ComboFix 08-10-29.04 - admin 2008-10-29 4:59:03.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.203 [GMT -4:00]
Running from: C:\Documents and Settings\admin\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\ujij.scr
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_006378_.tmp.dll
C:\WINDOWS\system32\_006379_.tmp.dll
C:\WINDOWS\system32\_006380_.tmp.dll
C:\WINDOWS\system32\_006381_.tmp.dll
C:\WINDOWS\system32\_006388_.tmp.dll
C:\WINDOWS\system32\_006390_.tmp.dll
C:\WINDOWS\system32\_006391_.tmp.dll
C:\WINDOWS\system32\_006393_.tmp.dll
C:\WINDOWS\system32\_006394_.tmp.dll
C:\WINDOWS\system32\_006397_.tmp.dll
C:\WINDOWS\system32\_006398_.tmp.dll
C:\WINDOWS\system32\_006400_.tmp.dll
C:\WINDOWS\system32\_006401_.tmp.dll
C:\WINDOWS\system32\_006402_.tmp.dll
C:\WINDOWS\system32\_006404_.tmp.dll
C:\WINDOWS\system32\_006405_.tmp.dll
C:\WINDOWS\system32\_006407_.tmp.dll
C:\WINDOWS\system32\_006408_.tmp.dll
C:\WINDOWS\system32\_006412_.tmp.dll
C:\WINDOWS\system32\_006413_.tmp.dll
C:\WINDOWS\system32\_006415_.tmp.dll
C:\WINDOWS\system32\_006418_.tmp.dll
C:\WINDOWS\system32\_006420_.tmp.dll
C:\WINDOWS\system32\_006422_.tmp.dll
C:\WINDOWS\system32\_006423_.tmp.dll
C:\WINDOWS\system32\_006424_.tmp.dll
C:\WINDOWS\system32\_006427_.tmp.dll
C:\WINDOWS\system32\_006428_.tmp.dll
C:\WINDOWS\system32\_006429_.tmp.dll
C:\WINDOWS\system32\_006430_.tmp.dll
C:\WINDOWS\system32\_006431_.tmp.dll
C:\WINDOWS\system32\_006436_.tmp.dll
C:\WINDOWS\system32\_006438_.tmp.dll
C:\WINDOWS\system32\MSINET.oca
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-29 )))))))))))))))))))))))))))))))
.
2008-10-28 04:51 . 2008-10-28 04:51 <DIR> d-------- C:\WINDOWS\ERUNT
2008-10-27 07:07 . 2008-10-27 07:07 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-27 07:07 . 2008-10-27 07:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-27 07:07 . 2008-10-27 07:07 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Malwarebytes
2008-10-27 07:07 . 2008-10-26 21:53 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-27 07:07 . 2008-10-26 21:53 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-27 06:12 . 2008-10-27 06:12 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-26 23:09 . 2008-10-26 23:09 <DIR> d-------- C:\Program Files\AOD
2008-10-26 23:09 . 2008-10-26 23:09 <DIR> d-------- C:\Program Files\AnswerWorks 4.0
2008-10-26 23:09 . 2008-10-26 23:09 <DIR> d-------- C:\Program Files\AIM6
2008-10-26 23:09 . 2008-10-27 05:47 <DIR> d-------- C:\Program Files\AIM
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\Java
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\HP
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\efax
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-10-26 23:08 . 2008-10-26 23:08 <DIR> d-------- C:\Program Files\Avira
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\eFax Messenger Plus
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\EA Games
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\DivX
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\Common Files\Remote Control USB Driver
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\Common Files\Remote Control Software Shared
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\Common Files\Real
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\Common Files\Nullsoft
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\Common Files\NSV
2008-10-26 23:07 . 2008-10-26 23:07 <DIR> d-------- C:\Program Files\Common Files\mozilla.org
2008-10-26 23:06 . 2008-10-26 23:06 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-10-26 23:06 . 2008-10-26 23:06 <DIR> d-------- C:\Program Files\Loader
2008-10-26 23:06 . 2008-10-26 23:06 <DIR> d-------- C:\Program Files\JavaSoft
2008-10-26 23:06 . 2008-10-26 23:06 <DIR> d-------- C:\Program Files\IrfanView
2008-10-26 23:06 . 2008-10-26 23:06 <DIR> d-------- C:\Program Files\iPod
2008-10-26 23:06 . 2008-10-26 23:06 <DIR> d-------- C:\Program Files\inKline Global
2008-10-26 23:06 . 2008-10-26 23:06 <DIR> d-------- C:\Program Files\INITIO
2008-10-26 23:06 . 2008-10-26 23:06 <DIR> d-------- C:\Program Files\hp photosmart
2008-10-26 23:05 . 2008-10-26 23:05 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-10-26 23:05 . 2008-10-26 23:05 <DIR> d-------- C:\Program Files\mozilla.org
2008-10-26 23:05 . 2008-10-26 23:05 <DIR> d-------- C:\Program Files\mIRC
2008-10-26 23:05 . 2008-10-26 23:05 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\WUSB11 WLAN Monitor
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Winamp
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Viewpoint
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\VideoLAN
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Support.com
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\SpyAssassin
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\SoftPlan Systems Inc
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\SharpC
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\RegCure
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Real
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Rapid.DeCoder
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\QuickTime
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Plaxo
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\PartyPoker
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\PartyGaming
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\Overland
2008-10-26 23:04 . 2008-10-26 23:04 <DIR> d-------- C:\Program Files\MUSICMATCH
2008-10-26 23:03 . 2008-10-26 23:03 <DIR> d-------- C:\Program Files\Yahoo!
