Hi, can't remeber if I disabled UAC - shall I turn it back on? Here are the logs you requested.
ComboFix 08-03-27.5 - Scott 2008-03-29 20:26:12.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1396 [GMT 0:00]
Running from: C:\Users\Scott\Desktop\ComboFix.exe
Command switches used :: C:\Users\Scott\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))
.
2008-03-27 19:25 . 2008-03-27 19:25 <DIR> d-------- C:\Program Files\EDraw1.6.4
2008-03-27 06:38 . 2008-03-27 06:38 <DIR> d-------- C:\Deckard
2008-03-24 10:59 . 2008-03-29 15:18 <DIR> d-------- C:\Users\All Users\Google Updater
2008-03-24 10:59 . 2008-03-29 15:18 <DIR> d-------- C:\ProgramData\Google Updater
2008-03-23 22:50 . 2008-03-23 22:50 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-03-23 22:29 . 2008-03-29 17:05 54,156 --ah----- C:\Windows\QTFont.qfn
2008-03-23 22:29 . 2008-03-23 22:29 1,409 --a------ C:\Windows\QTFont.for
2008-03-23 22:28 . 2008-03-23 22:28 <DIR> d-------- C:\Program Files\iTunes
2008-03-23 22:28 . 2008-03-23 22:28 <DIR> d-------- C:\Program Files\iPod
2008-03-23 22:14 . 2008-03-23 22:28 <DIR> d-------- C:\Users\All Users\Apple Computer
2008-03-23 22:14 . 2008-03-23 22:28 <DIR> d-------- C:\ProgramData\Apple Computer
2008-03-23 22:14 . 2008-03-23 22:15 <DIR> d-------- C:\Program Files\QuickTime
2008-03-23 22:13 . 2008-03-23 22:13 <DIR> d-------- C:\Program Files\Apple Software Update
2008-03-23 22:08 . 2008-03-23 22:08 <DIR> d-------- C:\Users\All Users\Apple
2008-03-23 22:08 . 2008-03-23 22:08 <DIR> d-------- C:\ProgramData\Apple
2008-03-23 22:08 . 2008-03-23 22:08 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-03-22 19:45 . 2008-03-23 21:30 <DIR> d-------- C:\Users\Scott\{6a9bee41-a652-41da-8090-b8c18593a4be}
2008-03-22 11:49 . 2008-03-22 11:49 4,440 --a------ C:\Windows\System32\tmp.reg
2008-03-21 09:41 . 2008-03-21 09:41 <DIR> d-------- C:\VundoFix Backups
2008-03-20 22:45 . 2008-03-20 22:45 <DIR> d-------- C:\Program Files\Common Files\GeoVid
2008-03-20 22:45 . 2007-06-28 18:55 77,824 --a------ C:\Windows\System32\xvid.ax
2008-03-20 22:45 . 2005-06-07 15:11 60,416 --a------ C:\Windows\System32\dsetup.dll
2008-03-20 19:59 . 2007-01-03 19:20 1,732 --a------ C:\Windows\System32\drivers\nvphy.bin
2008-03-20 18:57 . 2008-03-20 18:57 <DIR> d-------- C:\Users\Scott\AppData\Roaming\SUPERAntiSpyware.com
2008-03-19 21:05 . 2008-01-19 05:46 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-03-19 21:04 . 2008-01-19 07:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-03-19 21:03 . 2008-01-19 07:35 3,072,000 --a------ C:\Windows\System32\networkmap.dll
2008-03-19 21:02 . 2008-01-19 07:34 6,103,040 --a------ C:\Windows\System32\chtbrkr.dll
2008-03-19 21:01 . 2008-01-19 06:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-03-19 21:00 . 2008-01-19 07:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-03-19 21:00 . 2008-01-19 07:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-03-19 21:00 . 2008-01-19 07:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-03-19 21:00 . 2008-01-19 07:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-03-19 21:00 . 2008-01-19 07:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-03-19 20:59 . 2008-01-19 07:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-03-19 20:59 . 2008-01-19 07:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-03-19 20:59 . 2008-01-19 07:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-03-19 20:59 . 2008-01-19 07:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-03-19 19:52 . 2006-11-08 09:48 356,352 --a------ C:\Windows\System32\nvusmb.exe
2008-03-19 19:52 . 2006-10-19 10:36 1,864 --a------ C:\Windows\System32\nvsmb.nvu
2008-03-19 19:46 . 2007-05-01 08:11 356,352 --a------ C:\Windows\System32\nvunrm.exe
2008-03-18 18:04 . 2008-03-18 18:04 <DIR> d-------- C:\Users\Scott\AppData\Roaming\funkitron
2008-03-18 17:54 . 2008-03-18 17:54 <DIR> d-------- C:\Program Files\Poker Superstars II
2008-03-18 17:46 . 2008-03-18 17:46 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-03-18 07:10 . 2008-03-18 07:10 <DIR> d-------- C:\Program Files\DAP Premium
2008-03-16 09:58 . 2005-05-26 15:34 2,297,552 --a------ C:\Windows\System32\d3dx9_26.dll
2008-03-09 10:07 . 2008-03-09 10:07 <DIR> d-------- C:\divx
