Thank you so much for helping
Here is report.txt
SDFix: Version 1.219 Run by edoktorov1 on Wed 08/27/2008 at 11:47 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\0.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\1.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\2.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\3.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\4.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\a.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\b.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\c.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\d.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\e.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\f.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\g.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\h.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\i.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\j.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\k.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\l.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\m.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\n.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\o.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\p.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\q.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\r.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\s.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\t.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\u.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\v.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\w.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\x.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\y.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\z.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\0.exe - Deleted
C:\DOCUME~1\EDOKTO~1\LOCALS~1\Temp\1.exe - Deleted
C:\WINDOWS\system32\msxml71.dll - Deleted
Folder C:\Documents and Settings\edoktorov1\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#w*w.redtube.com - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-27 23:53:26
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 14 Apr 2008 1,695,232 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 7 Jul 2008 2,156,368 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Mon 14 Apr 2008 588,800 A..H. --- "C:\WINDOWS\I386\AUTOCHK.EXE"
Mon 14 Apr 2008 580,608 A..H. --- "C:\WINDOWS\I386\AUTOFMT.EXE"
Mon 14 Apr 2008 60,416 A..H. --- "C:\WINDOWS\I386\CABINET.DLL"
Mon 14 Apr 2008 847,872 A..H. --- "C:\WINDOWS\I386\DBGENG.DLL"
Mon 14 Apr 2008 640,000 A..H. --- "C:\WINDOWS\I386\DBGHELP.DLL"
Mon 14 Apr 2008 15,872 A..H. --- "C:\WINDOWS\I386\EXPAND.EXE"
Mon 14 Apr 2008 125,952 A..H. --- "C:\WINDOWS\I386\EXTS.DLL"
Mon 14 Apr 2008 20,992 A..H. --- "C:\WINDOWS\I386\FAXPATCH.EXE"
Mon 14 Apr 2008 69,632 A..H. --- "C:\WINDOWS\I386\HWDB.DLL"
Mon 14 Apr 2008 144,384 A..H. --- "C:\WINDOWS\I386\IMAGEHLP.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDA1.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDA2.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDA3.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDAL.DLL"
Mon 14 Apr 2008 5,120 A..H. --- "C:\WINDOWS\I386\KBDARME.DLL"
Mon 14 Apr 2008 5,120 A..H. --- "C:\WINDOWS\I386\KBDARMW.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDAZE.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDAZEL.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDBE.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDBLR.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDBR.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDBU.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDCA.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDCR.DLL"
Mon 14 Apr 2008 7,168 A..H. --- "C:\WINDOWS\I386\KBDCZ.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDCZ1.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDCZ2.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDDA.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDDIV1.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDDIV2.DLL"
Mon 14 Apr 2008 5,120 A..H. --- "C:\WINDOWS\I386\KBDDV.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDES.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDEST.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDFA.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDFC.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDFI.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDFR.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDGAE.DLL"
