Here's the combofix log:
ComboFix 08-02-25 - Administrator 2008-02-24 18:45:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.34 [GMT -9:00]Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\APPATC~1
C:\Documents and Settings\Administrator\Application Data\ASEMBL~1
C:\Documents and Settings\Administrator\Application Data\ASKS~1
C:\Documents and Settings\Administrator\Application Data\CROSOF~1
C:\Documents and Settings\Administrator\Application Data\CROSOF~1.NET
C:\Documents and Settings\Administrator\Application Data\CURITY~1
C:\Documents and Settings\Administrator\Application Data\DOBE~1
C:\Documents and Settings\Administrator\Application Data\ECURIT~1
C:\Documents and Settings\Administrator\Application Data\FNTS~1
C:\Documents and Settings\Administrator\Application Data\FNTS~2
C:\Documents and Settings\Administrator\Application Data\ICROSO~1
C:\Documents and Settings\Administrator\Application Data\ICROSO~1.NET
C:\Documents and Settings\Administrator\Application Data\MANTEC~1
C:\Documents and Settings\Administrator\Application Data\MBOLS~1
C:\Documents and Settings\Administrator\Application Data\MCROSO~1
C:\Documents and Settings\Administrator\Application Data\PPPATC~1
C:\Documents and Settings\Administrator\Application Data\RACLE~1
C:\Documents and Settings\Administrator\Application Data\RACLE~2
C:\Documents and Settings\Administrator\Application Data\SCURIT~1
C:\Documents and Settings\Administrator\Application Data\SEMBLY~1
C:\Documents and Settings\Administrator\Application Data\SMANTE~1
C:\Documents and Settings\Administrator\Application Data\SSEMBL~1
C:\Documents and Settings\Administrator\Application Data\SSTEM~1
C:\Documents and Settings\Administrator\Application Data\SSTEM3~1
C:\Documents and Settings\Administrator\Application Data\STEM~1
C:\Documents and Settings\Administrator\Application Data\STEM32~1
C:\Documents and Settings\Administrator\Application Data\WNSXS~1
C:\Documents and Settings\Administrator\Application Data\YMBOLS~1
C:\Documents and Settings\Administrator\Application Data\YSTEM~1
C:\Documents and Settings\Administrator\Desktop\Error Cleaner.url
C:\Documents and Settings\Administrator\Desktop\Privacy Protector.url
C:\Documents and Settings\Administrator\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Administrator\Favorites\Error Cleaner.url
C:\Documents and Settings\Administrator\Favorites\Privacy Protector.url
C:\Documents and Settings\Administrator\Favorites\Spyware&Malware Protection.url
C:\Documents and Settings\Administrator\My Documents\APPATC~1
C:\Documents and Settings\Administrator\My Documents\ASKS~1
C:\Documents and Settings\Administrator\My Documents\ASKS~2
C:\Documents and Settings\Administrator\My Documents\CROSOF~1
C:\Documents and Settings\Administrator\My Documents\CROSOF~1.NET
C:\Documents and Settings\Administrator\My Documents\DOBE~1
C:\Documents and Settings\Administrator\My Documents\DOBE~2
C:\Documents and Settings\Administrator\My Documents\ECURIT~1
