ComboFix 08-05-09.1 - Yam 2008-05-11 18:55:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.437 [GMT 3:00]
Running from: C:\Documents and Settings\Yam\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\bmmuxkws.dll
C:\WINDOWS\system32\cbyfieav.dll
C:\WINDOWS\system32\chbqfysu.ini
C:\WINDOWS\system32\cxprcoes.ini
C:\WINDOWS\system32\felqiptr.ini
C:\WINDOWS\system32\fopjqgcg.ini
C:\WINDOWS\system32\giwdiset.ini
C:\WINDOWS\system32\jbvqacsd.ini
C:\WINDOWS\system32\jdqupcpf.ini
C:\WINDOWS\system32\lalqmceu.dll
C:\WINDOWS\system32\lRYycMoq.ini
C:\WINDOWS\system32\lRYycMoq.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ntyyydex.ini
C:\WINDOWS\system32\okyrelmc.ini
C:\WINDOWS\system32\Onnnqtwa.ini
C:\WINDOWS\system32\Onnnqtwa.ini2
C:\WINDOWS\system32\qoMcyYRl.dll
C:\WINDOWS\system32\qwdteemn.ini
C:\WINDOWS\system32\seocrpxc.dll
C:\WINDOWS\system32\service.exe
C:\WINDOWS\system32\swkxummb.ini
C:\WINDOWS\system32\tesidwig.dll
C:\WINDOWS\system32\uecmqlal.ini
C:\WINDOWS\system32\uibtkptf.ini
C:\WINDOWS\system32\vaeifybc.ini
C:\WINDOWS\system32\xedyyytn.dll
C:\WINDOWS\system32\xwjiciqv.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
.
C:\ComboFix\CreateC00.bat .
2008-05-10 21:39 . 2008-05-10 21:46 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-05-10 21:39 . 2008-05-10 21:39 <DIR> d-------- C:\Documents and Settings\Yam\Application Data\PC Tools
2008-05-10 21:39 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-05-10 21:39 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-05-10 21:39 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-05-10 21:39 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-05-10 21:21 . 2008-05-10 21:21 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-10 11:56 . 2008-05-10 11:56 <DIR> d-------- C:\Documents and Settings\Yam\.tuxguitar-1.0-rc4
2008-05-10 11:53 . 2008-05-10 11:53 <DIR> d-------- C:\Program Files\tuxguitar-1.0-rc4
2008-05-10 08:18 . 2008-05-10 08:18 <DIR> d-------- C:\Program Files\Eidos Interactive
2008-05-07 12:24 . 2008-05-11 19:40 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-07 12:24 . 2008-05-07 12:24 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-04 19:03 . 2008-05-04 19:03 268 --ah----- C:\sqmdata07.sqm
2008-05-04 19:03 . 2008-05-04 19:03 244 --ah----- C:\sqmnoopt07.sqm
2008-04-30 16:40 . 2008-04-30 16:40 <DIR> d-------- C:\Program Files\blueprint
2008-04-29 20:50 . 2008-04-29 20:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-29 20:47 . 2008-04-29 20:47 <DIR> d-------- C:\VundoFix Backups
2008-04-27 13:36 . 2008-05-01 18:30 270,336 --a------ C:\WINDOWS\system32\imon.dll
2008-04-26 17:25 . 1994-09-21 01:00 92,208 --a------ C:\WINDOWS\system32\WING.DLL
2008-04-26 17:25 . 1994-09-21 01:00 12,800 --a------ C:\WINDOWS\system32\WING32.DLL
2008-04-26 13:09 . 2008-04-26 13:10 149 --a------ C:\WINDOWS\wininit.ini
2008-04-26 10:08 . 2008-04-26 10:00 691,545 --a------ C:\WINDOWS\unins000.exe
2008-04-26 10:08 . 2008-04-26 10:08 2,548 --a------ C:\WINDOWS\unins000.dat
2008-04-25 09:58 . 1994-08-24 01:00 188,960 --a------ C:\WINDOWS\system\WINGDE.DLL
2008-04-25 09:58 . 1994-09-21 01:00 92,208 --a------ C:\WINDOWS\system\WING.DLL
2008-04-25 09:58 . 1995-07-14 02:43 27,632 --a------ C:\WINDOWS\system\CTL3DV2.DLL
2008-04-25 09:58 . 1994-09-21 01:00 12,800 --a------ C:\WINDOWS\system\WING32.DLL
2008-04-25 09:58 . 1994-09-21 01:00 6,736 --a------ C:\WINDOWS\system\WINGDIB.DRV
2008-04-25 09:58 . 1994-09-21 01:00 5,024 --a------ C:\WINDOWS\system\WINGPAL.WND
2008-04-25 09:58 . 1994-06-27 01:00 1,966 --a------ C:\WINDOWS\system\DVA.386
2008-04-25 09:58 . 2008-04-25 09:58 42 --a------ C:\WINDOWS\ODDBALLZ.INI
2008-04-25 09:57 . 2008-04-25 09:59 <DIR> d-------- C:\ODDBALLZ.YAM
