Thank you for your help. I gave it a try in cronological order. But the same symptom applies here, so I ceased to run the Combofix. When I isntall Windows Recovery from the WinXp Cd, It goes into its Dynamic Update with Microsoft (Connecting to Microsoft). And even though internet access is working fine, it fails to update. The wizard was unable to downloaded the updated windows setupfile. So I downloaded it as another options suggest, but when i drag the icon over ther combo fix icon, it does not install it. It only starts running the combofix program and goes through is scans procedures . THANKS
omboFix 08-07-25.7 - admin 2008-07-26 9:34:42.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.274 [GMT -5:00]
Running from: C:\Documents and Settings\admin\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\admin\Application Data\macromedia\Flash Player\#SharedObjects\X8TMAWPW\interclick.com
C:\Documents and Settings\admin\Application Data\macromedia\Flash Player\#SharedObjects\X8TMAWPW\interclick.com\ud.sol
C:\Documents and Settings\admin\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\admin\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\admin\g2mdlhlpx.exe
C:\Program Files\dobe~1
C:\WINDOWS\system32\_000003_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-26 to 2008-07-26 )))))))))))))))))))))))))))))))
.
2008-07-25 22:38 . 2008-07-25 22:38 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Malwarebytes
2008-07-25 22:37 . 2008-07-25 22:37 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-25 22:37 . 2008-07-25 22:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-25 22:37 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-25 22:37 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-25 22:29 . 2001-08-17 13:28 771,581 --a--c--- C:\WINDOWS\system32\dllcache\winacisa.sys
2008-07-25 22:28 . 2001-08-17 13:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2008-07-25 22:27 . 2004-08-03 22:41 404,990 --a--c--- C:\WINDOWS\system32\dllcache\slntamr.sys
2008-07-25 22:26 . 2001-08-17 13:28 899,146 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-07-25 22:25 . 2004-08-04 00:56 4,274,816 --a--c--- C:\WINDOWS\system32\dllcache\nv4_disp.dll
2008-07-25 22:24 . 2004-08-04 00:56 1,737,856 --a--c--- C:\WINDOWS\system32\dllcache\mtxparhd.dll
2008-07-25 22:23 . 2001-08-17 13:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2008-07-25 22:22 . 2001-08-17 22:36 372,824 --a--c--- C:\WINDOWS\system32\dllcache\iconf32.dll
2008-07-25 22:21 . 2004-08-03 22:41 1,041,536 --a--c--- C:\WINDOWS\system32\dllcache\hsfdpsp2.sys
2008-07-25 22:20 . 2001-08-17 14:56 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2008-07-25 22:19 . 2001-08-17 12:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
2008-07-25 22:18 . 2001-08-17 12:13 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2008-07-25 22:17 . 2004-08-04 00:56 1,888,992 --a--c--- C:\WINDOWS\system32\dllcache\ati3duag.dll
2008-07-25 22:16 . 2001-08-17 13:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-07-25 22:15 . 2001-08-17 14:56 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-07-25 22:06 . 2008-07-25 22:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-25 20:45 . 2008-07-25 22:43 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-25 20:16 . 2008-07-25 20:16 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-25 20:16 . 2008-07-25 20:16 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-25 20:15 . 2008-07-25 20:15 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-25 20:15 . 2008-07-25 20:15 <DIR> d-------- C:\Program Files\AVG
2008-07-25 20:15 . 2008-07-25 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-25 20:15 . 2008-07-25 20:17 <DIR> d-------- C:\Documents and Settings\admin\Application Data\AVGTOOLBAR
2008-07-25 18:57 . 2008-07-25 18:57 <DIR> d-------- C:\Program Files\Acoolsoft
2008-07-24 20:28 . 2008-07-25 19:16 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-07-24 19:16 . 2008-07-24 19:16 <DIR> d-------- C:\Program Files\SmartFTP Client 3.0 Setup Files
2008-07-24 19:16 . 2008-07-24 19:16 <DIR> d-------- C:\Program Files\SmartFTP Client
2008-07-24 19:16 . 2008-07-24 19:16 <DIR> d-------- C:\Documents and Settings\admin\Application Data\SmartFTP
2008-07-24 18:58 . 2008-07-24 19:14 <DIR> d-------- C:\Documents and Settings\admin\Application Data\CoreFTP
2008-07-24 18:57 . 2008-07-24 18:57 <DIR> d-------- C:\Program Files\CoreFTP
2008-07-24 16:04 . 2008-07-25 19:03 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-24 16:04 . 2008-07-24 16:04 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-23 22:03 . 2008-07-23 22:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-07-23 21:57 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-07-23 21:57 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-07-23 21:56 . 2008-07-23 21:56 <DIR> d-------- C:\Program Files\Bonjour
2008-07-23 21:46 . 2008-07-23 21:46 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-07-23 00:53 . 2008-07-23 00:53 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-07-23 00:51 . 2008-07-23 00:51 <DIR> d-------- C:\Program Files\Microsoft Expression
2008-07-23 00:39 . 2008-07-23 00:39 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-07-23 00:39 . 2008-07-23 00:39 <DIR> d-------- C:\Program Files\MSBuild
2008-07-23 00:38 . 2008-07-23 00:38 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-07-23 00:38 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-07-21 20:31 . 2008-07-22 20:10 <DIR> d-------- C:\Program Files\Conference
2008-07-20 11:59 . 2008-07-20 11:59 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-20 11:59 . 2008-07-20 12:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-20 11:56 . 2008-07-20 11:56 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-20 11:54 . 2008-07-20 11:54 73 --a------ C:\WINDOWS\st_affiliate.ini
2008-07-20 11:08 . 2008-07-20 11:38 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-20 11:08 . 2008-07-20 11:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ludia
2008-07-20 11:08 . 2008-07-20 11:08 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Ludia
2008-07-20 11:07 . 2008-07-20 11:07 <DIR> d-------- C:\Program Files\Common Files\Oberon Media
2008-07-20 11:07 . 2008-07-20 12:24 <DIR> d-------- C:\Program Files\Chill
2008-07-18 16:52 . 2008-07-20 12:23 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Uniblue
