OTMoveIt2 Log:[Custom Input]
< C:\Windows\system32\msn.exe >
C:\Windows\system32\msn.exe moved successfully.
OTMoveIt2 v1.0.20 log created on 02212008_151009
ComboFix Log:ComboFix 08-02-22 - Jonathan 2008-02-21 15:13:32.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1033.18.297 [GMT -8:00]
Running from: C:\Users\Jonathan\Desktop\ComboFix.exe
* Created a new restore point
.
ADS - system32: deleted 27421 bytes in 2 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.
2008-02-21 15:10 . 2008-02-21 15:10 <DIR> d-------- C:\_OTMoveIt
2008-02-19 09:51 . 2008-02-19 23:49 <DIR> d-------- C:\Users\Jonathan\AppData\Roaming\skypePM
2008-02-19 09:51 . 2008-02-19 09:51 32 --a------ C:\Users\All Users\ezsid.dat
2008-02-19 09:51 . 2008-02-19 09:51 32 --a------ C:\ProgramData\ezsid.dat
2008-02-19 09:49 . 2008-02-19 23:50 <DIR> d-------- C:\Users\Jonathan\AppData\Roaming\Skype
2008-02-19 09:48 . 2008-02-19 09:48 <DIR> d-------- C:\Users\All Users\Skype
2008-02-19 09:48 . 2008-02-19 09:48 <DIR> d-------- C:\ProgramData\Skype
2008-02-19 09:48 . 2008-02-19 23:51 <DIR> d-------- C:\Program Files\Skype
2008-02-19 09:48 . 2008-02-19 09:48 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-02-18 20:36 . 2008-02-18 20:37 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-02-18 20:36 . 2008-02-18 20:37 <DIR> d-------- C:\ProgramData\Lavasoft
2008-02-18 20:36 . 2008-02-18 20:36 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-15 23:03 . 2008-02-18 22:01 <DIR> d-------- C:\Program Files\PSP ISO Compressor
2008-02-15 14:35 . 2008-02-15 14:35 <DIR> d-------- C:\Users\Jonathan\AppData\Roaming\Sonic
2008-02-15 14:35 . 2008-02-15 14:35 <DIR> d-------- C:\Users\Jonathan\AppData\Roaming\Leadertech
2008-02-15 14:34 . 2008-02-18 22:01 <DIR> d-------- C:\Windows\System32\DLA
2008-02-15 14:34 . 2006-07-21 11:21 99,176 --a------ C:\Windows\System32\drivers\DRVMCDB.SYS
2008-02-15 14:34 . 2006-10-26 16:21 92,920 --a------ C:\Windows\DLA.EXE
2008-02-15 14:34 . 2006-10-26 16:21 56,056 --a------ C:\Windows\System32\DLAAPI_W.DLL
2008-02-15 14:34 . 2007-02-09 12:34 51,768 --a------ C:\Windows\System32\drivers\DRVNDDM.SYS
2008-02-15 14:34 . 2007-02-08 20:05 28,120 --a------ C:\Windows\System32\drivers\DLARTL_M.SYS
2008-02-15 14:34 . 2007-02-08 20:05 12,856 --a------ C:\Windows\System32\drivers\DLACDBHM.SYS
2008-02-15 14:34 . 2008-02-15 14:34 120 --a------ C:\Windows\wininit.ini
2008-02-15 14:29 . 2008-02-18 22:01 <DIR> d-------- C:\Users\All Users\InstallShield
2008-02-15 14:29 . 2008-02-18 22:01 <DIR> d-------- C:\ProgramData\InstallShield
2008-02-15 14:23 . 2008-02-15 14:34 <DIR> d-------- C:\Program Files\Roxio
2008-02-15 14:23 . 2008-02-18 22:01 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-02-14 17:03 . 2008-02-14 17:03 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-02-14 14:47 . 2008-02-14 14:47 715,248 --a------ C:\Windows\System32\drivers\sptd.sys
2008-02-12 21:51 . 2007-05-11 00:12 43,520 --a------ C:\Windows\System32\libusb0.dll
2008-02-12 21:51 . 2007-05-11 00:12 28,672 --a------ C:\Windows\System32\drivers\libusb0.sys
2008-02-12 21:17 . 2008-02-12 21:17 <DIR> d-------- C:\Program Files\LibUSB-Win32
2008-02-12 20:22 . 2008-02-12 20:22 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-12 20:22 . 2008-02-12 20:22 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-12 20:16 . 2008-02-12 20:16 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-02-12 20:16 . 2008-02-12 20:16 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe
2008-02-12 20:16 . 2008-02-12 20:16 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-02-12 20:16 . 2008-02-12 20:16 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-02-12 20:16 . 2008-02-12 20:16 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-02-12 20:16 . 2008-02-12 20:16 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-02-12 20:16 . 2008-02-12 20:16 17,464 --a------ C:\Windows\System32\drivers\intelide.sys
2008-02-12 20:15 . 2008-02-12 20:15 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-12 20:15 . 2008-02-12 20:15 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-02-12 20:15 . 2008-02-12 20:15 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-02-12 20:15 . 2008-02-12 20:15 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-02-12 20:15 . 2008-02-12 20:15 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-02-12 20:15 . 2008-02-12 20:15 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-02-12 20:15 . 2008-02-12 20:15 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-02-12 19:57 . 2008-02-12 19:57 1,244,672 --a------ C:\Windows\System32\mcmde.dll
