ComboFix 08-09-25.07 - NICHOLAS MENDILLO 2008-09-26 12:37:36.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.155 [GMT -4:00]
Running from: C:\Documents and Settings\NICHOLAS MENDILLO\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\NICHOLAS MENDILLO\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\byXPHxYQ.dll
C:\WINDOWS\system32\frkosybh.dll
C:\WINDOWS\system32\leyxxn.dll
C:\WINDOWS\system32\lwughfvg.dll
C:\WINDOWS\system32\nnnmlMeE.dll
C:\WINDOWS\system32\QYxHPXyb.ini
C:\WINDOWS\system32\QYxHPXyb.ini2
C:\WINDOWS\system32\xgyinccj.dll
C:\WINDOWS\system32\YUR11.exe
C:\WINDOWS\system32\YUR12.exe
C:\WINDOWS\system32\YUR13.exe
C:\WINDOWS\system32\YUR76.exe
C:\WINDOWS\system32\YUR77.exe
C:\WINDOWS\system32\YUR78.exe
C:\WINDOWS\system32\YUR7A.exe
C:\WINDOWS\system32\YURD.exe
C:\x
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-08-26 to 2008-09-26 )))))))))))))))))))))))))))))))
.
2008-09-26 12:22 . 2008-09-24 02:13 25,088 --a------ C:\WINDOWS\system32\YUR8.exe
2008-09-26 01:07 . 2008-09-26 01:07 <DIR> d----c--- C:\_OTMoveIt
2008-09-25 21:16 . 2008-09-08 23:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-09-25 21:16 . 2008-09-19 12:26 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-09-25 21:16 . 2008-09-19 12:26 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-09-25 21:16 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-09-25 16:32 . 2008-09-26 01:22 <DIR> d----c--- C:\rsit
2008-09-24 19:38 . 2008-09-24 19:38 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-24 19:23 . 2008-09-26 11:45 <DIR> d----c--- C:\SDFix
2008-09-24 15:52 . 2008-09-24 15:52 <DIR> d-------- C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Lexmark Productivity Studio
2008-09-24 13:11 . 2008-09-24 13:11 <DIR> dr-hsc--- C:\resycled
2008-09-23 23:59 . 2008-09-23 23:59 <DIR> d-------- C:\Program Files\Lexmark Toolbar
2008-09-23 23:57 . 2008-09-24 15:56 <DIR> d-------- C:\Documents and Settings\All Users\Lx_cats
2008-09-23 23:48 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-09-23 23:48 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\dllcache\usbprint.sys
2008-09-23 23:46 . 2008-09-23 23:46 <DIR> d----c--- C:\logs
2008-09-23 23:45 . 2006-08-01 01:53 40,960 --a------ C:\WINDOWS\system32\lxdivs.dll
2008-09-23 23:44 . 2007-03-30 10:13 344,064 --a------ C:\WINDOWS\system32\lxdicoin.dll
2008-09-23 23:43 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-23 23:43 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-23 23:42 . 2001-08-17 22:36 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll
2008-09-23 23:42 . 2001-08-17 22:36 87,040 --a------ C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2008-09-23 23:41 . 2007-03-23 15:44 692,224 --a------ C:\WINDOWS\system32\lxdidrs.dll
2008-09-23 23:41 . 2007-02-09 14:07 69,632 --a------ C:\WINDOWS\system32\lxdicnv4.dll
2008-09-23 23:41 . 2007-01-23 19:40 65,536 --a------ C:\WINDOWS\system32\lxdicaps.dll
2008-09-23 23:20 . 2008-09-23 23:42 <DIR> d-------- C:\Program Files\Lexmark 3500-4500 Series
2008-09-22 23:13 . 2008-09-23 01:34 <DIR> d-------- C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\ImgBurn
