Hello Bruce,
Thank you for the details and instructions! I followed them and my logs are below. My computer is running much faster now and my Norton does not detect the virus anymore.
Thank you so much for your help!
Combofix
ComboFix 09-03-06.02 - HP_Administrator 2009-03-08 18:52:39.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.313 [GMT -5:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFscript.txt
AV: Norton AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\documents and settings\HP_Administrator\Incomplete\preview-t5745425-smell money syles p.mp3
c:\documents and settings\HP_Administrator\Incomplete\preview-t5745425-the game - red magic (ft. lil wayne).mp3
c:\documents and settings\HP_Administrator\Incomplete\t-5745425-the game - red magic (ft. lil wayne).mp3
c:\documents and settings\HP_Administrator\Shared\avant - message in a bottle.mp3
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Administrator\Application Data\Azureus
c:\documents and settings\HP_Administrator\Application Data\Azureus\.certs
c:\documents and settings\HP_Administrator\Application Data\Azureus\.keystore
c:\documents and settings\HP_Administrator\Application Data\Azureus\.lock
c:\documents and settings\HP_Administrator\Application Data\Azureus\active\587329B329A611D8A5262A237B284CA82BC8183F.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\active\587329B329A611D8A5262A237B284CA82BC8183F.dat.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\active\5E15EEAC08C739F29E411B78D10447DD96E12009.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\active\5E15EEAC08C739F29E411B78D10447DD96E12009.dat.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\active\cache.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\azureus.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\azureus.config.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\azureus.statistics
c:\documents and settings\HP_Administrator\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\dht\general.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\dht\version.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\downloads.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\downloads.config.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\friends.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\ipfilter.cache
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\clientid_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\MetaSearch_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\MetaSearch_Engine_3.txt
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_alerts_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_AutoSpeedSearchHistory_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_clientid_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_debug_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_Friends_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_MetaSearch_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_MetaSearch_Engine_3.txt
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_NetStatus_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_seltrace_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_Subscriptions_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_thread_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_thread_2.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_v3.ads_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_v3.CMsgr_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_v3.emp_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_v3.Friends_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_v3.MD_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_v3.PMsgr_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_v3.PMsgr_2.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\save\1232837873941_v3.Stream_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\Subscriptions_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\thread_2.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\v3.ads_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\v3.CMsgr_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\v3.emp_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\v3.Friends_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\v3.MD_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\v3.PMsgr_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\v3.PMsgr_2.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\logs\v3.Stream_1.log
c:\documents and settings\HP_Administrator\Application Data\Azureus\media\azpd\LBZSTMZJUYI5RJJGFIRXWKCMVAV4QGB7.azpd
c:\documents and settings\HP_Administrator\Application Data\Azureus\media\azpd\LYK65LAIY447FHSBDN4NCBCH3WLOCIAJ.azpd
c:\documents and settings\HP_Administrator\Application Data\Azureus\metasearch.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\metasearch.config.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\net\pm_6478.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\net\pm_default.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\sidebarauto.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\subs\19D197C718E86D5B1B15.vuze
c:\documents and settings\HP_Administrator\Application Data\Azureus\subs\6CE4CD4B41EB765CCBCF.vuze
c:\documents and settings\HP_Administrator\Application Data\Azureus\subs\808C6635290D32689561.vuze
