[b]
Again thank you![/b]
ComboFix 08-05-27.4 - Summer 2008-05-28 14:57:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.530 [GMT -4:00]
Running from: C:\Documents and Settings\Summer\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Summer\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Summer\Application Data\macromedia\Flash Player\#SharedObjects\ZTQJGZV9\www.broadcaster.com
C:\Documents and Settings\Summer\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Summer\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\temp\17o7
C:\temp\17o7\tmpTF.log
C:\WINDOWS\BM9f51ed4b.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\gvnacgag.ini
C:\WINDOWS\system32\hrwshjon.dll
C:\WINDOWS\system32\kkvcwdsp.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\MWHNnUvw.ini
C:\WINDOWS\system32\MWHNnUvw.ini2
C:\WINDOWS\system32\ps.exe
C:\WINDOWS\system32\psdwcvkk.ini
C:\WINDOWS\system32\smpi1
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CORE
-------\Service_core
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.
2008-05-28 10:37 . 2008-05-28 14:25 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-28 09:50 . 2008-05-28 09:50 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-28 09:44 . 2008-05-28 10:23 <DIR> d-------- C:\SDFix
2008-05-28 09:28 . 2008-05-28 14:43 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-28 09:28 . 2008-05-28 09:31 <DIR> d-------- C:\Documents and Settings\Summer\Application Data\AVGTOOLBAR
2008-05-28 09:28 . 2008-05-28 09:28 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-28 09:28 . 2008-05-28 09:28 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-28 09:28 . 2008-05-28 09:28 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-28 09:27 . 2008-05-28 09:27 <DIR> d-------- C:\Program Files\AVG
2008-05-28 09:27 . 2008-05-28 09:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-27 13:03 . 2008-05-27 13:03 <DIR> d-------- C:\VundoFix Backups
2008-05-27 09:42 . 2008-05-27 09:42 372,224 --a------ C:\WINDOWS\system32\{fbb7469d-f7eb-bb5b-860e-c46b28bda0af}.dll
2008-05-27 09:32 . 2008-05-27 09:32 895 --a------ C:\WINDOWS\b104.exe.bin
2008-05-27 09:27 . 2008-05-27 09:27 891 --a------ C:\WINDOWS\b103.exe.bin
2008-05-27 09:22 . 2008-05-27 09:22 212,992 --a------ C:\WINDOWS\b116.exe.bin
2008-05-27 09:12 . 2008-05-27 09:42 96,645 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-05-27 09:12 . 2008-05-27 09:42 87,941 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-05-27 09:09 . 2008-05-27 09:09 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-05-27 09:09 . 2008-05-27 10:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-27 09:09 . 2008-05-27 10:34 213,280 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-27 09:09 . 2008-05-27 10:34 8,480 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-27 09:09 . 2008-05-27 10:34 3,932 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-27 09:09 . 2008-05-27 10:34 1,868 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-23 09:01 . 2008-05-23 09:01 375,296 --a------ C:\WINDOWS\system32\wvUnNHWM.dll
2008-05-23 08:57 . 2008-05-28 13:39 <DIR> d--hs---- C:\WINDOWS\QXR0aXR1ZGUgJiBFeHBlcmllbmNlLCBJbmM
2008-05-23 08:57 . 2008-05-23 09:51 200,768 --a------ C:\WINDOWS\system32\pcntnkdm.exe
2008-05-23 08:57 . 2008-05-28 08:37 63,918 --a------ C:\WINDOWS\system32\{fbb7469d-f7eb-bb5b-860e-c46b28bda0af}.dll-uninst.exe
2008-05-23 08:57 . 2008-05-23 08:57 861 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-05-23 08:56 . 2008-05-28 13:55 <DIR> d-------- C:\WINDOWS\system32\vntiho18
2008-05-23 08:56 . 2008-05-28 13:52 <DIR> d-------- C:\WINDOWS\system32\igv
2008-05-23 08:56 . 2008-05-28 13:52 <DIR> d-------- C:\WINDOWS\system32\hI2
2008-05-23 08:56 . 2008-05-28 13:50 <DIR> d-------- C:\WINDOWS\system32\at1
2008-05-23 08:56 . 2008-05-28 13:49 <DIR> d-------- C:\WINDOWS\system32\1064a
2008-05-14 16:19 . 2008-05-14 16:19 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-14 16:19 . 2008-05-14 16:19 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-12 15:31 . 2008-05-12 15:31 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-05-12 15:31 . 2008-05-12 15:31 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-05-12 15:21 . 2008-05-12 15:23 <DIR> d-------- C:\Program Files\Avanquest update
2008-05-12 15:20 . 2008-05-12 15:27 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-05-12 15:20 . 2008-05-12 15:20 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared
2008-05-12 15:20 . 2008-05-12 15:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-05-12 15:20 . 2006-11-13 14:45 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-05-12 15:20 . 2006-12-13 17:52 20,992 --a------ C:\WINDOWS\system32\drivers\motmodem.sys
