ComboFix LogComboFix 08-07-08.3 - Owner 2008-07-08 22:36:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2404 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\XwvuDcfe.ini
C:\WINDOWS\system32\XwvuDcfe.ini2
N:\autorun.inf
N:\copy.exe
.
((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
.
2008-07-08 19:14 . 2008-07-08 19:14 1,355 --a--c--- C:\WINDOWS\imsins.BAK
2008-07-07 20:46 . 2008-07-07 20:46 <DIR> d----c--- C:\Program Files\GhostSurf Platinum
2008-07-07 20:46 . 2007-05-07 11:39 1,103,944 --a-sc--- C:\WINDOWS\system32\Protector.dll
2008-07-07 20:46 . 2007-05-07 11:39 169,544 --a-sc--- C:\WINDOWS\system32\SecuLoad.dll
2008-07-07 20:46 . 2006-07-26 22:13 57,344 --a--c--- C:\WINDOWS\system32\MFC71ENU.DLL
2008-07-07 20:46 . 2007-05-07 11:42 40,960 --a-sc--- C:\WINDOWS\system32\ProcessKiller.dll
2008-07-07 17:34 . 2008-07-07 17:34 <DIR> d----c--- C:\Program Files\iLike
2008-07-07 15:41 . 2008-07-07 15:41 <DIR> d----c--- C:\Deckard
2008-07-07 15:00 . 2008-07-07 15:00 <DIR> d----c--- C:\WINDOWS\ERUNT
2008-07-07 14:20 . 2008-07-07 15:34 <DIR> d----c--- C:\SDFix
2008-07-06 23:31 . 2008-07-06 23:31 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\Uniblue
2008-07-04 23:17 . 2008-07-04 23:17 <DIR> d----c--- C:\Program Files\Trend Micro
2008-07-04 13:27 . 2008-07-04 13:27 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Road Runner
2008-07-04 13:25 . 2007-05-09 15:05 327,680 --a--c--- C:\WINDOWS\Road Runner PhotoShow.scr
2008-07-04 13:21 . 2008-07-04 13:21 <DIR> d----c--- C:\Program Files\Road Runner
2008-07-04 13:21 . 2008-07-04 13:25 <DIR> d----c--- C:\Program Files\Common Files\Simple Star Shared
2008-07-04 13:21 . 2008-07-04 13:25 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Simple Star Shared
2008-07-04 13:20 . 2008-07-04 13:20 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Simple Star
2008-07-04 13:17 . 2008-07-04 13:27 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\Simple Star
2008-07-04 13:17 . 2008-07-08 01:39 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\Road Runner
2008-06-26 15:10 . 2008-06-26 15:10 42,320 --a--c--- C:\WINDOWS\system32\xfcodec.dll
2008-06-24 22:43 . 2008-07-04 13:27 <DIR> d----c--- C:\WINDOWS\Logs
2008-06-24 14:35 . 2008-07-04 09:22 76,040 --a--c--- C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-24 14:35 . 2008-07-04 09:22 10,520 --a--c--- C:\WINDOWS\system32\avgrsstx.dll
2008-06-24 14:34 . 2008-07-08 21:32 <DIR> d----c--- C:\WINDOWS\system32\drivers\Avg
2008-06-24 14:34 . 2008-06-28 11:27 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-06-24 14:34 . 2008-07-04 09:22 96,520 --a--c--- C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-23 19:51 . 2008-06-23 19:56 <DIR> d----c--- C:\Program Files\Panda Security
2008-06-21 02:38 . 2008-06-21 02:39 <DIR> d----c--- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-21 02:38 . 2008-06-21 02:38 <DIR> d----c--- C:\Program Files\Common Files\Download Manager
2008-06-21 02:38 . 2008-06-21 02:38 <DIR> d----c--- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-06-21 02:38 . 2008-06-21 02:38 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-21 02:38 . 2008-06-10 19:02 34,296 --a--c--- C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-21 02:38 . 2008-06-10 19:02 15,864 --a--c--- C:\WINDOWS\system32\drivers\mbam.sys
2008-06-21 01:57 . 2008-06-21 01:57 <DIR> d----c--- C:\Program Files\NVIDIA nTune Performance Application
2008-06-21 01:44 . 2008-06-21 01:44 <DIR> d----c--- C:\WINDOWS\nvidia icons
2008-06-21 01:43 . 2008-06-21 01:50 <DIR> d----c--- C:\WINDOWS\NV51845104.TMP
2008-06-20 12:46 . 2008-06-20 12:46 245,248 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 12:46 . 2008-06-20 12:46 147,968 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 06:51 . 2008-06-20 06:51 361,600 -----c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 06:40 . 2008-06-20 06:40 138,496 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 06:08 . 2008-06-20 06:08 225,856 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-10 19:16 . 2008-06-13 06:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 19:16 . 2008-05-08 09:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 03:24 120,792 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-07-09 03:16 --------- dc----w C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-07-08 21:15 136,888 -c--a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-08 21:15 111,928 -c--a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-07-08 04:19 --------- dc----w C:\Documents and Settings\Owner\Application Data\Tenebril
2008-07-08 01:53 --------- dc----w C:\Documents and Settings\All Users\Application Data\Tenebril
2008-07-08 01:27 --------- dcs---w C:\Program Files\Xfire
