ugh i knew i forgot a tool
here is the combfix logComboFix 08-02.05.3 - Megan Wells 2008-02-09 18:59:59.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.683 [GMT -5:00]
Running from: C:\Documents and Settings\Megan Wells\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ssqro.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Megan Wells\My Documents\CROSOF~1
C:\Program Files\dobe~1
C:\Program Files\dobe~1\?dobe\
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\kernInst.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\SYSTEM32\
000070.exe
C:\WINDOWS\SYSTEM32\
000090.exe
C:\WINDOWS\SYSTEM32\afxucoeu.ini
C:\WINDOWS\SYSTEM32\anaqksac.ini
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\SYSTEM32\nomvsmpr.ini
C:\WINDOWS\SYSTEM32\orqss.ini
C:\WINDOWS\SYSTEM32\orqss.ini2
C:\WINDOWS\system32\RCX3C.tmp
C:\WINDOWS\system32\RCX3D.tmp
C:\WINDOWS\system32\RCX3F.tmp
C:\WINDOWS\system32\RCX40.tmp
C:\WINDOWS\system32\ssqro.dll
C:\WINDOWS\system32\ssqro.exe
----- BITS: Possible infected sites -----
hxxp://80.93.48.74
.
((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.
2008-02-09 17:52 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\xebevexguksu.sys
2008-02-09 17:09 . 2008-02-09 17:51 <DIR> d-------- C:\HJT
2008-02-09 00:50 . 2008-02-09 00:51 <DIR> d-------- C:\autoruns
2008-02-08 00:04 . 2008-02-08 08:02 <DIR> d-------- C:\VundoFix Backups
2008-02-07 21:19 . 2008-02-07 21:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-07 21:17 . 2008-02-09 19:06 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-07 21:17 . 2008-02-07 21:17 <DIR> d-------- C:\Documents and Settings\Megan Wells\Application Data\SUPERAntiSpyware.com
2008-02-07 19:53 . 2007-01-18 07:00 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgArCln.sys
2008-02-07 19:42 . 2008-02-07 19:42 <DIR> d-------- C:\Documents and Settings\Megan Wells\Application Data\Grisoft
2008-02-07 19:31 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2008-02-07 19:30 . 2008-02-07 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-07 00:44 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SDTHOOK.SYS
2008-02-07 00:23 . 2008-02-09 17:57 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2008-02-07 00:23 . 2008-02-09 17:48 30,590 --a------ C:\WINDOWS\SYSTEM32\pavas.ico
2008-02-07 00:23 . 2008-02-09 17:48 2,550 --a------ C:\WINDOWS\SYSTEM32\Uninstall.ico
2008-02-07 00:23 . 2008-02-09 17:48 1,406 --a------ C:\WINDOWS\SYSTEM32\Help.ico
2008-02-07 00:20 . 2008-02-07 00:20 <DIR> d-------- C:\Rustbfix
2008-02-06 22:13 . 2008-02-07 00:05 <DIR> d-------- C:\Documents and Settings\Megan Wells\DoctorWeb
2008-02-06 20:47 . 2008-02-07 20:47 774 --ahs---- C:\WINDOWS\SYSTEM32\rlippixy.ini
2008-02-06 20:24 . 2008-02-09 17:51 <DIR> d-------- C:\Program Files\RcvSystem
2008-02-02 17:47 . 2008-02-08 01:07 15,360 --a------ C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-02-02 15:06 . 2008-02-02 15:06 4,286 --a------ C:\WINDOWS\SYSTEM32\Jamster.ico
2008-02-02 14:41 . 2008-02-06 23:15 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-26 18:33 . 2008-01-26 18:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-26 18:33 . 2008-01-26 18:33 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 00:06 --------- d-----w C:\Program Files\QuickTime
2008-02-10 00:06 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-02-09 22:51 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2008-02-09 22:51 --------- d-----w C:\Program Files\Google
2008-02-09 22:51 --------- d-----w C:\Program Files\Digital Line Detect
2008-02-09 22:51 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-08 02:17 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 06:36 --------- d-----w C:\Program Files\Norton Personal Firewall
2008-02-07 04:17 --------- d-----w C:\Program Files\SymNetDrv
2008-02-07 04:16 --------- d-----w C:\Program Files\Razer
2008-02-07 04:15 --------- d-----w C:\Program Files\iTunes
2008-01-31 01:01 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-28 18:01 --------- d-----w C:\Program Files\Norton SystemWorks
2008-01-25 00:18 --------- d-----w C:\Program Files\Battlefield 2142
2008-01-24 04:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-24 04:30 --------- d-----w C:\Program Files\Electronic Arts
2007-12-22 23:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\WildTangent
2007-12-22 23:03 --------- d-----w C:\Program Files\Dell Games
2007-02-26 20:21 65,408 ----a-w C:\Documents and Settings\Megan Wells\Application Data\GDIPFONTCACHEV1.DAT
2007-02-08 21:00 299,288 ----a-w C:\Program Files\GmailInstaller.exe
2006-02-26 19:43 725,250 ----a-w C:\Program Files\m01as-2.pdf
2006-02-16 15:32 290,692 ----a-w C:\Program Files\fafsaws67c.pdf
2002-10-13 22:38 10,432,544 ----a-w C:\Program Files\rp505enu.exe
2003-02-06 21:21 32 --sha-w C:\WINDOWS\{56A8CA0A-6075-4C30-94B4-35016D39C82A}.dat
2003-02-06 21:21 32 --sha-w C:\WINDOWS\SYSTEM32\{7696D9AE-B9E4-46F3-A949-10C598E99CDD}.dat
.