2008-03-09 09:26 . 2008-03-09 09:26 <DIR> d-------- C:\Program Files\Xilisoft
2008-03-09 07:43 . 2008-03-09 07:43 307,968 --a------ C:\Windows\System32\TuneUpDefragService.exe
2008-03-09 07:43 . 2008-02-27 13:15 28,416 --a------ C:\Windows\System32\uxtuneup.dll
2008-03-09 07:43 . 2008-02-27 13:15 16,640 --a------ C:\Windows\System32\authuitu.dll
2008-03-08 15:51 . 2008-03-22 11:48 <DIR> d-------- C:\Users\Scott\AppData\Roaming\IDM
2008-03-08 15:51 . 2008-03-29 16:00 <DIR> d-------- C:\Users\Scott\AppData\Roaming\DMCache
2008-03-08 15:51 . 2008-03-09 09:33 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-03-07 19:39 . 2008-03-14 19:13 <DIR> d-------- C:\Program Files\Xara
2008-03-07 19:39 . 2008-03-14 19:13 <DIR> d-------- C:\Program Files\Common Files\Xara
2008-03-07 18:41 . 2008-03-07 18:41 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-03-07 13:40 . 2008-03-07 13:40 13,035 --a------ C:\Windows\System32\drivers\SymRedir.cat
2008-03-07 13:40 . 2008-03-07 13:40 1,358 --a------ C:\Windows\System32\drivers\SymRedir.inf
2008-03-07 13:39 . 2008-03-07 13:39 191,536 --a------ C:\Windows\System32\drivers\symtdi.sys
2008-03-07 13:39 . 2008-03-07 13:39 145,968 --a------ C:\Windows\System32\drivers\symfw.sys
2008-03-07 13:39 . 2008-03-07 13:39 39,984 --a------ C:\Windows\System32\drivers\symids.sys
2008-03-07 13:39 . 2008-03-07 13:39 37,936 --a------ C:\Windows\System32\drivers\symndisv.sys
2008-03-07 13:39 . 2008-03-07 13:39 27,696 --a------ C:\Windows\System32\drivers\symredrv.sys
2008-03-07 13:39 . 2008-03-07 13:39 12,848 --a------ C:\Windows\System32\drivers\symdns.sys
2008-03-06 19:42 . 2008-03-06 19:42 10,208 --a------ C:\Windows\System32\gaeffect.sti
2008-03-06 19:42 . 2008-03-06 19:42 6,344 --a------ C:\Windows\System32\gafilter.sti
2008-03-06 19:36 . 2008-03-06 19:36 <DIR> d-------- C:\Windows\Noslip
2008-03-06 19:36 . 1998-10-29 16:45 306,688 --a------ C:\Windows\IsUninst.exe
2008-03-06 19:36 . 2008-03-06 19:36 16 --a------ C:\Windows\Wininit.ini
2008-03-06 19:01 . 2008-03-08 15:34 <DIR> d-------- C:\Program Files\Magic Swf2Gif
2008-03-06 07:04 . 2004-05-04 11:53 1,645,320 --a------ C:\Windows\gdiplus.dll
2008-03-06 07:04 . 2006-05-20 16:16 1,184,984 --a------ C:\Windows\System32\wvc1dmod.dll
2008-03-06 07:04 . 2006-05-11 19:21 626,688 --a------ C:\Windows\System32\vp7vfw.dll
2008-03-06 07:04 . 2007-03-18 20:37 65,602 --a------ C:\Windows\System32\cook3260.dll
2008-03-05 18:15 . 2008-03-05 18:15 <DIR> d-------- C:\Users\All Users\IncrediMail
2008-03-05 18:15 . 2008-03-05 18:16 <DIR> d-------- C:\Users\All Users\IM
2008-03-05 18:15 . 2008-03-05 18:15 <DIR> d-------- C:\ProgramData\IncrediMail
2008-03-05 18:15 . 2008-03-05 18:16 <DIR> d-------- C:\ProgramData\IM
2008-03-05 06:54 . 2008-03-05 06:54 <DIR> d-------- C:\Program Files\ESI
2008-03-04 19:47 . 2008-03-04 19:47 0 --ah----- C:\Windows\SwSys2.bmp
2008-03-04 19:47 . 2008-03-04 19:47 0 --ah----- C:\Windows\SwSys1.bmp
2008-03-04 18:04 . 2005-11-30 21:20 2,314,332 --a------ C:\Windows\System32\LIBMMD.DLL
2008-03-03 19:21 . 2008-03-04 07:09 <DIR> d-------- C:\Program Files\DJ Music Mixer
2008-03-03 19:11 . 2008-03-03 19:11 <DIR> d-------- C:\Users\All Users\Nokia
2008-03-03 19:11 . 2008-03-03 19:11 <DIR> d-------- C:\ProgramData\Nokia
2008-03-03 19:08 . 2008-03-03 19:08 <DIR> d-------- C:\Users\All Users\Installations
2008-03-03 19:08 . 2008-03-03 19:08 <DIR> d-------- C:\ProgramData\Installations
2008-03-03 18:49 . 2008-03-11 19:38 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-03 18:48 . 2008-03-11 19:25 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-03-03 18:48 . 2008-03-11 19:25 <DIR> d-------- C:\ProgramData\WLInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-29 20:20 --------- d-----w C:\ProgramData\Symantec
2008-03-27 19:54 --------- d-----w C:\Users\Scott\AppData\Roaming\uTorrent
2008-03-24 10:59 --------- d-----w C:\Program Files\SpywareGuard
2008-03-24 10:59 --------- d-----w C:\Program Files\Google
2008-03-23 23:55 --------- d-----w C:\Program Files\IncrediMail
2008-03-23 22:27 --------- d-----w C:\Program Files\Bonjour
2008-03-23 21:30 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-03-23 21:30 --------- d-----w C:\ProgramData\FLEXnet
2008-03-23 21:30 --------- d-----w C:\Program Files\Wide Angle Software
