process done but majority are still there and now there are more in C:\Qoobox\Quarantine\[4]-Submit_2009-05-24_13.04.50.zip:\DDACLSys3232.dll
(about 32 infected files like this, the other 96 or so are still in system32)
What ever that is and i can't delete them because avg is still telling me the virus valut is full when it is empty. I am really appreciating your help and hoping that we are somewhere near the end, please respond soon. Here is the new log
COMBOFIX LOG attempt number 2
ComboFix 09-05-22.05 - Trampy 24/05/2009 13:07.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.3070.1640 [GMT -7:00]
Running from: c:\users\Trampy\Desktop\ComboFix.exe
Command switches used :: c:\users\Trampy\Desktop\CFScript.txt
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
c:\users\Trampy\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
c:\windows\system32\DDACLSys3232.dll
c:\windows\system32\deploytk3232.dll
c:\windows\system32\deskperf3232.dll
c:\windows\system32\dfrgifps3232.dll
c:\windows\system32\DfsShlEx32.dll
c:\windows\system32\dhcpcmonitor3232.dll
c:\windows\system32\dhcpcsvc63232.dll
c:\windows\system32\diagperf32.dll
c:\windows\system32\difxapi3232.dll
c:\windows\system32\dimsjob32.dll
c:\windows\system32\dimsroam3232.dll
c:\windows\system32\dinput83232.dll
c:\windows\system32\dispci3232.dll
c:\windows\system32\dmcompos3232.dll
c:\windows\system32\dmdskres232.dll
c:\windows\system32\dmdskres23232.dll
c:\windows\system32\dmintf3232.dll
c:\windows\system32\dmscript323232.dll
c:\windows\system32\dmvdsitf32.dll
c:\windows\system32\dmvdsitf3232.dll
c:\windows\system32\dnshc32.dll
c:\windows\system32\dnssd32.dll
c:\windows\system32\dot3gpclnt32.dll
c:\windows\system32\dot3msm32.dll
c:\windows\system32\dot3ui32.dll
c:\windows\system32\dps32.dll
c:\windows\system32\drmmgrtn32.dll
c:\windows\system32\dskquoui32.dll
c:\windows\system32\dsprop32.dll
c:\windows\system32\dwmredir32.dll
.
PEV Error: LocalSettingsFile
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Trampy\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
c:\windows\system32\DDACLSys3232.dll
c:\windows\system32\deploytk3232.dll
c:\windows\system32\deskperf3232.dll
c:\windows\system32\dfrgifps3232.dll
c:\windows\system32\DfsShlEx32.dll
c:\windows\system32\dhcpcmonitor3232.dll
c:\windows\system32\dhcpcsvc63232.dll
c:\windows\system32\diagperf32.dll
c:\windows\system32\difxapi3232.dll
c:\windows\system32\dimsjob32.dll
c:\windows\system32\dimsroam3232.dll
c:\windows\system32\dinput83232.dll
c:\windows\system32\dispci3232.dll
c:\windows\system32\dmcompos3232.dll
c:\windows\system32\dmdskres232.dll
c:\windows\system32\dmdskres23232.dll
c:\windows\system32\dmintf3232.dll
c:\windows\system32\dmscript323232.dll
c:\windows\system32\dmvdsitf32.dll
c:\windows\system32\dmvdsitf3232.dll
c:\windows\system32\dnshc32.dll
c:\windows\system32\dnssd32.dll
c:\windows\system32\dot3gpclnt32.dll
c:\windows\system32\dot3msm32.dll
c:\windows\system32\dot3ui32.dll
c:\windows\system32\dps32.dll
c:\windows\system32\drmmgrtn32.dll
c:\windows\system32\dskquoui32.dll
c:\windows\system32\dsprop32.dll
c:\windows\system32\dwmredir32.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-24 to 2009-05-24 )))))))))))))))))))))))))))))))
.