<pre>
----a-w 58,992 2008-02-07 02:40:25 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
----a-w 58,392 2008-02-07 02:40:23 C:\Program Files\Common Files\Symantec Shared\ccRegVfy .exe
----a-w 270,336 2008-02-07 02:40:21 C:\Program Files\Dell\Support\Alert\bin\DAMon .exe
----a-w 61,440 2008-02-07 02:40:59 C:\Program Files\Dot1XCfg\Dot1XCfg .exe
----a-w 479,232 2008-02-07 02:15:03 C:\Program Files\Google\Gmail Notifier\gnotify .exe
----a-w 68,856 2008-02-07 02:40:48 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w 274,432 2008-02-07 02:40:30 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 1,694,208 2008-02-07 04:01:36 C:\Program Files\Messenger\msmsgs .exe
----a-w 473,928 2008-02-07 02:40:36 C:\Program Files\Microsoft AntiSpyware\gcasServ .exe
----a-w 90,112 2008-02-07 02:40:20 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray .exe
----a-w 147,456 2008-02-07 02:40:35 C:\Program Files\Razer\razerhid .exe
----a-w 1,318,912 2008-02-09 22:02:01 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
----a-w 100,056 2008-02-07 02:14:47 C:\Program Files\SymNetDrv\SNDMon .exe
----a-w 15,360 2008-02-08 06:07:00 C:\WINDOWS\SYSTEM32\ctfmon .exe
----a-w 99,840 2008-02-07 02:40:27 C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_S4I2L1 .EXE
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E60CDC1-5021-02FC-531B-5C00B6C98C9A}]
C:\WINDOWS\system32\mmlexchw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5fd4f6f2-22d7-4942-a76b-10deadba7226}]
C:\WINDOWS\system32\mvcakvie.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm .exe" [ ]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"Ntzfaxzw"="C:\Documents and Settings\Megan Wells\My Documents\??crosoft\spool32.exe" [ ]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\SYSTEM32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 12:22 86016 C:\WINDOWS\SYSTEM32\nvmctray.dll]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [ ]
"4063066a"="C:\WINDOWS\system32\plrsqywl.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2002-09-09 12:15:43 45056]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnkkjk]
pmnkkjk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
--a------ 2002-04-10 16:44 679936 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAZAA]
C:\Program Files\Kazaa\kazaa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaLoads Installer]
C:\Program Files\DownloadWare\dw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
--a------ 2001-07-25 10:00 184376 C:\Program Files\Microsoft Money\System\Money Express.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyStartUp10.0]
--a------ 2001-07-25 10:00 241714 C:\Program Files\Microsoft Money\System\Activation.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PromulGate]
C:\Program Files\DelFin\PromulGate\PgMonitr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2003-06-23 21:16 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaveNow]
C:\Program Files\SaveNow\SaveNow.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
R0 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]
R3 NPDriver;Norton Unerase Protection Driver;C:\WINDOWS\System32\Drivers\NPDRIVER.SYS [2004-08-30 22:38]
S3 Alpham;Ideazon Fang Composite Keyboard Driver;C:\WINDOWS\system32\DRIVERS\Alpham.sys [2005-12-04 13:55]
S3 bcgame;Nostromo HID Device Minidriver;C:\WINDOWS\system32\drivers\bcgame.sys []
S3 cusbohcn;cusbohcn;C:\DOCUME~1\MEGANW~1\LOCALS~1\Temp\cusbohcn.sys []
S3 DVC;USB DVC Svc;C:\WINDOWS\system32\Drivers\DVC.sys [2003-04-01 03:19]
S3 Razerlow;Razerlow USB Filter Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-04-24 21:43]
S3 SDdriver;SDdriver;C:\WINDOWS\System32\Drivers\sddriver.sys [2004-08-30 22:23]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-09 01:26:36 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Megan Wells.job"
- C:\PROGRA~1\NORTON~2\NORTON~1\Navw32.exeh/task:
"2008-01-28 18:01:55 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-02-09 05:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
- C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-09 19:11:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2008-02-09 19:33:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-10 00:33:04
.
2008-01-09 08:02:13 --- E O F ---
here is the new hjt logLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:33:46 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\HJT\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.osu.edu/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4E60CDC1-5021-02FC-531B-5C00B6C98C9A} - C:\WINDOWS\system32\mmlexchw.dll (file missing)
O2 - BHO: {6227abda-ed01-b67a-2494-7d222f6f4df5} - {5fd4f6f2-22d7-4942-a76b-10deadba7226} - C:\WINDOWS\system32\mvcakvie.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\Run: [4063066a] rundll32.exe "C:\WINDOWS\system32\plrsqywl.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm .exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Ntzfaxzw] "C:\Documents and Settings\Megan Wells\My Documents\??crosoft\spool32.exe"
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish....fishActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: pmnkkjk - pmnkkjk.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 8911 bytes
thanks
dawg
Edited by dawg3, 09 February 2008 - 06:24 PM.