 23:52
    d
    w c:\program files\Google
    2008-12-21 18:27
    d
    w c:\documents and settings\LocalService\Application Data\SACore
    2008-12-13 06:40 3,593,216
    w c:\windows\SYSTEM32\dllcache\mshtml.dll
    2008-12-13 00:43
    d
    w c:\program files\RealArcade
    2008-12-10 21:42
    d
    w c:\program files\Val`Gor
    2008-12-10 21:00
    d
    w c:\documents and settings\Owner\Application Data\Games
    2008-12-05 23:28
    d
    w c:\documents and settings\Owner\Application Data\PlayFirst
    2008-12-05 23:28
    d
    w c:\documents and settings\All Users\Application Data\PlayFirst
    2008-12-03 23:48
    d
    w c:\documents and settings\All Users\Application Data\NeptunesAdve
    2008-12-03 23:26
    d
    w c:\documents and settings\Owner\Application Data\Shape games
    2008-12-03 21:15
    d
    w c:\documents and settings\Owner\Application Data\MysteryStudio
    2008-12-03 00:28
    d
    w c:\documents and settings\All Users\Application Data\Alawar Stargaze
    2008-11-25 00:10
    d
    w c:\program files\Escape The Museum
    2008-11-23 19:30
    d
    w c:\documents and settings\Owner\Application Data\Gold Casual Games
    2008-11-23 19:30
    d
    w c:\documents and settings\All Users\Application Data\Gold Casual Games
    2008-11-23 16:28
    d
    w c:\program files\Spybot - Search & Destroy
    2008-11-21 20:59
    d
    w c:\documents and settings\Owner\Application Data\Gogii Games
    2008-11-21 20:59
    d
    w c:\documents and settings\All Users\Application Data\Gogii Games
    2008-11-18 21:36
    d
    w c:\documents and settings\Owner\Application Data\Artogon
    2008-11-17 01:17
    d
    w c:\documents and settings\Owner\Application Data\cerasus.media
    2008-10-27 15:04 70,992 ----a-w c:\windows\SYSTEM32\XAPOFX1_2.dll
    2008-10-27 15:04 514,384 ----a-w c:\windows\SYSTEM32\XAudio2_3.dll
    2008-10-27 15:04 235,856 ----a-w c:\windows\SYSTEM32\xactengine3_3.dll
    2008-10-27 15:04 23,376 ----a-w c:\windows\SYSTEM32\X3DAudio1_5.dll
    2008-10-24 11:21 455,296
    w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
    2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
    2008-10-23 12:36 286,720
    w c:\windows\SYSTEM32\dllcache\gdi32.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\dllcache\cdm.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
    2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
    2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
    2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\dllcache\wups.dll
    2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
    2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
    2008-10-16 13:11 70,656
    w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
    2008-10-16 13:11 13,824
    w c:\windows\SYSTEM32\dllcache\ieudinit.exe
    2008-10-15 16:34 337,408
    w c:\windows\SYSTEM32\dllcache\netapi32.dll
    2008-10-15 07:06 633,632
    w c:\windows\SYSTEM32\dllcache\iexplore.exe
    2008-10-15 07:04 161,792
    w c:\windows\SYSTEM32\dllcache\ieakui.dll
    2008-10-10 09:52 452,440 ----a-w c:\windows\SYSTEM32\d3dx10_40.dll
    2008-10-10 09:52 4,379,984 ----a-w c:\windows\SYSTEM32\D3DX9_40.dll
    2008-10-10 09:52 2,036,576 ----a-w c:\windows\SYSTEM32\D3DCompiler_40.dll
    2008-07-08 02:12 774,144 -c--a-w c:\program files\RngInterstitial.dll
    2008-02-26 19:53 0 -c--a-w c:\program files\temp01
    2006-06-16 00:24 308 -c--a-w c:\documents and settings\Owner\Application Data\bbbconfig.dat
    2005-03-28 16:42 284 -c--a-w c:\documents and settings\Owner\Application Data\ViewerApp.dat
    2002-05-20 12:19 61,440 -c--a-w c:\windows\INF\i386\onetUSD.dll
    2002-05-16 12:22 36,864 -c--a-w c:\windows\INF\i386\Vizmicro.dll
    2002-05-16 12:21 286,720 -c--a-w c:\windows\INF\i386\rtscan.dll
    2002-05-16 12:20 172,032 -c--a-w c:\windows\INF\i386\viceo.dll
    2001-08-03 22:29 13,824 -c--a-w c:\windows\INF\i386\Usbscan.sys
    1998-12-09 02:53 99,840 -c--a-w c:\program files\Common Files\IRAABOUT.DLL
    1998-12-09 02:53 70,144 -c--a-w c:\program files\Common Files\IRAMDMTR.DLL
    1998-12-09 02:53 48,640 -c--a-w c:\program files\Common Files\IRALPTTR.DLL
    1998-12-09 02:53 31,744 -c--a-w c:\program files\Common Files\IRAWEBTR.DLL
    1998-12-09 02:53 186,368 -c--a-w c:\program files\Common Files\IRAREG.DLL
    1998-12-09 02:53 17,920 -c--a-w c:\program files\Common Files\IRASRIAL.DLL
    2007-09-16 06:35 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
    2007-09-16 06:35 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
    2007-09-16 06:35 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
    2007-09-16 06:35 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
    2007-09-16 06:35 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
    2008-08-26 16:52 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082620080827\index.dat
    .

