Computer is in Normal Mode.
--------------------------------------------------------------------------------
System Restore was disabled; re-enabling.
Failed to create restore point: System Restore is disabled (service is not running).
Performed disk cleanup.
-- HijackThis log (run as admin.com) --------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:30:17 AM, on 2/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Multimedia keyboard utility\KbdAp32A.exe
C:\Program Files\Common Files\{20FFCB07-0960-1033-0827-040825200001}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\mmc.exe
C:\Documents and Settings\admin\Desktop\comboscan.exe
C:\DOCUME~1\admin\LOCALS~1\Temp\~rkaqpmy.tmp\admin.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/firefox
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Multimedia keyboard utility\KbdAp32A.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster Gold 17\Remind.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.c...es/MsnInstC.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall....ivex/hcImpl.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg...v45/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by20fd.bay20....es/MsnPUpld.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.co...amPlayerOCX.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1124405933109
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comne...login-devel.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://wpotc.kpdsb.o...sCamControl.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://www.dlink.com...in/h263ctrl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...779/mcfscan.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
-- HijackThis Fixed Entries (C:\Documents and Settings\admin\Desktop\backups\) --
backup-20070221-234636-172 O4 - HKLM\..\Run: [vidmon] C:\WINDOWS\system32\vidmon\vidmon.exe
backup-20070221-234636-205 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
backup-20070221-234636-322 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchgateway.net/search/
backup-20070221-234636-426 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
backup-20070221-234636-589 O8 - Extra context menu item: &Search - http://edits.mywebse...arch.jhtml?p=ZN
backup-20070221-234636-601 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
backup-20070221-234636-706 O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
backup-20070221-234636-835 O4 - HKLM\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
backup-20070221-234636-841 O4 - HKLM\..\Run: [MalwareBot] C:\Program Files\MalwareBot\MalwareBot.exe -boot
backup-20070221-234636-884 O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll (file missing)
backup-20070221-234636-973 O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\system32\nfomon\nfomon.exe
-- File Associations ------------------------------------------------------------
.bat - batfile - "%1" %*
.chm - chm.file - "C:\WINDOWS\hh.exe" %1
.com - comfile - "%1" %*
.exe - exefile - "%1" %*
.hlp - hlpfile - %SystemRoot%\System32\winhlp32.exe %1
.inf - inffile - %SystemRoot%\System32\NOTEPAD.EXE %1
.ini - inifile - %SystemRoot%\System32\NOTEPAD.EXE %1
.js - JSFile - %SystemRoot%\System32\WScript.exe "%1" %*
.lnk - lnkfile - {00021401-0000-0000-C000-000000000046}
.pif - piffile - "%1" %*
.reg - regfile - "%1"
