ComboFix 09-10-25.02 - HP_Administrator 26/10/2009 2:04.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.186 [GMT -4:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Local Settings\Temp\IadHide5.dll
c:\windows\kb913800.exe
c:\windows\system32\AVR09.exe
D:\Autorun.inf
K:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-09-26 to 2009-10-26 )))))))))))))))))))))))))))))))
.
2009-10-26 03:08 . 2009-10-26 03:08 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\HP
2009-10-26 02:08 . 2009-10-26 02:08 5956 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-26 00:17 . 2009-08-22 07:21 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-10-26 00:17 . 2009-10-26 01:19 -------- d-----w- c:\program files\Symantec
2009-10-26 00:17 . 2009-10-26 01:19 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-10-26 00:17 . 2009-10-26 01:19 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-10-26 00:16 . 2009-10-26 02:12 -------- d-----w- c:\windows\system32\drivers\NIS
2009-10-26 00:16 . 2009-10-26 00:16 -------- d-----w- c:\program files\Norton Internet Security
2009-10-26 00:16 . 2009-10-26 00:16 -------- d-----w- c:\program files\Windows Sidebar
2009-10-26 00:16 . 2009-10-26 00:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-10-26 00:13 . 2009-10-26 00:14 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-10-26 00:13 . 2009-10-26 00:13 -------- d-----w- c:\program files\NortonInstaller
2009-10-23 22:21 . 2009-10-23 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Geek Squad
2009-10-22 23:37 . 2009-10-25 01:24 -------- d-----w- c:\program files\apxdui
2009-10-22 23:28 . 2009-10-22 23:28 -------- d-----w- C:\Diskeeper
2009-10-22 07:48 . 2009-10-22 07:48 -------- d-----w- c:\program files\Common Files\Diskeeper Corporation
2009-10-22 07:48 . 2009-10-22 07:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Diskeeper Corporation
2009-10-16 03:48 . 2009-10-16 03:48 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-09-29 10:19 . 2009-09-29 10:19 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-10-26 06:15 . 2009-07-30 03:04 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Skype
2009-10-26 04:03 . 2009-07-30 03:06 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\skypePM
2009-10-26 01:19 . 2009-10-26 00:17 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-10-26 01:19 . 2009-10-26 00:17 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-10-26 01:13 . 2006-05-24 09:29 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-10-26 00:30 . 2009-09-24 17:38 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\HPAppData
2009-10-26 00:03 . 2009-04-26 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-24 03:20 . 2006-05-24 09:01 -------- d-----w- c:\program files\HP Rhapsody
2009-10-18 19:19 . 2009-04-29 00:52 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-10-11 06:33 . 2006-05-24 09:26 -------- d-----w- c:\program files\Google
2009-10-11 05:29 . 2006-05-24 08:31 -------- d-----w- c:\program files\Java
2009-10-05 19:56 . 2009-08-28 04:00 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-03 04:13 . 2009-09-25 23:14 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\HpUpdate
2009-10-02 16:02 . 2009-08-27 23:50 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Creative
2009-09-29 10:19 . 2009-09-24 17:19 147940 ----a-w- c:\windows\hpoins37.dat
2009-09-25 23:14 . 2006-05-24 08:48 -------- d-----w- c:\program files\HP
2009-09-24 17:31 . 2009-09-24 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2009-09-24 17:30 . 2006-05-24 09:08 -------- d-----w- c:\program files\Hewlett-Packard
2009-09-24 17:30 . 2006-05-24 08:52 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-09-24 17:28 . 2009-09-24 17:28 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-09-23 18:28 . 2009-09-23 18:28 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-09-21 02:06 . 2006-05-24 09:00 323376 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-21 02:03 . 2006-05-24 09:10 -------- d-----w- c:\program files\Microsoft Works
2009-09-11 14:18 . 2004-08-10 04:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-10 04:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:36 . 2004-08-10 04:00 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2004-08-10 04:00 78336 ------w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2004-08-10 04:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-28 04:01 . 2009-08-28 04:01 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\muvee Technologies
2009-08-28 00:15 . 2009-08-28 00:15 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Reallusion
2009-08-28 00:15 . 2009-08-28 00:15 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\tmp
2009-08-27 23:55 . 2009-08-27 23:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Creative
2009-08-27 23:48 . 2006-05-24 09:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-27 23:47 . 2009-08-27 23:36 -------- d-----w- c:\program files\Creative
2009-08-27 23:41 . 2006-05-24 09:14 -------- d-----w- c:\program files\muvee Technologies
2009-08-27 23:41 . 2009-08-27 23:41 -------- d-----w- c:\documents and settings\All Users\Application Data\muvee Technologies
2009-08-27 23:39 . 2009-08-27 23:39 81 --sh--r- c:\windows\CT4CET.bin
2009-08-27 23:39 . 2009-08-27 23:39 -------- d-----w- c:\program files\Common Files\Reallusion
2009-08-27 23:38 . 2009-08-27 23:38 -------- d-----w- c:\program files\Common Files\Creative
2009-08-26 08:00 . 2004-08-10 04:00 247326 ------w- c:\windows\system32\strmdll.dll
