< HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices\\Internet Firewall Layer >
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices\\Internet Firewall Layer deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices\\Internet Security Service >
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices\\Internet Security Service deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices\\Windows USB Monitor >
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices\\Windows USB Monitor deleted successfully.
File/Folder C:\Windows\tsqla.exe not found.
File/Folder C:\Windows\system32\tsqla.exe not found.
File/Folder C:\Windows\mysqlwin32.exe not found.
File/Folder C:\Windows\system32\mysqlwin32.exe not found.
File/Folder C:\Windows\servupdate.exe not found.
File/Folder C:\Windows\system32\servupdate.exe not found.
< HKEY_USERS\.default\software\microsoft\windows\currentversion\run\\nvcoi >
Registry value HKEY_USERS\.default\software\microsoft\windows\currentversion\run\\nvcoi deleted successfully.
< HKEY_USERS\.default\software\microsoft\windows\currentversion\run\\JavaCore >
Registry value HKEY_USERS\.default\software\microsoft\windows\currentversion\run\\JavaCore deleted successfully.
< HKEY_USERS\.default\software\microsoft\windows\currentversion\run\\Windows Service Agent >
Registry value HKEY_USERS\.default\software\microsoft\windows\currentversion\run\\Windows Service Agent deleted successfully.
File/Folder C:\Program Files\nvcoi not found.
File/Folder C:\Program Files\\JavaCore not found.
File/Folder C:\Windows\msngear.exe not found.
File/Folder C:\Windows\system32\msngear.exe not found.
File/Folder C:\WINDOWS\TEMP\DIL4.tmp not found.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoInclude >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoInclude\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fafa >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fafa\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Firewall Layer >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Firewall Layer\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Security Service >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Security Service\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pronto >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pronto\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1 >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1\\ deleted successfully.
File/Folder C:\WINDOWS\mrofinu1001186.exe not found.
File/Folder C:\WINDOWS\mrofinu1001186.exe.tmp not found.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDFix >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDFix\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinDLL (msygl32.exe)] >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinDLL (msygl32.exe)]\\ not found.
File/Folder C:\WINDOWS\system32\msygl32.exe not found.
< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\z0ogu >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\z0ogu\\ deleted successfully.
File/Folder F:\infrom.exe not found.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6a7247cc-e7c6-11dc-b9f7-0016178cdd58} >
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6a7247cc-e7c6-11dc-b9f7-0016178cdd58}\\ deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{821d6136-0189-11dd-ba43-0016178cdd58} >
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{821d6136-0189-11dd-ba43-0016178cdd58}\\ deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5b110b4-d74d-11dc-b9c9-0016178cdd58} >
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5b110b4-d74d-11dc-b9c9-0016178cdd58}\\ deleted successfully.
File/Folder F:\azkaban.vbs not found.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3f8c1e0-15fa-11dd-ba9d-0016178cdd58} >
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3f8c1e0-15fa-11dd-ba9d-0016178cdd58}\\ deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3f8c1df-15fa-11dd-ba9d-0016178cdd58} >
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3f8c1df-15fa-11dd-ba9d-0016178cdd58}\\ deleted successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05042008_155609
ComboFix 08-05-01.3 - Myds 2008-05-04 16:08:21.1 - NTFSx86
Running from: C:\Documents and Settings\Myds.MENLO-G9WECL961\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\b999.exe
C:\WINDOWS\explorer.exe.tmp
C:\WINDOWS\system32\tf5
C:\WINDOWS\system32\tf5\xopz89104.exe
C:\WINDOWS\system32\xk1
C:\WINDOWS\system32\zeb3
.
((((((((((((((((((((((((( Files Created from 2008-04-04 to 2008-05-04 )))))))))))))))))))))))))))))))
.
