ComboFix 08-01-31.1 - Brenda Mayorga 2008-01-30 18:41:35.1 - NTFSx86
Running from: C:\Documents and Settings\Brenda Mayorga\My Documents\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Antonio Escalante Jr\Start Menu\Programs\Startup\ta_start.lnk
C:\Documents and Settings\Brenda Mayorga\Application Data\apphash.dat
C:\temp\brr
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\glbdvpex.ini
C:\WINDOWS\system32\klnmp.ini
C:\WINDOWS\system32\klnmp.ini2
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.
2008-01-30 19:29 . 2008-01-30 19:29 92,736 --a------ C:\WINDOWS\system32\mnupsrpk.dll
2008-01-30 19:29 . 2008-01-30 19:29 87,616 --a------ C:\WINDOWS\system32\plqwttuj.dll
2008-01-30 19:25 . 2008-01-30 19:38 347,641 --ahs---- C:\WINDOWS\system32\klnmp.ini
2008-01-27 22:12 . 2008-01-27 22:17 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-18 02:22 . 2008-01-18 02:22 268 --ah----- C:\sqmdata11.sqm
2008-01-18 02:22 . 2008-01-18 02:22 244 --ah----- C:\sqmnoopt11.sqm
2008-01-05 07:24 . 2008-01-05 07:25 314,704 --------- C:\WINDOWS\system32\pmnlk.dll
2007-12-26 11:17 . 2007-12-26 11:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-26 11:17 . 2007-12-26 11:17 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-10 21:55 . 2007-12-10 21:55 268 --ah----- C:\sqmdata10.sqm
2007-12-10 21:55 . 2007-12-10 21:55 244 --ah----- C:\sqmnoopt10.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 01:29 347,641 --sha-w C:\WINDOWS\system32\klnmp.ini2
2008-01-20 06:54 --------- d-----w C:\Documents and Settings\Brenda Mayorga\Application Data\Image Zone Express
2008-01-13 22:24 --------- d-----w C:\Program Files\SUPERAntiSpyware
2007-12-29 22:13 --------- d-----w C:\Documents and Settings\Brenda Mayorga\Application Data\AdobeUM
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-30 11:38 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-30 05:58 --------- d-----w C:\Program Files\iTunes
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 23:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 23:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 06:13 474,112 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-10-11 06:13 151,040 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-10-11 06:13 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-10-11 06:13 1,054,208 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
2007-10-11 06:13 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ----a-w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ----a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-01-18 02:13 1,876 ----a-w C:\Documents and Settings\Brenda Mayorga\Application Data\wklnhst.dat
2006-07-24 02:26 64,496 ----a-w C:\Documents and Settings\Brenda Mayorga\Application Data\GDIPFONTCACHEV1.DAT
2003-08-05 16:41 53,248 ----a-w C:\WINDOWS\inf\ap561.exe
2002-11-26 21:24 32,768 ----a-w C:\WINDOWS\inf\Remove561.exe
2002-11-22 20:56 118,784 ----a-w C:\WINDOWS\inf\ShowBmp.exe
2002-10-29 23:07 36,864 ----a-w C:\WINDOWS\inf\Setup8a.exe
2002-10-01 19:43 119,798 ----a-w C:\WINDOWS\inf\spca561.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
Please help. :-[ I have some trojan on my laptop that keeps causing an HPProductAssistant Box to pop up and say it’s trying to configure my HPProductAssistant. I then get Error 1706 saying No valid source could be found for product HPProductAssistant. Windows Installer cannot continue. Below is the combofix i ran the day before. Thanks for your help.
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{E8E8960F-8174-4BF9-BFE5-622310C06514}]
2008-01-05 07:25 314704 --------- C:\WINDOWS\system32\pmnlk.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 02:00 15360]
“Yahoo! Pager”=“C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe” [2007-06-11 17:16 4670968]
“SUPERAntiSpyware”=“C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2007-05-23 09:12 1314816]
“MsnMsgr”=“C:\Program Files\MSN Messenger\MsnMsgr.exe” [2007-01-19 11:54 5674352]
“nvwiz.exe”=“nvwiz.exe”