ComboFix 08-04-03.3 - Owner 2008-04-03 20:49:09.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.130 [GMT -7:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\Documents and Settings\Owner\Desktop\Nero 8 Ultra Edition 8.2.8.0+Keymaker.zip
C:\Documents and Settings\Owner\My Documents\MavisBeacon16-dm.exe
C:\Program Files\Norton AntiVirus\Quarantine\
067F0F7F.dll
C:\Program Files\Norton AntiVirus\Quarantine\16B57354.dll
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\UADC_0001_D10M0210.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Rabio
C:\Documents and Settings\Owner\Desktop\Nero 8 Ultra Edition 8.2.8.0+Keymaker.zip
C:\Documents and Settings\Owner\My Documents\MavisBeacon16-dm.exe
C:\Program Files\SpyAway
C:\Program Files\SpyAway\stat.bin
C:\Program Files\SpyAway\uninstall.log
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\UADC_0001_D10M0210.exe
C:\WINDOWS\Downloaded Program Files\UADC_0001_D10M0210.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-04 to 2008-04-04 )))))))))))))))))))))))))))))))
.
2008-04-01 19:52 . 2008-04-01 19:52 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Template
2008-03-29 12:59 . 2008-03-29 12:59 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Talkback
2008-03-28 23:32 . 2008-03-28 23:32 <DIR> d-------- C:\Program Files\Picasa2
2008-03-28 23:29 . 2008-03-28 23:29 <DIR> d-------- C:\Program Files\Norton Security Scan
2008-03-28 23:27 . 2008-04-03 20:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-03-24 17:09 . 2008-03-24 17:09 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-24 17:09 . 2008-03-24 17:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-22 13:24 . 2008-03-22 13:25 <DIR> d-------- C:\Program Files\Winamp
2008-03-22 13:24 . 2008-03-22 14:17 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Winamp
2008-03-14 16:18 . 2008-03-14 16:18 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Viewpoint
2008-03-14 16:13 . 2008-03-14 16:13 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-03-14 15:36 . 2008-03-14 15:36 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\acccore
2008-03-11 12:03 . 2008-03-11 12:03 285 --a------ C:\WINDOWS\system32\MRT.INI
2008-03-11 00:01 . 2008-03-11 00:01 0 --a------ C:\WINDOWS\Irremote.ini
2008-03-10 00:11 . 2008-03-10 00:11 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Nero
2008-03-09 23:55 . 2008-03-09 23:55 <DIR> d-------- C:\Program Files\Nero
2008-03-09 23:55 . 2008-03-11 00:09 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-03-09 23:55 . 2008-03-11 00:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-09 23:46 . 2008-03-10 20:00 <DIR> d-------- C:\Program Files\AskTBar
2008-03-08 20:07 . 2008-03-22 00:00 <DIR> d-------- C:\Program Files\Registry Defender
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-03 08:13 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-04-03 06:15 10,396 ----a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2008-03-29 06:27 --------- d-----w C:\Program Files\Google
2008-03-25 04:18 --------- d-----w C:\Program Files\McAfee
2008-03-24 23:50 --------- d-----w C:\Program Files\AOL 9.1
2008-03-24 23:50 --------- d-----w C:\Program Files\AIM6
2008-03-24 04:54 --------- d-----w C:\Program Files\LimeWire
2008-03-14 23:18 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AOL
2008-03-09 08:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-03-09 08:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-08 21:53 --------- d-----w C:\Program Files\Real
2008-03-08 21:53 --------- d-----w C:\Program Files\Image-Line
2008-03-01 05:11 --------- d-----w C:\Documents and Settings\Guest\Application Data\DivX
2008-03-01 05:03 --------- d-----w C:\Documents and Settings\Guest\Application Data\Syntrillium
2008-03-01 04:36 --------- d-----w C:\Documents and Settings\Guest\Application Data\acccore
2008-03-01 04:10 0 ----a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat
2008-02-26 04:32 --------- d-----w C:\Program Files\Skype
2008-02-23 04:40 --------- d-----w C:\Program Files\DivX
2008-02-23 03:43 --------- d-----w C:\Program Files\Common Files\AOL
2008-02-23 03:42 --------- d-----w C:\Program Files\Common Files\aolshare
2008-02-23 03:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-12 04:25 --------- d-----w C:\Documents and Settings\Owner\Application Data\AOL
2008-02-11 04:59 3,044 -c--a-w C:\Documents and Settings\Owner\Application Data\ViewerApp.dat
2008-02-06 16:51 171,400 ----a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-06 02:33 --------- d-----w C:\Program Files\QuickTime
2008-02-04 04:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-04 04:54 --------- d-----w C:\Program Files\Common Files\McAfee
2008-02-04 04:50 --------- d-----w C:\Program Files\mcafee.com
2008-02-04 03:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-02-04 01:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
1998-04-02 23:51 77,312 -csha-r C:\WINDOWS\ic.exe
1998-04-02 23:55 80,384 -csha-r C:\WINDOWS\icfire.exe
1997-07-23 18:03 11,338 -csha-r C:\WINDOWS\ts.dll
.