2009-08-05 09:01 . 2004-08-10 04:00 204800 ------w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2004-08-10 11:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-10 11:00 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-07-30 03:06 . 2009-07-30 03:06 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2006-06-16 00:33 . 2009-08-27 23:39 233472 ----a-w- c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-25 22:43 . 2009-08-27 23:39 204895 ----a-w- c:\program files\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 18:41 . 2009-08-27 23:39 77824 ----a-w- c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll
2006-06-19 17:10 . 2009-08-27 23:39 426081 ----a-w- c:\program files\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 16:19 . 2009-08-27 23:39 458752 ----a-w- c:\program files\mozilla firefox\plugins\imagickrt.dll
2006-04-10 22:35 . 2009-08-27 23:39 139264 ----a-w- c:\program files\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 15:10 . 2009-08-27 23:39 204800 ----a-w- c:\program files\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 15:42 . 2009-08-27 23:39 106496 ----a-w- c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 15:22 . 2009-08-27 23:39 212992 ----a-w- c:\program files\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 15:21 . 2009-08-27 23:39 167936 ----a-w- c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll
2006-09-05 08:19 . 2009-04-26 22:55 22 -csha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-04 25623336]
"Creative Live! Cam Manager"="e:\program files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2007-06-07 155648]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2009-10-11 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"DISCover"="c:\program files\DISC\DISCover.exe" [2006-03-16 1077248]
"DiscUpdateManager"="c:\program files\DISC\DiscUpdMgr.exe" [2006-03-16 61440]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvC heck.exe" [2003-11-10 406016]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"MaxMenuMgr"="e:\freeagent status\StxMenuMgr.exe" [2008-10-28 181544]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-05-16 648504]
"nmapp"="e:\network magic\nmapp.exe" [2008-05-21 451896]
"V0380Mon.exe"="c:\windows\V0380Mon.exe" [2007-08-30 28672]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-10 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2006-05-10 86016]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-03-08 16010240]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" - c:\windows\arpwrmsg.exe [2005-08-03 77312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-10 1519616]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-5-24 27136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-5-24 36903]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP

HCP Discovery Service
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1007020 .00B\SymEFA.sys [25/10/2009 9:19 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1007020.00B \BHDrvx86.sys [25/10/2009 9:19 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1007020.0 0B\cchpx86.sys [25/10/2009 9:18 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091021. 001\IDSXpx86.sys [25/10/2009 8:33 PM 329080]
R2 FreeAgentGoNext Service;Seagate Service;e:\sync\FreeAgentService.exe [28/10/2008 4:42 PM 156968]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe [25/10/2009 9:18 PM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [25/10/2009 4:00 AM 102448]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\system32\drivers\livecamv.sys [27/08/2009 7:38 PM 31616]
S3 V0380Afx;Creative Camera VF0380 Audio Effects Driver;c:\windows\system32\drivers\V0380Afx.sys [27/08/2009 8:10 PM 142656]
S3 V0380Aud;Creative Camera VF0380 Noise Cancellation APO;c:\windows\system32\drivers\V0380Aud.sys [27/08/2009 8:10 PM 94976]
S3 V0380Dev;Creative Camera VF0380 Driver;c:\windows\system32\drivers\V0380Vid.sys [27/08/2009 8:10 PM 274400]
S3 V0380Vfx;Creative Camera VF0380 Video VFX Driver;c:\windows\system32\drivers\V0380Vfx.sys [27/08/2009 8:10 PM 7168]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILI ON&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILI ON&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://free.avg.com/ww.registration-appf8
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\tijz99fr.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://ca.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_ca&p=
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn. dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl. dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRLCT4Player.dll
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-LaunchList - c:\program files\Pinnacle\Studio 10\LaunchList.exe
HKLM-Run-MRIPEUndo - F:\MRI.exe
HKLM-Run-PCDrProfiler - (no file)
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-10-26 02:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N orton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.7.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4976)
c:\windows\system32\WININET.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\combofix\CF1972.exe
c:\windows\arservice.exe
e:\diskeeper defragmentor\DkService.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\DISC\DiscStreamHub.exe
c:\windows\eHome\ehmsas.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\windows\system\hpsysdrv.exe
c:\program files\Java\jre1.5.0_05\bin\jusched.exe
c:\combofix\PEV.cfxxe
.
************************************************** ************************
.
Completion time: 2009-10-26 2:18 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-26 06:18
Pre-Run: 3,625,746,432 bytes free
Post-Run: 3,589,308,416 bytes free
- - End Of File - - F9197E2C5290BA96F2A5CBD82C13B65D
As for as who fixed it, It was a Future Shop store