2008-07-08 01:22 --------- dc----w C:\Documents and Settings\Owner\Application Data\Xfire
2008-07-07 06:15 --------- dc----w C:\Program Files\Common Files\Adobe
2008-07-07 06:13 --------- dc----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-07-07 02:34 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-06 09:20 --------- dc----w C:\Program Files\uTorrent
2008-06-25 03:32 --------- dc----w C:\Program Files\MSECache
2008-06-24 19:34 --------- dc----w C:\Documents and Settings\All Users\Application Data\avg8
2008-06-24 06:44 --------- dc----w C:\Program Files\Plaxo
2008-06-23 00:28 --------- dc----w C:\Program Files\PhotoFiltre
2008-06-20 17:46 245,248 -c--a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 -c--a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 -c--a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 18:33 --------- dc----w C:\Program Files\SUPERAntiSpyware
2008-06-13 11:05 272,128 -c----w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-30 19:19 507,400 -c--a-w C:\WINDOWS\system32\XAudio2_1.dll
2008-05-30 19:18 238,088 -c--a-w C:\WINDOWS\system32\xactengine3_1.dll
2008-05-30 19:17 65,032 -c--a-w C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-30 19:17 25,608 -c--a-w C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-30 19:11 467,984 -c--a-w C:\WINDOWS\system32\d3dx10_38.dll
2008-05-30 19:11 3,850,760 -c--a-w C:\WINDOWS\system32\D3DX9_38.dll
2008-05-30 19:11 1,491,992 -c--a-w C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-30 06:13 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2008-05-30 06:13 --------- dc----w C:\Program Files\Common Files\Nikon
2008-05-30 06:10 --------- dc----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-05-30 03:09 --------- dc----w C:\Program Files\AOL 9.1a
2008-05-30 01:34 --------- dc----w C:\Program Files\Common Files\AOL
2008-05-30 01:33 --------- dc----w C:\Program Files\Common Files\aolshare
2008-05-30 01:33 --------- dc----w C:\Documents and Settings\All Users\Application Data\AOL
2008-05-30 01:31 --------- dc----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-05-28 01:20 --------- dc----w C:\Program Files\Apple Software Update
2008-05-24 04:12 --------- dc----w C:\Program Files\DIGStream
2008-05-24 00:28 --------- dc----w C:\Program Files\Spybot - Search & Destroy
2008-05-23 23:29 --------- dc----w C:\Program Files\Lavasoft
2008-05-23 23:29 --------- dc----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-23 23:29 --------- dc----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-23 20:07 --------- dc----w C:\Program Files\AVG
2008-05-23 20:06 --------- dc----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-05-20 04:32 --------- dc----w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-05-20 04:03 --------- dc----w C:\Program Files\Kodak
2008-05-20 04:01 --------- dc----w C:\Program Files\Common Files\Kodak
2008-05-19 11:33 4,445,184 -c--a-w C:\WINDOWS\system32\msi.dll
2008-05-19 11:33 332,800 -c--a-w C:\WINDOWS\system32\msihnd.dll
2008-05-19 11:33 18,944 -c--a-w C:\WINDOWS\system32\msisip.dll
2008-05-19 06:57 95,744 -c--a-w C:\WINDOWS\system32\msiexec.exe
2008-05-16 16:58 12,632 -c--a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-13 22:54 20 -c-h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2008-05-09 10:53 90,112 -c--a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:53 430,080 -c--a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53 180,224 -c--a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53 172,032 -c--a-w C:\WINDOWS\system32\scrrun.dll
2008-05-08 11:24 155,648 -c--a-w C:\WINDOWS\system32\wscript.exe
2008-05-07 09:07 135,168 -c--a-w C:\WINDOWS\system32\cscript.exe
2008-05-07 05:12 1,288,192 -c--a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 22:27 442,368 -c--a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-04-23 04:16 826,368 -c--a-w C:\WINDOWS\system32\wininet.dll
2008-04-17 06:43 2,560 -c--a-w C:\WINDOWS\system32\msimsg.dll
2008-04-14 10:42 985,088 -c--a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 10:42 11,264 -c--a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 10:41 423,936 -c--a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 -c--a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 -c--a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 -c--a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 -c--a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 12,168 -c--a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 997,376 -c--a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 -c--a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 -c--a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 -c--a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 21:00 103,424 -c--a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 19:30 1,845,632 -c--a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:24 2,145,280 -c--a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 -c--a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:35 24,064 -c--a-w C:\WINDOWS\system32\pidgen.dll
