ComboFix 08-04-16.5 - Beth 2008-04-18 9:35:59.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.520 [GMT -4:00]
Running from: F:\Beth\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\dmpcfqvi
C:\Documents and Settings\All Users\Application Data\Rabio
C:\Documents and Settings\All Users\Application Data\sdwfodgn.dll
C:\Documents and Settings\All Users\Application Data\wjqjchup
C:\Documents and Settings\All Users\Application Data\wjqjchup\anobqdqz.exe
C:\Documents and Settings\All Users\Application Data\xmfwtkve
C:\Documents and Settings\LocalService\cftmon.exe
C:\fixwareout
C:\fixwareout\dnsbak.reg
C:\fixwareout\FindT\clsid.bak
C:\fixwareout\FindT\dumphive.exe
C:\fixwareout\FindT\FixWareOut.reg
C:\fixwareout\FindT\nircmd.exe
C:\fixwareout\FindT\patterns.txt
C:\fixwareout\FindT\rbot.bat
C:\fixwareout\FindT\RestartIt.exe
C:\fixwareout\FindT\runback.txt
C:\fixwareout\FindT\runs.vbs
C:\fixwareout\FindT\swreg.exe
C:\fixwareout\FindT\vfind.exe
C:\fixwareout\FindT\XP-2K2.cmd
C:\fixwareout\FixIt.BAT
C:\fixwareout\report.txt
C:\mDxB.exe
C:\Program Files\Bat
C:\Program Files\Bat\Bat.dll
C:\Program Files\Bat\Bat.dll.intermediate.manifest
C:\Program Files\Bat\Bat.exe
C:\Program Files\Bat\Bat.info
C:\Program Files\Bat\Bat.original
C:\Program Files\Bat\Info.dll
C:\Program Files\Bat\un_BatSetup_15041.exe
C:\Program Files\Bat\un_BatSetup_15041.txt
C:\Program Files\Bat\X_Bat.exe
C:\Program Files\Bat\X_Bat.log
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\OneStepSearch
C:\Program Files\OneStepSearch\home.js
C:\Program Files\OneStepSearch\readme.html
C:\Program Files\OneStepSearch\uninstall.exe
C:\SDFix
C:\SDFix.exe
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FixComponents.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixSchedule.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\grep.exe
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\HPFix5.reg
C:\SDFix\apps\HPFix6.reg
C:\SDFix\apps\HPFix7.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\regedit.exe
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\sed.exe
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\srv2bk.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\vfind.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\winsec.reg
C:\SDFix\apps\zip.exe
C:\SDFix\catchme.exe
C:\SDFix\dummy.sys
C:\SDFix\HOSTS
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\VundoFix Backups
C:\WINDOWS\BM93e0d315.xml
C:\WINDOWS\cuawsppw
C:\WINDOWS\cuawsppw\1.png
C:\WINDOWS\cuawsppw\2.png
C:\WINDOWS\cuawsppw\3.png
C:\WINDOWS\cuawsppw\4.png
C:\WINDOWS\cuawsppw\5.png
C:\WINDOWS\cuawsppw\6.png
C:\WINDOWS\cuawsppw\7.png
C:\WINDOWS\cuawsppw\8.png
C:\WINDOWS\cuawsppw\9.png
C:\WINDOWS\cuawsppw\bottom-rc.gif
C:\WINDOWS\cuawsppw\config.png
C:\WINDOWS\cuawsppw\content.png
C:\WINDOWS\cuawsppw\download.gif
C:\WINDOWS\cuawsppw\frame-bg.gif
C:\WINDOWS\cuawsppw\frame-bottom-left.gif
C:\WINDOWS\cuawsppw\frame-h1bg.gif
C:\WINDOWS\cuawsppw\head.png
C:\WINDOWS\cuawsppw\icon.png
C:\WINDOWS\cuawsppw\indexwp.html
C:\WINDOWS\cuawsppw\main.css
C:\WINDOWS\cuawsppw\memory-prots.png
C:\WINDOWS\cuawsppw\net.png
C:\WINDOWS\cuawsppw\pc-mag.gif
C:\WINDOWS\cuawsppw\pc.gif
C:\WINDOWS\cuawsppw\poloska1.png
C:\WINDOWS\cuawsppw\poloska2.png
C:\WINDOWS\cuawsppw\poloska3.png
C:\WINDOWS\cuawsppw\promowp1.html
C:\WINDOWS\cuawsppw\promowp2.html
C:\WINDOWS\cuawsppw\promowp3.html
C:\WINDOWS\cuawsppw\promowp4.html
C:\WINDOWS\cuawsppw\promowp5.html
C:\WINDOWS\cuawsppw\reg.png
C:\WINDOWS\cuawsppw\repair.png
C:\WINDOWS\cuawsppw\scr-1.png
C:\WINDOWS\cuawsppw\scr-2.png
C:\WINDOWS\cuawsppw\start.png
C:\WINDOWS\cuawsppw\styles.css
C:\WINDOWS\cuawsppw\Thumbs.db
C:\WINDOWS\cuawsppw\top-rc.gif
C:\WINDOWS\cuawsppw\vline.gif
C:\WINDOWS\cuawsppw\wp.png
C:\WINDOWS\jkdsrwrg.dll
C:\WINDOWS\litgrqfc.dll
C:\WINDOWS\mrofinu72.exe
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\1E.tmp
C:\WINDOWS\system32\cnmlsj.bmp
C:\WINDOWS\system32\dccroits.dll
C:\WINDOWS\system32\etgfqdsjilsrel.bmp
C:\WINDOWS\system32\falcbidcrqh.bmp
C:\WINDOWS\system32\fetgjmlkbmlgb.bmp
C:\WINDOWS\system32\hsjqlcjmh.bmp
C:\WINDOWS\system32\itcnilcnqd.bmp
C:\WINDOWS\system32\jqlcnah.bmp
C:\WINDOWS\system32\kjmdkfepofipoj.bmp