.scr - scrfile - "%1" /S
.txt - txtfile - %SystemRoot%\system32\NOTEPAD.EXE %1
.vbs - VBSFile - %SystemRoot%\System32\WScript.exe "%1" %*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ----------------------
3 aeaudio - system32\drivers\aeaudio.sys
1 Avg7Core (AVG7 Kernel) - \SystemRoot\System32\Drivers\avg7core.sys
1 Avg7RsW (AVG7 Wrap Driver) - \SystemRoot\System32\Drivers\avg7rsw.sys
1 Avg7RsXP (AVG7 Resident Driver XP) - \SystemRoot\System32\Drivers\avg7rsxp.sys
1 AvgClean (AVG7 Clean Driver) - \SystemRoot\System32\Drivers\avgclean.sys
2 AvgTdi (AVG Network Redirector) - \SystemRoot\System32\Drivers\avgtdi.sys
3 CCDECODE (Closed Caption Decoder) - system32\DRIVERS\CCDECODE.sys
3 GEARAspiWDM - System32\Drivers\GEARAspiWDM.sys
3 HidUsb (Microsoft HID Class Driver) - system32\DRIVERS\hidusb.sys
3 ialm - System32\DRIVERS\ialmnt5.sys
1 InCDPass - System32\DRIVERS\InCDPass.sys
1 intelppm (Intel Processor Driver) - System32\DRIVERS\intelppm.sys
1 kbdhid (Keyboard HID Driver) - system32\DRIVERS\kbdhid.sys
3 mamotou - system32\DRIVERS\mamotou.sys
2 MaVctrl - system32\DRIVERS\MaVc2K.sys
3 moufiltr (Mouse Filter Driver) - system32\DRIVERS\moufiltr.sys
3 mouhid (Mouse HID Driver) - System32\DRIVERS\mouhid.sys
3 MSTEE (Microsoft Streaming Tee/Sink-to-Sink Converter) - system32\drivers\MSTEE.sys
3 NABTSFEC (NABTS/FEC VBI Codec) - system32\DRIVERS\NABTSFEC.sys
3 NdisIP (Microsoft TV/Video Connection) - system32\DRIVERS\NdisIP.sys
0 PCIIde - System32\DRIVERS\pciide.sys
0 PxHelp20 - System32\Drivers\PxHelp20.sys
3 rtl8139 (Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver) - System32\DRIVERS\RTL8139.SYS
0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - System32\drivers\sfdrv01.sys
0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - System32\drivers\sfhlp02.sys
0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - System32\drivers\sfvfs02.sys
3 SLIP (BDA Slip De-Framer) - system32\DRIVERS\SLIP.sys
3 smwdm - system32\drivers\smwdm.sys
3 snpstd2 (USB PC Camera (SN9C103)) - system32\DRIVERS\snpstd2.sys
3 streamip (BDA IPSink) - system32\DRIVERS\StreamIP.sys
3 usbaudio (USB Audio Driver (WDM)) - system32\drivers\usbaudio.sys
3 usbccgp (Microsoft USB Generic Parent Driver) - system32\DRIVERS\usbccgp.sys
3 usbehci (Microsoft USB 2.0 Enhanced Host Controller Miniport Driver) - System32\DRIVERS\usbehci.sys
3 usbprint (Microsoft USB PRINTER Class) - system32\DRIVERS\usbprint.sys
3 usbscan (USB Scanner Driver) - system32\DRIVERS\usbscan.sys
3 usbsermpt (Motorola USB Modem Driver for MPT) - system32\DRIVERS\usbsermpt.sys
3 USBSTOR (USB Mass Storage Driver) - System32\DRIVERS\USBSTOR.SYS
3 WpdUsb - System32\Drivers\wpdusb.sys
4 WS2IFSL (Windows Socket 2.0 Non-IFS Service Provider Support Environment) - \SystemRoot\System32\drivers\ws2ifsl.sys
3 WSTCODEC (World Standard Teletext Codec) - system32\DRIVERS\WSTCODEC.SYS
3 WudfPf (Windows Driver Foundation - User-mode Driver Framework Platform Driver) - system32\DRIVERS\WudfPf.sys
3 WudfRd (Windows Driver Foundation - User-mode Driver Framework Reflector) - system32\DRIVERS\wudfrd.sys
3 z520bus (Sony Ericsson 520 driver (WDM)) - system32\DRIVERS\z520bus.sys
3 z520mdfl (Sony Ericsson 520 USB WMC Modem Filter) - system32\DRIVERS\z520mdfl.sys
3 z520mdm (Sony Ericsson 520 USB WMC Modem Drivers) - system32\DRIVERS\z520mdm.sys