2008-04-13 18:31 7,424 -c--a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,023,936 -c--a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 -c--a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 18:14 76,800 -c----w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:39 438,784 -c--a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 17:39 2,897,920 -c--a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 187,392 -c--a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 -c--a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 -c--a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:27 79,872 -c--a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 94,208 -c--a-w C:\WINDOWS\system32\odbcint.dll
2008-04-13 17:26 12,288 -c--a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 -c--a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:24 20,480 -c--a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-13 17:21 733,696 -c--a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 17:09 4,096 -c--a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:03 63,488 -c--a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 17:03 549,376 -c--a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 16:48 1,647,616 -c--a-w C:\WINDOWS\system32\winbrand.dll
2005-05-13 23:12 217,073 -csha-r C:\WINDOWS\meta4.exe
2005-10-24 17:13 66,560 -csha-r C:\WINDOWS\MOTA113.exe
2005-10-14 03:27 422,400 -csha-r C:\WINDOWS\x2.64.exe
2005-10-08 01:14 308,224 -csha-r C:\WINDOWS\system32\avisynth.dll
2005-07-14 18:31 27,648 -csha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 21:32 616,448 -csha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 04:37 45,568 -csha-r C:\WINDOWS\system32\cygz.dll
2004-01-25 06:00 70,656 -csha-r C:\WINDOWS\system32\i420vfw.dll
2006-04-27 16:24 2,945,024 -csha-r C:\WINDOWS\system32\Smab.dll
2005-02-28 19:16 240,128 -csha-r C:\WINDOWS\system32\x.264.exe
2004-01-25 06:00 70,656 -csha-r C:\WINDOWS\system32\yv12vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="\Program" [X]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 00:13 1591808]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-14 13:33 1506544]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"Road Runner PhotoShow Media Manager"="C:\PROGRA~1\ROADRU~1\PHOTOS~1\data\xtras\mssysmgr.exe" [2008-05-09 17:20 361976]
"AOL Fast Start"="C:\Program Files\AOL 9.1a\AOL.EXE" [2008-03-06 05:12 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-12 00:18 135168]
"EPSON Stylus CX4800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE" [2005-02-01 22:00 98304]
"CTSysVol"="C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 11:43 57344]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 04:42 32768]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"SensKbd"="C:\WINDOWS\SAMSUNG\SensKbd\SensKbd.exe" [2001-11-10 14:50 28672]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-02-21 17:42 1115728]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-04 09:22 1232152]
"GhostSurf Reminder"="C:\Program Files\GhostSurf Platinum\Privacy Control Center.exe" [2005-08-14 23:32 82037]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"P17Helper"="P17.dll" [2005-05-03 20:38 64512 C:\WINDOWS\system32\P17.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="C:\Program Files\America Online 9.0a\AOL.EXE" [2005-07-12 00:17 50776]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
"iLike"="C:\Program Files\iLike\1.1.41\ilikesidebar.exe" [2008-02-12 14:21 63024]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Scheduler.lnk - C:\Program Files\GhostSurf Platinum\Scheduler daemon.exe [2008-07-07 20:46:38 86133]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
GhostSurf proxy.lnk - C:\Program Files\GhostSurf Platinum\Proxy.exe [2008-07-07 20:46:38 86133]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-09 14:41:43 784912]
Privacy Auditor.lnk - C:\Program Files\GhostSurf Platinum\Privacy Auditor.exe [2008-07-07 20:46:38 157288]
SpyCatcher Protector.lnk - C:\Program Files\GhostSurf Platinum\Protector.exe [2008-07-07 20:46:38 91576]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "C:\Program Files\Qualcomm\Eudora\EuShlExt.dll" [2005-11-14 17:15 86016]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-26 12:35 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 11:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=secuload.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MiniEYE-MiniREAD Launch .lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MiniEYE-MiniREAD Launch .lnk