C:\WINDOWS\system32\knapsfidgfihsf.bmp
C:\WINDOWS\system32\L12FE.tmp
C:\WINDOWS\system32\L15EC.tmp
C:\WINDOWS\system32\L707.tmp
C:\WINDOWS\system32\L840.tmp
C:\WINDOWS\system32\mhojihcjipcjap.bmp
C:\WINDOWS\system32\mtcbmtcfqdobmd.bmp
C:\WINDOWS\system32\qhgfapcjqlsb.bmp
C:\WINDOWS\system32\qlkfmlkjml.bmp
C:\WINDOWS\system32\rerydgvc.exe
C:\WINDOWS\system32\rilkjmpon.bmp
C:\WINDOWS\system32\rpurprdp.tmp
C:\WINDOWS\system32\yFOWvyxx.ini
.
((((((((((((((((((((((((( Files Created from 2008-03-18 to 2008-04-18 )))))))))))))))))))))))))))))))
.
2008-04-17 15:15 . 2008-04-18 09:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-17 15:15 . 2008-04-17 15:15 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-17 11:28 . 2008-04-17 11:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-16 12:43 . 2008-04-16 12:43 <DIR> d-------- C:\Program Files\TweakNow RegCleaner Std
2008-04-16 12:42 . 2003-06-25 16:05 266,360 --a------ C:\WINDOWS\system32\TweakUI.exe
2008-04-16 12:42 . 2002-06-21 15:09 160,217 --a------ C:\WINDOWS\system32\PowerToysLicense.rtf
2008-04-16 12:38 . 2008-04-16 12:38 <DIR> d-------- C:\Program Files\RegistryFix
2008-04-15 09:04 . 2008-04-15 09:04 <DIR> d--h----- C:\WINDOWS\PIF
2008-04-15 08:05 . 2008-04-15 08:05 <DIR> d-------- C:\Service Files-Temp
2008-04-14 22:38 . 2008-04-14 22:38 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\U3
2008-04-14 21:04 . 2008-04-14 21:04 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-04-14 20:34 . 2008-04-14 20:34 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\Lavasoft
2008-04-14 17:44 . 2008-04-14 17:44 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\Simply Super Software
2008-04-14 17:32 . 2008-04-16 15:03 <DIR> d-------- C:\Program Files\Trojan Remover
2008-04-14 17:32 . 2008-04-14 17:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-04-14 17:32 . 2008-04-14 17:32 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software
2008-04-14 17:32 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-04-14 17:32 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-04-14 16:48 . 2004-08-10 08:00 146,432 --a------ C:\Documents and Settings\Beth\regedit.exe
2008-04-14 16:48 . 2004-08-10 08:00 27,136 --a------ C:\Documents and Settings\Beth\findstr.exe
2008-04-14 16:48 . 2004-08-10 08:00 11,264 --a------ C:\Documents and Settings\Beth\attrib.exe
2008-04-14 16:48 . 2004-08-10 08:00 9,216 --a------ C:\Documents and Settings\Beth\find.exe
2008-04-14 16:40 . 2008-04-17 14:06 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\U3
2008-04-14 15:46 . 2008-04-14 15:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-04-14 15:27 . 2008-04-17 15:04 5,700 --a------ C:\WINDOWS\system32\Config.MPF
2008-04-14 15:02 . 2008-04-14 15:02 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-04-14 15:01 . 2008-04-14 15:04 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-04-14 15:01 . 2008-04-14 15:01 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\SiteAdvisor
2008-04-14 15:01 . 2008-04-14 15:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-04-14 14:58 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-04-14 14:55 . 2006-12-22 16:02 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-04-14 14:55 . 2006-12-22 16:02 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-04-14 14:55 . 2006-12-22 16:02 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-04-14 14:55 . 2006-12-22 16:02 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-04-14 14:55 . 2006-12-22 16:02 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-04-14 14:54 . 2007-03-02 14:16 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-04-14 14:38 . 2008-04-14 15:13 <DIR> d-------- C:\Program Files\McAfee
2008-04-14 14:34 . 2008-04-14 14:58 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-04-14 14:23 . 2008-04-15 14:49 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-04-14 14:18 . 2008-04-14 14:18 269,334 --a------ C:\WINDOWS\system32\lojahknmlcrat.bmp
2008-04-14 14:04 . 2008-04-14 14:04 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\McAfee
2008-04-14 14:02 . 2008-04-14 15:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-14 13:09 . 2008-04-14 13:09 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\PCToolsFirewallPlus