3 z520mgmt (Sony Ericsson 520 USB WMC Device Management Drivers) - system32\DRIVERS\z520mgmt.sys
3 z520obex (Sony Ericsson 520 USB WMC OBEX Interface Drivers) - system32\DRIVERS\z520obex.sys
3 {6080A529-897E-4629-A488-ABA0C29B635E} (Intel® Graphics Platform (SoftBIOS) Driver) - system32\drivers\ialmsbw.sys
3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (Intel® Graphics Chipset (KCH) Driver) - system32\drivers\ialmkchw.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
3 aspnet_state (ASP.NET State Service) - %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
2 Avg7Alrt (AVG7 Alert Manager Server) - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
2 Avg7UpdSvc (AVG7 Update Service) - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
2 AVGEMS (AVG E-mail Scanner) - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
4 Client IP-IPX - "C:\WINDOWS\system32\svchosts.exe" -e te-110-12-0000282
3 clr_optimization_v2.0.50727_32 (.NET Runtime Optimization Service v2.0.50727_X86) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
3 IDriverT (InstallDriver Table Manager) - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
2 InCDsrv (InCD Helper) - C:\Program Files\Ahead\InCD\InCDsrv.exe
3 iPod Service - "C:\Program Files\iPod\bin\iPodService.exe"
2 LexBceS (LexBce Server) - C:\WINDOWS\system32\LEXBCES.EXE
3 WMPNetworkSvc (Windows Media Player Network Sharing Service) - "C:\Program Files\Windows Media Player\WMPNetwk.exe"
3 WudfSvc (Windows Driver Foundation - User-mode Driver Framework) - %SystemRoot%\system32\svchost.exe -k WudfServiceGroup
-- Scheduled Tasks --------------------------------------------------------------
2007-02-16 13:34:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job<APPLES~1.JOB>
-- Files created between 2007-01-22 and 2007-02-22 ------------------------------
2007-02-21 23:49:59 0 d-------- C:\_OTMoveIt<_OTMOV~1>
2007-02-21 22:27:25 0 d-------- C:\Program Files\Common Files\{20FFCB07-095E-1033-0827-040825200001}<{20FFC~3>
2007-02-21 20:28:39 2 ---hs---- C:\WINDOWS\system32\taskkill.com
2007-02-21 20:28:39 2 ---hs---- C:\WINDOWS\system32\netstat.com
2007-02-21 16:41:11 0 d-------- C:\Program Files\1 Click PC Fix 2007<1CLICK~1>
2007-02-21 15:55:02 0 d-------- C:\!KillBox
2007-02-21 15:43:11 0 d-------- C:\Program Files\MalwareBot<MALWAR~1>
2007-02-21 13:57:32 0 d-------- C:\Program Files\webHancer<WEBHAN~1>
2007-02-21 11:14:15 32177 ---hs---- C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe<YAZZLE~2.EXE><Unsigned: n/a>
2007-02-21 10:44:13 0 d--h----- C:\Documents and Settings\All Users\Application Data\nfo
2007-02-21 10:44:07 0 d-------- C:\Program Files\InetGet2
2007-02-21 00:16:12 0 d-------- C:\Program Files\Common Files\{20FFCB07-095F-1033-0827-040825200001}<{20FFC~2>
2007-02-20 23:22:36 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2007-02-20 22:34:59 36864 --a------ C:\WINDOWS\system32\svchosts.exe<Unsigned: n/a>
2007-02-20 15:00:07 1154 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-20 14:59:13 79360 --a------ C:\WINDOWS\system32\swxcacls.exe<Unsigned: SteelWerX>
2007-02-20 14:59:13 40960 --a------ C:\WINDOWS\system32\swsc.exe<Unsigned: n/a>
2007-02-20 14:59:13 135168 --a------ C:\WINDOWS\system32\swreg.exe<Unsigned: SteelWerX>
2007-02-20 14:59:13 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe<Unsigned: S!Ri>