2008-04-24 09:27 . 2008-04-24 09:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-04-24 09:19 . 2008-04-24 09:19 <DIR> d-------- C:\Program Files\WinImage
2008-04-24 07:26 . 2008-04-24 07:26 <DIR> d-------- C:\New Folder
2008-04-24 07:25 . 2008-04-24 07:25 <DIR> d-------- C:\GMOD10
2008-04-23 21:46 . 2008-04-23 21:46 <DIR> d-------- C:\Program Files\iTunes
2008-04-23 21:46 . 2008-04-23 21:46 <DIR> d-------- C:\Program Files\iPod
2008-04-23 21:44 . 2008-04-23 21:45 <DIR> d-------- C:\Program Files\QuickTime
2008-04-23 21:41 . 2008-04-23 21:41 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-23 11:49 . 2008-04-23 11:55 <DIR> d-------- C:\Program Files\Phun
2008-04-23 10:50 . 2008-05-05 12:47 325 --a------ C:\TIM.SAV
2008-04-23 10:50 . 2008-05-05 12:47 249 --a------ C:\timwin.ini
2008-04-23 10:50 . 2008-04-23 10:50 246 --a------ C:\WINDOWS\SIERRA.INI
2008-04-23 10:49 . 2008-04-23 10:49 <DIR> d-------- C:\Documents and Settings\Yam\tim95
2008-04-23 10:21 . 2008-04-23 10:21 <DIR> d-------- C:\Program Files\Eidos
2008-04-23 09:14 . 2008-04-23 09:14 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-04-21 18:20 . 2008-04-21 18:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Corel
2008-04-21 18:20 . 2008-04-23 09:26 88 -rahs---- C:\WINDOWS\system32\121B949DE1.sys
2008-04-21 18:06 . 2008-04-21 18:06 274,432 --a------ C:\WINDOWS\system32\awtqnnnO.dll_old
2008-04-21 18:01 . 2008-04-23 09:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\hyheribu
2008-04-21 18:01 . 2008-04-21 18:01 38,400 --a------ C:\WINDOWS\system32\khfCtRlJ.dll
2008-04-12 11:10 . 2008-04-12 11:34 <DIR> d-------- C:\gmod
2008-04-11 15:10 . 2008-04-11 15:11 <DIR> d-------- C:\Program Files\Valve Hammer Editor
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 17:27 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-11 15:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-11 15:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-05-11 14:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-10 18:35 --------- d-----w C:\Documents and Settings\Yam\Application Data\iMesh
2008-05-10 05:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-03 06:23 --------- d-----w C:\Program Files\Eset
2008-05-01 15:30 502,368 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-04-29 17:45 --------- d-----w C:\Program Files\NCH Software
2008-04-29 16:03 --------- d-----w C:\Documents and Settings\Yam\Application Data\AVG7
2008-04-29 14:52 --------- d-----w C:\Program Files\DOSBox-0.72
2008-04-28 19:33 --------- d-----w C:\Program Files\ICQToolbar
2008-04-26 14:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-04-26 12:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-26 07:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-24 06:23 --------- d-----w C:\Program Files\UBISOFT
2008-04-23 06:56 7,308 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-04-23 06:12 --------- d-----w C:\Program Files\Common Files\Real
2008-04-23 06:06 --------- d-----w C:\Program Files\Free Download Manager
2008-04-23 06:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-23 06:04 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-04-21 15:20 --------- d-----w C:\Documents and Settings\Yam\Application Data\Corel
2008-04-21 15:15 --------- d-----w C:\Program Files\Common Files\Corel
2008-04-21 15:14 --------- d-----w C:\Program Files\Corel
2008-04-21 14:00 --------- d-----w C:\Documents and Settings\Yam\Application Data\uTorrent
2008-04-19 06:08 --------- d-----w C:\Program Files\ICQ6
2008-04-13 05:51 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-08 17:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Software
2008-04-08 17:35 --------- d-----w C:\Documents and Settings\Yam\Application Data\NCH Software