backup=C:\WINDOWS\pss\MiniEYE-MiniREAD Launch .lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Google Web Accelerator.lnk
backup=C:\WINDOWS\pss\Run Google Web Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Client Default.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Client Default.lnk
backup=C:\WINDOWS\pss\Client Default.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Wallperizer.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Wallperizer.lnk
backup=C:\WINDOWS\pss\Wallperizer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a--c--- 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a--c--- 2008-03-06 05:12 50528 C:\Program Files\AOL 9.1a\aol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra--c--- 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a--c--- 2008-04-13 19:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2007-05-25 12:16 42032 C:\Program Files\Common Files\AOL\1101494607\EE\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
--a--c--- 2006-03-27 10:57 126104 C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a--c--- 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a--c--- 2008-05-02 22:46 13529088 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a--c--- 2008-05-02 22:46 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
--a--c--- 2008-04-14 17:36 227914 C:\Program Files\Plaxo\2.13.1.6\PlaxoHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
--a--c--- 2006-05-08 05:17 81920 C:\PROGRA~1\Sony\SONICS~1\SSAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a--c--- 2006-08-10 20:18 1249280 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra--c--- 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
-----c--- 2000-05-11 02:00 90112 C:\WINDOWS\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-01-15 17:54 37376 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
--a--c--- 2005-07-25 11:47 2806272 C:\WINDOWS\ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
--a------ 2004-05-18 03:30 543232 C:\WINDOWS\zHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
-----c--- 2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a--c--- 2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a--c--- 2005-07-25 11:47 90112 C:\WINDOWS\SoundMan.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0a\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1101494607\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"C:\\Program Files\\EA Games\\MOHAADemo\\MOHAADemo.exe"=
"C:\\Program Files\\Xfire\\ua_lsp_inst.exe"=
"C:\\Program Files\\Call of Duty\\CoDMP.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Call of Duty\\CoDUOMP.exe"=
"C:\\Program Files\\myTunes Redux\\mDNSResponder.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Common Files\\AOL\\1101494607\\EE\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1101494607\\EE\\aim6.exe"=
"C:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"C:\\Program Files\\EA Games\\Battlefield 2\\BF2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Xfire\\Xfire.exe"=
"C:\\Program Files\\Sierra\\FEARCombat\\fpupdate.exe"=
"C:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
"C:\\Documents and Settings\\Owner\\Desktop\\utorrent.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis SP Demo\\Bin32\\Crysis.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\AOL 9.1\\waol.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AOL 9.1a\\waol.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"21851:TCP"= 21851:TCP:BitComet 21851 TCP
"21851:UDP"= 21851:UDP:BitComet 21851 UDP
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-04 09:22]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-04 09:22]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-24 14:34]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-04 09:22]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-06-30 00:53]
S0 ntcdrdrv;ntcdrdrv;C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys []
S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9cd8f9f-230b-11dd-9245-00038a000015}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-07-04 12:40:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-09 03:48:41 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKLM-Run-GhostSurfDelSatellite - C:\Program Files\GhostSurf Platinum\DeleteSatellite.exe
HKLM-Run-ShowWnd - ShowWnd.exe
MSConfigStartUp-AOL Spyware Protection - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
MSConfigStartUp-AVEDESK - C:\Program Files\AveDesk\AveDesk.exe