2008-04-14 13:08 . 2008-04-14 13:08 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\PCToolsSpamMonitorPlus
2008-04-14 12:59 . 2008-04-14 12:59 269,334 --a------ C:\WINDOWS\system32\bepsnet.bmp
2008-04-14 12:44 . 2008-04-14 12:51 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-14 12:38 . 2008-04-14 12:38 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\PCToolsSpamMonitorPlus
2008-04-14 12:38 . 2008-04-14 12:38 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\PCToolsFirewallPlus
2008-04-14 10:59 . 2008-04-15 08:45 20,176 --a------ C:\Documents and Settings\Beth\cftmon.exe
2008-04-14 10:49 . 2008-04-14 10:49 <DIR> d-------- C:\Program Files\Peggle Deluxe
2008-04-13 22:35 . 2008-04-13 22:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\3 Blokes Studios
2008-04-13 22:33 . 2008-04-14 10:49 <DIR> d-------- C:\Program Files\Magical Forest
2008-04-13 15:27 . 2008-04-13 15:27 269,334 --a------ C:\WINDOWS\system32\nmlsbqtsr.bmp
2008-04-13 15:23 . 2008-04-14 17:38 1,705 --ahs---- C:\WINDOWS\system32\wyJilnnn.ini2.ren
2008-04-13 15:23 . 2008-04-14 17:41 1,705 --ahs---- C:\WINDOWS\system32\wyJilnnn.ini.ren
2008-04-13 15:20 . 2008-04-13 15:20 <DIR> d-------- C:\Program Files\RcvSystem
2008-04-13 12:57 . 2008-04-13 12:57 4,286 --a------ C:\WINDOWS\system32\Jamster.ico
2008-04-11 21:34 . 2008-04-11 21:34 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\Cat's Eye Games
2008-04-11 17:02 . 2008-04-11 20:59 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\Restorer
2008-04-09 21:45 . 2008-04-09 21:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Media Art
2008-04-06 00:33 . 2008-04-06 00:33 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-04-05 17:23 . 2008-04-05 17:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PlayPond
2008-04-05 14:17 . 2008-04-05 14:14 77,824 --a------ C:\WINDOWS\system32\kdrhl.exe
2008-04-05 14:16 . 2008-04-15 14:49 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
2008-04-05 14:13 . 2008-04-05 14:13 1,775 --a------ C:\WINDOWS\system32\clbcfg.dat
2008-04-05 14:12 . 2008-04-05 14:12 269,334 --a------ C:\WINDOWS\system32\qtofadgnqd.bmp
2008-04-05 14:05 . 2008-04-05 14:05 7,168 --a------ C:\WINDOWS\system32\drivers\OLD1043.tmp
2008-04-04 23:26 . 2008-04-05 14:55 <DIR> d-------- C:\Program Files\Cooking Academy
2008-04-04 23:13 . 2008-04-04 23:13 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\Ludia
2008-04-04 20:12 . 2008-04-05 14:55 <DIR> d-------- C:\Program Files\Balloon Bliss
2008-04-04 19:42 . 2008-04-05 14:55 <DIR> d-------- C:\Program Files\The Price is Right
2008-04-04 12:10 . 2008-04-05 14:55 <DIR> d-------- C:\Program Files\Mystery P.I. - The Vegas Heist
2008-04-02 00:43 . 2008-04-02 00:43 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\Jane s Hotel Family Hero
2008-04-01 18:36 . 2008-04-06 11:38 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\Boomzap
2008-04-01 18:33 . 2008-04-01 21:50 <DIR> d-------- C:\Program Files\Hoyle Enchanted Puzzles
2008-04-01 18:16 . 2008-04-01 18:16 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\EleFun Games
2008-03-25 17:30 . 2008-03-25 17:30 <DIR> d-------- C:\Program Files\AOL Games
2008-03-25 11:11 . 2008-03-25 11:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Astar Games
2008-03-22 21:36 . 2008-03-23 21:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
2008-03-22 14:08 . 2008-03-22 14:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FireGlow
2008-03-21 18:49 . 2008-03-21 18:49 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\Friday's games
2008-03-19 23:47 . 2008-03-19 23:47 <DIR> d-------- C:\Documents and Settings\Beth\Application Data\iWinArcade
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 18:04 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-14 19:12 --------- d-----w C:\Program Files\McAfee.com
2008-04-14 19:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-04-14 14:49 --------- d-----w C:\Program Files\MySurvey Messenger
2008-04-14 14:49 --------- d-----w C:\Program Files\Google
2008-04-14 01:47 --------- d-----w C:\Program Files\iWin.com
2008-04-13 03:06 --------- d-----w C:\Program Files\MSN Games