2007-02-20 14:59:13 53248 --a------ C:\WINDOWS\system32\Process.exe<Unsigned: http://www.beyondlogic.org>
2007-02-20 14:59:13 51200 --a------ C:\WINDOWS\system32\dumphive.exe<Unsigned: n/a>
2007-02-20 01:45:00 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2007-02-16 18:02:53 0 d-------- C:\Program Files\SpywareBot<SPYWAR~1>
2007-02-15 19:12:40 12288625 -----n--- C:\AVG7QT.DAT
2007-02-15 19:11:26 18432 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys<Unsigned: GRISOFT, s.r.o.>
2007-02-15 19:06:24 0 d-------- C:\Documents and Settings\admin\Application Data\AVG7
2007-02-15 19:06:14 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-02-15 19:06:08 4960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys<Unsigned: GRISOFT, s.r.o.>
2007-02-15 19:06:08 3968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys<Unsigned: GRISOFT, s.r.o.>
2007-02-15 19:05:55 27776 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys<Unsigned: GRISOFT, s.r.o.>
2007-02-15 19:05:54 4224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys<Unsigned: GRISOFT, s.r.o.>
2007-02-15 19:05:51 839936 --a------ C:\WINDOWS\system32\drivers\avg7core.sys<Unsigned: GRISOFT, s.r.o.>
2007-02-15 19:05:45 0 d-------- C:\Program Files\Grisoft
2007-02-15 19:05:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-02-15 01:55:38 0 d-------- C:\Documents and Settings\admin\Application Data\Registry Cleaner<REGIST~1>
2007-02-15 01:43:38 0 d-------- C:\Documents and Settings\admin\.housecall6.6<HOUSEC~1.6>
2007-02-14 18:58:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Riverdeep Interactive Learning Limited<RIVERD~1>
2007-02-14 18:54:46 35840 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS<Signed: Oak Technology Inc.>
2007-02-14 18:54:34 0 d-------- C:\Documents and Settings\All Users\Application Data\Broderbund Software<BRODER~1>
2007-02-14 18:53:08 0 d-------- C:\Program Files\Web Publish<WEBPUB~1>
2007-02-14 18:53:00 970752 --a------ C:\WINDOWS\system32\cdintf210.dll<CDINTF~1.DLL><Unsigned: Amyuni Technologies>
2007-02-14 18:48:35 0 d-------- C:\Program Files\Common Files\Broderbund<BRODER~1>
2007-02-14 18:48:20 0 d-------- C:\Program Files\PrintMaster Gold 17<PRINTM~1>
2007-02-14 18:43:42 0 d-------- C:\WINDOWS\system32\URTTEMP
2007-02-14 03:59:36 0 d--h----- C:\Program Files\Common Files\Uninstall Information<UNINST~1>
2007-02-14 03:59:36 0 d--h----- C:\Documents and Settings\All Users\Application Data\vidmon
2007-02-14 03:28:40 2 --a------ C:\WINDOWS\system32\wapisvit.exe<Unsigned: n/a>
2007-02-14 03:28:28 0 d-------- C:\Program Files\??crosoft.NET
2007-02-14 02:57:35 0 d-------- C:\Documents and Settings\LocalService\Application Data\NetMon
2007-02-14 02:57:34 1989 --a------ C:\WINDOWS\uninstall_nmon.vbs<UNINST~1.VBS>
2007-02-14 02:18:28 0 d-------- C:\Program Files\Common Files\{30FFCB07-095F-1033-0827-040825200001}<{30FFC~2>
2007-02-14 01:43:44 0 d-------- C:\Documents and Settings\admin\Application Data\PC Tools<PCTOOL~1>
2007-02-12 22:31:58 0 d-------- C:\Program Files\iPod
2007-02-12 22:31:47 0 d-------- C:\Program Files\iTunes
2007-02-12 22:29:51 0 d-------- C:\Program Files\Apple Software Update<APPLES~1>
2007-02-07 16:10:31 0 d-------- C:\Program Files\Activision<ACTIVI~1>
2007-02-01 19:01:19 0 d-------- C:\Program Files\Kaspersky Lab<KASPER~1>
2007-01-31 21:10:20 62464 --a------ C:\WINDOWS\system32\bszip.dll<Unsigned: BigSpeedSoft>