2008-05-12 15:19 . 2008-05-12 15:19 <DIR> d-------- C:\Documents and Settings\Summer\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 19:05 --------- d-----w C:\Documents and Settings\Summer\Application Data\OpenOffice.org2
2008-05-28 19:04 --------- d-----w C:\Program Files\Trojan Remover
2008-05-28 19:01 --------- d-----w C:\Documents and Settings\Summer\Application Data\DNA
2008-05-28 18:07 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-05-28 12:29 --------- d-----w C:\Program Files\Weather Pulse
2008-05-15 20:01 --------- d-----w C:\Documents and Settings\Summer\Application Data\BitTorrent
2008-05-14 20:21 --------- d-----w C:\Documents and Settings\Summer\Application Data\AdobeUM
2008-05-12 19:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-09 16:29 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-04-09 16:28 --------- d-----w C:\Program Files\Java
2008-04-02 16:01 --------- d-----w C:\Program Files\Microsoft Works
2007-05-16 16:12 32,768 ----a-w C:\Documents and Settings\Summer\setup9x.exe
2007-05-16 14:57 90,112 ----a-w C:\Documents and Settings\Summer\ps.exe
2007-05-16 14:57 73 ----a-w C:\Documents and Settings\Summer\n.bat
2007-05-16 14:57 167 ----a-w C:\Documents and Settings\Summer\7417.bat
2007-05-15 19:31 167 ----a-w C:\Documents and Settings\Summer\5776.bat
2007-05-15 18:31 167 ----a-w C:\Documents and Settings\Summer\2933.bat
2007-05-15 18:30 90,112 ----a-w C:\Documents and Settings\Jason\ps.exe
2007-05-15 18:30 73 ----a-w C:\Documents and Settings\Jason\n.bat
2007-05-15 18:30 549 ----a-w C:\Documents and Settings\Jason\x.dat
2007-05-15 18:30 167 ----a-w C:\Documents and Settings\Jason\8373.bat
2007-05-15 18:29 32,768 ----a-w C:\Documents and Settings\Jason\setup9x.exe
2007-05-15 18:22 167 ----a-w C:\Documents and Settings\Summer\1631.bat
2007-01-25 08:52 65,536 ----a-w C:\Program Files\Common Files\NMSAccessU.exe
2005-07-29 20:24 472 --sha-r C:\WINDOWS\QXR0aXR1ZGUgJiBFeHBlcmllbmNlLCBJbmM\krlXurlYt3o0L21IyJ15wA55vAh5MF1LvAg.vbs
2006-09-19 21:25 56 --sh--r C:\WINDOWS\system32\2B4DB80345.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3095D50F-F1BA-4BBC-A54D-819EEB7E0898}]
C:\WINDOWS\system32\tuvSLEVN.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{645f8351-85b6-689c-ea11-b3309d12c430}]
2008-05-27 09:42 372224 --a------ C:\WINDOWS\system32\{fbb7469d-f7eb-bb5b-860e-c46b28bda0af}.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7F650917-006C-4260-87C0-89CC7AE467C6}]
2008-05-23 09:01 375296 --a------ C:\WINDOWS\system32\wvUnNHWM.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-28 09:28 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-28 09:28 2050816]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-28 09:28 2050816]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather Pulse"="C:\Program Files\Weather Pulse\weatherpulse.exe" [2008-04-21 08:36 1859072]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"ZVolume"="C:\Program Files\ZVolume\ZVolume.exe" [2006-05-09 20:07 339968]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-08 08:33 289088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
"Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-03-29 15:12 290816]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28 684032]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-09-13 21:36 50688]
"APL"="C:\Program Files\ACT\ACT for Win 7\APL.exe" [2005-05-24 16:42 20480]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 13:22 86016]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2007-05-15 18:21 1217104]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 16:15 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 16:15 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"{c0f33a35-cfa6-7426-e7c1-542840def001}"="C:\WINDOWS\system32\{fbb7469d-f7eb-bb5b-860e-c46b28bda0af}.dll" [2008-05-27 09:42 372224]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-28 09:27 1177368]
C:\Documents and Settings\Summer\Start Menu\Programs\Startup\
Instant Memory Cleaner.lnk - C:\Program Files\Vasilios Applications\Instant Memory Cleaner\Instant Memory Cleaner.exe [2007-06-01 13:28:39 1155241]
Microsoft Outlook (2).lnk - C:\WINDOWS\Installer\{00030409-78E1-11D2-B60F-006097C998E7}\outicon.exe [2006-09-08 14:43:10 104960]
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 15:41:28 393216]
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 13:57:16 2913584]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-01-26 18:06:24 110592]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 16:05:56 65588]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-01-13 20:44:46 972064]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{3095D50F-F1BA-4BBC-A54D-819EEB7E0898}"= C:\WINDOWS\system32\tuvSLEVN.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvSLEVN]
tuvSLEVN.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ACT\\ACT for Win 7\\Act7.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Intuit\\QuickBooks Pro\\QBDBMgrN.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-28 09:28]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-28 09:27]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-28 09:27]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-28 09:28]
R2 MSSQL$ACT7;MSSQL$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe [2003-05-31 18:02]
R2 NMSAccessU;NMSAccessU;C:\Program Files\Common Files\NMSAccessU.exe [2007-01-25 04:52]
R2 QuickBooksDB18;QuickBooksDB18;C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe [2006-09-13 11:32]
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 02:01]
S3 SQLAgent$ACT7;SQLAgent$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE [2002-12-17 19:23]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bb80a447-2737-11dd-b668-000d56205b41}]
\Shell\Auto\command - E:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fce1f1a6-4824-11db-b604-000d56205b41}]
\Shell\Auto\command - E:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-17 03:16:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-28 19:06:14 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-28 15:04:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\Summer\Local Settings\Application Data\ApplicationHistory\APL.exe.625fcfa3.ini.inuse
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.bin
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-28 15:12:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-28 19:12:24
Pre-Run: 101,495,390,208 bytes free
Post-Run: 101,358,276,608 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
246 --- E O F --- 2007-12-21 21:58:52
________________________________________________________________________________
______________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:19:08 PM, on 5/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Common Files\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Weather Pulse\weatherpulse.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\ZVolume\ZVolume.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Vasilios Applications\Instant Memory Cleaner\Instant Memory Cleaner.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Documents and Settings\Summer\Desktop\HiJackThis\HijackThis.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O2 - BHO: (no name) - {3095D50F-F1BA-4BBC-A54D-819EEB7E0898} - C:\WINDOWS\system32\tuvSLEVN.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: gooochi browser optimizer - {645f8351-85b6-689c-ea11-b3309d12c430} - C:\WINDOWS\system32\{fbb7469d-f7eb-bb5b-860e-c46b28bda0af}.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7F650917-006C-4260-87C0-89CC7AE467C6} - C:\WINDOWS\system32\wvUnNHWM.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [APL] "C:\Program Files\ACT\ACT for Win 7\APL.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{c0f33a35-cfa6-7426-e7c1-542840def001}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{fbb7469d-f7eb-bb5b-860e-c46b28bda0af}.dll" DllStart
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Weather Pulse] C:\Program Files\Weather Pulse\weatherpulse.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ZVolume] C:\Program Files\ZVolume\ZVolume.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Startup: Instant Memory Cleaner.lnk = C:\Program Files\Vasilios Applications\Instant Memory Cleaner\Instant Memory Cleaner.exe
O4 - Startup: Microsoft Outlook (2).lnk = ?
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Save to &KBase... - C:\Program Files\netXtract\SaveToKBmenu.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: netXtract® - {1FB62888-D13A-11d3-AF5D-00C0DF647817} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://crm.safetynet-inc.com'O16 - DPF: Web-Based Email Tools -
http://email.secures...et/Download.CABO16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) -
http://upload.facebo...toUploader5.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1006.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1158936801437O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1158933669500O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) -
http://servicemagic....p/view22RTE.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) -
http://upload.facebo...Uploader4_5.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{540A0807-7E34-4BB9-A609-300232ADF87D}: NameServer = 24.247.15.53,24.247.24.53
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks Pro\HelpAsyncPluggableProtocol.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: tuvSLEVN - tuvSLEVN.dll (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\Common Files\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickBooksDB18 - iAnywhere Solutions, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe
--
End of file - 10774 bytes