2008-05-04 15:29 . 2008-05-04 15:30 <DIR> d-------- C:\WINDOWS\LastGood
2008-05-04 15:29 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-05-04 15:29 . 2003-02-28 18:26 46,352 --a------ C:\WINDOWS\setdebug.exe
2008-05-04 15:29 . 2003-02-28 16:54 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2008-05-04 15:29 . 2003-02-28 16:35 6,550 --a------ C:\WINDOWS\jautoexp.dat
2008-05-04 15:29 . 2003-02-28 16:38 113 --a------ C:\WINDOWS\system32\zonedon.reg
2008-05-04 15:29 . 2003-02-28 16:38 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2008-05-03 11:05 . 2008-05-03 11:05 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-01 20:01 . 2008-05-02 14:55 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-05-01 20:01 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-29 16:55 . 2008-04-29 16:55 <DIR> d-------- C:\Program Files\FreeRIP2
2008-04-29 16:53 . 2008-04-29 16:55 <DIR> d-------- C:\Program Files\FairStars CD Ripper
2008-04-29 14:46 . 2008-04-29 14:46 <DIR> d-------- C:\Documents and Settings\Des Chanel.MENLO-G9WECL961\Application Data\AdobeUM
2008-04-29 14:42 . 2008-04-29 14:42 <DIR> d-------- C:\Documents and Settings\Elijah James\Application Data\AVG7
2008-04-29 14:07 . 2008-04-29 14:07 <DIR> d-------- C:\Documents and Settings\Myds.MENLO-G9WECL961\Application Data\Ahead
2008-04-29 14:05 . 2008-04-29 14:05 1,024 --ah----- C:\Documents and Settings\Default User\NtUser.dat.LOG
2008-04-29 14:05 . 2008-05-04 16:08 1,024 --ah----- C:\Documents and Settings\Default User.WINDOWS\NtUser.dat.LOG
2008-04-29 14:04 . 2001-07-06 06:41 569,344 -ra------ C:\WINDOWS\system32\imagr5.dll
2008-04-29 14:04 . 2001-07-06 04:44 544,768 -ra------ C:\WINDOWS\system32\imagx5.dll
2008-04-29 14:04 . 2001-07-06 10:24 283,920 -ra------ C:\WINDOWS\system32\ImagXpr5.dll
2008-04-29 14:04 . 2001-07-09 03:50 155,648 -ra------ C:\WINDOWS\system32\NeroCheck.exe
2008-04-29 14:04 . 2001-06-26 00:15 38,912 -ra------ C:\WINDOWS\system32\picn20.dll
2008-04-29 13:46 . 2008-04-29 13:46 <DIR> d-------- C:\Documents and Settings\Myds.MENLO-G9WECL961\Application Data\CyberLink
2008-04-29 13:43 . 2008-04-29 13:43 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2008-04-29 07:47 . 2008-04-29 07:47 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-04-29 07:25 . 2001-08-23 04:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-04-29 07:24 . 2001-08-23 04:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-04-29 07:23 . 2001-08-23 04:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-04-29 07:22 . 2004-08-03 15:56 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-04-29 07:20 . 2001-08-23 04:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-04-29 07:20 . 2008-04-29 07:20 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-04-29 07:20 . 2008-04-29 07:20 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-04-29 07:20 . 2008-04-29 07:20 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-04-29 07:20 . 2008-04-29 07:20 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-04-29 07:20 . 2008-04-29 07:20 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-04-29 07:20 . 2008-04-29 07:20 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-04-29 07:11 . 2003-07-01 13:42 27,904 --a------ C:\WINDOWS\system32\drivers\VIAAGP1.SYS
2008-04-29 04:34 . 2008-04-29 04:34 0 --a------ C:\23990098.$$$
2008-04-29 01:52 . 2008-04-29 02:37 <DIR> d-------- C:\Downloads
2008-04-29 01:52 . 2008-04-29 02:37 <DIR> d-------- C:\Bases
2008-04-29 01:51 . 2008-04-29 05:39 <DIR> d-------- C:\Kaspersky
2008-04-28 22:55 . 2008-04-30 06:35 <DIR> dr-h----- C:\$VAULT$.AVG
2008-04-28 21:40 . 2008-05-02 12:26 <DIR> d-------- C:\Documents and Settings\Des Chanel.MENLO-G9WECL961\Application Data\AVG7
2008-04-28 19:53 . 2008-04-28 19:53 <DIR> d-------- C:\Program Files\iTunes