2008-04-06 18:48 --------- d-----w C:\Program Files\ABC Amber XML Converter
2008-04-04 17:50 --------- d-----w C:\Program Files\StuffPlug3
2008-04-04 17:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-24 18:17 --------- d-----w C:\Documents and Settings\Yam\Application Data\FMZilla
2008-03-23 20:46 --------- d-----w C:\Program Files\iMesh Applications
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-12 14:49 --------- d-----w C:\Program Files\Rats!
2008-03-12 11:48 --------- d-----w C:\Program Files\Internet Download Manager
2008-03-11 12:21 --------- d-----w C:\Documents and Settings\Yam\Application Data\IDM
2008-03-11 12:18 --------- d-----w C:\Documents and Settings\Yam\Application Data\DMCache
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2004-12-01 16:34 716 ---ha-w C:\Documents and Settings\All Users\Application Data\pb7msys.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3CB7D426-9069-4CB0-80F0-160B5BA2E045}]
C:\WINDOWS\system32\awtqnnnO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4020100D-29D7-4392-AFD5-5AD713FF4B88}]
2008-04-21 18:01 38400 --a------ C:\WINDOWS\system32\khfCtRlJ.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-01-23 15:47 847872]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-04-10 15:14 1107848]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-23 09:08 185896]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{4020100D-29D7-4392-AFD5-5AD713FF4B88}"= C:\WINDOWS\system32\khfCtRlJ.dll [2008-04-21 18:01 38400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfCtRlJ]
khfCtRlJ.dll 2008-04-21 18:01 38400 C:\WINDOWS\system32\khfCtRlJ.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2007-10-17 19:16 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\yam3\\half-life 2 deathmatch\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\yam3\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"C:\\Program Files\\Soldier of Fortune II - Double Helix MP TEST\\SoF2MP-Test.exe"=
"C:\\Program Files\\TMU\\TmUnited.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\yam3\\half-life 2\\hl2.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\e frontier\\Poser 7 Demo\\PoserDemo.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2004-09-02 22:01]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c3399da-8772-11dc-8bbe-001485019281}]
\Shell\AutoRun\command - F:\SETUP.EXE /AUTORUN
\Shell\configure\command - F:\SETUP.EXE
\Shell\install\command - F:\SETUP.EXE
.
Contents of the 'Scheduled Tasks' folder
"2008-05-08 08:57:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-11 16:57:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-11 15:44:28 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-11 20:21:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\brss01a.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
.
**************************************************************************
.
Completion time: 2008-05-11 20:43:01 - machine was rebooted [Yam]
ComboFix-quarantined-files.txt 2008-05-11 17:37:29
Pre-Run: 69,610,991,616 bytes free
Post-Run: 69,723,242,496 bytes free
234 --- E O F --- 2008-04-11 15:07:32
HJ
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:45:50 PM, on 5/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {3CB7D426-9069-4CB0-80F0-160B5BA2E045} - C:\WINDOWS\system32\awtqnnnO.dll (file missing)
O2 - BHO: (no name) - {4020100D-29D7-4392-AFD5-5AD713FF4B88} - C:\WINDOWS\system32\khfCtRlJ.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ???? ?????? ?? Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O20 - Winlogon Notify: khfCtRlJ - C:\WINDOWS\SYSTEM32\khfCtRlJ.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
--
End of file - 5525 bytes