2007-01-31 21:10:10 0 ---hs---- C:\WINDOWS\system32\tracert.com
2007-01-31 21:10:10 0 ---hs---- C:\WINDOWS\system32\tasklist.com
2007-01-31 21:10:10 0 ---hs---- C:\WINDOWS\system32\regedit.com
2007-01-31 21:10:10 0 ---hs---- C:\WINDOWS\system32\ping.com
2007-01-31 21:10:10 0 ---hs---- C:\WINDOWS\system32\cmd.com
2007-01-31 21:10:10 0 d--hs---- C:\Program Files\outlook
2007-01-31 21:10:10 0 d--hs---- C:\Documents and Settings\admin\Complete
-- Find3M Report ----------------------------------------------------------------
2007-02-18 19:06:15 0 d-------- C:\Program Files\InterVideo<INTERV~1>
2007-02-18 19:06:15 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-02-18 19:05:57 0 d-------- C:\Program Files\Common Files\InterVideo<INTERV~1>
2007-02-16 21:55:04 0 d---s---- C:\Documents and Settings\admin\Application Data\Microsoft<MICROS~1>
2007-02-12 22:32:20 0 d-------- C:\Documents and Settings\admin\Application Data\Apple Computer<APPLEC~1>
2007-02-12 22:31:23 0 d-------- C:\Program Files\QuickTime<QUICKT~1>
2007-02-07 12:44:10 359808 --a------ C:\WINDOWS\system32\drivers\tcpip.sys<Unsigned: Microsoft Corporation>
2007-01-31 21:22:02 0 d-------- C:\Documents and Settings\admin\Application Data\Skype
2007-01-31 21:17:45 0 d-------- C:\Program Files\LimeWire
2007-01-14 23:54:08 0 d-------- C:\Program Files\Windows Media Connect 2<WINDOW~4>
2006-12-30 18:55:33 0 d-------- C:\Program Files\LG Electronics<LGELEC~1>
2006-12-30 18:55:20 0 d-------- C:\Program Files\LGGSM
-- Registry Dump ----------------------------------------------------------------
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"StandardInstall"=""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"FLMK08KB"="C:\\Program Files\\Multimedia keyboard utility\\KbdAp32A.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"="1"
"NoAdminPage"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"{20FFCB07-0960-1033-0827-040825200001}"="\"C:\\Program Files\\Common Files\\{20FFCB07-0960-1033-0827-040825200001}\\Update.exe\" te-110-12-0000282"
"{20FFCB07-095F-1033-0827-040825200001}"="\"C:\\Program Files\\Common Files\\{20FFCB07-095F-1033-0827-040825200001}\\Update.exe\" te-110-12-0000282"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
"{20FFCB07-095F-1033-0827-040825200001}"="\"C:\\Program Files\\Common Files\\{20FFCB07-095F-1033-0827-040825200001}\\Update.exe\" te-110-12-0000282"
"{20FFCB07-0960-1033-0827-040825200001}"="\"C:\\Program Files\\Common Files\\{20FFCB07-0960-1033-0827-040825200001}\\Update.exe\" te-110-12-0000282"
"{20FFCB07-095E-1033-0827-040825200001}"="\"C:\\Program Files\\Common Files\\{20FFCB07-095E-1033-0827-040825200001}\\Update.exe\" te-110-12-0000282"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
"{20FFCB07-095F-1033-0827-040825200001}"="\"C:\\Program Files\\Common Files\\{20FFCB07-095F-1033-0827-040825200001}\\Update.exe\" te-110-12-0000282"
"{20FFCB07-0960-1033-0827-040825200001}"="\"C:\\Program Files\\Common Files\\{20FFCB07-0960-1033-0827-040825200001}\\Update.exe\" te-110-12-0000282"
"{20FFCB07-095E-1033-0827-040825200001}"="\"C:\\Program Files\\Common Files\\{20FFCB07-095E-1033-0827-040825200001}\\Update.exe\" te-110-12-0000282"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
-- End of ComboScan: finished at 2007-02-22 at 00:31:34 -------------------------