ComboFix 07-08-30.3 - "Asif" 2007-09-02 17:25:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.75 [GMT -5:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Asif\APPLIC~1\FunWebProducts
C:\DOCUME~1\Asif\APPLIC~1\macromedia\Flash Player\#SharedObjects\QA3QW49Q\www.broadcaster.com
C:\DOCUME~1\Asif\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\Asif\err.log
C:\onoes.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\setup.exe
C:\WA6P
C:\WINDOWS\DOWNLO~1\UERT_0001_D19M2109NetInstaller.exe
C:\WINDOWS\DOWNLO~1\UWA6P_0001_N68M2301NetInstaller.exe
C:\WINDOWS\DOWNLO~1\UWA6P_0001_N91M1807NetInstaller.exe
C:\WINDOWS\DOWNLO~1\UWAS6_0001_N91M1508NetInstaller.exe
C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\cyirqvnk.exe
C:\WINDOWS\system32\drsmartload197a.exe
C:\WINDOWS\system32\ghsstetw.exe
C:\WINDOWS\system32\hpiajmmo.dll
C:\WINDOWS\system32\lvplhopj.exe
C:\WINDOWS\system32\mc-110-12-0000482.exe
C:\WINDOWS\system32\ndvmitiu.exe
C:\WINDOWS\system32\ommjaiph.ini
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\pyrsjrkq.dll
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tmp186.tmp.dll
C:\WINDOWS\system32\tmp338.tmp.dll
C:\WINDOWS\system32\tmp50.tmp.dll
C:\WINDOWS\system32\tmp84.tmp.dll
C:\WINDOWS\system32\tmpB0.tmp.dll
C:\WINDOWS\system32\tmpC4.tmp.dll
C:\WINDOWS\system32\tmpDA.tmp.dll
C:\WINDOWS\system32\tmpF2.tmp.dll
C:\WINDOWS\system32\tmpF9.tmp.dll
C:\WINDOWS\system32\tracert.com
C:\WINDOWS\system32\vtusrss.dll
C:\WINDOWS\winlogon.exe
C:\WINDOWS\yaabyy.dll
C:\WINDOWS\yybaay.ini
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_FOPN
-------\LEGACY_VSPF
-------\LEGACY_VSPF_HK
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-08-02 to 2007-09-02 )))))))))))))))))))))))))))))))
2007-09-02 17:23 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-02 17:22 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-01 15:55 <DIR> d-------- C:\Program Files\GoldWave
2007-09-01 14:12 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-09-01 14:11 <DIR> d-------- C:\WINDOWS\system32\athan
2007-09-01 14:11 <DIR> d-------- C:\Program Files\Athan
2007-09-01 13:04 98,304 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\nypqxglc.dll
2007-09-01 13:04 <DIR> d-------- C:\Program Files\Jbuuotlv
2007-09-01 13:04 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Real
2007-09-01 12:16 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB8.sys
2007-09-01 12:16 1,521,464 --a------ C:\WINDOWS\WRSetup.dll
2007-08-31 18:55 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2007-08-31 18:55 21,816 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2007-08-31 18:55 163,128 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2007-08-31 18:55 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
2007-08-31 18:54 <DIR> d-------- C:\Program Files\Webroot
2007-08-31 18:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
2007-08-31 18:53 164 --a------ C:\install.dat
2007-08-31 18:53 <DIR> d-------- C:\DOCUME~1\Asif\APPLIC~1\Webroot
2007-08-31 00:26 9,216 --a------ C:\WINDOWS\system32\ffnd.exe
2007-08-30 16:06 <DIR> d-------- C:\WINDOWS\system32\wowrlegl
2007-08-30 16:05 98,304 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\pudmforw.dll
2007-08-30 16:05 <DIR> d-------- C:\Program Files\Dpkhqjoe
2007-08-29 14:36 1,756,563 --ahs---- C:\WINDOWS\system32\vyadd.bak2
2007-08-28 15:52 6,448 --ahs---- C:\WINDOWS\system32\vyadd.bak1
2007-08-28 15:47 93,696 --a------ C:\WINDOWS\system32\drvmak.dll
2007-08-28 15:47 15,360 --a------ C:\WINDOWS\system32\drvmakr.dll
2007-08-28 15:47 <DIR> d-------- C:\Program Files\xwvebkla
2007-08-26 15:07 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-08-26 15:07 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-08-26 15:02 8,413 --a------ C:\WINDOWS\system32\drivers\mcstrm.sys
2007-08-26 14:17 <DIR> d-------- C:\Program Files\Best Buy Rhapsody
2007-08-25 00:31 <DIR> d-------- C:\DOCUME~1\Asif\APPLIC~1\DivX
2007-08-25 00:30 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2007-08-17 11:57 <DIR> d-------- C:\Program Files\FreeFixer
2007-08-17 11:54 <DIR> d-------- C:\Program Files\Bazooka Scanner
2007-08-16 17:21 3,804 --a------ C:\qiypa.exe
2007-08-13 14:08 <DIR> d-------- C:\Program Files\Qualcomm
2007-08-13 13:57 <DIR> d-------- C:\DOCUME~1\Asif\APPLIC~1\RecordPad
2007-08-13 13:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Swift Sound
2007-08-10 22:47 <DIR> d-------- C:\Program Files\NCH Swift Sound
2007-08-10 22:47 <DIR> d-------- C:\DOCUME~1\Asif\APPLIC~1\NCH Swift Sound