c:\documents and settings\HP_Administrator\Application Data\Azureus\subs\8DE6E5753F5ADF094F49.vuze
c:\documents and settings\HP_Administrator\Application Data\Azureus\subs\95B34C1A1F40931D0972.vuze
c:\documents and settings\HP_Administrator\Application Data\Azureus\subscriptions.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\subscriptions.config.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\tables.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\tables.config.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\timingstats.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5988.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5989.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5990.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5991.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5992.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5993.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5994.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5995.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\tmp\AZU5996.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\torrents\AZU9945.tmp
c:\documents and settings\HP_Administrator\Application Data\Azureus\torrents\Role Models Cast [LYK65LAIY447FHSBDN4NCBCH3WLOCIAJ].torrent
c:\documents and settings\HP_Administrator\Application Data\Azureus\torrents\The Wedding Day [LBZSTMZJUYI5RJJGFIRXWKCMVAV4QGB7].torrent
c:\documents and settings\HP_Administrator\Application Data\Azureus\tracker.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\tracker.config.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\unsentdata.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\unsentdata.config.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\v3.Friends.dat
c:\documents and settings\HP_Administrator\Application Data\Azureus\v3.Friends.dat.bak
c:\documents and settings\HP_Administrator\Application Data\Azureus\VuzeActivities.config
c:\documents and settings\HP_Administrator\Application Data\Azureus\VuzeActivities.config.bak
c:\documents and settings\Mateo\Application Data\LimeWire
c:\documents and settings\Mateo\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Mateo\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Mateo\Application Data\LimeWire\library.dat
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\
01_star.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\
02_star.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\
03_star.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\
04_star.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\
05_star.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\logo.png
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\notsearching.png
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\searching.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Mateo\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\program files\Vuze
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.zip
c:\program files\Vuze\plugins\azemp\azmplay.exe.bak
c:\program files\Vuze\plugins\azemp\cp1250-a.raw.bak
c:\program files\Vuze\plugins\azemp\cp1250-b.raw.bak
c:\program files\Vuze\plugins\azemp\font.desc.bak
c:\program files\Vuze\plugins\azemp\mplayer\config
c:\program files\Vuze\plugins\azemp\osd-mplayer-a.raw.bak
c:\program files\Vuze\plugins\azemp\osd-mplayer-b.raw.bak
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.32
.
((((((((((((((((((((((((( Files Created from 2009-02-08 to 2009-03-08 )))))))))))))))))))))))))))))))
.
2009-03-07 15:30 . 2009-03-07 15:30 <DIR> d-------- c:\windows\LastGood
2009-03-07 15:30 . 2009-02-27 06:02 36,400 -ra------ c:\windows\system32\drivers\SymIM.sys
2009-03-01 06:21 . 2009-03-01 19:17 250 --a------ c:\windows\gmer.ini
2009-03-01 05:09 . 2009-03-01 05:09 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-25 12:46 . 2009-02-25 12:46 <DIR> d-------- c:\documents and settings\Mateo\Application Data\MySpace
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-08 23:42 --------- d-----w c:\program files\WildTangent
2009-03-08 23:42 --------- d-----w c:\program files\HP Games
2009-03-08 23:42 --------- d-----w c:\documents and settings\All Users\Application Data\WildTangent
2009-03-08 23:38 --------- d-----w c:\program files\Viewpoint
2009-03-08 23:38 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\Viewpoint
2009-03-08 23:38 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-03-07 20:29 --------- d-----w c:\program files\OpenOffice.org1.1.5
2009-03-06 03:18 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-06 03:18 7,386 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-06 03:18 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-03-06 03:18 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-06 03:18 --------- d-----w c:\program files\Symantec
2009-03-01 10:32 --------- d-----w c:\program files\Norton Security Scan
2009-03-01 10:09 --------- d-----w c:\program files\Java
2009-02-12 09:05 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-17 03:35 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-01-11 16:58 --------- d-----w c:\program files\JumpStart
2009-01-11 16:58 --------- d-----w c:\documents and settings\All Users\Application Data\Knowledge Adventure