    ((((((((((((((((((((((((((((( snapshot@2009-01-05_10.43.09.82 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
    + 2009-01-08 18:34:24 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
    - 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    + 2009-01-08 18:34:24 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
    "PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~2\PSFree.exe" [2005-03-17 536576]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
    "KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
    "IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
    "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
    "PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
    "HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-04 196608]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
    "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
    "LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-07-08 249856]
    "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
    "SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
    "InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
    "Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
    "DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-10-02 94208]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "S3TRAY2"="S3tray2.exe" [2001-10-04 c:\windows\SYSTEM32\S3tray2.exe]
    "nwiz"="nwiz.exe" [2006-10-22 c:\windows\SYSTEM32\nwiz.exe]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-13 805392]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.I420"= vdrcodec.dll
    "VIDC.DVSD"= miroDV2avi.DLL
    "VIDC.PIM1"= pclepim1.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=&quot;"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
    backup=c:\windows\pss\hp center UI.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
    backup=c:\windows\pss\hp center.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
    backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a
    2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCActiveMenu]
    2001-10-02 22:23 94208 c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCM]
    c--- 2001-10-02 22:21 155648 c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
    c--- 2001-07-25 13:00 184376 c:\program files\Microsoft Money\System\Money Express.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --a
    2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
    --a
    1999-10-14 11:50 53248 c:\program files\Caere\OmniPagePro10.0\OPware32.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
    --a
    2002-05-20 07:17 86016 c:\program files\Visioneer OneTouch\OneTouchMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

    R0 pavboot;pavboot;c:\windows\SYSTEM32\drivers\pavboot.sys [2009-01-03 28544]
    R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-27 203280]
    S4 0040461230474749mcinstcleanup;McAfee Application Installer Cleanup (0040461230474749);c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - InCDrec

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-27 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

    2008-12-27 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Search_URL = hxxp://srch-us4.hpwis.com/
    mSearch Bar = hxxp://srch-us4.hpwis.com/
    uInternet Settings,ProxyOverride = localhost
    Trusted Zone: *.internet
    Trusted Zone: *.mcafee.com

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

    c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
    hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    c:\windows\Downloaded Program Files\sysreqlab.osd
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-08 13:44:10
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    **************************************************************************
    .
    DLLs Loaded Under Running Processes

    - - - - - - - > 'winlogon.exe'(672)
    c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    c:\program files\common files\logishrd\bluetooth\LBTServ.dll
    .
    Completion time: 2009-01-08 13:48:33
    ComboFix-quarantined-files.txt 2009-01-08 18:47:15
    ComboFix2.txt 2009-01-07 15:40:15
    ComboFix3.txt 2009-01-06 15:01:40
    ComboFix4.txt 2009-01-05 15:45:37

    Pre-Run: 83,663,224,832 bytes free
    Post-Run: 83,605,852,160 bytes free

    405 --- E O F --- 2008-12-18 21:59:33
  • edited January 2009
    (1) I have two (paid for) games that now no longer run. When I checked them out, I see that they have an extension of ".vir" rather than the typical "exe". The Combo logs indicate that both these games were worked on in the logs. Were these games infected? How do I get them back? If I remove the .vir extension and the game gets executed, do I reinfect, or maybe it won't work at all?
    As you can see, they are in the quarantine folder of CombFix.
    They were detected by Panda ActiveScan as being spyware. However, if you would like to get them back, you can simply move those files back, and change the extension back to .exe.
    (2) A few directories have been created that I'm not familiar with. Was this part of the cleanup? Can I delete them once I get resolved?
    (3) Does ComboFix reset my restore point or will I have to do that?
    After we are done with our work here, I will direct you to cleanup the tools that we have used during the fix. ComboFix creates a new System Restore point when it is run. So after everything is done here, you will need to go to System Restore and flush your Restore points.
    (4) My antivirus is picking up the file "Tool-NirCmd" as a PUP and it wants me to respond to remove, ignore or quarantine. I researched this file and apparently its part of ComboFix? How should I respond to McAfee's question?
    Yes it is part of ComboFix. You can choose the ignore option as ComboFix is a legitimate tool.