2009-05-23 09:23 . 2009-05-23 09:23 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-05-23 09:23 . 2009-05-23 09:23 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-05-23 09:22 . 2009-05-23 09:22 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-23 09:22 . 2009-05-24 16:10 -------- d-----w c:\windows\system32\drivers\Avg
2009-05-23 09:22 . 2009-05-23 09:22 27784 ----a-w c:\windows\system32\drivers\avgmfx86.sys
2009-05-23 09:12 . 2009-05-24 07:46 -------- d-----w c:\users\Scott\AppData\Local\temp
2009-05-22 00:12 . 2009-05-06 18:06 4784464 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{68B15C52-6A44-4444-8D37-1F1C45C8AF87}\mpengine.dll
2009-05-20 15:46 . 2009-05-10 03:00 2051864 ----a-w c:\programdata\avg8\update\backup\avgcorex.dll
2009-05-20 15:46 . 2009-05-10 03:00 354584 ----a-w c:\programdata\avg8\update\backup\avgxch32.dll
2009-05-20 15:46 . 2009-05-10 03:00 424472 ----a-w c:\programdata\avg8\update\backup\avgwdwsc.dll
2009-05-20 15:46 . 2009-05-10 02:59 177432 ----a-w c:\programdata\avg8\update\backup\avgmail.dll
2009-05-20 15:46 . 2009-05-10 03:00 3288344 ----a-w c:\programdata\avg8\update\backup\setup.exe
2009-05-20 15:46 . 2009-05-10 02:59 312088 ----a-w c:\programdata\avg8\update\backup\avglngx.dll
2009-05-20 15:46 . 2009-05-10 03:00 486168 ----a-w c:\programdata\avg8\update\backup\avgrsx.exe
2009-05-20 15:46 . 2009-05-10 02:59 755992 ----a-w c:\programdata\avg8\update\backup\avginet.dll
2009-05-20 15:46 . 2009-05-10 02:59 1437464 ----a-w c:\programdata\avg8\update\backup\avgupd.dll
2009-05-14 03:51 . 2009-05-10 03:00 3399960 ----a-w c:\programdata\avg8\update\backup\avgui.exe
2009-05-14 03:51 . 2009-05-10 03:00 2302232 ----a-w c:\programdata\avg8\update\backup\avguiadv.dll
2009-05-10 07:59 . 2008-06-20 01:14 97800 ----a-w c:\windows\system32\infocardapi.dll
2009-05-10 07:59 . 2008-06-20 01:14 43544 ----a-w c:\windows\system32\PresentationHostProxy.dll
2009-05-10 07:59 . 2008-06-20 01:14 105016 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-05-10 07:59 . 2008-06-20 01:14 11264 ----a-w c:\windows\system32\icardres.dll
2009-05-10 07:59 . 2008-06-20 01:14 622080 ----a-w c:\windows\system32\icardagt.exe
2009-05-10 07:59 . 2008-06-20 01:14 781344 ----a-w c:\windows\system32\PresentationNative_v0300.dll
2009-05-10 07:59 . 2008-06-20 01:14 326160 ----a-w c:\windows\system32\PresentationHost.exe
2009-05-10 07:53 . 2008-07-27 18:03 96760 ----a-w c:\windows\system32\dfshim.dll
2009-05-10 07:53 . 2008-07-27 18:03 282112 ----a-w c:\windows\system32\mscoree.dll
2009-05-10 07:53 . 2008-07-27 18:03 41984 ----a-w c:\windows\system32\netfxperf.dll
2009-05-10 07:53 . 2008-07-27 18:03 158720 ----a-w c:\windows\system32\mscorier.dll
2009-05-10 07:52 . 2008-07-27 18:03 83968 ----a-w c:\windows\system32\mscories.dll
2009-05-10 07:09 . 2009-05-10 07:09 -------- d-----w c:\program files\Trend Micro
2009-05-10 07:01 . 2009-05-10 07:01 -------- d-----w c:\program files\CCleaner
2009-05-10 06:49 . 2009-05-10 06:50 -------- d-----w c:\programdata\AOL
2009-05-09 06:28 . 2009-05-09 06:28 680 ----a-w c:\users\Trampy\AppData\Local\d3d9caps.dat
2009-05-08 22:35 . 2009-05-08 22:35 10134 ----a-r c:\users\Trampy\AppData\Roaming\Microsoft\Installer\{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}\ARPPRODUCTICON.exe
2009-05-08 22:33 . 2009-05-08 22:33 -------- d-----w c:\users\Trampy\AppData\Roaming\Avery
2009-05-08 22:18 . 2009-05-08 22:18 -------- d-----w c:\users\Trampy\AppData\Roaming\Yahoo!