2008-02-10 22:38 . 2008-02-10 23:54 <DIR> d-------- C:\DOSGames
2008-02-10 19:22 . 2007-11-05 05:34 43,528 --------- C:\Windows\System32\drivers\PxHelp20.sys
2008-02-10 14:07 . 2008-02-16 16:57 <DIR> d-------- C:\Program Files\DOSBox-0.72
2008-02-10 13:23 . 2008-02-10 13:23 <DIR> d-------- C:\Program Files\Microsoft Virtual PC
2008-02-08 15:59 . 2008-02-08 15:59 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-02-08 15:55 . 2008-02-18 21:36 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-02-03 00:07 . 2008-02-03 00:07 <DIR> d-------- C:\Program Files\Red Kawa
2008-02-01 08:26 . 2008-02-08 15:51 <DIR> d-------- C:\temp
2008-01-26 21:11 . 2008-01-26 21:11 <DIR> d-------- C:\Program Files\Veoh Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 23:17 0 ----a-w C:\Windows\system32\drivers\lvuvc.hs
2008-02-21 23:13 --------- d-----w C:\Users\Jonathan\AppData\Roaming\.purple
2008-02-21 22:24 --------- d-----w C:\Users\Jonathan\AppData\Roaming\Azureus
2008-02-20 00:54 --------- d-----w C:\Users\Jonathan\AppData\Roaming\Yahoo!
2008-02-20 00:54 --------- d-----w C:\ProgramData\Yahoo!
2008-02-19 06:01 --------- d-----w C:\ProgramData\FLEXnet
2008-02-19 06:01 --------- d-----w C:\Program Files\Free WMA to MP3 Converter
2008-02-19 06:01 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-02-19 06:00 --------- d-----w C:\Program Files\AutoCAD 2007
2008-02-15 22:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-13 18:34 --------- d-----w C:\Users\Jonathan\AppData\Roaming\gtk-2.0
2008-02-13 04:15 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 04:15 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 04:15 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 04:15 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 04:12 --------- d-----w C:\ProgramData\Microsoft Help
2008-02-13 03:59 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-13 03:59 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-13 03:59 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-13 03:59 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-10 21:26 --------- d-----w C:\Users\Jonathan\AppData\Roaming\LimeWire
2008-02-04 05:26 --------- d-----w C:\Program Files\Frets on Fire
2008-01-30 05:16 --------- d-----w C:\ProgramData\Nero
2008-01-30 05:16 --------- d-----w C:\Program Files\Common Files\Nero
2008-01-27 05:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-18 05:15 21,504 ----a-w C:\Windows\jestertb.dll
2008-01-18 02:00 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-17 21:27 --------- d-----w C:\Program Files\Microsoft Works
2008-01-17 21:26 --------- d-----w C:\Program Files\MSBuild
2008-01-17 21:20 --------- d-----w C:\Program Files\Microsoft.NET
2008-01-17 21:15 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-01-16 22:23 --------- d-----w C:\Program Files\Seabyrd Technologies
2008-01-14 16:55 --------- d-----w C:\Program Files\Nero
2008-01-14 08:22 --------- d-----w C:\Program Files\NeroInstall.bak
2008-01-14 07:57 --------- d-----w C:\Users\Jonathan\AppData\Roaming\Nero
2008-01-14 03:16 --------- d-----w C:\ProgramData\Ahead
2008-01-10 02:11 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-10 02:11 --------- d-----w C:\Program Files\Windows Mail
2008-01-10 01:45 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-10 01:45 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-01-10 01:44 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-04 21:44 --------- d-----w C:\Program Files\SCM Microsystems
2008-01-04 21:42 --------- d-----w C:\Program Files\Common Files\ActivIdentity
2008-01-04 21:42 --------- d-----w C:\Program Files\ActivIdentity
2007-12-27 20:42 --------- d-----w C:\Users\Jonathan\AppData\Roaming\SecondLife
2007-12-27 19:43 --------- d-----w C:\Program Files\Google
2007-12-23 06:20 --------- d-----w C:\Program Files\Azureus