2008-04-12 03:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intenium
2008-04-12 02:06 --------- d-----w C:\Program Files\bfgclient
2008-04-10 16:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-04-10 12:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\HipSoft
2008-04-08 20:11 --------- d-----w C:\Documents and Settings\Beth\Application Data\PlayFirst
2008-04-08 20:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-04-07 01:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Gogii
2008-04-05 20:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-04-05 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\DivoGames
2008-04-05 18:53 --------- d-----w C:\Program Files\Napster
2008-04-05 18:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Napster
2008-04-05 18:13 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
2008-04-05 03:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Fugazo
2008-04-02 17:07 --------- d-----w C:\Program Files\GameHouse
2008-04-02 03:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpinTop Games
2008-04-02 03:54 --------- d-----w C:\Documents and Settings\Beth\Application Data\GameHouse
2008-03-26 14:15 --------- d-----w C:\Program Files\Games
2008-03-24 23:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\SugarGames
2008-03-24 20:31 --------- d-----w C:\Documents and Settings\Beth\Application Data\AdobeUM
2008-03-23 16:41 --------- d-----w C:\Documents and Settings\Beth\Application Data\funkitron
2008-03-23 01:17 --------- d-----w C:\Program Files\iWin Games
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-14 02:28 --------- d-----w C:\Program Files\iTunes
2008-03-14 02:27 --------- d-----w C:\Program Files\iPod
2008-03-14 02:25 --------- d-----w C:\Program Files\Bonjour
2008-03-14 02:24 --------- d-----w C:\Program Files\QuickTime
2008-03-14 02:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-14 02:22 --------- d-----w C:\Program Files\Common Files\Apple
2008-03-14 02:22 --------- d-----w C:\Program Files\Apple Software Update
2008-03-14 02:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-03-13 21:25 --------- d-----w C:\Program Files\PlayFirst
2008-03-12 15:58 --------- d-----w C:\Documents and Settings\Beth\Application Data\Spandex Force
2008-03-12 14:39 --------- d-----w C:\Documents and Settings\Beth\Application Data\Meridian93
2008-03-11 03:28 --------- d-----w C:\Documents and Settings\Beth\Application Data\SprillBermudeEng
2008-03-09 05:05 --------- d-----w C:\Documents and Settings\Beth\Application Data\cerasus.media
2008-03-07 14:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Friends Games
2008-03-05 20:52 --------- d-----w C:\Documents and Settings\Beth\Application Data\Big Fish Games
2008-03-05 20:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Big Fish Games
2008-03-03 01:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\MonteCristo
2008-03-02 23:52 0 ----a-w C:\Program Files\temp01
2008-03-02 23:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-02-29 15:59 --------- d-----w C:\Documents and Settings\Beth\Application Data\Fuzzy Games
2008-02-26 13:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\GoBit Games
2008-02-21 04:52 --------- d-----w C:\Documents and Settings\Beth\Application Data\Pirate Stories Kit Ellis
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-18 15:16 30,464 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-02-18 08:17 --------- d-----w C:\Program Files\DIGStream
2008-02-18 05:26 44,288 ----a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-02-17 16:13 270,698 ----a-w C:\WINDOWS\system32\L8617.tmp
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-07 01:24 2,044 ----a-w C:\Documents and Settings\Beth\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-04-17_15.20.35.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-17 19:06:51 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-18 13:24:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-18 13:30:23 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_794.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-12 14:48 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 08:00 15360]