C:\Documents and Settings\Administrator\My Documents\FNTS~1
C:\Documents and Settings\Administrator\My Documents\FNTS~2
C:\Documents and Settings\Administrator\My Documents\ICROSO~1
C:\Documents and Settings\Administrator\My Documents\ICROSO~1.NET
C:\Documents and Settings\Administrator\My Documents\MANTEC~1
C:\Documents and Settings\Administrator\My Documents\MBOLS~1
C:\Documents and Settings\Administrator\My Documents\MCROSO~1
C:\Documents and Settings\Administrator\My Documents\MCROSO~1.NET
C:\Documents and Settings\Administrator\My Documents\PPATCH~1
C:\Documents and Settings\Administrator\My Documents\PPPATC~1
C:\Documents and Settings\Administrator\My Documents\RACLE~1
C:\Documents and Settings\Administrator\My Documents\RACLE~2
C:\Documents and Settings\Administrator\My Documents\SCURIT~1
C:\Documents and Settings\Administrator\My Documents\SEMBLY~1
C:\Documents and Settings\Administrator\My Documents\SKS~1
C:\Documents and Settings\Administrator\My Documents\SMANTE~1
C:\Documents and Settings\Administrator\My Documents\SMBOLS~1
C:\Documents and Settings\Administrator\My Documents\SSTEM~1
C:\Documents and Settings\Administrator\My Documents\SSTEM3~1
C:\Documents and Settings\Administrator\My Documents\STEM~1
C:\Documents and Settings\Administrator\My Documents\STEM32~1
C:\Documents and Settings\Administrator\My Documents\TSKS~1
C:\Documents and Settings\Administrator\My Documents\WNSXS~1
C:\Documents and Settings\Administrator\My Documents\YMBOLS~1
C:\Documents and Settings\Administrator\My Documents\YSTEM~1
C:\Documents and Settings\Administrator\My Documents\YSTEM3~1
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\appatc~1
C:\Program Files\asembl~1
C:\Program Files\asks~1
C:\Program Files\Common Files\asembl~1
C:\Program Files\Common Files\asks~1
C:\Program Files\Common Files\asks~2
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\crosof~1
C:\Program Files\Common Files\crosof~1.net
C:\Program Files\Common Files\curity~1
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\dobe~2
C:\Program Files\Common Files\ecurit~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~2
C:\Program Files\Common Files\icroso~1
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\icroso~2
C:\Program Files\Common Files\mantec~1
C:\Program Files\Common Files\mbols~1
C:\Program Files\Common Files\mcroso~1.net
C:\Program Files\Common Files\pppatc~1
C:\Program Files\Common Files\racle~1
C:\Program Files\Common Files\racle~2
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\sembly~1
C:\Program Files\Common Files\sks~1
C:\Program Files\Common Files\sks~2
C:\Program Files\Common Files\smante~1
C:\Program Files\Common Files\smbols~1
C:\Program Files\Common Files\sstem~1
C:\Program Files\Common Files\sstem3~1
C:\Program Files\Common Files\stem~1
C:\Program Files\Common Files\stem32~1
C:\Program Files\Common Files\tsks~1
C:\Program Files\Common Files\wnsxs~1
