ComboFix 08-05-01.3 - Soo 2008-05-04 20:55:26.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.949.82.1033.18.2099 [GMT 1:00]
Running from: C:\Users\Soo\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-04-04 to 2008-05-04 )))))))))))))))))))))))))))))))
.
2008-05-04 10:10 . 2008-05-04 10:10 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-03 18:18 . 2008-05-03 18:18 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-03 15:45 . 2008-05-03 15:45 <DIR> d-------- C:\Users\Soo\AppData\Roaming\Download Manager
2008-04-23 15:19 . 2008-04-23 15:19 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-04 19:51 --------- d---a-w C:\ProgramData\TEMP
2008-05-03 11:50 --------- d-----w C:\Program Files\Java
2008-05-03 09:39 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-24 12:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-10 15:39 --------- d-----w C:\Users\Soo\AppData\Roaming\Skype
2008-04-10 15:07 --------- d-----w C:\Users\Soo\AppData\Roaming\skypePM
2008-04-09 08:29 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-09 08:29 --------- d-----w C:\Program Files\Windows Mail
2008-04-01 14:07 1,531,904 ----a-r C:\Windows\System32\clubbox.exe
2008-04-01 14:06 155,648 ----a-r C:\Windows\System32\downengine.dll
2008-03-26 17:42 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-03-22 20:23 --------- d-----w C:\Program Files\Common Files\snp2std
2008-03-22 20:23 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-19 23:24 --------- d-----w C:\Users\Soo\AppData\Roaming\yahoo!
2008-03-19 23:24 --------- d-----w C:\ProgramData\Yahoo!
2008-03-19 23:23 --------- d-----w C:\Program Files\Yahoo!
2008-03-19 23:20 --------- d-----w C:\ProgramData\NVIDIA
2008-03-19 23:19 174 --sha-w C:\Program Files\desktop.ini
2008-03-19 23:12 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-19 23:12 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-03-19 23:12 --------- d-----w C:\Program Files\Windows Journal
2008-03-19 23:12 --------- d-----w C:\Program Files\Windows Defender
2008-03-19 23:12 --------- d-----w C:\Program Files\Windows Collaboration
2008-03-19 23:12 --------- d-----w C:\Program Files\Windows Calendar
2008-03-19 21:38 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-03-19 21:38 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-03-19 18:55 --------- d-----w C:\ProgramData\Skype
2008-03-19 18:55 --------- d-----w C:\Program Files\Skype
2008-03-19 18:55 --------- d-----w C:\Program Files\Common Files\Skype
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-28 10:57 1,622,016 ----a-r C:\Windows\System32\pdbox28.exe
2008-02-25 16:24 159,744 ----a-r C:\Windows\System32\fscagent.exe
2008-02-22 05:05 615,992 ----a-w C:\Windows\System32\ci.dll
2008-02-22 05:01 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-02-22 04:57 295,936 ----a-w C:\Windows\System32\gdi32.dll
2008-02-06 07:18 32 ----a-w C:\Users\All Users\ezsid.dat
2008-02-06 07:18 32 ----a-w C:\ProgramData\ezsid.dat
2007-11-09 12:24 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-11-09 12:24 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-11-09 12:24 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 08:33 125952]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 08:33 1233920]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 18:43 4670704]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 08:38 1008184]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-25 07:03 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 08:22 4907008 C:\Windows\RtHDVCpl.exe]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 20:40 16384]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 21:16 286720]
"ClubBox"="" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-16 15:00 185896]
"Korean IME Migration"="C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE" [2006-10-26 15:53 26400]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 18:24 1065800]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 09:07 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-17 09:07 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 09:07 81920]