2008-09-22 02:35 . 2008-09-22 02:35 <DIR> d-------- C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\dvdcss
2008-09-17 00:46 . 2008-09-24 12:50 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-15 13:59 . 2008-09-24 16:13 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-15 13:59 . 2008-09-15 13:59 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-06 15:54 . 2008-09-06 15:55 117,527 --a--c--- C:\Route 2 on Independence Day.mp3
2008-09-06 15:52 . 2008-09-06 15:52 894,504 --a------ C:\Program Files\WGAPluginInstall.exe
2008-08-30 00:15 . 2008-08-30 00:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-08-30 00:13 . 2008-08-30 00:14 <DIR> d-------- C:\Program Files\Dell Support Center
2008-08-30 00:13 . 2008-08-30 00:13 <DIR> d-------- C:\Program Files\Common Files\supportsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-26 20:00 --------- d-----w C:\Program Files\Config
2008-09-26 19:59 --------- d-----w C:\Program Files\Logs
2008-09-26 15:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-24 05:11 --------- d-----w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\uTorrent
2008-09-23 02:41 --------- d-----w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Vso
2008-09-10 03:21 267,056 ----a-w C:\Program Files\uTorrent.exe
2008-09-03 17:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-09-01 06:24 --------- d-----w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Registry Booster
2008-08-31 20:07 --------- d-----w C:\Program Files\TabIt
2008-08-30 04:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-08-25 04:31 --------- d-----w C:\Program Files\Reports
2008-08-25 04:26 --------- d-----w C:\Program Files\wxp
2008-08-25 04:26 --------- d-----w C:\Program Files\w2k
2008-08-25 04:26 --------- d-----w C:\Program Files\Trans
2008-08-25 04:26 --------- d-----w C:\Program Files\License
2008-08-25 04:26 --------- d-----w C:\Program Files\DbgHelp
2008-08-25 04:24 5,991,904 ----a-w C:\Program Files\Sunbelt-Personal-Firewall.exe
2008-08-24 22:18 86,733,638 -c--a-w C:\registrybackup.reg
2008-08-24 17:34 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-08-24 17:34 --------- d-----w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Malwarebytes
2008-08-24 17:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-24 17:33 2,085,280 ----a-w C:\Program Files\mbam-setup.exe
2008-08-22 16:38 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-20 17:31 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-17 19:01 38,472 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-17 19:01 17,144 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-08-07 05:53 --------- d-----w C:\Program Files\Google
2008-07-31 00:59 32,768 ----a-w C:\Program Files\bcd_installed.exe
2008-07-30 14:36 95,528 ----a-w C:\Program Files\SbPFLnch.exe
2008-07-30 14:36 95,528 ----a-w C:\Program Files\SbFw.dll
2008-07-30 14:36 91,432 ----a-w C:\Program Files\SbFwIm.dll
2008-07-30 14:36 79,144 ----a-w C:\Program Files\SbPFWsc.dll
2008-07-30 14:36 62,760 ----a-w C:\Program Files\SDK_Inst.exe
2008-07-30 14:36 275,752 ----a-w C:\Program Files\SbFwe.dll
2008-07-30 14:36 111,912 ----a-w C:\Program Files\SbErrRpt.exe