2009-05-08 08:15 . 2009-05-08 08:15 -------- d-----w c:\users\Trampy\AppData\Roaming\Malwarebytes
2009-05-08 08:15 . 2009-04-06 22:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-08 08:15 . 2009-04-06 22:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-08 08:15 . 2009-05-08 08:15 -------- d-----w c:\programdata\Malwarebytes
2009-05-08 08:15 . 2009-05-08 08:15 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-07 05:03 . 2009-05-07 05:03 -------- d-----w c:\programdata\SUPERAntiSpyware.com
2009-05-07 05:03 . 2009-05-23 08:25 -------- d-----w c:\users\Trampy\AppData\Roaming\SUPERAntiSpyware.com
2009-05-07 05:03 . 2009-05-23 08:24 -------- d-----w c:\program files\SUPERAntiSpyware
2009-05-06 20:25 . 2009-05-07 03:34 -------- d--h--w C:\$AVG8.VAULT$
2009-05-06 20:23 . 2009-05-06 20:23 139264 ----a-w c:\windows\system32\dmcompos32.dll
2009-05-04 19:46 . 2009-05-04 19:46 -------- d-----w c:\users\Trampy\AppData\Roaming\Shareaza
2009-05-04 19:46 . 2009-05-04 19:46 -------- d-----w c:\users\Trampy\AppData\Local\Shareaza
2009-05-03 09:05 . 2009-05-03 09:05 -------- d-----w c:\program files\Shareaza
2009-05-03 09:05 . 2009-05-03 09:05 -------- d-----w c:\users\Scott\AppData\Roaming\Shareaza
2009-05-03 09:05 . 2009-05-03 09:05 -------- d-----w c:\users\Scott\AppData\Local\Shareaza
2009-05-03 08:41 . 2009-05-03 09:12 -------- d-----w c:\program files\LimeWire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-23 09:22 . 2008-06-07 08:01 -------- d-----w c:\programdata\avg8
2009-05-23 08:24 . 2009-03-04 00:50 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-14 03:50 . 2008-03-22 03:34 27430 ----a-w c:\users\Trampy\AppData\Roaming\nvModes.dat
2009-05-13 10:00 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-05-11 04:39 . 2008-03-26 06:52 -------- d-----w c:\users\Trampy\AppData\Roaming\Skype
2009-05-11 03:06 . 2008-06-14 03:33 -------- d-----w c:\users\Trampy\AppData\Roaming\skypePM
2009-05-10 09:14 . 2008-03-22 02:11 114176 ----a-w c:\users\Trampy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-10 09:09 . 2008-03-22 02:06 -------- d-----w c:\program files\Yahoo!
2009-05-10 08:14 . 2008-03-22 04:20 114176 ----a-w c:\users\Scott\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-10 08:11 . 2007-11-26 05:02 -------- d-----w c:\programdata\Microsoft Help
2009-05-10 06:52 . 2007-11-26 03:22 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-10 06:52 . 2008-03-22 02:00 -------- d-----w c:\program files\Electronic Arts
2009-05-06 23:39 . 2008-03-22 03:56 -------- d-----w c:\users\Trampy\AppData\Roaming\FrostWire
2009-05-06 20:24 . 2009-05-06 20:24 139264 ----a-w c:\windows\system32\d3dx9_313232.dll
2009-05-06 20:23 . 2009-05-06 20:23 139264 ----a-w c:\windows\system32\dispci32.dll
2009-05-03 19:15 . 2008-03-22 04:34 -------- d-----w c:\users\Scott\AppData\Roaming\FrostWire
2009-05-03 09:13 . 2008-03-22 03:56 -------- d-----w c:\program files\FrostWire
2009-05-03 08:58 . 2009-05-03 08:42 -------- d-----w c:\users\Scott\AppData\Roaming\LimeWire
2009-04-19 19:13 . 2008-03-22 19:33 -------- d-----w c:\programdata\DVD Shrink
2009-04-13 05:42 . 2008-04-05 22:07 -------- d-----w c:\users\Trampy\AppData\Roaming\Image Zone Express
2009-04-13 05:36 . 2007-11-26 05:08 -------- d-----w c:\programdata\HP
2009-04-05 19:22 . 2009-04-05 19:22 -------- d-----w c:\program files\TOD 042009
2009-03-29 06:29 . 2009-03-29 06:29 -------- d-----w c:\users\Scott\AppData\Roaming\Vso
2009-03-29 06:29 . 2009-03-29 06:29 47360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-03-29 06:29 . 2009-03-29 06:29 47360 ----a-w c:\users\Scott\AppData\Roaming\pcouffin.sys
2009-03-29 06:29 . 2009-03-29 06:29 47360 ----a-w c:\users\Scott\AppData\Roaming\pcouffin.sys
2009-03-29 06:29 . 2009-03-29 06:28 -------- d-----w c:\program files\DVDFab 5
2009-03-27 07:39 . 2007-11-26 05:37 -------- d-----w c:\program files\Java
2009-03-24 16:39 . 2008-06-13 01:00 139163 ----a-w c:\windows\hpoins15.dat