"tsnp2std"="C:\Windows\tsnp2std.exe" [2006-07-07 16:04 258048]
"snp2std"="C:\Windows\vsnp2std.exe" [2006-07-10 18:33 675840]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-11 19:15 101136 C:\Windows\KHALMNPR.Exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4053F49B-C7B2-4115-B2FF-58A47B3B9B2F}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{7A38F620-B9AA-4BCA-B1B9-1185F3E10624}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{F41305C3-1BB0-4807-88EA-9BC3B782AE25}C:\\windows\\system32\\fscagent.exe"= UDP:C:\windows\system32\fscagent.exe:FSCAgent Service program
"UDP Query User{3AC9FBF5-E35F-4490-8B17-72F11D7188BA}C:\\windows\\system32\\fscagent.exe"= TCP:C:\windows\system32\fscagent.exe:FSCAgent Service program
"TCP Query User{54FB1721-4F62-475A-ABE3-9F8425D464A8}C:\\windows\\system32\\grdmgr.exe"= UDP:C:\windows\system32\grdmgr.exe:나우콤 캐쉬 매니저
"UDP Query User{3B6B6F1F-94E6-48BB-84B6-7A9280F0DD20}C:\\windows\\system32\\grdmgr.exe"= TCP:C:\windows\system32\grdmgr.exe:나우콤 캐쉬 매니저
"TCP Query User{11BEE21A-7F41-408E-93D4-E9033599F7F7}C:\\windows\\system32\\clubbox.exe"= UDP:C:\windows\system32\clubbox.exe:CLUBBOX File Transfer Manager V2
"UDP Query User{1F3E65B3-73C5-43FD-8FB2-1025530BF8D6}C:\\windows\\system32\\clubbox.exe"= TCP:C:\windows\system32\clubbox.exe:CLUBBOX File Transfer Manager V2
"TCP Query User{18266E97-0877-4816-BFB2-21D908868DF7}C:\\users\\soo\\downloads\\pdman_client13-lwoals.exe"= UDP:C:\users\soo\downloads\pdman_client13-lwoals.exe:pdman_client13-lwoals.exe
"UDP Query User{2FF811D9-DEFD-4E63-8DF5-B6ECF0F4254B}C:\\users\\soo\\downloads\\pdman_client13-lwoals.exe"= TCP:C:\users\soo\downloads\pdman_client13-lwoals.exe:pdman_client13-lwoals.exe
"TCP Query User{41D4B063-1F05-4164-81F1-1E2A727305A4}C:\\users\\soo\\desktop\\pdmanclient 1.3.exe"= UDP:C:\users\soo\desktop\pdmanclient 1.3.exe:pdmanclient 1.3.exe
"UDP Query User{1C65DEDB-B07D-47FD-9C5F-D4673AB135B7}C:\\users\\soo\\desktop\\pdmanclient 1.3.exe"= TCP:C:\users\soo\desktop\pdmanclient 1.3.exe:pdmanclient 1.3.exe
"TCP Query User{45EFBEB5-F312-4021-B014-4080F8D55443}C:\\windows\\system32\\pdbox28.exe"= UDP:C:\windows\system32\pdbox28.exe:PDBOX File Transfer Manager
"UDP Query User{3CB634DB-A5FE-40EC-88A3-DB20E2A2CCD7}C:\\windows\\system32\\pdbox28.exe"= TCP:C:\windows\system32\pdbox28.exe:PDBOX File Transfer Manager
"TCP Query User{15B07B82-21FB-404B-9AAD-236C42065C7A}C:\\program files\\gretech\\gomplayer\\gom.exe"= UDP:C:\program files\gretech\gomplayer\gom.exe:GOM Player
"UDP Query User{5B697877-8E39-4BF8-8D19-E7AFE2A9FB2C}C:\\program files\\gretech\\gomplayer\\gom.exe"= TCP:C:\program files\gretech\gomplayer\gom.exe:GOM Player
"{E42717E9-3E32-49E9-BF3D-2531DD14095B}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{B7C9BCD7-9185-4F6F-8CA0-44852D6F027A}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{A3F0DDE9-E211-4217-BBC0-9DBAE0AFCCD4}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"TCP Query User{1A58B3DB-25A5-4505-A464-078426461090}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3279D664-1579-4043-8C62-9A581688890A}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{2B60C285-580B-49D9-ABA6-1D3873C7616A}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B8BBE193-D893-494B-B2FD-82CFE9A317A2}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{7ECFCFAD-D2A1-41D5-84CD-4D44967913F3}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{3700968A-9B88-4FBC-8C2C-07A896F1412C}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{825D861D-155C-4B26-B44C-E758A4FF8536}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{46900148-41C6-4C5E-AD3E-8DC6417D06CF}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{DC988308-863B-44E0-9C6F-5F727560F109}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{0C901D33-487B-45AD-BC48-15B3EDA1796B}C:\\users\\soo\\desktop\\pdbox search.exe"= UDP:C:\users\soo\desktop\pdbox search.exe:pdbox search.exe