    Run your computer for a couple of days, and let me know if any issues remain. Then I'll direct you to clean up all the tools.
  • edited January 2009
    Hey Chiaz!
    OK. Will run PC couple of days and will report back to you on Sunday. FYI: Did a Spybot scan today and found "Virtumonde". I fixed it and hope this helps too. Will talk on Sunday. Thanks!
  • edited January 2009
    chiaz wrote:
    As you can see, they are in the quarantine folder of CombFix.
    They were detected by Panda ActiveScan as being spyware. However, if you would like to get them back, you can simply move those files back, and change the extension back to .exe.


    After we are done with our work here, I will direct you to cleanup the tools that we have used during the fix. ComboFix creates a new System Restore point when it is run. So after everything is done here, you will need to go to System Restore and flush your Restore points.


    Yes it is part of ComboFix. You can choose the ignore option as ComboFix is a legitimate tool.



    Run your computer for a couple of days, and let me know if any issues remain. Then I'll direct you to clean up all the tools.

    Hi Chiaz,
    I have run the PC for a couple of days and I see a slight improvement. It's not as fast as it was , but it seems better. Per my last text to you, Spybot found Virtumonde, which was removed and that may have caused some of the slowness too? Not totally convinced that something is still not lurking, but.............

    If, based on my logs, you feel I'm good to go then I guess we can move forward and remove the tools and do a new system restore point (could use help on these). I'm pretty sure some additional memory wouldn't hurt either.\

    What do you think?

    Thanks, Gail
  • edited January 2009
    I'm pretty convinced that whatever was detected by Spybot S&D is a harmless remnant. ComboFix is a tool designed to remove infections like Virtumonde.


    This will clear away any of the files and folders that were created by ComboFix.

    Go to :
    Start > Run then copy and paste the following highlighted text below and click OK.

    ComboFix /u



    When ComboFix receives such an instruction, it will do the following:

    a) Deletes the following files/folders:
    * ComboFix.exe
    * %system%\swxcacls.exe
    * %system%\swsc.exe
    * %system%\VFind.exe
    * %system%\moveex.exe
    * %system%\swreg.exe
    * %systemroot%\catchme.exe
    * \ComboFix
    * \Qoobox
    * \VundoFix Backups
    * \Deckard
    * \_OTMoveIt
    * %systemroot%\erdnt\subs
    b) Resets the clock settings.
    c) Hides file extensions
    d) Hides System/Hidden files
    e) Clears System Restore cache and create new Restore point
  • edited January 2009
    chiaz wrote:
    I'm pretty convinced that whatever was detected by Spybot S&D is a harmless remnant. ComboFix is a tool designed to remove infections like Virtumonde.


    This will clear away any of the files and folders that were created by ComboFix.

    Go to :
    Start > Run then copy and paste the following highlighted text below and click OK.
    Morning Chiaz,

    Performed the above procedure, but I see a c:\Combofix folder with three files (badclsid, clsid and nircmd) still present. Should I manually delete these files? ALSO, wanted your opinion on keeping SpyBots Teatimer as a resident file. It seems to really slow down the PC during startup. Any thoughts?



    When ComboFix receives such an instruction, it will do the following:

    a) Deletes the following files/folders:
    * ComboFix.exe
    * %system%\swxcacls.exe
    * %system%\swsc.exe
    * %system%\VFind.exe
    * %system%\moveex.exe
    * %system%\swreg.exe
    * %systemroot%\catchme.exe
    * \ComboFix
    * \Qoobox
    * \VundoFix Backups
    * \Deckard
    * \_OTMoveIt
    * %systemroot%\erdnt\subs
    b) Resets the clock settings.
    c) Hides file extensions
    d) Hides System/Hidden files
    e) Clears System Restore cache and create new Restore point
  • edited January 2009
    Yes, just delete the Combofix folder if it's still there.

    TeaTimer can sometimes take up lots of resources. If it's bugging you, then I will say disable the feature. I really see no need on having an anti-spyware real-time protection, just have your anti-virus program on whenever you are connected to the internet. Do keep one or two anti-spyware programs on your computer, keep them updated and run a scan with them occasionally.
  • edited January 2009
    Hey Chiaz!

    Just wanted to thank you so much for all your time and assistance. I don't know what we would do without you and others at Icrontic. Thanks again and have a happy and healthy new year! Gail
  • edited January 2009
    Glad we could be of assistance! The help you received here was free.

    This topic is now closed. If you wish it reopened, please send a Private Message to Trogan with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead :)
    _______________________________

    Have we helped you with any issues you have had with your PCs or other items? If so, you can now help us by Joining Team 93 and fold for a cure.
Sign In or Register to comment.