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-31 16:40 --------- d-------- C:\DOCUME~1\Asif\APPLIC~1\LimeWire
2007-08-31 12:54 --------- d-------- C:\Program Files\iTunes
2007-08-28 16:44 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-26 17:58 --------- d-------- C:\Program Files\Real
2007-08-26 17:13 --------- d-------- C:\Program Files\LimeWire
2007-08-26 15:02 --------- d-------- C:\DOCUME~1\Asif\APPLIC~1\Real
2007-08-25 00:30 --------- d-------- C:\Program Files\DivX
2007-08-19 11:31 --------- d-------- C:\DOCUME~1\Asif\APPLIC~1\Yahoo!
2007-08-16 17:21 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-08-11 16:47 --------- d-------- C:\Program Files\Yahoo!
2007-08-11 16:47 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\yahoo!
2007-07-26 20:26 --------- d-------- C:\Program Files\MAIET
2007-07-25 22:06 144704 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-07-25 21:53 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-07-25 21:53 43528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-07-25 21:53 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-25 21:53 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-25 21:53 120056 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2007-07-25 21:53 118520 --a------ C:\WINDOWS\system32\pxinsi64.exe
2007-07-25 21:53 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-25 21:50 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-07-25 21:50 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-07-25 21:50 81920 --a------ C:\WINDOWS\system32\dpl100.dll
2007-07-25 21:50 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-07-25 21:50 740442 --a------ C:\WINDOWS\system32\DivX.dll
2007-07-25 21:50 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-07-25 21:50 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-07-25 21:50 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-07-25 21:50 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-07-25 21:50 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-07-25 21:50 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-07-25 21:50 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-07-25 21:49 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-11 20:07 --------- d-------- C:\Program Files\Incomplete
2007-03-15 21:38 114 --a------ C:\DOCUME~1\Asif\hhjj.bat
2007-03-15 21:37 128 --a------ C:\DOCUME~1\Asif\install.exe
2007-03-15 20:31 32768 --a------ C:\DOCUME~1\Asif\setup9x.exe
2007-02-08 20:57 32768 --a------ C:\DOCUME~1\Asif\stup9x.exe
2007-02-08 20:57 190 --a------ C:\DOCUME~1\Asif\ggg.bat
2007-02-05 16:51 128 --a------ C:\DOCUME~1\Asif\hhhl.exe
2007-02-05 16:50 32768 --a------ C:\DOCUME~1\Asif\setup.exe
2006-03-31 13:40 484560 --a------ C:\DOCUME~1\directx\DXSETUP.exe
2006-03-31 13:40 2248912 --a------ C:\DOCUME~1\directx\dsetup32.dll
2006-03-31 13:39 74448 --a------ C:\DOCUME~1\directx\DSETUP.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39C6B6C8-E01E-3175-B583-04FDA1EE088B}]
2007-09-01 13:04 98304 --a------ C:\Program Files\Jbuuotlv\jqjvzskt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91207231-8B35-4D5D-BD9C-9D7AE87BCF71}]
C:\WINDOWS\system32\ddayv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C666CF63-767F-4831-94AC-E683D962C63C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-05-19 10:30]
"SoundMan"="SOUNDMAN.EXE" [2003-08-05 13:59 C:\WINDOWS\SOUNDMAN.EXE]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-03-18 20:28]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-07-09 13:42]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2005-03-07 15:07]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\McAgent.exe" [2005-03-07 15:05]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 02:56 C:\WINDOWS\system32\rundll32.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 02:56 C:\WINDOWS\system32\rundll32.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-06-01 17:09]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"cbinanmt"="rundll32.exe" [2004-08-04 02:56 C:\WINDOWS\system32\rundll32.exe]
"pudmforw"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\pudmforw.dll" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
"nypqxglc"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\nypqxglc.dll" []
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-07-19 22:54]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-07-16 15:17]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ConfirmFileDelete"=0 (0x0)