"UDP Query User{D5406BFD-0623-480F-B797-57A4044AD0E9}C:\\users\\soo\\desktop\\pdbox search.exe"= TCP:C:\users\soo\desktop\pdbox search.exe:pdbox search.exe
"{1A58B957-E7ED-4E2E-89B1-BBB2DC4AA6B0}"= UDP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{A14D32A7-2335-4C00-A87E-7912BBCCC32E}"= TCP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{4A2381E1-4643-456B-B33E-C589DB9CC9EC}"= UDP:C:\Program Files\AOL 9.0\waol.exe:AOL
"{C3DAAF28-DC29-44F5-A482-83A36B9F6B0A}"= TCP:C:\Program Files\AOL 9.0\waol.exe:AOL
"{48BF1874-DC4A-4855-B990-B9E54871A0B9}"= UDP:C:\Program Files\AOL 9.0\waol.exe:AOL
"{64356C8D-7290-4431-9AF7-B743F4384472}"= TCP:C:\Program Files\AOL 9.0\waol.exe:AOL
"{35AFD13F-19E3-49DF-AEF7-F20104013611}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{91CA7135-2DB1-437E-AD7F-AB0C9C9464F6}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{9B8D3218-0704-4549-9A04-758CFC293928}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{89E9650B-1D1F-49AF-941D-2595AF829BF1}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{67003152-7D37-4FB1-AAC3-D11851B7FAE2}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{9D735875-BB98-4F3A-9920-9A063A879F15}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{AFF3EB1B-9945-4BC3-8882-E02B8D2B397A}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{654A5360-4331-47BD-A95A-C88ACCE01570}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"TCP Query User{FFDDE738-C370-4AF5-9CB1-834261E2582B}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{8B44D11E-09F5-41E8-8B5C-06073390E302}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"TCP Query User{F5054044-45B2-4838-A505-0207ECB36C5C}C:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{1D937DBE-80F2-4395-8014-FC27D30D9F30}C:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{66ECCCEE-528A-4B72-822D-919455B69B69}C:\\program files\\sopcast\\sopcast.exe"= UDP:C:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{235AEBA7-6E59-414D-A91E-3E826D3E4B8E}C:\\program files\\sopcast\\sopcast.exe"= TCP:C:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{37E1FFF5-0E13-485A-B5CE-7645670DA3D7}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{7DC1C6E6-8D69-493B-9D5D-08631D952D40}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{A39891EA-D860-4570-90D3-A4EF14470BCC}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{19CB1D71-F980-480F-B255-BD81ACDDFB26}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R2 AERTFilters;Andrea RT Filters Service;C:\Windows\system32\AERTSrv.exe [2007-12-05 07:17]
R3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 08:30]
S3 NOWMEMDF;NOWMEMDF;C:\Windows\system32\NOWMEMDF.sys [2005-11-02 12:23]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 08:36]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\Windows\system32\DRIVERS\snp2sxp.sys [2006-08-04 16:30]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-04 19:41:24 C:\Windows\Tasks\User_Feed_Synchronization-{82E3D4F3-D41D-495A-B439-DE56E6FD9389}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-04 20:58:18
Windows 6.0.6001 Service Pack 1 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 5
**************************************************************************
.
Completion time: 2008-05-04 20:59:31
ComboFix-quarantined-files.txt 2008-05-04 19:59:26
Pre-Run: 241,123,782,656 bytes free
Post-Run: 241,094,942,720 bytes free
187 --- E O F --- 2008-05-03 10:13:10
and heres my new hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:10:07, on 04/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\vsnp2std.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Korean IME Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [tsnp2std] C:\Windows\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - ESC Trusted Zone:
http://*.update.microsoft.comO16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) -
http://www.clubbox.c.../NowStarter.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail....NPUplden-gb.cabO16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx...owserPlugin.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 6120 bytes