Hello Tea, Thanks for the help. Here's the Combofix Log and the new HijackThis Log.
Combofix Log;ComboFix 08-08-23.03 - Jeannie 2008-08-24 18:56:49.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.583 [GMT -4:00]
Running from: C:\Documents and Settings\Jeannie\Desktop\Christopher Folder [DoNotDelete]\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Jeannie\Application Data\FunWebProducts
C:\Documents and Settings\Jeannie\Application Data\macromedia\Flash Player\#SharedObjects\8ZR99AQF\interclick.com
C:\Documents and Settings\Jeannie\Application Data\macromedia\Flash Player\#SharedObjects\8ZR99AQF\interclick.com\ud.sol
C:\Documents and Settings\Jeannie\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Jeannie\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Jeannie\Application Data\rhcvc8j0e567
C:\Documents and Settings\Jeannie\Cookies\jeannie@ads.pointroll[1].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@autos.yahoo[1].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@cubics[1].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@edge.ru4[2].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@insightexpressai[2].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@my.clearchannelradio[2].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@peanutlabs[2].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@questionmarket[1].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@server.cpmstar[2].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@spamblockerutility[2].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@specificclick[2].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@turn[2].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@www-t.cars[1].txt
C:\Documents and Settings\Jeannie\Cookies\jeannie@www.brides[1].txt
C:\Documents and Settings\Jeannie\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
C:\Documents and Settings\Jeannie\Local Settings\Temporary Internet Files\ijjistarter2.exe
C:\Documents and Settings\Jeannie\Local Settings\Temporary Internet Files\ijjistarter2FxB.exe
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00C649B8.urr
C:\Program Files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\
00019B60
C:\Program Files\MyWebSearch\bar\Cache\
00033440
C:\Program Files\MyWebSearch\bar\Cache\
0006A9FE.bin
C:\Program Files\MyWebSearch\bar\Cache\
0006C1EB.bin
C:\Program Files\MyWebSearch\bar\Cache\
0006C5A4.bin
C:\Program Files\MyWebSearch\bar\Cache\
0006CC1C
C:\Program Files\MyWebSearch\bar\Cache\
0046E654.bin
C:\Program Files\MyWebSearch\bar\Cache\
0046E877.bin
C:\Program Files\MyWebSearch\bar\Cache\
0046EA3C.bin
C:\Program Files\MyWebSearch\bar\Cache\
0046EAD8.bin
C:\Program Files\MyWebSearch\bar\Cache\
00693922
C:\Program Files\MyWebSearch\bar\Cache\
00694111.bin
C:\Program Files\MyWebSearch\bar\Cache\
00694864.bin
C:\Program Files\MyWebSearch\bar\Cache\
00694FF6.bin
C:\Program Files\MyWebSearch\bar\Cache\
00695341.bin
C:\Program Files\MyWebSearch\bar\Cache\
02439087.bin
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\Program Files\rhcvc8j0e567
C:\Program Files\VirusRemover2008
C:\Program Files\VirusRemover2008\Viruses.bdt
C:\Program Files\VirusRemover2008\VRM2008.exe
C:\Program Files\Zumie
C:\Program Files\Zumie\home.js
C:\Program Files\Zumie\uninstall.exe
C:\Program Files\Zumie\zopt.exe
C:\Program Files\Zumie\zumie.dll
C:\Program Files\Zumie\zumie.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\emtb.exe
C:\WINDOWS\jestertb.dll
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rafbsvnx.dll
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\aysrvbja.ini
C:\WINDOWS\system32\effOnnnn.ini
C:\WINDOWS\system32\effOnnnn.ini2
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\giimli.dll
C:\WINDOWS\system32\ixyjnhbf.ini
C:\WINDOWS\system32\lsnupgpm.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mpgpunsl.dll
C:\WINDOWS\system32\nnnnOffe.dll
C:\WINDOWS\system32\phcrc8j0e567.bmp
C:\WINDOWS\system32\pqbkdpvq.ini
C:\WINDOWS\system32\rCeLoUvw.ini
C:\WINDOWS\system32\rCeLoUvw.ini2
C:\WINDOWS\system32\uurxkkhw.dll
C:\WINDOWS\system32\vav.cpl
C:\WINDOWS\system32\vmlswdqo.dll
C:\WINDOWS\system32\wbvmfaib.dll
C:\WINDOWS\system32\wqwecw.dll
C:\WINDOWS\system32\wvUlIYOI.dll
C:\WINDOWS\system32\xdsqcyub.dll
C:\WINDOWS\system32\xxyyxvtS.dll
C:\WINDOWS\tsxngabr.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SYSREST.SYS
-------\Legacy_ZUMIE_SEARCH_SERVICE
-------\Service_Zumie Search Service
((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.