Mon 14 Apr 2008 5,120 A..H. --- "C:\WINDOWS\I386\KBDGEO.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDGKL.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDGR.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDGR1.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDHE.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDHE220.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDHE319.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDHEB.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDHELA2.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDHELA3.DLL"
Mon 14 Apr 2008 8,192 A..H. --- "C:\WINDOWS\I386\KBDHEPT.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDHU.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDHU1.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDIC.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDINDEV.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDINGUJ.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDINHIN.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDINKAN.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDINMAR.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDINPUN.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDINTAM.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDINTEL.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDIR.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDIT.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDIT142.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDKAZ.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDKYR.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDLA.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDLT.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDLT1.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDLV.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDLV1.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDMON.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDNE.DLL"
Mon 14 Apr 2008 7,168 A..H. --- "C:\WINDOWS\I386\KBDNEC.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDNO.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDPL.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDPL1.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDPO.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDRO.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDRU.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDRU1.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDSF.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDSG.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDSL.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDSL1.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDSP.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDSW.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDSYR1.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDSYR2.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDTAT.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDTH0.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDTH1.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDTH2.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDTH3.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDTUF.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDTUQ.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDUK.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDUR.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDURDU.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDUS.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDUSL.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDUSR.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\KBDUSX.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDUZB.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDVNTC.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\KBDYCC.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\KBDYCL.DLL"
Mon 14 Apr 2008 92,288 A..H. --- "C:\WINDOWS\I386\KSECDD.SYS"
Mon 14 Apr 2008 329,728 A..H. --- "C:\WINDOWS\I386\NETSETUP.EXE"
Mon 14 Apr 2008 706,048 A..H. --- "C:\WINDOWS\I386\NTDLL.DLL"
Mon 14 Apr 2008 574,976 A..H. --- "C:\WINDOWS\I386\NTFS.SYS"
Mon 14 Apr 2008 31,744 A..H. --- "C:\WINDOWS\I386\NTSD.EXE"
Mon 14 Apr 2008 36,864 A..H. --- "C:\WINDOWS\I386\NTSDEXTS.DLL"
Mon 14 Apr 2008 24,064 A..H. --- "C:\WINDOWS\I386\PIDGEN.DLL"
Mon 14 Apr 2008 146,432 A..H. --- "C:\WINDOWS\I386\REGEDIT.EXE"
Mon 14 Apr 2008 232,960 A..H. --- "C:\WINDOWS\I386\SPCMDCON.SYS"
Mon 14 Apr 2008 11,264 A..H. --- "C:\WINDOWS\I386\SPNPINST.EXE"