2008-03-23 21:29 --------- d-----w C:\Program Files\iPod Access for Windows
2008-03-22 19:45 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-03-22 19:45 --------- d-----w C:\Program Files\Realtek
2008-03-21 19:27 --------- d-----w C:\Users\Scott\AppData\Roaming\Vso
2008-03-20 19:02 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-20 18:56 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-20 18:43 174 --sha-w C:\Program Files\desktop.ini
2008-03-20 02:27 --------- d-----w C:\ProgramData\NVIDIA
2008-03-19 22:24 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-19 22:24 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-03-19 22:24 --------- d-----w C:\Program Files\Windows Mail
2008-03-19 22:24 --------- d-----w C:\Program Files\Windows Defender
2008-03-19 22:24 --------- d-----w C:\Program Files\Windows Calendar
2008-03-18 17:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-14 18:35 --------- d-----w C:\ProgramData\Ulead Systems
2008-03-14 18:35 --------- d-----w C:\Program Files\Ulead Systems
2008-03-14 18:26 --------- d-----w C:\Program Files\DVDPean Pro 5.6.0
2008-03-14 18:21 --------- d-----w C:\Program Files\MixVibesDVS
2008-03-14 18:21 --------- d-----w C:\Program Files\MagicISO
2008-03-14 17:59 --------- d-----w C:\Program Files\Java
2008-03-11 19:24 --------- d-----w C:\Program Files\Windows Live
2008-03-11 06:54 --------- d-----w C:\Program Files\Norton Internet Security
2008-03-11 06:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-09 10:02 --------- d-----w C:\Program Files\DivX
2008-03-09 07:44 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-03-06 21:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-03-06 21:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-03-06 21:32 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat
2008-03-06 07:05 47,360 ----a-w C:\Users\Scott\AppData\Roaming\pcouffin.sys
2008-03-06 07:05 --------- d-----w C:\Program Files\vso
2008-03-04 17:33 --------- d-----w C:\Program Files\Nokia
2008-03-04 17:33 --------- d-----w C:\Program Files\Common Files\Nokia
2008-03-03 19:04 --------- d-----w C:\Users\Scott\AppData\Roaming\LimeWire
2008-03-03 18:33 --------- d---a-w C:\ProgramData\TEMP
2008-03-02 10:20 --------- d-----w C:\Users\Scott\AppData\Roaming\SoundSpectrum
2008-03-02 10:20 --------- d-----w C:\Program Files\SoundSpectrum
2008-02-21 17:44 --------- d-----w C:\Users\Scott\AppData\Roaming\Thinstall
2008-02-18 11:16 30,464 ----a-w C:\Windows\system32\drivers\usbaapl.sys
2008-02-17 19:10 --------- d-----w C:\Users\Scott\AppData\Roaming\DVDPeanSoftware
2008-02-14 18:14 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-14 18:13 --------- d-----w C:\Program Files\Common Files\Control Panels
2008-02-14 18:10 --------- d-----w C:\ProgramData\ALM
2008-02-12 18:11 --------- d-----w C:\Program Files\Common Files\Java
2008-02-10 20:47 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com
2008-02-10 10:48 --------- d-----w C:\ProgramData\Grisoft
2008-02-10 09:51 --------- d-----w C:\Program Files\Trend Micro
2008-02-09 10:50 --------- d-----w C:\Program Files\Common Files\Real
2008-02-08 19:15 --------- d-----w C:\Program Files\DAP
2008-02-07 20:58 --------- d-----w C:\Program Files\Common Files\Nero
2008-02-07 20:55 --------- d-----w C:\ProgramData\Nero
2008-02-07 20:55 --------- d-----w C:\Program Files\Nero
2008-02-03 09:39 --------- d-----w C:\ProgramData\PC Drivers Headquarters
2008-02-03 09:35 --------- d-----w C:\Program Files\PC Drivers HeadQuarters
2008-01-19 07:34 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-01-19 07:33 58,880 ----a-w C:\Windows\bfsvc.exe
2008-01-19 07:33 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-19 07:33 498,176 ----a-w C:\Windows\HelpPane.exe
2008-01-19 07:33 459,264 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-19 07:33 40,960 ----a-w C:\Windows\AppPatch\apihex86.dll
2008-01-19 07:33 237,568 ----a-w C:\Windows\AppPatch\AcRedir.dll
2008-01-19 07:33 2,927,104 ----a-w C:\Windows\explorer.exe
2008-01-19 07:33 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-19 07:33 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-19 07:33 151,040 ----a-w C:\Windows\notepad.exe
2008-01-19 07:33 134,656 ----a-w C:\Windows\regedit.exe
2008-01-19 07:33 13,312 ----a-w C:\Windows\fveupdate.exe