2008-08-22 10:16 . 2008-08-24 14:55 <DIR> d-------- C:\Documents and Settings\Jeannie\Download
2008-08-22 10:07 . 2008-08-24 18:47 193,259 --a------ C:\Documents and Settings\Jeannie\base.dat
2008-08-21 23:47 . 2008-08-21 23:47 <DIR> d-------- C:\Program Files\HoneyPrivatefolder
2008-08-21 22:48 . 2008-08-21 22:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SEC
2008-08-21 22:47 . 2008-08-24 18:54 <DIR> d-------- C:\Program Files\SecureExpertCleaner
2008-08-21 22:47 . 2008-08-24 18:23 <DIR> d-------- C:\My Downloads
2008-08-21 22:43 . 2008-08-24 18:50 <DIR> d-------- C:\Documents and Settings\Jeannie\Application Data\Simply Super Software
2008-08-21 22:43 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-08-21 22:43 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\unrar3.dll
2008-08-21 22:43 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-08-21 22:43 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-08-21 22:43 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-08-21 12:49 . 2008-08-21 12:49 156,556 --a------ C:\WINDOWS\system32\efcASkHW.dll
2008-08-21 12:43 . 2008-08-21 04:13 86,016 --a------ C:\WINDOWS\tqwolser.exe
2008-08-19 20:59 . 2008-08-19 20:59 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-19 20:59 . 2008-08-19 20:59 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-19 20:59 . 2008-08-19 20:59 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-19 20:59 . 2008-08-19 20:59 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-19 20:57 . 2008-08-19 21:00 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-18 23:16 . 2008-04-13 20:12 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-08-18 23:15 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-08-18 23:14 . 2008-04-13 20:11 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-08-18 21:26 . 2008-08-18 21:26 <DIR> d-------- C:\Program Files\Alwil Software
2008-08-18 21:09 . 2008-08-18 21:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-08-18 21:03 . 2008-08-18 21:03 0 --a------ C:\WINDOWS\system32\13.tmp
2008-08-14 18:37 . 2008-08-14 18:37 <DIR> d-------- C:\Documents and Settings\Jeannie\Application Data\acccore
2008-08-14 18:36 . 2008-08-14 18:36 <DIR> d-------- C:\Program Files\AIM Search
2008-08-14 18:36 . 2008-08-14 18:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\acccore
2008-08-14 18:35 . 2008-08-14 18:36 <DIR> d-------- C:\Program Files\AIM6
2008-08-12 19:49 . 2008-08-12 19:49 <DIR> d-------- C:\WINDOWS\system32\FxsTmp
2008-08-12 16:37 . 2008-04-11 15:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-12 16:37 . 2008-05-01 10:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-10 20:49 . 2008-08-13 10:29 <DIR> d-------- C:\Program Files\Cheat Engine
2008-08-10 20:49 . 2007-12-26 17:30 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2008-08-10 20:49 . 2007-12-26 17:30 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2008-08-09 10:59 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-08-07 00:54 . 2008-08-07 01:12 <DIR> d-------- C:\Program Files\Audacity
2008-08-07 00:35 . 2008-08-07 00:35 <DIR> d-------- C:\Documents and Settings\Jeannie\Application Data\Simple Star
2008-08-07 00:35 . 2004-05-07 18:24 413,696 --a------ C:\WINDOWS\Snapfish PhotoShow.scr
2008-08-07 00:33 . 2008-08-07 00:33 <DIR> d-------- C:\Program Files\LimeWire
2008-08-07 00:33 . 2008-08-22 20:12 <DIR> d-------- C:\Documents and Settings\Jeannie\Application Data\LimeWire
2008-08-07 00:32 . 2008-08-07 00:32 <DIR> d-------- C:\Program Files\Snapfish
2008-08-07 00:26 . 2008-08-07 00:36 <DIR> d-------- C:\Documents and Settings\Jeannie\Application Data\Snapfish
2008-08-02 19:40 . 2008-08-02 20:22 <DIR> d-------- C:\Documents and Settings\Jeannie\Application Data\U3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 05:23 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 23:16 --------- d-----w C:\Documents and Settings\Jeannie\Application Data\Hamachi
2008-08-22 19:43 --------- d-----w C:\Documents and Settings\Jeannie\Application Data\Yahoo!
2008-08-20 20:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-08-14 22:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-14 22:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-08-13 03:05 --------- d-----w C:\Program Files\MoodLogic
2008-08-11 18:47 --------- d-----w C:\Program Files\Verizon
2008-08-11 18:47 --------- d-----w C:\Program Files\Common Files\SupportSoft
2008-07-15 21:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\NexonUS
2008-07-15 14:49 --------- d-----w C:\Program Files\Hamachi
2008-07-15 14:48 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-07-14 19:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-14 19:52 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-07-14 19:48 --------- d-----w C:\Documents and Settings\Jeannie\Application Data\nfsmwdemo_Downloader[1]
2008-07-14 19:15 --------- d--h--w C:\Documents and Settings\Jeannie\Application Data\ijjigame
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-27 03:23 --------- d-----w C:\Program Files\Canon
2008-06-27 03:19 --------- d-----w C:\Program Files\Common Files\NewSoft
2008-06-27 03:18 --------- d-----w C:\Program Files\NewSoft
2008-06-27 03:18 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2008-06-27 03:18 --------- d-----w C:\Program Files\Common Files\PDFView
2008-06-27 03:18 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-27 03:18 --------- d-----w C:\Documents and Settings\Jeannie\Application Data\ScanSoft
2008-06-27 03:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-06-27 03:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-06-27 03:17 --------- d-----w C:\Program Files\ScanSoft
2008-06-27 03:16 --------- d-----w C:\Program Files\Common Files\CANON
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:09 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-04-03 07:15 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0A94B116-4504-4e26-AB05-E61E474AA38B}"= "C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL" [2008-01-27 03:16 61440]
[HKEY_CLASSES_ROOT\clsid\{0a94b116-4504-4e26-ab05-e61e474aa38b}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PanelApp"="C:\Documents and Settings\Jeannie\Local Settings\Application Data\Knowledge Networks\PanelApp\PanelApp.exe" [2007-01-24 13:57 31232]
"VPSKEYS"="C:\Program Files\Vpskeys\vpskeys.exe" [2003-03-29 11:52 102400]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-13 18:06 3660848]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Snapfish\SNAPFI~1\data\Xtras\mssysmgr.exe" [2005-01-31 15:06 208896]
"QuickInstallPack"="C:\Documents and Settings\Jeannie\Local Settings\Application Data\qip\QuickInstallPack.exe" [2008-08-21 22:47 1077200]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 11:12 695808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 08:04 59392]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-29 11:15 344064]
"CreateCD_Reminder"="C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe" [2004-07-16 15:17 53248]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2004-09-21 22:54 151552]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 01:08 28672]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-09-28 14:30 936960]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-27 21:18 185896]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 21:01 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 21:50 1603152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]
"WrtMon.exe"="C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 08:35 20480]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 10:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 19:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-10-21 18:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-10-21 21:44 2744832 C:\WINDOWS\ALCWZRD.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 18:35 1294336]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
PalTalk.lnk - C:\Program Files\Paltalk Messenger\paltalk.exe [2008-05-08 18:17:29 10452992]
SpySubtract.lnk - C:\Program Files\interMute\SpySubtract\SpySub.exe [2007-11-10 11:58:53 1187840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wqwecw.dll giimli.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\1194709151\\ee\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\Nexon\Combat Arms\CombatArms.exe"= C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe"= C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\\Nexon\\Combat Arms\\NMService.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"41340:TCP"= 41340:TCP:*:Disabled:SolidNetworkManager
"41340:UDP"= 41340:UDP:*:Disabled:SolidNetworkManager
"17056:TCP"= 17056:TCP:*:Disabled:SolidNetworkManager
"17056:UDP"= 17056:UDP:*:Disabled:SolidNetworkManager
"9339:TCP"= 9339:TCP:FB ** Game for big ones **