2008-10-26 22:58 . 2008-10-26 22:58 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-10-26 22:45 . 2008-10-26 22:45 18,941 --a------ C:\WINDOWS\elyhyca.lib
2008-10-26 22:45 . 2008-10-26 22:45 17,852 --a------ C:\WINDOWS\caqygaqu.bin
2008-10-26 22:45 . 2008-10-26 22:45 17,054 --a------ C:\WINDOWS\ijabub.ban
2008-10-26 22:45 . 2008-10-26 22:45 16,100 --a------ C:\WINDOWS\diqawum._sy
2008-10-26 22:45 . 2008-10-26 22:45 15,863 --a------ C:\WINDOWS\zobovyji._sy
2008-10-26 22:45 . 2008-10-26 22:45 10,321 --a------ C:\WINDOWS\okykeguho.lib
2008-10-26 19:44 . 2008-10-26 21:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-26 14:35 . 2008-10-26 14:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-10-26 11:08 . 2008-10-26 11:10 <DIR> d-------- C:\WINDOWS\ShellNew
2008-10-09 13:31 . 2008-10-09 13:31 <DIR> d-------- C:\Documents and Settings\admin\Application Data\dvdcss
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 11:20 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-10-27 03:08 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-27 03:07 --------- d-----w C:\Program Files\Google
2008-10-27 03:07 --------- d-----w C:\Program Files\eFax Messenger 4.2
2008-10-27 03:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-27 03:06 --------- d-----w C:\Program Files\Microsoft Broadband Networking
2008-10-27 02:34 --------- d-----w C:\Program Files\Logitech
2008-10-27 02:34 --------- d-----w C:\Program Files\HP
2008-10-27 02:33 --------- d-----w C:\Program Files\AutoCAD 2004
2008-10-27 01:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-26 17:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-09-26 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-09-26 17:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-09-26 01:28 --------- d-----w C:\Documents and Settings\admin\Application Data\mIRC
2008-09-19 21:54 100,912 ----a-w C:\Documents and Settings\admin\Application Data\GDIPFONTCACHEV1.DAT
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2007-12-20 00:07 0 --sha-w C:\Documents and Settings\admin\Application Data\GDIPFONTCACHEV17d7dd891b4f4074878521e530ba1e2bc.dat
2007-12-17 22:20 0 --sha-w C:\Documents and Settings\admin\Application Data\d30a475ddb5847764bfd135508b412fbeae602b1.dat
2004-06-13 18:15 449 ----a-w C:\Documents and Settings\admin\UpdateReg.reg
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-14 1576176]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"cdloader"="C:\Documents and Settings\admin\Application Data\mjusbsp\cdloader2.exe" [2008-07-22 50520]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-01-05 176128]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2002-07-22 577602]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-09 28672]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-13 98304]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Tweak UI"="TWEAKUI.CPL" [2003-05-01 C:\WINDOWS\system32\TWEAKUI.CPL]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-8796-100000000002}\SC_Acrobat.exe [2006-10-17 25214]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2003-12-05 169472]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-09-14 09:57 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Documents and Settings\\admin\\Application Data\\mjusbsp\\magicJack.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4676:UDP"= 4676:UDP:Windows Media Format SDK (iexplore.exe)
"4677:UDP"= 4677:UDP:Windows Media Format SDK (iexplore.exe)
"4679:UDP"= 4679:UDP:Windows Media Format SDK (iexplore.exe)
R2 SSIPDDP;SSIPDDP Parallel port device driver;C:\WINDOWS\System32\DRIVERS\SSIPDDP.SYS [1998-07-14 55296]
R3 Dot4Usb HPH09;Dot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2003-01-30 18864]
.
Contents of the 'Scheduled Tasks' folder
2008-10-29 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-10-25 18:02]
2008-10-25 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-10-25 18:02]
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
Notify-dimsntfy - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\default.e4r\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-29 05:02:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\taskmgr.exe
.
**************************************************************************
.
Completion time: 2008-10-29 5:07:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-29 09:07:31
Pre-Run: 50,710,958,080 bytes free
Post-Run: 50,706,051,072 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
243 --- E O F --- 2008-10-29 05:03:32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:55 PM, on 10/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://mail.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\admin\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1207282089937O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1207282072750O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.c.../cpcScanner.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
--
End of file - 6957 bytes