2007-12-12 18:55 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-12 18:54 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 18:54 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-11 19:46 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2007-12-11 19:46 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2007-12-11 19:45 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2007-12-11 19:45 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2007-12-11 19:43 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2007-08-29 18:53 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 17:44 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:34 125440]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-01-23 12:23 3497984]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-07-12 20:37 1006264]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-12-12 09:02 98304]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-12-12 09:03 106496]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-12-12 09:02 81920]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 18:06 815104]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"SigmatelSysTrayApp"="sttray.exe" [2007-01-12 09:51 303104 C:\Windows\sttray.exe]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 15:02 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 15:06 2027792]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-16 20:41 28738]
"WebcamMaxMoniter"="C:\Program Files\WebcamMax\wcmmon.exe" [2007-09-15 21:15 450048]
"accrdsub"="C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe" [2007-05-15 16:08 293168]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe" [2007-11-05 05:32 61440]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
ActivClient Agent.lnk - C:\Program Files\ActivIdentity\ActivClient\acsagent.exe [2007-05-15 16:08:00 130864]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-10-12 08:56:59 113664]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe [2006-03-05 04:43:54 11000]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-08-07 15:06:54 24633]
QuickSet.lnk - C:\Windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-07-12 16:05:02 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]
R2 accoca;ActivClient Middleware Service;"C:\Program Files\ActivIdentity\ActivClient\accoca.exe" [2007-05-15 16:08]
R2 CamthWDM;WebcamMax, WDM Video Capture;C:\Windows\system32\DRIVERS\CamthWDM.sys [2007-01-10 21:39]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-12-12 09:49]
R3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-01 23:30]
S3 libusb0;LibUsb-Win32 - Kernel Driver 08/27/2006, 0.1.12.0;C:\Windows\system32\DRIVERS\libusb0.sys [2007-05-11 00:12]
S3 SCR131C;SCRx31 Serial Smart Card Reader;C:\Windows\system32\DRIVERS\SCR131C.sys [2002-11-07 04:04]
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;C:\Windows\system32\DRIVERS\SCR33X2K.sys [2004-04-06 04:24]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;C:\Windows\system32\DRIVERS\SCR3XX2K.sys [2007-10-17 23:11]
S3 UMPass;Microsoft UMPass Driver;C:\Windows\system32\DRIVERS\umpass.sys [2006-11-02 00:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{758abefe-b5ce-11dc-952a-0015c53d2b07}]
\shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DE9ED297-926F-8C6A-6A43-1C42A72DC024}]
C:\Windows\system32:rundl32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F90F0807-EEC0-EF54-B8E4-CD63C00106D0}]
C:\Windows\system32\msn.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-22 15:18:17
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-22 15:19:30
.
2008-02-20 02:41:41 --- E O F ---
HijackThis Log:Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:22:44 PM, on 2/22/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Windows\sttray.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\microsoft shared\Works Shared\WkUFind.exe
C:\Program Files\WebcamMax\wcmmon.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\System32\mobsync.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Jonathan\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [WebcamMaxMoniter] "C:\Program Files\WebcamMax\wcmmon.exe" /a
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: ActivClient Agent.lnk = C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\accoca.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
--
End of file - 8462 bytes
Thanks.