MSConfigStartUp-iLike - C:\Program Files\iLike\1.1.27\ilikesidebar.exe
MSConfigStartUp-MoneyAgent - C:\Program Files\Microsoft Money\System\mnyexpr.exe
MSConfigStartUp-Pure Networks Port Magic - C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-08 22:46:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ATWPKT2]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\ATWPKT2.SYS"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AOL 9.1a\waol.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\AOL 9.1a\shellmon.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-07-08 23:03:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-09 04:03:25
Pre-Run: 63,380,779,008 bytes free
Post-Run: 63,673,958,400 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
438 --- E O F --- 2008-07-09 00:18:45
Hijack LogLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:46 PM, on 7/8/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SAMSUNG\SensKbd\SensKbd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AOL 9.1a\waol.exe
C:\Program Files\GhostSurf Platinum\Proxy.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\GhostSurf Platinum\Privacy Auditor.exe
C:\Program Files\GhostSurf Platinum\Protector.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\GhostSurf Platinum\Scheduler daemon.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\AOL 9.1a\shellmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.rr.com/br...H...RR&d=homerrR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\GhostSurf Platinum\SCActiveBlock.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\Digital Media Reader\shwiconem.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE" /P26 "EPSON Stylus CX4800 Series" /O6 "USB004" /M "Stylus CX4800"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SensKbd] C:\WINDOWS\SAMSUNG\SensKbd\SensKbd.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GhostSurf Reminder] "C:\Program Files\GhostSurf Platinum\Privacy Control Center.exe" reminder
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Road Runner PhotoShow Media Manager] C:\PROGRA~1\ROADRU~1\PHOTOS~1\data\xtras\mssysmgr.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1a\AOL.EXE" -b
O4 - HKUS\S-1-5-18\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [iLike] C:\Program Files\iLike\1.1.41\ilikesidebar.exe /checkforupdate (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b (User 'Default user')
O4 - Startup: Scheduler.lnk = C:\Program Files\GhostSurf Platinum\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: GhostSurf proxy.lnk = C:\Program Files\GhostSurf Platinum\Proxy.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Privacy Auditor.lnk = C:\Program Files\GhostSurf Platinum\Privacy Auditor.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\GhostSurf Platinum\Protector.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://support.gatew...r/PCPitStop.CABO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
https://www-secure.s...sa/LSSupCtl.cabO16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) -
http://community.web...wsaxcontrol.cabO16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) -
https://support.micr...ActiveX/odc.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) -
http://asp.mathxl.co...GenXInstall.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.av.a...83/mcinsctl.cabO16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) -
http://simcity.ea.co...date/EARTPX.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1124232469093O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) -
http://tsweb.cps-satx.com/msrdp.cabO16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) -
http://asp.mathxl.co...nstallAsst2.cabO16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) -
http://download.zone...ctor/WebSWK.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} -
http://pictures06.ai...AIM.9.5.1.8.cabO16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) -
http://cdn.digitalci....1.11_en_dl.cabO16 - DPF: {B8E71371-F7F7-11D2-A2CE-0060B0FB9D0D} (CDToolCtrl Class) -
http://free.aol.com/...5/aolcdt175.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.av.a...,20/mcgdmgr.cabO16 - DPF: {BE71A78B-77DB-451C-A761-59B37022D544} (AOL Newport Downloader Ctrl) -
http://o.aolcdn.com/...ns.10.4.0.3.cabO16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) -
http://simcity.ea.co...ty4PatcherX.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
https://www-secure.s...sa/SymAData.cabO16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) -
http://asp.mathxl.co.../MathPlayer.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: secuload.dll,avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 15479 bytes