Combo Fix:
ComboFix 08-02.05.3 - Monta Bellrose 2008-02-07 18:13:12.14 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.420 [GMT -8:00]
Running from: C:\Documents and Settings\Monta Bellrose\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\awtqnno.dll
C:\WINDOWS\system32\geebb.dll
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Monta Bellrose\Favorites\Online Security Guide.lnk
C:\Program Files\Helper
C:\Program Files\Helper\superfinderusa.dll
C:\Program Files\Helper\superfindout.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\msettings.ini
C:\WINDOWS\system32\aagjnxxc.dll
C:\WINDOWS\system32\afrxgkwe.dll
C:\WINDOWS\system32\aiumyuqm.ini
C:\WINDOWS\system32\akxeskoc.dll
C:\WINDOWS\system32\awtqnno.dll
C:\WINDOWS\system32\axeaaljk.dll
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\bemyvpqm.dll
C:\WINDOWS\system32\bkyjbmbo.dll
C:\WINDOWS\system32\bouhegog.ini
C:\WINDOWS\system32\caknjhfh.dll
C:\WINDOWS\system32\cbpgqfiy.dll
C:\WINDOWS\system32\cbvyeusd.ini
C:\WINDOWS\system32\cvrfcpki.dll
C:\WINDOWS\system32\cxxnjgaa.ini
C:\WINDOWS\system32\ddhjispo.ini
C:\WINDOWS\system32\ddjeojbj.dll
C:\WINDOWS\system32\dghwswgv.dll
C:\WINDOWS\system32\dikfjgyv.dll
C:\WINDOWS\system32\drvjonr.dll
C:\WINDOWS\system32\dsueyvbc.dll
C:\WINDOWS\system32\duqrrmxo.dll
C:\WINDOWS\system32\dvvfoqvi.dll
C:\WINDOWS\system32\efccaxw.dll
C:\WINDOWS\system32\ekmdxvxp.dll
C:\WINDOWS\system32\euxdargy.dll
C:\WINDOWS\system32\fihvtoig.dll
C:\WINDOWS\system32\fnnohode.dll
C:\WINDOWS\system32\fyvbpplk.dll
C:\WINDOWS\system32\gdamckha.dll
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\gfpqcjtk.dll
C:\WINDOWS\system32\giotvhif.ini
C:\WINDOWS\system32\gmyxjquw.ini
C:\WINDOWS\system32\gsvqvhat.dll
C:\WINDOWS\system32\gxnprckk.dll
C:\WINDOWS\system32\hfhjnkac.ini
C:\WINDOWS\system32\hvrgqeit.ini
C:\WINDOWS\system32\ibnxudsd.dll
C:\WINDOWS\system32\ifjljhcw.dll
C:\WINDOWS\system32\igivqqyl.ini
C:\WINDOWS\system32\iijshmio.dll
C:\WINDOWS\system32\ijkmp.ini
C:\WINDOWS\system32\ijkmp.ini2
C:\WINDOWS\system32\ijlfrghr.ini
C:\WINDOWS\system32\jdpifxwu.ini
C:\WINDOWS\system32\josvpvws.dll
C:\WINDOWS\system32\kfpeqmhs.ini
C:\WINDOWS\system32\kfsxbopc.ini
C:\WINDOWS\system32\klbvlxox.dll
C:\WINDOWS\system32\klppbvyf.ini
C:\WINDOWS\system32\lkaufpof.dll
C:\WINDOWS\system32\lkifpfbv.dll
C:\WINDOWS\system32\lmmmxieq.dll
C:\WINDOWS\system32\lnjaytpu.dll
C:\WINDOWS\system32\ltnxlgce.dll
C:\WINDOWS\system32\ltwnoqsf.dll
C:\WINDOWS\system32\lyqqvigi.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mjhxquis.dll
C:\WINDOWS\system32\mpnddxyv.dll
C:\WINDOWS\system32\msbxelvy.dll
C:\WINDOWS\system32\mtdwruxb.dll
C:\WINDOWS\system32\nfillfdw.ini
C:\WINDOWS\system32\ngusgmdu.dll
C:\WINDOWS\system32\obuvubfu.dll
C:\WINDOWS\system32\oglhkprx.dll
C:\WINDOWS\system32\oimhsjii.ini
C:\WINDOWS\system32\opfjqsxp.ini
C:\WINDOWS\system32\opsijhdd.dll
C:\WINDOWS\system32\oviksctc.dll
C:\WINDOWS\system32\oxmrrqud.ini
C:\WINDOWS\system32\plwglwki.dll
C:\WINDOWS\system32\pnfxwakq.ini
C:\WINDOWS\system32\pvsewkcl.ini
C:\WINDOWS\system32\pvuhoqrj.dll
C:\WINDOWS\system32\qafkqmms.ini
C:\WINDOWS\system32\qbwuveam.dll
C:\WINDOWS\system32\qfaemgxm.dll
C:\WINDOWS\system32\qjesyjth.dll
C:\WINDOWS\system32\qkawxfnp.dll
C:\WINDOWS\system32\qmttwvyc.dll
C:\WINDOWS\system32\qqcqqcgm.ini
C:\WINDOWS\system32\qstwa.ini
C:\WINDOWS\system32\qstwa.ini2
C:\WINDOWS\system32\qtsbofxn.dll
C:\WINDOWS\system32\qvjtgmpj.dll
C:\WINDOWS\system32\ricakgts.ini
C:\WINDOWS\system32\rstwa.ini
C:\WINDOWS\system32\rstwa.ini2
C:\WINDOWS\system32\rsxderer.dll
C:\WINDOWS\system32\rxlmbfdy.dll
C:\WINDOWS\system32\sfuyvfri.ini