2008-07-30 14:36 1,705,256 ----a-w C:\Program Files\SbPFCl.exe
2008-07-30 14:36 1,361,192 ----a-w C:\Program Files\SbPFSvc.exe
2008-07-30 13:58 3,293 ----a-w C:\Program Files\Readme.txt
2008-06-12 23:24 1,495,112 ----a-w C:\Program Files\install_flash_player.exe
2008-03-21 15:40 122,879 -c--a-w C:\Program Files\4482-utorrent.8020.dmp
2008-03-19 08:37 144,665 -c--a-w C:\Program Files\4482-utorrent.d009.dmp
2008-03-14 21:38 1,454,656 ----a-w C:\Program Files\Silverlight.exe
2008-02-17 03:12 132,608 ----a-w C:\Program Files\VundoFix.exe
2008-02-15 22:29 50,688 ----a-w C:\Program Files\ATF-Cleaner.exe
2008-02-04 19:04 555,572 ----a-w C:\Program Files\spf4-en.chm
2008-01-29 21:47 125,164 -c--a-w C:\Program Files\4482-utorrent.5094.dmp
2008-01-26 18:36 158,275 -c--a-w C:\Program Files\4482-utorrent.b16a.dmp
2007-12-09 08:36 2,400,784 ----a-w C:\Program Files\WLinstaller.exe
2007-10-02 12:34 148,511 -c--a-w C:\Program Files\4482-utorrent.54f2.dmp
2007-08-10 03:11 1,436,096 ----a-w C:\Program Files\Silverlight.1.0.RC.exe
2007-08-09 11:32 270,336 ----a-w C:\Program Files\cfgconv.exe
2007-06-28 15:41 47,360 -c--a-w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\pcouffin.sys
2007-05-18 00:40 1,066 -c--a-w C:\Program Files\SuperDAT.log
2007-05-18 00:36 736,180 ----a-w C:\Program Files\CSA.exe
2007-04-09 21:47 5,632 -csha-w C:\Program Files\Thumbs.db
2007-01-22 15:22 859,648 ----a-w C:\Program Files\PocoFoundation.dll
2007-01-22 15:22 470,016 ----a-w C:\Program Files\PocoXML.dll
2007-01-22 15:22 467,456 ----a-w C:\Program Files\PocoNet.dll
2007-01-22 15:22 211,456 ----a-w C:\Program Files\PocoUtil.dll
2007-01-22 15:22 18,432 ----a-w C:\Program Files\PocoExt.dll
2007-01-08 18:15 29,424 ----a-w C:\Program Files\1942.zip
2006-12-24 01:40 680,575 ----a-w C:\Program Files\TabIt-2.03-full.exe
2006-09-25 16:11 263,680 ----a-w C:\Program Files\FairUse4WM.exe
2006-07-19 20:52 466,944 ----a-w C:\Program Files\boost_regex-vc71-mt-1_33_1.dll
2006-03-09 15:59 36,465,208 ----a-w C:\Program Files\iTunesSetup.exe
2006-02-28 19:46 290,816 ----a-w C:\Program Files\curllib.dll
2006-02-14 19:36 97,280 ----a-w C:\Program Files\zlibwapi.dll
2006-02-14 19:36 155,648 ----a-w C:\Program Files\ssleay32.dll
2006-02-14 19:35 888,832 ----a-w C:\Program Files\kticonv.dll
2006-02-14 19:35 827,392 ----a-w C:\Program Files\libeay32.dll
2006-01-21 21:10 11,817,800 ----a-w C:\Program Files\GoogleEarth.exe
2006-01-17 23:28 8,715,352 ----a-w C:\Program Files\Install_AIM.exe
2005-12-05 23:00 74,448 -c----w C:\Program Files\DSETUP.dll
2005-12-05 23:00 484,560 ------w C:\Program Files\DXSETUP.exe
2005-12-05 23:00 2,247,888 -c----w C:\Program Files\dsetup32.dll
2004-11-09 14:21 29,619,712 ----a-w C:\Program Files\finaldraft7.exe
2003-08-20 11:05 41 -c--a-w C:\Program Files\Setup.Ini
2003-03-19 01:20 1,060,864 ----a-w C:\Program Files\mfc71.dll
2003-03-19 01:12 1,047,552 ----a-w C:\Program Files\mfc71u.dll
2003-03-19 00:14 499,712 ----a-w C:\Program Files\msvcp71.dll
2003-02-21 08:42 348,160 ----a-w C:\Program Files\msvcr71.dll
2001-09-25 20:05 1,707,856 ----a-w C:\Program Files\InstMsiA.Exe
2001-09-11 23:04 1,821,008 ----a-w C:\Program Files\InstMsiW.Exe
.
((((((((((((((((((((((((((((( snapshot@2008-09-26_11.33.18.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-24 06:13:13 25,088 ----a-w C:\WINDOWS\system32\YURE.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-06-02 67160]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"\YUR8.exe"="C:\Windows\system32\YUR8.exe" [2008-09-24 25088]
"\YURE.exe"="C:\Windows\system32\YURE.exe" [2008-09-24 25088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]
"vptray"="C:\Program Files\NavNT\vptray.exe" [2001-09-24 73728]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-24 729178]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 114688]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 77824]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" [2008-01-24 136512]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"lxdimon.exe"="C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 434864]
"lxdiamon"="C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 25264]
"\YUR8.exe"="C:\Windows\system32\YUR8.exe" [2008-09-24 25088]
"\YURE.exe"="C:\Windows\system32\YURE.exe" [2008-09-24 25088]
"SigmatelSysTrayApp"="stsystra.exe" [2005-09-09 C:\WINDOWS\stsystra.exe]
C:\Documents and Settings\NICHOLAS MENDILLO\Start Menu\Programs\Startup\
MEMonitor.lnk - E:\Programs\V CAST Music Manager\MEMonitor.exe [2008-05-23 951640]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-10-06 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
SafeConnect.lnk - C:\Program Files\SafeConnect\scClient.exe [2007-04-09 206368]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll schannel.dll digest.dll msnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2007-10-19 21:16 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"mW[־`=v%S8>grl>\=۱"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\uTorrent.exe"=
"E:\\Programs\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"c:\\program files\\bcd_installed.exe"=
"C:\\WINDOWS\\system32\\lxdicoms.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"C:\\WINDOWS\\system32\\lxdicfg.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
"C:\\WINDOWS\\system32\\lxdiih.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 SbFw;SbFw;C:\WINDOWS\system32\drivers\SbFw.sys [2008-07-16 269736]
R1 sbhips;Sunbelt HIPS Driver;C:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 66600]
R2 lxdi_device;lxdi_device;C:\WINDOWS\system32\lxdicoms.exe [2007-06-11 517040]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe [2007-06-11 99248]
R2 SbPF.Launcher;SbPF.Launcher;C:\Program Files\SbPFLnch.exe [2008-07-30 95528]
R2 SCManager;SafeConnect Manager;C:\Program Files\SafeConnect\scManager.sys servicestart [ ]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\SbPFSvc.exe [2008-07-30 1361192]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{D260345B-44B5-4EFD-A172-602B3F5D8296} - C:\WINDOWS\system32\byXPHxYQ.dll
HKCU-Run-\YUR11.exe - C:\Windows\system32\YUR11.exe
HKCU-Run-\YURD.exe - C:\Windows\system32\YURD.exe
HKLM-Run-\YUR11.exe - C:\Windows\system32\YUR11.exe
HKLM-Run-\YURD.exe - C:\Windows\system32\YURD.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-26 16:00:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\YURE.exe 25088 bytes executable
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdiserv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\SafeConnect\scManager.sys
C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\SbPFCl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\WLTRAY.EXE
C:\Program Files\Network Associates\Common Framework\Mctray.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-09-26 16:17:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-26 20:15:49
ComboFix2.txt 2008-09-26 15:38:19
ComboFix3.txt 2008-08-24 07:43:13
ComboFix4.txt 2008-02-19 00:43:58
Pre-Run: 22,472,081,408 bytes free
Post-Run: 22,464,983,040 bytes free
273 --- E O F --- 2008-09-10 07:06:54
The HJT scan log is THIS
(Quick question... why do i all of a sudden have a 2nd hijack this icon logo in my programs folder but it is titled NICHOLAS MENDILLO.exe (that's my name...))
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:25:07, on 9/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe
C:\WINDOWS\system32\lxdicoms.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\SbPFLnch.exe
C:\Program Files\SafeConnect\scManager.sys
C:\Program Files\SbPFSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SbPFCl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
C:\Windows\system32\YUR8.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SafeConnect\scClient.exe
E:\Programs\V CAST Music Manager\MEMonitor.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Programs\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
O4 - HKLM\..\Run: [\YUR8.exe] C:\Windows\system32\YUR8.exe
O4 - HKLM\..\Run: [\YURE.exe] C:\Windows\system32\YURE.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [\YUR8.exe] C:\Windows\system32\YUR8.exe
O4 - HKCU\..\Run: [\YURE.exe] C:\Windows\system32\YURE.exe
O4 - HKUS\S-1-5-19\..\Run: [larepemijo] Rundll32.exe "C:\WINDOWS\system32\petolahu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [larepemijo] Rundll32.exe "C:\WINDOWS\system32\petolahu.dll",s (User 'NETWORK SERVICE')
O4 - Startup: MEMonitor.lnk = E:\Programs\V CAST Music Manager\MEMonitor.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SafeConnect.lnk = ?
O8 - Extra context menu item: Save with Download Manager... - file://C:\Program Files\J River\Media Center 11\DMDownload.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.micr...ActiveX/odc.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures05.ai...AIM.9.5.1.8.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\SbPFLnch.exe
O23 - Service: SafeConnect Manager (SCManager) - Unknown owner - C:\Program Files\SafeConnect\scManager.sys servicestart (file missing)
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\SbPFSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
--
End of file - 9485 bytes
thanks