2008-01-04 21:41 3,532 ----a-w C:\drmHeader.bin
2007-11-11 16:27 94,080 ----a-w C:\Users\Scott\AppData\Roaming\ezplay.sys
2007-11-11 16:27 81,920 ----a-w C:\Users\Scott\AppData\Roaming\ezpinst.exe
2007-09-01 11:21 22 --sha-w C:\Windows\SMINST\HPCD.sys
2007-07-15 19:23 88 --sha-r C:\Windows\System32\71CE9D815B.sys
2007-07-16 07:35 88 --sha-r C:\Windows\System32\DC2E12B9C6.sys
2007-05-17 20:03 88 --sha-r C:\Windows\System32\DEA2665800.sys
2007-07-16 07:36 3,764 --sha-w C:\Windows\System32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-03-29_16.19.40.72 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-29 16:16:02 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-03-29 20:31:52 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-03-29 16:16:19 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-03-29 20:32:10 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-03-29 20:32:10 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-03-29 16:16:19 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-03-29 20:32:10 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-03-29 20:32:10 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-03-29 16:07:53 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-03-29 20:13:35 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-03-29 16:07:53 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-29 20:13:35 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-29 16:07:53 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-29 20:13:35 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-03-29 16:09:24 113,442 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-03-29 17:11:34 113,442 ----a-w C:\Windows\System32\perfc009.dat
- 2008-03-29 16:09:24 612,766 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-03-29 17:11:34 612,766 ----a-w C:\Windows\System32\perfh009.dat
- 2008-03-29 16:04:33 15,324 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1466205036-3104418628-1934201306-1000_UserData.bin
+ 2008-03-29 17:07:09 15,604 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1466205036-3104418628-1934201306-1000_UserData.bin
- 2008-03-29 16:04:33 89,630 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-03-29 17:07:08 89,808 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-03-29 17:03:05 3,076 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-03-29 16:04:29 68,860 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-03-29 17:07:06 68,876 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IE Privacy Keeper"="C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" [2005-12-03 13:52 1015808]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-22 23:13 1591808]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 01:15 221184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 07:33 202240]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-03-20 19:02 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 07:38 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 13:42 65536]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 05:52 4702208 C:\Windows\RtHDVCpl.exe]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 16:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 14:52 849280]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 07:59 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 14:21 2213160]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"Acrobat Assistant 8.0"="K:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-11 17:06 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-11 17:06 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-11 17:06 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 17:15 1634304]
C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 7:05:35 PM 360448]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [3/24/2008 10:59:20 AM 125624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\Windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Scott^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^U46DJ Control Panel.lnk]
path=C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\U46DJ Control Panel.lnk
backup=C:\Windows\pss\U46DJ Control Panel.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DPService]
C:\Program Files\HP\DVDPlay\DPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo R800]