C:\WINDOWS\system32\shmqepfk.dll
C:\WINDOWS\system32\slvurmuj.dll
C:\WINDOWS\system32\swefwiep.dll
C:\WINDOWS\system32\tahvqvsg.ini
C:\WINDOWS\system32\tieqgrvh.dll
C:\WINDOWS\system32\tltnmlny.dll
C:\WINDOWS\system32\trfmcvtx.dll
C:\WINDOWS\system32\ubtmxnva.dll
C:\WINDOWS\system32\uwxfipdj.dll
C:\WINDOWS\system32\vbekkceg.dll
C:\WINDOWS\system32\vcevnfmq.ini
C:\WINDOWS\system32\vtvmkroe.dll
C:\WINDOWS\system32\vukjwkvl.dll
C:\WINDOWS\system32\vygjfkid.ini
C:\WINDOWS\system32\vyxddnpm.ini
C:\WINDOWS\system32\wchjljfi.ini
C:\WINDOWS\system32\wdfllifn.dll
C:\WINDOWS\system32\whbdhlxh.dll
C:\WINDOWS\system32\wsyipyfd.dll
C:\WINDOWS\system32\wuqjxymg.dll
C:\WINDOWS\system32\wvudesnm.dllbox
C:\WINDOWS\system32\wybeg.ini
C:\WINDOWS\system32\wybeg.ini2
C:\WINDOWS\system32\wyrwcdye.dll
C:\WINDOWS\system32\xdabkwpt.dll
C:\WINDOWS\system32\xntxnlue.dll
C:\WINDOWS\system32\xpgoqnaw.dll
C:\WINDOWS\system32\xrpkhlgo.ini
C:\WINDOWS\system32\xybjeela.dll
C:\WINDOWS\system32\yccdd.ini
C:\WINDOWS\system32\yccdd.ini2
C:\WINDOWS\system32\ydjcvvfd.dll
C:\WINDOWS\system32\ygradxue.ini
C:\WINDOWS\system32\yifqgpbc.ini
C:\WINDOWS\system32\yuklagof.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SYMAVC32
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-06 22:24 . 2008-02-06 22:24 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-06 21:05 . 2008-02-06 21:26 <DIR> d-------- C:\Documents and Settings\Monta Bellrose\.housecall6.6
2008-02-06 15:16 . 2004-08-03 23:56 40,448 --a------ C:\WINDOWS\system32\rundll32.exe
2008-02-05 06:35 . 2008-02-05 06:35 90,688 --a------ C:\WINDOWS\system32\smmqkfaq.dll
2008-01-29 22:48 . 2008-01-31 21:27 <DIR> d-------- C:\Program Files\BitComet
2008-01-29 22:48 . 2008-02-06 20:03 <DIR> d-------- C:\Downloads
2008-01-29 22:48 . 2008-01-29 22:48 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2008-01-29 17:43 . 2008-02-06 19:35 <DIR> d-------- C:\Program Files\ClamWin
2008-01-29 17:43 . 2008-01-29 17:44 <DIR> d-------- C:\Documents and Settings\Monta Bellrose\Application Data\.clamwin
2008-01-29 17:43 . 2008-01-29 17:43 <DIR> d-------- C:\Documents and Settings\All Users\.clamwin
2008-01-29 07:51 . 2008-01-29 07:51 85,568 --a------ C:\WINDOWS\system32\klmvsbpy.exe
2008-01-19 10:54 . 2008-01-19 10:54 85,568 --a------ C:\WINDOWS\system32\bulnwrgr.exe
2008-01-18 10:57 . 2008-01-18 10:57 85,568 --a------ C:\WINDOWS\system32\mhwxdmpx.exe
2008-01-17 10:51 . 2008-01-18 10:52 294 --ahs---- C:\WINDOWS\system32\kncxtxfs.ini
2008-01-11 10:50 . 2008-02-06 06:34 49 --a------ C:\WINDOWS\BMf797109a.xml
2008-01-11 10:50 . 2008-02-07 18:13 21 --a------ C:\WINDOWS\pskt.ini
2008-01-09 13:51 . 2008-01-09 13:51 85,568 --a------ C:\WINDOWS\system32\nfpjqrxj.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 05:04 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-02-07 04:48 --------- d-----w C:\Program Files\Java
2008-02-07 03:35 --------- d-----w C:\Program Files\Apple Software Update
2008-02-07 03:32 --------- d-----w C:\Program Files\Last.fm
2008-02-06 22:19 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-01-30 04:20 --------- d-----w C:\Documents and Settings\Monta Bellrose\Application Data\Azureus
2008-01-30 01:44 --------- d-----w C:\Documents and Settings\Monta Bellrose\Application Data\.clamwin
2008-01-07 04:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Last.fm
2008-01-03 07:44 --------- d-----w C:\Documents and Settings\Monta Bellrose\Application Data\Uniblue
2007-12-24 22:12 --------- d-----w C:\Program Files\Azureus
2007-12-23 20:42 --------- d-----w C:\Program Files\DIFX
2007-12-11 06:37 --------- d-----w C:\Program Files\Acoustica MP3 Audio Mixer