R1 aswsp;avast! Self Protection;C:\WINDOWS\system32\drivers\aswsp.sys [2008-07-19 10:35]
R2 aswfsblk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 10:37]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
S3 DBKDRVR54;DBKDRVR54;C:\Program Files\Cheat Engine\dbk32.sys [2007-12-27 05:45]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\Documents and Settings\Jeannie\Desktop\New Folder\ML engine\IlvMoney1129.sys []
S3 PanelSvc;PanelSvc;C:\Program Files\Knowledge Networks\PanelApp\PanelSvc.exe [2007-11-09 13:45]
S3 XDva030;XDva030;C:\WINDOWS\system32\XDva030.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-08-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
2008-04-03 C:\WINDOWS\Tasks\rpc.job
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-HookURL - (no file)
URLSearchHooks-Rank - (no file)
BHO-{513D0B8C-32F9-473D-8199-08CDCB57E783} - C:\WINDOWS\system32\wvUoLeCr.dll
Toolbar-{1B27DC3F-A487-486D-BBA8-CA45373B1457} - C:\WINDOWS\rafbsvnx.dll
HKCU-Run-\SUE67.exe - C:\Windows\SUE67.exe
HKCU-Run-\SUE6A.exe - C:\Windows\SUE6A.exe
HKCU-Run-\SUE6B.exe - C:\Windows\SUE6B.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-sysrest32.exe - C:\WINDOWS\system32\sysrest32.exe
HKLM-Run-\SUE67.exe - C:\Windows\SUE67.exe
HKLM-Run-\SUE6A.exe - C:\Windows\SUE6A.exe
HKLM-Run-\SUE6B.exe - C:\Windows\SUE6B.exe
HKLM-Run-Antivirus - C:\Program Files\VAV\vav.exe
HKLM-Run-VirusRemover2008 - C:\Program Files\VirusRemover2008\VRM2008.exe
HKLM-Run-cc528e63 - C:\WINDOWS\system32\mpgpunsl.dll
ShellExecuteHooks-{FA010552-4A27-4cb1-A1BB-3E2D697F1639} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Jeannie\Application Data\Mozilla\Firefox\Profiles\jhcryaqz.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://verizon-online.aol.com
FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.1.0.30109.0.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\nprcpt.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF -: plugin - C:\Program Files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-24 18:58:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"\\SUE67.exe"="C:\\Windows\\SUE67.exe"
"\\SUE6A.exe"="C:\\Windows\\SUE6A.exe"
"\\SUE6B.exe"="C:\\Windows\\SUE6B.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"\\SUE67.exe"="C:\\Windows\\SUE67.exe"
"\\SUE6A.exe"="C:\\Windows\\SUE6A.exe"
"\\SUE6B.exe"="C:\\Windows\\SUE6B.exe"
.
Completion time: 2008-08-24 18:58:52
ComboFix-quarantined-files.txt 2008-08-24 22:58:40
Pre-Run: 212,324,151,296 bytes free
Post-Run: 212,308,508,672 bytes free
413 --- E O F --- 2008-08-20 21:14:48
and HijackThis Log;Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:03:13 PM, on 8/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
C:\Program Files\Vpskeys\vpskeys.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\Snapfish\SNAPFI~1\data\Xtras\mssysmgr.exe
C:\Documents and Settings\Jeannie\Local Settings\Application Data\qip\QuickInstallPack.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HoneyPrivatefolder\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://verizon-online.aol.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR3 - URLSearchHook: (no name) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
R3 - URLSearchHook: Yahoo! 工具列 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O2 - BHO: Bho Class - {AB37CD3D-DC1D-46b2-ADCA-3CDC80FD2AD6} - C:\Documents and Settings\Jeannie\Local Settings\Application Data\Knowledge Networks\PanelApp\PanelApp_0806.2008.0725.1159.dll
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Yahoo! 工具列 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKCU\..\Run: [PanelApp] C:\Documents and Settings\Jeannie\Local Settings\Application Data\Knowledge Networks\PanelApp\PanelApp.exe
O4 - HKCU\..\Run: [VPSKEYS] C:\Program Files\Vpskeys\vpskeys.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Snapfish\SNAPFI~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [QuickInstallPack] "C:\Documents and Settings\Jeannie\Local Settings\Application Data\qip\QuickInstallPack.exe" /autorun
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/...?p=ZNxpt024YYUSO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
https://activatemydsl.verizon.net/sdcCommon...20Installer.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) -
http://disney.go.com/pirates/online/testAc...OnlineGames.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebook.com/controls/Facebo...toUploader3.cabO16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) -
http://www.solidstatenetworks.com/demos/pl...lidstateion.cabO20 - AppInit_DLLs: wqwecw.dll giimli.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PanelSvc - Unknown owner - C:\Program Files\Knowledge Networks\PanelApp\PanelSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
O23 - Service: Sony TVTA Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 11637 bytes