C:\Program Files\Common Files\ymante~1
C:\Program Files\Common Files\ymbols~1
C:\Program Files\Common Files\ystem3~1
C:\Program Files\crosof~1
C:\Program Files\crosof~1.net
C:\Program Files\dobe~1
C:\Program Files\dobe~2
C:\Program Files\ecurit~1
C:\Program Files\fnts~1
C:\Program Files\fnts~2
C:\Program Files\icroso~1
C:\Program Files\icroso~1.net
C:\Program Files\mbols~1
C:\Program Files\mcroso~1
C:\Program Files\mcroso~1.net
C:\Program Files\ppatch~1
C:\Program Files\ppatch~2
C:\Program Files\racle~1
C:\Program Files\scurit~1
C:\Program Files\sembly~1
C:\Program Files\smante~1
C:\Program Files\ssembl~1
C:\Program Files\sstem3~1
C:\Program Files\stem~1
C:\Program Files\wnsxs~1
C:\Program Files\ymante~1
C:\Program Files\ystem~1
C:\Program Files\ystem3~1
C:\WINDOWS\appatc~1
C:\WINDOWS\asembl~1
C:\WINDOWS\crosof~1
C:\WINDOWS\crosof~1.net
C:\WINDOWS\curity~1
C:\WINDOWS\dat.txt
C:\WINDOWS\dobe~1
C:\WINDOWS\dobe~2
C:\WINDOWS\ecurit~1
C:\WINDOWS\fnts~1
C:\WINDOWS\icroso~1
C:\WINDOWS\icroso~1.net
C:\WINDOWS\mantec~1
C:\WINDOWS\mbols~1
C:\WINDOWS\mcroso~1
C:\WINDOWS\mcroso~1.net
C:\WINDOWS\ppatch~1
C:\WINDOWS\ppatch~2
C:\WINDOWS\pppatc~1
C:\WINDOWS\pppatc~2
C:\WINDOWS\racle~1
C:\WINDOWS\rs.txt
C:\WINDOWS\scurit~1
C:\WINDOWS\search_res.txt
C:\WINDOWS\sks~1
C:\WINDOWS\sks~1\SKS~1\ctxad-503.0000
C:\WINDOWS\sks~1\SKS~1\ctxad-503.0001
C:\WINDOWS\sks~1\SKS~1\ctxad-503.0002
C:\WINDOWS\sks~2
C:\WINDOWS\smante~1
C:\WINDOWS\smbols~1
C:\WINDOWS\sstem~1
C:\WINDOWS\stem~1
C:\WINDOWS\stem32~1
C:\WINDOWS\system32\appatc~1
C:\WINDOWS\system32\asembl~1
C:\WINDOWS\system32\asks~1
C:\WINDOWS\system32\crosof~1.net
C:\WINDOWS\system32\curity~1
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dobe~2
C:\WINDOWS\system32\ecurit~1
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\fnts~2
C:\WINDOWS\system32\icroso~1
C:\WINDOWS\system32\icroso~1.net
C:\WINDOWS\system32\mantec~1
C:\WINDOWS\system32\mbols~1
C:\WINDOWS\system32\mcroso~1
C:\WINDOWS\system32\mcroso~1.net
C:\WINDOWS\system32\ppatch~1
C:\WINDOWS\system32\ppatch~1\??pPatch\
C:\WINDOWS\system32\pppatc~1
C:\WINDOWS\system32\pppatc~2
C:\WINDOWS\system32\racle~1
C:\WINDOWS\system32\racle~2
C:\WINDOWS\system32\sembly~1
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\smbols~1
C:\WINDOWS\system32\ssembl~1
C:\WINDOWS\system32\sstem3~1
C:\WINDOWS\system32\stem32~1
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\tsks~1
C:\WINDOWS\system32\wnsxs~1
C:\WINDOWS\system32\wtsit.exe
C:\WINDOWS\system32\ymante~1
C:\WINDOWS\system32\ymbols~1
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\system32\ystem3~1
C:\WINDOWS\wnsxs~1
C:\WINDOWS\ymante~1
C:\WINDOWS\ymbols~1
C:\WINDOWS\ystem~1
C:\WINDOWS\ystem3~1
----- BITS: Possible infected sites -----
hxxp://softworldnetwork.com
hxxp://onsafepro.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_FOPN
-------\LEGACY_FWSVC
-------\LEGACY_VSPF
-------\LEGACY_VSPF_HK
((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.