--a------ 2007-01-16 04:00 177664 C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATI9YE.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-17 07:11 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 2008-03-08 15:52 2594224 C:\Program Files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
--a------ 2008-03-11 17:30 243072 C:\Program Files\IncrediMail\bin\IncMail.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-02-17 01:15 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-02-17 01:15 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2006-11-28 14:12 222720 C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiSpywareOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{38B1A04E-A897-4B53-BB14-7418D2D2AC5C}C:\\users\\scott\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\scott\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{6BD45AE4-C9A8-4F2C-B506-1502AD5C975F}C:\\users\\scott\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\scott\program files\utorrent\utorrent.exe:utorrent.exe
"{ED13F298-6B08-4201-8674-A50834ACC569}"= UDP:14444:utorrent
"{AAC41441-F976-4BAB-BB2E-982E22A5B047}"= TCP:14444:utorrent
"{21D0C3F0-7550-4BD6-BAAB-22E5E9AA55E5}"= UDP:C:\Users\Scott\Program Files\uTorrent\uTorrent.exe:µTorrent
"{C80CD74D-AB31-4F25-BD20-B1410FCDC0F3}"= TCP:C:\Users\Scott\Program Files\uTorrent\uTorrent.exe:µTorrent
"{F3863C16-564A-4F6D-A82D-546CD1382D57}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{49B292F1-C9FB-4449-B264-E503BD8D52BA}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{F63335E0-9DA2-4D32-9290-0DBF7ACDD0CB}"= UDP:C:\Program Files\Orb Networks\Orb\bin\Orb.exe:Orb
"{6B30BB90-EF92-4908-B661-9E64DDC8C215}"= TCP:C:\Program Files\Orb Networks\Orb\bin\Orb.exe:Orb
"{A1932CAC-3AD3-43B0-927D-830FC9C325D7}"= UDP:C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe:OrbTray
"{0EEAA0A3-F14A-4F0E-AF23-699A568CCE36}"= TCP:C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe:OrbTray
"{6DF4984C-19D2-4E07-95AC-57D6418FAA2D}"= UDP:C:\Program Files\Orb Networks\Orb\bin\OrbStreamerClient.exe:Orb Stream Client
"{CCBC6E24-AD93-4197-89AC-C72DE6E552AB}"= TCP:C:\Program Files\Orb Networks\Orb\bin\OrbStreamerClient.exe:Orb Stream Client
"{B15F8E10-48A4-4B9B-9C3F-91206175718F}"= UDP:C:\Program Files\Orb Networks\Orb\bin\xmltv.exe:OrbTVGuide
"{F9540578-331C-4FF0-9286-16096B8E6BD1}"= TCP:C:\Program Files\Orb Networks\Orb\bin\xmltv.exe:OrbTVGuide
"{CF0F4A96-D828-4827-94CF-9A7EB1B2670C}"= UDP:C:\Program Files\Orb Networks\Orb\bin\OrbChannelScan.exe:OrbChannelScan
"{497CE2CF-5499-49E0-89A7-DEB2FD6EC571}"= TCP:C:\Program Files\Orb Networks\Orb\bin\OrbChannelScan.exe:OrbChannelScan
"{9B425107-8617-4C77-B6D1-BB92E8CAC247}"= C:\Program Files\Windows Live\Messenger\wlcsdk.exe:Windows Live Messenger (Phone)
"{5B5635A6-F8E8-4308-9373-180161E0EFCA}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{C55FF4CD-77E3-41CD-B3DF-65D271972880}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{6D2C8490-05C1-4CBC-B56A-CE139D2F28ED}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{A96AFFBC-762B-44EC-B523-362FCB86162D}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{A2017AB2-2A7C-474A-B24A-B045EC744D08}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
"{440943C1-4C29-4128-9699-692FF2BB8EEC}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
"{ED3457AA-404F-48A7-8DBD-456D28376B9B}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:umi
"{B6EEEC4A-D095-47E5-AD66-B0154346980E}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:umi
"{AC7828F7-D563-4709-9922-4BC812E691C0}"= UDP:3703:Adobe Version Cue CS3 Server
"{96CDAD8B-8E52-4C6B-8F79-36E014DF87D2}"= UDP:3704:Adobe Version Cue CS3 Server
"{5B9B8B44-2CF3-4A9A-8362-7BAAEAE07685}"= UDP:50900:Adobe Version Cue CS3 Server
"{7D64EFF9-8736-4396-9A28-CCC790186551}"= UDP:50901:Adobe Version Cue CS3 Server