2008-07-16 20:13 . 2008-07-16 20:15 <DIR> d-------- C:\Program Files\Linksys EasyLink Advisor
2008-07-16 20:05 . 2008-07-16 20:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comcast
2008-07-14 03:07 . 2008-07-14 03:07 <DIR> d-------- C:\WINDOWS\SQL9_KB948109_ENU
2008-07-13 18:41 . 2008-07-13 18:46 <DIR> d-------- C:\Program Files\LimeWire
2008-07-13 18:41 . 2008-07-13 18:45 <DIR> d-------- C:\Documents and Settings\admin\Application Data\LimeWire
2008-07-13 18:32 . 2008-07-13 20:04 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Apple Computer
2008-07-13 18:31 . 2008-07-13 18:32 <DIR> d-------- C:\Program Files\QuickTime
2008-07-13 18:30 . 2008-07-13 18:30 <DIR> d-------- C:\Program Files\iTunes
2008-07-13 18:29 . 2008-07-13 18:29 <DIR> d-------- C:\Program Files\iPod
2008-07-13 18:29 . 2008-07-13 18:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-13 18:29 . 2004-12-18 20:32 38,229 --------- C:\WINDOWS\system32\drivers\StMp3Rec.sys
2008-07-13 17:29 . 2008-06-13 08:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-13 17:29 . 2008-06-13 08:10 272,128 --a--c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-26 12:48 --------- d-----w C:\Documents and Settings\admin\Application Data\Move Networks
2008-07-26 02:10 --------- d-----w C:\Program Files\32Vegas Casino
2008-07-26 00:17 --------- d-----w C:\Program Files\Java
2008-07-24 18:34 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-23 06:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-20 17:26 --------- d-----w C:\Program Files\MorpheusBar
2008-07-20 17:24 --------- d-----w C:\Program Files\Citrix
2008-07-20 17:23 --------- d-----w C:\Program Files\Vstep
2008-07-20 17:22 --------- d-----w C:\Program Files\VstPlugins
2008-07-20 17:22 --------- d-----w C:\Program Files\Image-Line
2008-07-20 17:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-07-20 17:19 --------- d-----w C:\Program Files\PCFriendly
2008-07-20 16:56 --------- d-----w C:\Program Files\Prima Games
2008-07-14 08:08 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-07-13 23:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-05-16 16:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 00:56 158208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 20:47 8720384]
[HKLM\~\startupfolder\C:^Documents and Settings^admin^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\admin\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DNS4Me Tray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DNS4Me Tray.lnk
backup=C:\WINDOWS\pss\DNS4Me Tray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
backup=C:\WINDOWS\pss\Monitor Apache Servers.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mxmez]
C:\Program Files\?dobe\r?ndll.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-02-28 23:06 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
--a------ 2008-07-25 20:15 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
--a------ 2008-01-30 21:24 1481472 C:\Program Files\COMODO\Firewall\cfp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
--a------ 2007-03-15 18:16 454784 C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-09-20 09:32 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-09-20 09:36 114688 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-09-20 09:35 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2005-12-20 20:54 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-07-13 18:31 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"C:\\Program Files\\Conference\\Conference.dll"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-25 20:16]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-01-30 21:24]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-01-30 21:24]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-25 20:15]
S4 DynDNS_Updater_Service;DynDNS Updater Service;C:\Program Files\DynDNS Updater\DynDNS.exe []
S4 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 22:08]
S4 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 16:38]
.
Contents of the 'Scheduled Tasks' folder
2008-07-20 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job - s !7C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe-sadmin0' []
2008-07-18 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
- - - - ORPHANS REMOVED - - - -
Notify-NavLogon - (no file)
MSConfigStartUp-ares - C:\Program Files\Ares Galaxy P2P Plus\Ares.exe
MSConfigStartUp-ccApp - C:\Program Files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-ddoctorv2 - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
MSConfigStartUp-GoToMeeting - C:\Program Files\Citrix\GoToMeeting\198\g2mstart.exe
MSConfigStartUp-SunJavaUpdateSched - C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
MSConfigStartUp-Uace - C:\WINDOWS\system32\SMBOLS~1\iexplore.exe
MSConfigStartUp-vptray - C:\PROGRA~1\SYMANT~1\VPTray.exe
MSConfigStartUp-WinVNC - C:\Program Files\TightVNC\WinVNC.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Window Title = Windows Internet Explorer provided by Comcast
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O18 -: Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - C:\Program Files\CoreFTP\pftpns.dll
O16 -: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
C:\WINDOWS\Downloaded Program Files\sprtexternal.inf
C:\WINDOWS\Downloaded Program Files\tgctlsi.dll
C:\WINDOWS\Downloaded Program Files\sprtexternal.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-26 09:38:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-07-26 9:42:27
ComboFix-quarantined-files.txt 2008-07-26 14:41:23
Pre-Run: 9,187,618,816 bytes free
Post-Run: 9,176,440,832 bytes free
228 --- E O F --- 2008-07-25 23:52:49
HIJACK THIS:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:44:55 AM, on 7/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) -
http://inst.c-wss.co...ll/gtdownlr.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) -
https://actsvr.comca..... Controls.cabO16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1006.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1189461425046O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1203305127015O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://demos.webex....bex/ieatgpc.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 5894 bytes
Edited by Chad Oneal, 26 July 2008 - 08:45 AM.