Mon 14 Apr 2008 244,736 A..H. --- "C:\WINDOWS\I386\SYSPARSE.EXE"
Mon 14 Apr 2008 75,776 A..H. --- "C:\WINDOWS\I386\TELNET.EXE"
Mon 14 Apr 2008 25,600 A..H. --- "C:\WINDOWS\I386\TSCUPDC.DLL"
Mon 14 Apr 2008 469,504 A..H. --- "C:\WINDOWS\I386\USETUP.EXE"
Mon 14 Apr 2008 84,939 A..H. --- "C:\WINDOWS\I386\WINNT.EXE"
Mon 14 Apr 2008 48,128 A..H. --- "C:\WINDOWS\I386\WINNT32.EXE"
Mon 14 Apr 2008 1,171,456 A..H. --- "C:\WINDOWS\I386\WINNT32A.DLL"
Mon 14 Apr 2008 1,298,432 A..H. --- "C:\WINDOWS\I386\WINNT32U.DLL"
Mon 14 Apr 2008 754,176 A..H. --- "C:\WINDOWS\I386\WINNTBBA.DLL"
Mon 14 Apr 2008 756,224 A..H. --- "C:\WINDOWS\I386\WINNTBBU.DLL"
Mon 14 Apr 2008 53,248 A..H. --- "C:\WINDOWS\I386\WSDU.DLL"
Mon 14 Apr 2008 77,824 A..H. --- "C:\WINDOWS\I386\WSDUENG.DLL"
Mon 14 Apr 2008 162,128 A..H. --- "C:\WINDOWS\I386\DRW\DWWIN.EXE"
Mon 14 Apr 2008 28,672 A..H. --- "C:\WINDOWS\I386\DRW\FAULTH.DLL"
Mon 14 Apr 2008 706,048 A..H. --- "C:\WINDOWS\I386\SYSTEM32\NTDLL.DLL"
Mon 14 Apr 2008 470,016 A..H. --- "C:\WINDOWS\I386\SYSTEM32\SMSS.EXE"
Mon 14 Apr 2008 55,056 A..H. --- "C:\WINDOWS\I386\WIN9XUPG\CABINET.DLL"
Mon 14 Apr 2008 25,600 A..H. --- "C:\WINDOWS\I386\WIN9XUPG\CFGMGR32.DLL"
Mon 14 Apr 2008 99,376 A..H. --- "C:\WINDOWS\I386\WIN9XUPG\IMAGEHLP.DLL"
Mon 14 Apr 2008 106,496 A..H. --- "C:\WINDOWS\I386\WIN9XUPG\ISMIG.DLL"
Mon 14 Apr 2008 267,536 A..H. --- "C:\WINDOWS\I386\WIN9XUPG\MSVCRT.DLL"
Mon 14 Apr 2008 888,832 A..H. --- "C:\WINDOWS\I386\WIN9XUPG\SETUPAPI.DLL"
Mon 14 Apr 2008 3,584 A..H. --- "C:\WINDOWS\I386\WIN9XUPG\TWID.EXE"
Mon 14 Apr 2008 872,448 A..H. --- "C:\WINDOWS\I386\WIN9XUPG\W95UPG.DLL"
Mon 14 Apr 2008 12,288 A..H. --- "C:\WINDOWS\I386\WINNTUPG\APMUPGRD.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\WINNTUPG\BOSCOMP.DLL"
Mon 14 Apr 2008 58,128 A..H. --- "C:\WINDOWS\I386\WINNTUPG\CFGMGR32.DLL"
Mon 14 Apr 2008 40,960 A..H. --- "C:\WINDOWS\I386\WINNTUPG\CLUSCOMP.DLL"
Mon 14 Apr 2008 5,120 A..H. --- "C:\WINDOWS\I386\WINNTUPG\FSFILTER.DLL"
Mon 14 Apr 2008 6,656 A..H. --- "C:\WINDOWS\I386\WINNTUPG\FTCOMP.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\WINNTUPG\INPUPGRD.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\WINNTUPG\MSMQCOMP.DLL"
Mon 14 Apr 2008 121,344 A..H. --- "C:\WINDOWS\I386\WINNTUPG\NETUPGRD.DLL"
Mon 14 Apr 2008 11,264 A..H. --- "C:\WINDOWS\I386\WINNTUPG\NTDSUPG.DLL"
Mon 14 Apr 2008 6,144 A..H. --- "C:\WINDOWS\I386\WINNTUPG\NV4PREP.DLL"
Mon 14 Apr 2008 323,344 A..H. --- "C:\WINDOWS\I386\WINNTUPG\SETUPAPI.DLL"
Mon 14 Apr 2008 4,608 A..H. --- "C:\WINDOWS\I386\WINNTUPG\TSCOMP.DLL"
Mon 14 Apr 2008 11,776 A..H. --- "C:\WINDOWS\I386\WINNTUPG\VIDUPGRD.DLL"
Thu 3 Jul 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 14 Apr 2008 55,632 A..H. --- "C:\WINDOWS\I386\DRW\1033\DWINTL.DLL"
Mon 14 Apr 2008 65,536 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\ACROBAT\MIGRATE.DLL"
Mon 14 Apr 2008 30,208 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\CMMGR\MIGRATE.DLL"
Mon 14 Apr 2008 53,248 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\DEVUPGRD\MIGRATE.DLL"
Mon 14 Apr 2008 3,952 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\DMICALL\DMICALL.SYS"
Mon 14 Apr 2008 32,768 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\DMICALL\MIGRATE.DLL"
Mon 14 Apr 2008 13,824 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\DVD\MIGRATE.DLL"
Mon 14 Apr 2008 69,632 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\EASTMAN\MIGRATE.DLL"
Mon 14 Apr 2008 73,728 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\FAX\AWDVSTUB.EXE"
Mon 14 Apr 2008 25,600 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\FAX\MIGRATE.DLL"
Mon 14 Apr 2008 83,456 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\HPTOOLS\MIGRATE.DLL"
Mon 14 Apr 2008 40,960 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\IBMAV\MIGRATE.DLL"
Mon 14 Apr 2008 8,704 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\ICM\MIGRATE.DLL"
Mon 14 Apr 2008 10,240 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\IEMIG\MIGRATE.DLL"
Mon 14 Apr 2008 39,424 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MODEMS\MIGRATE.DLL"
Mon 14 Apr 2008 11,776 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MSGQUEUE\MIGRATE.DLL"
Mon 14 Apr 2008 7,680 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MSI\MIGRATE.DLL"
Mon 14 Apr 2008 33,792 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MSI\MSI9XMIG.DLL"
Mon 14 Apr 2008 31,744 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MSI\MSINTMIG.DLL"
Mon 14 Apr 2008 46,864 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MSP\MIGRATE.DLL"