2008-02-24 17:43 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-02-24 17:43 . 2004-08-03 22:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-02-24 14:05 . 2008-02-24 14:15 <DIR> d-------- C:\fixwareout
2008-02-23 22:54 . 2008-02-23 23:17 <DIR> d-------- C:\SDFix
2008-02-23 17:18 . 2008-02-23 17:18 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-23 13:55 . 2008-02-23 13:55 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-02-23 13:30 . 2007-05-30 03:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-23 13:29 . 2008-02-23 13:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-22 18:00 . 2008-02-22 18:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Anti-Virus-Pro.com
2008-02-22 17:55 . 2008-02-23 07:28 <DIR> d-------- C:\Program Files\AntiVirusPro
2008-02-21 15:10 . 2008-02-20 13:56 315,392 --a------ C:\WINDOWS\dmdvpnslp.dll
2008-02-21 15:10 . 2008-02-20 13:56 282,624 --a------ C:\WINDOWS\bdmanager.dll
2008-02-21 15:10 . 2008-02-20 13:56 262,144 --a------ C:\WINDOWS\admgcx.dll
2008-02-21 15:10 . 2008-02-20 13:56 217,088 --a------ C:\WINDOWS\emotigt.dll
2008-02-21 15:10 . 2008-02-20 13:56 90,112 --a------ C:\WINDOWS\fsxloqf.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 03:59 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-02-22 22:02 --------- d-----w C:\Program Files\PokerStars
2008-01-19 03:44 --------- d-----w C:\Program Files\Java
2008-01-07 01:10 --------- d-----w C:\Program Files\The Weather Channel FW
2008-01-07 01:02 --------- d-----w C:\Program Files\Common Files\xing shared
2008-01-07 01:02 --------- d-----w C:\Program Files\Common Files\Real
2008-01-07 00:55 --------- d-----w C:\Program Files\Real
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6FFDE480-14C1-43FC-BEC1-CA97A2541FFD}]
2008-02-20 13:56 315392 --a------ C:\WINDOWS\dmdvpnslp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 07:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04 1415824]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"Bvocs"="C:\Documents and Settings\Administrator\Application Data\?ssembly\n?pdb.exe" [ ]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [2007-12-20 08:10 715888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03 36975]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 09:21 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 19:27 85696]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-12 18:00 282624]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-10-05 22:11 866584]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06 40048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-06 15:56 185632]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-11-10 09:52 34832]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 22:23:26 282624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdmanager"= {99A33923-FF5D-41E8-8B3C-E61DDBE1EAEB} - C:\WINDOWS\bdmanager.dll [2008-02-20 13:56 282624]
"admgcx"= {745BAAC0-8A69-4621-AA26-9E39434B2A92} - C:\WINDOWS\admgcx.dll [2008-02-20 13:56 262144]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R3 EraserUtilDrvI4;EraserUtilDrvI4;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI4.sys [2007-11-14 14:11]
R3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 03:19]
R3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 04:47]
R3 nv3;nv3;C:\WINDOWS\system32\DRIVERS\nv3.sys [2001-08-17 03:50]
R3 USRTI;U.S. Robotics Faxmodem Driver TI;C:\WINDOWS\system32\DRIVERS\USRTI.SYS [2001-08-17 04:28]
S3 ALABULK;Fujifilm USB MemoryCard ReaderWriter device driver;C:\WINDOWS\system32\Drivers\ALABULK2.sys [2002-09-19 16:33]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\CDStart.Exe
\Shell\Install\Command - D:\navsetup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-25 04:05:18 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-24 19:03:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\The Weather Channel FW\Framework\TheWeatherChannelSlnchr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2008-02-24 19:14:50 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-02-25 04:14:31
.
2007-12-23 18:20:59 --- E O F ---
And here is the hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:23:35 PM, on 2/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://softwarerefer...=...6Ojg5&lid=2R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SXG Advisor - {6FFDE480-14C1-43FC-BEC1-CA97A2541FFD} - C:\WINDOWS\dmdvpnslp.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7
O4 - HKCU\..\Run: [Bvocs] C:\Documents and Settings\Administrator\Application Data\?ssembly\n?pdb.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) -
http://www.photowork...ImageEditor.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1136832039984O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) -
http://www.photowork...ropUploader.cabO16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) -
http://a532.g.akamai...l/installer.exeO21 - SSODL: bdmanager - {99A33923-FF5D-41E8-8B3C-E61DDBE1EAEB} - C:\WINDOWS\bdmanager.dll
O21 - SSODL: admgcx - {745BAAC0-8A69-4621-AA26-9E39434B2A92} - C:\WINDOWS\admgcx.dll
O22 - SharedTaskScheduler: Reload Browse - {A1D9D3F0-8C2A-9A1D-A376-2CACFB10AB72} - (no file)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: (no name) -
http://www.crochetme...ges/cm_logo.gif--
End of file - 7040 bytes