((((((((((((((((((((((((((((( snapshot@2008-03-14_18.24.56.78 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 15:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 03:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 15:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 15:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
+ 2008-03-29 06:29:25 29,184 ----a-r C:\WINDOWS\Installer\{3A4FFB84-D070-4DA5-AB7B-D41D87FD8D19}\Icon3A4FFB84.exe
+ 2000-08-31 15:00:00 98,816 ----a-w C:\WINDOWS\sed.exe
+ 2000-08-31 15:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe
+ 2000-08-31 15:00:00 136,704 ----a-w C:\WINDOWS\swsc.exe
+ 2000-08-31 15:00:00 212,480 ----a-w C:\WINDOWS\swxcacls.exe
- 2007-07-02 19:41:10 36,624 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
+ 2007-03-07 23:51:00 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
+ 2005-05-24 19:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 22:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 22:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2007-07-02 19:41:10 527,096 ------w C:\WINDOWS\system32\px.dll
+ 2007-03-07 23:51:00 547,576 ------w C:\WINDOWS\system32\px.dll
- 2007-07-02 19:41:09 129,784 ------w C:\WINDOWS\system32\pxafs.dll
+ 2007-03-07 23:51:00 129,784 ------w C:\WINDOWS\system32\pxafs.dll
- 2007-07-02 19:41:10 64,760 ------w C:\WINDOWS\system32\pxcpya64.exe
+ 2007-03-07 23:51:00 64,760 ------w C:\WINDOWS\system32\pxcpya64.exe
- 2007-07-02 19:41:10 502,520 ------w C:\WINDOWS\system32\pxdrv.dll
+ 2007-03-07 23:51:00 510,712 ------w C:\WINDOWS\system32\pxdrv.dll
- 2007-07-02 19:41:11 72,440 ------w C:\WINDOWS\system32\pxhpinst.exe
+ 2007-03-07 23:51:00 72,440 ------w C:\WINDOWS\system32\pxhpinst.exe
- 2007-07-02 19:41:10 64,760 ------w C:\WINDOWS\system32\pxinsa64.exe
+ 2007-03-07 23:51:00 64,760 ------w C:\WINDOWS\system32\pxinsa64.exe
- 2007-07-02 19:41:11 183,032 ------w C:\WINDOWS\system32\pxmas.dll
+ 2007-03-07 23:51:00 187,128 ------w C:\WINDOWS\system32\pxmas.dll
- 2007-07-02 19:41:10 1,329,912 ------w C:\WINDOWS\system32\pxsfs.dll
+ 2007-03-07 23:51:00 1,628,920 ------w C:\WINDOWS\system32\pxsfs.dll
- 2007-07-02 19:41:10 379,640 ------w C:\WINDOWS\system32\pxwave.dll
+ 2007-03-07 23:51:00 379,640 ------w C:\WINDOWS\system32\pxwave.dll
+ 2000-08-31 15:00:00 49,152 ----a-w C:\WINDOWS\VFind.exe
+ 2000-08-31 15:00:00 68,096 ----a-w C:\WINDOWS\zip.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-02-16 12:39 50528]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-03-10 11:25 1688872]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-28 23:27 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 09:09 36864 C:\WINDOWS\ShowWnd.exe]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [ ]
"HostManager"="C:\Program Files\Common Files\AOL\1128561137\ee\AOLSoftware.exe" [2008-03-06 09:52 42032]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [ ]
"ViewMgr"="C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [ ]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [ ]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [ ]
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [ ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2005-05-12 14:00 90112 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-12 14:00 2805248 C:\WINDOWS\alcwzrd.exe]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-03-10 11:11 2213160]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 15:54 37376]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
AOL Desktop.lnk - C:\Program Files\Common Files\AOL\Launch\aollaunch.exe [2007-05-25 10:16:09 42032]
RegistryDefender.lnk - C:\Program Files\Registry Defender\RegistryDefender.exe [2008-02-22 19:56:02 2433024]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-03-28 23:27:40 124400]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1128561137\\ee\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"C:\\Program Files\\AOL\\RC\\regClient.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Common Files\\AOL\\1128561137\\ee\\AOLDesktop.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\AOL 9.1\\waol.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 23:41]
.
Contents of the 'Scheduled Tasks' folder
"2004-12-26 17:16:25 C:\WINDOWS\Tasks\ISP signup reminder 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2008-02-15 09:58:15 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-04-01 08:00:24 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-03-29 06:29:30 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-03 20:53:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-03 20:54:36
ComboFix-quarantined-files.txt 2008-04-04 03:54:27
ComboFix2.txt 2008-03-25 00:01:58
ComboFix3.txt 2008-03-22 20:15:15
ComboFix4.txt 2008-03-15 01:25:20
Pre-Run: 128,328,929,280 bytes free
Post-Run: 128,325,492,736 bytes free
.
2008-03-11 19:05:09 --- E O F ---
=============================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:11, on 2008-04-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\1128561137\ee\AOLSoftware.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Registry Defender\RegistryDefender.exe
C:\PROGRA~1\AOL9~1.1\waol.exe
C:\Program Files\Common Files\AOL\1128561137\ee\AOLDesktop.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\AOL9~1.1\shellmon.exe
C:\Program Files\Common Files\AOL\1128561137\ee\aexplore.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://www.crawler.c...spx?tb_id=60131R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
http://dnl.crawler.c...aspx?TbId=60131R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1128561137\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\PROGRA~1\AOL9~1.1\AOL.EXE" -b
O4 - Startup: AOL Desktop.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
O4 - Startup: RegistryDefender.lnk = C:\Program Files\Registry Defender\RegistryDefender.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.gateway.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....aceUploader.cabO16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) -
http://asp.mathxl.co...nstallAsst2.cabO23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O24 - Desktop Component 0: (no name) -
http://documents.wfp...m/wfp091426.jpg--
End of file - 8624 bytes