Mon 14 Apr 2008 36,352 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\NECKBD\MIGRATE.DLL"
Mon 14 Apr 2008 176,128 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\NECPA\MIGRATE.DLL"
Mon 14 Apr 2008 147,456 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\NECWPS\MIGRATE.DLL"
Mon 14 Apr 2008 86,016 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\OCTOPUS\MIGRATE.DLL"
Mon 14 Apr 2008 37,888 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\OEWAB\MIGRATE.DLL"
Mon 14 Apr 2008 30,208 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\PRINT\MIGRATE.DLL"
Mon 14 Apr 2008 35,328 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\PWS\MIGRATE.DLL"
Mon 14 Apr 2008 184,320 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\RUMBA\MIGRATE.DLL"
Mon 14 Apr 2008 69,632 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\SETUP\MIGRATE.DLL"
Mon 14 Apr 2008 76,288 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\TRANSACT\MIGRATE.DLL"
Mon 14 Apr 2008 14,848 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\WIA\MIGRATE.DLL"
Mon 14 Apr 2008 40,960 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\WMP\MIGRATE.DLL"
Mon 14 Apr 2008 108,544 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MAPI\DLL\MIGRATE.DLL"
Mon 14 Apr 2008 36,864 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MAPI\DLL\MKNTFRMCACHE.EXE"
Mon 14 Apr 2008 25,629 A..H. --- "C:\WINDOWS\I386\WIN9XMIG\MAPI\DLL\MSPATCHA.DLL"
Mon 14 Apr 2008 5,632 A..H. --- "C:\WINDOWS\I386\WINNTUPG\MS\MODEMSHR\MDMSHRUP.DLL"
Mon 14 Apr 2008 30,748 A..H. --- "C:\WINDOWS\I386\WINNTUPG\MS\SNA\IBMMGUG.DLL"
Mon 14 Apr 2008 38,941 A..H. --- "C:\WINDOWS\I386\WINNTUPG\MS\SNA\NTSNAUPG.DLL"
Mon 14 Apr 2008 28,701 A..H. --- "C:\WINDOWS\I386\WINNTUPG\MS\SNA\SNADLCUG.DLL"
Mon 14 Apr 2008 114,717 A..H. --- "C:\WINDOWS\I386\WINNTUPG\OEM\EQN\EQNUPGRD.DLL"
Mon 14 Apr 2008 33,792 A..H. --- "C:\WINDOWS\I386\WINNTUPG\OEM\TIGERJET\TJUPG.DLL"
Mon 14 Apr 2008 74,802 A..H. --- "C:\WINDOWS\I386\ASMS\6000\MSFT\VCRTL\ATL.DLL"
Mon 14 Apr 2008 995,383 A..H. --- "C:\WINDOWS\I386\ASMS\6000\MSFT\VCRTL\MFC42.DLL"
Mon 14 Apr 2008 995,384 A..H. --- "C:\WINDOWS\I386\ASMS\6000\MSFT\VCRTL\MFC42U.DLL"
Mon 14 Apr 2008 401,462 A..H. --- "C:\WINDOWS\I386\ASMS\6000\MSFT\VCRTL\MSVCP60.DLL"
Mon 14 Apr 2008 9,756 A..H. --- "C:\WINDOWS\I386\WINNTUPG\OEM\DIGI\ASYNC\DGUPGRD.DLL"
Mon 14 Apr 2008 11,292 A..H. --- "C:\WINDOWS\I386\WINNTUPG\OEM\DIGI\REALPORT\DGRPUPG.DLL"
Mon 14 Apr 2008 31,744 A..H. --- "C:\WINDOWS\I386\WINNTUPG\OEM\SPX\MPS\SPXUPGRD.DLL"
Mon 14 Apr 2008 1,724,416 A..H. --- "C:\WINDOWS\I386\ASMS\1000\MSFT\WINDOWS\GDIPLUS\GDIPLUS.DLL"
Mon 14 Apr 2008 50,688 A..H. --- "C:\WINDOWS\I386\ASMS\7000\MSFT\WINDOWS\MSWINCRT\MSVCIRT.DLL"
Mon 14 Apr 2008 322,560 A..H. --- "C:\WINDOWS\I386\ASMS\7000\MSFT\WINDOWS\MSWINCRT\MSVCRT.DLL"
Mon 14 Apr 2008 72,732 A..H. --- "C:\WINDOWS\I386\WINNTUPG\OEM\DIGI\ISDN\BRI\DIGIUPG.DLL"
Mon 14 Apr 2008 28,701 A..H. --- "C:\WINDOWS\I386\WINNTUPG\OEM\DIGI\ISDN\PRI\DIGPRIUP.DLL"
Mon 14 Apr 2008 921,088 A..H. --- "C:\WINDOWS\I386\ASMS\6000\MSFT\WINDOWS\COMMON\CONTROLS\COMCTL32.DLL"
Finished!The second hijack log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:15 PM, on 8/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Softricity\SoftGrid for Windows Desktops\sftvsa.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Softricity\SoftGrid for Windows Desktops\sftlist.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Softricity\SoftGrid for Windows Desktops\sftdcc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\vsnp2uvc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,"C:\Program Files\Softricity\SoftGrid for Windows Desktops\sftdcc.exe"
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [SoftGridTray] C:\Program Files\Softricity\SoftGrid for Windows Desktops\SFTTray.exe /autostart
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.babson.edu
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1215105907878O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = babson.edu
O17 - HKLM\Software\..\Telephony: DomainName = babson.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = babson.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = babson.edu
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SoftGrid Client (sftlist) - Softricity, Inc. - C:\Program Files\Softricity\SoftGrid for Windows Desktops\sftlist.exe
O23 - Service: SoftGrid Virtual Service Agent (sftvsa) - Softricity, Inc. - C:\Program Files\Softricity\SoftGrid for Windows Desktops\sftvsa.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
--
End of file - 11803 bytes
Once again Thanks a million!