2009-03-17 03:38 . 2009-04-15 00:42 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 00:42 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-09 12:19 . 2009-01-06 05:27 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2009-05-10 08:05 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-05-10 08:05 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-05-10 08:05 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-05-10 08:05 109056 ----a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-05-10 08:05 109568 ----a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-05-10 08:05 132608 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-05-10 08:05 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-05-10 08:05 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-05-10 08:05 103936 ----a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-05-10 08:05 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-05-10 08:05 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-05-10 08:05 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-05-10 08:05 66560 ----a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-05-10 08:05 169472 ----a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-05-10 08:05 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-05-10 08:05 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-05-10 08:05 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-05-10 08:05 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 18:54 . 2008-03-25 05:48 4718 ----a-w c:\users\Trampy\AppData\Roaming\wklnhst.dat
2009-03-03 04:46 . 2009-04-15 00:42 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 00:42 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-15 00:42 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 00:42 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 00:42 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 00:42 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 00:42 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-15 00:42 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-15 00:42 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 00:42 17408 ----a-w c:\windows\system32\iashost.exe
2008-08-23 20:23 . 2008-08-23 20:23 22 --sha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-05-23_09.10.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-26 03:18 . 2009-05-24 20:14 45968 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-24 20:14 94868 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-03-22 09:49 . 2009-05-22 17:45 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-22 09:49 . 2009-05-23 09:24 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-03-22 09:49 . 2009-05-22 17:45 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-22 09:49 . 2009-05-23 09:24 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-22 09:49 . 2009-05-22 17:45 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-03-22 09:49 . 2009-05-23 09:24 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-03-22 17:32 . 2009-05-21 06:13 5700 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-03-22 17:32 . 2009-05-24 20:11 5700 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-03-22 01:58 . 2009-05-24 20:14 8612 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3414194690-3933354525-3287570163-1000_UserData.bin
- 2009-05-23 08:58 . 2009-05-23 08:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-24 20:12 . 2009-05-24 20:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-06-21 19:32 . 2009-05-24 19:55 468512 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-03-22 02:46 . 2009-05-24 20:11 129960 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-24 455968]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-02 1783136]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-23 1947928]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-10 4390912]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-6-6 967960]
Vongo Tray.lnk - c:\windows\Installer\{8C3AE2D1-854D-4650-A73D-C7CC7EE36B80}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe [2007-11-25 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"<NO NAME>"=
"c:\\Program Files\\Vongo\\VongoService.exe"= c:\program files\Vongo\VongoService.exe:*:enabled:VongoService
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{334D7D46-1D66-4022-9908-87E1DE0A7302}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{BB94DB1A-C77D-4DCA-92AD-54C57CE00BEE}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{024EC2AC-121D-42C7-B3BF-433BBDDF1748}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{7B7D14B1-C7CA-4E65-A56B-B4E6D0B1FF4B}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{547192FF-6A40-4864-9D00-AFECDB174310}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{391B6388-EF39-4888-80F0-848D80BEDBAC}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{F03776F8-FA59-4F49-A87C-38E4C8EA9856}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{83C3586C-66B5-4931-BFDD-44D97CCBE7FF}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A6CFE4D9-FAAA-4D67-8343-52AB596F832C}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A39F5BBE-109E-486E-890C-52083EB71AC6}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{1549E52B-0550-4D8C-B4D8-F2F2E329B029}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{9DCE8ADF-2ADB-48A7-B6C2-40E215C1E407}"= UDP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{37823207-F53D-459C-9145-89EC4EFD9396}"= TCP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{18BBEB1E-B2C8-4BDD-AFA4-398D088275EE}"= Disabled:UDP:c:\users\Scott\AppData\Local\Temp\7zS9DCD.tmp\setup\HPZnui01.exe:hpznui01.exe