"NoDesktopCleanupWizard"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoSharedDocuments"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoInstrumentation"=1 (0x1)
"NoResolveTrack"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoSharedDocuments"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoInstrumentation"=1 (0x1)
"NoResolveTrack"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\comesh]
comesh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddayv]
C:\WINDOWS\system32\ddayv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\ddayyyw.dll
R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINDOWS\system32\Drivers\SSFS0BB8.SYS
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys
R1 oreans32;oreans32;\??\C:\WINDOWS\system32\drivers\oreans32.sys
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys
S3 AIDA32Driver;AIDA32Driver;\??\C:\Documents and Settings\Asif\Desktop\Aida32\aida32.sys
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys
S3 NaiFiltr;NaiFiltr;C:\WINDOWS\system32\DRIVERS\NaiFiltr.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys
S3 VNICPKT5;VNICPKT5 Protocol Driver;\??\C:\WINDOWS\system32\VNICPKT5.SYS
S3 XDva009;XDva009;\??\C:\WINDOWS\system32\XDva009.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService LmHosts upnphost SSDPSRV
*Newly Created Service* - ERSVC
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-09-02 17:42:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-02 17:42:58
C:\ComboFix-quarantined-files.txt ... 2007-09-02 17:42
--- E O F ---
heres my hijacklog
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:44:32 PM, on 9/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://sbc.yahoo.com/dslR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {39C6B6C8-E01E-3175-B583-04FDA1EE088B} - C:\Program Files\Jbuuotlv\jqjvzskt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {91207231-8B35-4D5D-BD9C-9D7AE87BCF71} - C:\WINDOWS\system32\ddayv.dll (file missing)
O2 - BHO: (no name) - {C666CF63-767F-4831-94AC-E683D962C63C} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [AudioDeck] "C:\Program Files\VIAudioi\SBADeck\ADeck.exe" 1
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cbinanmt] "rundll32.exe" "C:\Program Files\xwvebkla\fmpivepq.dll",Init
O4 - HKLM\..\Run: [pudmforw] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\pudmforw.dll"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [nypqxglc] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\nypqxglc.dll"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search -
http://edits.mywebse...html?p=ZJfox000O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O12 - Plugin for .htm: C:\Program Files\\Netscape\\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) -
http://www.mymathtes...GenXInstall.cabO20 - AppInit_DLLs: c:\windows\system32\ddayyyw.dll
O20 - Winlogon Notify: comesh - comesh.dll (file missing)
O20 - Winlogon Notify: ddayv - C:\WINDOWS\system32\ddayv.dll (file missing)
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exe
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) -
http://www.md9-studi...walls/tmac3.jpg--
End of file - 7846 bytes
and the uninstall
Adobe Flash Player ActiveX
Adobe Photoshop 7.0
Adobe Reader 7.0.8
AIM 6
Apple Software Update
Bazooka Scanner
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
EPSON Printer Software
EPSON Scan
Express Burn
FreeFixer
GoldWave v5.20
Google Earth
HijackThis 2.0.2
Hotfix for Windows XP (KB926239)
iPod for Windows 2006-03-23
IrfanView (remove only)
iTunes
J2SE Runtime Environment 5.0 Update 7
LimeWire PRO 4.14.0
Macromedia Shockwave Player
McAfee SecurityCenter
McAfee VirusScan
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Mixman StudioPro (Free Version)
Mozilla ActiveX Control v1.7.12
Mozilla Firefox (2.0.0.6)
MSN Music Assistant
Netscape Browser (remove only)
NVIDIA Drivers
PowerDVD
ProgramChecker
PureVoice
QuickTime
RealPlayer
Realtek AC'97 Audio
RecordPad Sound Recorder
SBC Yahoo! DSL Home Networking Installer
Security Update for Windows Media Player (KB911564)
Sony Picture Utility
Sony USB Driver
Spy Sweeper
Spybot - Search & Destroy 1.4
Switch
Total Control
VIA NICSET
VIA Platform Device Manager
VideoLAN VLC media player 0.8.5
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WavePad Uninstall
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
WinRAR archiver
WinZip
Yahoo! Browser Services
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Toolbar
ZoneAlarm
doesnt seem like they'res any problems now