"{A6AB4499-62B3-4F3E-83DC-0675C69E8FBC}"= UDP:C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{46D468CC-1552-40E3-B354-59FB53563E06}"= TCP:C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{3910CA99-20CD-49F1-95DF-31A0DFEF40E3}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{0C5B8293-F35C-453E-B98E-FE04A9BD1BC8}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{F1F1105A-7479-459C-8E1A-0A2700CB64B9}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8D1C8EB0-E20A-42DC-B244-8AE5948EF888}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FFB94416-2769-477B-B6F6-FA06D95920C8}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{BF6B9468-4CD6-4453-B0FD-B763300ED4EF}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{1CE52F1D-6813-44EA-B6C4-40F38104A02F}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{CB17BCE3-D45A-4907-9E07-19B667949671}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{88AD49B3-448D-40C0-8A40-B53AFF48D178}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{406201F1-124F-4FFB-A695-788A76AD620A}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{47DB9E4A-7887-409D-80A6-E4EB47502913}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{5A61FD86-EFC7-467A-86BD-1039F58D54CD}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{01BF2DF4-2CD4-4A36-BCB4-6CFB20553707}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{92E5C759-E3E5-48EC-9558-E1A6726BAD8D}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{3ED4A772-AFFF-4D0F-98FA-467FB54D4521}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{DC08BD25-35EC-4FEF-B071-485A3B9332EA}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{DA740D35-178C-417B-AD63-3177891CCD73}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{29823646-C8FC-4FCC-914E-D067493F9176}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{9BFD69B5-C6C2-4711-9865-BF08BA36A3C7}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{13B66C1C-3640-432C-9F82-76C27901E8DF}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 AmdAcpi;AmdAcpi Bus Filter Driver;C:\Windows\system32\DRIVERS\AmdAcpi.sys [2006-09-05 16:04]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080325.002\IDSvix86.sys [2008-02-13 16:18]
R3 AmdTools;AMD Special Tools Driver;C:\Windows\system32\DRIVERS\AmdTools.sys [2006-08-24 15:37]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 13:39]
S3 Navcar;Navman In-car Navigator USB Driver Service;C:\Windows\system32\DRIVERS\Navcar.sys [2006-09-18 12:48]
S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010004};PCD5SRVC{8A863ACB-F5F6CC6A-05010004} - PCDR Kernel Mode Service Helper Driver;C:\PROGRA~1\PC-DOC~1\PCD5SRVC.pkms [2006-11-18 00:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-03-29 20:32:03 C:\Windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-03-24 20:51:38 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Scott.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-29 20:32:20
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\PSIService.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\iPod\bin\iPodService.exe
K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroDist.exe
.
**************************************************************************
.
Completion time: 2008-03-29 20:36:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-29 20:36:09
ComboFix2.txt 2008-03-29 16:20:13
Pre-Run: 73,829,945,344 bytes free
Post-Run: 73,599,942,656 bytes free
.
2008-03-21 19:18:24 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:37:00, on 29/03/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
K:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\Explorer.exe
K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroDist.exe
C:\Windows\system32\notepad.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - K:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - K:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "K:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [IE Privacy Keeper] "C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" -startup
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Append to existing PDF - res://K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://K:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} -
http://www.skybroadband.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) -
http://www.ca.com/us...an/pestscan.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.co.../sysreqlab2.cabO16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2....re/HPDEXAXO.cabO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www.ca.com/us...nfo/webscan.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
--
End of file - 13389 bytes