2009-01-11 16:56 --------- d-----w c:\program files\Common Files\Knowledge Adventure
2009-01-11 16:45 --------- d-----w c:\documents and settings\All Users\Application Data\acccore
2009-01-11 16:44 --------- d-----w c:\program files\AIM6
2009-01-11 16:42 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-12-19 09:10 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\dllcache\srv.sys
2007-10-08 20:45 4,788 ----a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-05_19.07.48.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-21 02:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2008-12-05 09:52:09 36,272 ----a-r c:\windows\LastGood\system32\DRIVERS\SymIM.sys
- 2000-08-31 14:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 13:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2000-08-31 14:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 13:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2009-02-27 11:02:23 258,608 ----a-w c:\windows\system32\drivers\NAV\1005000.086\BHDrvx86.sys
+ 2009-03-06 03:17:40 482,352 ----a-w c:\windows\system32\drivers\NAV\1005000.086\cchpx86.sys
+ 2009-02-27 11:02:23 307,760 ----a-w c:\windows\system32\drivers\NAV\1005000.086\srtsp.sys
+ 2009-02-27 11:02:23 43,696 ----a-w c:\windows\system32\drivers\NAV\1005000.086\srtspx.sys
+ 2009-02-27 11:02:23 310,320 ----a-w c:\windows\system32\drivers\NAV\1005000.086\SymEFA.sys
+ 2009-02-27 11:02:23 89,776 ----a-w c:\windows\system32\drivers\NAV\1005000.086\symfw.sys
+ 2009-02-27 11:02:23 34,736 ----a-w c:\windows\system32\drivers\NAV\1005000.086\symids.sys
+ 2009-02-27 11:02:23 37,296 ----a-w c:\windows\system32\drivers\NAV\1005000.086\symndis.sys
+ 2009-02-27 11:02:23 39,984 ----a-w c:\windows\system32\drivers\NAV\1005000.086\symndisv.sys
+ 2009-02-27 11:02:23 217,392 ----a-w c:\windows\system32\drivers\NAV\1005000.086\symtdi.sys
+ 2009-03-07 20:32:28 16,384 ----atw c:\windows\TEMP\Perflib_Perfdata_1400.dat
+ 2009-03-07 20:27:49 16,384 ----atw c:\windows\TEMP\Perflib_Perfdata_5dc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-31 50480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-11 68856]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10a.exe" [2008-10-04 235936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-01 136600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2008-11-25 356352]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
OpenOffice.org 1.1.5.lnk - c:\program files\OpenOffice.org1.1.5\program\quickstart.exe [2005-07-12 61440]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-10-15 385024]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-15 180224]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 16423]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\lxcycoms.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\GameHouse\\Jigsaw\\Jigsaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1005000.086\SymEFA.sys [2009-03-05 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1005000.086\BHDrvx86.sys [2009-03-05 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1005000.086\cchpx86.sys [2009-03-05 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090303.001\IDSxpx86.sys [2009-03-04 276344]
R2 LeapFrog Connect Device Service;LeapFrog Connect Device Service;c:\program files\LeapFrog\LeapFrog Connect\CommandService.exe [2008-11-25 991232]
R2 lxcy_device;lxcy_device;c:\windows\system32\lxcycoms.exe -service --> c:\windows\system32\lxcycoms.exe -service [?]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe [2009-03-05 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-28 101936]
S2 vdo_68c6-6c81;vdo_68c6-6c81;\??\c:\windows\system32\vdo_68c6-6c81.sys --> c:\windows\system32\vdo_68c6-6c81.sys [?]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2008-12-25 18560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2009-03-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-08 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
2009-03-08 c:\windows\Tasks\Norton Security Scan for HP_Administrator.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.myspace.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uInternet Settings,ProxyOverride = *.local
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} - hxxp://clubgames.pogo.com/online2/pogop/mahjong_escape_ancient/PTGameLauncher.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-08 18:55:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1664)
c:\windows\system32\WRLogonNTF.dll
.
Completion time: 2009-03-08 18:57:40
ComboFix-quarantined-files.txt 2009-03-08 23:57:35
ComboFix2.txt 2009-03-06 01:08:54
Pre-Run: 152,791,367,680 bytes free
Post-Run: 152,804,962,304 bytes free
348 --- E O F --- 2009-03-08 09:00:27
Kaspersky
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, March 9, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, March 09, 2009 00:57:06
Records in database: 1881392
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan statistics:
Files scanned: 121222
Threat name: 1
Infected objects: 4
Suspicious objects: 0
Duration of the scan: 02:30:58
File name / Threat name / Threats count
D:\I386\APPS\APP02654\src\CompaqPresario_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 2
D:\I386\APPS\APP02654\src\HPPavillion_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 2
The selected area was scanned.