"Mtrgyex"="C:\Program Files\Common Files\?ymantec\?hkdsk.exe" [ ]
"Dmos"="C:\PROGRA~1\COMMON~1\RACLE~1\alg.exe" [ ]
"QdrModule15"="C:\Program Files\QdrModule\QdrModule15.exe" [ ]
"QdrPack15"="C:\Program Files\QdrPack\QdrPack15.exe" [ ]
"tsdligqw"="C:\WINDOWS\system32\rerydgvc.exe" [ ]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 03:32 65536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 07:04 59392]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 04:10 88358 C:\WINDOWS\agrsmmsg.exe]
"00THotkey"="C:\WINDOWS\system32\
00THotkey.exe" [2005-03-01 03:43 245760]
"000StTHK"="000StTHK.exe" [2001-06-23 07:28 24576 C:\WINDOWS\system32\
000StTHK.exe]
"TFncKy"="TFncKy.exe" []
"TFNF5"="TFNF5.exe" [2004-12-15 13:02 73728 C:\WINDOWS\system32\TFNF5.exe]
"TPSMain"="TPSMain.exe" [2005-03-12 01:03 278528 C:\WINDOWS\system32\TPSMain.exe]
"TPSODDCtl"="TPSODDCtl.exe" [2005-03-12 01:03 110592 C:\WINDOWS\system32\TPSODDCtl.exe]
"NDSTray.exe"="NDSTray.exe" []
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-01-14 04:05 122939]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 19:37 151552]
"CFSServ.exe"="CFSServ.exe" []
"DXDllRegExe"="dxdllreg.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-12-22 07:29 67752]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 16:30 152144]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6145\SiteAdv.exe" [2007-06-21 16:06 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-01-19 17:11 1082920]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-04-05 19:25 73728]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2003-01-21 21:00 126976]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-15 19:51 122880]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 17:03 1077301]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-08-06 11:27 860160]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 12:11 1388544]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 14:27 385024]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2004-03-24 01:40 196608]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-04-15 20:31 5918720]
C:\Documents and Settings\Beth\Start Menu\Programs\Startup\
Bat - Auto Update.lnk - C:\QooBox\Quarantine\C\Program Files\Bat\Bat.exe.vir [2008-04-13 15:19:41 178419]
iWin Desktop Alerts.lnk - C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe [2007-12-21 12:43:10 58368]
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2004-06-12 00:57:52 59080]
MySurvey Messenger.lnk - C:\Program Files\MySurvey Messenger\MySurveyMessenger.exe [2007-03-23 21:13:45 462848]
wkcalrem.LNK - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-06-23 20:23:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 09:19:24 237568]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-05-10 13:27:11 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 14:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnljgHw]
pmnljgHw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= C:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"=
"C:\\WINDOWS\\system32\\mshta.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\iWin Games\\iWinGames.exe"=
"C:\\Program Files\\iWin Games\\WebUpdater.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys [2005-01-12 04:05]
R2 iWinGamesInstaller;iWinGamesInstaller;C:\Program Files\iWin Games\iWinGamesInstaller.exe [2008-03-05 08:49]
R3 ttv300x;TOSHIBA PCI TV Tuner;C:\WINDOWS\system32\drivers\ttv300x.sys [2005-05-12 13:33]
S2 OneStep Search Service;OneStep Search Service;"C:\Program Files\OneStepSearch\onestep.exe" "C:\Program Files\OneStepSearch\onestep.dll" Service []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-04-09 13:08:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-14 18:49:53 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-04-14 18:49:52 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-18 09:39:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\svchost.ex_:exe.exe 28160 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2008-04-18 9:42:21
ComboFix-quarantined-files.txt 2008-04-18 13:41:57
ComboFix2.txt 2008-04-17 19:21:07
Pre-Run: 74,790,727,680 bytes free
Post-Run: 74,775,392,256 bytes free
.