2008-04-28 19:41 . 2008-04-28 19:41 <DIR> d-------- C:\Documents and Settings\Myds.MENLO-G9WECL961\Application Data\Apple Computer
2008-04-28 19:35 . 2008-04-28 19:35 <DIR> d-------- C:\Program Files\QuickTime
2008-04-28 18:39 . 2008-04-28 18:39 <DIR> d-------- C:\Documents and Settings\Myds.MENLO-G9WECL961\Application Data\AdobeUM
2008-04-28 18:36 . 2008-04-28 18:36 <DIR> d-------- C:\WINDOWS\Cache
2008-04-28 17:55 . 2008-04-28 18:00 <DIR> d-------- C:\Documents and Settings\Myds.MENLO-G9WECL961\DoctorWeb
2008-04-28 13:58 . 2008-04-28 13:58 <DIR> d-------- C:\_OTMoveIt
2008-04-24 11:53 . 2008-04-24 11:53 <DIR> d-------- C:\Deckard
2008-04-24 10:00 . 2008-04-24 10:00 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-24 09:48 . 2008-04-24 09:48 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-24 09:47 . 2008-04-29 07:13 <DIR> d-------- C:\SDFix
2008-04-23 16:01 . 2008-05-04 15:19 <DIR> d-------- C:\Documents and Settings\Myds.MENLO-G9WECL961\Application Data\AVG7
2008-04-21 13:34 . 2008-04-21 13:34 <DIR> d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\AVG7
2008-04-21 13:34 . 2008-04-29 07:46 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2008-04-21 11:22 . 2008-04-21 11:22 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-21 11:20 . 2008-04-21 11:21 172 --a------ C:\WINDOWS\wininit.ini
2008-04-21 10:43 . 2008-04-29 07:47 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-21 10:43 . 2008-05-04 16:08 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-09 17:53 . 2008-04-09 17:53 111,616 --ah----- C:\WINDOWS\system32\len.exe
2008-04-08 22:23 . 2008-04-08 22:23 111,616 --ah----- C:\WINDOWS\system32\jer.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-29 21:04 --------- d-----w C:\Program Files\Ahead
2008-04-29 12:54 --------- d-----w C:\Program Files\Winamp
2008-04-29 10:14 --------- d-----w C:\Program Files\kari
2008-04-29 02:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-29 02:53 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2008-04-29 01:39 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 21:35 33,952 ----a-w C:\WINDOWS\system32\drivers\oreans32.sys
2008-03-26 06:56 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-26 06:56 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-03-26 06:30 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2004-08-03 22:56 168,960 --sha-r C:\WINDOWS\system32\bqrr.exe
2004-08-03 22:56 168,960 --sha-r C:\WINDOWS\system32\brnj.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 01:22 577536 C:\WINDOWS\SOUNDMAN.EXE]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-29 07:47 579584]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-04-28 19:35 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 16:24 278528]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 03:50 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-29 07:47 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 13:59 44544]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 09:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinDLL (msygl32.exe)]
C:\WINDOWS\system32\msygl32.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2008-04-28 14:35]
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys []
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-04 16:10:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-04 16:11:46
ComboFix-quarantined-files.txt 2008-05-04 23:11:44
Pre-Run: 28,459,929,600 bytes free
Post-Run: 28,687,011,840 bytes free
153 --- E O F --- 2008-05-04 22:30:07
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:18:26 PM, on 5/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{A7F2600D-2596-48BC-B361-72DD753419B0}: NameServer = 58.69.254.3,58.69.254.8
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 4246 bytes