"{069B6ECC-8E0D-407F-A5DA-457984E02139}"= Disabled:TCP:c:\users\Scott\AppData\Local\Temp\7zS9DCD.tmp\setup\HPZnui01.exe:hpznui01.exe
"{85259C0D-B7E5-4C74-9244-93EE52C1C830}"= Disabled:UDP:c:\users\Trampy\AppData\Local\Temp\7zS7D98.tmp\setup\HPZnui01.exe:hpznui01.exe
"{41CE7228-B13A-48FA-A9E5-97BA526D78A9}"= Disabled:TCP:c:\users\Trampy\AppData\Local\Temp\7zS7D98.tmp\setup\HPZnui01.exe:hpznui01.exe
"{61EE5DA8-B126-4D58-A1E1-39A0139D5D32}"= Disabled:UDP:c:\users\Trampy\AppData\Local\Temp\7zS7FC9.tmp\setup\HPZnui01.exe:hpznui01.exe
"{C9812562-C151-4011-9FEC-3DD314C5CE9A}"= Disabled:TCP:c:\users\Trampy\AppData\Local\Temp\7zS7FC9.tmp\setup\HPZnui01.exe:hpznui01.exe
"{3A0F950A-CF7D-4A65-AF95-161B767DA018}"= Disabled:UDP:c:\users\Trampy\AppData\Local\Temp\7zSF160.tmp\setup\HPZnui01.exe:hpznui01.exe
"{FAD2E12F-7D82-47E0-83B8-04DE22178A02}"= Disabled:TCP:c:\users\Trampy\AppData\Local\Temp\7zSF160.tmp\setup\HPZnui01.exe:hpznui01.exe
"{08F2A214-F5B0-4B86-AD7C-6633EBEFC297}"= Disabled:UDP:c:\users\Trampy\AppData\Local\Temp\7zS8822.tmp\setup\HPZnui01.exe:hpznui01.exe
"{C390FFF2-A1F0-47A8-A853-8671830BE557}"= Disabled:TCP:c:\users\Trampy\AppData\Local\Temp\7zS8822.tmp\setup\HPZnui01.exe:hpznui01.exe
"{DC731DB9-23FC-4534-AABF-51FE12018A88}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{5D77B784-BAAD-48E3-8C2D-B1286B73032E}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{953E10EA-2A67-487E-A725-CC550BE71468}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{A04F628A-AA4E-408D-8F2F-94DB898D9BD8}"= UDP:c:\program files\HP\Photosmart Essential\UserTrackUtility.exe:Enable HP Product Improvement Data Collection
"{F5FA984C-88E8-4E3F-AECA-202CC0F4C0E4}"= TCP:c:\program files\HP\Photosmart Essential\UserTrackUtility.exe:Enable HP Product Improvement Data Collection
"{41F7482A-5C03-4786-82E6-CF858CD2E281}"= UDP:c:\program files\HP\Digital Imaging\bin\hpqdirec.exe:HP Solution Center
"{F852C74E-73AA-4055-A6C4-361989A3FF45}"= TCP:c:\program files\HP\Digital Imaging\bin\hpqdirec.exe:HP Solution Center
"{C68F2381-8457-4DDF-B64D-326BB3153A2E}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{DC03CD86-D09C-4081-BB36-759C5D5C4C00}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3A597B70-96C8-4BE1-83E4-DF52C2C588CC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{684C5F2F-5777-4148-ABAB-9DEA23B6DA12}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{BF4A58F8-269B-414E-A2E9-7EAFA65BF846}c:\\program files\\shareaza\\shareaza.exe"= UDP:c:\program files\shareaza\shareaza.exe:Shareaza Ultimate File Sharing
"UDP Query User{9B618E5A-FE77-4893-A8A3-23655226787F}c:\\program files\\shareaza\\shareaza.exe"= TCP:c:\program files\shareaza\shareaza.exe:Shareaza Ultimate File Sharing
"{92A16C25-B307-480D-82BE-64EB8E337E60}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{A3D84D6C-5709-43DF-8A70-C1663F53A7F8}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R0 MDFSYSNT;MacDrive file system driver;c:\windows\System32\drivers\MDFSYSNT.SYS [12/02/2008 8:58 AM 279808]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [23/05/2009 2:22 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [23/05/2009 2:23 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [23/05/2009 2:22 AM 298776]
R2 M4iPodWPDService;M4iPodWPDService;c:\program files\Common Files\Mediafour\iPod\M4iPodWPDService.exe [23/01/2008 1:31 PM 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-05-24 c:\windows\Tasks\User_Feed_Synchronization-{B1C2A2BD-0430-464E-B358-34383BAF06DD}.job
- c:\windows\system32\msfeedssync.exe [2009-05-10 11:31]
2009-05-24 c:\windows\Tasks\User_Feed_Synchronization-{FED050BD-772C-4099-AEC5-36373193B218}.job
- c:\windows\system32\msfeedssync.exe [2009-05-10 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-24 13:13
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5920)
c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
c:\program files\Mediafour\XPlay 3\XPCopyHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-05-24 13:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-24 20:22
ComboFix2.txt 2009-05-23 09:12
Pre-Run: 107,391,275,008 bytes free
Post-Run: 107,574,005,760 bytes free
405 --- E O F --- 2009-05-22 00:12