2008-04-09 07:07:43 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:33, on 2008-04-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SiteAdvisor\6145\SAService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\00THotkey.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\SiteAdvisor\6145\SiteAdv.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
C:\Program Files\MySurvey Messenger\MySurveyMessenger.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy.paintsville.kyschools.us:8080;https=proxy.paintsville.kyschools.us:80
80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.180.16.8;<local>;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6145\SiteAdv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6145\SiteAdv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPSODDCtl] TPSODDCtl.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MskAgentexe] "C:\Program Files\McAfee\MSK\MskAgent.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6145\SiteAdv.exe"
O4 - HKLM\..\Run: [McENUI] "C:\PROGRA~1\McAfee\MHN\McENUI.exe" /hide
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Tvs] "C:\Program Files\Toshiba\Tvs\TvsTray.exe"
O4 - HKLM\..\Run: [TouchED] "C:\Program Files\TOSHIBA\TouchED\TouchED.Exe"
O4 - HKLM\..\Run: [SmoothView] "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe"
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Mtrgyex] "C:\Program Files\Common Files\?ymantec\?hkdsk.exe"
O4 - HKCU\..\Run: [Dmos] "C:\PROGRA~1\COMMON~1\RACLE~1\alg.exe" -vt yazb
O4 - HKCU\..\Run: [QdrModule15] "C:\Program Files\QdrModule\QdrModule15.exe"
O4 - HKCU\..\Run: [QdrPack15] "C:\Program Files\QdrPack\QdrPack15.exe"
O4 - HKCU\..\Run: [tsdligqw] C:\WINDOWS\system32\rerydgvc.exe
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 - Startup: Bat - Auto Update.lnk = C:\QooBox\Quarantine\C\Program Files\Bat\Bat.exe.vir
O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Startup: MySurvey Messenger.lnk = C:\Program Files\MySurvey Messenger\MySurveyMessenger.exe
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - Trusted Zone:
http://*.mcafee.comO16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Mystery P.I. - The Vegas Heist\Images\stg_drm.ocx
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} (SDANetConClass Class) - file://C:\Program Files\Mystery Solitaire\Images\stg_drm.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1005.cabO16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) -
http://zone.msn.com/...h2.1.0.0.55.cabO16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} -
http://a19.g.akamai....son/Coupons.cabO16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) -
http://offers.e-cent...bin/actxcab.cabO16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) -
http://games.bigfish...esPlayer_v4.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn...ro.cab56649.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://aolsvc.aol.co...zylomplayer.cabO16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) -
http://zone.msn.com/...ersion=1,0,0,10O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Sally's Salon\Images\armhelper.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E466669-1A9A-4E31-81C1-DF4B9F97A8C0}: NameServer = 85.255.115.107,85.255.112.217
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A372CB2-3228-453C-901F-B9B69A2CEEA4}: NameServer = 85.255.115.107,85.255.112.217
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBF4906A-E583-4985-90CF-4B167BB8D05B}: NameServer = 85.255.115.107,85.255.112.217
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.107 85.255.112.217
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.107 85.255.112.217
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.115.107 85.255.112.217
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.107 85.255.112.217
O20 - Winlogon Notify: pmnljgHw - pmnljgHw.dll (file missing)
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OneStep Search Service - Unknown owner - C:\Program Files\OneStepSearch\onestep.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6145\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
--
End of file - 15111 bytes