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2005-05-24 00:17 32256 C:\WINDOWS\MIDIDEF.EXE]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-07-15 12:23 5674352]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-05-14 14:37 975872]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 10:28 147456]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 13:06 1327104]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-07-16 14:17 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2005-05-24 00:28 23552 C:\WINDOWS\CTHELPER.EXE]
"D-Link AirPlus XtremeG"="C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-03-28 13:25 1028096]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 16:49 65536]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 163840]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24 294912]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
"dont-touch-my-ads"="C:\Documents and Settings\Monta Bellrose\Desktop\Dont-Touch-My-Ads.exe" [ ]
"lxccmon.exe"="C:\Program Files\Lexmark 3300 Series\lxccmon.exe" [2005-02-21 05:21 200704]
"VTTimer"="VTTimer.exe" [2006-09-14 17:54 61440 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2007-04-25 14:41 184320 C:\WINDOWS\system32\VTTrayp.exe]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2008-01-20 22:08 86016]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-01-23 14:47 856064]
C:\Documents and Settings\Monta Bellrose\Start Menu\Programs\Startup\
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2008-01-06 20:01:10 114688]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-26 22:42:38 120832]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wingsa32]
wingsa32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvudesnm]
wvudesnm.dll
R0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys [2007-11-11 01:23]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2005-03-22 18:17]
S3 PL-40R;CASIO USB MIDI;C:\WINDOWS\system32\Drivers\pl40rwdm.sys [2004-09-30 23:08]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 21:57:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-02 07:33:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-01-03 07:33:01 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-07 18:20:33
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\WINDOWS\system32\lxcccoms.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Completion time: 2008-02-07 18:23:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 02:23:30
ComboFix2.txt 2008-02-07 09:38:22
ComboFix3.txt 2008-01-20 01:37:06
ComboFix4.txt 2008-01-03 07:07:16
.
2008-01-10 03:01:40 --- E O F ---
HI JACK THIS :
Logfile of HijackThis v1.99.1
Scan saved at 6:27:28 PM, on 2/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Lexmark 3300 Series\lxccmon.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\WINDOWS\system32\lxcccoms.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Monta Bellrose\Desktop\Program Files\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [dont-touch-my-ads] C:\Documents and Settings\Monta Bellrose\Desktop\Dont-Touch-My-Ads.exe
O4 - HKLM\..\Run: [lxccmon.exe] "C:\Program Files\Lexmark 3300 Series\lxccmon.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1005.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebo...toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: wingsa32 - wingsa32.dll (file missing)
O20 - Winlogon Notify: wvudesnm - wvudesnm.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Apple Mobile Device - Unknown owner - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (file missing)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe